From: Michael Kaply <345868+mkaply@users.noreply.github.com> Date: Thu, 2 Jan 2025 21:57:42 +0000 (-0500) Subject: Merge branch 'master' into DLP_Templates X-Git-Tag: v6.6~6^2 X-Git-Url: https://git.p6c8.net/policy-templates.git/commitdiff_plain/e8b73eda4584a89a899c2c756681e72c0e5d4ee2?hp=9fda47bb713c056cdb64dd091464780014f3643e Merge branch 'master' into DLP_Templates --- diff --git a/windows/en-US/firefox.adml b/windows/en-US/firefox.adml index 4027dea..e1a1523 100644 --- a/windows/en-US/firefox.adml +++ b/windows/en-US/firefox.adml @@ -74,6 +74,7 @@ Firefox 129 or later, Firefox 115.14 ESR or later Firefox 130 or later, Firefox 115.15 ESR or later Firefox 130 or later + Firefox 131 or later, Firefox 115.16 ESR or later Firefox Permissions Camera @@ -101,6 +102,7 @@ Proxy Settings Security Devices Firefox Suggest (US only) + Content Analysis (DLP) Allowed Sites Allowed Sites (Session Only) Blocked Sites @@ -1132,6 +1134,55 @@ If this policy is disabled or not configured, Private Browsing Mode is available Allow Private Browsing Mode Disable Private Browsing Mode Force Private Browsing Mode + Agent Name + If this policy is enabled, you can specify the name of the DLP agent, used in dialogs and notifications about DLP operations. + +If this policy is disabled or not configured, the agent name "A DLP Agent" is used. + Agent Timeout + If this policy is enabled, you can specify the timeout in number of seconds after a DLP request is sent to the agent. After this timeout, the request will be denied unless 'Default Result' is set to 1 or 2. + +If this policy is disabled or not configured, the timeout is 30 seconds. + Allow Url Regex List + If this policy is enabled, you can specify a space-separated list of regular expressions that indicates URLs for which DLP operations will always be allowed without consulting the agent. The default is "^about:(?!blank|srcdoc).*", meaning that any pages that start with "about:" will be exempt from DLP except for "about:blank" and "about:srcdoc", as these can be controlled by web content. + +If this policy is disabled or not configured, the DLP agent will always be consulted. + Bypass For Same Tab Operations + If this policy is enabled, Firefox will automatically allow DLP requests whose data comes from the same tab and frame - for example, if data is copied to the clipboard and then pasted on the same page. + +If this policy is disabled or not configured, Firefox Firefox will not pass DLP requests whose data comes from the same tab and frame to the DLP agent as normal. + Client Signature + If this policy is enabled, you can set the required signature of the DLP agent connected to the pipe. If this is a non-empty string and the DLP agent does not have a signature with a Subject Name that exactly matches this value, Firefox will not connect to the pipe. + +If this policy is disabled or not configured, the signature will not be verified. + Default Result + If this policy is enabled, you can indicate the desired behavior for DLP requests if there is a problem connecting to the DLP agent. + +If this policy is disabled or not configured, the DLP request will be denied if there is a problem connecting to the agent. + Deny the request + Warn the user and allow them to choose whether to allow or deny + Allow the request + Deny Url Regex List + If this policy is enabled, you can specify a space-separated list of regular expressions that indicates URLs for which DLP operations will always be denied without consulting the agent. + +If this policy is disabled or not configured, the DLP agent will always be consulted. + Enabled + If this policy is enabled, Firefox will use DLP. + +If this policy is disabled or not configured, Firefox will not use DLP. + +Note: If this policy is enabled and no DLP agent is running, all DLP requests will be denied unless Default Result is set to 1 or 2. + Is Per User + If this policy is disabled, the pipe the DLP agent creates is per-system. + +If this policy is enabled or not configured, the pipe the DLP agent creates is per-user. + Pipe Path Name + If this policy is enabled, you can change the name of the pipe for the DLP agent. + +If this policy is disabled or not configured, the default pipe name of 'path_user' is used. + Show Blocked Result + If this policy is disabled, Firefox will not show a notification when a DLP request is denied. + +If this policy is enabled or not configured, Firefox will show a notification when a DLP request is denied. If this policy is enabled, the preference is locked to true. If this policy is disabled, the preference is locked to false. For a description of the preference, see: @@ -1504,6 +1555,12 @@ https://github.com/mozilla/policy-templates/blob/master/README.md#preferences. - + + + + + + + diff --git a/windows/firefox.admx b/windows/firefox.admx index d081399..d31f4e4 100644 --- a/windows/firefox.admx +++ b/windows/firefox.admx @@ -76,7 +76,8 @@ - + + @@ -169,6 +170,9 @@ + + + @@ -4304,5 +4308,110 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +