Group Policy Blog

Group Policy Tips, Tricks, and News from Darren Mar-Elia

GP Preferences for Internet Explorer 11

With IE 11 now generally available for Windows 7 and newer versions, the obvious question is, how do I manage IE 11 configuration using Group Policy? Of course, now that IE Maintenance Policy has been deprecated, your choices for managing IE using GP include either the Admin Template settings (inetres.admx) that come with the version of IE you need to manage, or GP Preferences Internet Settings. Microsoft has been *pretty good* at adding support for new browser versions in GP Preferences as they rev Windows, well, until Windows 8.1, that is. In that version, we might have expected to see an update to GP Preferences, supporting IE 11. That however, was not the case, as shown here:

IE 10 support in Windows 8.1

IE 10 support in Windows 8.1

But, all is not lost. In previous versions of IE support in GP Preferences, Microsoft would add new browser support whenever there were substantial changes in configurable features and functionality within IE. For example, when they went from IE 5 and 6 support to IE 7, they added explicit support for IE 7. When IE 8 support was made available in GPP, a hotfix added support for IE 9, but didn’t really change any of the options available to configure in GPP. IE 8 and 9 became lumped together. Similarly, when Windows 8 shipped with IE 10, Microsoft added explicit support for IE 10 in GPP because of fairly significant option changes in IE 10. All along the way, if you looked under the covers at how Microsoft targeted IE GPP settings for each version of IE, it was rather clever.

Within the XML underlying the IE settings in the GPO, they leveraged Item-level targeting (ILT) to ensure the right settings made it to the right version of IE on the client. Specifically, they use a hidden File ILT to check for the version of IExplore.exe running on the client machine and the use that to determine which IE settings to deploy from the GPO. An example of this File filter for IE 8 and 9 settings is shown here:

<FilterFile hidden="1" not="0" bool="AND" path="%ProgramFilesDir%\Internet Explorer\iexplore.exe" type="VERSION" gte="1" min="" max="" lte="0"/>

Note that the version number of the iexplore.exe file is greater than or equal to 8 and less than 10. This means that you can have IE settings for IE 5 &6, IE 7 and IE 8 & 9 in a single GPO, and using these filters, Microsoft ensures that the right settings go to the right version of IE.  Now, when Microsoft shipped Windows 8 and IE 10, this filter condition changed to >= and <! And when Windows 8.1 shipped, the same condition held true.

So, what can we assume from this? Well, first off, it means that setting IE 10 GP Preferences settings will indeed apply to IE 11 just fine. It also means that any versions beyond IE 11 will work as well, using IE 10 GPP  settings. Of course, this starts to break down as features in subsequent versions of IE are changed or added, because unless Microsoft updates the UI for editing these newer IE features, they won’t be exposed in GP editor. But, for the time being, you’re covered on IE 11 with the current IE 10 support, at least for the stuff that is the same across both browser versions. Hopefully it doesn’t also mean that Microsoft has no plans to update GPP IE settings in the future, should browser settings change significantly.

Finally, I will add, with a plug to my buddy Jeremy Moskowitz, that his PolicyPak product, which extends GP to manage 3rd party application settings, also includes a “Pak” for IE, that has explicit support for all versions of IE up to 11. So check it out!


There are 5 comments .

Matt —


I’m a little unsure if this works for a full GPO (instead of individual settings) and if so how?
Are you saying that if there is a hidden file called ILT.xml in the GPO folder and that text is entered then this will filter out the whole GPO for machines without IE 8, 9 or 10?



Reply »
Sourabh —

Hello Experts!!

Hello Experts!!!!
I need help to understand the issue,
Description : I am creating a test GPO to configure the IE11 settings from Win2k12 server, with below steps.
1. User Configurations->Preferences->Control Panel Setting->Internet Settings
2. Then I right clicked and selected “Internet Explorer 10” and configured different settings.
3. Linked this GPO to OU where userid exists.
4. ran gpupdate /force and the GPO is applied.
5. ran gpresult /h report.html, when opening this report Instead of showing Internet Explorer 10 it is showing Internet Explorer 5 and 6.

Reply »
Sourabh —

I missed one thing to mention that on machine (with IE11)when I am pulling out the gpresult report, all IE11 settings are missing, means IE11 newly added settings are not showing in the report.
However at the same time, on gpmc console on Win2k12 server the settings are visible in settings tab of my test GPO of IE11 Settings.
is there any patch\KB or anything required on the client machine, I am stuck in my task. Please help.

Reply »

Share Your Thoughts!


Copyright © 2015 SDM Software, Inc.
Site design by Social Media Ninjas