Configuration policy for Microsoft Edge for Business Reporting Connectors
Verified with Microsoft Edge 152.0.4191.53 — updated on September 2, 2026
Supported on: Microsoft Edge version 139, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions. The service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider. This policy can only be configured through the Microsoft 365 Admin Center. It requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446. Example value: [ { "enabled_event_names": [ "passwordChangedEvent", "sensitiveDataEvent" ], "enabled_opt_in_events": [ { "name": "loginEvent", "url_patterns": [ "*" ] }, { "name": "passwordBreachEvent", "url_patterns": [ "example.com", "other.example.com" ] } ], "service_provider": "microsoft" } ]
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 139, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"OnSecurityEventEnterpriseConnector"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnSecurityEventEnterpriseConnector' -Value '' -Type String Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'OnSecurityEventEnterpriseConnector' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnSecurityEventEnterpriseConnector' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'OnSecurityEventEnterpriseConnector' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configuration policy for Microsoft Edge for Business Reporting Connectors
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 139, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnSecurityEventEnterpriseConnector' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.