Post updated in September 2025.
Testing Safe Edge
This thread is about an experimental Edge web browser setup for kids or casual users. Please test it in a Virtual Machine.
Users' feedback is welcome.
After conducting some research, I compiled a list of useful Edge Policies focused on browsing security.
Unfortunately, some useful policies are blocked for non-enterprise users. However, there is a known tweak (Fake-MDM-Provider) that enables those policies for all users:
I had to add one setting (ManagedDefenderProductType=0) via Defender policies to work the tweak properly on Windows Home and Pro.
The list of interesting policies:
AudioSandboxEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/audiosandboxenabled
AutoplayAllowed
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/autoplayallowed
BingAdsSuppression
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/bingadssuppression
BlockExternalExtensions
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/blockexternalextensions
BrowserCodeIntegritySetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-policies#browsercodeintegritysetting
BrowserLegacyExtensionPointsBlockingEnabled
https://learn.microsoft.com/en-gb/D...s/browserlegacyextensionpointsblockingenabled
ClearBrowsingDataOnExit
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clearbrowsingdataonexit
ClickOnceEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clickonceenabled
ClipboardBlockedForUrls
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clipboardblockedforurls
DefaultClipboardSetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/defaultclipboardsetting
DefaultCookiesSetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/defaultcookiessetting
DefaultJavaScriptJitSetting
https://learn.microsoft.com/en-gb/D...-browser-policies/defaultjavascriptjitsetting
DefaultSearchProviderEnabled
https://learn.microsoft.com/en-gb/D...browser-policies/defaultsearchproviderenabled
DefaultEearchProviderName
https://learn.microsoft.com/en-gb/D...ge-browser-policies/defaultsearchprovidername
DefaultSearchProviderSearchURL
https://learn.microsoft.com/en-gb/D...owser-policies/defaultsearchprovidersearchurl
DefaultWebUsbGuardSetting
https://learn.microsoft.com/en-gb/D...ge-browser-policies/defaultwebusbguardsetting
DnsOverHttpsMode
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dnsoverhttpsmode
DnsOverHttpsTemplates
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dnsoverhttpstemplates
DownloadRestrictions
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/downloadrestrictions
DynamicCodeSettings
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dynamiccodesettings
EnhanceSecurityMode
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/enhancesecuritymode
ExtensionInstallAllowlist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallallowlist
ExtensionInstallBlocklist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallblocklist
ExtensionInstallForcelist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallforcelist
HideFrstRunExperience (non-security rule)
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/hidefirstrunexperience
HttpsUpgradesEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/httpsupgradesenabled
NetworkServiceSandboxEnabled
https://learn.microsoft.com/en-gb/D...browser-policies/networkservicesandboxenabled
NotifyDisableIEOptions
https://kb.cybertecsecurity.com/knowledge/removing-internet-explorer
PasswordDeleteOnBrowserCloseEnabled
https://learn.microsoft.com/en-us/d...-policies/passworddeleteonbrowsercloseenabled
PreventSmartscreenPromptOverride
https://learn.microsoft.com/en-gb/D...ser-policies/preventsmartscreenpromptoverride
PreventSmartscreenPromptOverrideForFiles
https://learn.microsoft.com/en-gb/D...cies/preventsmartscreenpromptoverrideforfiles
QuickViewOfficeFilesEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/quickviewofficefilesenabled
RendererAppContainerEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/rendererappcontainerenabled
RestoreOnStartupURLs
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/restoreonstartupurls
SandboxExternalProtocolBlocked
https://learn.microsoft.com/en-gb/D...owser-policies/sandboxexternalprotocolblocked
SaveCookiesOnExit
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/savecookiesonexit
ScarewareBlockerProtectionEnabled
https://learn.microsoft.com/en-gb/D...er-policies/scarewareblockerprotectionenabled
ScreenCaptureAllowed
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/screencaptureallowed
TyposquattingCheckerEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/typosquattingcheckerenabled
WebRtcLocalhostIpHandling
https://learn.microsoft.com/en-gb/D...ge-browser-policies/webrtclocalhostiphandling
The settings for casual adult users:
The restrictions can be removed by deleting the Registry keys:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Accounts\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
and:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"ManagedDefenderProductType"=dword:00000000
Those settings prevent most application installations, so the user must use Patch My PC, UniGetUI, Ninite, or Winstall to install new applications.
Browsing data is deleted on exit, except for cookies listed in SaveCookiesOnExit and passwords saved in Edge's password manager.
The Edge extensions are in the allowlist mode, so the user cannot install new extensions except those included in the ExtensionInstallAllowlist.
The DNS Provider is set to "https://doh.cleanbrowsing.org/doh/security-filter".
After applying policies, the security settings are greyed out:
All Edge policies can be seen in Edge by using: Edge://policy
For example:
Testing Safe Edge
This thread is about an experimental Edge web browser setup for kids or casual users. Please test it in a Virtual Machine.
Users' feedback is welcome.
After conducting some research, I compiled a list of useful Edge Policies focused on browsing security.
Unfortunately, some useful policies are blocked for non-enterprise users. However, there is a known tweak (Fake-MDM-Provider) that enables those policies for all users:
I had to add one setting (ManagedDefenderProductType=0) via Defender policies to work the tweak properly on Windows Home and Pro.
Code:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"ManagedDefenderProductType"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
"EnrollmentState"=dword:00000001
"EnrollmentType"=dword:00000000
"IsFederated"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Accounts\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
"Flags"=dword:00d6fb7f
"AcctUId"="0x000000000000000000000000000000000000000000000000000000000000000000000000"
"RoamingCount"=dword:00000000
"SslClientCertReference"="MY;User;0000000000000000000000000000000000000000"
"ProtoVer"="1.2"
The list of interesting policies:
AudioSandboxEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/audiosandboxenabled
AutoplayAllowed
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/autoplayallowed
BingAdsSuppression
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/bingadssuppression
BlockExternalExtensions
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/blockexternalextensions
BrowserCodeIntegritySetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-policies#browsercodeintegritysetting
BrowserLegacyExtensionPointsBlockingEnabled
https://learn.microsoft.com/en-gb/D...s/browserlegacyextensionpointsblockingenabled
ClearBrowsingDataOnExit
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clearbrowsingdataonexit
ClickOnceEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clickonceenabled
ClipboardBlockedForUrls
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/clipboardblockedforurls
DefaultClipboardSetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/defaultclipboardsetting
DefaultCookiesSetting
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/defaultcookiessetting
DefaultJavaScriptJitSetting
https://learn.microsoft.com/en-gb/D...-browser-policies/defaultjavascriptjitsetting
DefaultSearchProviderEnabled
https://learn.microsoft.com/en-gb/D...browser-policies/defaultsearchproviderenabled
DefaultEearchProviderName
https://learn.microsoft.com/en-gb/D...ge-browser-policies/defaultsearchprovidername
DefaultSearchProviderSearchURL
https://learn.microsoft.com/en-gb/D...owser-policies/defaultsearchprovidersearchurl
DefaultWebUsbGuardSetting
https://learn.microsoft.com/en-gb/D...ge-browser-policies/defaultwebusbguardsetting
DnsOverHttpsMode
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dnsoverhttpsmode
DnsOverHttpsTemplates
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dnsoverhttpstemplates
DownloadRestrictions
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/downloadrestrictions
DynamicCodeSettings
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/dynamiccodesettings
EnhanceSecurityMode
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/enhancesecuritymode
ExtensionInstallAllowlist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallallowlist
ExtensionInstallBlocklist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallblocklist
ExtensionInstallForcelist
https://learn.microsoft.com/en-gb/D...ge-browser-policies/extensioninstallforcelist
HideFrstRunExperience (non-security rule)
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/hidefirstrunexperience
HttpsUpgradesEnabled
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/httpsupgradesenabled
NetworkServiceSandboxEnabled
https://learn.microsoft.com/en-gb/D...browser-policies/networkservicesandboxenabled
NotifyDisableIEOptions
https://kb.cybertecsecurity.com/knowledge/removing-internet-explorer
PasswordDeleteOnBrowserCloseEnabled
https://learn.microsoft.com/en-us/d...-policies/passworddeleteonbrowsercloseenabled
PreventSmartscreenPromptOverride
https://learn.microsoft.com/en-gb/D...ser-policies/preventsmartscreenpromptoverride
PreventSmartscreenPromptOverrideForFiles
https://learn.microsoft.com/en-gb/D...cies/preventsmartscreenpromptoverrideforfiles
QuickViewOfficeFilesEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/quickviewofficefilesenabled
RendererAppContainerEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/rendererappcontainerenabled
RestoreOnStartupURLs
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/restoreonstartupurls
SandboxExternalProtocolBlocked
https://learn.microsoft.com/en-gb/D...owser-policies/sandboxexternalprotocolblocked
SaveCookiesOnExit
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/savecookiesonexit
ScarewareBlockerProtectionEnabled
https://learn.microsoft.com/en-gb/D...er-policies/scarewareblockerprotectionenabled
ScreenCaptureAllowed
https://learn.microsoft.com/en-gb/DeployEdge/microsoft-edge-browser-policies/screencaptureallowed
TyposquattingCheckerEnabled
https://learn.microsoft.com/en-gb/D...-browser-policies/typosquattingcheckerenabled
WebRtcLocalhostIpHandling
https://learn.microsoft.com/en-gb/D...ge-browser-policies/webrtclocalhostiphandling
The settings for casual adult users:
Code:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge]
"AudioSandboxEnabled"=dword:00000001
"AutoplayAllowed"=dword:00000000
"BingAdsSuppression"=dword:00000001
"BrowserCodeIntegritySetting"=dword:00000001
"BrowserLegacyExtensionPointsBlockingEnabled"=dword:00000001
"ClearBrowsingDataOnExit"=dword:00000001
"BlockExternalExtensions"=dword:00000001
"ClickOnceEnabled"=dword:00000000
"ClipboardBlockedForUrls"=dword:00000001
"DefaultClipboardSetting"=dword:00000002
"DefaultCookiesSetting"=dword:00000004
"DefaultJavaScriptJitSetting"=dword:00000002
"DefaultSearchProviderEnabled"=dword:00000001
"DefaultSearchProviderName"="Google-Policy-Locked"
"DefaultSearchProviderSearchURL"="{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}"
"DefaultWebUsbGuardSetting"=dword:00000002
"DnsOverHttpsMode"="automatic"
"DnsOverHttpsTemplates"="https://doh.cleanbrowsing.org/doh/security-filter{?dns}"
"DownloadRestrictions"=dword:00000001
"DynamicCodeSettings"=dword:00000001
"EnhanceSecurityMode"=dword:00000002
"HideFirstRunExperience"=dword:00000001
"HttpsUpgradesEnabled"=dword:00000001
"NetworkServiceSandboxEnabled"=dword:00000001
"PasswordDeleteOnBrowserCloseEnabled"=dword:00000001
"PreventSmartScreenPromptOverride"=dword:00000001
"PreventSmartScreenPromptOverrideForFiles"=dword:00000001
"SmartScreenEnabled"=dword:00000001
"SmartScreenPuaEnabled"=dword:00000001
"ScarewareBlockerProtectionEnabled"=dword:00000001
"QuickViewOfficeFilesEnabled"=dword:00000001
"RendererAppContainerEnabled"=dword:00000001
"SandboxExternalProtocolBlocked"=dword:00000001
"ScreenCaptureAllowed"=dword:00000000
"SitePerProcess"=dword:00000001
"TyposquattingCheckerEnabled"=dword:00000001
"WebRtcLocalhostIpHandling"="DisableNonProxiedUdp"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ClipboardBlockedForUrls]
"1"="[*.]*"
# Must be edited to add required extensions
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallAllowlist]
"1"="cnlefmmeadmemmdciolhbnfeacpdfbkd"
"2"="ghbmnnjooekpmoecnnnilnnbdlolhkhi"
"3"="jbkfoedolllekgbhcbcoahefnbanhhlh"
"4"="pdffkfellgipmhklpdmokmckkkfcopbh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallBlocklist]
"1"="*"
# Must be edited to add required extensions
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist]
"1"="pdffkfellgipmhklpdmokmckkkfcopbh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\RestoreOnStartupURLs]
"1"="https://www.google.com/"
# Must be edited to add required websites
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\SaveCookiesOnExit]
"1"="[*.]grammarly.com"
"2"="[*.]google.com"
"3"="[*.]msn.com"
"4"="[*.]microsoft.com"
The restrictions can be removed by deleting the Registry keys:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Accounts\FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF]
and:
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"ManagedDefenderProductType"=dword:00000000
Those settings prevent most application installations, so the user must use Patch My PC, UniGetUI, Ninite, or Winstall to install new applications.
Browsing data is deleted on exit, except for cookies listed in SaveCookiesOnExit and passwords saved in Edge's password manager.
The Edge extensions are in the allowlist mode, so the user cannot install new extensions except those included in the ExtensionInstallAllowlist.
The DNS Provider is set to "https://doh.cleanbrowsing.org/doh/security-filter".
After applying policies, the security settings are greyed out:
All Edge policies can be seen in Edge by using: Edge://policy
For example:
Last edited:
