<?xml version="1.0" encoding="utf-16"?>
<GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings">
  <Identifier>
    <Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types">{5E528929-7FFD-40F2-8C67-57EEBD58BF47}</Identifier>
    <Domain xmlns="http://www.microsoft.com/GroupPolicy/Types">DCC-SCH-4505.local</Domain>
  </Identifier>
  <Name>edge pupil policy</Name>
  <IncludeComments>true</IncludeComments>
  <CreatedTime>2020-06-17T11:05:29</CreatedTime>
  <ModifiedTime>2020-06-17T12:23:42</ModifiedTime>
  <ReadTime>2020-09-30T13:34:46.7095527Z</ReadTime>
  <SecurityDescriptor>
    <SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">O:DAG:DAD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-4210983284-1767645381-1147546538-519)(A;CI;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)(OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)</SDDL>
    <Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
      <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-4210983284-1767645381-1147546538-512</SID>
      <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">DCC-SCH-4505\Domain Admins</Name>
    </Owner>
    <Group xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
      <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-4210983284-1767645381-1147546538-512</SID>
      <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">DCC-SCH-4505\Domain Admins</Name>
    </Group>
    <PermissionsPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">true</PermissionsPresent>
    <Permissions xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
      <InheritsFromParent>false</InheritsFromParent>
      <TrusteePermissions>
        <Trustee>
          <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-4210983284-1767645381-1147546538-512</SID>
          <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">DCC-SCH-4505\Domain Admins</Name>
        </Trustee>
        <Type xsi:type="PermissionType">
          <PermissionType>Allow</PermissionType>
        </Type>
        <Inherited>false</Inherited>
        <Applicability>
          <ToSelf>true</ToSelf>
          <ToDescendantObjects>false</ToDescendantObjects>
          <ToDescendantContainers>true</ToDescendantContainers>
          <ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
        </Applicability>
        <Standard>
          <GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
        </Standard>
        <AccessMask>0</AccessMask>
      </TrusteePermissions>
      <TrusteePermissions>
        <Trustee>
          <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-9</SID>
          <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS</Name>
        </Trustee>
        <Type xsi:type="PermissionType">
          <PermissionType>Allow</PermissionType>
        </Type>
        <Inherited>false</Inherited>
        <Applicability>
          <ToSelf>true</ToSelf>
          <ToDescendantObjects>false</ToDescendantObjects>
          <ToDescendantContainers>true</ToDescendantContainers>
          <ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
        </Applicability>
        <Standard>
          <GPOGroupedAccessEnum>Read</GPOGroupedAccessEnum>
        </Standard>
        <AccessMask>0</AccessMask>
      </TrusteePermissions>
      <TrusteePermissions>
        <Trustee>
          <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-18</SID>
          <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\SYSTEM</Name>
        </Trustee>
        <Type xsi:type="PermissionType">
          <PermissionType>Allow</PermissionType>
        </Type>
        <Inherited>false</Inherited>
        <Applicability>
          <ToSelf>true</ToSelf>
          <ToDescendantObjects>false</ToDescendantObjects>
          <ToDescendantContainers>true</ToDescendantContainers>
          <ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
        </Applicability>
        <Standard>
          <GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
        </Standard>
        <AccessMask>0</AccessMask>
      </TrusteePermissions>
      <TrusteePermissions>
        <Trustee>
          <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-4210983284-1767645381-1147546538-519</SID>
          <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">DCC-SCH-4505\Enterprise Admins</Name>
        </Trustee>
        <Type xsi:type="PermissionType">
          <PermissionType>Allow</PermissionType>
        </Type>
        <Inherited>false</Inherited>
        <Applicability>
          <ToSelf>true</ToSelf>
          <ToDescendantObjects>false</ToDescendantObjects>
          <ToDescendantContainers>true</ToDescendantContainers>
          <ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
        </Applicability>
        <Standard>
          <GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
        </Standard>
        <AccessMask>0</AccessMask>
      </TrusteePermissions>
      <TrusteePermissions>
        <Trustee>
          <SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-11</SID>
          <Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\Authenticated Users</Name>
        </Trustee>
        <Type xsi:type="PermissionType">
          <PermissionType>Allow</PermissionType>
        </Type>
        <Inherited>false</Inherited>
        <Applicability>
          <ToSelf>true</ToSelf>
          <ToDescendantObjects>false</ToDescendantObjects>
          <ToDescendantContainers>true</ToDescendantContainers>
          <ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
        </Applicability>
        <Standard>
          <GPOGroupedAccessEnum>Apply Group Policy</GPOGroupedAccessEnum>
        </Standard>
        <AccessMask>0</AccessMask>
      </TrusteePermissions>
    </Permissions>
    <AuditingPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">false</AuditingPresent>
  </SecurityDescriptor>
  <FilterDataAvailable>true</FilterDataAvailable>
  <Computer>
    <VersionDirectory>0</VersionDirectory>
    <VersionSysvol>0</VersionSysvol>
    <Enabled>true</Enabled>
  </Computer>
  <User>
    <VersionDirectory>25</VersionDirectory>
    <VersionSysvol>25</VersionSysvol>
    <Enabled>true</Enabled>
    <ExtensionData>
      <Extension xmlns:q1="http://www.microsoft.com/GroupPolicy/Settings/Registry" xsi:type="q1:RegistrySettings">
        <q1:Policy>
          <q1:Name>Allow media autoplay for websites</q1:Name>
          <q1:State>Disabled</q1:State>
          <q1:Explain>This policy sets the media autoplay policy for websites.

The default setting, "Not configured" respects the current media autoplay settings and lets users configure their autoplay settings.

Setting to "Enabled" sets media autoplay to "Allow".  All websites are allowed to autoplay media. Users can’t override this policy.

Setting to "Disabled" sets media autoplay to "Block".  No websites are allowed to autoplay media. Users can’t override this policy.

A tab will need to be closed and re-opened for this policy to take effect.
</q1:Explain>
          <q1:Supported>Microsoft Edge version 78, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Block access to a list of URLs</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Define a list of sites, based on URL patterns, that are blocked (your users can't load them).

Format the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.

You can define exceptions in the 'URLAllowlist' (Define a list of allowed URLs) policy. These policies are limited to 1000 entries; subsequent entries are ignored.

Note that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.

This policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.

If you don't configure this policy, no URLs are blocked.

Example value:

contoso.com
https://ssl.server.com
hosting.com/bad_path
https://server:8080/path
.exact.hostname.com
file://*
custom_scheme:*
*</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge</q1:Category>
          <q1:ListBox>
            <q1:Name>Block access to a list of URLs</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:ExplicitValue>false</q1:ExplicitValue>
            <q1:Additive>false</q1:Additive>
            <q1:ValuePrefix />
            <q1:Value>
              <q1:Element>
                <q1:Data>edge://</q1:Data>
              </q1:Element>
              <q1:Element>
                <q1:Data>edge://settings</q1:Data>
              </q1:Element>
            </q1:Value>
          </q1:ListBox>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Force minimum YouTube Restricted Mode</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.

Set to Strict (2) to enforce Strict Restricted Mode on YouTube.

Set to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.

Set to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.

* 0 = Do not enforce Restricted Mode on YouTube

* 1 = Enforce at least Moderate Restricted Mode on YouTube

* 2 = Enforce Strict Restricted Mode for YouTube</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge</q1:Category>
          <q1:DropDownList>
            <q1:Name>Force minimum YouTube Restricted Mode</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>
              <q1:Name>Enforce Strict Restricted Mode for YouTube</q1:Name>
            </q1:Value>
          </q1:DropDownList>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Enable Google Cast</q1:Name>
          <q1:State>Disabled</q1:State>
          <q1:Explain>Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.

Disable this policy to disable Google Cast.

By default, Google Cast is enabled.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Cast</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Default notification setting</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Set whether websites can display desktop notifications. You can allow them by default (1), deny them by default (2), or have the user be asked each time a website wants to show a notification (3).

