User Profile
Gunnar-Haslinger
Iron Contributor
Joined 9 years ago
User Widgets
Recent Discussions
Re: Make Edge Beta Default
Deleted if your System doesn't offer to select Edge Beta as Default Browser something seems to be wrong. Of course it should show up for Selection in Start > Settings > Apps > Default apps. -> Search for "Edge Beta" and configure it as Default Browser.900Views0likes0CommentsRe: Make Edge Beta Default
Why you like to use "SetDefaultBrowser.exe" which is a tool for automating Settings during Automated/Unattended-Deployment if you are "new to computers"? This is not a tool an End-User needs, this is a tool for IT-Professionals. As an End-User just use the GUI to configure your default Browser. But to answer your question: If you like to use the Tool without providing full path name you have to put it in a folder which is included in the %PATH% Variable.950Views0likes2CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Currently there is no known Issue with Edge v120 regarding Policy HomePageLocation. So I guess your issue is not related to this Thread. I suggest to check out edge://Policy for debugging and check if the needed prerequisites (Windows Pro/Enterprise, Managed Device) are fulfilled.963Views0likes0CommentsRe: Bug in Edge Policy Handling: This policy is blocked - its value will be ignored.
JoshGardner luckily there is a great Blog post about your question I wrote some years ago: https://hitco.at/blog/apply-edge-policies-for-non-domain-joined-devices/ ... I'm sure you will like this solution 😉1.5KViews0likes0CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Kelly_Y I can now confirm, that in the "single MSA Profile Sync Szenario" the filtered Edge Policies are now working again on following Versions: Edge Dev Version 117.0.2045.7 Edge Canary Version 118.0.2057.0 Still unchanged (not working) are those Versions which didn't get an Update so far: Edge Beta Version 116.0.1938.54 Edge Stable Version 116.0.1938.54 Tested on both OSes: Windows 10 v22H2 as well as Windows 11 v22H2.5.8KViews2likes7CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Robert_Holcombe there is no Update offered to my clients here. Still unchanged Version 116.0.1938.54 Stable, behaviour unchanged as described. Even tried to download a Fresh MSI-File from https://www.microsoft.com/de-de/edge/business/download?form=MA13FJ but it is identically, unchanged - Authenticode signed last Friday. So I will patiently wait to make the magic happen 😉6.6KViews3likes1CommentRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Kelly_Y Restarting Edge Browser doesn't change anything Sign out from MSA and restart Browser: now (with disabled sync) the Policies are OK and work Sign in again to enable Sync, restart Browser -> Problem is back, Policies show up "ignored" and don't work as before.6.7KViews0likes3CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Thanks Kelly_Y, but I checked both Edge Stable 116.0.1938.54 as well as Beta 116.0.1938.54 ... no newer update is offered and behaviour is as already described, only one single MSA Profile is configured and the policies show up as "ignored" as already screenshotted.6.7KViews0likes10CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
TairikuOkami as a (temporary) Workaround you can set the Policy RestrictSigninToPattern to something like ".@no-signin-allowed". HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge -> RestrictSigninToPattern (Type: Reg-SZ) Value e.g.: ".*@no-signin-allowed" If you do this (and restart Edge, I needed to restart twice) the Sync with personal Microsoft Accounts gets paused and the Policies work again.6.9KViews1like20CommentsEdge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
On most current Edge Beta & DEV Versions there is a NEW BUG regarding accepting the Configuration of "sensitive Policies" which need the device to be Enterprise Managed (AD-Join or MDM-Enrolled). [Edit on next day 22.08.2023: see newer post below, not only sensitive Policies but much more policies are ignored! Therefore I modified the title of this Discussion and removed "sensitive"] First, the affected Versions are: Beta: Version 116.0.1938.54 Dev: Version 117.0.2045.1 NOT affected, still working as expected is: Stable: Version 115.0.1901.203 To reproduce the issue, use a Windows 10 or Windows 11 22H2 Machine which is MDM-Enrolled. Fresh Edge-Browser install, first NO