The new Group Policy Settings for Internet Explorer Security Zones
Internet Explorer Maintenance changes the registry settings under the HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER registry hives. Here are two examples.
Under the HKEY_LOCAL_MACHINE registry hive
- Start Group Policy Object Editor.
- In the left pane, expand Computer Configuration, expand Administrative Templates, expand Windows Components, expand Internet Explorer, expand Internet Control Panel, expand Security Page, and then click Internet Zone.
- In the right pane, double-click Initialize and script ActiveX controls not marked as safe.
- Select Enabled, and then click OK.
- In Registry Editor, locate the following subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- The value data of the 1201 Value name will be changed to 0.
Under the HKEY_CURRENT_USER registry hive
- Start Group Policy Object Editor.
- In the left pane, expand User Configuration, expand Administrative Templates, expand Windows Components, expand Internet Explorer, expand Internet Control Panel, expand Security Page, and then click Internet Zone.
- In the right pane, double-click Initialize and script ActiveX controls not marked as safe.
- Select Enabled, and then click OK.
- In Registry Editor, locate the following subkey:
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- The value data of the 1201 Value name will be changed to 0.
In Windows Server 2003 Service Pack 1 and in Windows XP Service Pack 2, there is a new order in which Internet Explorer looks for policy settings. The original order is as follows:
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
The new order is as follows:
HKEY_LOCAL_MACHINE\SOFTWARE\<policies>
HKEY_CURRENT_USER\SOFTWARE\<policies>
HKEY_CURRENT_USER\<preference hive>
HKEY_LOCAL_MACHINE\<preference hive>
Overview of the new Group Policy settings
To view the new Group Policy settings, follow these steps:
- Start Group Policy Object Editor.
- In the left pane, expand User Configuration, expand Administrative Templates, expand Windows Components, expand Internet Explorer, expand Internet Control Panel, and then click Security Page.
The new Group Policy settings appear in the right pane.
The following is a list of the new Group Policy settings and their corresponding registry keys:
Site to Zone Assignment List
Local Machine Zone Template
- Locked-Down Local Machine Zone TemplateNote This applies only to Windows Server 2003 SP 1.
Intranet Zone Template
- Locked-Down Intranet Zone TemplateNote This applies only to Windows Server 2003 SP 1.
Trusted Sites Zone Template
- Locked-Down Trusted Sites Zone TemplateNote This applies only to Windows Server 2003 SP1.
Internet Zone Template
- Locked-Down Internet Zone TemplateNote This applies only to Windows Server 2003 SP1.
Restricted Sites Zone Template
- Locked-Down Restricted Sites Zone TemplateNote This applies only to Windows Server 2003 SP 1.