Information
This policy setting allows for the configuration for users to add exceptions to allow mixed content for specific sites.
The recommended state for this setting is: Enabled: Do not allow any site to load mixed content
Note: This policy can be overridden for specific URL patterns using the
insecurecontentAllowedForUrls (Allow insecure content on specified sites)
and
insecurecontentBlockedForUrls (Block insecure content on specified sites) policies
.
Allowing mixed (secure / insecure) content from a site can lead to malicious content being loaded. Mixed content occurs if the initial request is secure over HTTPS, but HTTPS and HTTP content is subsequently loaded to display the web page. HTTPS content is secure. HTTP content is insecure.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to load mixed content :
Computer Configuration\Polices\Administrative Templates\Microsoft Edge\Content Settings\Control use of insecure content exceptions
Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:
Download Microsoft Edge for Business - Microsoft
.
Impact:
Users will not be able to add exceptions for mixed content webpages.