Prevent profile changes?

%3CLINGO-SUB%20id%3D%22lingo-sub-1123264%22%20slang%3D%22en-US%22%3EPrevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1123264%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20getting%20my%20feet%20wet%20with%20a%20GPO%20for%20Edge.%26nbsp%3B%20My%20preference%20would%20be%20that%20the%20user%20cannot%20create%20or%20delete%20any%20profiles.%26nbsp%3B%20From%20what%20I%20understand%20of%20guest%20profiles%2C%20I'd%20be%20fine%20if%20that%20was%20forced%20all%20the%20time%2C%20but%20I%20can't%20figure%20out%20if%20that%20is%20possible.%26nbsp%3B%20The%20biggest%20thing%20would%20be%20to%20prevent%20creation%20of%20additional%20profiles.%26nbsp%3B%20Is%20that%20possible%3F%26nbsp%3B%20Or%20can%20I%20force%20a%20guest%20profile%20all%20the%20time%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1130209%22%20slang%3D%22en-US%22%3ERe%3A%20Prevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1130209%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3Eyou%20can%20use%20this%20policy%20to%20disable%20Guest%20profiles%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fenterprise-state-roaming-enable%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fenterprise-state-roaming-enable%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3Emore%20sign%20in%20policies%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%23browsersignin%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%23browsersignin%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%23restrictsignintopattern%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%23restrictsignintopattern%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1138290%22%20slang%3D%22en-US%22%3ERe%3A%20Prevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1138290%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOf%20course...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSPAN%3EEnterprise%20State%20Roaming%20is%20available%20to%20any%20organization%20with%20an%20Azure%20AD%20Premium%20or%20Enterprise%20Mobility%20%2B%20Security%20(EMS)%20license.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ESo%2C%20not%20generally%20available%20in%20group%20policies%20is%20what%20I'm%20reading.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1138356%22%20slang%3D%22en-US%22%3ERe%3A%20Prevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1138356%22%20slang%3D%22en-US%22%3EFor%20syncing%20with%20Microsoft%20work%20accounts%20yes%20it's%20necessary%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1138390%22%20slang%3D%22en-US%22%3ERe%3A%20Prevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1138390%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPerhaps%20I'm%20not%20in%20the%20right%20area%20then.%26nbsp%3B%20All%20I%20would%20like%20is%20to%20prevent%20profile%20creation%20in%20Edge%20Chromium%20using%20a%20group%20policy%20in%20an%20Active%20Directory%20environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1139123%22%20slang%3D%22en-US%22%3ERe%3A%20Prevent%20profile%20changes%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1139123%22%20slang%3D%22en-US%22%3EYou%20can%20view%20the%20full%20available%20policies%20in%20here%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-policies%3C%2FA%3E%3CBR%20%2F%3EI%20didn't%20come%20across%20anything%20that%20would%20do%20that%3C%2FLINGO-BODY%3E
New Contributor

Just getting my feet wet with a GPO for Edge.  My preference would be that the user cannot create or delete any profiles.  From what I understand of guest profiles, I'd be fine if that was forced all the time, but I can't figure out if that is possible.  The biggest thing would be to prevent creation of additional profiles.  Is that possible?  Or can I force a guest profile all the time?

5 Replies

@HotCakeX 

Of course...

 

"Enterprise State Roaming is available to any organization with an Azure AD Premium or Enterprise Mobility + Security (EMS) license."

 

So, not generally available in group policies is what I'm reading.

 

For syncing with Microsoft work accounts yes it's necessary

@HotCakeX 

Perhaps I'm not in the right area then.  All I would like is to prevent profile creation in Edge Chromium using a group policy in an Active Directory environment.

 

You can view the full available policies in here:
https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies
I didn't come across anything that would do that