Tag: User Configuration
Local Machine Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Locked-Down Local Machine Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Intranet Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Locked-Down Intranet Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Restricted Sites Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Internet Zone Template
This template policy setting allows you to configure policy settings in this zone consistent with a selected security level for example Low Medium Low Medium or High. If you enable this template policy setting and select a security level all values for individual settings in the zone will be overwritten by the standard template defaults. If you disable this template policy setting no security level is configured. If you do not configure this template policy setting no security level is configured. Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL’s zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security) the same change should be made to the Locked-Down equivalent. Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example precedence inheritance or enforce) to apply individual settings to specific targets.
Allow script-initiated windows without size or position constraints
This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars. If you enable this policy setting Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature. If you disable this policy setting the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process. If you do not configure this policy setting the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.
Web sites in less privileged Web content zones can navigate into this zone
This policy setting allows you to manage whether Web sites from less privileged zones such as Internet sites can navigate into this zone. If you enable this policy setting Web sites from less privileged zones can open new windows in or navigate into this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box a warning is issued to the user that potentially risky navigation is about to occur. If you disable this policy setting the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control. If you do not configure this policy setting the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.
Intranet Sites: Include all local (intranet) sites not listed in other zones
This policy setting controls whether local sites which are not explicitly mapped into any Security Zone are forced into the local Intranet security zone. If you enable this policy setting local sites which are not explicitly mapped into a zone are considered to be in the Intranet Zone. If you disable this policy setting local sites which are not explicitly mapped into a zone will not be considered to be in the Intranet Zone (so would typically be in the Internet Zone). If you do not configure this policy setting users choose whether to force local sites into the Intranet Zone.
Turn on certificate address mismatch warning
This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks. If you enable this policy setting the certificate address mismatch warning always appears. If you disable or do not configure this policy setting the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).