If you don't configure this policy, notifications are allowed by default, and the user can change this setting.

* 1 = Allow sites to show desktop notifications

* 2 = Don't allow any site to show desktop notifications

* 3 = Ask every time a site wants to show desktop notifications</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Content settings</q1:Category>
          <q1:DropDownList>
            <q1:Name>Default notification setting</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>
              <q1:Name>Don't allow any site to show desktop notifications</q1:Name>
            </q1:Value>
          </q1:DropDownList>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Default search provider search URL</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.

Specify Bing's search URL as:

'{bing:baseURL}search?q={searchTerms}'.

Specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&amp;{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.

This policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored.

Example value: https://search.contoso.com/search?q={searchTerms}</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Default search provider</q1:Category>
          <q1:EditText>
            <q1:Name>Default search provider search URL</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>{google:baseURL}search?q={searchTerms}&amp;{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}</q1:Value>
          </q1:EditText>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Default search provider URL for suggestions</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.

This policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.

Bing's suggest URL can be specified as:

'{bing:baseURL}qbox?query={searchTerms}'.

Google's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&amp;q={searchTerms}'.

This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.

Example value: https://search.contoso.com/suggest?q={searchTerms}</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Default search provider</q1:Category>
          <q1:EditText>
            <q1:Name>Default search provider URL for suggestions</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>{google:baseURL}complete/search?output=chrome&amp;q={searchTerms}</q1:Value>
          </q1:EditText>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Enable the default search provider</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Enables the ability to use a default search provider.

If you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).

You can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.

If you disable this policy, the user can't search from the address bar.

If you enable or disable this policy, users can't change or override it.

If you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Default search provider</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Control which extensions cannot be installed</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.

Use "*" to block all extensions that aren't explicitly listed in the allow list.

If you don't configure this policy, users can install any extension in Microsoft Edge.

Example value:

extension_id1
extension_id2</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Extensions</q1:Category>
          <q1:ListBox>
            <q1:Name>Extension IDs the user should be prevented from installing (or * for all)</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:ExplicitValue>false</q1:ExplicitValue>
            <q1:Additive>false</q1:Additive>
            <q1:ValuePrefix />
            <q1:Value>
              <q1:Element>
                <q1:Data>*</q1:Data>
              </q1:Element>
            </q1:Value>
          </q1:ListBox>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Allow user-level native messaging hosts (installed without admin permissions)</q1:Name>
          <q1:State>Disabled</q1:State>
          <q1:Explain>Enables user-level installation of native messaging hosts.

If you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.

By default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Native Messaging</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure address or URL of proxy server</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specifies the URL of the proxy server.

This policy is applied only if you have selected 'Use fixed proxy servers' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.

If you enable this policy, the proxy server configured by this policy will be used for all URLs.

If you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you've specified any other method for setting proxy policies.

For more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.

Example value: 123.123.123.123:8080</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Proxy server</q1:Category>
          <q1:EditText>
            <q1:Name>Configure address or URL of proxy server</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>sslfilter.proxy.swgfl.org.uk:8080</q1:Value>
          </q1:EditText>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure proxy server settings</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.

If you choose to never use a proxy server and to always connect directly, all other options are ignored.

If you choose to use system proxy settings, all other options are ignored.

If you choose to auto detect the proxy server, all other options are ignored.

If you choose fixed server proxy mode, you can specify further options in 'ProxyServer' (Configure address or URL of proxy server) and 'Comma-separated list of proxy bypass rules'.

If you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.

For detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.

If you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.

If you don't configure this policy users can choose their own proxy settings.

* "direct" = Never use a proxy

* "auto_detect" = Auto detect proxy settings

* "pac_script" = Use a .pac proxy script

* "fixed_servers" = Use fixed proxy servers

* "system" = Use system proxy settings

Example value: direct</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Proxy server</q1:Category>
          <q1:DropDownList>
            <q1:Name>Configure proxy server settings</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>
              <q1:Name>Use fixed proxy servers</q1:Name>
            </q1:Value>
          </q1:DropDownList>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure Microsoft Defender SmartScreen</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.

