]> git.p6c8.net - policy-templates.git/blob - docs/index.md
Bump version for release
[policy-templates.git] / docs / index.md
1 Firefox policies can be specified using the [Group Policy templates on Windows](https://github.com/mozilla/policy-templates/tree/master/windows), [Intune on Windows](https://support.mozilla.org/kb/managing-firefox-intune), [configuration profiles on macOS](https://github.com/mozilla/policy-templates/tree/master/mac), or by creating a file called `policies.json`. On Windows, create a directory called `distribution` where the EXE is located and place the file there. On Mac, the file goes into `Firefox.app/Contents/Resources/distribution`. On Linux, the file goes into `firefox/distribution`, where `firefox` is the installation directory for firefox, which varies by distribution or you can specify system-wide policy by placing the file in `/etc/firefox/policies`.
2
3 Unfortunately, JSON files do not support comments, but you can add extra entries to the JSON to use as comments. You will see an error in about:policies, but the policies will still work properly. For example:
4
5 ```
6 {
7 "policies": {
8 "Authentication": {
9 "SPNEGO": ["mydomain.com", "https://myotherdomain.com"]
10 }
11 "Authentication_Comment": "These domains are required for us"
12 }
13 }
14 ```
15
16 | Policy Name | Description
17 | --- | --- |
18 | **[`3rdparty`](#3rdparty)** | Set policies that WebExtensions can access via chrome.storage.managed.
19 | **[`AllowedDomainsForApps`](#alloweddomainsforapps)** | Define domains allowed to access Google Workspace.
20 | **[`AppAutoUpdate`](#appautoupdate)** | Enable or disable automatic application update.
21 | **[`AppUpdatePin`](#appupdatepin)** | Prevent Firefox from being updated beyond the specified version.
22 | **[`AppUpdateURL`](#appupdateurl)** | Change the URL for application update.
23 | **[`Authentication`](#authentication)** | Configure sites that support integrated authentication.
24 | **[`AutoLaunchProtocolsFromOrigins`](#autolaunchprotocolsfromorigins)** | Define a list of external protocols that can be used from listed origins without prompting the user.
25 | **[`BackgroundAppUpdate`](#backgroundappupdate)** | Enable or disable the background updater (Windows only).
26 | **[`BlockAboutAddons`](#blockaboutaddons)** | Block access to the Add-ons Manager (about:addons).
27 | **[`BlockAboutConfig`](#blockaboutconfig)** | Block access to about:config.
28 | **[`BlockAboutProfiles`](#blockaboutprofiles)** | Block access to About Profiles (about:profiles).
29 | **[`BlockAboutSupport`](#blockaboutsupport)** | Block access to Troubleshooting Information (about:support).
30 | **[`Bookmarks`](#bookmarks)** | Add bookmarks in either the bookmarks toolbar or menu.
31 | **[`CaptivePortal`](#captiveportal)** | Enable or disable the detection of captive portals.
32 | **[`Certificates`](#certificates)** |
33 | **[`Certificates -> ImportEnterpriseRoots`](#certificates--importenterpriseroots)** | Trust certificates that have been added to the operating system certificate store by a user or administrator.
34 | **[`Certificates -> Install`](#certificates--install)** | Install certificates into the Firefox certificate store.
35 | **[`Containers`](#containers)** | Set policies related to [containers](https://addons.mozilla.org/firefox/addon/multi-account-containers/).
36 | **[`Cookies`](#cookies)** | Configure cookie preferences.
37 | **[`DefaultDownloadDirectory`](#defaultdownloaddirectory)** | Set the default download directory.
38 | **[`DisableAppUpdate`](#disableappupdate)** | Turn off application updates.
39 | **[`DisableBuiltinPDFViewer`](#disablebuiltinpdfviewer)** | Disable the built in PDF viewer.
40 | **[`DisabledCiphers`](#disabledciphers)** | Disable ciphers.
41 | **[`DisableDefaultBrowserAgent`](#disabledefaultbrowseragent)** | Prevent the default browser agent from taking any actions (Windows only).
42 | **[`DisableDeveloperTools`](#disabledevelopertools)** | Remove access to all developer tools.
43 | **[`DisableFeedbackCommands`](#disablefeedbackcommands)** | Disable the menus for reporting sites.
44 | **[`DisableFirefoxAccounts`](#disablefirefoxaccounts)** | Disable Firefox Accounts integration (Sync).
45 | **[`DisableFirefoxScreenshots`](#disablefirefoxscreenshots)** | Remove access to Firefox Screenshots.
46 | **[`DisableFirefoxStudies`](#disablefirefoxstudies)** | Disable Firefox studies (Shield).
47 | **[`DisableForgetButton`](#disableforgetbutton)** | Disable the "Forget" button.
48 | **[`DisableFormHistory`](#disableformhistory)** | Turn off saving information on web forms and the search bar.
49 | **[`DisableMasterPasswordCreation`](#disablemasterpasswordcreation)** | Remove the master password functionality.
50 | **[`DisablePasswordReveal`](#disablepasswordreveal)** | Do not allow passwords to be revealed in saved logins.
51 | **[`DisablePocket`](#disablepocket)** | Remove Pocket in the Firefox UI.
52 | **[`DisablePrivateBrowsing`](#disableprivatebrowsing)** | Remove access to private browsing.
53 | **[`DisableProfileImport`](#disableprofileimport)** | Disables the "Import data from another browser" option in the bookmarks window.
54 | **[`DisableProfileRefresh`](#disableprofilerefresh)** | Disable the Refresh Firefox button on about:support and support.mozilla.org
55 | **[`DisableSafeMode`](#disablesafemode)** | Disable safe mode within the browser.
56 | **[`DisableSecurityBypass`](#disablesecuritybypass)** | Prevent the user from bypassing security in certain cases.
57 | **[`DisableSetDesktopBackground`](#disablesetdesktopbackground)** | Remove the "Set As Desktop Background..." menuitem when right clicking on an image.
58 | **[`DisableSystemAddonUpdate`](#disablesystemaddonupdate)** | Prevent system add-ons from being installed or updated.
59 | **[`DisableTelemetry`](#disabletelemetry)** | DisableTelemetry
60 | **[`DisableThirdPartyModuleBlocking`](#disablethirdpartymoduleblocking)** | Do not allow blocking third-party modules.
61 | **[`DisplayBookmarksToolbar`](#displaybookmarkstoolbar)** | Set the initial state of the bookmarks toolbar.
62 | **[`DisplayMenuBar`](#displaymenubar)** | Set the state of the menubar.
63 | **[`DNSOverHTTPS`](#dnsoverhttps)** | Configure DNS over HTTPS.
64 | **[`DontCheckDefaultBrowser`](#dontcheckdefaultbrowser)** | Don't check if Firefox is the default browser at startup.
65 | **[`DownloadDirectory`](#downloaddirectory)** | Set and lock the download directory.
66 | **[`EnableTrackingProtection`](#enabletrackingprotection)** | Configure tracking protection.
67 | **[`EncryptedMediaExtensions`](#encryptedmediaextensions)** | Enable or disable Encrypted Media Extensions and optionally lock it.
68 | **[`EnterprisePoliciesEnabled`](#enterprisepoliciesenabled)** | Enable policy support on macOS.
69 | **[`ExemptDomainFileTypePairsFromFileTypeDownloadWarnings`](#exemptdomainfiletypepairsfromfiletypedownloadwarnings)** | Disable warnings based on file extension for specific file types on domains.
70 | **[`Extensions`](#extensions)** | Control the installation, uninstallation and locking of extensions.
71 | **[`ExtensionSettings`](#extensionsettings)** | Manage all aspects of extensions.
72 | **[`ExtensionUpdate`](#extensionupdate)** | Control extension updates.
73 | **[`FirefoxHome`](#firefoxhome)** | Customize the Firefox Home page.
74 | **[`FirefoxSuggest`](#firefoxsuggest)** | Customize Firefox Suggest.
75 | **[`GoToIntranetSiteForSingleWordEntryInAddressBar`](#gotointranetsiteforsinglewordentryinaddressbar)** | Force direct intranet site navigation instead of searching when typing single word entries in the address bar.
76 | **[`Handlers`](#handlers)** | Configure default application handlers.
77 | **[`HardwareAcceleration`](#hardwareacceleration)** | Control hardware acceleration.
78 | **[`Homepage`](#homepage)** | Configure the default homepage and how Firefox starts.
79 | **[`InstallAddonsPermission`](#installaddonspermission)** | Configure the default extension install policy as well as origins for extension installs are allowed.
80 | **[`LegacyProfiles`](#legacyprofiles)** | Disable the feature enforcing a separate profile for each installation.
81 | **[`LegacySameSiteCookieBehaviorEnabled`](#legacysamesitecookiebehaviorenabled)** | Enable default legacy SameSite cookie behavior setting.
82 | **[`LegacySameSiteCookieBehaviorEnabledForDomainList`](#legacysamesitecookiebehaviorenabledfordomainlist)** | Revert to legacy SameSite behavior for cookies on specified sites.
83 | **[`LocalFileLinks`](#localfilelinks)** | Enable linking to local files by origin.
84 | **[`ManagedBookmarks`](#managedbookmarks)** | Configures a list of bookmarks managed by an administrator that cannot be changed by the user.
85 | **[`ManualAppUpdateOnly`](#manualappupdateonly)** | Allow manual updates only and do not notify the user about updates.
86 | **[`NetworkPrediction`](#networkprediction)** | Enable or disable network prediction (DNS prefetching).
87 | **[`NewTabPage`](#newtabpage)** | Enable or disable the New Tab page.
88 | **[`NoDefaultBookmarks`](#nodefaultbookmarks)** | Disable the creation of default bookmarks.
89 | **[`OfferToSaveLogins`](#offertosavelogins)** | Control whether or not Firefox offers to save passwords.
90 | **[`OfferToSaveLoginsDefault`](#offertosaveloginsdefault)** | Set the default value for whether or not Firefox offers to save passwords.
91 | **[`OverrideFirstRunPage`](#overridefirstrunpage)** | Override the first run page.
92 | **[`OverridePostUpdatePage`](#overridepostupdatepage)** | Override the upgrade page.
93 | **[`PasswordManagerEnabled`](#passwordmanagerenabled)** | Remove (some) access to the password manager.
94 | **[`PasswordManagerExceptions`](#passwordmanagerexceptions)** | Prevent Firefox from saving passwords for specific sites.
95 | **[`PDFjs`](#pdfjs)** | Disable or configure PDF.js, the built-in PDF viewer.
96 | **[`Permissions`](#permissions)** | Set permissions associated with camera, microphone, location, and notifications.
97 | **[`PictureInPicture`](#pictureinpicture)** | Enable or disable Picture-in-Picture.
98 | **[`PopupBlocking`](#popupblocking)** | Configure the default pop-up window policy as well as origins for which pop-up windows are allowed.
99 | **[`Preferences`](#preferences)** | Set and lock preferences.
100 | **[`PrimaryPassword`](#primarypassword)** | Require or prevent using a primary (formerly master) password.
101 | **[`PrintingEnabled`](#printingenabled)** | Enable or disable printing.
102 | **[`PromptForDownloadLocation`](#promptfordownloadlocation)** | Ask where to save each file before downloading.
103 | **[`Proxy`](#proxy)** | Configure proxy settings.
104 | **[`RequestedLocales`](#requestedlocales)** | Set the the list of requested locales for the application in order of preference.
105 | **[`SanitizeOnShutdown` (All)](#sanitizeonshutdown-all)** | Clear all data on shutdown.
106 | **[`SanitizeOnShutdown` (Selective)](#sanitizeonshutdown-selective)** | Clear data on shutdown.
107 | **[`SearchBar`](#searchbar)** | Set whether or not search bar is displayed.
108 | **[`SearchEngines`](#searchengines-this-policy-is-only-available-on-the-esr)** |
109 | **[`SearchEngines -> Add`](#searchengines--add)** | Add new search engines.
110 | **[`SearchEngines -> Default`](#searchengines--default)** | Set the default search engine.
111 | **[`SearchEngines -> PreventInstalls`](#searchengines--preventinstalls)** | Prevent installing search engines from webpages.
112 | **[`SearchEngines -> Remove`](#searchengines--remove)** | Hide built-in search engines.
113 | **[`SearchSuggestEnabled`](#searchsuggestenabled)** | Enable search suggestions.
114 | **[`SecurityDevices`](#securitydevices)** | Install PKCS #11 modules.
115 | **[`ShowHomeButton`](#showhomebutton)** | Show the home button on the toolbar.
116 | **[`SSLVersionMax`](#sslversionmax)** | Set and lock the maximum version of TLS.
117 | **[`SSLVersionMin`](#sslversionmin)** | Set and lock the minimum version of TLS.
118 | **[`StartDownloadsInTempDirectory`](#startdownloadsintempdirectory)** | Force downloads to start off in a local, temporary location rather than the default download directory.
119 | **[`SupportMenu`](#supportmenu)** | Add a menuitem to the help menu for specifying support information.
120 | **[`UserMessaging`](#usermessaging)** | Don't show certain messages to the user.
121 | **[`UseSystemPrintDialog`](#usesystemprintdialog)** | Print using the system print dialog instead of print preview.
122 | **[`WebsiteFilter`](#websitefilter)** | Block websites from being visited.
123 | **[`WindowsSSO`](#windowssso)** | Allow Windows single sign-on for Microsoft, work, and school accounts.
124
125 ### 3rdparty
126
127 Allow WebExtensions to configure policy. For more information, see [Adding policy support to your extension](https://extensionworkshop.com/documentation/enterprise/adding-policy-support-to-your-extension/).
128
129 For GPO and Intune, the extension developer should provide an ADMX file.
130
131 **Compatibility:** Firefox 68\
132 **CCK2 Equivalent:** N/A\
133 **Preferences Affected:** N/A
134
135 #### macOS
136 ```
137 <dict>
138 <key>3rdparty</key>
139 <dict>
140 <key>Extensions</key>
141 <dict>
142 <key>uBlock0@raymondhill.net</key>
143 <dict>
144 <key>adminSettings</key>
145 <dict>
146 <key>selectedFilterLists</key>
147 <array>
148 <string>ublock-privacy</string>
149 <string>ublock-badware</string>
150 <string>ublock-filters</string>
151 <string>user-filters</string>
152 </array>
153 </dict>
154 </dict>
155 </dict>
156 </dict>
157 </dict>
158 ```
159 #### policies.json
160 ```
161 {
162 "policies": {
163 "3rdparty": {
164 "Extensions": {
165 "uBlock0@raymondhill.net": {
166 "adminSettings": {
167 "selectedFilterLists": [
168 "ublock-privacy",
169 "ublock-badware",
170 "ublock-filters",
171 "user-filters"
172 ]
173 }
174 }
175 }
176 }
177 }
178 }
179 ```
180
181 ### AllowedDomainsForApps
182
183 Define domains allowed to access Google Workspace.
184
185 This policy is based on the [Chrome policy](https://chromeenterprise.google/policies/#AllowedDomainsForApps) of the same name.
186
187 If this policy is enabled, users can only access Google Workspace using accounts from the specified domains. If you want to allow Gmail, you can add ```consumer_accounts``` to the list.
188
189 **Compatibility:** Firefox 89, Firefox ESR 78.11\
190 **CCK2 Equivalent:** N/A\
191 **Preferences Affected:** N/A
192
193 #### Windows (GPO)
194 ```
195 Software\Policies\Mozilla\Firefox\AllowedDomainsForApps = "managedfirefox.com,example.com"
196 ```
197 #### Windows (Intune)
198 OMA-URI:
199 ```
200 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/AllowedDomainsForApps
201 ```
202 Value (string):
203 ```
204 <enabled/>
205 <data id="AllowedDomainsForApps" value="managedfirefox.com,example.com"/>
206 ```
207 #### macOS
208 ```
209 <dict>
210 <key>AllowedDomainsForApps</key>
211 <string>managedfirefox.com,example.com</string>
212 </dict>
213 ```
214 #### policies.json
215 ```
216 {
217 "policies": {
218 "AllowedDomainsForApps": "managedfirefox.com,example.com"
219 }
220 }
221 ```
222 ### AppAutoUpdate
223
224 Enable or disable **automatic** application update.
225
226 If set to true, application updates are installed without user approval within Firefox. The operating system might still require approval.
227
228 If set to false, application updates are downloaded but the user can choose when to install the update.
229
230 If you have disabled updates via `DisableAppUpdate`, this policy has no effect.
231
232 **Compatibility:** Firefox 75, Firefox ESR 68.7\
233 **CCK2 Equivalent:** N/A\
234 **Preferences Affected:** `app.update.auto`
235
236 #### Windows (GPO)
237 ```
238 Software\Policies\Mozilla\Firefox\AppAutoUpdate = 0x1 | 0x0
239 ```
240 #### Windows (Intune)
241 OMA-URI:
242 ```
243 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/AppAutoUpdate
244 ```
245 Value (string):
246 ```
247 <enabled/> or <disabled/>
248 ```
249 #### macOS
250 ```
251 <dict>
252 <key>AppAutoUpdate</key>
253 <true/> | <false/>
254 </dict>
255 ```
256 #### policies.json
257 ```
258 {
259 "policies": {
260 "AppAutoUpdate": true | false
261 }
262 }
263 ```
264 ### AppUpdatePin
265
266 Prevent Firefox from being updated beyond the specified version.
267
268 You can specify the any version as ```xx.``` and Firefox will be updated with all minor versions, but will not be updated beyond the major version.
269
270 You can also specify the version as ```xx.xx``` and Firefox will be updated with all patch versions, but will not be updated beyond the minor version.
271
272 You should specify a version that exists or is guaranteed to exist. If you specify a version that doesn't end up existing, Firefox will update beyond that version.
273
274 **Compatibility:** Firefox 102,\
275 **CCK2 Equivalent:** N/A\
276 **Preferences Affected:** N/A
277
278 #### Windows (GPO)
279 ```
280 Software\Policies\Mozilla\Firefox\AppUpdatePin = "106."
281 ```
282 #### Windows (Intune)
283 OMA-URI:
284 ```
285 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/AppUpdatePin
286 ```
287 Value (string):
288 ```
289 <enabled/>
290 <data id="AppUpdatePin" value="106."/>
291 ```
292 #### macOS
293 ```
294 <dict>
295 <key>AppUpdatePin</key>
296 <string>106.</string>
297 </dict>
298 ```
299 #### policies.json
300 ```
301 {
302 "policies": {
303 "AppUpdatePin": "106."
304 }
305 }
306 ```
307 ### AppUpdateURL
308
309 Change the URL for application update if you are providing Firefox updates from a custom update server.
310
311 **Compatibility:** Firefox 62, Firefox ESR 60.2\
312 **CCK2 Equivalent:** N/A\
313 **Preferences Affected:** `app.update.url`
314
315 #### Windows (GPO)
316 ```
317 Software\Policies\Mozilla\Firefox\AppUpdateURL = "https://yoursite.com"
318 ```
319 #### Windows (Intune)
320 OMA-URI:
321 ```
322 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/AppUpdateURL
323 ```
324 Value (string):
325 ```
326 <enabled/>
327 <data id="AppUpdateURL" value="https://yoursite.com"/>
328 ```
329 #### macOS
330 ```
331 <dict>
332 <key>AppUpdateURL</key>
333 <string>https://yoursite.com</string>
334 </dict>
335 ```
336 #### policies.json
337 ```
338 {
339 "policies": {
340 "AppUpdateURL": "https://yoursite.com"
341 }
342 }
343 ```
344 ### Authentication
345
346 Configure sites that support integrated authentication.
347
348 See [Integrated authentication](https://htmlpreview.github.io/?https://github.com/mdn/archived-content/blob/main/files/en-us/mozilla/integrated_authentication/raw.html) for more information.
349
350 `PrivateBrowsing` enables integrated authentication in private browsing.
351
352 **Compatibility:** Firefox 60, Firefox ESR 60 (AllowNonFQDN added in 62/60.2, AllowProxies added in 70/68.2, Locked added in 71/68.3, PrivateBrowsing added in 77/68.9)\
353 **CCK2 Equivalent:** N/A\
354 **Preferences Affected:** `network.negotiate-auth.trusted-uris`,`network.negotiate-auth.delegation-uris`,`network.automatic-ntlm-auth.trusted-uris`,`network.automatic-ntlm-auth.allow-non-fqdn`,`network.negotiate-auth.allow-non-fqdn`,`network.automatic-ntlm-auth.allow-proxies`,`network.negotiate-auth.allow-proxies`,`network.auth.private-browsing-sso`
355
356 #### Windows (GPO)
357 ```
358 Software\Policies\Mozilla\Firefox\Authentication\SPNEGO\1 = "mydomain.com"
359 Software\Policies\Mozilla\Firefox\Authentication\SPNEGO\2 = "https://myotherdomain.com"
360 Software\Policies\Mozilla\Firefox\Authentication\Delegated\1 = "mydomain.com"
361 Software\Policies\Mozilla\Firefox\Authentication\Delegated\2 = "https://myotherdomain.com"
362 Software\Policies\Mozilla\Firefox\Authentication\NTLM\1 = "mydomain.com"
363 Software\Policies\Mozilla\Firefox\Authentication\NTLM\2 = "https://myotherdomain.com"
364 Software\Policies\Mozilla\Firefox\Authentication\AllowNonFQDN\SPNEGO = 0x1 | 0x0
365 Software\Policies\Mozilla\Firefox\Authentication\AllowNonFQDN\NTLM = 0x1 | 0x0
366 Software\Policies\Mozilla\Firefox\Authentication\AllowProxies\SPNEGO = 0x1 | 0x0
367 Software\Policies\Mozilla\Firefox\Authentication\AllowProxies\NTLM = 0x1 | 0x0
368 Software\Policies\Mozilla\Firefox\Authentication\Locked = 0x1 | 0x0
369 Software\Policies\Mozilla\Firefox\Authentication\PrivateBrowsing = 0x1 | 0x0
370 ```
371 #### Windows (Intune)
372 OMA-URI:
373 ```
374 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_SPNEGO
375 ```
376 Value (string):
377 ```
378 <enabled/>
379 <data id="Authentication" value="1&#xF000;mydomain&#xF000;2&#xF000;https://myotherdomain.com"/>
380 ```
381 OMA-URI:
382 ```
383 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_Delegated
384 ```
385 Value (string):
386 ```
387 <enabled/>
388 <data id="Authentication" value="1&#xF000;mydomain&#xF000;2&#xF000;https://myotherdomain.com"/>
389 ```
390 OMA-URI:
391 ```
392 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_NTLM
393 ```
394 Value (string):
395 ```
396 <enabled/>
397 <data id="Authentication" value="1&#xF000;mydomain&#xF000;2&#xF000;https://myotherdomain.com"/>
398 ```
399 OMA-URI:
400 ```
401 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_AllowNonFQDN
402 ```
403 Value (string):
404 ```
405 <enabled/>
406 <data id="Authentication_AllowNonFQDN_NTLM" value="true | false"/>
407 <data id="Authentication_AllowNonFQDN_SPNEGO" value="true | false"/>
408 ```
409 OMA-URI:
410 ```
411 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_Locked
412 ```
413 Value (string):
414 ```
415 <enabled/> or <disabled/>
416 ```
417 OMA-URI:
418 ```
419 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Authentication/Authentication_PrivateBrowsing
420 ```
421 Value (string):
422 ```
423 <enabled/> or <disabled/>
424 ```
425 #### macOS
426 ```
427 <dict>
428 <key>Authentication</key>
429 <dict>
430 <key>SPNEGO</key>
431 <array>
432 <string>mydomain.com</string>
433 <string>https://myotherdomain.com</string>
434 </array>
435 <key>Delegated</key>
436 <array>
437 <string>mydomain.com</string>
438 <string>https://myotherdomain.com</string>
439 </array>
440 <key>NTLM</key>
441 <array>
442 <string>mydomain.com</string>
443 <string>https://myotherdomain.com</string>
444 </array>
445 <key>AllowNonFQDN</key>
446 <dict>
447 <key>SPNEGO</key>
448 <true/> | <false/>
449 <key>NTLM</key>
450 <true/> | <false/>
451 </dict>
452 <key>AllowProxies</key>
453 <dict>
454 <key>SPNEGO</key>
455 <true/> | <false/>
456 <key>NTLM</key>
457 <true/> | <false/>
458 </dict>
459 <key>Locked</key>
460 <true/> | <false/>
461 <key>PrivateBrowsing</key>
462 <true/> | <false/>
463 </dict>
464 </dict>
465 ```
466 #### policies.json
467 ```
468 {
469 "policies": {
470 "Authentication": {
471 "SPNEGO": ["mydomain.com", "https://myotherdomain.com"],
472 "Delegated": ["mydomain.com", "https://myotherdomain.com"],
473 "NTLM": ["mydomain.com", "https://myotherdomain.com"],
474 "AllowNonFQDN": {
475 "SPNEGO": true | false,
476 "NTLM": true | false
477 },
478 "AllowProxies": {
479 "SPNEGO": true | false,
480 "NTLM": true | false
481 },
482 "Locked": true | false,
483 "PrivateBrowsing": true | false
484 }
485 }
486 }
487 ```
488 ### AutoLaunchProtocolsFromOrigins
489 Define a list of external protocols that can be used from listed origins without prompting the user. The origin is the scheme plus the hostname.
490
491 The syntax of this policy is exactly the same as the [Chrome AutoLaunchProtocolsFromOrigins policy](https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoLaunchProtocolsFromOrigins) except that you can only use valid origins (not just hostnames). This also means that you cannot specify an asterisk for all origins.
492
493 The schema is:
494 ```
495 {
496 "items": {
497 "properties": {
498 "allowed_origins": {
499 "items": {
500 "type": "string"
501 },
502 "type": "array"
503 },
504 "protocol": {
505 "type": "string"
506 }
507 },
508 "required": [
509 "protocol",
510 "allowed_origins"
511 ],
512 "type": "object"
513 },
514 "type": "array"
515 }
516 ```
517 **Compatibility:** Firefox 90, Firefox ESR 78.12\
518 **CCK2 Equivalent:** N/A\
519 **Preferences Affected:** N/A
520
521 #### Windows (GPO)
522 Software\Policies\Mozilla\Firefox\AutoLaunchProtocolsFromOrigins (REG_MULTI_SZ) =
523 ```
524 [
525 {
526 "protocol": "zoommtg",
527 "allowed_origins": [
528 "https://somesite.zoom.us"
529 ]
530 }
531 ]
532 ```
533 #### Windows (Intune)
534 OMA-URI:
535 ```
536 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/AutoLaunchProtocolsFromOrigins
537 ```
538 Value (string):
539 ```
540 <enabled/>
541 <data id="JSON" value='
542 [
543 {
544 "protocol": "zoommtg",
545 "allowed_origins": [
546 "https://somesite.zoom.us"
547 ]
548 }
549 ]'/>
550 ```
551 #### macOS
552 ```
553 <dict>
554 <key>AutoLaunchProtocolsFromOrigins</key>
555 <array>
556 <dict>
557 <key>protocol</key>
558 <string>zoommtg</string>
559 <key>allowed_origins</key>
560 <array>
561 <string>https://somesite.zoom.us</string>
562 </array>
563 </dict>
564 </array>
565 </dict>
566 ```
567 #### policies.json
568 ```
569 {
570 "policies": {
571 "AutoLaunchProtocolsFromOrigins": [{
572 "protocol": "zoommtg",
573 "allowed_origins": [
574 "https://somesite.zoom.us"
575 ]
576 }]
577 }
578 }
579 ```
580 ### BackgroundAppUpdate
581
582 Enable or disable **automatic** application update **in the background**, when the application is not running.
583
584 If set to true, application updates may be installed (without user approval) in the background, even when the application is not running. The operating system might still require approval.
585
586 If set to false, the application will not try to install updates when the application is not running.
587
588 If you have disabled updates via `DisableAppUpdate` or disabled automatic updates via `AppAutoUpdate`, this policy has no effect.
589
590 **Compatibility:** Firefox 90 (Windows only)\
591 **CCK2 Equivalent:** N/A\
592 **Preferences Affected:** `app.update.background.enabled`
593
594 #### Windows (GPO)
595 ```
596 Software\Policies\Mozilla\Firefox\BackgroundAppUpdate = 0x1 | 0x0
597 ```
598 #### Windows (Intune)
599 OMA-URI:
600 ```
601 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BackgroundAppUpdate
602 ```
603 Value (string):
604 ```
605 <enabled/> or <disabled/>
606 ```
607 #### macOS
608 ```
609 <dict>
610 <key>BackgroundAppUpdate</key>
611 <true/> | <false/>
612 </dict>
613 ```
614 #### policies.json
615 ```
616 {
617 "policies": {
618 "BackgroundAppUpdate": true | false
619 }
620 }
621 ```
622 ### BlockAboutAddons
623
624 Block access to the Add-ons Manager (about:addons).
625
626 **Compatibility:** Firefox 60, Firefox ESR 60\
627 **CCK2 Equivalent:** `disableAddonsManager`\
628 **Preferences Affected:** N/A
629
630 #### Windows (GPO)
631 ```
632 Software\Policies\Mozilla\Firefox\BlockAboutAddons = 0x1 | 0x0
633 ```
634 #### Windows (Intune)
635 OMA-URI:
636 ```
637 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BlockAboutAddons
638 ```
639 Value (string):
640 ```
641 <enabled/> or <disabled/>
642 ```
643 #### macOS
644 ```
645 <dict>
646 <key>BlockAboutAddons</key>
647 <true/> | <false/>
648 </dict>
649 ```
650 #### policies.json
651 ```
652 {
653 "policies": {
654 "BlockAboutAddons": true | false
655 }
656 }
657 ```
658 ### BlockAboutConfig
659
660 Block access to about:config.
661
662 **Compatibility:** Firefox 60, Firefox ESR 60\
663 **CCK2 Equivalent:** `disableAboutConfig`\
664 **Preferences Affected:** N/A
665
666 #### Windows (GPO)
667 ```
668 Software\Policies\Mozilla\Firefox\BlockAboutConfig = 0x1 | 0x0
669 ```
670 #### Windows (Intune)
671 OMA-URI:
672 ```
673 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BlockAboutConfig
674 ```
675 Value (string):
676 ```
677 <enabled/> or <disabled/>
678 ```
679 #### macOS
680 ```
681 <dict>
682 <key>BlockAboutConfig</key>
683 <true/> | <false/>
684 </dict>
685 ```
686 #### policies.json
687 ```
688 {
689 "policies": {
690 "BlockAboutConfig": true | false
691 }
692 }
693 ```
694 ### BlockAboutProfiles
695
696 Block access to About Profiles (about:profiles).
697
698 **Compatibility:** Firefox 60, Firefox ESR 60\
699 **CCK2 Equivalent:** `disableAboutProfiles`\
700 **Preferences Affected:** N/A
701
702 #### Windows (GPO)
703 ```
704 Software\Policies\Mozilla\Firefox\BlockAboutProfiles = 0x1 | 0x0
705 ```
706 #### Windows (Intune)
707 OMA-URI:
708 ```
709 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BlockAboutProfiles
710 ```
711 Value (string):
712 ```
713 <enabled/> or <disabled/>
714 ```
715 #### macOS
716 ```
717 <dict>
718 <key>BlockAboutProfiles</key>
719 <true/> | <false/>
720 </dict>
721 ```
722 #### policies.json
723 ```
724 {
725 "policies": {
726 "BlockAboutProfiles": true | false
727 }
728 }
729 ```
730 ### BlockAboutSupport
731
732 Block access to Troubleshooting Information (about:support).
733
734 **Compatibility:** Firefox 60, Firefox ESR 60\
735 **CCK2 Equivalent:** `disableAboutSupport`\
736 **Preferences Affected:** N/A
737
738 #### Windows (GPO)
739 ```
740 Software\Policies\Mozilla\Firefox\BlockAboutSupport = 0x1 | 0x0
741 ```
742 #### Windows (Intune)
743 OMA-URI:
744 ```
745 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BlockAboutSupport
746 ```
747 Value (string):
748 ```
749 <enabled/> or <disabled/>
750 ```
751 #### macOS
752 ```
753 <dict>
754 <key>BlockAboutSupport</key>
755 <true/> | <false/>
756 </dict>
757 ```
758 #### policies.json
759 ```
760 {
761 "policies": {
762 "BlockAboutSupport": true | false
763 }
764 }
765 ```
766 ### Bookmarks
767
768 Note: [`ManagedBookmarks`](#managedbookmarks) is the new recommended way to add bookmarks. This policy will continue to be supported.
769
770 Add bookmarks in either the bookmarks toolbar or menu. Only `Title` and `URL` are required. If `Placement` is not specified, the bookmark will be placed on the toolbar. If `Folder` is specified, it is automatically created and bookmarks with the same folder name are grouped together.
771
772 If you want to clear all bookmarks set with this policy, you can set the value to an empty array (```[]```). This can be on Windows via the new Bookmarks (JSON) policy available with GPO and Intune.
773
774 **Compatibility:** Firefox 60, Firefox ESR 60\
775 **CCK2 Equivalent:** `bookmarks.toolbar`,`bookmarks.menu`\
776 **Preferences Affected:** N/A
777
778 #### Windows (GPO)
779 ```
780 Software\Policies\Mozilla\Firefox\Bookmarks\1\Title = "Example"
781 Software\Policies\Mozilla\Firefox\Bookmarks\1\URL = "https://example.com"
782 Software\Policies\Mozilla\Firefox\Bookmarks\1\Favicon = "https://example.com/favicon.ico"
783 Software\Policies\Mozilla\Firefox\Bookmarks\1\Placement = "toolbar" | "menu"
784 Software\Policies\Mozilla\Firefox\Bookmarks\1\Folder = "FolderName"
785
786 Software\Policies\Mozilla\Firefox\Bookmarks (REG_MULTI_SZ) =
787 ```
788 []
789 ```
790
791 ```
792 #### Windows (Intune)
793 OMA-URI:
794 ```
795 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Bookmarks/Bookmark01
796 ```
797 Value (string):
798 ```
799 <enabled/>
800 <data id="BookmarkTitle" value="Example"/>
801 <data id="BookmarkURL" value="https://example.com"/>
802 <data id="BookmarkFavicon" value="https://example.com/favicon.ico"/>
803 <data id="BookmarkPlacement" value="toolbar | menu"/>
804 <data id="BookmarkFolder" value="FolderName"/>
805 ```
806 OMA-URI:
807 ```
808 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/Bookmarks
809 ```
810 Value (string):
811 ```
812 <enabled/>
813 <data id="JSON" value='[]'/>
814 ```
815 #### macOS
816 ```
817 <dict>
818 <key>Bookmarks</key>
819 <array>
820 <dict>
821 <key>Title</key>
822 <string>Example</string>
823 <key>URL</key>
824 <string>https://example.com</string>
825 <key>Favicon</key>
826 <string>https://example.com/favicon.ico</string>
827 <key>Placement</key>
828 <string>toolbar | menu</string>
829 <key>Folder</key>
830 <string>FolderName</string>
831 </dict>
832 </array>
833 </dict>
834 ```
835 #### policies.json
836 ```
837 {
838 "policies": {
839 "Bookmarks": [
840 {
841 "Title": "Example",
842 "URL": "https://example.com",
843 "Favicon": "https://example.com/favicon.ico",
844 "Placement": "toolbar" | "menu",
845 "Folder": "FolderName"
846 }
847 ]
848 }
849 }
850 ```
851 ### CaptivePortal
852 Enable or disable the detection of captive portals.
853
854 **Compatibility:** Firefox 67, Firefox ESR 60.7\
855 **CCK2 Equivalent:** N/A\
856 **Preferences Affected:** `network.captive-portal-service.enabled`
857
858 #### Windows (GPO)
859 ```
860 Software\Policies\Mozilla\Firefox\CaptivePortal = 0x1 | 0x0
861 ```
862 #### Windows (Intune)
863 OMA-URI:
864 ```
865 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/CaptivePortal
866 ```
867 Value (string):
868 ```
869 <enabled/> or <disabled/>
870 ```
871 #### macOS
872 ```
873 <dict>
874 <key>CaptivePortal</key>
875 <true/> | <false/>
876 </dict>
877 ```
878 #### policies.json
879 ```
880 {
881 "policies": {
882 "CaptivePortal": true | false
883 }
884 }
885 ```
886 ### Certificates
887
888 ### Certificates | ImportEnterpriseRoots
889
890 Trust certificates that have been added to the operating system certificate store by a user or administrator.
891
892 Note: This policy only works on Windows and macOS. For Linux discussion, see [bug 1600509](https://bugzilla.mozilla.org/show_bug.cgi?id=1600509).
893
894 See https://support.mozilla.org/kb/setting-certificate-authorities-firefox for more detail.
895
896 **Compatibility:** Firefox 60, Firefox ESR 60 (macOS support in Firefox 63, Firefox ESR 68)\
897 **CCK2 Equivalent:** N/A\
898 **Preferences Affected:** `security.enterprise_roots.enabled`
899
900 #### Windows (GPO)
901 ```
902 Software\Policies\Mozilla\Firefox\Certificates\ImportEnterpriseRoots = 0x1 | 0x0
903 ```
904 #### Windows (Intune)
905 OMA-URI:
906 ```
907 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Certificates/Certificates_ImportEnterpriseRoots
908 ```
909 Value (string):
910 ```
911 <enabled/> or <disabled/>
912 ```
913 #### macOS
914 ```
915 <dict>
916 <key>Certificates</key>
917 <dict>
918 <key>ImportEnterpriseRoots</key>
919 <true/> | <false/>
920 </dict>
921 </dict>
922 ```
923 #### policies.json
924 ```
925 {
926 "policies": {
927 "Certificates": {
928 "ImportEnterpriseRoots": true | false
929 }
930 }
931 }
932 ```
933 ### Certificates | Install
934
935 Install certificates into the Firefox certificate store. If only a filename is specified, Firefox searches for the file in the following locations:
936
937 - Windows
938 - %USERPROFILE%\AppData\Local\Mozilla\Certificates
939 - %USERPROFILE%\AppData\Roaming\Mozilla\Certificates
940 - macOS
941 - /Library/Application Support/Mozilla/Certificates
942 - ~/Library/Application Support/Mozilla/Certificates
943 - Linux
944 - /usr/lib/mozilla/certificates
945 - /usr/lib64/mozilla/certificates
946 - ~/.mozilla/certificates
947
948 Starting with Firefox 65, Firefox 60.5 ESR, a fully qualified path can be used, including UNC paths. You should use the native path style for your operating system. We do not support using %USERPROFILE% or other environment variables on Windows.
949
950 If you are specifying the path in the policies.json file on Windows, you need to escape your backslashes (`\\`) which means that for UNC paths, you need to escape both (`\\\\`). If you use group policy, you only need one backslash.
951
952 Certificates are installed using the trust string `CT,CT,`.
953
954 Binary (DER) and ASCII (PEM) certificates are both supported.
955
956 **Compatibility:** Firefox 64, Firefox ESR 64\
957 **CCK2 Equivalent:** `certs.ca`\
958 **Preferences Affected:** N/A
959
960 #### Windows (GPO)
961 ```
962 Software\Policies\Mozilla\Firefox\Certificates\Install\1 = "cert1.der"
963 Software\Policies\Mozilla\Firefox\Certificates\Install\2 = "C:\Users\username\cert2.pem"
964 ```
965 #### Windows (Intune)
966 OMA-URI:
967 ```
968 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Certificates/Certificates_Install
969 ```
970 Value (string):
971 ```
972 <enabled/>
973 <data id="Certificates_Install" value="1&#xF000;cert1.der&#xF000;2&#xF000;C:\Users\username\cert2.pem"/>
974 ```
975 #### macOS
976 ```
977 <dict>
978 <key>Certificates</key>
979 <dict>
980 <key>Install</key>
981 <array>
982 <string>cert1.der</string>
983 <string>/Users/username/cert2.pem</string>
984 </array>
985 </dict>
986 </dict>
987 ```
988 #### policies.json
989 ```
990 {
991 "policies": {
992 "Certificates": {
993 "Install": ["cert1.der", "/home/username/cert2.pem"]
994 }
995 }
996 }
997 ```
998 ### Containers
999 Set policies related to [containers](https://addons.mozilla.org/firefox/addon/multi-account-containers/).
1000
1001 Currently you can set the initial set of containers.
1002
1003 For each container, you can specify the name, icon, and color.
1004
1005 | Name | Description |
1006 | --- | --- |
1007 | `name`| Name of container
1008 | `icon` | Can be `fingerprint`, `briefcase`, `dollar`, `cart`, `vacation`, `gift`, `food`, `fruit`, `pet`, `tree`, `chill`, `circle`, `fence`
1009 | `color` | Can be `blue`, `turquoise`, `green`, `yellow`, `orange`, `red`, `pink`, `purple`, `toolbar`
1010
1011 **Compatibility:** Firefox 113\
1012 **CCK2 Equivalent:** N/A\
1013 **Preferences Affected:** N/A
1014
1015 #### Windows (GPO)
1016 Software\Policies\Mozilla\Firefox\Containers (REG_MULTI_SZ) =
1017 ```
1018 {
1019 "Default": [
1020 {
1021 "name": "My container",
1022 "icon": "pet",
1023 "color": "turquoise"
1024 }
1025 ]
1026 }
1027 ```
1028 #### Windows (Intune)
1029 OMA-URI:
1030 ```
1031 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/Containers
1032 ```
1033 Value (string):
1034 ```
1035 <enabled/>
1036 <data id="JSON" value='
1037 {
1038 "Default": [
1039 {
1040 "name": "My container",
1041 "icon": "pet",
1042 "color": "turquoise"
1043 }
1044 ]
1045 }
1046 '/>
1047 ```
1048 #### macOS
1049 ```
1050 <dict>
1051 <key>Default</key>
1052 <dict>
1053 <key>Containers</key>
1054 <array>
1055 <dict>
1056 <key>name</key>
1057 <string>My container</string>
1058 <key>icon</key>
1059 <string>pet</string>
1060 <key>color</key>
1061 <string>turquoise</string>
1062 </dict>
1063 </array>
1064 </dict>
1065 </dict>
1066 ```
1067 #### policies.json
1068 ```
1069 {
1070 "policies": {
1071 "Containers": {
1072 "Default": [
1073 {
1074 "name": "My container",
1075 "icon": "pet",
1076 "color": "turquoise"
1077 }
1078 ]
1079 }
1080 }
1081 }
1082 ```
1083 ### Cookies
1084 Configure cookie preferences.
1085
1086 `Allow` is a list of origins (not domains) where cookies are always allowed. You must include http or https.
1087
1088 `AllowSession` is a list of origins (not domains) where cookies are only allowed for the current session. You must include http or https.
1089
1090 `Block` is a list of origins (not domains) where cookies are always blocked. You must include http or https.
1091
1092 `Behavior` sets the default behavior for cookies based on the values below.
1093
1094 `BehaviorPrivateBrowsing` sets the default behavior for cookies in private browsing based on the values below.
1095
1096 | Value | Description
1097 | --- | --- |
1098 | accept | Accept all cookies
1099 | reject-foreign | Reject third party cookies
1100 | reject | Reject all cookies
1101 | limit-foreign | Reject third party cookies for sites you haven't visited
1102 | reject-tracker | Reject cookies for known trackers (default)
1103 | reject-tracker-and-partition-foreign | Reject cookies for known trackers and partition third-party cookies (Total Cookie Protection) (default for private browsing)
1104
1105 `Locked` prevents the user from changing cookie preferences.
1106
1107 **Compatibility:** Firefox 60, Firefox ESR 60 (RejectTracker added in Firefox 63, AllowSession added in Firefox 79/78.1, Behavior added in Firefox 95/91.4)\
1108 **CCK2 Equivalent:** N/A\
1109 **Preferences Affected:** `network.cookie.cookieBehavior`, `network.cookie.cookieBehavior.pbmode`, `network.cookie.lifetimePolicy`
1110
1111 #### Windows (GPO)
1112 ```
1113 Software\Policies\Mozilla\Firefox\Cookies\Allow\1 = "https://example.com"
1114 Software\Policies\Mozilla\Firefox\Cookies\AllowSession\1 = "https://example.edu"
1115 Software\Policies\Mozilla\Firefox\Cookies\Block\1 = "https://example.org"
1116 Software\Policies\Mozilla\Firefox\Cookies\Default = 0x1 | 0x0
1117 Software\Policies\Mozilla\Firefox\Cookies\AcceptThirdParty = "always" | "never" | "from-visited"
1118 Software\Policies\Mozilla\Firefox\Cookies\ExpireAtSessionEnd = 0x1 | 0x0
1119 Software\Policies\Mozilla\Firefox\Cookies\RejectTracker = 0x1 | 0x0
1120 Software\Policies\Mozilla\Firefox\Cookies\Behavior = "accept" | "reject-foreign" | "reject" | "limit-foreign" | "reject-tracker" | "reject-tracker-and-partition-foreign"
1121 Software\Policies\Mozilla\Firefox\Cookies\BehaviorPrivateBrowsing = "accept" | "reject-foreign" | "reject" | "limit-foreign" | "reject-tracker" | "reject-tracker-and-partition-foreign"
1122 Software\Policies\Mozilla\Firefox\Cookies\Locked = 0x1 | 0x0
1123 ```
1124 #### Windows (Intune)
1125 OMA-URI:
1126 ```
1127 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_Allow
1128 ```
1129 Value (string):
1130 ```
1131 <enabled/>
1132 <data id="Permissions" value="1&#xF000;https://example.com"/>
1133 ```
1134 OMA-URI:
1135 ```
1136 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_AllowSession
1137 ```
1138 Value (string):
1139 ```
1140 <enabled/>
1141 <data id="Permissions" value="1&#xF000;https://example.edu"/>
1142 ```
1143 OMA-URI:
1144 ```
1145 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_Block
1146 ```
1147 Value (string):
1148 ```
1149 <enabled/>
1150 <data id="Permissions" value="1&#xF000;https://example.org"/>
1151 ```
1152 OMA-URI:
1153 ```
1154 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_Default
1155 ```
1156 Value (string):
1157 ```
1158 <enabled/> or <disabled/>
1159 ```
1160 OMA-URI:
1161 ```
1162 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_AcceptThirdParty
1163 ```
1164 Value (string):
1165 ```
1166 <enabled/>
1167 <data id="Cookies_AcceptThirdParty" value="always | never | from-visited"/>
1168 ```
1169 OMA-URI:
1170 ```
1171 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_ExpireAtSessionEnd
1172 ```
1173 Value (string):
1174 ```
1175 <enabled/> or <disabled/>
1176 ```
1177 OMA-URI:
1178 ```
1179 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_RejectTracker
1180 ```
1181 Value (string):
1182 ```
1183 <enabled/> or <disabled/>
1184 ```
1185 OMA-URI:
1186 ```
1187 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_Locked
1188 ```
1189 Value (string):
1190 ```
1191 <enabled/> or <disabled/>
1192 ```
1193 OMA-URI:
1194 ```
1195 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_Behavior
1196 ```
1197 Value (string):
1198 ```
1199 <enabled/>
1200 <data id="Cookies_Behavior" value="accept | reject-foreign | reject | limit-foreign | reject-tracker | reject-tracker-and-partition-foreign"/>
1201 ```
1202 OMA-URI:
1203 ```
1204 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Cookies/Cookies_BehaviorPrivateBrowsing
1205 ```
1206 Value (string):
1207 ```
1208 <enabled/>
1209 <data id="Cookies_BehaviorPrivateBrowsing" value="accept | reject-foreign | reject | limit-foreign | reject-tracker | reject-tracker-and-partition-foreign"/>
1210 ```
1211 #### macOS
1212 ```
1213 <dict>
1214 <key>Cookies</key>
1215 <dict>
1216 <key>Allow</key>
1217 <array>
1218 <string>http://example.com</string>
1219 </array>
1220 <key>AllowSession</key>
1221 <array>
1222 <string>http://example.edu</string>
1223 </array>
1224 <key>Block</key>
1225 <array>
1226 <string>http://example.org</string>
1227 </array>
1228 <key>Default</key>
1229 <true/> | <false/>
1230 <key>AcceptThirdParty</key>
1231 <string>always | never | from-visited</string>
1232 <key>ExpireAtSessionEnd</key>
1233 <true/> | <false/>
1234 <key>RejectTracker</key>
1235 <true/> | <false/>
1236 <key>Locked</key>
1237 <true/> | <false/>
1238 <key>Behavior</key>
1239 <string>accept | reject-foreign | reject | limit-foreign | reject-tracker | reject-tracker-and-partition-foreign</string>
1240 <key>BehaviorPrivateBrowsing</key>
1241 <string>accept | reject-foreign | reject | limit-foreign | reject-tracker | reject-tracker-and-partition-foreign</string>
1242 </dict>
1243 </dict>
1244 ```
1245 #### policies.json
1246 ```
1247 {
1248 "policies": {
1249 "Cookies": {
1250 "Allow": ["http://example.org/"],
1251 "AllowSession": ["http://example.edu/"],
1252 "Block": ["http://example.edu/"],
1253 "Default": true | false,
1254 "AcceptThirdParty": "always" | "never" | "from-visited",
1255 "ExpireAtSessionEnd": true | false,
1256 "RejectTracker": true | false,
1257 "Locked": true | false,
1258 "Behavior": "accept" | "reject-foreign" | "reject" | "limit-foreign" | "reject-tracker" | "reject-tracker-and-partition-foreign",
1259 "BehaviorPrivateBrowsing": "accept" | "reject-foreign" | "reject" | "limit-foreign" | "reject-tracker" | "reject-tracker-and-partition-foreign",
1260 }
1261 }
1262 }
1263 ```
1264 ### DefaultDownloadDirectory
1265 Set the default download directory.
1266
1267 You can use ${home} for the native home directory.
1268
1269 **Compatibility:** Firefox 68, Firefox ESR 68\
1270 **CCK2 Equivalent:** N/A\
1271 **Preferences Affected:** `browser.download.dir`, `browser.download.folderList`
1272
1273 #### Windows (GPO)
1274 ```
1275 Software\Policies\Mozilla\Firefox\DefaultDownloadDirectory = "${home}\Downloads"
1276 ```
1277 #### Windows (Intune)
1278 OMA-URI:
1279 ```
1280 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DefaultDownloadDirectory
1281 ```
1282 Value (string):
1283 ```
1284 <enabled/>
1285 <data id="Preferences_String" value="${home}\Downloads"/>
1286 ```
1287 #### macOS
1288 ```
1289 <dict>
1290 <key>DefaultDownloadDirectory</key>
1291 <string>${home}/Downloads</string>
1292 </dict>
1293 ```
1294 #### policies.json (macOS and Linux)
1295 ```
1296 {
1297 "policies": {
1298 "DefaultDownloadDirectory": "${home}/Downloads"
1299 }
1300 }
1301 ```
1302 #### policies.json (Windows)
1303 ```
1304 {
1305 "policies": {
1306 "DefaultDownloadDirectory": "${home}\\Downloads"
1307 }
1308 }
1309 ```
1310 ### DisableAppUpdate
1311 Turn off application updates within Firefox.
1312
1313 **Compatibility:** Firefox 60, Firefox ESR 60\
1314 **CCK2 Equivalent:** `disableFirefoxUpdates`\
1315 **Preferences Affected:** N/A
1316
1317 #### Windows (GPO)
1318 ```
1319 Software\Policies\Mozilla\Firefox\DisableAppUpdate = 0x1 | 0x0
1320 ```
1321 #### Windows (Intune)
1322 OMA-URI:
1323 ```
1324 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableAppUpdate
1325 ```
1326 Value (string):
1327 ```
1328 <enabled/> or <disabled/>
1329 ```
1330 #### macOS
1331 ```
1332 <dict>
1333 <key>DisableAppUpdate</key>
1334 <true/> | <false/>
1335 </dict>
1336 ```
1337 #### policies.json
1338 ```
1339 {
1340 "policies": {
1341 "DisableAppUpdate": true | false
1342 }
1343 }
1344 ```
1345 ### DisableBuiltinPDFViewer
1346 Disable the built in PDF viewer. PDF files are downloaded and sent externally.
1347
1348 **Compatibility:** Firefox 60, Firefox ESR 60\
1349 **CCK2 Equivalent:** `disablePDFjs`\
1350 **Preferences Affected:** `pdfjs.disabled`
1351
1352 #### Windows (GPO)
1353 ```
1354 Software\Policies\Mozilla\Firefox\DisableBuiltinPDFViewer = 0x1 | 0x0
1355 ```
1356 #### Windows (Intune)
1357 OMA-URI:
1358 ```
1359 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableBuiltinPDFViewer
1360 ```
1361 Value (string):
1362 ```
1363 <enabled/> or <disabled/>
1364 ```
1365 #### macOS
1366 ```
1367 <dict>
1368 <key>DisableBuiltinPDFViewer</key>
1369 <true/> | <false/>
1370 </dict>
1371 ```
1372 #### policies.json
1373 ```
1374 {
1375 "policies": {
1376 "DisableBuiltinPDFViewer": true | false
1377 }
1378 }
1379 ```
1380 ### DisabledCiphers
1381 Disable specific cryptographic ciphers, listed below.
1382
1383 ```
1384 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
1385 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
1386 TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
1387 TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
1388 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
1389 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
1390 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
1391 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
1392 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
1393 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
1394 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
1395 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
1396 TLS_RSA_WITH_AES_128_GCM_SHA256
1397 TLS_RSA_WITH_AES_256_GCM_SHA384
1398 TLS_RSA_WITH_AES_128_CBC_SHA
1399 TLS_RSA_WITH_AES_256_CBC_SHA
1400 TLS_RSA_WITH_3DES_EDE_CBC_SHA
1401 ```
1402
1403 **Preferences Affected:** `security.ssl3.ecdhe_rsa_aes_128_gcm_sha256`, `security.ssl3.ecdhe_ecdsa_aes_128_gcm_sha256`, `security.ssl3.ecdhe_ecdsa_chacha20_poly1305_sha256`, `security.ssl3.ecdhe_rsa_chacha20_poly1305_sha256`, `security.ssl3.ecdhe_ecdsa_aes_256_gcm_sha384`, `security.ssl3.ecdhe_rsa_aes_256_gcm_sha384`, `security.ssl3.ecdhe_rsa_aes_128_sha`, `security.ssl3.ecdhe_ecdsa_aes_128_sha`, `security.ssl3.ecdhe_rsa_aes_256_sha`, `security.ssl3.ecdhe_ecdsa_aes_256_sha`, `security.ssl3.dhe_rsa_aes_128_sha`, `security.ssl3.dhe_rsa_aes_256_sha`, `security.ssl3.rsa_aes_128_gcm_sha256`, `security.ssl3.rsa_aes_256_gcm_sha384`, `security.ssl3.rsa_aes_128_sha`, `security.ssl3.rsa_aes_256_sha`, `security.ssl3.deprecated.rsa_des_ede3_sha`
1404
1405 ---
1406 **Note:**
1407
1408 This policy was updated in Firefox 78 to allow enabling ciphers as well. Setting the value to true disables the cipher, setting the value to false enables the cipher. Previously setting the value to true or false disabled the cipher.
