Thursday, 8 January 2015

Locking Down Internet Explorer on Windows 8

Sometimes you need to lock down the browser so that a user can only access a single site. This can be achieved by the use of a single group policy setting.

User Configuration \ Administrative Templates \ Windows components \ Internet Explorer

Set Enforce Full Screen Mode to Enabled this will force the Desktop version of internet explorer to have no menus, toolbars, status bar or even the address bar, and no address bar means no way to get to a new site. This has been possible since IE7 but with the addition of the new modern browser in Windows 8, they always had the other option accessed by clicking on the IE shortcut on the start menu.

But Microsoft did think of that so there are 2 more group policy settings at:

User Configuration \ Administrative Templates \ Windows components \ Internet Explorer \ Internet Settings

First one
Open Internet Explorer tiles on the desktop should be enabled to force the use of the desktop version which you can then control

Second one
Set how links are opened in Internet Explorer can be enabled and set to Always in Internet Explorer on the desktop

As all of these settings are User Configuration they can also be set using Multiple Local Group Policy, so that you can set them for any non Administrators on the device making an option of Kiosks or other single task systems.