SOLVED

Extensions are remembered in Application Guard mode after fully closing it and the Edge browser

%3CLINGO-SUB%20id%3D%22lingo-sub-1144655%22%20slang%3D%22en-US%22%3EExtensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1144655%22%20slang%3D%22en-US%22%3E%3CP%3EVersion%2081.0.410.0%20(Official%20build)%20canary%20(64-bit)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20went%20to%20WDAG%20mode%20window%2C%20installed%20an%20extension%20from%20Microsoft%20add-on%20store%2C%20continued%20browsing%20the%20web%20for%20few%20minutes%2C%20then%20i%20closed%20the%20Application%20Guard%20window%20and%20closed%20Edge.%3C%2FP%3E%3CP%3Ewaited%20approx%201%20or%202%20minutes%2C%20launched%20Edge%20canary%20again%20and%20started%20a%20new%20Application%20Guard%20window%2C%20then%20I%20noticed%20the%20extension%20that%20I%20had%20installed%20is%20still%20in%20there!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethat%20was%20absolutely%20not%20what%20I%20expected%2C%20the%20Application%20Guard%20window%20should%20flush%20itself%20and%20clear%20all%20of%20user%20data%20once%20closed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20554px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F168406i5C4414E9EDD305F3%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22DSDA.png%22%20title%3D%22DSDA.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1144655%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E81.0.410%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ecanary%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EEdge%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eextension%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EInstall%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eproblem%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWDAG%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1153497%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1153497%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3B-%20Thanx%20for%20the%20feedback.%20Currently%20the%20functionality%20is%20when%20%22Allow%20Data%20persistence%20For%20...%22%20policy%20is%20enabled%20on%20the%20device.%20The%20Application%20Guard%20will%20persist%20the%20previous%20state.%20If%20this%20policy%20is%20turned%20off%20the%20state%20is%20flushed%20on%20container%20startup.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1165420%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1165420%22%20slang%3D%22en-US%22%3EThe%20Prelaunch%20feature%20is%20to%20improve%20the%20performance%20of%20Application%20Guard.%20This%20may%20hold%20the%20container%20running%20for%2015%20mins%20longer%20if%20the%20host%20instance%20is%20running%20but%20the%20state%20of%20the%20container%20will%20be%20flushed%20when%20the%20container%20restarts.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1153575%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1153575%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F398823%22%20target%3D%22_blank%22%3E%40Arunesh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethat%20wasn't%20it%20though%20in%20my%20case%2C%20%3CSTRIKE%3Eturns%20out%20this%20feature%20is%20the%20culprit%3C%2FSTRIKE%3E%3C%2FP%3E%3CP%3E%3CSTRIKE%3Ewhich%20is%20a%20flag%20and%20apparently%20enabled%20by%20default%3F%3C%2FSTRIKE%3E%3C%2FP%3E%3CH3%20id%3D%22toc-hId-1085368756%22%20id%3D%22toc-hId-1085368756%22%20id%3D%22toc-hId-1085368756%22%20id%3D%22toc-hId-1085368756%22%20id%3D%22toc-hId-1085368756%22%3E%3CSTRIKE%3EApplication%20Guard%26nbsp%3BPrelaunch%3C%2FSTRIKE%3E%3C%2FH3%3E%3CP%3E%3CSTRIKE%3EIf%20enabled%2C%20Microsoft%20Edge%20Application%20Guard%20will%20be%20prelaunched%20in%20the%20background%20when%20recently%20used.%20%E2%80%93%20Windows%3C%2FSTRIKE%3E%3C%2FP%3E%3CP%3E%3CSTRIKE%3E%3CA%20href%3D%22edge%3A%2F%2Fflags%2F%23edge-wdag-prelaunch%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%23edge-wdag-prelaunch%3C%2FA%3E%3C%2FSTRIKE%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewhen%20the%20prelaunch%20happens%20and%20i%20can%20see%20it%20happen%20in%20the%20task%20manager%2C%20so%20when%20it%20happens%2C%20the%20data%20is%20not%20flushed%2C%20it%20is%20retained%20until%20a%20specific%20time%20is%20past%20and%20then%20Edge%20flushes%20it.%3C%2FP%3E%3CP%3EI%20don't%20know%20how%20many%20minutes%20or%20hours%20it%20takes%2C%20no%20information%20available%20about%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebut%20i'm%20sure%20it%20wasn't%20a%20policy%2C%20this%20is%20my%20own%20personal%20system%20and%20i%20never%20set%20anything%20like%20that.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1165861%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1165861%22%20slang%3D%22en-US%22%3E%3CUL%3E%3CLI%3EI'm%20on%20Windows%2010%20insider%20fast%20ring%20build%2019559%20x64.