If you enable this setting, Microsoft Defender SmartScreen is turned on.

If you disable this setting, Microsoft Defender SmartScreen is turned off.

If you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/SmartScreen settings</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure Microsoft Defender SmartScreen to block potentially unwanted apps</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.

If you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.

If you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.

If you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.</q1:Explain>
          <q1:Supported>Microsoft Edge version 80, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/SmartScreen settings</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Prevent bypassing Microsoft Defender SmartScreen prompts for sites</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.

If you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.

If you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/SmartScreen settings</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.

If you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.

If you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/SmartScreen settings</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Action to take on startup</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specify how Microsoft Edge behaves when it starts.

If you want a new tab to always open on startup, choose 'Open new tab' (5).

If you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).

If you want to open a specific set of URLs, choose 'Open a list of URLs' (4).

Disabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.

* 1 = Restore the last session

* 4 = Open a list of URLs

* 5 = Open a new tab</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Startup, home page and new tab page</q1:Category>
          <q1:DropDownList>
            <q1:Name>Action to take on startup</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>
              <q1:Name>Open a new tab</q1:Name>
            </q1:Value>
          </q1:DropDownList>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure the home page URL</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Configures the default home page URL in Microsoft Edge.

The home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.

You can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.

If you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.

If you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.

Example value: https://www.contoso.com</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Startup, home page and new tab page</q1:Category>
          <q1:EditText>
            <q1:Name>Home page URL</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>https://www.google.co.uk</q1:Value>
          </q1:EditText>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Configure the new tab page URL</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Configures the default URL for the new tab page.

This policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.

This policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.

If you don't configure this policy, the default new tab page is used.

If you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.

If an invalid URL is provided, new tabs will open about://blank.

This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.

Example value: https://www.fabrikam.com</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Startup, home page and new tab page</q1:Category>
          <q1:EditText>
            <q1:Name>New tab page URL</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:Value>https://www.google.co.uk</q1:Value>
          </q1:EditText>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Hide the default top sites from the new tab page</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Hides the default top sites from the new tab page in Microsoft Edge.

If you set this policy to true, the default top site tiles are hidden.

If you set this policy to false or don't configure it, the default top site tiles remain visible.</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Startup, home page and new tab page</q1:Category>
        </q1:Policy>
        <q1:Policy>
          <q1:Name>Sites to open when the browser starts</q1:Name>
          <q1:State>Enabled</q1:State>
          <q1:Explain>Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.

This policy only works if you also set the 'RestoreOnStartup' (Action to take on startup) policy to 'Open a list of URLs' (4).

This policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.

Example value:

https://contoso.com
https://www.fabrikam.com</q1:Explain>
          <q1:Supported>Microsoft Edge version 77, Windows 7 or later</q1:Supported>
          <q1:Category>Microsoft Edge/Startup, home page and new tab page</q1:Category>
          <q1:ListBox>
            <q1:Name>Sites to open when the browser starts</q1:Name>
            <q1:State>Enabled</q1:State>
            <q1:ExplicitValue>false</q1:ExplicitValue>
            <q1:Additive>false</q1:Additive>
            <q1:ValuePrefix />
            <q1:Value>
              <q1:Element>
                <q1:Data>https://www.google.co.uk</q1:Data>
              </q1:Element>
            </q1:Value>
          </q1:ListBox>
        </q1:Policy>
        <q1:Blocked>false</q1:Blocked>
      </Extension>
      <Name>Registry</Name>
    </ExtensionData>
  </User>
  <LinksTo>
    <SOMName>Managed Pupils (7)</SOMName>
    <SOMPath>DCC-SCH-4505.local/Learning Gateway/Managed Pupils (7)</SOMPath>
    <Enabled>true</Enabled>
    <NoOverride>false</NoOverride>
  </LinksTo>
</GPO>