1409
1410 ---
1411 **Compatibility:** Firefox 76, Firefox ESR 68.8 (TLS_RSA_WITH_AES_128_GCM_SHA256 and TLS_RSA_WITH_AES_256_GCM_SHA384 were added in Firefox 78, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA38, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, and TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 were added in Firefox 97 and Firefox 91.6)\
1412 **CCK2 Equivalent:** N/A\
1413 **Preferences Affected:** N/A
1414
1415 #### Windows (GPO)
1416 ```
1417 Software\Policies\Mozilla\Firefox\DisabledCiphers\CIPHER_NAME = 0x1 | 0x0
1418 ```
1419 #### Windows (Intune)
1420 OMA-URI:
1421 ```
1422 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~DisabledCiphers/DisabledCiphers_CIPHER_NAME
1423
1424 ```
1425 Value (string):
1426 ```
1427 <enabled/> or <disabled/>
1428 ```
1429 #### macOS
1430 ```
1431 <dict>
1432 <key>DisabledCiphers</key>
1433 <dict>
1434 <key>CIPHER_NAME</key>
1435 <true/> | <false/>
1436 </dict>
1437 </dict>
1438 ```
1439 #### policies.json
1440 ```
1441 {
1442 "policies": {
1443 "DisabledCiphers": {
1444 "CIPHER_NAME": true | false,
1445 }
1446 }
1447 }
1448 ```
1449 ### DisableDefaultBrowserAgent
1450 Prevent the default browser agent from taking any actions. Only applicable to Windows; other platforms don’t have the agent.
1451
1452 The browser agent is a Windows-only scheduled task which runs in the background to collect and submit data about the browser that the user has set as their OS default. More information is available [here](https://firefox-source-docs.mozilla.org/toolkit/mozapps/defaultagent/default-browser-agent/index.html).
1453
1454 **Compatibility:** Firefox 75, Firefox ESR 68.7 (Windows only)\
1455 **CCK2 Equivalent:** N/A\
1456 **Preferences Affected:** N/A
1457
1458 #### Windows (GPO)
1459 ```
1460 Software\Policies\Mozilla\Firefox\DisableDefaultBrowserAgent = 0x1 | 0x0
1461 ```
1462 #### Windows (Intune)
1463 OMA-URI:
1464 ```
1465 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableDefaultBrowserAgent
1466 ```
1467 Value (string):
1468 ```
1469 <enabled/> or <disabled/>
1470 ```
1471 #### policies.json
1472 ```
1473 {
1474 "policies": {
1475 "DisableDefaultBrowserAgent": true | false
1476 }
1477 }
1478 ```
1479 ### DisableDeveloperTools
1480 Remove access to all developer tools.
1481
1482 **Compatibility:** Firefox 60, Firefox ESR 60\
1483 **CCK2 Equivalent:** `removeDeveloperTools`\
1484 **Preferences Affected:** `devtools.policy.disabled`
1485
1486 #### Windows (GPO)
1487 ```
1488 Software\Policies\Mozilla\Firefox\DisableDeveloperTools = 0x1 | 0x0`
1489 ```
1490 #### Windows (Intune)
1491 OMA-URI:
1492 ```
1493 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableDeveloperTools
1494 ```
1495 Value (string):
1496 ```
1497 <enabled/> or <disabled/>
1498 ```
1499 #### macOS
1500 ```
1501 <dict>
1502 <key>DisableDeveloperTools</key>
1503 <true/> | <false/>
1504 </dict>
1505 ```
1506 #### policies.json
1507 ```
1508 {
1509 "policies": {
1510 "DisableDeveloperTools": true | false
1511 }
1512 }
1513 ```
1514 ### DisableFeedbackCommands
1515 Disable the menus for reporting sites (Submit Feedback, Report Deceptive Site).
1516
1517 **Compatibility:** Firefox 60, Firefox ESR 60\
1518 **CCK2 Equivalent:** N/A\
1519 **Preferences Affected:** N/A
1520
1521 #### Windows (GPO)
1522 ```
1523 Software\Policies\Mozilla\Firefox\DisableFeedbackCommands = 0x1 | 0x0
1524 ```
1525 #### Windows (Intune)
1526 OMA-URI:
1527 ```
1528 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableFeedbackCommands
1529 ```
1530 Value (string):
1531 ```
1532 <enabled/> or <disabled/>
1533 ```
1534 #### macOS
1535 ```
1536 <dict>
1537 <key>DisableFeedbackCommands</key>
1538 <true/> | <false/>
1539 </dict>
1540 ```
1541 #### policies.json
1542 ```
1543 {
1544 "policies": {
1545 "DisableFeedbackCommands": true | false
1546 }
1547 }
1548 ```
1549 ### DisableFirefoxAccounts
1550 Disable Firefox Accounts integration (Sync).
1551
1552 **Compatibility:** Firefox 60, Firefox ESR 60\
1553 **CCK2 Equivalent:** `disableSync`\
1554 **Preferences Affected:** `identity.fxaccounts.enabled`
1555
1556 #### Windows (GPO)
1557 ```
1558 Software\Policies\Mozilla\Firefox\DisableFirefoxAccounts = 0x1 | 0x0
1559 ```
1560 #### Windows (Intune)
1561 OMA-URI:
1562 ```
1563 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableFirefoxAccounts
1564 ```
1565 Value (string):
1566 ```
1567 <enabled/> or <disabled/>
1568 ```
1569 #### macOS
1570 ```
1571 <dict>
1572 <key>DisableFirefoxAccounts</key>
1573 <true/> | <false/>
1574 </dict>
1575 ```
1576 #### policies.json
1577 ```
1578 {
1579 "policies": {
1580 "DisableFirefoxAccounts": true | false
1581 }
1582 }
1583 ```
1584 ### DisableFirefoxScreenshots
1585 Remove access to Firefox Screenshots.
1586
1587 **Compatibility:** Firefox 60, Firefox ESR 60\
1588 **CCK2 Equivalent:** N/A\
1589 **Preferences Affected:** `extensions.screenshots.disabled`
1590
1591 #### Windows (GPO)
1592 ```
1593 Software\Policies\Mozilla\Firefox\DisableFirefoxScreenshots = 0x1 | 0x0
1594 ```
1595 #### Windows (Intune)
1596 OMA-URI:
1597 ```
1598 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableFirefoxScreenshots
1599 ```
1600 Value (string):
1601 ```
1602 <enabled/> or <disabled/>
1603 ```
1604 #### macOS
1605 ```
1606 <dict>
1607 <key>DisableFirefoxScreenshots</key>
1608 <true/> | <false/>
1609 </dict>
1610 ```
1611 #### policies.json
1612 ```
1613 {
1614 "policies": {
1615 "DisableFirefoxScreenshots": true | false
1616 }
1617 }
1618 ```
1619 ### DisableFirefoxStudies
1620 Disable Firefox studies (Shield).
1621
1622 **Compatibility:** Firefox 60, Firefox ESR 60\
1623 **CCK2 Equivalent:** N/A\
1624 **Preferences Affected:** N/A
1625
1626 #### Windows (GPO)
1627 ```
1628 Software\Policies\Mozilla\Firefox\DisableFirefoxStudies = 0x1 | 0x0
1629 ```
1630 #### Windows (Intune)
1631 OMA-URI:
1632 ```
1633 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableFirefoxStudies
1634 ```
1635 Value (string):
1636 ```
1637 <enabled/> or <disabled/>
1638 ```
1639 #### macOS
1640 ```
1641 <dict>
1642 <key>DisableFirefoxStudies</key>
1643 <true/> | <false/>
1644 </dict>
1645 ```
1646 #### policies.json
1647 ```
1648 {
1649 "policies": {
1650 "DisableFirefoxStudies": true | false
1651 }
1652 }
1653 ```
1654 ### DisableForgetButton
1655 Disable the "Forget" button.
1656
1657 **Compatibility:** Firefox 60, Firefox ESR 60\
1658 **CCK2 Equivalent:** `disableForget`\
1659 **Preferences Affected:** N/A
1660
1661 #### Windows (GPO)
1662 ```
1663 Software\Policies\Mozilla\Firefox\DisableForgetButton = 0x1 | 0x0
1664 ```
1665 #### Windows (Intune)
1666 OMA-URI:
1667 ```
1668 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableForgetButton
1669 ```
1670 Value (string):
1671 ```
1672 <enabled/> or <disabled/>
1673 ```
1674 #### macOS
1675 ```
1676 <dict>
1677 <key>DisableForgetButton</key>
1678 <true/> | <false/>
1679 </dict>
1680 ```
1681 #### policies.json
1682 ```
1683 {
1684 "policies": {
1685 "DisableForgetButton": true | false
1686 }
1687 }
1688 ```
1689 ### DisableFormHistory
1690 Turn off saving information on web forms and the search bar.
1691
1692 **Compatibility:** Firefox 60, Firefox ESR 60\
1693 **CCK2 Equivalent:** `disableFormFill`\
1694 **Preferences Affected:** `browser.formfill.enable`
1695
1696 #### Windows (GPO)
1697 ```
1698 Software\Policies\Mozilla\Firefox\DisableFormHistory = 0x1 | 0x0
1699 ```
1700 #### Windows (Intune)
1701 OMA-URI:
1702 ```
1703 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableFormHistory
1704 ```
1705 Value (string):
1706 ```
1707 <enabled/> or <disabled/>
1708 ```
1709 #### macOS
1710 ```
1711 <dict>
1712 <key>DisableFormHistory</key>
1713 <true/> | <false/>
1714 </dict>
1715 ```
1716 #### policies.json
1717 ```
1718 {
1719 "policies": {
1720 "DisableFormHistory": true | false
1721 }
1722 }
1723 ```
1724 ### DisableMasterPasswordCreation
1725 Remove the master password functionality.
1726
1727 If this value is true, it works the same as setting [`PrimaryPassword`](#primarypassword) to false and removes the primary password functionality.
1728
1729 If both `DisableMasterPasswordCreation` and `PrimaryPassword` are used, `DisableMasterPasswordCreation` takes precedent.
1730
1731 **Compatibility:** Firefox 60, Firefox ESR 60\
1732 **CCK2 Equivalent:** `noMasterPassword`\
1733 **Preferences Affected:** N/A
1734
1735 #### Windows (GPO)
1736 ```
1737 Software\Policies\Mozilla\Firefox\DisableMasterPasswordCreation = 0x1 | 0x0
1738 ```
1739 #### Windows (Intune)
1740 OMA-URI:
1741 ```
1742 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableMasterPasswordCreation
1743 ```
1744 Value (string):
1745 ```
1746 <enabled/> or <disabled/>
1747 ```
1748 #### macOS
1749 ```
1750 <dict>
1751 <key>DisableMasterPasswordCreation</key>
1752 <true/> | <false/>
1753 </dict>
1754 ```
1755 #### policies.json
1756 ```
1757 {
1758 "policies": {
1759 "DisableMasterPasswordCreation": true | false
1760 }
1761 }
1762 ```
1763 ### DisablePasswordReveal
1764 Do not allow passwords to be shown in saved logins
1765
1766 **Compatibility:** Firefox 71, Firefox ESR 68.3\
1767 **CCK2 Equivalent:** N/A
1768 **Preferences Affected:** N/A
1769
1770 #### Windows (GPO)
1771 ```
1772 Software\Policies\Mozilla\Firefox\DisablePasswordReveal = 0x1 | 0x0
1773 ```
1774 #### Windows (Intune)
1775 OMA-URI:
1776 ```
1777 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisablePasswordReveal
1778 ```
1779 Value (string):
1780 ```
1781 <enabled/> or <disabled/>
1782 ```
1783 #### macOS
1784 ```
1785 <dict>
1786 <key>DisablePasswordReveal</key>
1787 <true/> | <false/>
1788 </dict>
1789 ```
1790 #### policies.json
1791 ```
1792 {
1793 "policies": {
1794 "DisablePasswordReveal": true | false
1795 }
1796 }
1797 ```
1798 ### DisablePocket
1799 Remove Pocket in the Firefox UI. It does not remove it from the new tab page.
1800
1801 **Compatibility:** Firefox 60, Firefox ESR 60\
1802 **CCK2 Equivalent:** `disablePocket`\
1803 **Preferences Affected:** `extensions.pocket.enabled`
1804
1805 #### Windows (GPO)
1806 ```
1807 Software\Policies\Mozilla\Firefox\DisablePocket = 0x1 | 0x0
1808 ```
1809 #### Windows (Intune)
1810 OMA-URI:
1811 ```
1812 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisablePocket
1813 ```
1814 Value (string):
1815 ```
1816 <enabled/> or <disabled/>
1817 ```
1818 #### macOS
1819 ```
1820 <dict>
1821 <key>DisablePocket</key>
1822 <true/> | <false/>
1823 </dict>
1824 ```
1825 #### policies.json
1826 ```
1827 {
1828 "policies": {
1829 "DisablePocket": true | false
1830 }
1831 }
1832 ```
1833 ### DisablePrivateBrowsing
1834 Remove access to private browsing.
1835
1836 **Compatibility:** Firefox 60, Firefox ESR 60\
1837 **CCK2 Equivalent:** `disablePrivateBrowsing`\
1838 **Preferences Affected:** N/A
1839
1840 #### Windows (GPO)
1841 ```
1842 Software\Policies\Mozilla\Firefox\DisablePrivateBrowsing = 0x1 | 0x0
1843 ```
1844 #### Windows (Intune)
1845 OMA-URI:
1846 ```
1847 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisablePrivateBrowsing
1848 ```
1849 Value (string):
1850 ```
1851 <enabled/> or <disabled/>
1852 ```
1853 #### macOS
1854 ```
1855 <dict>
1856 <key>DisablePrivateBrowsing</key>
1857 <true/> | <false/>
1858 </dict>
1859 ```
1860 #### policies.json
1861 ```
1862 {
1863 "policies": {
1864 "DisablePrivateBrowsing": true | false
1865 }
1866 }
1867 ```
1868 ### DisableProfileImport
1869 Disables the "Import data from another browser" option in the bookmarks window.
1870
1871 **Compatibility:** Firefox 60, Firefox ESR 60\
1872 **CCK2 Equivalent:** N/A\
1873 **Preferences Affected:** N/A
1874
1875 #### Windows (GPO)
1876 ```
1877 Software\Policies\Mozilla\Firefox\DisableProfileImport = 0x1 | 0x0
1878 ```
1879 #### Windows (Intune)
1880 OMA-URI:
1881 ```
1882 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableProfileImport
1883 ```
1884 Value (string):
1885 ```
1886 <enabled/> or <disabled/>
1887 ```
1888 #### macOS
1889 ```
1890 <dict>
1891 <key>DisableProfileImport</key>
1892 <true/> | <false/>
1893 </dict>
1894 ```
1895 #### policies.json
1896 ```
1897 {
1898 "policies": {
1899 "DisableProfileImport": true | false
1900 }
1901 }
1902 ```
1903 ### DisableProfileRefresh
1904 Disable the Refresh Firefox button on about:support and support.mozilla.org, as well as the prompt that displays offering to refresh Firefox when you haven't used it in a while.
1905
1906 **Compatibility:** Firefox 60, Firefox ESR 60\
1907 **CCK2 Equivalent:** `disableResetFirefox`\
1908 **Preferences Affected:** `browser.disableResetPrompt`
1909
1910 #### Windows (GPO)
1911 ```
1912 Software\Policies\Mozilla\Firefox\DisableProfileRefresh = 0x1 | 0x0
1913 ```
1914 #### Windows (Intune)
1915 OMA-URI:
1916 ```
1917 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableProfileRefresh
1918 ```
1919 Value (string):
1920 ```
1921 <enabled/> or <disabled/>
1922 ```
1923 #### macOS
1924 ```
1925 <dict>
1926 <key>DisableProfileRefresh</key>
1927 <true/> | <false/>
1928 </dict>
1929 ```
1930 #### policies.json
1931 ```
1932 {
1933 "policies": {
1934 "DisableProfileRefresh": true | false
1935 }
1936 }
1937 ```
1938 ### DisableSafeMode
1939 Disable safe mode within the browser.
1940
1941 On Windows, this disables safe mode via the command line as well.
1942
1943 **Compatibility:** Firefox 60, Firefox ESR 60 (Windows, macOS)\
1944 **CCK2 Equivalent:** `disableSafeMode`\
1945 **Preferences Affected:** N/A
1946
1947 #### Windows (GPO)
1948 ```
1949 Software\Policies\Mozilla\Firefox\DisableSafeMode = 0x1 | 0x0
1950 ```
1951 #### Windows (Intune)
1952 OMA-URI:
1953 ```
1954 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableSafeMode
1955 ```
1956 Value (string):
1957 ```
1958 <enabled/> or <disabled/>
1959 ```
1960 #### macOS
1961 ```
1962 <dict>
1963 <key>DisableSafeMode</key>
1964 <true/> | <false/>
1965 </dict>
1966 ```
1967 #### policies.json
1968 ```
1969 {
1970 "policies": {
1971 "DisableSafeMode": true | false
1972 }
1973 }
1974 ```
1975 ### DisableSecurityBypass
1976 Prevent the user from bypassing security in certain cases.
1977
1978 `InvalidCertificate` prevents adding an exception when an invalid certificate is shown.
1979
1980 `SafeBrowsing` prevents selecting "ignore the risk" and visiting a harmful site anyway.
1981
1982 These policies only affect what happens when an error is shown, they do not affect any settings in preferences.
1983
1984 **Compatibility:** Firefox 60, Firefox ESR 60\
1985 **CCK2 Equivalent:** N/A\
1986 **Preferences Affected:** `security.certerror.hideAddException`, `browser.safebrowsing.allowOverride`
1987
1988 #### Windows (GPO)
1989 ```
1990 Software\Policies\Mozilla\Firefox\DisableSecurityBypass\InvalidCertificate = 0x1 | 0x0
1991 Software\Policies\Mozilla\Firefox\DisableSecurityBypass\SafeBrowsing = 0x1 | 0x0
1992 ```
1993 #### Windows (Intune)
1994 OMA-URI:
1995 ```
1996 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/P_DisableSecurityBypass_InvalidCertificate
1997 ```
1998 Value (string):
1999 ```
2000 <enabled/> or <disabled/>
2001 ```
2002 OMA-URI:
2003 ```
2004 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/P_DisableSecurityBypass_SafeBrowsing
2005 ```
2006 Value (string):
2007 ```
2008 <enabled/> or <disabled/>
2009 ```
2010
2011 #### macOS
2012 ```
2013 <dict>
2014 <key>DisableSecurityBypass</key>
2015 <dict>
2016 <key>InvalidCertificate</key>
2017 <true/> | <false/>
2018 <key>SafeBrowsing</key>
2019 <true/> | <false/>
2020 </dict>
2021 </dict>
2022 ```
2023 #### policies.json
2024 ```
2025 {
2026 "policies": {
2027 "DisableSecurityBypass": {
2028 "InvalidCertificate": true | false,
2029 "SafeBrowsing": true | false
2030 }
2031 }
2032 }
2033 ```
2034 ### DisableSetDesktopBackground
2035 Remove the "Set As Desktop Background..." menuitem when right clicking on an image.
2036
2037 **Compatibility:** Firefox 60, Firefox ESR 60\
2038 **CCK2 Equivalent:** `removeSetDesktopBackground`\
2039 **Preferences Affected:** N/A
2040
2041 #### Windows (GPO)
2042 ```
2043 Software\Policies\Mozilla\Firefox\DisableSetDesktopBackground = 0x1 | 0x0
2044 ```
2045 #### Windows (Intune)
2046 OMA-URI:
2047 ```
2048 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableSetDesktopBackground
2049 ```
2050 Value (string):
2051 ```
2052 <enabled/> or <disabled/>
2053 ```
2054 #### macOS
2055 ```
2056 <dict>
2057 <key>DisableSetDesktopBackground</key>
2058 <true/> | <false/>
2059 </dict>
2060 ```
2061 #### policies.json
2062 ```
2063 {
2064 "policies": {
2065 "DisableSetDesktopBackground": true | false
2066 }
2067 }
2068 ```
2069 ### DisableSystemAddonUpdate
2070 Prevent system add-ons from being installed or updated.
2071
2072 **Compatibility:** Firefox 60, Firefox ESR 60\
2073 **CCK2 Equivalent:** N/A\
2074 **Preferences Affected:** N/A
2075
2076 #### Windows (GPO)
2077 ```
2078 Software\Policies\Mozilla\Firefox\DisableSystemAddonUpdate = 0x1 | 0x0
2079 ```
2080 #### Windows (Intune)
2081 OMA-URI:
2082 ```
2083 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableSystemAddonUpdate
2084 ```
2085 Value (string):
2086 ```
2087 <enabled/> or <disabled/>
2088 ```
2089 #### macOS
2090 ```
2091 <dict>
2092 <key>DisableSystemAddonUpdate</key>
2093 <true/> | <false/>
2094 </dict>
2095 ```
2096 #### policies.json
2097 ```
2098 {
2099 "policies": {
2100 "DisableSystemAddonUpdate": true | false
2101 }
2102 }
2103 ```
2104 ### DisableTelemetry
2105 Prevent the upload of telemetry data.
2106
2107 As of Firefox 83 and Firefox ESR 78.5, local storage of telemetry data is disabled as well.
2108
2109 Mozilla recommends that you do not disable telemetry. Information collected through telemetry helps us build a better product for businesses like yours.
2110
2111 **Compatibility:** Firefox 60, Firefox ESR 60\
2112 **CCK2 Equivalent:** `disableTelemetry`\
2113 **Preferences Affected:** `datareporting.healthreport.uploadEnabled`, `datareporting.policy.dataSubmissionEnabled`, `toolkit.telemetry.archive.enabled`
2114
2115 #### Windows (GPO)
2116 ```
2117 Software\Policies\Mozilla\Firefox\DisableTelemetry = 0x1 | 0x0
2118 ```
2119 #### Windows (Intune)
2120 OMA-URI:
2121 ```
2122 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableTelemetry
2123 ```
2124 Value (string):
2125 ```
2126 <enabled/> or <disabled/>
2127 ```
2128 #### macOS
2129 ```
2130 <dict>
2131 <key>DisableTelemetry</key>
2132 <true/> | <false/>
2133 </dict>
2134 ```
2135 #### policies.json
2136 ```
2137 {
2138 "policies": {
2139 "DisableTelemetry": true | false
2140 }
2141 }
2142 ```
2143 ### DisableThirdPartyModuleBlocking
2144 Do not allow blocking third-party modules from the `about:third-party` page.
2145
2146 This policy only works on Windows through GPO (not policies.json).
2147
2148 **Compatibility:** Firefox 110 (Windows only, GPO only)\
2149 **CCK2 Equivalent:** N/A\
2150 **Preferences Affected:** N/A
2151
2152 #### Windows (GPO)
2153 ```
2154 Software\Policies\Mozilla\Firefox\DisableThirdPartyModuleBlocking = = 0x1 | 0x0
2155 ```
2156 #### Windows (Intune)
2157 OMA-URI:
2158 ```
2159 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisableThirdPartyModuleBlocking
2160 ```
2161 Value (string):
2162 ```
2163 <enabled/> or <disabled/>
2164 ```
2165 ### DisplayBookmarksToolbar
2166 Set the initial state of the bookmarks toolbar. A user can still change how it is displayed.
2167
2168 `always` means the bookmarks toolbar is always shown.
2169
2170 `never` means the bookmarks toolbar is not shown.
2171
2172 `newtab` means the bookmarks toolbar is only shown on the new tab page.
2173
2174 **Compatibility:** Firefox 109, Firefox ESR 102.7\
2175 **CCK2 Equivalent:** N/A\
2176 **Preferences Affected:** N/A
2177
2178 #### Windows (GPO)
2179 ```
2180 Software\Policies\Mozilla\Firefox\DisplayBookmarksToolbar = "always", "never", "newtab"
2181 ```
2182 #### Windows (Intune)
2183 OMA-URI:
2184 ```
2185 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisplayBookmarksToolbar_Enum
2186 ```
2187 Value (string):
2188 ```
2189 <enabled/>
2190 <data id="DisplayBookmarksToolbar" value="always | never | newtab"/>
2191 ```
2192 #### macOS
2193 ```
2194 <dict>
2195 <key>DisplayBookmarksToolbar</key>
2196 <string>always | never | newtab</string>
2197 </dict>
2198 ```
2199 #### policies.json
2200 ```
2201 {
2202 "policies": {
2203 "DisplayBookmarksToolbar": "always" | "never" | "newtab"
2204 }
2205 }
2206 ```
2207 ### DisplayMenuBar
2208 Set the state of the menubar.
2209
2210 `always` means the menubar is shown and cannot be hidden.
2211
2212 `never` means the menubar is hidden and cannot be shown.
2213
2214 `default-on` means the menubar is on by default but can be hidden.
2215
2216 `default-off` means the menubar is off by default but can be shown.
2217
2218 **Compatibility:** Firefox 73, Firefox ESR 68.5 (Windows, some Linux)\
2219 **CCK2 Equivalent:** `displayMenuBar`\
2220 **Preferences Affected:** N/A
2221
2222 #### Windows (GPO)
2223 ```
2224 Software\Policies\Mozilla\Firefox\DisplayMenuBar = "always", "never", "default-on", "default-off"
2225 ```
2226 #### Windows (Intune)
2227 OMA-URI:
2228 ```
2229 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DisplayMenuBar_Enum
2230 ```
2231 Value (string):
2232 ```
2233 <enabled/>
2234 <data id="DisplayMenuBar" value="always | never | default-on | default-off"/>
2235 ```
2236 #### macOS
2237 ```
2238 <dict>
2239 <key>DisplayMenuBar</key>
2240 <string>always | never | default-on | default-off</string>
2241 </dict>
2242 ```
2243 #### policies.json
2244 ```
2245 {
2246 "policies": {
2247 "DisplayMenuBar": "always", "never", "default-on", "default-off"
2248 }
2249 }
2250 ```
2251 ### DNSOverHTTPS
2252 Configure DNS over HTTPS.
2253
2254 `Enabled` determines whether DNS over HTTPS is enabled
2255
2256 `ProviderURL` is a URL to another provider.
2257
2258 `Locked` prevents the user from changing DNS over HTTPS preferences.
2259
2260 `ExcludedDomains` excludes domains from DNS over HTTPS.