%3C%2FLI%3E%3CLI%3EI%20didn't%20set%20any%20policies%20manually.%3C%2FLI%3E%3CLI%3EI%20don't%20know%20where%20that%20policy%20is%20exactly%2C%20it's%3CFONT%20color%3D%22%23FF0000%22%3E%3CSTRONG%3E%20Not%3C%2FSTRONG%3E%3C%2FFONT%3E%20here%3A%3CSTRONG%3E%20Computer%20Configuration%20%26gt%3B%20Administrative%20Templates%20%26gt%3B%20Windows%20Components%20%26gt%3B%20Windows%20Defender%20Application%20Guard%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fwindows-insider-program%2Fwindows-defender-application-guard-update-persistence%2Fm-p%2F82505%22%20target%3D%22_self%22%3Ebased%20on%20this%20post%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EI%20only%20have%20%22Windows%20Defender%20SmartScreen%22%20policy%20in%20there.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EThis%20is%20my%20Windows%20Defender%20settings%20(I%20don't%20use%203rd%20party%20AV)%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22trtete.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170258i11BFC2CFF723E583%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22trtete.png%22%20alt%3D%22trtete.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EEdge%20Application%20Guard%20data%20is%20not%20flushed%20(the%20extension%20is%20still%20installed)%2C%20I%20even%20waited%2030%20minutes%20and%20then%20opened%20Application%20Guard%20in%20Edge%20again%2C%20the%20extension%20was%20still%20there.%3C%2FLI%3E%3CLI%3Ethe%20only%20way%20to%20flush%20it%20is%20a%20system%20restart.%3C%2FLI%3E%3CLI%3EMicrosoft%20Edge%20canary%20Version%2082.0.421.0%20(Official%20build)%20canary%20(64-bit)%3C%2FLI%3E%3C%2FUL%3E%3CUL%3E%3CLI%3EThe%20flag%20%3CEM%3E%22Application%20Guard%20Prelaunch%22%3C%2FEM%3E%20had%20no%20effect.%20I%20tried%20enabling%2Fdisabling%20it%2C%20I%20got%20the%20same%20result%20every%20time.%3C%2FLI%3E%3CLI%3ENot%20sure%20if%20it's%20relevant%20but%20I%20have%20Windows%20Sandbox%20and%20Hyper-V%20features%20enabled%20on%20my%20Windows%20PC.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EHope%20this%20info%20help%20solve%20the%20issue%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1170585%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1170585%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3BThis%20all%20sounds%20as%20expected%20behavior.%20With%20persistence%20disabled%2C%20the%20extensions%20(and%20other%20settings%2Fdata)%20will%20persist%20as%20long%20as%20the%20container%20VM%20exists%20(it%20will%20be%20destroyed%20when%20the%20host%20shuts%20down).%20The%20container%20VM%20might%20be%20destroyed%20before%20that%20--%20you%20can%20force%20the%20issue%20by%20restarting%20the%20hvsics%20service%20for%20example.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20see%20if%20you%20have%20persistence%20policy%20on%2Foff%20at%26nbsp%3B%3CA%20href%3D%22edge%3A%2F%2Fapplication-guard-internals%2F%23host%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eedge%3A%2F%2Fapplication-guard-internals%2F%23host%3C%2FA%3E%26nbsp%3B(look%20for%20%22container%20persistence%22%20in%20the%20%22Policies%22%20section).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20would%20be%20unexpected%20for%20the%20extension%20settings%20to%20outlive%20the%20container%20(when%20persistence%20is%20disabled)%20--%20that%20they%20are%20going%20away%20with%20a%20restart%20indicates%20this%20is%20all%20working.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETying%20the%20profile%20(settings)%20lifetime%20to%20the%20browser%20lifetime%20(instead%20of%20the%20container%20lifetime)%20is%20something%20we%20are%20discussing%20internally.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1171551%22%20slang%3D%22en-US%22%3ERe%3A%20Extensions%20are%20remembered%20in%20Application%20Guard%20mode%20after%20fully%20closing%20it%20and%20the%20Edge%20browser%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1171551%22%20slang%3D%22en-US%22%3EThank%20you%20very%20much%20for%20the%20explanation%2C%3CBR%20%2F%3E%3CBR%20%2F%3E%22Tying%20the%20profile%20(settings)%20lifetime%20to%20the%20browser%20lifetime%20(instead%20of%20the%20container%20lifetime)%20is%20something%20we%20are%20discussing%20internally.%22%3CBR%20%2F%3E%3CBR%20%2F%3EThat%20was%20exactly%20what%20I%20was%20expecting%20to%20happen.%20because%20I%20see%20how%20Windows%20Sandbox%20(container%3F)%20works%20(closing%20it%20flushes%20everything)%20and%20I%20thought%20Windows%20Defender%20Application%20Guard%20container%20would%20have%20the%20same%20behavior%20but%20now%20I%20see%20they%20have%20different%20behaviors.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Highlighted
Honored Contributor

