From: Michael Kaply <345868+mkaply@users.noreply.github.com>
Date: Thu, 2 Jan 2025 21:57:42 +0000 (-0500)
Subject: Merge branch 'master' into DLP_Templates
X-Git-Tag: v6.6~6^2
X-Git-Url: https://git.p6c8.net/policy-templates.git/commitdiff_plain/e8b73eda4584a89a899c2c756681e72c0e5d4ee2?hp=9fda47bb713c056cdb64dd091464780014f3643e
Merge branch 'master' into DLP_Templates
---
diff --git a/windows/en-US/firefox.adml b/windows/en-US/firefox.adml
index 4027dea..e1a1523 100644
--- a/windows/en-US/firefox.adml
+++ b/windows/en-US/firefox.adml
@@ -74,6 +74,7 @@
Firefox 129 or later, Firefox 115.14 ESR or later
Firefox 130 or later, Firefox 115.15 ESR or later
Firefox 130 or later
+ Firefox 131 or later, Firefox 115.16 ESR or later
Firefox
Permissions
Camera
@@ -101,6 +102,7 @@
Proxy Settings
Security Devices
Firefox Suggest (US only)
+ Content Analysis (DLP)
Allowed Sites
Allowed Sites (Session Only)
Blocked Sites
@@ -1132,6 +1134,55 @@ If this policy is disabled or not configured, Private Browsing Mode is available
Allow Private Browsing Mode
Disable Private Browsing Mode
Force Private Browsing Mode
+ Agent Name
+ If this policy is enabled, you can specify the name of the DLP agent, used in dialogs and notifications about DLP operations.
+
+If this policy is disabled or not configured, the agent name "A DLP Agent" is used.
+ Agent Timeout
+ If this policy is enabled, you can specify the timeout in number of seconds after a DLP request is sent to the agent. After this timeout, the request will be denied unless 'Default Result' is set to 1 or 2.
+
+If this policy is disabled or not configured, the timeout is 30 seconds.
+ Allow Url Regex List
+ If this policy is enabled, you can specify a space-separated list of regular expressions that indicates URLs for which DLP operations will always be allowed without consulting the agent. The default is "^about:(?!blank|srcdoc).*", meaning that any pages that start with "about:" will be exempt from DLP except for "about:blank" and "about:srcdoc", as these can be controlled by web content.
+
+If this policy is disabled or not configured, the DLP agent will always be consulted.
+ Bypass For Same Tab Operations
+ If this policy is enabled, Firefox will automatically allow DLP requests whose data comes from the same tab and frame - for example, if data is copied to the clipboard and then pasted on the same page.
+
+If this policy is disabled or not configured, Firefox Firefox will not pass DLP requests whose data comes from the same tab and frame to the DLP agent as normal.
+ Client Signature
+ If this policy is enabled, you can set the required signature of the DLP agent connected to the pipe. If this is a non-empty string and the DLP agent does not have a signature with a Subject Name that exactly matches this value, Firefox will not connect to the pipe.
+
+If this policy is disabled or not configured, the signature will not be verified.
+ Default Result
+ If this policy is enabled, you can indicate the desired behavior for DLP requests if there is a problem connecting to the DLP agent.
+
+If this policy is disabled or not configured, the DLP request will be denied if there is a problem connecting to the agent.
+ Deny the request
+ Warn the user and allow them to choose whether to allow or deny
+ Allow the request
+ Deny Url Regex List
+ If this policy is enabled, you can specify a space-separated list of regular expressions that indicates URLs for which DLP operations will always be denied without consulting the agent.
+
+If this policy is disabled or not configured, the DLP agent will always be consulted.
+ Enabled
+ If this policy is enabled, Firefox will use DLP.
+
+If this policy is disabled or not configured, Firefox will not use DLP.
+
+Note: If this policy is enabled and no DLP agent is running, all DLP requests will be denied unless Default Result is set to 1 or 2.
+ Is Per User
+ If this policy is disabled, the pipe the DLP agent creates is per-system.
+
+If this policy is enabled or not configured, the pipe the DLP agent creates is per-user.
+ Pipe Path Name
+ If this policy is enabled, you can change the name of the pipe for the DLP agent.
+
+If this policy is disabled or not configured, the default pipe name of 'path_user' is used.
+ Show Blocked Result
+ If this policy is disabled, Firefox will not show a notification when a DLP request is denied.
+
+If this policy is enabled or not configured, Firefox will show a notification when a DLP request is denied.
If this policy is enabled, the preference is locked to true. If this policy is disabled, the preference is locked to false.
For a description of the preference, see:
@@ -1504,6 +1555,12 @@ https://github.com/mozilla/policy-templates/blob/master/README.md#preferences.
-
+
+
+
+
+
+
+
diff --git a/windows/firefox.admx b/windows/firefox.admx
index d081399..d31f4e4 100644
--- a/windows/firefox.admx
+++ b/windows/firefox.admx
@@ -76,7 +76,8 @@
-
+
+
@@ -169,6 +170,9 @@
+
+
+
@@ -4304,5 +4308,110 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ -
+
+
+
+
+ -
+
+
+
+
+ -
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+