X-Git-Url: https://git.p6c8.net/policy-templates.git/blobdiff_plain/4f1ce08204b3d6e5b0bcdb39a4171f0c84cfa690..0e7748766cc989c21816b5f45cb823f6b73a8ba5:/README.md?ds=inline diff --git a/README.md b/README.md index a07a0b2..7ccd504 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,7 @@ Policies can be specified using the [Group Policy templates on Windows](https:// | **[`AppAutoUpdate`](#appautoupdate)** | Enable or disable automatic application update. | **[`AppUpdateURL`](#appupdateurl)** | Change the URL for application update. | **[`Authentication`](#authentication)** | Configure sites that support integrated authentication. +| **[`BackgroundAppUpdate`](#backgroundappupdate)** | Enable or disable automatic application update in the background, when the application is not running. | **[`BlockAboutAddons`](#blockaboutaddons)** | Block access to the Add-ons Manager (about:addons). | **[`BlockAboutConfig`](#blockaboutconfig)** | Block access to about:config. | **[`BlockAboutProfiles`](#blockaboutprofiles)** | Block access to About Profiles (about:profiles). @@ -64,6 +65,7 @@ Policies can be specified using the [Group Policy templates on Windows](https:// | **[`LegacyProfiles`](#legacyprofiles)** | Disable the feature enforcing a separate profile for each installation. | **[`LocalFileLinks`](#localfilelinks)** | Enable linking to local files by origin. | **[`ManagedBookmarks`](#managedbookmarks)** | Configures a list of bookmarks managed by an administrator that cannot be changed by the user. +| **[`ManualAppUpdateOnly`](#manualappupdateonly)** | Allow manual updates only and do not notify the user about updates.. | **[`PrimaryPassword`](#primarypassword)** | Require or prevent using a primary (formerly master) password. | **[`NetworkPrediction`](#networkprediction)** | Enable or disable network prediction (DNS prefetching). | **[`NewTabPage`](#newtabpage)** | Enable or disable the New Tab page. @@ -92,6 +94,7 @@ Policies can be specified using the [Group Policy templates on Windows](https:// | **[`SearchEngines -> Add`](#searchengines--add)** | Add new search engines. | **[`SearchSuggestEnabled`](#searchsuggestenabled)** | Enable search suggestions. | **[`SecurityDevices`](#securitydevices)** | Install PKCS #11 modules. +| **[`ShowHomeButton`](#showhomebutton)** | Show the home button on the toolbar. | **[`SSLVersionMax`](#sslversionmax)** | Set and lock the maximum version of TLS. | **[`SSLVersionMin`](#sslversionmin)** | Set and lock the minimum version of TLS. | **[`SupportMenu`](#supportmenu)** | Add a menuitem to the help menu for specifying support information. @@ -325,6 +328,48 @@ Value (string): } } ``` +### BackgroundAppUpdate + +Enable or disable **automatic** application update **in the background**, when the application is not running. + +If set to true, application updates may be installed (without user approval) in the background, even when the application is not running. The operating system might still require approval. + +If set to false, the application will not try to install updates when the application is not running. + +If you have disabled updates via `DisableAppUpdate` or disabled automatic updates via `AppUpdateAuto`, this policy has no effect. + +**Compatibility:** Firefox 89\ +**CCK2 Equivalent:** N/A\ +**Preferences Affected:** `app.update.background.enabled` + +#### Windows (GPO) +``` +Software\Policies\Mozilla\Firefox\BackgroundAppUpdate = 0x1 | 0x0 +``` +#### Windows (Intune) +OMA-URI: +``` +./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/BackgroundAppUpdate +``` +Value (string): +``` + or +``` +#### macOS +``` + + BackgroundAppUpdate + | + +``` +#### policies.json +``` +{ + "policies": { + "BackgroundAppUpdate": true | false + } +} +``` ### BlockAboutAddons Block access to the Add-ons Manager (about:addons). @@ -981,6 +1026,8 @@ Value (string): ### DisabledCiphers Disable specific cryptographic ciphers. +**Preferences Affected:** `security.ssl3.dhe_rsa_aes_128_sha`, `security.ssl3.dhe_rsa_aes_256_sha`, `security.ssl3.ecdhe_ecdsa_aes_128_gcm_sha256`, `security.ssl3.ecdhe_rsa_aes_128_gcm_sha256`, `security.ssl3.ecdhe_rsa_aes_128_sha`, `security.ssl3.ecdhe_rsa_aes_256_sha`, `security.ssl3.rsa_aes_128_gcm_sha256`, `security.ssl3.rsa_aes_128_sha`, `security.ssl3.rsa_aes_256_gcm_sha384`, `security.ssl3.rsa_aes_256_sha`, `security.ssl3.rsa_des_ede3_sha` + --- **Note:** @@ -2176,7 +2223,7 @@ Control the installation, uninstallation and locking of extensions. While this policy is not technically deprecated, it is recommended that you use the **[`ExtensionSettings`](#extensionsettings)** policy. It has the same functionality and adds more. It does not support native paths, though, so you'll have to use file:/// URLs. -`Install` is a list of URLs or native paths for extensions to be installed. +`Install` is a list of URLs or native paths for extensions to be installed. `Uninstall` is a list of extension IDs that should be uninstalled if found. @@ -2295,7 +2342,7 @@ Software\Policies\Mozilla\Firefox\ExtensionSettings (REG_MULTI_SZ) = "install_url": "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi" }, "https-everywhere@eff.org": { - "installation_mode": "allowed", + "installation_mode": "allowed" } } ``` @@ -2320,7 +2367,7 @@ Value (string): "install_url": "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi" }, "https-everywhere@eff.org": { - "installation_mode": "allowed", + "installation_mode": "allowed" } }'/> ``` @@ -3162,6 +3209,29 @@ Value (string): } } ``` +### ManualAppUpdateOnly + +Switch to manual updates only. + +If this policy is enabled: + 1. The user will never be prompted to install updates + 2. Firefox will not check for updates in the background, though it will check automatically when an update UI is displayed (such as the one in the About dialog). This check will be used to show "Update to version X" in the UI, but will not automatically download the update or prompt the user to update in any other way. + 3. The update UI will work as expected, unlike when using DisableAppUpdate. + +This policy is primarily intended for advanced end users, not for enterprises. + +**Compatibility:** Firefox 87\ +**CCK2 Equivalent:** N/A\ +**Preferences Affected:** N/A + +#### policies.json +``` +{ + "policies": { + "ManualAppUpdateOnly": true | false + } +} +``` ### PrimaryPassword Require or prevent using a primary (formerly master) password. @@ -3945,6 +4015,7 @@ Previously you could only set and lock a subset of preferences. Starting with Fi Preferences that start with the following prefixes are supported: ``` accessibility. +app.update.* (Firefox 86, Firefox 78.8) browser. datareporting.policy. dom. @@ -3983,6 +4054,8 @@ as well as the following security preferences: |     If false, SSL errors cannot be sent to Mozilla. | security.tls.hello_downgrade_check | boolean | true |     If false, the TLS 1.3 downgrade check is disabled. +| security.tls.version.enable-deprecated | boolean | false +|     If true, browser will accept TLS 1.0. and TLS 1.1 (Firefox 86, Firefox 78.8) | security.warn_submit_secure_to_insecure | boolean | true |     If false, no warning is shown when submitting s form from https to http.   @@ -4192,7 +4265,7 @@ disabled | network.dns.disableIPv6 | boolean | Firefox 68, Firefox ESR 68 | false |     If true, IPv6 DNS lokoups are disabled. | network.IDN_show_punycode | boolean | Firefox 68, Firefox ESR 68 | false -|     If true, display the punycode version of internationalized domain names. +|     If true, display the punycode version of internationalized domain names. | places.history.enabled | boolean | Firefox 68, Firefox ESR 68 | true |     If false, history is not enabled. | print.save_print_settings | boolean | Firefox 70, Firefox ESR 68.2 | true @@ -4996,6 +5069,43 @@ Value (string): } } ``` +### ShowHomeButton +Show the home button on the toolbar. + +Future versions of Firefox will not show the home button by default. + +**Compatibility:** Firefox 88, Firefox ESR 78.10\ +**CCK2 Equivalent:** N/A\ +**Preferences Affected:** N/A + +#### Windows (GPO) +``` +Software\Policies\Mozilla\Firefox\ShowHomeButton = 0x1 | 0x0 +``` +#### Windows (Intune) +OMA-URI: +``` +./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/ShowHomeButton +``` +Value (string): +``` + or +``` +#### macOS +``` + + ShowHomeButton + | + +``` +#### policies.json +``` +{ + "policies": { + "ShowHomeButton": true | false + } +} +``` ### SSLVersionMax Set and lock the maximum version of TLS. @@ -5127,17 +5237,19 @@ Value (string): Prevent Firefox from messaging the user in certain situations. -`WhatsNew` Remove the "What's New" icon and menuitem. (Firefox 75 only) +`WhatsNew` Remove the "What's New" icon and menuitem. -`ExtensionRecommendations` Don't recommend extensions while the user is visiting web pages. +`ExtensionRecommendations` If false, don't recommend extensions while the user is visiting web pages. -`FeatureRecommendations` Don't recommend browser features. +`FeatureRecommendations` IF false, don't recommend browser features. -`UrlbarInterventions` Don't offer Firefox specific suggestions in the URL bar. (Firefox 75 only) +`UrlbarInterventions` If false, Don't offer Firefox specific suggestions in the URL bar. + +`SkipOnboarding` If true, don't show onboarding messages on the new tab page. **Compatibility:** Firefox 75, Firefox ESR 68.7\ **CCK2 Equivalent:** N/A\ -**Preferences Affected:** `browser.messaging-system.whatsNewPanel.enabled`,`browser.newtabpage.activity-stream.asrouter.userprefs.cfr.addons`,`browser.newtabpage.activity-stream.asrouter.userprefs.cfr.features` +**Preferences Affected:** `browser.messaging-system.whatsNewPanel.enabled`,`browser.newtabpage.activity-stream.asrouter.userprefs.cfr.addons`,`browser.newtabpage.activity-stream.asrouter.userprefs.cfr.features`,`browser.aboutwelcome.enabled` #### Windows (GPO) ``` @@ -5145,6 +5257,7 @@ Software\Policies\Mozilla\Firefox\UserMessaging\WhatsNew = 0x1 | 0x0 Software\Policies\Mozilla\Firefox\UserMessaging\ExtensionRecommendations = 0x1 | 0x0 Software\Policies\Mozilla\Firefox\UserMessaging\FeatureRecommendations = 0x1 | 0x0 Software\Policies\Mozilla\Firefox\UserMessaging\UrlbarInterventions = 0x1 | 0x0 +Software\Policies\Mozilla\Firefox\UserMessaging\SkipOnboarding = 0x1 | 0x0 ``` #### Windows (Intune) OMA-URI: @@ -5153,6 +5266,7 @@ OMA-URI: ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/UserMessaging_ExtensionRecommendations ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/UserMessaging_FeatureRecommendations ./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/UserMessaging_UrlbarInterventions +./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox/UserMessaging_SkipOnboarding ``` Value (string): ``` @@ -5171,6 +5285,8 @@ Value (string): | UrlbarInterventions | + SkipOnboarding + | ``` @@ -5183,6 +5299,7 @@ Value (string): "ExtensionRecommendations": true | false, "FeatureRecommendations": true | false, "UrlbarInterventions": true | false + "SkipOnboarding": true | false } } }