Profile Sync / logged on User Account in Edge: OK; Policies work, are applied - as you see in this screenshot: Now enable Profile-Sync / log on with personal Microsoft Account in Edge Browser (Profile). After Syncing Profile now restart Browser. => Problem: Device is not recognised as "MDM-Enrolled" any more, the "sensitive policies" are now ignored: If you "sign out" (no need to delete Favorites, just "sign out" is enough) the policies start working again after next browser-start: As I already said in the beginning, this is "brand new" problem in the most recent Beta- and DEV-Version. Was definitely not there in the last Beta-Version last week before (I think Beta Version 116.0.1938.51 was still OK). And Problem is not there in current Stable, only in Beta&Dev. So please look into this and fix this before it gets into Stable! Thank you! mkruger& Kelly_Y I hope you are still working on the Edge team and can bring this to the attention of the right person? Thank you! Not sure if this is an Edge Issue or an underlying Chromium-Issue. If it is a Chromium-Issue it maybe could be this Change: https://chromium-review.googlesource.com/c/chromium/src/+/4762065/1?tab=commentsSolved10KViews1like26CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Robert_Holcombe yes, I think your troubles are related to my Issue described above. Last night (August 21st to 22nd) new Edge v116.0.1938.54 Stable got rolled out via EdgeUpdate. Yesterday I wrote (see post above), that STABLE v115 is not affected so far. Today with the rollout of v116 now all machines using Stable are affected. You are listing some affected policies: InternetExplorerIntegrationLevel, InternetExplorerIntegrationSiteList and EnterpriseModeSiteListManagerAllowed - but those three policies are NOT so called "sensitive Policies" Yesterday when I was writing my initial post above I thought only the "sensitive Policies" are affected. "Sensitive Policies" are Policies like e.g. those: DefaultSearchProviderEnabled PreventSmartScreenPromptOverride SmartScreenAllowListDomains HomepageIsNewTabPage HomepageLocation NewTabPageLocation RestoreOnStartup RestoreOnStartupURLs AutoOpenFileTypes CustomHelpLink All "Sensitive Policies" are marked in the Microsoft Edge Policy Documentation as "This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro, or Enterprise instances enrolled for device management." BUT: You are right, not only "Sensitive Policies" are affected by this behaviour but also most of the other policies are affected and show up as ignored. It seems Kelly_Y has already pointed out the right core issue, it is Edge for Business added with v116. But according to the documentation and FAQ for Edge for Business it should not be activated by default without having a work-profile. Here we find the list of Policies which are filtered out as ignored when "Edge for Business" is used with an Enterprise personal browser (MSA profile) ... and "Signing in" with a personal Microsoft Account to get Favorites synced seem to kick in this filtered mode regardless of Edge for Business is used or not. In my case it is NOT used, not activated. No visual signs like the "Icon updated with the briefcase" shows up. There is no "one-time banner will appear at the top of the browser after first launching Edge for Business informing the user of the change with a link to learn more". Nothing of this described experiences which would give me an information that "Edge for Business" is activated are shown. No Idea why the "Edge for Business" behaviour for a Browser only having a single Profile (which is a "Personal Profile") kicks in. There is NO Work Profile configured / available, so no Idea why Edge thinks it should filter the policies out from the single profile available. We are not using Entra ID (which I read would enable Edge for Business by default). So for me stripping out almost all policies we set because user is "Signed in" with a personal Microsoft Account is a huge issue. If this is not a bug but a wanted behaviour by Microsoft they really immediately have to add a policy to configure this / turn this off. I understand the concept of "Edge for Business" to have a Work-Profile having assigned the policies and a Personal-Profile having stripped off most of the Policies. But in my case there is no Work-Profile and Edge for Business is not used. So with Edge v116 all Users can just disable almost all Policies by just signing in with a Microsoft Account to sync their Favorites. Thats crazy. Asking Kelly_Y , mkruger for help and advice.6.9KViews4likes22CommentsRe: edge 116 does not work ie mode by enterprise site list(when login edge proflie)
