X-Git-Url: https://git.p6c8.net/policy-templates.git/blobdiff_plain/7bdccd55292fa4a4d08210af733e2e67b341c976..8167d4cb6d0645df265775950c431bf7bc70237f:/windows/en-US/firefox.adml diff --git a/windows/en-US/firefox.adml b/windows/en-US/firefox.adml index ea66f2e..8ff464a 100644 --- a/windows/en-US/firefox.adml +++ b/windows/en-US/firefox.adml @@ -1,12 +1,19 @@ - - + + Microsoft Windows XP SP2 or later + Firefox 60 or later, Firefox 60 ESR or later + Firefox 62 or later, Firefox 60.2 ESR or later + Firefox 60 ESR or later Firefox Permissions + Camera + Microphone + Location + Notifications Authentication Bookmarks Certificates @@ -19,22 +26,50 @@ Search Allowed Sites Blocked Sites + Custom Update URL + If this policy is enabled, you can set a URL to an update server other than the default. This could be helpful if you run your own update server on your network. + +If this policy is disabled or not configured, the default update URL is used. SPNEGO - List of sites that are permitted to engage in SPNEGO authentication with the browser. + If this policy is enabled, the specified websites are permitted to engage in SPNEGO authentication with the browser. Entries in the list are formatted as mydomain.com or https://myotherdomain.com. + +If this policy is disabled or not configured, no websites are permitted to engage in SPNEGO authentication with the browser. + +For more information, see https://developer.mozilla.org/en-US/docs/Mozilla/Integrated_authentication. Delegated - List of sites for which the browser may delegate user authorization to the server. + If this policy is enabled, the browser may delegate user authorization to the server for the specified websites. Entries in the list are formatted as mydomain.com or https://myotherdomain.com. + +If this policy is disabled or not configured, the browser will not delegate user authorization to the server for any websites. + +For more information, see https://developer.mozilla.org/en-US/docs/Mozilla/Integrated_authentication. NTLM - List of sites trusted to use NTLM authentification. - Block About Addons - Block access to the Add-ons Mananger (about:addons). - Block About Config - Blocks access to the about:config page. - Block About Profiles - Blocks access to the about:profiles page. - Block About Support - Blocks access to the about:support page. + If this policy is enabled, the specified websites are trusted to use NTLM authentification. Entries in the list are formatted as mydomain.com or https://myotherdomain.com. + +If this policy is disabled or not configured, no websites are trusted to use NTLM authentification. + +For more information, see https://developer.mozilla.org/en-US/docs/Mozilla/Integrated_authentication. + Allow Non FQDN + If this policy is enabled, you can always allow SPNEGO or NTLM on non FQDNs (fully qualified domain names). + +If this policy is disabled or not configured, NTLM and SPNEGO are not enabled on non FQDNs. + Block Add-ons Manager + If this policy is enabled, the user cannot access the Add-ons Manager or about:addons. + +If this policy is disabled or not configured, the user can access the Add-ons Manager and about:addons. + Block about:config + If this policy is enabled, the user cannot access about:config. + +If this policy is disabled or not configured, the user can access about:config. + Block about:profiles + If this policy is enabled, the user cannot access about:profiles. + +If this policy is disabled or not configured, the user can access about:profiles. + Block Troubleshooting Information + If this policy is enabled, the user cannot access Troubleshooting Information or about:support. + +If this policy is disabled or not configured, the user can access Troubleshooting Information and about:support. Disable Set Desktop Background - If this policy is enabled, the user can not set an image as their desktop background. + If this policy is enabled, the user cannot set an image as their desktop background. If this policy is disabled or not configured, users can set images as their desktop background. Import Enterprise Roots @@ -46,78 +81,128 @@ If this policy is disabled or not configured, Firefox will not read certificates If this policy is disabled or not configured, users can create a master password. Disable Update - Prevent the browser from updating. - Disable Builtin PDF Viewer - Disables PDF.js, which displays PDFs within Firefox. + If this policy is enabled, the browser does not receive udpates. + +If this policy is disabled or not configured, the browser receives updates. + +Starting with Firefox 62, this policy will only work from Computer Configuration. + Disable Built-in PDF Viewer (PDF.js) + If this policy is enabled, PDF files are not viewed within Firefox. + +If this policy is disabled or not configured, PDF files are viewed within Firefox. Disable Developer Tools - Prevents access to developer tools. + If this policy is enabled, web developer tools are not available within Firefox. + +If this policy is disabled or not configured, web developer tools are available within Firefox. Disable Feedback Commands - Prevents ability to send feedback from the help menu ("Submit Feedback" and "Report Deceptive Site"). + If this policy is enabled, the "Submit Feedback" and "Report Deceptive Site" menuitems are not available from the help menu. + +If this policy is disabled or not configured, the "Submit Feedback" and "Report Deceptive Site" menuitems are available from the help menu. Disable Firefox Accounts - Disables Firefox Account based services, including Sync. + If this policy is enabled, Firefox Accounts is disabled which includes disabling Sync. + +If this policy is disabled or not configured, Firefox Accounts and Sync are available. Disable Firefox Screenshots - Prevents usage of the Firefox Screenshots feature. + If this policy is enabled, Firefox Screenshots is not available. + +If this policy is disabled or not configured, Firefox Screenshots is available. Disable Firefox Studies - Prevents Firefox from running studies. + If this policy is enabled, Firefox will never run SHIELD studies or do Heartbeat surveys. + +If this policy is disabled or not configured, the user can choose to enable SHIELD studies or Heartbeat surveys. + +For more information, see https://support.mozilla.org/en-US/kb/shield and https://wiki.mozilla.org/Firefox/Shield/Heartbeat Disable Forget Button If this policy is enabled, the "Forget" button is not available. If this policy is disabled or not configured, the "Forget" button is available. Disable Form History - Don't remember search and form history. + If this policy is enabled, Firefox will not remember form or search history. + +If this policy is disabled or not configured, Firefox will remember form and search history. Disable Pocket - Prevents ability to save webpages to Pocket. + If this policy is enabled, Pocket is not available. + +If this policy is disabled or not configured, Pocket is available. Disable Private Browsing - Disables private browsing. + If this policy is enabled, private browsing is not allowed. + +If this policy is disabled or not configured, private browsing is allowed. + Disable Profile Import + If this policy is enabled, the "Import data from another browser" option is not available in the bookmarks window. + +If this policy is disabled or not configured, the "Import data from another browser" option is available. Disable Profile Refresh If this policy is enabled, the "Refresh Firefox" button is not available on the about:support page or on support.mozilla.org. If this policy is disabled or not configured, the "Refresh Firefox" button is available. Disable Safe Mode - Prevents ability to restart in safe mode. + If this policy is enabled, the user cannot restart the browser into safe mode. + +If this policy is disabled or not configured, safe mode is allowed. Prevent overriding certificate errors If this policy is enabled, the "Add Exception" button is not available when a certificate is invalid. This prevents the user from overriding the certificate error. If this policy is disabled or not configured, certificate errors can be overridden. Prevent overriding safe browsing errors - If this policy is enabled, a user can not bypass the warning and visit a harmful site. + If this policy is enabled, a user cannot bypass the warning and visit a harmful site. If this policy is disabled or not configured, a user can choose to visit a harmful site. Disable System Addon Updates If this policy is enabled, new system add-ons will not be installed and existing system add-ons will not be updated. -If this policy is disabled or not configured, system add-ons are installed and updated. +If this policy is disabled or not configured, system add-ons are installed and updated. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Disable Telemetry If this policy is enabled, telemetry is not uploaded. If this policy is disabled or not configured, telemetry is collected and uploaded. -Mozilla strongly recommends that you do NOT disable telemetry if you do not have a business need to do so. +Mozilla recommends that you do not disable telemetry. Information collected through telemetry helps us build a better product for businesses like yours. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Display Bookmarks Toolbar - Causes the bookmarks toolbar to be displayed by default. + If this policy is enabled, the bookmarks toolbar is displayed by default. The user can still hide it. + +If this policy is disabled or not configured, the bookmarks toolbar is not displayed by default. Display Menu Bar - Causes the menu bar to be displayed by default. + If this policy is enabled, the menu bar is displayed by default. The user can still hide it. + +If this policy is disabled or not configured, the menu bar is not displayed by default. Don't Check Default Browser - Don't check for the default browser on startup. - Install + If this policy is enabled, Firefox does not check to see if it is the default browser at startup. + +If this policy is disabled or not configured, Firefox checks to see if it is the default browser at startup. + Extensions to Install If this policy is enabled, you can specify a list of extension URLs or paths that will be installed when Firefox is started. Anytime this list is changed, the extensions will be reinstalled. -If this policy is disabled or not configured, no extensions are installed. - Uninstall +If this policy is disabled or not configured, no extensions are installed. + +Starting with Firefox 62, this policy will only work from Computer Configuration. + Extensions to Uninstall If this policy is enabled, you can specify a list of extension IDs that will be uninstalled. Anytime this list is changed, the extensions will be uninstalled. -If this policy is disabled or not configured, no extensions are uninstalled. - Locked +If this policy is disabled or not configured, no extensions are uninstalled. + +Starting with Firefox 62, this policy will only