Configure default state of Allow extensions from other stores setting
Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026
Supported on: Microsoft Edge version 101, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge - Default Settings (users can override)\Extensions User Configuration\Administrative Templates\Microsoft Edge - Default Settings (users can override)\Extensions Description
This policy allows you to control the default state of the Allow extensions from other stores setting. This policy can't be used to stop installation of extensions from other stores such as Chrome Web Store. To stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098. When enabled, Allow extensions from other stores are turned on. So, users don't have to turn on the flag manually while installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting. If the user turned on the setting and then turned it off, this setting may not work. If the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it has no impact on user settings and the setting remains as it is. When disabled or not configured, the user can manage the Allow extensions from other store setting.
Registry
Software\Policies\Microsoft\Edge\Recommended Software\Policies\Microsoft\Edge\Recommended Value name: ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled
Enabled: ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled = 1
Disabled: ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled = 0
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Configure default state of Allow extensions from other stores setting
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 101, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\Recommended]
"ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\Recommended'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge\Recommended' -Name 'ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\Recommended'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge\Recommended' -Name 'ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure default state of Allow extensions from other stores setting
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 101, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge\Recommended'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.