Allow socket pool size randomization for proxies
Verified with Microsoft Edge 152.0.4191.53 — updated on September 2, 2026
Supported on: Microsoft Edge version 150, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections. Socket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice. This policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies. If you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections. If you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Value name: AllowSocketPoolSizeRandomizationForProxies
Enabled: AllowSocketPoolSizeRandomizationForProxies = 1
Disabled: AllowSocketPoolSizeRandomizationForProxies = 0
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Allow socket pool size randomization for proxies
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 150, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"AllowSocketPoolSizeRandomizationForProxies"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowSocketPoolSizeRandomizationForProxies' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'AllowSocketPoolSizeRandomizationForProxies' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowSocketPoolSizeRandomizationForProxies' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'AllowSocketPoolSizeRandomizationForProxies' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow socket pool size randomization for proxies
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 150, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowSocketPoolSizeRandomizationForProxies' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.