Jul 01 2020 08:13 AM
We have deployed the Intune Windows 10 Security Baseline, which includes the default IE Settings. However, via GPO we have published intranet sites to the intranet security zone via... GPO setting \User Configuration\Preferences\Windows Settings\Registry\IE Settings, which creates registry entries at ...HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
and we also allow our users to add sites to the zones as they deem necessary. This works as expected and has for many years....
However, machines that are enrolled in the Intune Windows 10 Security Baseline have all internet explorer security settings blocked including adding sites...
It appears the setting in the baseline "Internet Explorer users adding sites: Disabled" does not function. I have changed this to "Not Configured" and "Enabled" with no change.. the add sites box is greyed out along with all IE Security options...
Changing the setting "Internet Explorer security zones use only machine settings" to disabled does allow the sites published via GPO to show and be effective....
We are looking to publish specific intranet sites along with a few internet sites while retaining the ability of our users to add custom sites.... Any Thoughts/suggestions...
Jul 14 2020 05:25 PM
@MJ_Black Any update on this one? We are experiencing the same problem. The "Internet Explorer users adding sites" does not change the behavior.
Jul 14 2020 06:27 PM
@MattMT, I have not received any suggestions... My plan on going forward is to move away from the baseline configurations and move toward a more granular configuration policy. Which kinda sucks as the baselines are easy to manage and translating all the settings from the baselines into individual policies is going to be diffucult.
Jun 25 2021 12:24 PM
I'm having the same issue. Did anyone figure out a solution?
Jun 25 2021 12:31 PM
Jul 02 2021 03:00 PM
@MJ_Black I have the same issue
Jul 06 2021 01:58 PM
SolutionJul 06 2021 02:05 PM
Jul 06 2021 01:58 PM
Solution