2261
2262 **Compatibility:** Firefox 63, Firefox ESR 68 (ExcludedDomains added in 75/68.7)\
2263 **CCK2 Equivalent:** N/A\
2264 **Preferences Affected:** `network.trr.mode`, `network.trr.uri`
2265
2266 #### Windows (GPO)
2267 ```
2268 Software\Policies\Mozilla\Firefox\DNSOverHTTPS\Enabled = 0x1 | 0x0
2269 Software\Policies\Mozilla\Firefox\DNSOverHTTPS\ProviderURL = "URL_TO_ALTERNATE_PROVIDER"
2270 Software\Policies\Mozilla\Firefox\DNSOverHTTPS\Locked = 0x1 | 0x0
2271 Software\Policies\Mozilla\Firefox\DNSOverHTTPS\ExcludedDomains\1 = "example.com"
2272 ```
2273 #### Windows (Intune)
2274 OMA-URI:
2275 ```
2276 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~DNSOverHTTPS/DNSOverHTTPS_Enabled
2277 ```
2278 Value (string):
2279 ```
2280 <enabled/> or <disabled/>
2281 ```
2282 OMA-URI:
2283 ```
2284 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~DNSOverHTTPS/DNSOverHTTPS_ProviderURL
2285 ```
2286 Value (string):
2287 ```
2288 <enabled/>
2289 <data id="String" value="URL_TO_ALTERNATE_PROVIDER"/>
2290 ```
2291 OMA-URI:
2292 ```
2293 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~DNSOverHTTPS/DNSOverHTTPS_Locked
2294 ```
2295 Value (string):
2296 ```
2297 <enabled/> or <disabled/>
2298 ```
2299 OMA-URI:
2300 ```
2301 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~DNSOverHTTPS/DNSOverHTTPS_ExcludedDomains
2302 ```
2303 Value (string):
2304 ```
2305 <enabled/>
2306 <data id="List" value="1&#xF000;example.com"/>
2307 ```
2308 #### macOS
2309 ```
2310 <dict>
2311 <key>DNSOverHTTPS</key>
2312 <dict>
2313 <key>Enabled</key>
2314 <true/> | <false/>
2315 <key>ProviderURL</key>
2316 <string>URL_TO_ALTERNATE_PROVIDER</string>
2317 <key>Locked</key>
2318 <true/> | <false/>
2319 <key>ExcludedDomains</key>
2320 <array>
2321 <string>example.com</string>
2322 </array>
2323 </dict>
2324 </dict>
2325 ```
2326 #### policies.json
2327 ```
2328 {
2329 "policies": {
2330 "DNSOverHTTPS": {
2331 "Enabled": true | false,
2332 "ProviderURL": "URL_TO_ALTERNATE_PROVIDER",
2333 "Locked": true | false,
2334 "ExcludedDomains": ["example.com"]
2335 }
2336 }
2337 }
2338 ```
2339 ### DontCheckDefaultBrowser
2340 Don't check if Firefox is the default browser at startup.
2341
2342 **Compatibility:** Firefox 60, Firefox ESR 60\
2343 **CCK2 Equivalent:** `dontCheckDefaultBrowser`\
2344 **Preferences Affected:** `browser.shell.checkDefaultBrowser`
2345
2346 #### Windows (GPO)
2347 ```
2348 Software\Policies\Mozilla\Firefox\DontCheckDefaultBrowser = 0x1 | 0x0
2349 ```
2350 #### Windows (Intune)
2351 OMA-URI:
2352 ```
2353 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DontCheckDefaultBrowser
2354 ```
2355 Value (string):
2356 ```
2357 <enabled/> or <disabled/>
2358 ```
2359 #### macOS
2360 ```
2361 <dict>
2362 <key>DontCheckDefaultBrowser</key>
2363 <true/> | <false/>
2364 </dict>
2365 ```
2366 #### policies.json
2367 ```
2368 {
2369 "policies": {
2370 "DontCheckDefaultBrowser": true | false
2371 }
2372 }
2373 ```
2374 ### DownloadDirectory
2375 Set and lock the download directory.
2376
2377 You can use ${home} for the native home directory.
2378
2379 **Compatibility:** Firefox 68, Firefox ESR 68\
2380 **CCK2 Equivalent:** N/A\
2381 **Preferences Affected:** `browser.download.dir`, `browser.download.folderList`, `browser.download.useDownloadDir`
2382
2383 #### Windows (GPO)
2384 ```
2385 Software\Policies\Mozilla\Firefox\DownloadDirectory = "${home}\Downloads"
2386 ```
2387 #### Windows (Intune)
2388 OMA-URI:
2389 ```
2390 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/DownloadDirectory
2391 ```
2392 Value (string):
2393 ```
2394 <enabled/>
2395 <data id="Preferences_String" value="${home}\Downloads"/>
2396 ```
2397 #### macOS
2398 ```
2399 <dict>
2400 <key>DownloadDirectory</key>
2401 <string>${home}/Downloads</string>
2402 </dict>
2403 ```
2404 #### policies.json (macOS and Linux)
2405 ```
2406 {
2407 "policies": {
2408 "DownloadDirectory": "${home}/Downloads"
2409 }
2410 ```
2411 #### policies.json (Windows)
2412 ```
2413 {
2414 "policies": {
2415 "DownloadDirectory": "${home}\\Downloads"
2416 }
2417 ```
2418 ### EnableTrackingProtection
2419 Configure tracking protection.
2420
2421 If this policy is not configured, tracking protection is not enabled by default in the browser, but it is enabled by default in private browsing and the user can change it.
2422
2423 If `Value` is set to false, tracking protection is disabled and locked in both the regular browser and private browsing.
2424
2425 If `Value` is set to true, tracking protection is enabled by default in both the regular browser and private browsing and the `Locked` value determines whether or not a user can change it.
2426
2427 If `Cryptomining` is set to true, cryptomining scripts on websites are blocked.
2428
2429 If `Fingerprinting` is set to true, fingerprinting scripts on websites are blocked.
2430
2431 If `EmailTracking` is set to true, hidden email tracking pixels and scripts on websites are blocked. (Firefox 112)
2432
2433 `Exceptions` are origins for which tracking protection is not enabled.
2434
2435 **Compatibility:** Firefox 60, Firefox ESR 60 (Cryptomining and Fingerprinting added in 70/68.2, Exceptions added in 73/68.5)\
2436 **CCK2 Equivalent:** N/A\
2437 **Preferences Affected:** `privacy.trackingprotection.enabled`, `privacy.trackingprotection.pbmode.enabled`, `privacy.trackingprotection.cryptomining.enabled`, `privacy.trackingprotection.fingerprinting.enabled`
2438
2439 #### Windows (GPO)
2440 ```
2441 Software\Policies\Mozilla\Firefox\EnableTrackingProtection\Value = 0x1 | 0x0
2442 Software\Policies\Mozilla\Firefox\EnableTrackingProtection\Locked = 0x1 | 0x0
2443 Software\Policies\Mozilla\Firefox\EnableTrackingProtection\Cryptomining = 0x1 | 0x0
2444 Software\Policies\Mozilla\Firefox\EnableTrackingProtection\Fingerprinting = 0x1 | 0x0
2445 Software\Policies\Mozilla\Firefox\EnableTrackingProtection\Exceptions\1 = "https://example.com"
2446 ```
2447 #### Windows (Intune)
2448 OMA-URI:
2449 ```
2450 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~TrackingProtection/A_TrackingProtection_Value
2451 ```
2452 Value (string):
2453 ```
2454 <enabled/> or <disabled/>
2455 ```
2456 OMA-URI:
2457 ```
2458 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~TrackingProtection/B_TrackingProtection_Cryptomining
2459 ```
2460 Value (string):
2461 ```
2462 <enabled/> or <disabled/>
2463 ```
2464 OMA-URI:
2465 ```
2466 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~TrackingProtection/C_TrackingProtection_Fingerprinting
2467 ```
2468 Value (string):
2469 ```
2470 <enabled/> or <disabled/>
2471 ```
2472 OMA-URI:
2473 ```
2474 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~TrackingProtection/D_TrackingProtection_Exceptions
2475 ```
2476 Value (string):
2477 ```
2478 <enabled/>
2479 <data id="TrackingProtection_Exceptions" value="1&#xF000;https://example.com"/>
2480 ```
2481 OMA-URI:
2482 ```
2483 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~TrackingProtection/E_TrackingProtection_Locked
2484 ```
2485 Value (string):
2486 ```
2487 <enabled/> or <disabled/>
2488 ```
2489 #### macOS
2490 ```
2491 <dict>
2492 <key>EnableTrackingProtection</key>
2493 <dict>
2494 <key>Value</key>
2495 <true/> | <false/>
2496 <key>Locked</key>
2497 <true/> | <false/>
2498 <key>Cryptomining</key>
2499 <true/> | <false/>
2500 <key>Fingerprinting</key>
2501 <true/> | <false/>
2502 <key>Exceptions</key>
2503 <array>
2504 <string>https://example.com</string>
2505 </array>
2506 </dict>
2507 </dict>
2508 ```
2509 #### policies.json
2510 ```
2511 {
2512 "policies": {
2513 "EnableTrackingProtection": {
2514 "Value": true | false,
2515 "Locked": true | false,
2516 "Cryptomining": true | false,
2517 "Fingerprinting": true | false,
2518 "Exceptions": ["https://example.com"]
2519 }
2520 }
2521 }
2522 ```
2523 ### EncryptedMediaExtensions
2524 Enable or disable Encrypted Media Extensions and optionally lock it.
2525
2526 If `Enabled` is set to false, encrypted media extensions (like Widevine) are not downloaded by Firefox unless the user consents to installing them.
2527
2528 If `Locked` is set to true and `Enabled` is set to false, Firefox will not download encrypted media extensions (like Widevine) or ask the user to install them.
2529
2530 **Compatibility:** Firefox 77, Firefox ESR 68.9\
2531 **CCK2 Equivalent:** N/A\
2532 **Preferences Affected:** `media.eme.enabled`
2533
2534 #### Windows (GPO)
2535 ```
2536 Software\Policies\Mozilla\Firefox\EncryptedMediaExtensions\Enabled = 0x1 | 0x0
2537 Software\Policies\Mozilla\Firefox\EncryptedMediaExtensions\Locked = 0x1 | 0x0
2538 ```
2539 #### Windows (Intune)
2540 OMA-URI:
2541 ```
2542 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~EncryptedMediaExtensions/EncryptedMediaExtensions_Enabled
2543 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~EncryptedMediaExtensions/EncryptedMediaExtensions_Locked
2544 ```
2545 Value (string):
2546 ```
2547 <enabled/>or <disabled/>
2548 ```
2549 #### macOS
2550 ```
2551 <dict>
2552 <key>EncryptedMediaExtensions</key>
2553 <dict>
2554 <key>Enabled</key>
2555 <true/> | <false/>
2556 <key>Locked</key>
2557 <true/> | <false/>
2558 </dict>
2559 </dict>
2560 ```
2561 #### policies.json
2562 ```
2563 {
2564 "policies": {
2565 "EncryptedMediaExtensions": {
2566 "Enabled": true | false,
2567 "Locked": true | false
2568 }
2569 }
2570 }
2571 ```
2572 ### EnterprisePoliciesEnabled
2573 Enable policy support on macOS.
2574
2575 **Compatibility:** Firefox 63, Firefox ESR 60.3 (macOS only)\
2576 **CCK2 Equivalent:** N/A\
2577 **Preferences Affected:** N/A
2578
2579 #### macOS
2580 ```
2581 <dict>
2582 <key>EnterprisePoliciesEnabled</key>
2583 <true/>
2584 </dict>
2585 ```
2586 ### ExemptDomainFileTypePairsFromFileTypeDownloadWarnings
2587
2588 Disable warnings based on file extension for specific file types on domains.
2589
2590 This policy is based on the [Chrome policy](https://chromeenterprise.google/policies/#ExemptDomainFileTypePairsFromFileTypeDownloadWarnings) of the same name.
2591
2592 Important: The documentation for the policy for both Edge and Chrome is incorrect. The ```domains``` value must be a domain, not a URL pattern. Also, we do not support using ```*``` to mean all domains.
2593
2594 **Compatibility:** Firefox 102\
2595 **CCK2 Equivalent:** N/A\
2596 **Preferences Affected:** N/A
2597
2598 #### Windows (GPO)
2599 Software\Policies\Mozilla\Firefox\ExemptDomainFileTypePairsFromFileTypeDownloadWarnings (REG_MULTI_SZ) =
2600 ```
2601 [
2602 {
2603 "file_extension": "jnlp",
2604 "domains": ["example.com"]
2605 }
2606 ]
2607 ```
2608 #### Windows (Intune)
2609 OMA-URI:
2610 ```
2611 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/ExemptDomainFileTypePairsFromFileTypeDownloadWarnings
2612 ```
2613 Value (string):
2614 ```
2615 <enabled/>
2616 <data id="JSON" value='
2617 [
2618 {
2619 "file_extension": "jnlp",
2620 "domains": ["example.com"]
2621 }
2622 ]
2623 '/>
2624 ```
2625 #### macOS
2626 ```
2627 <dict>
2628 <key>ExemptDomainFileTypePairsFromFileTypeDownloadWarnings</key>
2629 <array>
2630 <dict>
2631 <key>file_extension</key>
2632 <string>jnlp</string>
2633 <key>domains</key>
2634 <array>
2635 <string>example.com</string>
2636 </array>
2637 </dict>
2638 </array>
2639 </dict>
2640 ```
2641 #### policies.json
2642 ```
2643 {
2644 "policies": {
2645 "ExemptDomainFileTypePairsFromFileTypeDownloadWarnings": [{
2646 "file_extension": "jnlp",
2647 "domains": ["example.com"]
2648 }]
2649 }
2650 }
2651 ```
2652 ### Extensions
2653 Control the installation, uninstallation and locking of extensions.
2654
2655 While this policy is not technically deprecated, it is recommended that you use the **[`ExtensionSettings`](#extensionsettings)** policy. It has the same functionality and adds more. It does not support native paths, though, so you'll have to use file:/// URLs.
2656
2657 `Install` is a list of URLs or native paths for extensions to be installed.
2658
2659 `Uninstall` is a list of extension IDs that should be uninstalled if found.
2660
2661 `Locked` is a list of extension IDs that the user cannot disable or uninstall.
2662
2663 **Compatibility:** Firefox 60, Firefox ESR 60\
2664 **CCK2 Equivalent:** `addons`\
2665 **Preferences Affected:** N/A
2666
2667 #### Windows (GPO)
2668 ```
2669 Software\Policies\Mozilla\Firefox\Extensions\Install\1 = "https://addons.mozilla.org/firefox/downloads/somefile.xpi"
2670 Software\Policies\Mozilla\Firefox\Extensions\Install\2 = "//path/to/xpi"
2671 Software\Policies\Mozilla\Firefox\Extensions\Uninstall\1 = "bad_addon_id@mozilla.org"
2672 Software\Policies\Mozilla\Firefox\Extensions\Locked\1 = "addon_id@mozilla.org"
2673 ```
2674 #### Windows (Intune)
2675 OMA-URI:
2676 ```
2677 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Extensions/Extensions_Install
2678 ```
2679 Value (string):
2680 ```
2681 <enabled/>
2682 <data id="Extensions" value="1&#xF000;https://addons.mozilla.org/firefox/downloads/somefile.xpi&#xF000;2&#xF000;//path/to/xpi"/>
2683 ```
2684 OMA-URI:
2685 ```
2686 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Extensions/Extensions_Uninstall
2687 ```
2688 Value (string):
2689 ```
2690 <enabled/>
2691 <data id="Extensions" value="1&#xF000;bad_addon_id@mozilla.org"/>
2692 ```
2693 OMA-URI:
2694 ```
2695 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Extensions/Extensions_Locked
2696 ```
2697 Value (string):
2698 ```
2699 <enabled/>
2700 <data id="Extensions" value="1&#xF000;addon_id@mozilla.org"/>
2701 ```
2702 #### macOS
2703 ```
2704 <dict>
2705 <key>Extensions</key>
2706 <dict>
2707 <key>Install</key>
2708 <array>
2709 <string>https://addons.mozilla.org/firefox/downloads/somefile.xpi</string>
2710 <string>//path/to/xpi</string>
2711 </array>
2712 <key>Uninstall</key>
2713 <array>
2714 <string>bad_addon_id@mozilla.org</string>
2715 </array>
2716 <key>Locked</key>
2717 <array>
2718 <string>addon_id@mozilla.org</string>
2719 </array>
2720 </dict>
2721 </dict>
2722 ```
2723 #### policies.json
2724 ```
2725 {
2726 "policies": {
2727 "Extensions": {
2728 "Install": ["https://addons.mozilla.org/firefox/downloads/somefile.xpi", "//path/to/xpi"],
2729 "Uninstall": ["bad_addon_id@mozilla.org"],
2730 "Locked": ["addon_id@mozilla.org"]
2731 }
2732 }
2733 }
2734 ```
2735 ### ExtensionSettings
2736 Manage all aspects of extensions. This policy is based heavily on the [Chrome policy](https://dev.chromium.org/administrators/policy-list-3/extension-settings-full) of the same name.
2737
2738 This policy maps an extension ID to its configuration. With an extension ID, the configuration will be applied to the specified extension only. A default configuration can be set for the special ID "*", which will apply to all extensions that don't have a custom configuration set in this policy.
2739
2740 To obtain an extension ID, install the extension and go to about:support. You will see the ID in the Extensions section. I've also created an extension that makes it easy to find the ID of extensions on AMO. You can download it [here](https://github.com/mkaply/queryamoid/releases/tag/v0.1).
2741
2742 The configuration for each extension is another dictionary that can contain the fields documented below.
2743
2744 | Name | Description |
2745 | --- | --- |
2746 | `installation_mode` | Maps to a string indicating the installation mode for the extension. The valid strings are `allowed`,`blocked`,`force_installed`, and `normal_installed`.
2747 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`allowed` | Allows the extension to be installed by the user. This is the default behavior. There is no need for an install_url; it will automatically be allowed based on the ID.
2748 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`blocked`| Blocks installation of the extension and removes it from the device if already installed.
2749 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`force_installed`| The extension is automatically installed and can't be removed by the user. This option is not valid for the default configuration and requires an install_url.
2750 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`normal_installed`| The extension is automatically installed but can be disabled by the user. This option is not valid for the default configuration and requires an install_url.
2751 | `install_url`| Maps to a URL indicating where Firefox can download a force_installed or normal_installed extension. If installing from the local file system, use a [```file:///``` URL](https://en.wikipedia.org/wiki/File_URI_scheme). If installing from the addons.mozilla.org, use the following URL (substituting SHORT_NAME from the URL on AMO), https://addons.mozilla.org/firefox/downloads/latest/SHORT_NAME/latest.xpi. Languages packs are available from https://releases.mozilla.org/pub/firefox/releases/VERSION/PLATFORM/xpi/LANGUAGE.xpi. If you need to update the extension, you can change the name of the extension and it will be automatically updated. Extensions installed from file URLs will additional be updated when their internal version changes.
2752 | `install_sources` | A list of sources from which installing extensions is allowed using URL match patterns. **This is unnecessary if you are only allowing the installation of certain extensions by ID.** Each item in this list is an extension-style match pattern. Users will be able to easily install items from any URL that matches an item in this list. Both the location of the *.xpi file and the page where the download is started from (i.e. the referrer) must be allowed by these patterns. This setting can be used only for the default configuration.
2753 | `allowed_types` | This setting whitelists the allowed types of extension/apps that can be installed in Firefox. The value is a list of strings, each of which should be one of the following: "extension", "theme", "dictionary", "locale" This setting can be used only for the default configuration.
2754 | `blocked_install_message` | This maps to a string specifying the error message to display to users if they're blocked from installing an extension. This setting allows you to append text to the generic error message displayed when the extension is blocked. This could be be used to direct users to your help desk, explain why a particular extension is blocked, or something else. This setting can be used only for the default configuration.
2755 | `restricted_domains` | An array of domains on which content scripts can't be run. This setting can be used only for the default configuration.
2756 | `updates_disabled` | (Firefox 89, Firefox ESR 78.11) Boolean that indicates whether or not to disable automatic updates for an individual extension.
2757 | `default_area` | (Firefox 113) String that indicates where to place the extension icon by default. Possible values are `navbar` and `menupanel`.
2758
2759 **Compatibility:** Firefox 69, Firefox ESR 68.1 (As of Firefox 85, Firefox ESR 78.7, installing a theme makes it the default.)\
2760 **CCK2 Equivalent:** N/A\
2761 **Preferences Affected:** N/A
2762
2763 #### Windows (GPO)
2764 Software\Policies\Mozilla\Firefox\ExtensionSettings (REG_MULTI_SZ) =
2765 ```
2766 {
2767 "*": {
2768 "blocked_install_message": "Custom error message.",
2769 "install_sources": ["https://yourwebsite.com/*"],
2770 "installation_mode": "blocked",
2771 "allowed_types": ["extension"]
2772 },
2773 "uBlock0@raymondhill.net": {
2774 "installation_mode": "force_installed",
2775 "install_url": "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi"
2776 },
2777 "https-everywhere@eff.org": {
2778 "installation_mode": "allowed"
2779 }
2780 }
2781 ```
2782 #### Windows (Intune)
2783 OMA-URI:
2784 ```
2785 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Extensions/ExtensionSettings
2786 ```
2787 Value (string):
2788 ```
2789 <enabled/>
2790 <data id="ExtensionSettings" value='
2791 {
2792 "*": {
2793 "blocked_install_message": "Custom error message.",
2794 "install_sources": ["https://yourwebsite.com/*"],
2795 "installation_mode": "blocked",
2796 "allowed_types": ["extension"]
2797 },
2798 "uBlock0@raymondhill.net": {
2799 "installation_mode": "force_installed",
2800 "install_url": "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi"
2801 },
2802 "https-everywhere@eff.org": {
2803 "installation_mode": "allowed"
2804 }
2805 }'/>
2806 ```
2807 #### macOS
2808 ```
2809 <dict>
2810 <key>ExtensionSettings</key>
2811 <dict>
2812 <key>*</key>
2813 <dict>
2814 <key>blocked_install_message</key>
2815 <string>Custom error message.</string>
2816 <key>install_sources</key>
2817 <array>
2818 <string>"https://yourwebsite.com/*"</string>
2819 </array>
2820 <key>installation_mode</key>
2821 <string>blocked</string>
2822 <key>allowed_types</key>
2823 <array>
2824 <string>extension</string>
2825 </array>
2826 </dict>
2827 <key>uBlock0@raymondhill.net</key>
2828 <dict>
2829 <key>installation_mode</key>
2830 <string>force_installed</string>
2831 <key>install_url</key>
2832 <string>https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi</string>
2833 </dict>
2834 <key>https-everywhere@eff.org</key>
2835 <dict>
2836 <key>installation_mode</key>
2837 <string>allowed</string>
2838 </dict>
2839 </dict>
2840 </dict>
2841 ```
2842 #### policies.json
2843 ```
2844 {
2845 "policies": {
2846 "ExtensionSettings": {
2847 "*": {
2848 "blocked_install_message": "Custom error message.",
2849 "install_sources": ["https://yourwebsite.com/*"],
2850 "installation_mode": "blocked",
2851 "allowed_types": ["extension"]
2852 },
2853 "uBlock0@raymondhill.net": {
2854 "installation_mode": "force_installed",
2855 "install_url": "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi"
2856 },
2857 "https-everywhere@eff.org": {
2858 "installation_mode": "allowed"
2859 }
2860 }
2861 }
2862 }
2863 ```
2864 ### ExtensionUpdate
2865 Control extension updates.
2866
2867 **Compatibility:** Firefox 67, Firefox ESR 60.7\
2868 **CCK2 Equivalent:** N/A\
2869 **Preferences Affected:** `extensions.update.enabled`
2870
2871 #### Windows (GPO)
2872 ```
2873 Software\Policies\Mozilla\Firefox\ExtensionUpdate = 0x1 | 0x0
2874 ```
2875 #### Windows (Intune)
2876 OMA-URI:
2877 ```
2878 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Extensions/ExtensionUpdate
2879 ```
2880 Value (string):
2881 ```
2882 <enabled/> or <disabled/>
2883 ```
2884 #### macOS
2885 ```
2886 <dict>
2887 <key>ExtensionUpdate</key>
2888 <true/> | <false/>
2889 </dict>
2890 ```
2891 #### policies.json
2892 ```
2893 {
2894 "policies": {
2895 "ExtensionUpdate": true | false
2896 }
2897 }
2898 ```
2899 ### FirefoxHome
2900 Customize the Firefox Home page.
2901
2902 **Compatibility:** Firefox 68, Firefox ESR 68 (SponsoredTopSites and SponsoredPocket were added in Firefox 95, Firefox ESR 91.4)
2903 **CCK2 Equivalent:** N/A\
2904 **Preferences Affected:** `browser.newtabpage.activity-stream.showSearch`, `browser.newtabpage.activity-stream.feeds.topsites`, `browser.newtabpage.activity-stream.feeds.section.highlights`, `browser.newtabpage.activity-stream.feeds.section.topstories`, `browser.newtabpage.activity-stream.feeds.snippets`, `browser.newtabpage.activity-stream.showSponsoredTopSites`, `browser.newtabpage.activity-stream.showSponsored`
2905
2906 #### Windows (GPO)
2907 ```
2908 Software\Policies\Mozilla\Firefox\FirefoxHome\Search = 0x1 | 0x0
2909 Software\Policies\Mozilla\Firefox\FirefoxHome\TopSites = 0x1 | 0x0
2910 Software\Policies\Mozilla\Firefox\FirefoxHome\SponsoredTopSites = 0x1 | 0x0
2911 Software\Policies\Mozilla\Firefox\FirefoxHome\Highlights = 0x1 | 0x0
2912 Software\Policies\Mozilla\Firefox\FirefoxHome\Pocket = 0x1 | 0x0
2913 Software\Policies\Mozilla\Firefox\FirefoxHome\SponsoredPocket = 0x1 | 0x0
2914 Software\Policies\Mozilla\Firefox\FirefoxHome\Snippets = 0x1 | 0x0
2915 Software\Policies\Mozilla\Firefox\FirefoxHome\Locked = 0x1 | 0x0
2916 ```
2917 #### Windows (Intune)
2918 OMA-URI:
2919 ```
2920 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/CustomizeFirefoxHome
2921 ```
2922 Value (string):
2923 ```
2924 <enabled/>
2925 <data id="FirefoxHome_Search" value="true | false"/>
2926 <data id="FirefoxHome_TopSites" value="true | false"/>
2927 <data id="FirefoxHome_SponsoredTopSites" value="true | false"/>
2928 <data id="FirefoxHome_Highlights" value="true | false"/>
2929 <data id="FirefoxHome_Pocket" value="true | false"/>
2930 <data id="FirefoxHome_SponsoredPocket" value="true | false"/>
2931 <data id="FirefoxHome_Snippets" value="true | false"/>
2932 <data id="FirefoxHome_Locked" value="true | false"/>
2933 ```
2934 #### macOS
2935 ```
2936 <dict>
2937 <key>FirefoxHome</key>
2938 <dict>
2939 <key>Search</key>
2940 <true/> | <false/>
2941 <key>TopSites</key>
2942 <true/> | <false/>
2943 <key>SponsoredTopSites</key>
2944 <true/> | <false/>
2945 <key>Highlights</key>
2946 <true/> | <false/>
2947 <key>Pocket</key>
2948 <true/> | <false/>
2949 <key>SponsoredPocket</key>
2950 <true/> | <false/>
2951 <key>Snippets</key>
2952 <true/> | <false/>
2953 <key>Locked</key>
2954 <true/> | <false/>
2955 </dict>
2956 </dict>
2957 ```
2958 #### policies.json
2959 ```
2960 {
2961 "policies": {
2962 "FirefoxHome": {
2963 "Search": true | false,
2964 "TopSites": true | false,
2965 "SponsoredTopSites": true | false,
2966 "Highlights": true | false,
2967 "Pocket": true | false,
2968 "SponsoredPocket": true | false,
2969 "Snippets": true | false,
2970 "Locked": true | false
2971 }
2972 }
2973 }
2974 ```
2975 ### FirefoxSuggest
2976 Customize Firefox Suggest (US only).
2977
2978 **Compatibility:** Firefox 118, Firefox ESR 115.3.
