Forum Discussion
Disable EAF for firefox.exe as a part of the security baseline
Hi!
I'm working for Mozilla. We have https://bugzilla.mozilla.org/show_bug.cgi?id=1509748 that Firefox does not launch because EAF is turned on for firefox.exe by the customer's corporate IT policy. Since Firefox does not support EAF, what we can do is to ask customers to disable EAF, but they can't if they don't have admin rights.
The current security baseline contains a script to disable EAF for several executables such as onedrive.exe or acrord32. Could you please add an entry to disable EAF for firefox.exe as well?
I also confirmed Chrome (chrome.exe) and the new MS Edge (msedge.exe) has the same issue.
Thanks,
Toshihito
3 Replies
- Rick_Munck
Microsoft
tokikuch from a security baseline perspective we would not make this change to our baseline as it appears this is something your local IT department changed. The EP-reset.xml that we distribute resets the settings we originally had in EP.xml. If you look in it (EP.xml) we do not mess with EAF for the ones you mention.
What Reza_Ameri-Archived mentions below is your best bet.
- tokikuchCopper Contributor
Rick_MunckOh, I see. It means a previous baseline had enabled EAF for those applications like Adobe. Thanks you for clarifying it!
- Reza_Ameri-ArchivedBronze Contributor
You could configure Exploit Protection , they way you want (like disable EAF for firefox.exe or other apps) and then export it, take a look at:
Then you may use number of ways like Group Policy, MEM ,... to deploy policy and manage it, take a look at: