Except where noted, everything here applies only to Firefox 153. Firefox 153 is the new ESR, so, going forward, no enterprise changes will be backported to Firefox 140 ESR.
Firefox Professional Support
Mozilla offers Firefox Professional Support for organizations that need dedicated enterprise support. For more information, see https://www.firefox.com/browsers/enterprise/.
Other Changes
- Automatically discovered printers are now listed after manually configured printers in the print destination list. This was changed in bug 1996569.
- Firefox installed from a macOS
.pkgpackage can now update without prompting for administrator credentials. This was fixed in bug 1812480.
Bug Fixes
- The SanitizeOnShutdown policy now correctly locks the History settings when configured. This was fixed in bug 1888451.
- The DisableSecurityBypass policy now correctly removes the "Allow download" button when Safe Browsing bypass is disabled. This was fixed in bug 1894373.
- The PopupBlocking policy now correctly locks all popup permission controls. This was fixed in bug 1888477.
- Extensions that are no longer permitted by the ExtensionSettings policy are now correctly removed or blocked when
allowed_typeschanges. This was fixed in bug 2008100. - The PasswordManagerEnabled policy now correctly disables the Passwords sidebar panel. This was fixed in bug 2041232.
- The ExtensionSettings policy now correctly handles Windows registry configurations that use both JSON and individual REG_SZ values. Individual REG_SZ values no longer override the JSON policy configuration. This was fixed in bug 2048696.
- The FirefoxHome policy is now correctly reflected in the redesigned Settings interface. This was fixed in bug 2048048.
- AutoConfig can once again set the
browser.startup.homepagepreference to adata:URL. This fixes a regression introduced in Firefox 152. This was fixed in bug 2047962.
Policies
- The DisableRemoteSettingsAndAcceptSecurityConsequences policy has been added to disable Remote Settings. This policy should only be used when the consequences are fully understood.
- The ExtensionSettings policy has been updated with several new capabilities:
- Administrators can now control extension host permissions using
runtime_allowed_hostsandruntime_blocked_hosts. - Administrators can now use
allowed_permissionsto control which permissions extensions may request. - Users can no longer change the host permissions of Manifest Version 3 extensions installed using
force_installed.
- Administrators can now control extension host permissions using
- The ExtensionSettings policy has been updated to allow
force_installedandnormal_installedextensions to be installed directly from addons.mozilla.org wheninstall_urlis omitted. - The ManagedBookmarks policy has been updated to support bookmarklets using
javascript:URLs. - The EnableTrackingProtection policy now uses
partition-foreignas the name for the cookie behavior previously calledreject-tracker-and-partition-foreign. Existing configurations usingreject-tracker-and-partition-foreignwill continue to work. - The Containers policy has been updated for Firefox's new container color palette. Existing color names are automatically migrated to the new names for compatibility.
- The Homepage policy has been updated to open the default start page or
about:newtabafter restoring a previous session.
Special Notes
Firefox 153 is the next ESR. Firefox 140 ESR will continue to receive security updates during the ESR transition period.
If you use the ESR, we strongly recommend testing Firefox 153 with your enterprise configuration, extensions, authentication systems, and deployment tooling. Testing during the transition period gives you time to identify and report issues before Firefox 140 ESR users are automatically upgraded to Firefox 153 ESR.
If you need to prevent upgrades for any reason, you can use the AppUpdatePin policy.