2979 **CCK2 Equivalent:** N/A\
2980 **Preferences Affected:** `browser.urlbar.suggest.quicksuggest.nonsponsored`, `browser.urlbar.suggest.quicksuggest.sponsored`, `browser.urlbar.quicksuggest.dataCollection.enabled`
2981
2982 #### Windows (GPO)
2983 ```
2984 Software\Policies\Mozilla\Firefox\FirefoxSuggest\WebSuggestions = 0x1 | 0x0
2985 Software\Policies\Mozilla\Firefox\FirefoxSuggest\SponsoredSuggestions = 0x1 | 0x0
2986 Software\Policies\Mozilla\Firefox\FirefoxSuggest\ImproveSuggest = 0x1 | 0x0
2987 Software\Policies\Mozilla\Firefox\FirefoxSuggest\Locked = 0x1 | 0x0
2988 ```
2989 #### Windows (Intune)
2990 OMA-URI:
2991 ```
2992 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~FirefoxSuggest/WebSuggestions
2993 ```
2994 Value (string):
2995 ```
2996 <enabled/> or <disabled/>
2997 ```
2998 OMA-URI:
2999 ```
3000 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~FirefoxSuggest/SponsoredSuggestions
3001 ```
3002 Value (string):
3003 ```
3004 <enabled/> or <disabled/>
3005 ```
3006 OMA-URI:
3007 ```
3008 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~FirefoxSuggest/ImproveSuggest
3009 ```
3010 Value (string):
3011 ```
3012 <enabled/> or <disabled/>
3013 ```
3014 OMA-URI:
3015 ```
3016 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~FirefoxSuggest/Locked
3017 ```
3018 Value (string):
3019 ```
3020 <enabled/> or <disabled/>
3021 ```
3022 #### macOS
3023 ```
3024 <dict>
3025 <key>FirefoxSuggest</key>
3026 <dict>
3027 <key>WebSuggestions</key>
3028 <true/> | <false/>
3029 <key>SponsoredSuggestions</key>
3030 <true/> | <false/>
3031 <key>ImproveSuggest</key>
3032 <true/> | <false/>
3033 <key>Locked</key>
3034 <true/> | <false/>
3035 </dict>
3036 </dict>
3037 ```
3038 #### policies.json
3039 ```
3040 {
3041 "policies": {
3042 "FirefoxSuggest": {
3043 "WebSuggestions": true | false,
3044 "SponsoredSuggestions": true | false,
3045 "ImproveSuggest": true | false,
3046 "Locked": true | false
3047 }
3048 }
3049 }
3050 ```
3051 ### GoToIntranetSiteForSingleWordEntryInAddressBar
3052 Whether to always go through the DNS server before sending a single word search string to a search engine.
3053
3054 If the site exists, it will navigate to the website. If the intranet responds with a 404, the page will show a 404. If the intranet does not respond, the browser will attempt a search.
3055
3056 The second result in the URL bar will be a search result to allow users to conduct a web search exactly as it was entered.
3057
3058 If instead you would like to enable the ability to have your domain appear as a valid URL and to disallow the browser from ever searching that term using the first result that matches it, add the pref `browser.fixup.domainwhitelist.YOUR_DOMAIN` (where `YOUR_DOMAIN` is the name of the domain you'd like to add), and set the pref to `true`. The URL bar will then suggest `YOUR_DOMAIN` when the user fully types `YOUR_DOMAIN`. If the user attempts to load that domain and it fails to load, it will show an "Unable to connect" error page.
3059
3060 You can also whitelist a domain suffix that is not part of the [Public Suffix List](https://publicsuffix.org/) by adding the pref `browser.fixup.domainsuffixwhitelist.YOUR_DOMAIN_SUFFIX` with a value of `true`.
3061
3062 Additionally, if you want users to see a "Did you mean to go to 'YOUR_DOMAIN'" prompt below the URL bar if they land on a search results page instead of an intranet domain that provides a response, set the pref `browser.urlbar.dnsResolveSingleWordsAfterSearch` to `1`. Enabling this will cause the browser to commit a DNS check after every single word search. If the browser receives a response from the intranet, a prompt will ask the user if they'd like to instead navigate to `YOUR_DOMAIN`. If the user presses the **yes** button, `browser.fixup.domainwhitelist.YOUR_DOMAIN` will be set to `true`.
3063
3064 **Compatibility:** Firefox 104, Firefox ESR 102.2\
3065 **CCK2 Equivalent:** `N/A`\
3066 **Preferences Affected:** `browser.fixup.dns_first_for_single_words`
3067
3068 #### Windows (GPO)
3069 ```
3070 Software\Policies\Mozilla\Firefox\GoToIntranetSiteForSingleWordEntryInAddressBar = 0x1 | 0x0
3071 ```
3072 #### Windows (Intune)
3073 OMA-URI:
3074 ```
3075 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/GoToIntranetSiteForSingleWordEntryInAddressBar
3076 ```
3077 Value (string):
3078 ```
3079 <enabled/> or <disabled/>
3080 ```
3081 #### macOS
3082 ```
3083 <dict>
3084 <key>GoToIntranetSiteForSingleWordEntryInAddressBar</key>
3085 <true/> | <false/>
3086 </dict>
3087 ```
3088 #### policies.json
3089 ```
3090 {
3091 "policies": {
3092 "GoToIntranetSiteForSingleWordEntryInAddressBar": true | false
3093 }
3094 }
3095 ```
3096 ### Handlers
3097 Configure default application handlers. This policy is based on the internal format of `handlers.json`.
3098
3099 You can configure handlers based on a mime type (`mimeTypes`), a file's extension (`extensions`), or a protocol (`schemes`).
3100
3101 Within each handler type, you specify the given mimeType/extension/scheme as a key and use the following subkeys to describe how it is handled.
3102
3103 | Name | Description |
3104 | --- | --- |
3105 | `action`| Can be either `saveToDisk`, `useHelperApp`, `useSystemDefault`.
3106 | `ask` | If `true`, the user is asked if what they want to do with the file. If `false`, the action is taken without user intervention.
3107 | `handlers` | An array of handlers with the first one being the default. If you don't want to have a default handler, use an empty object for the first handler. Choose between path or uriTemplate.
3108 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`name` | The display name of the handler (might not be used).
3109 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`path`| The native path to the executable to be used.
3110 | &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;`uriTemplate`| A url to a web based application handler. The URL must be https and contain a %s to be used for substitution.
3111
3112 **Compatibility:** Firefox 78, Firefox ESR 78\
3113 **CCK2 Equivalent:** N/A\
3114 **Preferences Affected:** N/A
3115
3116 #### Windows (GPO)
3117 Software\Policies\Mozilla\Firefox\Handlers (REG_MULTI_SZ) =
3118 ```
3119 {
3120 "mimeTypes": {
3121 "application/msword": {
3122 "action": "useSystemDefault",
3123 "ask": true | false
3124 }
3125 },
3126 "schemes": {
3127 "mailto": {
3128 "action": "useHelperApp",
3129 "ask": true | false,
3130 "handlers": [{
3131 "name": "Gmail",
3132 "uriTemplate": "https://mail.google.com/mail/?extsrc=mailto&url=%s"
3133 }]
3134 }
3135 },
3136 "extensions": {
3137 "pdf": {
3138 "action": "useHelperApp",
3139 "ask": true | false,
3140 "handlers": [{
3141 "name": "Adobe Acrobat",
3142 "path": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe"
3143 }]
3144 }
3145 }
3146 }
3147 ```
3148 #### Windows (Intune)
3149 OMA-URI:
3150 ```
3151 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/Handlers
3152 ```
3153 Value (string):
3154 ```
3155 <enabled/>
3156 <data id="Handlers" value='
3157 {
3158 "mimeTypes": {
3159 "application/msword": {
3160 "action": "useSystemDefault",
3161 "ask": true | false
3162 }
3163 },
3164 "schemes": {
3165 "mailto": {
3166 "action": "useHelperApp",
3167 "ask": true | false,
3168 "handlers": [{
3169 "name": "Gmail",
3170 "uriTemplate": "https://mail.google.com/mail/?extsrc=mailto&amp;url=%s"
3171 }]
3172 }
3173 },
3174 "extensions": {
3175 "pdf": {
3176 "action": "useHelperApp",
3177 "ask": true | false,
3178 "handlers": [{
3179 "name": "Adobe Acrobat",
3180 "path": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe"
3181 }]
3182 }
3183 }
3184 }
3185 '/>
3186 ```
3187 #### macOS
3188 ```
3189 <dict>
3190 <key>Handlers</key>
3191 <dict>
3192 <key>mimeTypes</key>
3193 <dict>
3194 <key>application/msword</key>
3195 <dict>
3196 <key>action</key>
3197 <string>useSystemDefault</string>
3198 <key>ask</key>
3199 <true/> | <false/>
3200 </dict>
3201 </dict>
3202 <key>schemes</key>
3203 <dict>
3204 <key>mailto</key>
3205 <dict>
3206 <key>action</key>
3207 <string>useHelperApp</string>
3208 <key>ask</key>
3209 <true/> | <false/>
3210 <key>handlers</key>
3211 <array>
3212 <dict>
3213 <key>name</key>
3214 <string>Gmail</string>
3215 <key>uriTemplate</key>
3216 <string>https://mail.google.com/mail/?extsrc=mailto&url=%s</string>
3217 </dict>
3218 </array>
3219 </dict>
3220 </dict>
3221 <key>extensions</key>
3222 <dict>
3223 <key>pdf</key>
3224 <dict>
3225 <key>action</key>
3226 <string>useHelperApp</string>
3227 <key>ask</key>
3228 <true/> | <false/>
3229 <key>handlers</key>
3230 <array>
3231 <dict>
3232 <key>name</key>
3233 <string>Adobe Acrobat</string>
3234 <key>path</key>
3235 <string>/System/Applications/Preview.app</string>
3236 </dict>
3237 </array>
3238 </dict>
3239 </dict>
3240 </dict>
3241 </dict>
3242 ```
3243 #### policies.json
3244 ```
3245 {
3246 "policies": {
3247 "Handlers": {
3248 "mimeTypes": {
3249 "application/msword": {
3250 "action": "useSystemDefault",
3251 "ask": false
3252 }
3253 },
3254 "schemes": {
3255 "mailto": {
3256 "action": "useHelperApp",
3257 "ask": true | false,
3258 "handlers": [{
3259 "name": "Gmail",
3260 "uriTemplate": "https://mail.google.com/mail/?extsrc=mailto&url=%s"
3261 }]
3262 }
3263 },
3264 "extensions": {
3265 "pdf": {
3266 "action": "useHelperApp",
3267 "ask": true | false,
3268 "handlers": [{
3269 "name": "Adobe Acrobat",
3270 "path": "/usr/bin/acroread"
3271 }]
3272 }
3273 }
3274 }
3275 }
3276 }
3277 ```
3278 ### HardwareAcceleration
3279 Control hardware acceleration.
3280
3281 **Compatibility:** Firefox 60, Firefox ESR 60\
3282 **CCK2 Equivalent:** N/A\
3283 **Preferences Affected:** `layers.acceleration.disabled`
3284
3285 #### Windows (GPO)
3286 ```
3287 Software\Policies\Mozilla\Firefox\HardwareAcceleration = 0x1 | 0x0
3288 ```
3289 #### Windows (Intune)
3290 OMA-URI:
3291 ```
3292 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/HardwareAcceleration
3293 ```
3294 Value (string):
3295 ```
3296 <enabled/> or <disabled/>
3297 ```
3298 #### macOS
3299 ```
3300 <dict>
3301 <key>HardwareAcceleration</key>
3302 <true/> | <false/>
3303 </dict>
3304 ```
3305 #### policies.json
3306 ```
3307 {
3308 "policies": {
3309 "HardwareAcceleration": true | false
3310 }
3311 }
3312 ```
3313 ### Homepage
3314 Configure the default homepage and how Firefox starts.
3315
3316 `URL` is the default homepage.
3317
3318 `Locked` prevents the user from changing homepage preferences.
3319
3320 `Additional` allows for more than one homepage.
3321
3322 `StartPage` is how Firefox starts. The choices are no homepage, the default homepage or the previous session.
3323
3324 With Firefox 78, an additional option as added for `Startpage`, `homepage-locked`. If this is value is set for the Startpage, the user will always get the homepage at startup and cannot choose to restore their session.
3325
3326 **Compatibility:** Firefox 60, Firefox ESR 60 (StartPage was added in Firefox 60, Firefox ESR 60.4, homepage-locked added in Firefox 78)\
3327 **CCK2 Equivalent:** `homePage`,`lockHomePage`\
3328 **Preferences Affected:** `browser.startup.homepage`, `browser.startup.page`
3329
3330 #### Windows (GPO)
3331 ```
3332 Software\Policies\Mozilla\Firefox\Homepage\URL = "https://example.com"
3333 Software\Policies\Mozilla\Firefox\Homepage\Locked = 0x1 | 0x0
3334 Software\Policies\Mozilla\Firefox\Homepage\Additional\1 = "https://example.org"
3335 Software\Policies\Mozilla\Firefox\Homepage\Additional\2 = "https://example.edu"
3336 Software\Policies\Mozilla\Firefox\Homepage\StartPage = "none" | "homepage" | "previous-session" | "homepage-locked"
3337 ```
3338 #### Windows (Intune)
3339 OMA-URI:
3340 ```
3341 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Homepage/HomepageURL
3342 ```
3343 Value (string):
3344 ```
3345 <enabled/>
3346
3347 <data id="HomepageURL" value="https://example.com"/>
3348 <data id="HomepageLocked" value="true | false"/>
3349 ```
3350 OMA-URI:
3351 ```
3352 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Homepage/HomepageAdditional
3353 ```
3354 Value (string):
3355 ```
3356 <enabled/>
3357
3358 <data id="HomepageAdditional" value="1&#xF000;http://example.org&#xF000;2&#xF000;http://example.edu"/>
3359 ```
3360 OMA-URI:
3361 ```
3362 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Homepage/HomepageStartPage
3363 ```
3364 Value (string):
3365 ```
3366 <enabled/>
3367
3368 <data id="StartPage" value="none | homepage | previous-session"/>
3369 ```
3370 #### macOS
3371 ```
3372 <dict>
3373 <key>Homepage</key>
3374 <dict>
3375 <key>URL</key>
3376 <string>http://example.com</string>
3377 <key>Locked</key>
3378 <true/> | <false/>
3379 <key>Additional</key>
3380 <array>
3381 <string>http://example.org</string>
3382 <string>http://example.edu</string>
3383 </array>
3384 <key>StartPage</key>
3385 <string>none | homepage | previous-session | homepage-locked</string>
3386 </dict>
3387 </dict>
3388 ```
3389 #### policies.json
3390 ```
3391 {
3392 "policies": {
3393 "Homepage": {
3394 "URL": "http://example.com/",
3395 "Locked": true | false,
3396 "Additional": ["http://example.org/",
3397 "http://example.edu/"],
3398 "StartPage": "none" | "homepage" | "previous-session" | "homepage-locked"
3399 }
3400 }
3401 }
3402 ```
3403 ### InstallAddonsPermission
3404 Configure the default extension install policy as well as origins for extension installs are allowed. This policy does not override turning off all extension installs.
3405
3406 `Allow` is a list of origins where extension installs are allowed.
3407
3408 `Default` determines whether or not extension installs are allowed by default.
3409
3410 **Compatibility:** Firefox 60, Firefox ESR 60\
3411 **CCK2 Equivalent:** `permissions.install`\
3412 **Preferences Affected:** `xpinstall.enabled`
3413
3414 #### Windows (GPO)
3415 ```
3416 Software\Policies\Mozilla\Firefox\InstallAddonsPermission\Allow\1 = "https://example.org"
3417 Software\Policies\Mozilla\Firefox\InstallAddonsPermission\Allow\2 = "https://example.edu"
3418 Software\Policies\Mozilla\Firefox\InstallAddonsPermission\Default = 0x1 | 0x0
3419 ```
3420 #### Windows (Intune)
3421 OMA-URI:
3422 ```
3423 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Addons/InstallAddonsPermission_Allow
3424 ```
3425 Value (string):
3426 ```
3427 <enabled/>
3428 <data id="Permissions" value="1&#xF000;https://example.org&#xF000;2&#xF000;https://example.edu"/>
3429 ```
3430 OMA-URI:
3431 ```
3432 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Addons/InstallAddonsPermission_Default
3433 ```
3434 Value (string):
3435 ```
3436 <enabled/>
3437 ```
3438 #### macOS
3439 ```
3440 <dict>
3441 <key>InstallAddonsPermission</key>
3442 <dict>
3443 <key>Allow</key>
3444 <array>
3445 <string>http://example.org</string>
3446 <string>http://example.edu</string>
3447 </array>
3448 <key>Default</key>
3449 <true/> | <false/>
3450 </dict>
3451 </dict>
3452 ```
3453 #### policies.json
3454 ```
3455 {
3456 "policies": {
3457 "InstallAddonsPermission": {
3458 "Allow": ["http://example.org/",
3459 "http://example.edu/"],
3460 "Default": true | false
3461 }
3462 }
3463 }
3464 ```
3465 ### LegacyProfiles
3466 Disable the feature enforcing a separate profile for each installation.
3467
3468 If this policy set to true, Firefox will not try to create different profiles for installations of Firefox in different directories. This is the equivalent of the MOZ_LEGACY_PROFILES environment variable.
3469
3470 If this policy set to false, Firefox will create a new profile for each unique installation of Firefox.
3471
3472 This policy only work on Windows via GPO (not policies.json).
3473
3474 **Compatibility:** Firefox 70, Firefox ESR 68.2 (Windows only, GPO only)\
3475 **CCK2 Equivalent:** N/A\
3476 **Preferences Affected:** N/A
3477
3478 #### Windows (GPO)
3479 ```
3480 Software\Policies\Mozilla\Firefox\LegacyProfiles = = 0x1 | 0x0
3481 ```
3482 #### Windows (Intune)
3483 OMA-URI:
3484 ```
3485 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/LegacyProfiles
3486 ```
3487 Value (string):
3488 ```
3489 <enabled/> or <disabled/>
3490 ```
3491 ### LegacySameSiteCookieBehaviorEnabled
3492 Enable default legacy SameSite cookie behavior setting.
3493
3494 If this policy is set to true, it reverts all cookies to legacy SameSite behavior which means that cookies that don't explicitly specify a ```SameSite``` attribute are treated as if they were ```SameSite=None```.
3495
3496 **Compatibility:** Firefox 96\
3497 **CCK2 Equivalent:** N/A\
3498 **Preferences Affected:** `network.cookie.sameSite.laxByDefault`
3499
3500 #### Windows (GPO)
3501 ```
3502 Software\Policies\Mozilla\Firefox\LegacySameSiteCookieBehaviorEnabled = = 0x1 | 0x0
3503 ```
3504 #### Windows (Intune)
3505 OMA-URI:
3506 ```
3507 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/LegacySameSiteCookieBehaviorEnabled
3508 ```
3509 Value (string):
3510 ```
3511 <enabled/> or <disabled/>
3512 ```
3513 #### macOS
3514 ```
3515 <dict>
3516 <key>LegacySameSiteCookieBehaviorEnabled</key>
3517 <true/> | <false/>
3518 </dict>
3519 ```
3520 #### policies.json
3521 ```
3522 {
3523 "policies": {
3524 "LegacySameSiteCookieBehaviorEnabled": true | false
3525 }
3526 ```
3527 ### LegacySameSiteCookieBehaviorEnabledForDomainList
3528 Revert to legacy SameSite behavior for cookies on specified sites.
3529
3530 If this policy is set to true, cookies set for domains in this list will revert to legacy SameSite behavior which means that cookies that don't explicitly specify a ```SameSite``` attribute are treated as if they were ```SameSite=None```.
3531
3532 **Compatibility:** Firefox 96\
3533 **CCK2 Equivalent:** N/A\
3534 **Preferences Affected:** `network.cookie.sameSite.laxByDefault.disabledHosts`
3535
3536 #### Windows (GPO)
3537 ```
3538 Software\Policies\Mozilla\Firefox\LegacySameSiteCookieBehaviorEnabledForDomainList\1 = "example.org"
3539 Software\Policies\Mozilla\Firefox\LegacySameSiteCookieBehaviorEnabledForDomainList\2 = "example.edu"
3540 ```
3541 #### Windows (Intune)
3542 OMA-URI:
3543 ```
3544 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/LegacySameSiteCookieBehaviorEnabledForDomainList
3545 ```
3546 Value (string):
3547 ```
3548 <enabled/>
3549 <data id="LegacySameSiteCookieBehaviorEnabledForDomainList" value="1&#xF000;example.org&#xF000;2&#xF000;example.edu"/>
3550 ```
3551 #### macOS
3552 ```
3553 <dict>
3554 <key>LegacySameSiteCookieBehaviorEnabledForDomainList</key>
3555 <array>
3556 <string>example.org</string>
3557 <string>example.edu</string>
3558 </array>
3559 </dict>
3560 ```
3561 #### policies.json
3562 ```
3563 {
3564 "policies": {
3565 "LegacySameSiteCookieBehaviorEnabledForDomainList": ["example.org",
3566 "example.edu"]
3567 }
3568 }
3569 ```
3570 ### LocalFileLinks
3571 Enable linking to local files by origin.
3572
3573 **Compatibility:** Firefox 68, Firefox ESR 68\
3574 **CCK2 Equivalent:** N/A\
3575 **Preferences Affected:** `capability.policy.localfilelinks.*`
3576
3577 #### Windows (GPO)
3578 ```
3579 Software\Policies\Mozilla\Firefox\LocalFileLinks\1 = "https://example.org"
3580 Software\Policies\Mozilla\Firefox\LocalFileLinks\2 = "https://example.edu"
3581 ```
3582 #### Windows (Intune)
3583 OMA-URI:
3584 ```
3585 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/LocalFileLinks
3586 ```
3587 Value (string):
3588 ```
3589 <enabled/>
3590 <data id="LocalFileLinks" value="1&#xF000;https://example.org&#xF000;2&#xF000;https://example.edu"/>
3591 ```
3592 #### macOS
3593 ```
3594 <dict>
3595 <key>LocalFileLinks</key>
3596 <array>
3597 <string>http://example.org</string>
3598 <string>http://example.edu</string>
3599 </array>
3600 </dict>
3601 ```
3602 #### policies.json
3603 ```
3604 {
3605 "policies": {
3606 "LocalFileLinks": ["http://example.org/",
3607 "http://example.edu/"]
3608 }
3609 }
3610 ```
3611 ### ManagedBookmarks
3612 Configures a list of bookmarks managed by an administrator that cannot be changed by the user.
3613
3614 The bookmarks are only added as a button on the personal toolbar. They are not in the bookmarks folder.
3615
3616 The syntax of this policy is exactly the same as the [Chrome ManagedBookmarks policy](https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ManagedBookmarks). The schema is:
3617 ```
3618 {
3619 "items": {
3620 "id": "BookmarkType",
3621 "properties": {
3622 "children": {
3623 "items": {
3624 "$ref": "BookmarkType"
3625 },
3626 "type": "array"
3627 },
3628 "name": {
3629 "type": "string"
3630 },
3631 "toplevel_name": {
3632 "type": "string"
3633 },
3634 "url": {
3635 "type": "string"
3636 }
3637 },
3638 "type": "object"
3639 },
3640 "type": "array"
3641 }
3642 ```
3643 **Compatibility:** Firefox 83, Firefox ESR 78.5\
3644 **CCK2 Equivalent:** N/A\
3645 **Preferences Affected:** N/A
3646
3647 #### Windows (GPO)
3648 Software\Policies\Mozilla\Firefox\ManagedBookmarks (REG_MULTI_SZ) =
3649 ```
3650 [
3651 {
3652 "toplevel_name": "My managed bookmarks folder"
3653 },
3654 {
3655 "url": "example.com",
3656 "name": "Example"
3657 },
3658 {
3659 "name": "Mozilla links",
3660 "children": [
3661 {
3662 "url": "https://mozilla.org",
3663 "name": "Mozilla.org"
3664 },
3665 {
3666 "url": "https://support.mozilla.org/",
3667 "name": "SUMO"
3668 }
3669 ]
3670 }
3671 ]
3672 ```
3673 #### Windows (Intune)
3674 OMA-URI:
3675 ```
3676 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/ManagedBookmarks
3677 ```
3678 Value (string):
3679 ```
3680 <enabled/>
3681 <data id="JSON" value='
3682 [
3683 {
3684 "toplevel_name": "My managed bookmarks folder"
3685 },
3686 {
3687 "url": "example.com",
3688 "name": "Example"
3689 },
3690 {
3691 "name": "Mozilla links",
3692 "children": [
3693 {
3694 "url": "https://mozilla.org",
3695 "name": "Mozilla.org"
3696 },
3697 {
3698 "url": "https://support.mozilla.org/",
3699 "name": "SUMO"
3700 }
3701 ]
3702 }
3703 ]'/>
3704 ```
3705 #### macOS
3706 ```
3707 <dict>
3708 <key>ManagedBookmarks</key>
3709 <array>
3710 <dict>
3711 <key>toplevel_name</key>
3712 <string>My managed bookmarks folder</string>
3713 <dict>
3714 <key>url</key>
3715 <string>example.com</string>
3716 <key>name</key>
3717 <string>Example</string>
3718 </dict>
3719 <dict>
3720 <key>name</key>
3721 <string>Mozilla links</string>
3722 <key>children</key>
3723 <array>
3724 <dict>
3725 <key>url</key>
3726 <string>https://mozilla.org</string>
3727 <key>name</key>
3728 <string>Mozilla</string>
3729 </dict>
3730 <dict>
3731 <key>url</key>
3732 <string>https://support.mozilla.org/</string>
3733 <key>name</key>
3734 <string>SUMO</string>
3735 </dict>
3736 </array>
3737 </dict>
3738 </array>
3739 </dict>
3740 ```
3741 #### policies.json
3742 ```
3743 {
3744 "policies": {
3745 "ManagedBookmarks": [
3746 {
3747 "toplevel_name": "My managed bookmarks folder"
3748 },
3749 {
3750 "url": "example.com",
3751 "name": "Example"
3752 },
3753 {
3754 "name": "Mozilla links",
3755 "children": [
3756 {
3757 "url": "https://mozilla.org",
3758 "name": "Mozilla.org"
3759 },
3760 {
3761 "url": "https://support.mozilla.org/",
3762 "name": "SUMO"
3763 }
3764 ]
3765 }
3766 ]
3767 }
3768 }
3769 ```
3770 ### ManualAppUpdateOnly
3771
3772 Switch to manual updates only.
3773
3774 If this policy is enabled:
3775 1. The user will never be prompted to install updates
3776 2. Firefox will not check for updates in the background, though it will check automatically when an update UI is displayed (such as the one in the About dialog). This check will be used to show "Update to version X" in the UI, but will not automatically download the update or prompt the user to update in any other way.
3777 3. The update UI will work as expected, unlike when using DisableAppUpdate.
