Information
This policy setting allows you to manage whether users can install Active Desktop items
from this zone. The recommended state for this setting is- Enabled-Disable.
*Rationale*
Active Desktop items could contain links to unauthorized websites or other undesirable
content, it is prudent to prevent users from installing desktop items from this security
zone.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow installation
of desktop itemsThen set the Allow installation of desktop items option to Disable.
Impact-The settings for this option are- Enabled, users can install desktop items from this zone
automatically. Prompt, users are queried to choose whether to install desktop items from
this zone. Disabled, users are prevented from installing desktop items from this zone. If you
do not configure this policy setting, users are prevented from installing desktop items from
this zone.
Default Value-Disabled