Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Intune»Enable WD SmartScreen in your browser with Intune
    Intune

    Enable WD SmartScreen in your browser with Intune

    Peter KlapwijkBy Peter KlapwijkAugust 2, 2018Updated:December 7, 20194 Mins Read

    In this blog I will show you how to enable Windows Defender SmartScreen in the browsers Internet Explorer 11, Edge and Google Chrome. SmartScreen is a feature built-in the browsers IE11 and Edge to protect the user against malicious websites and since a few months you can get SmartScreen as an extension for the Google Chrome browser.

    Enable SmartScreen for the Edge Browser

    For the Edge Browser it is pretty simple to enable SmartScreen via Intune. We can use a Windows 10 device restrictions policy for this job. Logon to the Azure portal, open Intune en browse to Device Configuration. Here you need to open Profiles and choose Create Profile. As platform pick Windows 10 and later and as Profile type Device Restrictions. On the right site choose Windows Defender SmartScreen which opens the available options to set for this feature. Click on Require located behind SmartScreen for Microsoft Edge. Click two times OK and Create and the policy will be created. Don`t forget to assign the newly created policy to a (device) group).

    Device restrictions policy

    Your subtitle here

    Now switch over to a Windows 10 device and perform a sperform a sync with Intune from the Account settings location. When the sync is finished start Edge and open the Settings. The setting we are looking for is located under the Advanced settings, the very last setting. We now see Windows Defender SmartScreen is enabled and the option to switch it off is greyed out.

    Edge settings

    Your subtitle here

    Next is Internet Explorer.

    Enable Smartscreen for Internet Explorer

    Like I have shown in my previous blogposts about managing Internet Explorer settings with Intune, we have no predefined setting in the Intune portal to enable SmartScreen in IE. For IE we need to use a CSP Policy to configure this setting. Because I have described in the previous posts in more detail how the CSP policies need to be used, I will only show in short which setting to use to enable SmartScreen in IE.
    In the Intune portal create another Windows 10 profile, this time of the profile type Custom. Click Add to add a new row. Fill in the information like below:
    Add the OMA-URI: ./User/Vendor/MSFT/Policy/Config/InternetExplorer/AllowEnhancedProtectedMode
    As data type you choose string.
    And in the value field you enter: <enabled/><data id=”Advanced_EnableEnhancedProtectedMode” value=”PMEM”/>

    OMA-URI settings

    Create the new profile and assign it to a group.

    Switch over to your Windows 10 device and perform another Intune sync. In IE when you click the tools button and click on Safety, you see the option to turn off SmartScreen is greyed out. Which means SmartScreen is turned on and you are not able to turn it off.

    IE 11 setting

    WD Smartscreen turned on

    Install the SmartScreen extension in the Google Chrome browser

    For the Google Chrome browser we have no policies In Intune we can use to install the extension in the browser so we have to use another feature from Intune.
    By setting a registry entry it is possible to force the installation of the browser extension. The entry we need to set is a String with value bkbeeeffjjeopflfhgeknacdieedcoml;https://clients2.google.com/service/update2/crx which we need to create at this location HKLM:\Software\Policies\Google\Chrome\ExtensionInstallForcelist

    Registry editor

    ExtensionInstallForcelist

    We can set this entry using a PowerShell script and deploy that script with Intune. For some reason the script I created to set the entry was never deployed to my devices (it didn`t even get a device status for one device), so I decided to put this entry in a msi file and deploy it as a mobile app.
    To create the msi, I used the Express edition of Advanced Installer. You just need to created a new project, below Resources choose Registry and add the keys and value I mentioned.

    Advanced Installer

    Express edition


    After adding the value you need to perform a default build to create a msi file which is ready for deployment with Intune.
    Open the Intune portal and switch to the Mobile apps section. Here you need to add a new Line-of-business app. Pick your msi file, enter the required information and click Add to upload the file and create your LOB app. When the file is finished uploading you need to assign the app to a group as assignment type required.

    Intune Mobile app

    WD Browser Protection Chrome

    Again, perform a Intune sync from you Windows 10 device (which has Google Chrome installed). The registry entry is set and in a few minutes the extension is visible on the right next to the address bar.

    Google Chrome

    WD Smartscreen

    If you want to test SmartScreen in those three browsers visit https://demo.smartscreen.msft.net

    Browser EMS Intune Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Security
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Hide try the new Outlook toggle the correct way

    October 12, 2023

    Enable passwordless security key sign-in in Hybrid Azure Active Directory environments

    February 25, 2020

    Configure the Enterprise Mode Site List with Microsoft Intune

    February 15, 2020
    Add A Comment
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025

    Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs

    April 13, 2025

    Using Visual Studio with Microsoft Endpoint Privilege Management, some notes

    April 8, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Peter Klapwijk on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • John M on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • Christoffer Jakobsen on Connect to Azure file shares with Microsoft Entra Private Access
    • Ludo on How to block Bluetooth file transfer with Microsoft Intune
    • RCharles on Automatically configure the time zone (during Autopilot enrollment)
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}