work from Computer Configuration. + Prevent extensions from being disabled or removed If this policy is enabled, you can specify a list of extension IDs that the user will be unable to uninstall or disable. -If this policy is disabled or not configured, no extensions are locked. +If this policy is disabled or not configured, no extensions are locked + +Starting with Firefox 62, this policy will only work from Computer Configuration. + Hardware Acceleration + If this policy is disabled, hardware acceleration and cannot be enabled. + +If this policy is enabled or not configured, hardware acceleration is enabled. Offer to save logins If this policy is enabled or not configured, Firefox will offer to save website logins and passwords. -If this policy is disabled, firefox will not offer to save website logins and passwords. - If this policy is enabled, pop-up windows are always allowed for the URLS indicated. If a top level domain is specified (http://example.org), pop-up windows are allowed for all subdomains as well. +If this policy is disabled, Firefox will not offer to save website logins and passwords. + If this policy is enabled, pop-up windows are always allowed for the origins indicated. If a top level domain is specified (http://example.org), pop-up windows are allowed for all subdomains as well. If this policy is disabled or not configured, the default pop-up policy is followed. Allow pop-ups from websites @@ -125,20 +210,20 @@ If this policy is disabled or not configured, the default pop-up policy is follo If this policy is not configured or enabled, popups are not allowed from websites. Do not allow preferences to be changed - If this policy is enabled pop-up preferences cannot be changed by the user. + If this policy is enabled, pop-up preferences cannot be changed by the user. If this policy is disabled or not configured, the user can change their pop-up preferences. - If this policy is enabled, add-ons are always allowed for the URLS indicated unless add-on install is disabled. If a top level domain is specified (http://example.org), add-ons are allowed for all subdomains as well. + If this policy is enabled, add-ons are always allowed for the origins indicated unless add-on install is disabled. If a top level domain is specified (http://example.org), add-ons are allowed for all subdomains as well. If this policy is disabled or not configured, the default add-on policy is followed. Allow add-on installs from websites If this policy is disabled, add-ons cannot be installed. If this policy is not configured or enabled, add-ons can be installed. - If this policy is enabled, cookies are always allowed for the URLS indicated. If a top level domain is specified (http://example.org), cookies are allowed for all subdomains as well. + If this policy is enabled, cookies are always allowed for the origins indicated. If a top level domain is specified (http://example.org), cookies are allowed for all subdomains as well. If this policy is disabled or not configured, the default cookie policy is followed. - If this policy is enabled, cookies are blocked for the URLS indicated. If a top level domain is specified (http://example.org), cookies are blocked from all subdomains as well. + If this policy is enabled, cookies are blocked for the origins indicated. If a top level domain is specified (http://example.org), cookies are blocked from all subdomains as well. If this policy is disabled or not configured, cookies are not blocked by default. Accept cookies from websites @@ -157,61 +242,143 @@ This setting is ignored if this policy is disabled or not configured or if cooki This setting is ignored if this policy is disabled or not configured or if cookies are not allowed. Do not allow preferences to be changed - If this policy is enabled cookie preferences cannot be changed by the user. + If this policy is enabled, cookie preferences cannot be changed by the user. If this policy is disabled or not configured, the user can change their cookie preferences. - If this policy is enabled, Flash is activated by default for the URLS indicated unless Flash is completely disabled. If a top level domain is specified (http://example.org), Flash is allowed for all subdomains as well. + If this policy is enabled, access to the camera is always allowed for the origins indicated. + +If this policy is disabled or not configured, the default camera policy is followed. + If this policy is enabled, access to the camera is blocked for the origins indicated. + +If this policy is disabled or not configured, access to the camera is not blocked by default. + Block new requests asking to access the camera + If this policy is enabled, sites that are not in the Allow policy will not be allowed to ask permission to access the camera. + +If this policy is disabled or not configured, any site that is not in the Block policy can ask permission to access the camera. + Do not allow preferences to be changed + If this policy is enabled, camera preferences cannot be changed by the user. + +If this policy is disabled or not configured, the user can change their camera preferences. + If this policy is enabled, access to the microphone is always allowed for the origins indicated. + +If this policy is disabled or not configured, the default microphone policy is followed. + If this policy is enabled, access to the microphone is blocked for the origins indicated. + +If this policy is disabled or not configured, access to the microphone is not blocked by default. + Block new requests asking to access the microphone + If this policy is enabled, sites that are not in the Allow policy will not be allowed to ask permission to access the microphone. + +If this policy is disabled or not configured, any site that is not in the Block policy can ask permission to access the microphone. + Do not allow preferences to be changed + If this policy is enabled, microphone preferences cannot be changed by the user. + +If this policy is disabled or not configured, the user can change their camera preferences. + If this policy is enabled, access to location is always allowed for the origins indicated. + +If this policy is disabled or not configured, the default location policy is followed. + If this policy is enabled, access to location is blocked for the origins indicated. + +If this policy is disabled or not configured, access to location is not blocked by default. + Block new requests asking to access location + If this policy is enabled, sites that are not in the Allow policy will not be allowed to ask permission to access location. + +If this policy is disabled or not configured, any site that is not in the Block policy can ask permission to access location. + Do not allow preferences to be changed + If this policy is enabled, location preferences cannot be changed by the user. + +If this policy is disabled or not configured, the user can change location preferences. + If this policy is enabled, notifications can always be sent for the origins indicated. + +If this policy is disabled or not configured, the default nofication policy is followed. + If this policy is enabled, notifications are always blocked for the origins indicated. + +If this policy is disabled or not configured, notifications are not blocked by default. + Block new requests asking to send notifications + If this policy is enabled, sites that are not in the Allow policy will not be allowed to ask permission to send notifications. + +If this policy is disabled or not configured, any site that is not in the Block policy can ask permission to send notifications. + Do not allow preferences to be changed + If this policy is enabled, notification preferences cannot be changed by the user. + +If this policy is disabled or not configured, the user can change their notification preferences. + If this policy is enabled, Flash is activated by default for the origins indicated unless Flash is completely disabled. If a top level domain is specified (http://example.org), Flash is allowed for all subdomains as well. If this policy is disabled or not configured, the default Flash policy is followed. - If this policy is enabled, Flash is blocked for the URLS indicated. If a top level domain is specified (http://example.org), Flas is blocked from all subdomains as well. + If this policy is enabled, Flash is blocked for the origins indicated. If a top level domain is specified (http://example.org), Flash is blocked from all subdomains as well. If this policy is disabled or not configured, the default Flash policy is followed. Activate Flash on websites - If this policy is enabled, Flash is always activates on websites. + If this policy is enabled, Flash is always activated on websites. If this policy is disabled, Flash is never activated on websites, even if they are in the specified in the Allow list. -If this policy is not configured Flash, Flash is click to play. +If this policy is not configured, Flash is click to play. Do not allow preferences to be changed - If this policy is enabled Flash preferences cannot be changed by the user. + If this policy is enabled, Flash preferences cannot be changed by the user. If this policy is disabled or not configured, the user can change their Flash preferences. Override the first run page If this policy is enabled, you can specify a URL to be used as the first run page. If you leave the URL blank, no first run page will be shown. -If this policy is disabled or not configured the first run page is displayed. +If this policy is disabled or not configured, the first run page is displayed. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Override the upgrade page If this policy is enabled, you can specify a URL to be displayed after Firefox is updated. If you leave the URL blank, no upgrade page will be shown. -If this policy is disabled or not configured the upgrade is displayed. +If this policy is disabled or not configured, the upgrade is displayed. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Clear all data when browser is closed If this policy is enabled, all data is cleared when Firefox is closed. This includes Browsing & Download History, Cookies, Active Logins, Cache, Form & Search History, Site Preferences and Offline Website Data. If this policy is disabled or not configured, data is not cleared when the browser is closed. Blocked websites - If this policy is enabled, you can specify match patterns that indicate sites to be blocked. The match patterns are documented at https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Match_patterns. Only http/https accesses are supported at the moment. There is a 1000 entry limit.", + If this policy is enabled, you can specify match patterns that indicate sites to be blocked. The match patterns are documented at https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Match_patterns. Only http/https addresses are supported at the moment. There is a 1000 entry limit. + +If this policy is disabled or not