en-US edge computer user

HTTP Allowlist

Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026

Microsoft Edge 152.0.4191.53

Supported on: Microsoft Edge version 123, Windows 7 or later

Path in the GPO console

Computer Configuration\Administrative Templates\Microsoft Edge WebView2

Description

Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable "HttpsUpgradesEnabled". Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. Blanket host wildcards (that is, "*" or "[*]") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies. Note: This policy doesn't apply to HSTS upgrades. Example value: testserver.example.com [*.]example.org

Registry

HKLM Software\Policies\Microsoft\Edge\WebView2
HKCU Software\Policies\Microsoft\Edge\WebView2

More options available

Options

HTTP Allowlist
List (registry values) list
- list under Software\Policies\Microsoft\Edge\WebView2\HttpAllowlist

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

Scope

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: HTTP Allowlist
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 123, Windows 7 or later

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\WebView2\HttpAllowlist]
; List values: enter one value per line in the builder UI.
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: HTTP Allowlist
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 123, Windows 7 or later

$path = 'HKLM:\Software\Policies\Microsoft\Edge\WebView2\HttpAllowlist'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI.

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview