Hiển thị các câu hỏi cho chủ đề:
Hiển thị các câu hỏi được đánh dấu:

In version 154 no start pages are displayed that were set via registry entries.

Hi, In the latest firefox update 154, no start pages are displayed that were distributed with a registry key via group policy. It only works again if you change this sett… (xem thêm)

Hi,

In the latest firefox update 154, no start pages are displayed that were distributed with a registry key via group policy. It only works again if you change this setting manually in the Firefox settings.

In Version 153 it´s fine.

Jan

Mở 2 10

Questions About Enterprise Deployment, Updating and Rollback of Firefox Policy Templates

Dear Firefox Support Team, We are evaluating the deployment of Mozilla Firefox Group Policy templates in our organization to support Microsoft Defender for Endpoint Netw… (xem thêm)

Dear Firefox Support Team,

We are evaluating the deployment of Mozilla Firefox Group Policy templates in our organization to support Microsoft Defender for Endpoint Network Protection.

Microsoft has advised us that, for custom URL/domain Indicators to work correctly in Firefox, we need to:

1. Download the Firefox policy templates from:

  https://github.com/mozilla/policy-templates/releases

2. Copy the files and folders under the Windows directory to:

  `C:\Windows\PolicyDefinitions`

3. Enable the **Disable Encrypted Client Hello** policy.

4. Configure the following preference to disable HTTP/3:

```json {

 "network.http.http3.enable": {
   "Value": false,
   "Status": "default"
 }

} ```

Microsoft referred us to Mozilla for clarification regarding the lifecycle, compatibility and rollback of the Firefox policy templates. Before deploying the configuration across our managed Windows devices, we would appreciate your guidance on the following questions.

1. Policy template update frequency

We noticed that new versions of the Firefox policy templates are released quite frequently.

  • Is it necessary to deploy every new version of the policy templates?
  • Should organizations establish a regular schedule for updating the ADMX/ADML files?
  • Alternatively, should the templates only be updated when a required policy has changed or when the installed Firefox version requires a newer template?
  • Is there a recommended method for matching a policy-template version with Firefox Release and Firefox ESR versions?
  • Could an older policy-template version continue to be used if it already contains the required policies?

2. Different Firefox versions across endpoints

Our users may have different versions of Firefox or Firefox ESR installed.

If the same policy templates and settings are deployed to all managed Windows devices:

  • What happens when an installed Firefox version does not support a setting included in the policy template?
  • Will Firefox simply ignore an unsupported policy, or could it cause policy-processing errors or browser compatibility issues?
  • Is there a minimum supported Firefox or Firefox ESR version for `DisableEncryptedClientHello` and the `network.http.http3.enable` preference?
  • Do you recommend targeting the deployment according to the installed Firefox version?

3. Devices without Firefox installed

Some managed devices do not have Firefox installed.

  • Is it safe to deploy the Firefox ADMX/ADML files and related registry-based policy settings to those devices?
  • Will the files and settings remain inactive until Firefox is installed?
  • Could deploying the templates or registry settings have any effect on Windows or other browsers?

4. Replacement of existing templates

When copying the files into `C:\Windows\PolicyDefinitions`, Windows may prompt us to replace existing Mozilla ADMX/ADML files.

  • Is it safe to replace older versions with the latest released templates?
  • Could replacement affect or remove existing Firefox Group Policy configurations?
  • Should the existing files be backed up before replacement?
  • Do we only need `mozilla.admx`, `firefox.admx` and the corresponding language-specific ADML files, or should every file and language folder in the Windows package be copied?

5. Rollback procedure

If the deployment causes an unexpected browser, compatibility or performance issue, what is Mozilla’s recommended rollback procedure?

Should we:

  • Change **Disable Encrypted Client Hello** to *Not Configured* or *Disabled*;
  • Remove or reverse the `network.http.http3.enable` preference;
  • Remove the associated Firefox policy registry values;
  • Restore the previous ADMX/ADML files; and/or
  • Remove the current templates from `C:\Windows\PolicyDefinitions`?

Please clarify whether withdrawing the Group Policy assignment is sufficient to restore Firefox’s default ECH and HTTP/3 behavior, or whether endpoint-level cleanup is also required.

6. Recommended enterprise deployment approach

For a managed enterprise environment, would Mozilla recommend deploying these templates through:

  • The Active Directory Group Policy Central Store;
  • Local `C:\Windows\PolicyDefinitions`;
  • Microsoft Intune ADMX ingestion;
  • Direct registry-based policies; or
  • Another supported method?

We would appreciate Mozilla’s official recommendation so that we can complete our internal risk assessment and prepare an appropriate deployment, maintenance and rollback plan.

Thank you for your assistance.

Best regards, Summer

Mở 2 10

cannot create auto:config

I don't understand why auto:config is so difficult (for me at least) to create. Isn't there an easier way? I've tried following the directions and creating the 2 files. … (xem thêm)

I don't understand why auto:config is so difficult (for me at least) to create. Isn't there an easier way? I've tried following the directions and creating the 2 files. But I can't manage to successfully create auto:config.

I created and pasted the first tile into the prefs folder. For the 2nd, I noticed the firefox.cfg file I created in Notepad appended a .txt suffix. I pasted it into the Firefox top directory. Then typed auto:config into the address bar. Nothing happened. Can anyone tell what I did wrong? Is the .txt suffix not recognized? Or is there's an easier way to do this?

Mở 5 20

Refresh in KIOSK mode

Hello, For FF on Linux running in KIOSK mode, is there a way to allow the user to perform a refresh like you can do in normal mode by pressing F5 ? This seems to be disa… (xem thêm)

Hello, For FF on Linux running in KIOSK mode, is there a way to allow the user to perform a refresh like you can do in normal mode by pressing F5 ? This seems to be disabled in KIOSK mode.

Thank you, Tom

Đã lưu trữ 1 180

problem on web filtering with Intune

Cree una política para filtrado web donde bloquea por ejemplo páginas de juegos de azar, sin embargo, varias páginas las está dejando abrir, para contrarestar eso, por me… (xem thêm)

Cree una política para filtrado web donde bloquea por ejemplo páginas de juegos de azar, sin embargo, varias páginas las está dejando abrir, para contrarestar eso, por medio de indicadores bloquee las páginas que deja pasar pero aún así está dejando abrir ciertas páginas, por ejemplo betplay, para solventar eso apliqué una política de filtrado web, para esto importé el admx de Mozilla, sin embargo en Mozilla todavía está dejando entrar a esa página.

Đã lưu trữ 1 191

Request for configuration option to block Internet access when Proxy PAC file if unavailable or cannot be downloaded

Hello Everyone, I am seeking assistance to configure Firefox browser so that internet access is blocked when the browser cannot download or access the proxy Auto-configur… (xem thêm)

Hello Everyone,

I am seeking assistance to configure Firefox browser so that internet access is blocked when the browser cannot download or access the proxy Auto-configuration (PAC) file. Our organisation enforces all web traffic through proxy servers defined by a PAC file. For compliance and security reasons, users should not have any direct internet access unless the browser is able to successfully retrieve and apply the PAC file.

The desired behaviour is:

1. Firefox attempts to download the PAC file from a defined URL. 2. If the PAC file is unreachable or fails to load (e.g., due to network restrictions or the device being outside the corporate network), Firefox should "fail closed" - meaning it should not allow any direct internet traffic. 3. This is effectively a "fail-block" mode: no fallback to direct connections, and no cached or bypassed proxy settings should allow internet browsing.

This behaviour is critical to prevent devices from accessing the internet without applying corporate proxy rules. I would like to know:

1/ Whether Firefox currently supports a setting or policy that enforces this fail-block condition when the PAC file is unavailable. 2/ If not, whether there are recommended configurations or enterprise policies (e.g., via `policies.json` or Group Policy templates) that could achieve equivalent enforcement.

Thank you for your assistance and guidance.

Đã lưu trữ 2 568

"Your browser is being managed by your organization"

How to get rid of "Your browser is being managed by your organization"? This thing is driving me crazy(er)! Please 'dumb down' your reply, as I am not computer literate. … (xem thêm)

How to get rid of "Your browser is being managed by your organization"? This thing is driving me crazy(er)! Please 'dumb down' your reply, as I am not computer literate. If it's a malicious attack, my anti-virus is not picking it up. Thanks!

Đã lưu trữ 3 405

Intune CSP - UserMessaging Firefox Labs

We have Firefox deployed and managed through Intune/Endpoint and all works well but every device has an error with this line of the policy: UserMessaging_FirefoxLabs [./D… (xem thêm)

We have Firefox deployed and managed through Intune/Endpoint and all works well but every device has an error with this line of the policy:

UserMessaging_FirefoxLabs [./Device/Vendor/MSFT/Policy/Config/Firefox~Policy~firefox~UserMessaging/UserMessaging_FirefoxLabs] STATE Error SOURCE PROFILES Source Profile Mozilla_Firefox_Configuration ERROR CODE 0x87d1fde8

The error code is the same on all devices and is the only one present in on each device config.

Does anyone have any idea what the issue and resolution would be?

Thanks, Matt

Đã giải quyết Đã lưu trữ 4 130

Adding an internal range to firefox intune policy management for access control

Hi All, I want to block traffic on firefox externally for managed devices via Intune, following the import of the ADMX/ADML files into intune. Having read https://support… (xem thêm)

Hi All, I want to block traffic on firefox externally for managed devices via Intune, following the import of the ADMX/ADML files into intune.

Having read https://support.mozilla.org/en-US/kb/managing-firefox-intune I have set '\Mozilla\Firefox\Exceptions to blocked websites' to the following; //*.mydomain.com/*

Which works, however, I also want to add hosts that are only resolving on IPs and not DNS. I can add specific IPs if known, but is there a way I can allow IP ranges? Ie

//10.10.*/* (this doesn't currently work) Of the included screenshot, only the wildcard for mydomain.com and the specific IP currently work

I've looked over the link that is recommened in the policy (indirectly) and can't see an option for allowing an IP range. https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Match_patterns

If there is a better way to do this via intune for firefox only, please let me know.

Thanks

Đã giải quyết Đã lưu trữ 3 190

differences and interchangibility of pref(); user_pref(); and lockPref();

Firefox is used on Windows 11 Enterprise. There is a firefox.cfg in the installation directory (and an autoconfig.js in the ./defaults/pref sub-directory). The firefox.cf… (xem thêm)

Firefox is used on Windows 11 Enterprise. There is a firefox.cfg in the installation directory (and an autoconfig.js in the ./defaults/pref sub-directory). The firefox.cfg targets an autoconfigfile.js. This setup is recommended here: [firefox using autoconfig"]

  1. In the support article´s example, the firefox.cfg uses a pref(); expression. Is it possible to use a lockPref(); expression instead?
  2. What is the result of either using pref(); expressions or user_pref(); expressions in the remoted autoconfigfile.js? Are both of them possible, especially while the firefox.cfg uses lockPref(); expressions instead of pref();?

I hope that somesone can help with one of these questions. Thanks a lot!

Đã lưu trữ 1 250

New Preference clearOnShutdown Cache/Cookies/Storage is now v2

Dear Community, i had .cfg file with following settings to clean up some userdata after closing firefox: //Clean UP Cache etc. lockPref("privacy.sanitize.sanitizeOnShutdo… (xem thêm)

Dear Community,

i had .cfg file with following settings to clean up some userdata after closing firefox:

//Clean UP Cache etc. lockPref("privacy.sanitize.sanitizeOnShutdown", true); lockPref("privacy.clearOnShutdown.cache", true); lockPref("privacy.clearOnShutdown.cookies", false); lockPref("privacy.clearOnShutdown.offlineApps", true); lockPref("privacy.clearOnShutdown.sessions", false);

This cleaned the "Storage" Folder in the Firefox Profile folder, but cookies and sessions where remaining, so the logins where active.

Now i saw that all useres have lots of folders in the "Storage/Default" folder. After some research i found out that this behavior startet at 02.10.2024.

I also found a new pref: privacy.clearOnShutdown_v2.cookiesAndStorage which was set to "false". No idea where this key came from? When I set this key to "Yes", the storage is cleared after closing Firefox. But so also all the cookies. Was there a change at the prefs?

And is ther any other solution to clear the Storage but remain the cookies?

Thank you in advance!

Đã lưu trữ 1 151