Forum Discussion

MJ_Black's avatar
MJ_Black
Copper Contributor
Jul 01, 2020

Intune Windows 10 Security Baseline IE Settings

We have deployed the Intune Windows 10 Security Baseline, which includes the default IE Settings. However, via GPO we have published intranet sites to the intranet security zone via... GPO setting \User Configuration\Preferences\Windows Settings\Registry\IE Settings, which creates registry entries at ...HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap

 

and we also allow our users to add sites to the zones as they deem necessary. This works as expected and has for many years....

 

However, machines that are enrolled in the Intune Windows 10 Security Baseline have all internet explorer security settings blocked including adding sites...

 

It appears the setting in the baseline "Internet Explorer users adding sites: Disabled" does not function. I have changed this to "Not Configured" and "Enabled" with no change.. the add sites box is greyed out along with all IE Security options...

 

Changing the setting "Internet Explorer security zones use only machine settings" to disabled does allow the sites published via GPO to show and be effective....

 

We are looking to publish specific intranet sites along with a few internet sites while retaining the ability of our users to add custom sites.... Any Thoughts/suggestions...

  • Bruno_Marcelo's avatar
    Bruno_Marcelo
    Jul 06, 2021
    I guess I found a solutions for this issue, try this


    Internet explorer security zones use only machine settings: Disabled
    Internet explorer users adding sites= Enabled
    Internet explorer users changing policies = Enabled
  • MattMT's avatar
    MattMT
    Copper Contributor

    MJ_Black Any update on this one? We are experiencing the same problem. The "Internet Explorer users adding sites" does not change the behavior. 

    • MJ_Black's avatar
      MJ_Black
      Copper Contributor

      MattMT, I have not received any suggestions... My plan on going forward is to move away from the baseline configurations and move toward a more granular configuration policy. Which kinda sucks as the baselines are easy to manage and translating all the settings from the baselines into individual policies is going to be diffucult.  

  • ThirdCoffee's avatar
    ThirdCoffee
    Copper Contributor

    I'm having the same issue.  Did anyone figure out a solution?

     

     

    • MJ_Black's avatar
      MJ_Black
      Copper Contributor
      Do our time constraints we moved away from Intune all together. My hope is to come back to it...
    • Bruno_Marcelo's avatar
      Bruno_Marcelo
      Icon for Microsoft rankMicrosoft
      I guess I found a solutions for this issue, try this


      Internet explorer security zones use only machine settings: Disabled
      Internet explorer users adding sites= Enabled
      Internet explorer users changing policies = Enabled
      • ThirdCoffee's avatar
        ThirdCoffee
        Copper Contributor
        Nice job figuring it out. I was able to solve this by setting all three settings to "Not Configured".

Resources