lee_1_1 it seems Microsoft strips out almost all policies when you are "signed in" in Browser with a personal Microsoft Account now with Edge v116 (Edge for Business). For me this behaviour even if there is no Work-Profile configured (which would enable Edge for Business) is crazy, see my post here.5.1KViews1like5CommentsRe: Edge 116 Beta: Policies are blocked if MDM-Managed & Userprofile-Sync personal Account
Thanks Kelly_Y for the pointer to Edge for business, but no. Not using Edge for Business Preview and even not using Azure AD (Microsoft Entra ID login). Problem as described above, not Edge for business related. - Gunnar7.1KViews0likes0CommentsRe: Edge v93 - v96 opens .MHT Files but shows no content ("white page")
Without setting policies .mht Files like I published in the given examples above won't work in Edge v113. To get them to open in IE-Mode use following Policies: 1. Set "InternetExplorerIntegrationLevel" (I used Level 1 to test). 2. Set "InternetExplorerIntegrationLocalMhtFileAllowed" to 1 3. Set "InternetExplorerIntegrationLocalFileExtensionAllowList" -> "1" -> ".mht" with those 3 policies set my Edge v113 opens .mht Files in IE-Mode by default and renders them correctly. Here a Screenshot of my policies, filtered by "InternetExplorer": Here a Link to my Test-MHT-Files: https://hitco.at/mht-test/ Here a Screenshot of an random .mht File, automatically opened in IE-Mode:7.3KViews0likes1CommentRe: Dev Channel update to 109.0.1495.2 is live
AndresPae yes, I think you understand it wrong. And I think the article is written misleading. There is this small sentence which should get your attention: In addition to trusting the built-in roots that ship with Microsoft Edge, the browser will also query the underlying platform for—and trust—locally installed roots that users and/or enterprises installed. so in fact nothing seems to change for Enterprise-CAs deployed to Windows-OS-CertStore. See this Blog-Post here, which is written much clearer than the official documentation: https://textslashplain.com/2022/12/06/tls-certificate-verification-changes-in-edge/ This blog is written by https://twitter.com/ericlaw who is working at MSFT/Edge4.1KViews0likes1CommentRe: Dev Channel update to 109.0.1495.2 is live
Thanks Eric_E for your reply. but what's missing is not the Policy-Documentation (this is a simple on/off policy - so the documentation is fine) but the Information about how to add own Enterprise CAs, SubCAs to MicrosoftRootStore of Edge. In this announcement Microsoft tells us: Microsoft recommends that enterprises that have break-and-inspect proxies or other scenarios involving TLS server certificates issued by roots not in the Microsoft CTL to proactively test with the policy enabled in Microsoft Edge 109 and report any compatibility issues to Microsoft. OK. So where to report? We cannot start the test because Information on how to configure this is missing. Please update / add Information to the announcement and provide documentation.5.8KViews0likes0CommentsRe: Dev Channel update to 109.0.1495.2 is live
where can I find Information about how to add own Enterprise CAs, SubCAs to MicrosoftRootStore of Edge when the MicrosoftRootStoreEnabled Feature is turned on? I currently have to add several CAs to the Windows 10 Certificate Store, as I understand in future Versions of Edge I would have to add them to the internal Edge MicrosoftRootStore too. How to do this automated during deployment? Where can I find documentation about this? On this page I can only find the timeline of Edge v109 to Edge v111 and the Policy itself but no link to details.5.9KViews0likes5CommentsRe: SmartScreen turned off -> Java Webstart JNLP Files are marked as "can harm your computer"
HowonChoi I have no Idea what you like to tell or ask. Using edge://policy to view your current settings offers no GUI to change the according Registry-Keys directly in Edge. Use MDM, GroupPolicies or directly edit the Registry-Keys according to your needs / Management-System. You find the Policy Reference here: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies3.3KViews0likes0Comments
Recent Blog Articles
No content to show