Define a list of protocols that can launch an external application from listed origins without prompting the user
Verified with Microsoft Edge 152.0.4191.53 — updated on July 12, 2026
Supported on: Microsoft Edge version 85, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator shouldn't be included when listing the protocol and the protocol should be all lower case. For example, list "skype" instead of "skype:", "skype://" or "Skype". If you configure this policy, a protocol is only permitted to launch an external application without prompting by policy if: - the protocol is listed - the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false, the external protocol launch prompt isn't omitted, by policy. If you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an "Always open" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users. The origin-matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322. However, origin-matching patterns for this policy can't contain "/path" or "@query" elements. Any pattern that contains a "/path" or "@query" element is ignored. This policy doesn't work as expected with file://* wildcards. Example value: [ { "allowed_origins": [ "example.com", "http://www.example.com:8080" ], "protocol": "spotify" }, { "allowed_origins": [ "https://example.com", "https://.mail.example.com" ], "protocol": "msteams" }, { "allowed_origins": [ "*" ], "protocol": "msoutlook" } ]
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 85, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"AutoLaunchProtocolsFromOrigins"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutoLaunchProtocolsFromOrigins' -Value '' -Type String Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'AutoLaunchProtocolsFromOrigins' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutoLaunchProtocolsFromOrigins' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'AutoLaunchProtocolsFromOrigins' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Define a list of protocols that can launch an external application from listed origins without prompting the user
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 85, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutoLaunchProtocolsFromOrigins' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.