3778
3779 This policy is primarily intended for advanced end users, not for enterprises.
3780
3781 **Compatibility:** Firefox 87\
3782 **CCK2 Equivalent:** N/A\
3783 **Preferences Affected:** N/A
3784
3785 #### policies.json
3786 ```
3787 {
3788 "policies": {
3789 "ManualAppUpdateOnly": true | false
3790 }
3791 }
3792 ```
3793 ### NetworkPrediction
3794 Enable or disable network prediction (DNS prefetching).
3795
3796 **Compatibility:** Firefox 67, Firefox ESR 60.7\
3797 **CCK2 Equivalent:** N/A\
3798 **Preferences Affected:** `network.dns.disablePrefetch`, `network.dns.disablePrefetchFromHTTPS`
3799
3800 #### Windows (GPO)
3801 ```
3802 Software\Policies\Mozilla\Firefox\NetworkPrediction = 0x1 | 0x0
3803 ```
3804 #### Windows (Intune)
3805 OMA-URI:
3806 ```
3807 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/NetworkPrediction
3808 ```
3809 Value (string):
3810 ```
3811 <enabled/> or <disabled/>
3812 ```
3813 #### macOS
3814 ```
3815 <dict>
3816 <key>NetworkPrediction</key>
3817 <true/> | <false/>
3818 </dict>
3819 ```
3820 #### policies.json
3821 ```
3822 {
3823 "policies": {
3824 "NetworkPrediction": true | false
3825 }
3826 ```
3827 ### NewTabPage
3828 Enable or disable the New Tab page.
3829
3830 **Compatibility:** Firefox 68, Firefox ESR 68\
3831 **CCK2 Equivalent:** N/A\
3832 **Preferences Affected:** `browser.newtabpage.enabled`
3833
3834 #### Windows (GPO)
3835 ```
3836 Software\Policies\Mozilla\Firefox\NewTabPage = 0x1 | 0x0
3837 ```
3838 #### Windows (Intune)
3839 OMA-URI:
3840 ```
3841 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/NewTabPage
3842 ```
3843 Value (string):
3844 ```
3845 <enabled/> or <disabled/>
3846 ```
3847 #### macOS
3848 ```
3849 <dict>
3850 <key>NewTabPage</key>
3851 <true/> | <false/>
3852 </dict>
3853 ```
3854 #### policies.json
3855 ```
3856 {
3857 "policies": {
3858 "NewTabPage": true | false
3859 }
3860 ```
3861 ### NoDefaultBookmarks
3862 Disable the creation of default bookmarks.
3863
3864 This policy is only effective if the user profile has not been created yet.
3865
3866 **Compatibility:** Firefox 60, Firefox ESR 60\
3867 **CCK2 Equivalent:** `removeDefaultBookmarks`\
3868 **Preferences Affected:** N/A
3869
3870 #### Windows (GPO)
3871 ```
3872 Software\Policies\Mozilla\Firefox\NoDefaultBookmarks = 0x1 | 0x0
3873 ```
3874 #### Windows (Intune)
3875 OMA-URI:
3876 ```
3877 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/NoDefaultBookmarks
3878 ```
3879 Value (string):
3880 ```
3881 <enabled/> or <disabled/>
3882 ```
3883 #### macOS
3884 ```
3885 <dict>
3886 <key>NoDefaultBookmarks</key>
3887 <true/> | <false/>
3888 </dict>
3889 ```
3890 #### policies.json
3891 ```
3892 {
3893 "policies": {
3894 "NoDefaultBookmarks": true | false
3895 }
3896 }
3897 ```
3898 ### OfferToSaveLogins
3899 Control whether or not Firefox offers to save passwords.
3900
3901 **Compatibility:** Firefox 60, Firefox ESR 60\
3902 **CCK2 Equivalent:** `dontRememberPasswords`\
3903 **Preferences Affected:** `signon.rememberSignons`
3904
3905 #### Windows (GPO)
3906 ```
3907 Software\Policies\Mozilla\Firefox\OfferToSaveLogins = 0x1 | 0x0
3908 ```
3909 #### Windows (Intune)
3910 OMA-URI:
3911 ```
3912 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/OfferToSaveLogins
3913 ```
3914 Value (string):
3915 ```
3916 <enabled/> or <disabled/>
3917 ```
3918 #### macOS
3919 ```
3920 <dict>
3921 <key>OfferToSaveLogins</key>
3922 <true/> | <false/>
3923 </dict>
3924 ```
3925 #### policies.json
3926 ```
3927 {
3928 "policies": {
3929 "OfferToSaveLogins": true | false
3930 }
3931 }
3932 ```
3933 ### OfferToSaveLoginsDefault
3934 Sets the default value of signon.rememberSignons without locking it.
3935
3936 **Compatibility:** Firefox 70, Firefox ESR 60.2\
3937 **CCK2 Equivalent:** `dontRememberPasswords`\
3938 **Preferences Affected:** `signon.rememberSignons`
3939
3940 #### Windows (GPO)
3941 ```
3942 Software\Policies\Mozilla\Firefox\OfferToSaveLoginsDefault = 0x1 | 0x0
3943 ```
3944 #### Windows (Intune)
3945 OMA-URI:
3946 ```
3947 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/OfferToSaveLoginsDefault
3948 ```
3949 Value (string):
3950 ```
3951 <enabled/> or <disabled/>
3952 ```
3953 #### macOS
3954 ```
3955 <dict>
3956 <key>OfferToSaveLoginsDefault</key>
3957 <true/> | <false/>
3958 </dict>
3959 ```
3960 #### policies.json
3961 ```
3962 {
3963 "policies": {
3964 "OfferToSaveLoginsDefault": true | false
3965 }
3966 }
3967 ```
3968 ### OverrideFirstRunPage
3969 Override the first run page. If the value is an empty string (""), the first run page is not displayed.
3970
3971 Starting with Firefox 83, Firefox ESR 78.5, you can also specify multiple URLS separated by a vertical bar (|).
3972
3973 **Compatibility:** Firefox 60, Firefox ESR 60\
3974 **CCK2 Equivalent:** `welcomePage`,`noWelcomePage`\
3975 **Preferences Affected:** `startup.homepage_welcome_url`
3976
3977 #### Windows (GPO)
3978 ```
3979 Software\Policies\Mozilla\Firefox\OverrideFirstRunPage = "http://example.org"
3980 ```
3981 #### Windows (Intune)
3982 OMA-URI:
3983 ```
3984 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/OverrideFirstRunPage
3985 ```
3986 Value (string):
3987 ```
3988 <enabled/>
3989 <data id="OverridePage" value="https://example.com"/>
3990 ```
3991 #### macOS
3992 ```
3993 <dict>
3994 <key>OverrideFirstRunPage</key>
3995 <string>http://example.org</string>
3996 </dict>
3997 ```
3998 #### policies.json
3999 ```
4000 {
4001 "policies": {
4002 "OverrideFirstRunPage": "http://example.org"
4003 }
4004 }
4005 ```
4006 ### OverridePostUpdatePage
4007 Override the upgrade page. If the value is an empty string (""), no extra pages are displayed when Firefox is upgraded.
4008
4009 **Compatibility:** Firefox 60, Firefox ESR 60\
4010 **CCK2 Equivalent:** `upgradePage`,`noUpgradePage`\
4011 **Preferences Affected:** `startup.homepage_override_url`
4012
4013 #### Windows (GPO)
4014 ```
4015 Software\Policies\Mozilla\Firefox\OverridePostUpdatePage = "http://example.org"
4016 ```
4017 #### Windows (Intune)
4018 OMA-URI:
4019 ```
4020 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/OverridePostUpdatePage
4021 ```
4022 Value (string):
4023 ```
4024 <enabled/>
4025 <data id="OverridePage" value="https://example.com"/>
4026 ```
4027 #### macOS
4028 ```
4029 <dict>
4030 <key>OverridePostUpdatePage</key>
4031 <string>http://example.org</string>
4032 </dict>
4033 ```
4034 #### policies.json
4035 ```
4036 {
4037 "policies": {
4038 "OverridePostUpdatePage": "http://example.org"
4039 }
4040 }
4041 ```
4042 ### PasswordManagerEnabled
4043 Remove access to the password manager via preferences and blocks about:logins on Firefox 70.
4044
4045 **Compatibility:** Firefox 70, Firefox ESR 60.2\
4046 **CCK2 Equivalent:** N/A\
4047 **Preferences Affected:** `pref.privacy.disable_button.view_passwords`
4048
4049 #### Windows (GPO)
4050 ```
4051 Software\Policies\Mozilla\Firefox\PasswordManagerEnabled = 0x1 | 0x0
4052 ```
4053 #### Windows (Intune)
4054 OMA-URI:
4055 ```
4056 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/PasswordManagerEnabled
4057 ```
4058 Value (string):
4059 ```
4060 <enabled/> or <disabled/>
4061 ```
4062 #### macOS
4063 ```
4064 <dict>
4065 <key>PasswordManagerEnabled</key>
4066 <true/> | <false/>
4067 </dict>
4068 ```
4069 #### policies.json
4070 ```
4071 {
4072 "policies": {
4073 "PasswordManagerEnabled": true | false
4074 }
4075 }
4076 ```
4077 ### PasswordManagerExceptions
4078 Prevent Firefox from saving passwords for specific sites.
4079
4080 The sites are specified as a list of origins.
4081
4082 **Compatibility:** Firefox 101\
4083 **CCK2 Equivalent:** N/A\
4084 **Preferences Affected:** N/A
4085
4086 #### Windows (GPO)
4087 ```
4088 Software\Policies\Mozilla\Firefox\PasswordManagerExceptions\1 = "https://example.org"
4089 Software\Policies\Mozilla\Firefox\PasswordManagerExceptions\2 = "https://example.edu"
4090 ```
4091 #### Windows (Intune)
4092 OMA-URI:
4093 ```
4094 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/PasswordManagerExceptions
4095 ```
4096 Value (string):
4097 ```
4098 <enabled/>
4099 <data id="List" value="1&#xF000;https://example.org&#xF000;2&#xF000;https://example.edu"/>
4100 ```
4101 #### macOS
4102 ```
4103 <dict>
4104 <key>PasswordManagerExceptions</key>
4105 <array>
4106 <string>https://example.org</string>
4107 <string>https://example.edu</string>
4108 </array>
4109 </dict>
4110 ```
4111 #### policies.json
4112 ```
4113 {
4114 "policies": {
4115 "PasswordManagerExceptions": ["https://example.org",
4116 "https://example.edu"]
4117 }
4118 }
4119 ```
4120
4121 ### PDFjs
4122 Disable or configure PDF.js, the built-in PDF viewer.
4123
4124 If `Enabled` is set to false, the built-in PDF viewer is disabled.
4125
4126 If `EnablePermissions` is set to true, the built-in PDF viewer will honor document permissions like preventing the copying of text.
4127
4128 Note: DisableBuiltinPDFViewer has not been deprecated. You can either continue to use it, or switch to using PDFjs->Enabled to disable the built-in PDF viewer. This new permission was added because we needed a place for PDFjs->EnabledPermissions.
4129
4130 **Compatibility:** Firefox 77, Firefox ESR 68.9\
4131 **CCK2 Equivalent:** N/A\
4132 **Preferences Affected:** `pdfjs.diabled`, `pdfjs.enablePermissions`
4133
4134 #### Windows (GPO)
4135 ```
4136 Software\Policies\Mozilla\Firefox\PDFjs\Enabled = 0x1 | 0x0
4137 Software\Policies\Mozilla\Firefox\PDFjs\EnablePermissions = 0x1 | 0x0
4138 ```
4139 #### Windows (Intune)
4140 OMA-URI:
4141 ```
4142 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~PDFjs/PDFjs_Enabled
4143 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~PDFjs/PDFjs_EnablePermissions
4144 ```
4145 Value (string):
4146 ```
4147 <enabled/>or <disabled/>
4148 ```
4149 #### macOS
4150 ```
4151 <dict>
4152 <key>PDFjs</key>
4153 <dict>
4154 <key>Enabled</key>
4155 <true/> | <false/>
4156 <key>EnablePermissions</key>
4157 <true/> | <false/>
4158 </dict>
4159 </dict>
4160 ```
4161 #### policies.json
4162 ```
4163 {
4164 "policies": {
4165 "PDFjs": {
4166 "Enabled": true | false,
4167 "EnablePermissions": true | false
4168 }
4169 }
4170 }
4171 ```
4172 ### Permissions
4173 Set permissions associated with camera, microphone, location, notifications, autoplay, and virtual reality. Because these are origins, not domains, entries with unique ports must be specified separately. This explicitly means that it is not possible to add wildcards. See examples below.
4174
4175 `Allow` is a list of origins where the feature is allowed.
4176
4177 `Block` is a list of origins where the feature is not allowed.
4178
4179 `BlockNewRequests` determines whether or not new requests can be made for the feature.
4180
4181 `Locked` prevents the user from changing preferences for the feature.
4182
4183 `Default` specifies the default value for Autoplay. block-audio-video is not supported on Firefox ESR 68.
4184
4185 **Compatibility:** Firefox 62, Firefox ESR 60.2 (Autoplay added in Firefox 74, Firefox ESR 68.6, Autoplay Default/Locked added in Firefox 76, Firefox ESR 68.8, VirtualReality added in Firefox 80, Firefox ESR 78.2)\
4186 **CCK2 Equivalent:** N/A\
4187 **Preferences Affected:** `permissions.default.camera`, `permissions.default.microphone`, `permissions.default.geo`, `permissions.default.desktop-notification`, `media.autoplay.default`, `permissions.default.xr`
4188
4189 #### Windows (GPO)
4190 ```
4191 Software\Policies\Mozilla\Firefox\Permissions\Camera\Allow\1 = "https://example.org"
4192 Software\Policies\Mozilla\Firefox\Permissions\Camera\Allow\2 = "https://example.org:1234"
4193 Software\Policies\Mozilla\Firefox\Permissions\Camera\Block\1 = "https://example.edu"
4194 Software\Policies\Mozilla\Firefox\Permissions\Camera\BlockNewRequests = 0x1 | 0x0
4195 Software\Policies\Mozilla\Firefox\Permissions\Camera\Locked = 0x1 | 0x0
4196 Software\Policies\Mozilla\Firefox\Permissions\Microphone\Allow\1 = "https://example.org"
4197 Software\Policies\Mozilla\Firefox\Permissions\Microphone\Block\1 = "https://example.edu"
4198 Software\Policies\Mozilla\Firefox\Permissions\Microphone\BlockNewRequests = 0x1 | 0x0
4199 Software\Policies\Mozilla\Firefox\Permissions\Microphone\Locked = 0x1 | 0x0
4200 Software\Policies\Mozilla\Firefox\Permissions\Location\Allow\1 = "https://example.org"
4201 Software\Policies\Mozilla\Firefox\Permissions\Location\Block\1 = "https://example.edu"
4202 Software\Policies\Mozilla\Firefox\Permissions\Location\BlockNewRequests = 0x1 | 0x0
4203 Software\Policies\Mozilla\Firefox\Permissions\Location\Locked = 0x1 | 0x0
4204 Software\Policies\Mozilla\Firefox\Permissions\Notifications\Allow\1 = "https://example.org"
4205 Software\Policies\Mozilla\Firefox\Permissions\Notifications\Block\1 = "https://example.edu"
4206 Software\Policies\Mozilla\Firefox\Permissions\Notifications\BlockNewRequests = 0x1 | 0x0
4207 Software\Policies\Mozilla\Firefox\Permissions\Notifications\Locked = 0x1 | 0x0
4208 Software\Policies\Mozilla\Firefox\Permissions\Autoplay\Allow\1 = "https://example.org"
4209 Software\Policies\Mozilla\Firefox\Permissions\Autoplay\Block\1 = "https://example.edu"
4210 Software\Policies\Mozilla\Firefox\Permissions\Autoplay\Default = "allow-audio-video" | "block-audio" | "block-audio-video"
4211 Software\Policies\Mozilla\Firefox\Permissions\Autoplay\Locked = 0x1 | 0x0
4212 Software\Policies\Mozilla\Firefox\Permissions\VirtualReality\Allow\1 = "https://example.org"
4213 Software\Policies\Mozilla\Firefox\Permissions\VirtualReality\Block\1 = "https://example.edu"
4214 Software\Policies\Mozilla\Firefox\Permissions\VirtualReality\BlockNewRequests = 0x1 | 0x0
4215 Software\Policies\Mozilla\Firefox\Permissions\VirtualReality\Locked = 0x1 | 0x0
4216 ```
4217 #### Windows (Intune)
4218 OMA-URI:
4219 ```
4220 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Location/Location_BlockNewRequests
4221 ```
4222 Value (string):
4223 ```
4224 <enabled/> or <disabled/>
4225 ```
4226 OMA-URI:
4227 ```
4228 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Location/Location_Locked
4229 ```
4230 Value (string):
4231 ```
4232 <enabled/> or <disabled/>
4233 ```
4234 OMA-URI:
4235 ```
4236 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/Notifications_Allow
4237 ```
4238 Value (string):
4239 ```
4240 <enabled/>
4241 <data id="Permissions" value="1&#xF000;https://example.org"/>
4242 ```
4243 OMA-URI:
4244 ```
4245 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/Notifications_BlockNewRequests
4246 ```
4247 Value (string):
4248 ```
4249 <enabled/> or <disabled/>
4250 ```
4251 OMA-URI:
4252 ```
4253 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/Notifications_Locked
4254 ```
4255 Value (string):
4256 ```
4257 <enabled/> or <disabled/>
4258 ```
4259 OMA-URI:
4260 ```
4261 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Autoplay/Autoplay_Allow
4262 ```
4263 Value (string):
4264 ```
4265 <enabled/>
4266 <data id="Permissions" value="1&#xF000;https://example.org"/>
4267 ```
4268 OMA-URI:
4269 ```
4270 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Autoplay/Autoplay_Block
4271 ```
4272 Value (string):
4273 ```
4274 <enabled/>
4275 <data id="Permissions" value="1&#xF000;https://example.edu"/>
4276 ```
4277 OMA-URI:
4278 ```
4279 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Autoplay/Autoplay_Default
4280 ```
4281 Value (string):
4282 ```
4283 <enabled/>
4284 <data id="Autoplay_Default" value="allow-audio-video | block-audio | block-audio-video"/>
4285 ```
4286 OMA-URI:
4287 ```
4288 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Autoplay/Autoplay_Locked
4289 ```
4290 Value (string):
4291 ```
4292 <enabled/> or <disabled/>
4293 ```
4294 OMA-URI:
4295 ```
4296 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/VirtualReality_Allow
4297 ```
4298 Value (string):
4299 ```
4300 <enabled/>
4301 <data id="Permissions" value="1&#xF000;https://example.org"/>
4302 ```
4303 OMA-URI:
4304 ```
4305 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/VirtualReality_Block
4306 ```
4307 Value (string):
4308 ```
4309 <enabled/>
4310 <data id="Permissions" value="1&#xF000;https://example.edu"/>
4311 ```
4312 OMA-URI:
4313 ```
4314 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/VirtualReality_BlockNewRequests
4315 ```
4316 Value (string):
4317 ```
4318 <enabled/> or <disabled/>
4319 ```
4320 OMA-URI:
4321 ```
4322 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Permissions~Notifications/VirtualReality_Locked
4323 ```
4324 Value (string):
4325 ```
4326 <enabled/> or <disabled/>
4327 ```
4328 #### macOS
4329 ```
4330 <dict>
4331 <key>Permissions</key>
4332 <dict>
4333 <key>Camera</key>
4334 <dict>
4335 <key>Allow</key>
4336 <array>
4337 <string>https://example.org</string>
4338 <string>https://example.org:1234</string>
4339 </array>
4340 <key>Block</key>
4341 <array>
4342 <string>https://example.edu</string>
4343 </array>
4344 <key>BlockNewRequests</key>
4345 <true/> | <false/>
4346 <key>Locked</key>
4347 <true/> | <false/>
4348 </dict>
4349 <key>Microphone</key>
4350 <dict>
4351 <key>Allow</key>
4352 <array>
4353 <string>https://example.org</string>
4354 </array>
4355 <key>Block</key>
4356 <array>
4357 <string>https://example.edu</string>
4358 </array>
4359 <key>BlockNewRequests</key>
4360 <true/> | <false/>
4361 <key>Locked</key>
4362 <true/> | <false/>
4363 </dict>
4364 <key>Location</key>
4365 <dict>
4366 <key>Allow</key>
4367 <array>
4368 <string>https://example.org</string>
4369 </array>
4370 <key>Block</key>
4371 <array>
4372 <string>https://example.edu</string>
4373 </array>
4374 <key>BlockNewRequests</key>
4375 <true/> | <false/>
4376 <key>Locked</key>
4377 <true/> | <false/>
4378 </dict>
4379 <key>Notifications</key>
4380 <dict>
4381 <key>Allow</key>
4382 <array>
4383 <string>https://example.org</string>
4384 </array>
4385 <key>Block</key>
4386 <array>
4387 <string>https://example.edu</string>
4388 </array>
4389 <key>BlockNewRequests</key>
4390 <true/>
4391 <key>Locked</key>
4392 <true/>
4393 </dict>
4394 <key>Autoplay</key>
4395 <dict>
4396 <key>Allow</key>
4397 <array>
4398 <string>https://example.org</string>
4399 </array>
4400 <key>Block</key>
4401 <array>
4402 <string>https://example.edu</string>
4403 </array>
4404 <key>Default</key>
4405 <string>allow-audio-video | block-audio | block-audio-video</string>
4406 <key>Locked</key>
4407 <true/> | <false/>
4408 </dict>
4409 </dict>
4410 </dict>
4411 ```
4412 #### policies.json
4413 ```
4414 {
4415 "policies": {
4416 "Permissions": {
4417 "Camera": {
4418 "Allow": ["https://example.org","https://example.org:1234"],
4419 "Block": ["https://example.edu"],
4420 "BlockNewRequests": true | false,
4421 "Locked": true | false
4422 },
4423 "Microphone": {
4424 "Allow": ["https://example.org"],
4425 "Block": ["https://example.edu"],
4426 "BlockNewRequests": true | false,
4427 "Locked": true | false
4428 },
4429 "Location": {
4430 "Allow": ["https://example.org"],
4431 "Block": ["https://example.edu"],
4432 "BlockNewRequests": true | false,
4433 "Locked": true | false
4434 },
4435 "Notifications": {
4436 "Allow": ["https://example.org"],
4437 "Block": ["https://example.edu"],
4438 "BlockNewRequests": true | false,
4439 "Locked": true | false
4440 },
4441 "Autoplay": {
4442 "Allow": ["https://example.org"],
4443 "Block": ["https://example.edu"],
4444 "Default": "allow-audio-video" | "block-audio" | "block-audio-video",
4445 "Locked": true | false
4446 }
4447 }
4448 }
4449 }
4450 ```
4451 ### PictureInPicture
4452
4453 Enable or disable Picture-in-Picture as well as prevent the user from enabling or disabling it (Locked).
4454
4455 **Compatibility:** Firefox 78, Firefox ESR 78\
4456 **CCK2 Equivalent:** N/A\
4457 **Preferences Affected:** `media.videocontrols.picture-in-picture.video-toggle.enabled`
4458
4459 #### Windows (GPO)
4460 ```
4461 Software\Policies\Mozilla\Firefox\PictureInPicture\Enabled = 0x1 | 0x0
4462 Software\Policies\Mozilla\Firefox\PictureInPicture\Locked = 0x1 | 0x0
4463
4464 ```
4465 #### Windows (Intune)
4466 OMA-URI:
4467 ```
4468 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~PictureInPicture/PictureInPicture_Enabled
4469 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~PictureInPicture/PictureInPicture_Locked
4470 ```
4471 Value (string):
4472 ```
4473 <enabled/> or <disabled/>
4474 ```
4475 #### macOS
4476 ```
4477 <dict>
4478 <key>PictureInPicture</key>
4479 <dict>
4480 <key>Enabled</key>
4481 <true/> | <false/>
4482 <key>Locked</key>
4483 <true/> | <false/>
4484 </dict>
4485 </dict>
4486 ```
4487 #### policies.json
4488 ```
4489 {
4490 "policies": {
4491 "PictureInPicture": {
4492 "Enabled": true | false,
4493 "Locked": true | false
4494 }
4495 }
4496 }
4497 ```
4498 ### PopupBlocking
4499 Configure the default pop-up window policy as well as origins for which pop-up windows are allowed.
4500
4501 `Allow` is a list of origins where popup-windows are allowed.
4502
4503 `Default` determines whether or not pop-up windows are allowed by default.
4504
4505 `Locked` prevents the user from changing pop-up preferences.
4506
4507 **Compatibility:** Firefox 60, Firefox ESR 60\
4508 **CCK2 Equivalent:** `permissions.popup`\
4509 **Preferences Affected:** `dom.disable_open_during_load`
4510
4511 #### Windows (GPO)
4512 ```
4513 Software\Policies\Mozilla\Firefox\PopupBlocking\Allow\1 = "https://example.org"
4514 Software\Policies\Mozilla\Firefox\PopupBlocking\Allow\2 = "https://example.edu"
4515 Software\Policies\Mozilla\Firefox\PopupBlocking\Default = 0x1 | 0x0
4516 Software\Policies\Mozilla\Firefox\PopupBlocking\Locked = 0x1 | 0x0
4517 ```
4518 #### Windows (Intune)
4519 OMA-URI:
4520 ```
4521 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Popups/PopupBlocking_Allow
4522 ```
4523 Value (string):
4524 ```
4525 <enabled/>
4526 <data id="Permissions" value="1&#xF000;https://example.org&#xF000;2&#xF000;https://example.edu"/>
4527 ```
4528 OMA-URI:
4529 ```
4530 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Popups/PopupBlocking_Default
4531 ```
4532 Value (string):
4533 ```
4534 <enabled/> or <disabled/>
4535 ```
4536 OMA-URI:
4537 ```
4538 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Popups/PopupBlocking_Locked
4539 ```
4540 Value (string):
4541 ```
4542 <enabled/> or <disabled/>
4543 ```
4544 #### macOS
4545 ```
4546 <dict>
4547 <key>PopupBlocking</key>
4548 <dict>
4549 <key>Allow</key>
4550 <array>
4551 <string>http://example.org</string>
4552 <string>http://example.edu</string>
4553 </array>
4554 <key>Default</key>
4555 <true/> | <false/>
4556 <key>Locked</key>
4557 <true/> | <false/>
4558 </dict>
4559 </dict>
4560 ```
4561 #### policies.json
4562 ```
4563 {
4564 "policies": {
4565 "PopupBlocking": {
4566 "Allow": ["http://example.org/",
4567 "http://example.edu/"],
4568 "Default": true | false,
4569 "Locked": true | false
4570 }
4571 }
4572 }
4573 ```
4574 ### Preferences
4575 Set and lock preferences.
4576
4577 **NOTE** On Windows, in order to use this policy, you must clear all settings in the old **Preferences (Deprecated)** section in group policy.
4578
4579 Previously you could only set and lock a subset of preferences. Starting with Firefox 81 and Firefox ESR 78.3 you can set many more preferences. You can also set default preferences, user preferences and you can clear preferences.
4580
4581 Preferences that start with the following prefixes are supported:
4582 ```
4583 accessibility.
4584 app.update.* (Firefox 86, Firefox 78.8)
4585 browser.
4586 datareporting.policy.
4587 dom.
4588 extensions.
4589 general.autoScroll (Firefox 83, Firefox ESR 78.5)
4590 general.smoothScroll (Firefox 83, Firefox ESR 78.5)
4591 geo.
4592 gfx.
4593 intl.
4594 keyword.enabled (Firefox 95, Firefox ESR 91.4)
4595 layers.
4596 layout.
4597 media.
4598 network.
4599 pdfjs. (Firefox 84, Firefox ESR 78.6)
4600 places.
4601 pref.
4602 print.
4603 signon. (Firefox 83, Firefox ESR 78.5)
4604 spellchecker. (Firefox 84, Firefox ESR 78.6)
4605 toolkit.legacyUserProfileCustomizations.stylesheets (Firefox 95, Firefox ESR 91.4)
4606 ui.
4607 widget.
4608 xpinstall.signatures.required (Firefox ESR 102.10, Firefox ESR only)
4609 xpinstall.whitelist.required (Firefox 118, Firefox ESR 115.3)
4610 ```
4611 as well as the following security preferences:
4612
4613 | Preference | Type | Default
4614 | --- | --- | --- |
4615 | security.default_personal_cert | string | Ask Every Time
4616 | &nbsp;&nbsp;&nbsp;&nbsp;If set to Select Automatically, Firefox automatically chooses the default personal certificate.
