Allow scripting of Internet Explorer WebBrowser controls

This policy setting determines whether a page can control embedded WebBrowser controls via script. If you enable this policy setting script access to the WebBrowser control is allowed. If you disable this policy setting script access to the WebBrowser control is not allowed. If you do not configure this policy setting the user can enable or disable script access to the WebBrowser control. By default script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.

Turn off . NET Framework Setup

This policy setting prevents the user’s computer from starting Microsoft . NET Framework Setup when the user is browsing to . NET Framework content in Internet Explorer. The . NET Framework is the next-generation platform for Windows. It uses the common language runtime and incorporates support from multiple developer tools. It includes the new managed code APIs for Windows. If you enable this policy setting . NET Framework Setup is turned off. The user cannot change this behavior. If you disable this policy setting . NET Framework Setup is turned on. The user cannot change this behavior. If you do not configure this policy setting . NET Framework Setup is turned on by default. The user can change this behavior.

Allow loading of XAML files

This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation. If you enable this policy setting and set the drop-down box to Enable XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt the user is prompted for loading XAML files. If you disable this policy setting XAML files are not loaded inside Internet Explorer. The user cannot change this behavior. If you do not configure this policy setting the user can decide whether to load XAML files inside Internet Explorer.

Allow loading of XPS files

This policy setting allows you to manage the loading of XPS files. These files contain a fixed-layout representation of paginated content and are portable across platforms devices and applications. If you enable this policy setting and set the drop-down box to Enable XPS files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt the user is prompted for loading XPS files. If you disable this policy setting XPS files are not loaded inside Internet Explorer. The user cannot change this behavior. If you do not configure this policy setting the user can decide whether to load XPS files inside Internet Explorer.

Access data sources across domains

This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO). If you enable this policy setting users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone. If you disable this policy setting users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you do not configure this policy setting users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.

Include local path when user is uploading files to a server

This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent some information may be unintentionally revealed to the server. For instance files sent from the user’s desktop may contain the user name as a part of the path. If you enable this policy setting path information is sent when the user is uploading a file via an HTML form. If you disable this policy setting path information is removed when the user is uploading a file via an HTML form. If you do not configure this policy setting the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default path information is sent.

Turn on SmartScreen Filter scan

This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content. If you enable this policy setting SmartScreen Filter scans pages in this zone for malicious content. If you disable this policy setting SmartScreen Filter does not scan pages in this zone for malicious content. If you do not configure this policy setting the user can choose whether SmartScreen Filter scans pages in this zone for malicious content. Note: In Internet Explorer 7 this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.

Allow updates to status bar via script

This policy setting allows you to manage whether script is allowed to update the status bar within the zone. If you enable this policy setting script is allowed to update the status bar. If you disable or do not configure this policy setting script is allowed to update the status bar.

Turn on Protected Mode

This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system. If you enable this policy setting Protected Mode is turned on. The user cannot turn off Protected Mode. If you disable this policy setting Protected Mode is turned off. The user cannot turn on Protected Mode. If you do not configure this policy setting the user can turn on or turn off Protected Mode.