Category: At least Internet Explorer 6.0 in Windows XP with Service Pack 2 or Windows Server 2003 with Service Pack 1
Launching applications and files in an IFRAME
This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone. If you enable this policy setting users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone. If you disable this policy setting users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone. If you do not configure this policy setting users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.
Launching applications and files in an IFRAME
This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone. If you enable this policy setting users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone. If you disable this policy setting users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone. If you do not configure this policy setting users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.
Logon options
This policy setting allows you to manage settings for logon options. If you enable this policy setting you can choose from the following logon options. Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol. Prompt for user name and password to query users for user IDs and passwords. After a user is queried these values can be used silently for the remainder of the session. Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried these values can be used silently for the remainder of the session. Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server the logon uses the user’s network user name and password for logon. If Windows NT Challenge Response is not supported by the server the user is queried to provide the user name and password. If you disable this policy setting logon is set to Automatic logon only in Intranet zone. If you do not configure this policy setting logon is set to Automatic logon only in Intranet zone.
Logon options
This policy setting allows you to manage settings for logon options. If you enable this policy setting you can choose from the following logon options. Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol. Prompt for user name and password to query users for user IDs and passwords. After a user is queried these values can be used silently for the remainder of the session. Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried these values can be used silently for the remainder of the session. Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server the logon uses the user’s network user name and password for logon. If Windows NT Challenge Response is not supported by the server the user is queried to provide the user name and password. If you disable this policy setting logon is set to Automatic logon only in Intranet zone. If you do not configure this policy setting logon is set to Automatic logon only in Intranet zone.
Enable MIME Sniffing
This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature. If you enable this policy setting the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature. If you disable this policy setting the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone as dictated by the feature control setting for the process. If you do not configure this policy setting the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone as dictated by the feature control setting for the process.
Enable MIME Sniffing
This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature. If you enable this policy setting the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature. If you disable this policy setting the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone as dictated by the feature control setting for the process. If you do not configure this policy setting the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone as dictated by the feature control setting for the process.
Download unsigned ActiveX controls
This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful especially when coming from an untrusted zone. If you enable this policy setting users can run unsigned controls without user intervention. If you select Prompt in the drop-down box users are queried to choose whether to allow the unsigned control to run. If you disable this policy setting users cannot run unsigned controls. If you do not configure this policy setting users cannot run unsigned controls.
Allow drag and drop or copy and paste files
This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone. If you enable this policy setting users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box users are queried to choose whether to drag or copy files from this zone. If you disable this policy setting users are prevented from dragging files or copying and pasting files from this zone. If you do not configure this policy setting users can drag files or copy and paste files from this zone automatically.
Allow drag and drop or copy and paste files
This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone. If you enable this policy setting users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box users are queried to choose whether to drag or copy files from this zone. If you disable this policy setting users are prevented from dragging files or copying and pasting files from this zone. If you do not configure this policy setting users can drag files or copy and paste files from this zone automatically.
Allow file downloads
This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download not the zone from which the file is delivered. If you enable this policy setting files can be downloaded from the zone. If you disable this policy setting files are prevented from being downloaded from the zone. If you do not configure this policy setting files can be downloaded from the zone.