4617 | security.disable_button.openCertManager | string | N/A
4618 | &nbsp;&nbsp;&nbsp;&nbsp;If set to true and locked, the View Certificates button in preferences is disabled (Firefox 121, Firefox ESR 115.6)
4619 | security.disable_button.openDeviceManager | string | N/A
4620 | &nbsp;&nbsp;&nbsp;&nbsp;If set to true and locked, the Security Devices button in preferences is disabled (Firefox 121, Firefox ESR 115.6)
4621 | security.insecure_connection_text.enabled | bool | false
4622 | &nbsp;&nbsp;&nbsp;&nbsp;If set to true, adds the words "Not Secure" for insecure sites.
4623 | security.insecure_connection_text.pbmode.enabled | bool | false
4624 | &nbsp;&nbsp;&nbsp;&nbsp;If set to true, adds the words "Not Secure" for insecure sites in private browsing.
4625 | security.mixed_content.block_active_content | boolean | true
4626 | &nbsp;&nbsp;&nbsp;&nbsp;If false, mixed active content (HTTP and HTTPS) is not blocked.
4627 | security.osclientcerts.autoload | boolean | false
4628 | &nbsp;&nbsp;&nbsp;&nbsp;If true, client certificates are loaded from the operating system certificate store.
4629 | security.OCSP.enabled | integer | 1
4630 | &nbsp;&nbsp;&nbsp;&nbsp;If 0, do not fetch OCSP. If 1, fetch OCSP for DV and EV certificates. If 2, fetch OCSP only for EV certificates.
4631 | security.OCSP.require | boolean | false
4632 | &nbsp;&nbsp;&nbsp;&nbsp; If true, if an OCSP request times out, the connection fails.
4633 | security.osclientcerts.assume_rsa_pss_support | boolean | true
4634 | &nbsp;&nbsp;&nbsp;&nbsp; If false, we don't assume an RSA key can do RSA-PSS. (Firefox 114, Firefox ESR 102.12)
4635 | security.ssl.enable_ocsp_stapling | boolean | true
4636 | &nbsp;&nbsp;&nbsp;&nbsp; If false, OCSP stapling is not enabled.
4637 | security.ssl.errorReporting.enabled | boolean | true
4638 | &nbsp;&nbsp;&nbsp;&nbsp;If false, SSL errors cannot be sent to Mozilla.
4639 | security.ssl.require_safe_negotiation | boolean | false
4640 | &nbsp;&nbsp;&nbsp;&nbsp;If true, Firefox will only negotiate TLS connections with servers that indicate they support secure renegotiation. (Firefox 118, Firefox ESR 115.3)
4641 | security.tls.enable_0rtt_data | boolean | true
4642 | &nbsp;&nbsp;&nbsp;&nbsp;If false, TLS early data is turned off. (Firefox 93, Firefox 91.2, Firefox 78.15)
4643 | security.tls.hello_downgrade_check | boolean | true
4644 | &nbsp;&nbsp;&nbsp;&nbsp;If false, the TLS 1.3 downgrade check is disabled.
4645 | security.tls.version.enable-deprecated | boolean | false
4646 | &nbsp;&nbsp;&nbsp;&nbsp;If true, browser will accept TLS 1.0. and TLS 1.1. (Firefox 86, Firefox 78.8)
4647 | security.warn_submit_secure_to_insecure | boolean | true
4648 | &nbsp;&nbsp;&nbsp;&nbsp;If false, no warning is shown when submitting a form from https to http.
4649
4650 Using the preference as the key, set the `Value` to the corresponding preference value.
4651
4652 `Status` can be "default", "locked", "user" or "clear"
4653
4654 * `"default"`: Read/Write: Settings appear as default even if factory default differs.
4655 * `"locked"`: Read-Only: Settings appear as default even if factory default differs.
4656 * `"user"`: Read/Write: Settings appear as changed if it differs from factory default.
4657 * `"clear"`: Read/Write: `Value` has no effect. Resets to factory defaults on each startup.
4658
4659 `"user"` preferences persist across invocations of Firefox. It is the equivalent of a user setting the preference. They are most useful when a preference is needed very early in startup so it can't be set as default by policy. An example of this is ```toolkit.legacyUserProfileCustomizations.stylesheets```.
4660
4661 `"user"` preferences persist even if the policy is removed, so if you need to remove them, you should use the clear policy.
4662
4663 See the examples below for more detail.
4664
4665 IMPORTANT: Make sure you're only setting a particular preference using this mechanism and not some other way.
4666
4667 Status
4668 **Compatibility:** Firefox 81, Firefox ESR 78.3\
4669 **CCK2 Equivalent:** `preferences`\
4670 **Preferences Affected:** Many
4671
4672 #### Windows (GPO)
4673 Software\Policies\Mozilla\Firefox\Preferences (REG_MULTI_SZ) =
4674 ```
4675 {
4676 "accessibility.force_disabled": {
4677 "Value": 1,
4678 "Status": "default"
4679 },
4680 "browser.cache.disk.parent_directory": {
4681 "Value": "SOME_NATIVE_PATH",
4682 "Status": "user"
4683 },
4684 "browser.tabs.warnOnClose": {
4685 "Value": false,
4686 "Status": "locked"
4687 }
4688 }
4689 ```
4690 #### Windows (Intune)
4691 OMA-URI:
4692 ```
4693 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/Preferences
4694 ```
4695 Value (string):
4696 ```
4697 <enabled/>
4698 <data id="JSON" value='
4699 {
4700 "accessibility.force_disabled": {
4701 "Value": 1,
4702 "Status": "default"
4703 },
4704 "browser.cache.disk.parent_directory": {
4705 "Value": "SOME_NATIVE_PATH",
4706 "Status": "user"
4707 },
4708 "browser.tabs.warnOnClose": {
4709 "Value": false,
4710 "Status": "locked"
4711 }
4712 }'/>
4713 ```
4714 #### macOS
4715 ```
4716 <dict>
4717 <key>Preferences</key>
4718 <dict>
4719 <key>accessibility.force_disabled</key>
4720 <dict>
4721 <key>Value</key>
4722 <integer>1</integer>
4723 <key>Status</key>
4724 <string>default</string>
4725 </dict>
4726 <key>browser.cache.disk.parent_directory</key>
4727 <dict>
4728 <key>Value</key>
4729 <string>SOME_NATIVE_PATH</string>
4730 <key>Status</key>
4731 <string>user</string>
4732 </dict>
4733 <key>browser.tabs.warnOnClose</key>
4734 <dict>
4735 <key>Value</key>
4736 <false/>
4737 <key>Status</key>
4738 <string>locked</string>
4739 </dict>
4740 </dict>
4741 </dict>
4742 ```
4743 #### policies.json
4744 ```
4745 {
4746 "policies": {
4747 "Preferences": {
4748 "accessibility.force_disabled": {
4749 "Value": 1,
4750 "Status": "default"
4751 },
4752 "browser.cache.disk.parent_directory": {
4753 "Value": "SOME_NATIVE_PATH",
4754 "Status": "user"
4755 },
4756 "browser.tabs.warnOnClose": {
4757 "Value": false,
4758 "Status": "locked"
4759 }
4760 }
4761 }
4762 }
4763 ```
4764 ### PrimaryPassword
4765 Require or prevent using a primary (formerly master) password.
4766
4767 If this value is true, a primary password is required. If this value is false, it works the same as if [`DisableMasterPasswordCreation`](#disablemasterpasswordcreation) was true and removes the primary password functionality.
4768
4769 If both DisableMasterPasswordCreation and PrimaryPassword are used, DisableMasterPasswordCreation takes precedent.
4770
4771 **Compatibility:** Firefox 79, Firefox ESR 78.1\
4772 **CCK2 Equivalent:** `noMasterPassword`\
4773 **Preferences Affected:** N/A
4774
4775 #### Windows (GPO)
4776 ```
4777 Software\Policies\Mozilla\Firefox\PrimaryPassword = 0x1 | 0x0
4778 ```
4779 #### Windows (Intune)
4780 OMA-URI:
4781 ```
4782 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/PrimaryPassword
4783 ```
4784 Value (string):
4785 ```
4786 <enabled/> or <disabled/>
4787 ```
4788 #### macOS
4789 ```
4790 <dict>
4791 <key>PrimaryPassword</key>
4792 <true/> | <false/>
4793 </dict>
4794 ```
4795 #### policies.json
4796 ```
4797 {
4798 "policies": {
4799 "PrimaryPassword": true | false
4800 }
4801 }
4802 ```
4803 ### PrintingEnabled
4804 Enable or disable printing.
4805
4806 **Compatibility:** Firefox 120, Firefox ESR 115.5\
4807 **CCK2 Equivalent:** N/A\
4808 **Preferences Affected:** `print.enabled`
4809
4810 #### Windows (GPO)
4811 ```
4812 Software\Policies\Mozilla\Firefox\PrintingEnabled = 0x1 | 0x0
4813 ```
4814 #### Windows (Intune)
4815 OMA-URI:
4816 ```
4817 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/PrintingEnabled
4818 ```
4819 Value (string):
4820 ```
4821 <enabled/> or <disabled/>
4822 ```
4823 #### macOS
4824 ```
4825 <dict>
4826 <key>PrintingEnabled</key>
4827 <true/> | <false/>
4828 </dict>
4829 ```
4830 #### policies.json
4831 ```
4832 {
4833 "policies": {
4834 "PrintingEnabled": true | false
4835 }
4836 }
4837 ```
4838 ### PromptForDownloadLocation
4839 Ask where to save each file before downloading.
4840
4841 **Compatibility:** Firefox 68, Firefox ESR 68\
4842 **CCK2 Equivalent:** N/A\
4843 **Preferences Affected:** `browser.download.useDownloadDir`
4844
4845 #### Windows (GPO)
4846 ```
4847 Software\Policies\Mozilla\Firefox\PromptForDownloadLocation = 0x1 | 0x0
4848 ```
4849 #### Windows (Intune)
4850 OMA-URI:
4851 ```
4852 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/PromptForDownloadLocation
4853 ```
4854 Value (string):
4855 ```
4856 <enabled/> or <disabled/>
4857 ```
4858 #### macOS
4859 ```
4860 <dict>
4861 <key>PromptForDownloadLocation</key>
4862 <true/> | <false/>
4863 </dict>
4864 ```
4865 #### policies.json
4866 ```
4867 {
4868 "policies": {
4869 "PromptForDownloadLocation": true | false
4870 }
4871 }
4872 ```
4873 ### Proxy
4874 Configure proxy settings. These settings correspond to the connection settings in Firefox preferences.
4875 To specify ports, append them to the hostnames with a colon (:).
4876
4877 Unless you lock this policy, changes the user already has in place will take effect.
4878
4879 `Mode` is the proxy method being used.
4880
4881 `Locked` is whether or not proxy settings can be changed.
4882
4883 `HTTPProxy` is the HTTP proxy server.
4884
4885 `UseHTTPProxyForAllProtocols` is whether or not the HTTP proxy should be used for all other proxies.
4886
4887 `SSLProxy` is the SSL proxy server.
4888
4889 `FTPProxy` is the FTP proxy server.
4890
4891 `SOCKSProxy` is the SOCKS proxy server
4892
4893 `SOCKSVersion` is the SOCKS version (4 or 5)
4894
4895 `Passthrough` is list of hostnames or IP addresses that will not be proxied. Use `<local>` to bypass proxying for all hostnames which do not contain periods.
4896
4897 `AutoConfigURL` is a URL for proxy configuration (only used if Mode is autoConfig).
4898
4899 `AutoLogin` means do not prompt for authentication if password is saved.
4900
4901 `UseProxyForDNS` to use proxy DNS when using SOCKS v5.
4902
4903 **Compatibility:** Firefox 60, Firefox ESR 60\
4904 **CCK2 Equivalent:** `networkProxy*`\
4905 **Preferences Affected:** `network.proxy.type`, `network.proxy.autoconfig_url`, `network.proxy.socks_remote_dns`, `signon.autologin.proxy`, `network.proxy.socks_version`, `network.proxy.no_proxies_on`, `network.proxy.share_proxy_settings`, `network.proxy.http`, `network.proxy.http_port`, `network.proxy.ftp`, `network.proxy.ftp_port`, `network.proxy.ssl`, `network.proxy.ssl_port`, `network.proxy.socks`, `network.proxy.socks_port`
4906
4907 #### Windows (GPO)
4908 ```
4909 Software\Policies\Mozilla\Firefox\Proxy\Mode = "none" | "system" | "manual" | "autoDetect" | "autoConfig"
4910 Software\Policies\Mozilla\Firefox\Proxy\Locked = 0x1 | 0x0
4911 Software\Policies\Mozilla\Firefox\Proxy\HTTPProxy = https://httpproxy.example.com
4912 Software\Policies\Mozilla\Firefox\Proxy\UseHTTPProxyForAllProtocols = 0x1 | 0x0
4913 Software\Policies\Mozilla\Firefox\Proxy\SSLProxy = https://sslproxy.example.com
4914 Software\Policies\Mozilla\Firefox\Proxy\FTPProxy = https://ftpproxy.example.com
4915 Software\Policies\Mozilla\Firefox\Proxy\SOCKSProxy = https://socksproxy.example.com
4916 Software\Policies\Mozilla\Firefox\Proxy\SOCKSVersion = 0x4 | 0x5
4917 Software\Policies\Mozilla\Firefox\Proxy\Passthrough = <local>
4918 Software\Policies\Mozilla\Firefox\Proxy\AutoConfigURL = URL_TO_AUTOCONFIG
4919 Software\Policies\Mozilla\Firefox\Proxy\AutoLogin = 0x1 | 0x0
4920 Software\Policies\Mozilla\Firefox\Proxy\UseProxyForDNS = 0x1 | 0x0
4921 ```
4922 #### Windows (Intune)
4923 **Note**
4924 These setttings were moved to a category to make them easier to configure via Intune.
4925
4926 OMA-URI:
4927 ```
4928 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_Locked
4929 ```
4930 Value (string):
4931 ```
4932 <enabled/> or <disabled/>
4933 ```
4934 OMA-URI:
4935 ```
4936 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_ConnectionType
4937 ```
4938 Value (string):
4939 ```
4940 <enabled/>
4941 <data id="Proxy_ConnectionType" value="none | system | manual | autoDetect | autoConfig"/>
4942 ```
4943 OMA-URI:
4944 ```
4945 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_HTTPProxy
4946 ```
4947 Value (string):
4948 ```
4949 <enabled/>
4950 <data id="Proxy_HTTPProxy" value="httpproxy.example.com"/>
4951 ```
4952 OMA-URI:
4953 ```
4954 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_UseHTTPProxyForAllProtocols
4955 ```
4956 Value (string):
4957 ```
4958 <enabled/> or <disabled/>
4959 ```
4960 OMA-URI:
4961 ```
4962 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_SSLProxy
4963 ```
4964 Value (string):
4965 ```
4966 <enabled/>
4967 <data id="Proxy_SSLProxy" value="sslproxy.example.com"/>
4968 ```
4969 OMA-URI:
4970 ```
4971 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_SOCKSProxy
4972 ```
4973 Value (string):
4974 ```
4975 <enabled/>
4976 <data id="Proxy_SOCKSProxy" value="socksproxy.example.com"/>
4977 <data id="Proxy_SOCKSVersion" value="4 | 5"/>
4978 ```
4979 OMA-URI:
4980 ```
4981 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_AutoConfigURL
4982 ```
4983 Value (string):
4984 ```
4985 <enabled/>
4986 <data id="Proxy_AutoConfigURL" value="URL_TO_AUTOCONFIG"/>
4987 ```
4988 OMA-URI:
4989 ```
4990 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_Passthrough
4991 ```
4992 Value (string):
4993 ```
4994 <enabled/>
4995 <data id="Proxy_Passthrough" value="&lt;local&gt;"/>
4996 ```
4997 OMA-URI:
4998 ```
4999 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_AutoLogin
5000 ```
5001 Value (string):
5002 ```
5003 <enabled/> or <disabled/>
5004 ```
5005 OMA-URI:
5006 ```
5007 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~ProxySettings/Proxy_UseProxyForDNS
5008 ```
5009 Value (string):
5010 ```
5011 <enabled/> or <disabled/>
5012 ```
5013 OMA-URI (Old way):
5014 ```
5015 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/Proxy
5016 ```
5017 Value (string):
5018 ```
5019 <enabled/>
5020 <data id="ProxyLocked" value="true | false"/>
5021 <data id="ConnectionType" value="none | system | manual | autoDetect | autoConfig"/>
5022 <data id="HTTPProxy" value="httpproxy.example.com"/>
5023 <data id="UseHTTPProxyForAllProtocols" value="true | false"/>
5024 <data id="SSLProxy" value="sslproxy.example.com"/>
5025 <data id="FTPProxy" value="ftpproxy.example.com"/>
5026 <data id="SOCKSProxy" value="socksproxy.example.com"/>
5027 <data id="SOCKSVersion" value="4 | 5"/>
5028 <data id="AutoConfigURL" value="URL_TO_AUTOCONFIG"/>
5029 <data id="Passthrough" value="<local>"/>
5030 <data id="AutoLogin" value="true | false"/>
5031 <data id="UseProxyForDNS" value="true | false"/>
5032 ```
5033 #### macOS
5034 ```
5035 <dict>
5036 <key>Proxy</key>
5037 <dict>
5038 <key>Mode</key>
5039 <string>none | system | manual | autoDetect | autoConfig</string>
5040 <key>Locked</key>
5041 <true> | </false>
5042 <key>HTTPProxy</key>
5043 <string>https://httpproxy.example.com</string>
5044 <key>UseHTTPProxyForAllProtocols</key>
5045 <true> | </false>
5046 <key>SSLProxy</key>
5047 <string>https://sslproxy.example.com</string>
5048 <key>FTPProxy</key>
5049 <string>https://ftpproxy.example.com</string>
5050 <key>SOCKSProxy</key>
5051 <string>https://socksproxy.example.com</string>
5052 <key>SOCKSVersion</key>
5053 <string>4 | 5</string>
5054 <key>Passthrough</key>
5055 <string>&lt;local>&gt;</string>
5056 <key>AutoConfigURL</key>
5057 <string>URL_TO_AUTOCONFIG</string>
5058 <key>AutoLogin</key>
5059 <true> | </false>
5060 <key>UseProxyForDNS</key>
5061 <true> | </false>
5062 </dict>
5063 </dict>
5064 ```
5065 #### policies.json
5066 ```
5067 {
5068 "policies": {
5069 "Proxy": {
5070 "Mode": "none" | "system" | "manual" | "autoDetect" | "autoConfig",
5071 "Locked": true | false,
5072 "HTTPProxy": "hostname",
5073 "UseHTTPProxyForAllProtocols": true | false,
5074 "SSLProxy": "hostname",
5075 "FTPProxy": "hostname",
5076 "SOCKSProxy": "hostname",
5077 "SOCKSVersion": 4 | 5,
5078 "Passthrough": "<local>",
5079 "AutoConfigURL": "URL_TO_AUTOCONFIG",
5080 "AutoLogin": true | false,
5081 "UseProxyForDNS": true | false
5082 }
5083 }
5084 }
5085 ```
5086 ### RequestedLocales
5087 Set the the list of requested locales for the application in order of preference. It will cause the corresponding language pack to become active.
5088
5089 Note: For Firefox 68, this can now be a string so that you can specify an empty value.
5090
5091 **Compatibility:** Firefox 64, Firefox ESR 60.4, Updated in Firefox 68, Firefox ESR 68\
5092 **CCK2 Equivalent:** N/A\
5093 **Preferences Affected:** N/A
5094 #### Windows (GPO)
5095 ```
5096 Software\Policies\Mozilla\Firefox\RequestedLocales\1 = "de"
5097 Software\Policies\Mozilla\Firefox\RequestedLocales\2 = "en-US"
5098
5099 or
5100
5101 Software\Policies\Mozilla\Firefox\RequestedLocales = "de,en-US"
5102 ```
5103 #### Windows (Intune)
5104 OMA-URI:
5105 ```
5106 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/RequestedLocalesString
5107 ```
5108 Value (string):
5109 ```
5110 <enabled/>
5111 <data id="Preferences_String" value="de,en-US"/>
5112 ```
5113 #### macOS
5114 ```
5115 <dict>
5116 <key>RequestedLocales</key>
5117 <array>
5118 <string>de</string>
5119 <string>en-US</string>
5120 </array>
5121 </dict>
5122
5123 or
5124
5125 <dict>
5126 <key>RequestedLocales</key>
5127 <string>de,en-US</string>
5128 </dict>
5129
5130 ```
5131 #### policies.json
5132 ```
5133 {
5134 "policies": {
5135 "RequestedLocales": ["de", "en-US"]
5136 }
5137 }
5138
5139 or
5140
5141 {
5142 "policies": {
5143 "RequestedLocales": "de,en-US"
5144 }
5145 }
5146 ```
5147 <a name="SanitizeOnShutdown"></a>
5148
5149 ### SanitizeOnShutdown (Selective)
5150 Clear data on shutdown. Choose from Cache, Cookies, Download History, Form & Search History, Browsing History, Active Logins, Site Preferences and Offline Website Data.
5151
5152 Previously, these values were always locked. Starting with Firefox 74 and Firefox ESR 68.6, you can use the `Locked` option to either keep the values unlocked (set it to false), or lock only the values you set (set it to true). If you want the old behavior of locking everything, do not set `Locked` at all.
5153
5154 **Compatibility:** Firefox 68, Firefox ESR 68 (Locked added in 74/68.6)\
5155 **CCK2 Equivalent:** N/A\
5156 **Preferences Affected:** `privacy.sanitize.sanitizeOnShutdown`, `privacy.clearOnShutdown.cache`, `privacy.clearOnShutdown.cookies`, `privacy.clearOnShutdown.downloads`, `privacy.clearOnShutdown.formdata`, `privacy.clearOnShutdown.history`, `privacy.clearOnShutdown.sessions`, `privacy.clearOnShutdown.siteSettings`, `privacy.clearOnShutdown.offlineApps`
5157 #### Windows (GPO)
5158 ```
5159 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\Cache = 0x1 | 0x0
5160 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\Cookies = 0x1 | 0x0
5161 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\Downloads = 0x1 | 0x0
5162 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\FormData = 0x1 | 0x0
5163 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\History = 0x1 | 0x0
5164 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\Sessions = 0x1 | 0x0
5165 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\SiteSettings = 0x1 | 0x0
5166 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\OfflineApps = 0x1 | 0x0
5167 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown\Locked = 0x1 | 0x0
5168 ```
5169 #### Windows (Intune)
5170 OMA-URI:
5171 ```
5172 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/A_SanitizeOnShutdown_Cache
5173 ```
5174 Value (string):
5175 ```
5176 <enabled/> or <disabled/>
5177 ```
5178 OMA-URI:
5179 ```
5180 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/B_SanitizeOnShutdown_Cookies
5181 ```
5182 Value (string):
5183 ```
5184 <enabled/> or <disabled/>
5185 ```
5186 OMA-URI:
5187 ```
5188 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/C_SanitizeOnShutdown_Downloads
5189 ```
5190 Value (string):
5191 ```
5192 <enabled/> or <disabled/>
5193 ```
5194 OMA-URI:
5195 ```
5196 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/D_SanitizeOnShutdown_FormData
5197 ```
5198 Value (string):
5199 ```
5200 <enabled/> or <disabled/>
5201 ```
5202 OMA-URI:
5203 ```
5204 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/E_SanitizeOnShutdown_History
5205 ```
5206 Value (string):
5207 ```
5208 <enabled/> or <disabled/>
5209 ```
5210 OMA-URI:
5211 ```
5212 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/F_SanitizeOnShutdown_Sessions
5213 ```
5214 Value (string):
5215 ```
5216 <enabled/> or <disabled/>
5217 ```
5218 OMA-URI:
5219 ```
5220 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/G_SanitizeOnShutdown_SiteSettings
5221 ```
5222 Value (string):
5223 ```
5224 <enabled/> or <disabled/>
5225 ```
5226 OMA-URI:
5227 ```
5228 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/H_SanitizeOnShutdown_OfflineApps
5229 ```
5230 Value (string):
5231 ```
5232 <enabled/> or <disabled/>
5233 ```
5234 OMA-URI:
5235 ```
5236 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~SanitizeOnShutdown/I_SanitizeOnShutdown_Locked
5237 ```
5238 Value (string):
5239 ```
5240 <enabled/> or <disabled/>
5241 ```
5242 #### macOS
5243 ```
5244 <dict>
5245 <key>SanitizeOnShutdown</key>
5246 <dict>
5247 <key>Cache</key>
5248 <true/> | <false/>
5249 <key>Cookies</key>
5250 <true/> | <false/>
5251 <key>Downloads</key>
5252 <true/> | <false/>
5253 <key>FormData</key>
5254 <true/> | <false/>
5255 <key>History</key>
5256 <true/> | <false/>
5257 <key>Sessions</key>
5258 <true/> | <false/>
5259 <key>SiteSettings</key>
5260 <true/> | <false/>
5261 <key>OfflineApps</key>
5262 <true/> | <false/>
5263 <key>Locked</key>
5264 <true/> | <false/>
5265 </dict>
5266 </dict>
5267 ```
5268 #### policies.json
5269 ```
5270 {
5271 "policies": {
5272 "SanitizeOnShutdown": {
5273 "Cache": true | false,
5274 "Cookies": true | false,
5275 "Downloads": true | false,
5276 "FormData": true | false,
5277 "History": true | false,
5278 "Sessions": true | false,
5279 "SiteSettings": true | false,
5280 "OfflineApps": true | false,
5281 "Locked": true | false
5282 }
5283 }
5284 }
5285 ```
5286 ### SanitizeOnShutdown (All)
5287 Clear all data on shutdown, including Browsing & Download History, Cookies, Active Logins, Cache, Form & Search History, Site Preferences and Offline Website Data.
5288
5289 **Compatibility:** Firefox 60, Firefox ESR 60\
5290 **CCK2 Equivalent:** N/A\
5291 **Preferences Affected:** `privacy.sanitize.sanitizeOnShutdown`, `privacy.clearOnShutdown.cache`, `privacy.clearOnShutdown.cookies`, `privacy.clearOnShutdown.downloads`, `privacy.clearOnShutdown.formdata`, `privacy.clearOnShutdown.history`, `privacy.clearOnShutdown.sessions`, `privacy.clearOnShutdown.siteSettings`, `privacy.clearOnShutdown.offlineApps`
5292 #### Windows (GPO)
5293 ```
5294 Software\Policies\Mozilla\Firefox\SanitizeOnShutdown = 0x1 | 0x0
5295 ```
5296 #### Windows (Intune)
5297 OMA-URI:
5298 ```
5299 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/C_SanitizeOnShutdown
5300 ```
5301 Value (string):
5302 ```
5303 <enabled/> or <disabled/>
5304 ```
5305 #### macOS
5306 ```
5307 <dict>
5308 <key>SanitizeOnShutdown</key>
5309 <true/> | <false/>
5310 </dict>
5311 ```
5312 #### policies.json
5313 ```
5314 {
5315 "policies": {
5316 "SanitizeOnShutdown": true | false
5317 }
5318 }
5319 ```
5320 ### SearchBar
5321 Set whether or not search bar is displayed.
5322
5323 **Compatibility:** Firefox 60, Firefox ESR 60\
5324 **CCK2 Equivalent:** `showSearchBar`\
5325 **Preferences Affected:** N/A
5326
5327 #### Windows (GPO)
5328 ```
5329 Software\Policies\Mozilla\Firefox\SearchBar = "unified" | "separate"
5330 ```
5331
5332 #### Windows (Intune)
5333 OMA-URI:
5334 ```
5335 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SearchBar
5336 ```
5337 Value (string):
5338 ```
5339 <enabled/>
5340 <data id="SearchBar" value="unified | separate"/>
5341 ```
5342 #### macOS
5343 ```
5344 <dict>
5345 <key>SearchBar</key>
5346 <string>unified | separate</string>
5347 </dict>
5348 ```
5349 #### policies.json
5350 ```
5351 {
5352 "policies": {
5353 "SearchBar": "unified" | "separate"
5354 }
5355 }
5356 ```
5357 <a name="SearchEngines"></a>
5358
5359 ### SearchEngines (This policy is only available on the ESR.)
5360
5361 ### SearchEngines | Add
5362
5363 Add new search engines. Although there are only five engines available in the ADMX template, there is no limit. To add more in the ADMX template, you can duplicate the XML.
5364
5365 This policy is only available on the ESR. `Name` and `URLTemplate` are required.
5366
5367 `Name` is the name of the search engine.
5368
5369 `URLTemplate` is the search URL with {searchTerms} to substitute for the search term.
5370
5371 `Method` is either GET or POST
5372
5373 `IconURL` is a URL for the icon to use.
5374
5375 `Alias` is a keyword to use for the engine.
5376
5377 `Description` is a description of the search engine.
5378
5379 `PostData` is the POST data as name value pairs separated by &.
5380
5381 `SuggestURLTemplate` is a search suggestions URL with {searchTerms} to substitute for the search term.
5382
5383 `Encoding` is the query charset for the engine. It defaults to UTF-8.
5384
5385 **Compatibility:** Firefox ESR 60 (POST support in Firefox ESR 68, Encoding support in Firefox 91)\
5386 **CCK2 Equivalent:** `searchplugins`\
5387 **Preferences Affected:** N/A
5388
5389 #### Windows (GPO)
5390 ```
5391 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\Name = "Example1"
5392 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\URLTemplate = "https://www.example.org/q={searchTerms}"
5393 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\Method = "GET" | "POST"
5394 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\IconURL = "https://www.example.org/favicon.ico"
5395 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\Alias = "example"
5396 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\Description = "Example Description"
5397 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\SuggestURLTemplate = "https://www.example.org/suggestions/q={searchTerms}"
5398 Software\Policies\Mozilla\Firefox\SearchEngines\Add\1\PostData = "name=value&q={searchTerms}"
5399 ```
5400 #### Windows (Intune)
5401 OMA-URI:
5402 ```
5403 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Search/SearchEngines_1
5404 ```
5405 Value (string):
5406 ```
5407 <enabled/>
5408 <data id="SearchEngine_Name" value="Example1"/>
5409 <data id="SearchEngine_URLTemplate" value="https://www.example.org/q={searchTerms"/>
5410 <data id="SearchEngine_Method" value="GET | POST"/>
5411 <data id="SearchEngine_IconURL" value="https://www.example.org/favicon.ico"/>
5412 <data id="SearchEngine_Alias" value="example"/>
5413 <data id="SearchEngine_Description" value="Example Description"/>
5414 <data id="SearchEngine_SuggestURLTemplate" value="https://www.example.org/suggestions/q={searchTerms}"/>
5415 <data id="SearchEngine_PostData" value="name=value&amp;q={searchTerms}"/>
5416 ```
5417 #### macOS
5418 ```
5419 <dict>
5420 <key>SearchEngines</key>
5421 <dict>
5422 <key>Add</key>
5423 <array>
5424 <dict>
5425 <key>Name</key>
5426 <string>Example1</string>
5427 <key>URLTemplate</key>
5428 <string>https://www.example.org/q={searchTerms}</string>
5429 <key>Method</key>
5430 <string>GET | POST </string>
5431 <key>IconURL</key>
5432 <string>https://www.example.org/favicon.ico</string>
5433 <key>Alias</key>
5434 <string>example</string>
5435 <key>Description</key>
5436 <string>Example Description</string>
5437 <key>SuggestURLTemplate</key>
5438 <string>https://www.example.org/suggestions/q={searchTerms}</string>
5439 <key>PostData</key>
5440 <string>name=value&q={searchTerms}</string>
5441 </dict>
5442 <array>
5443 </dict>
5444 </dict>
5445 ```
5446 #### policies.json
5447 ```
5448 {
5449 "policies": {
5450 "SearchEngines": {
5451 "Add": [
5452 {
5453 "Name": "Example1",
5454 "URLTemplate": "https://www.example.org/q={searchTerms}",
5455 "Method": "GET" | "POST",
5456 "IconURL": "https://www.example.org/favicon.ico",
5457 "Alias": "example",
5458 "Description": "Description",
5459 "PostData": "name=value&q={searchTerms}",
5460 "SuggestURLTemplate": "https://www.example.org/suggestions/q={searchTerms}"
5461 }
5462 ]
5463 }
5464 }
5465 }
5466 ```
5467 ### SearchEngines | Default
5468
5469 Set the default search engine. This policy is only available on the ESR.
5470
5471 **Compatibility:** Firefox ESR 60\
5472 **CCK2 Equivalent:** `defaultSearchEngine`\
5473 **Preferences Affected:** N/A
5474
5475 #### Windows (GPO)
5476 ```
5477 Software\Policies\Mozilla\Firefox\SearchEngines\Default = NAME_OF_SEARCH_ENGINE
5478 ```
5479 #### Windows (Intune)
5480 OMA-URI:
5481 ```
5482 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Search/SearchEngines_Default
5483 ```
5484 Value (string):
5485 ```
5486 <enabled/>
5487 <data id="SearchEngines_Default" value="NAME_OF_SEARCH_ENGINE"/>
5488 ```
5489 #### macOS
5490 ```
5491 <dict>
5492 <key>SearchEngines</key>
5493 <dict>
5494 <key>Default</key>
5495 <string>NAME_OF_SEARCH_ENGINE</string>
5496 </dict>
5497 </dict>
5498 ```
5499 #### policies.json
5500 ```
5501 {
5502 "policies": {
5503 "SearchEngines": {
5504 "Default": "NAME_OF_SEARCH_ENGINE"
5505 }
5506 }
5507 }
5508 ```
5509 ### SearchEngines | PreventInstalls
5510
5511 Prevent installing search engines from webpages.
5512
5513 **Compatibility:** Firefox ESR 60\
5514 **CCK2 Equivalent:** `disableSearchEngineInstall`\
5515 **Preferences Affected:** N/A
5516
5517 #### Windows (GPO)
5518 ```
5519 Software\Policies\Mozilla\Firefox\SearchEngines\PreventInstalls = 0x1 | 0x0
5520 ```
5521 #### Windows (Intune)
5522 OMA-URI:
5523 ```
5524 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Search/SearchEngines_PreventInstalls
5525 ```
5526 Value (string):
5527 ```
5528 <enabled/> or <disabled/>
5529 ```
5530 #### macOS
5531 ```
5532 <dict>
5533 <key>SearchEngines</key>
5534 <dict>
5535 <key>PreventInstalls</key>
5536 <true/> | <false/>
5537 </dict>
5538 </dict>
5539 ```
5540 #### policies.json
5541 ```
5542 {
5543 "policies": {
5544 "SearchEngines": {
5545 "PreventInstalls": true | false
5546 }
5547 }
5548 }
5549 ```
5550 ### SearchEngines | Remove
5551
5552 Hide built-in search engines. This policy is only available on the ESR.
5553
5554 **Compatibility:** Firefox ESR 60.2\
5555 **CCK2 Equivalent:** `removeDefaultSearchEngines` (removed all built-in engines)\
5556 **Preferences Affected:** N/A
5557
5558 #### Windows (GPO)
5559 ```
5560 Software\Policies\Mozilla\Firefox\SearchEngines\Remove\1 = NAME_OF_SEARCH_ENGINE
5561 ```
5562 #### Windows (Intune)
5563 OMA-URI:
5564 ```
5565 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Search/SearchEngines_Remove
5566 ```
5567 Value (string):
5568 ```
5569 <enabled/>
5570 <data id="SearchEngines_Remove" value="1&#xF000;NAME_OF_SEARCH_ENGINE"/>
5571 ```
5572 #### macOS
5573 ```
5574 <dict>
5575 <key>SearchEngines</key>
5576 <dict>
5577 <key>Remove</key>
5578 <array>
5579 <string>NAME_OF_SEARCH_ENGINE</string>
5580 </array>
5581 </dict>
5582 </dict>
5583 ```
5584 #### policies.json
5585 ```
5586 {
5587 "policies": {
5588 "SearchEngines": {
5589 "Remove": ["NAME_OF_SEARCH_ENGINE"]
5590 }
5591 }
5592 }
5593 ```
5594 ### SearchSuggestEnabled
5595
5596 Enable search suggestions.
5597
5598 **Compatibility:** Firefox 68, Firefox ESR 68\
5599 **CCK2 Equivalent:** N/A\
5600 **Preferences Affected:** `browser.urlbar.suggest.searches`, `browser.search.suggest.enabled`
5601
5602 #### Windows (GPO)
5603 ```
5604 Software\Policies\Mozilla\Firefox\SearchSuggestEnabled = 0x1 | 0x0
5605 ```
5606 #### Windows (Intune)
5607 OMA-URI:
5608 ```
5609 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Search/SearchSuggestEnabled
5610 ```
5611 Value (string):
5612 ```
5613 <enabled/> or <disabled/>
5614 ```
5615 #### macOS
5616 ```
5617 <dict>
5618 <key>SearchSuggestEnabled</key>
5619 <true/> | <false/>
5620 </dict>
5621 ```
5622 #### policies.json
5623 ```
5624 {
5625 "policies": {
5626 "SearchSuggestEnabled": true | false
5627 }
5628 }
5629 ```
5630 ### SecurityDevices
5631
5632 Add or delete PKCS #11 modules.
5633
5634 **Compatibility:** Firefox 114, Firefox ESR 112.12\
5635 **CCK2 Equivalent:** N/A\
5636 **Preferences Affected:** N/A
5637
5638 #### Windows (GPO)
5639 ```
5640 Software\Policies\Mozilla\Firefox\SecurityDevices\Add\NAME_OF_DEVICE_TO_ADD = PATH_TO_LIBRARY_FOR_DEVICE
5641 Software\Policies\Mozilla\Firefox\SecurityDevices\Remove\1 = NAME_OF_DEVICE_TO_REMOVE
5642 ```
5643 #### Windows (Intune)
5644 OMA-URI:
5645 ```
5646 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SecurityDevices/SecurityDevices_Add
5647 ```
5648 Value (string):
5649 ```
5650 <enabled/>
5651 <data id="SecurityDevices" value="NAME_OF_DEVICE_TO_ADD&#xF000;PATH_TO_LIBRARY_FOR_DEVICE"/>
5652 ```
5653 OMA-URI:
5654 ```
5655 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SecurityDevices/SecurityDevices_Delete
5656 ```
5657 Value (string):
5658 ```
5659 <enabled/>
5660 <data id="SecurityDevices" value="1&#xF000;NAME_OF_DEVICE_TO_REMOVE"/>
5661 ```
5662 #### macOS
5663 ```
5664 <dict>
5665 <key>SecurityDevices</key>
5666 <dict>
5667 <key>Add<key>
5668 <dict>
5669 <key>NAME_OF_DEVICE_TO_ADD</key>
5670 <string>PATH_TO_LIBRARY_FOR_DEVICE</string>
5671 </dict>
5672 <key>Delete</add>
5673 <array>
5674 <string>NAME_OF_DEVICE_TO_DELETE</string>
5675 </array>
5676 </dict>
5677 </dict>
5678 ```
5679 #### policies.json
5680 ```
5681 {
5682 "policies": {
5683 "SecurityDevices": {
5684 "Add": {
5685 "NAME_OF_DEVICE_TO_ADD": "PATH_TO_LIBRARY_FOR_DEVICE"
5686 },
5687 "Delete": ["NAME_OF_DEVICE_TO_DELETE"]
5688 }
5689 }
5690 }
5691 ```
5692 ### SecurityDevices (Deprecated)
5693
5694 Install PKCS #11 modules.
5695
5696 **Compatibility:** Firefox 64, Firefox ESR 60.4\
5697 **CCK2 Equivalent:** `certs.devices`\
5698 **Preferences Affected:** N/A
5699
5700 #### Windows (GPO)
5701 ```
5702 Software\Policies\Mozilla\Firefox\SecurityDevices\NAME_OF_DEVICE = PATH_TO_LIBRARY_FOR_DEVICE
5703 ```
5704 #### Windows (Intune)
5705 OMA-URI:
5706 ```
5707 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SecurityDevices
5708 ```
5709 Value (string):
5710 ```
5711 <enabled/>
5712 <data id="SecurityDevices" value="NAME_OF_DEVICE&#xF000;PATH_TO_LIBRARY_FOR_DEVICE"/>
5713 ```
5714 #### macOS
5715 ```
5716 <dict>
5717 <key>SecurityDevices</key>
5718 <dict>
5719 <key>NAME_OF_DEVICE</key>
5720 <string>PATH_TO_LIBRARY_FOR_DEVICE</string>
5721 </dict>
5722 </dict>
5723 ```
5724 #### policies.json
5725 ```
5726 {
5727 "policies": {
5728 "SecurityDevices": {
5729 "NAME_OF_DEVICE": "PATH_TO_LIBRARY_FOR_DEVICE"
5730 }
5731 }
5732 }
5733 ```
5734 ### ShowHomeButton
5735 Show the home button on the toolbar.
5736
5737 Future versions of Firefox will not show the home button by default.
5738
5739 **Compatibility:** Firefox 88, Firefox ESR 78.10\
5740 **CCK2 Equivalent:** N/A\
5741 **Preferences Affected:** N/A
5742
5743 #### Windows (GPO)
5744 ```
5745 Software\Policies\Mozilla\Firefox\ShowHomeButton = 0x1 | 0x0
5746 ```
5747 #### Windows (Intune)
5748 OMA-URI:
5749 ```
5750 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~Homepage/Homepage_ShowHomeButton
5751 ```
5752 Value (string):
5753 ```
5754 <enabled/> or <disabled/>
5755 ```
5756 #### macOS
5757 ```
5758 <dict>
5759 <key>ShowHomeButton</key>
5760 <true/> | <false/>
5761 </dict>
5762 ```
5763 #### policies.json
5764 ```
5765 {
5766 "policies": {
5767 "ShowHomeButton": true | false
5768 }
5769 }
5770 ```
5771 ### SSLVersionMax
5772
5773 Set and lock the maximum version of TLS. (Firefox defaults to a maximum of TLS 1.3.)
5774
5775 **Compatibility:** Firefox 66, Firefox ESR 60.6\
5776 **CCK2 Equivalent:** N/A\
5777 **Preferences Affected:** `security.tls.version.max`
5778
5779 #### Windows (GPO)
5780 ```
5781 Software\Policies\Mozilla\Firefox\SSLVersionMax = "tls1" | "tls1.1" | "tls1.2" | "tls1.3"
5782 ```
5783 #### Windows (Intune)
5784 OMA-URI:
5785 ```
5786 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SSLVersionMax
5787 ```
5788 Value (string):
5789 ```
5790 <enabled/>
5791 <data id="SSLVersion" value="tls1 | tls1.2 | tls1.3"/>
5792 ```
5793 #### macOS
5794 ```
5795 <dict>
5796 <key>SSLVersionMax</key>
5797 <string>tls1 | tls1.1 | tls1.2 | tls1.3</string>
5798 </dict>
5799 ```
5800
5801 #### policies.json
5802 ```
5803 {
5804 "policies": {
5805 "SSLVersionMax": "tls1" | "tls1.1" | "tls1.2" | "tls1.3"
5806 }
5807 }
5808 ```
5809 ### SSLVersionMin
5810
5811 Set and lock the minimum version of TLS. (Firefox defaults to a minimum of TLS 1.2.)
5812
5813 **Compatibility:** Firefox 66, Firefox ESR 60.6\
5814 **CCK2 Equivalent:** N/A\
5815 **Preferences Affected:** `security.tls.version.min`
5816
5817 #### Windows (GPO)
5818 ```
5819 Software\Policies\Mozilla\Firefox\SSLVersionMin = "tls1" | "tls1.1" | "tls1.2" | "tls1.3"
5820 ```
5821 #### Windows (Intune)
5822 OMA-URI:
5823 ```
5824 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SSLVersionMin
5825 ```
5826 Value (string):
5827 ```
5828 <enabled/>
5829 <data id="SSLVersion" value="tls1 | tls1.2 | tls1.3"/>
5830 ```
5831 #### macOS
5832 ```
5833 <dict>
5834 <key>SSLVersionMin</key>
5835 <string>tls1 | tls1.1 | tls1.2 | tls1.3</string>
5836 </dict>
5837 ```
5838
5839 #### policies.json
5840 ```
5841 {
5842 "policies": {
5843 "SSLVersionMin": "tls1" | "tls1.1" | "tls1.2" | "tls1.3"
5844 }
5845 }
5846 ```
5847 ### SupportMenu
5848 Add a menuitem to the help menu for specifying support information.
5849
5850 **Compatibility:** Firefox 68.0.1, Firefox ESR 68.0.1\
5851 **CCK2 Equivalent:** helpMenu\
5852 **Preferences Affected:** N/A
5853
5854 #### Windows (GPO)
5855 ```
5856 Software\Policies\Mozilla\Firefox\SupportMenu\Title = "Support Menu"
5857 Software\Policies\Mozilla\Firefox\SupportMenu\URL = "http://example.com/support"
5858 Software\Policies\Mozilla\Firefox\SupportMenu\AccessKey = "S"
5859 ```
5860 #### Windows (Intune)
5861 OMA-URI:
5862 ```
5863 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/SupportMenu
5864 ```
5865 Value (string):
5866 ```
5867 <enabled/>
5868 <data id="SupportMenuTitle" value="Support Menu"/>
5869 <data id="SupportMenuURL" value="http://example.com/support"/>
5870 <data id="SupportMenuAccessKey" value="S"/>
5871 ```
5872 #### macOS
5873 ```
5874 <dict>
5875 <key>SupportMenu</key>
5876 <dict>
5877 <key>Title</key>
5878 <string>SupportMenu</string>
5879 <key>URL</key>
5880 <string>http://example.com/support</string>
5881 <key>AccessKey</key>
5882 <string>S</string>
5883 </dict>
5884 </dict>
5885 ```
5886 #### policies.json
5887 ```
5888 {
5889 "policies": {
5890 "SupportMenu": {
5891 "Title": "Support Menu",
5892 "URL": "http://example.com/support",
5893 "AccessKey": "S"
5894 }
5895 }
5896 }
5897 ```
5898 ### StartDownloadsInTempDirectory
5899 Force downloads to start off in a local, temporary location rather than the default download directory.
5900
5901 **Compatibility:** Firefox 102\
5902 **CCK2 Equivalent:** N/A\
5903 **Preferences Affected:** `browser.download.start_downloads_in_tmp_dir`
5904
5905 #### Windows (GPO)
5906 ```
5907 Software\Policies\Mozilla\Firefox\StartDownloadsInTempDirectory = 0x1 | 0x0
5908 ```
5909 #### Windows (Intune)
5910 OMA-URI:
5911 ```
5912 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/StartDownloadsInTempDirectory
5913 ```
5914 Value (string):
5915 ```
5916 <enabled/> or <disabled/>
5917 ```
5918 #### macOS
5919 ```
5920 <dict>
5921 <key>StartDownloadsInTempDirectory</key>
5922 <true/> | <false/>
5923 </dict>
5924 ```
5925 #### policies.json
5926 ```
5927 {
5928 "policies": {
5929 "StartDownloadsInTempDirectory": true | false
5930 }
5931 ```
5932 ### UserMessaging
5933
5934 Prevent Firefox from messaging the user in certain situations.
5935
5936 `WhatsNew` Remove the "What's New" icon and menuitem.
5937
5938 `ExtensionRecommendations` If false, don't recommend extensions while the user is visiting web pages.
5939
5940 `FeatureRecommendations` If false, don't recommend browser features.
5941
5942 `UrlbarInterventions` If false, Don't offer Firefox specific suggestions in the URL bar.
5943
5944 `SkipOnboarding` If true, don't show onboarding messages on the new tab page.
5945
5946 `MoreFromMozilla` If false, don't show the "More from Mozilla" section in Preferences. (Firefox 98)
5947
5948 `Locked` prevents the user from changing user messaging preferences.
5949
5950 **Compatibility:** Firefox 75, Firefox ESR 68.7\
5951 **CCK2 Equivalent:** N/A\
5952 **Preferences Affected:** `browser.messaging-system.whatsNewPanel.enabled`, `browser.newtabpage.activity-stream.asrouter.userprefs.cfr.addons`, `browser.newtabpage.activity-stream.asrouter.userprefs.cfr.features`, `browser.aboutwelcome.enabled`, `browser.preferences.moreFromMozilla`
5953
5954 #### Windows (GPO)
5955 ```
5956 Software\Policies\Mozilla\Firefox\UserMessaging\WhatsNew = 0x1 | 0x0
5957 Software\Policies\Mozilla\Firefox\UserMessaging\ExtensionRecommendations = 0x1 | 0x0
5958 Software\Policies\Mozilla\Firefox\UserMessaging\FeatureRecommendations = 0x1 | 0x0
5959 Software\Policies\Mozilla\Firefox\UserMessaging\UrlbarInterventions = 0x1 | 0x0
5960 Software\Policies\Mozilla\Firefox\UserMessaging\SkipOnboarding = 0x1 | 0x0
5961 Software\Policies\Mozilla\Firefox\UserMessaging\MoreFromMozilla = 0x1 | 0x0
5962 Software\Policies\Mozilla\Firefox\UserMessaging\Locked = 0x1 | 0x0
5963 ```
5964 #### Windows (Intune)
5965 OMA-URI:
5966 ```
5967 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_WhatsNew
5968 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_ExtensionRecommendations
5969 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_FeatureRecommendations
5970 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_UrlbarInterventions
5971 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_SkipOnboarding
5972 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_MoreFromMozilla
5973 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_Locked
5974 ```
5975 Value (string):
5976 ```
5977 <enabled/> or <disabled/>
5978 ```
5979 #### macOS
5980 ```
5981 <dict>
5982 <key>UserMessaging</key>
5983 <dict>
5984 <key>WhatsNew</key>
5985 <true/> | <false/>
5986 <key>ExtensionRecommendations</key>
5987 <true/> | <false/>
5988 <key>FeatureRecommendations</key>
5989 <true/> | <false/>
5990 <key>UrlbarInterventions</key>
5991 <true/> | <false/>
5992 <key>SkipOnboarding</key>
5993 <true/> | <false/>
5994 <key>MoreFromMozilla</key>
5995 <true/> | <false/>
5996 <key>Locked</key>
5997 <true/> | <false/>
5998 </dict>
5999 </dict>
6000 ```
6001 #### policies.json
6002 ```
6003 {
6004 "policies": {
6005 "UserMessaging": {
6006 "WhatsNew": true | false,
6007 "ExtensionRecommendations": true | false,
6008 "FeatureRecommendations": true | false,
6009 "UrlbarInterventions": true | false,
6010 "SkipOnboarding": true | false,
6011 "MoreFromMozilla": true | false,
6012 "Locked": true | false
6013 }
6014 }
6015 }
6016 ```
6017 ### UseSystemPrintDialog
6018 Use the system print dialog instead of the print preview window.
6019
6020 **Compatibility:** Firefox 102\
6021 **CCK2 Equivalent:** N/A\
6022 **Preferences Affected:** `print.prefer_system_dialog`
6023
6024 #### Windows (GPO)
6025 ```
6026 Software\Policies\Mozilla\Firefox\UseSystemPrintDialog = 0x1 | 0x0
6027 ```
6028 #### Windows (Intune)
6029 OMA-URI:
6030 ```
6031 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/UseSystemPrintDialog
6032 ```
6033 Value (string):
6034 ```
6035 <enabled/> or <disabled/>
6036 ```
6037 #### macOS
6038 ```
6039 <dict>
6040 <key>UseSystemPrintDialog</key>
6041 <true/> | <false/>
6042 </dict>
6043 ```
6044 #### policies.json
6045 ```
6046 {
6047 "policies": {
6048 "UseSystemPrintDialog": true | false
6049 }
6050 }
6051 ```
6052 ### WebsiteFilter
6053 Block websites from being visited. The parameters take an array of Match Patterns, as documented in https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Match_patterns.
6054 The arrays are limited to 1000 entries each.
6055
6056 If you want to block all URLs, you can use `<all_urls>` or `*://*/*`. You can't have just a `*` on the right side.
6057
6058 For specific protocols, use `https://*/*` or `http://*/*`.
6059
6060 As of Firefox 83 and Firefox ESR 78.5, file URLs are supported.
6061
6062 **Compatibility:** Firefox 60, Firefox ESR 60\
6063 **CCK2 Equivalent:** N/A\
6064 **Preferences Affected:** N/A
6065
6066 #### Windows (GPO)
6067 ```
6068 Software\Policies\Mozilla\Firefox\WebsiteFilter\Block\1 = "<all_urls>"
6069 Software\Policies\Mozilla\Firefox\WebsiteFilter\Exceptions\1 = "http://example.org/*"
6070 ```
6071 #### Windows (Intune)
6072 OMA-URI:
6073 ```
6074 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/B_WebsiteFilter_Block
6075 ```
6076 Value (string):
6077 ```
6078 <enabled/> <data id="WebsiteFilter" value="1&#xF000;&#60;all_urls&#62;"/>
6079 ```
6080 OMA-URI:
6081 ```
6082 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/B_WebsiteFilter_Exceptions
6083 ```
6084 Value (string):
6085 ```
6086 <enabled/>
6087 <data id="WebsiteFilter" value="1&#xF000;http://example.org/*"/>
6088 ```
6089 #### macOS
6090 ```
6091 <dict>
6092 <key>WebsiteFilter</key>
6093 <dict>
6094 <key>Block</key>
6095 <array>
6096 <string><all_urls></string>
6097 </array>
6098 <key>Exceptions</key>
6099 <array>
6100 <string>http://example.org/*</string>
6101 </array>
6102 </dict>
6103
6104 </dict>
6105 ```
6106 #### policies.json
6107 ```
6108 {
6109 "policies": {
6110 "WebsiteFilter": {
6111 "Block": ["<all_urls>"],
6112 "Exceptions": ["http://example.org/*"]
6113 }
6114 }
6115 }
6116 ```
6117 ### WindowsSSO
6118 Allow Windows single sign-on for Microsoft, work, and school accounts.
6119
6120 If this policy is set to true, Firefox will use credentials stored in Windows to sign in to Microsoft, work, and school accounts.
6121
6122 **Compatibility:** Firefox 91\
6123 **CCK2 Equivalent:** N/A\
6124 **Preferences Affected:** `network.http.windows-sso.enabled`
6125
6126 #### Windows (GPO)
6127 ```
6128 Software\Policies\Mozilla\Firefox\WindowsSSO = 0x1 | 0x0
6129 ```
6130 #### Windows (Intune)
6131 OMA-URI:
6132 ```
6133 ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/WindowsSSO
6134 ```
6135 Value (string):
6136 ```
6137 <enabled/> or <disabled/>
6138 ```
6139 #### policies.json
6140 ```
6141 {
6142 "policies": {
6143 "WindowsSSO": true | false
6144 }
6145 }
6146 ```

patrick-canterino.de