en-US edge computer user

Allow HTTPS-Only Mode to be enabled

Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026

Microsoft Edge 152.0.4191.53

Supported on: Microsoft Edge version 140, Windows 7 or later

Path in the GPO console

Computer Configuration\Administrative Templates\Microsoft Edge - Default Settings (users can override)

Description

This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS. If this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode. If this setting is set to Disallowed, HTTPS-Only Mode will be disabled. If this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode. If this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode. The settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it. If you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Policy options mapping: * allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting * disallowed (disallowed) = Disable HTTPS-Only Mode * force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode * force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode Use the preceding information when configuring this policy. Example value: disallowed

Registry

HKLM Software\Policies\Microsoft\Edge\Recommended
HKCU Software\Policies\Microsoft\Edge\Recommended

More options available

Options

Allow HTTPS-Only Mode to be enabled
HttpsOnlyMode enum
  • Don't restrict users' HTTPS-Only Mode setting -> allowed
  • Disable HTTPS-Only Mode -> disallowed
  • Force enable HTTPS-Only Mode in Strict mode -> force_enabled
  • Force enable HTTPS-Only Mode in Balanced Mode -> force_balanced_enabled

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

Scope

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Allow HTTPS-Only Mode to be enabled
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 140, Windows 7 or later

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\Recommended]
"HttpsOnlyMode"="allowed"
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Allow HTTPS-Only Mode to be enabled
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 140, Windows 7 or later

$path = 'HKLM:\Software\Policies\Microsoft\Edge\Recommended'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'HttpsOnlyMode' -Value 'allowed' -Type String

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder
What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview