Tag: Computer Configuration
Submit non-encrypted form data
This policy setting allows you to manage whether data on HTML forms on pages in the zone may be submitted. Forms sent with SSL (Secure Sockets Layer) encryption are always allowed; this setting only affects non-SSL form data submission. If you enable this policy setting information using HTML forms on pages in this zone can be submitted automatically. If you select Prompt in the drop-down box users are queried to choose whether to allow information using HTML forms on pages in this zone to be submitted. If you disable this policy setting information using HTML forms on pages in this zone is prevented from being submitted. If you do not configure this policy setting users are queried to choose whether to allow information using HTML forms on pages in this zone to be submitted.
Turn on Cross-Site Scripting Filter
This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone. If you enable this policy setting the XSS Filter is turned on for sites in this zone and the XSS Filter attempts to block cross-site script injections. If you disable this policy setting the XSS Filter is turned off for sites in this zone and Internet Explorer permits cross-site script injections.
Automatic prompting for ActiveX controls
This policy setting manages whether users will be automatically prompted for ActiveX control installations. If you enable this policy setting users will receive a prompt when a site instantiates an ActiveX control they do not have installed. If you disable this policy setting ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt. If you do not configure this policy setting ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.
Automatic prompting for file downloads
This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting users will receive file download dialogs for user-initiated downloads. If you enable this setting users will receive a file download dialog for automatic download attempts. If you disable or do not configure this setting file downloads that are not user-initiated will be blocked and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.
Run ActiveX controls and plugins
This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone. If you enable this policy setting controls and plug-ins can run without user intervention. If you selected Prompt in the drop-down box users are asked to choose whether to allow the controls or plug-in to run. If you disable this policy setting controls and plug-ins are prevented from running. If you do not configure this policy setting controls and plug-ins can run without user intervention.
Script ActiveX controls marked safe for scripting
This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script. If you enable this policy setting script interaction can occur automatically without user intervention. If you select Prompt in the drop-down box users are queried to choose whether to allow script interaction. If you disable this policy setting script interaction is prevented from occurring. If you do not configure this policy setting script interaction can occur automatically without user intervention.
Don’t run antimalware programs against ActiveX controls
This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls to check if they’re safe to load on pages. If you enable this policy setting Internet Explorer won’t check with your antimalware program to see if it’s safe to create an instance of the ActiveX control. If you disable this policy setting Internet Explorer always checks with your antimalware program to see if it’s safe to create an instance of the ActiveX control. If you don’t configure this policy setting Internet Explorer always checks with your antimalware program to see if it’s safe to create an instance of the ActiveX control. Users can turn this behavior on or off using Internet Explorer Security settings.
Allow active content over restricted protocols to access my computer
This policy setting allows you to manage whether a resource hosted on an admin-restricted protocol in the Intranet Zone can run active content such as script ActiveX Java and Binary Behaviors. The list of restricted protocols may be set in the Intranet Zone Restricted Protocols section under Network Protocol Lockdown policy. If you enable this policy setting no Intranet Zone content accessed is affected even for protocols on the restricted list. If you select Prompt from the drop-down box the Notification bar will appear to allow control over questionable content accessed over any restricted protocols; content over other protocols is unaffected. If you disable this policy setting all attempts to access such content over the restricted protocols is blocked. If you do not configure this policy setting the Notification bar will appear to allow control over questionable content accessed over any restricted protocols when the Network Protocol Lockdown security feature is enabled.
Do not prompt for client certificate selection when no certificates or only one certificate exists.
This policy setting allows you to manage whether users are prompted to select a certificate when no certificate or only one certificate exists. If you enable this policy setting Internet Explorer does not prompt users with a “Client Authentication” message when they connect to a Web site that has no certificate or only one certificate. If you disable this policy setting Internet Explorer prompts users with a “Client Authentication” message when they connect to a Web site that has no certificate or only one certificate. If you do not configure this policy setting Internet Explorer prompts users with a Client Authentication message when they connect to a Web site that has no certificate or only one certificate.
Java permissions
This policy setting allows you to manage permissions for Java applets. If you enable this policy setting you can choose options from the drop-down box. Custom to control permissions settings individually. Low Safety enables applets to perform all operations. Medium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls) plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O. High Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running. If you disable this policy setting Java applets cannot run. If you do not configure this policy setting the permission is set to High Safety.