configured, no websites are blocked. -If this policy is disabled or not configured, no websites are blocked. +Starting with Firefox 62, this policy will only work from Computer Configuration. Exceptions to blocked websites - If this policy is enabled, and the website filter is enabled, you can specify match patterns for sites you do not want to block. The match patterns are documented at https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Match_patterns. Only http/https accesses are supported at the moment. There is a 1000 entry limit.", - -If this policy is disabled or not configured, there are no exceptions to the website filter. - Bookmark 1 - Bookmark 2 - Bookmark 3 - Bookmark 4 - Bookmark 5 - Bookmark Explanation + If this policy is enabled, and the website filter is enabled, you can specify match patterns for sites you do not want to block. The match patterns are documented at https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Match_patterns. Only http/https addresses are supported at the moment. There is a 1000 entry limit. + +If this policy is disabled or not configured, there are no exceptions to the website filter. + +Starting with Firefox 62, this policy will only work from Computer Configuration. + Bookmark One + Bookmark Two + Bookmark Three + Bookmark Four + Bookmark Five + If this policy is enabled, you can configure a bookmark be added to Firefox. Due to a bug, you must select the location. Note that you must specify the bookmarks in order. + +If this policy is disabled or not configured, a new bookmark is not added. Toolbar Menu No Default Bookmarks - Don't create the default bookmarks or the Smart Bookmarks (Most Visited, Recent Tags). Note: this policy is only effective if used before the first run of the profile. + If this policy is enabled, the default bookmarks and Smart Bookmarks (Most Visited, Recent Tags) are not created. + +If this policy is disabled or not configured, default bookmarks and Smart Bookmarks (Most Visited, Recent Tags) are created. + +Note: this policy is only effective if used before the first run of the profile. URL for Home page - Homepage Settings + If this policy is enabled, you can set a default home page. You can also lock the home page. + +If this policy is disabled or not configured, the user can set and change the home page. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Additional Homepages - If you want to have more than one homepage + If this policy is enabled, you can have additional home pages. They are opened in multiple tabs. + +If this policy is disabled or not configured, there is only one home page. + +Starting with Firefox 62, this policy will only work from Computer Configuration. Proxy Settings - If this policy is enabled, you should select the connection type and then fill in the appropriate sections. Due to a bug, you must select a value for the SOCKS proxy version. + If this policy is enabled, you can configure and lock network settings. + +Select the connection type and then fill in the appropriate sections. Due to a bug, you must select a value for the SOCKS proxy version. + +If this policy is disabled or not configured, the default network settings are used and user can change them. SOCKS v4 SOCKS v5 Automatic proxy configuration URL @@ -233,7 +400,7 @@ If this policy is enabled, private browsing is enabled by default in both the br Search bar location If this policy is enabled, you can set whether the search bar is separate from the URL bar. -If this policy is not configured or disabled, new users get a unified search bar, users upgrading from Firefox 56 and below get a separate search bar. +If this policy is disabled or not configured, new users get a unified search bar, users upgrading from Firefox 56 and below get a separate search bar. Search Engine One Search Engine Two Search Engine Three @@ -241,24 +408,37 @@ If this policy is not configured or disabled, new users get a unified search bar Search Engine Five If this policy is enabled, you can configure a search engine to be added to Firefox. Use {searchTerms} to indicate where the search term is placed. Due to a bug, you must select the method (usually GET). Note that you must specify the search engines in order. -If this policy is not configured or disabled, a new search engine is not added. +If this policy is disabled or not configured, a new search engine is not added. Unified Separate GET POST Default Search Engine - If this policy is enabled, you can set type the name of a search engine to be used as the default. + If this policy is enabled, you can set the name of a search engine to be used as the default. -If this policy is not configured or disabled, the Firefox default engine is used. +If this policy is disabled or not configured, the Firefox default engine is used. Prevent Search Engine Installs If this policy is enabled, the user cannot install search engines from web page. -If this policy is not configured or disabled, search engines can be installed from web pages. +If this policy is disabled or not configured, search engines can be installed from web pages. + Remove Search Engines + If this policy is enabled, you can specify the names of engines to be removed or hidden. + +If this policy is disabled or not configured, search engines will not be removed or hidden. + + + + + + + Always allow NTLM on non FQDNs + Always allow SPNEGO on non FQDNs + @@ -338,6 +518,9 @@ If this policy is not configured or disabled, search engines can be installed fr