Version 81.0.410.0 (Official build) canary (64-bit)

 

I went to WDAG mode window, installed an extension from Microsoft add-on store, continued browsing the web for few minutes, then i closed the Application Guard window and closed Edge.

waited approx 1 or 2 minutes, launched Edge canary again and started a new Application Guard window, then I noticed the extension that I had installed is still in there!

 

that was absolutely not what I expected, the Application Guard window should flush itself and clear all of user data once closed.

 

DSDA.png

 

 

6 Replies
Highlighted

@HotCakeX - Thanx for the feedback. Currently the functionality is when "Allow Data persistence For ..." policy is enabled on the device. The Application Guard will persist the previous state. If this policy is turned off the state is flushed on container startup. 

Highlighted

Hi @Arunesh 

that wasn't it though in my case, turns out this feature is the culprit

which is a flag and apparently enabled by default?

Application Guard Prelaunch

If enabled, Microsoft Edge Application Guard will be prelaunched in the background when recently used. – Windows

#edge-wdag-prelaunch

 

when the prelaunch happens and i can see it happen in the task manager, so when it happens, the data is not flushed, it is retained until a specific time is past and then Edge flushes it.

I don't know how many minutes or hours it takes, no information available about it.

 

but i'm sure it wasn't a policy, this is my own personal system and i never set anything like that.

Highlighted
The Prelaunch feature is to improve the performance of Application Guard. This may hold the container running for 15 mins longer if the host instance is running but the state of the container will be flushed when the container restarts.
Highlighted
  • I'm on Windows 10 insider fast ring build 19559 x64.
  • I didn't set any policies manually.
  • I don't know where that policy is exactly, it's Not here: Computer Configuration > Administrative Templates > Windows Components > Windows Defender Application Guard

based on this post

 

  • I only have "Windows Defender SmartScreen" policy in there.

 

  • This is my Windows Defender settings (I don't use 3rd party AV)

 

trtete.png

 

 

  • Edge Application Guard data is not flushed (the extension is still installed), I even waited 30 minutes and then opened Application Guard in Edge again, the extension was still there.
  • the only way to flush it is a system restart.
  • Microsoft Edge canary Version 82.0.421.0 (Official build) canary (64-bit)
  • The flag "Application Guard Prelaunch" had no effect. I tried enabling/disabling it, I got the same result every time.
  • Not sure if it's relevant but I have Windows Sandbox and Hyper-V features enabled on my Windows PC.

Hope this info help solve the issue

 

Highlighted
Solution

@HotCakeX This all sounds as expected behavior. With persistence disabled, the extensions (and other settings/data) will persist as long as the container VM exists (it will be destroyed when the host shuts down). The container VM might be destroyed before that -- you can force the issue by restarting the hvsics service for example.

 

You can see if you have persistence policy on/off at edge://application-guard-internals/#host (look for "container persistence" in the "Policies" section).

 

It would be unexpected for the extension settings to outlive the container (when persistence is disabled) -- that they are going away with a restart indicates this is all working.

 

Tying the profile (settings) lifetime to the browser lifetime (instead of the container lifetime) is something we are discussing internally.

 

Highlighted
Thank you very much for the explanation,

"Tying the profile (settings) lifetime to the browser lifetime (instead of the container lifetime) is something we are discussing internally."

That was exactly what I was expecting to happen. because I see how Windows Sandbox (container?) works (closing it flushes everything) and I thought Windows Defender Application Guard container would have the same behavior but now I see they have different behaviors.