en-US edge computer user

Control the mode of DNS-over-HTTPS

Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026

Microsoft Edge 152.0.4191.53

Supported on: Microsoft Edge version 83, Windows 7 or later

Path in the GPO console

Computer Configuration\Administrative Templates\Microsoft Edge

Description

Control the mode of the DNS-over-HTTPS resolver. This policy only sets the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname. The "off" mode disables DNS-over-HTTPS. The "automatic" mode sends DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available, and falls back to sending insecure queries on error. The "secure" mode only sends DNS-over-HTTPS queries and will fail to resolve on error. If you don't configure this policy for managed devices, DNS-over-HTTPS queries aren't sent. Instead, the browser may send DNS requests to a resolver associated with the user's system resolver. This could lead to a less secure or private DNS resolution process, depending on the resolver in use. Policy options mapping: * off (off) = Disable DNS-over-HTTPS * automatic (automatic) = Enable DNS-over-HTTPS with insecure fallback * secure (secure) = Enable DNS-over-HTTPS without insecure fallback Use the preceding information when configuring this policy. Example value: off

Registry

HKLM Software\Policies\Microsoft\Edge
HKCU Software\Policies\Microsoft\Edge

More options available

Options

Control the mode of DNS-over-HTTPS
DnsOverHttpsMode enum
  • Disable DNS-over-HTTPS -> off
  • Enable DNS-over-HTTPS with insecure fallback -> automatic
  • Enable DNS-over-HTTPS without insecure fallback -> secure

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

Scope

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Control the mode of DNS-over-HTTPS
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 83, Windows 7 or later

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"DnsOverHttpsMode"="off"
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Control the mode of DNS-over-HTTPS
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 83, Windows 7 or later

$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DnsOverHttpsMode' -Value 'off' -Type String

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview