#Requires -RunAsAdministrator # Firefox Policy Deployment - Nur Registry-Werte # Deployment via Intune: Devices > Scripts > Add > Windows PowerShell # Run as: System | Run in 64-bit: Yes $base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox" # --------------------------------------------------------------- # 1. JSON-String-Wert loeschen (Konflikt-Quelle aus alter Intune-Policy) # --------------------------------------------------------------- Remove-ItemProperty -Path $base -Name "ExtensionSettings" -ErrorAction SilentlyContinue # --------------------------------------------------------------- # 2. Firefox Basis-Policies (aus firefox.reg uebernommen) # --------------------------------------------------------------- $basePolicies = @{ AppAutoUpdate = 1 AutofillAddressEnabled = 0 AutofillCreditCardEnabled = 0 BackgroundAppUpdate = 1 BlockAboutAddons = 0 # MUSS 0 sein - sonst kein Add-on-Manager BlockAboutConfig = 1 BlockAboutProfiles = 1 DisableDeveloperTools = 1 DisableFeedbackCommands = 1 DisableFirefoxAccounts = 1 DisableFirefoxScreenshots = 1 DisableFirefoxStudies = 1 DisableForgetButton = 1 DisableMasterPasswordCreation = 1 DisablePasswordReveal = 1 DisablePocket = 1 DisableProfileImport = 1 DisableTelemetry = 1 HardwareAcceleration = 0 LegacyProfiles = 0 NetworkPrediction = 0 OfferToSaveLogins = 0 PasswordManagerEnabled = 0 SearchSuggestEnabled = 0 TranslateEnabled = 0 } if (-not (Test-Path $base)) { New-Item -Path $base -Force | Out-Null } foreach ($name in $basePolicies.Keys) { Set-ItemProperty -Path $base -Name $name -Value $basePolicies[$name] -Type DWord } # String-Werte Set-ItemProperty -Path $base -Name "DisplayBookmarksToolbar" -Value "always" -Type String Set-ItemProperty -Path $base -Name "OverrideFirstRunPage" -Value "" -Type String Set-ItemProperty -Path $base -Name "SSLVersionMin" -Value "tls1.2" -Type String # --------------------------------------------------------------- # 3. ExtensionSettings als Unterkeys (KEIN JSON-String) # --------------------------------------------------------------- $extBase = "$base\ExtensionSettings" if (-not (Test-Path $extBase)) { New-Item -Path $extBase -Force | Out-Null } $extensions = @{ # Wildcard: alle nicht gelisteten Add-ons blockieren "*" = @{ installation_mode = "blocked" } # Bestehende Add-ons aus Intune-Policy "keepassxc-browser@keepassxc.org" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/keepassxc-browser/latest.xpi" } "acrobat_reader@adobe.com" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/acrobat-reader/latest.xpi" } "foxitreader@foxitsoftware.com" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/foxit-reader/latest.xpi" } # Neu hinzugefuegte Add-ons "addon@darkreader.org" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/darkreader/latest.xpi" } "uBlock0@raymondhill.net" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi" } "{446900e4-71c2-419f-a6a7-df9c091e268b}" = @{ installation_mode = "force_installed" install_url = "https://addons.mozilla.org/firefox/downloads/latest/bitwarden-password-manager/latest.xpi" } } foreach ($id in $extensions.Keys) { $key = "$extBase\$id" if (-not (Test-Path $key)) { New-Item -Path $key -Force | Out-Null } foreach ($prop in $extensions[$id].Keys) { Set-ItemProperty -Path $key -Name $prop -Value $extensions[$id][$prop] -Type String } } # --------------------------------------------------------------- # 4. Weitere Policy-Unterkeys (aus firefox.reg) # --------------------------------------------------------------- # Authentication $authBase = "$base\Authentication" if (-not (Test-Path $authBase)) { New-Item -Path $authBase -Force | Out-Null } $allowProxies = "$authBase\AllowProxies" if (-not (Test-Path $allowProxies)) { New-Item -Path $allowProxies -Force | Out-Null } Set-ItemProperty -Path $allowProxies -Name "NTLM" -Value 1 -Type DWord Set-ItemProperty -Path $allowProxies -Name "SPNEGO" -Value 1 -Type DWord $ntlm = "$authBase\NTLM" if (-not (Test-Path $ntlm)) { New-Item -Path $ntlm -Force | Out-Null } Set-ItemProperty -Path $ntlm -Name "1" -Value "*.hh.hansemerkur.de" -Type String Set-ItemProperty -Path $ntlm -Name "2" -Value "*.hanse-merkur.de" -Type String Set-ItemProperty -Path $ntlm -Name "3" -Value "*.hansemerkur.de" -Type String Set-ItemProperty -Path $ntlm -Name "4" -Value "hansemerkur.flexopus.com" -Type String # Certificates $cert = "$base\Certificates" if (-not (Test-Path $cert)) { New-Item -Path $cert -Force | Out-Null } Set-ItemProperty -Path $cert -Name "ImportEnterpriseRoots" -Value 1 -Type DWord # Cookies $cookies = "$base\Cookies" if (-not (Test-Path $cookies)) { New-Item -Path $cookies -Force | Out-Null } Set-ItemProperty -Path $cookies -Name "Behavior" -Value "accept" -Type String # DNSOverHTTPS $dns = "$base\DNSOverHTTPS" if (-not (Test-Path $dns)) { New-Item -Path $dns -Force | Out-Null } Set-ItemProperty -Path $dns -Name "Enabled" -Value 1 -Type DWord Set-ItemProperty -Path $dns -Name "Fallback" -Value 1 -Type DWord # EnableTrackingProtection $tp = "$base\EnableTrackingProtection" if (-not (Test-Path $tp)) { New-Item -Path $tp -Force | Out-Null } Set-ItemProperty -Path $tp -Name "Value" -Value 1 -Type DWord Set-ItemProperty -Path $tp -Name "Cryptomining" -Value 1 -Type DWord Set-ItemProperty -Path $tp -Name "Fingerprinting"-Value 1 -Type DWord Set-ItemProperty -Path $tp -Name "Locked" -Value 1 -Type DWord Set-ItemProperty -Path $tp -Name "EmailTracking" -Value 1 -Type DWord # FirefoxHome $home = "$base\FirefoxHome" if (-not (Test-Path $home)) { New-Item -Path $home -Force | Out-Null } Set-ItemProperty -Path $home -Name "Search" -Value 1 -Type DWord Set-ItemProperty -Path $home -Name "TopSites" -Value 0 -Type DWord Set-ItemProperty -Path $home -Name "SponsoredTopSites"-Value 0 -Type DWord Set-ItemProperty -Path $home -Name "Highlights" -Value 0 -Type DWord Set-ItemProperty -Path $home -Name "Pocket" -Value 0 -Type DWord Set-ItemProperty -Path $home -Name "SponsoredPocket" -Value 0 -Type DWord Set-ItemProperty -Path $home -Name "Snippets" -Value 0 -Type DWord Set-ItemProperty -Path $home -Name "Locked" -Value 0 -Type DWord # FlashPlugin $flash = "$base\FlashPlugin" if (-not (Test-Path $flash)) { New-Item -Path $flash -Force | Out-Null } Set-ItemProperty -Path $flash -Name "Default" -Value 0 -Type DWord Set-ItemProperty -Path $flash -Name "Locked" -Value 1 -Type DWord # InstallAddonsPermission $iap = "$base\InstallAddonsPermission" if (-not (Test-Path $iap)) { New-Item -Path $iap -Force | Out-Null } Set-ItemProperty -Path $iap -Name "Default" -Value 0 -Type DWord # Permissions foreach ($perm in @("Autoplay","Camera","Location","Microphone","VirtualReality")) { $pk = "$base\Permissions\$perm" if (-not (Test-Path $pk)) { New-Item -Path $pk -Force | Out-Null } if ($perm -ne "Autoplay") { Set-ItemProperty -Path $pk -Name "BlockNewRequests" -Value 1 -Type DWord } Set-ItemProperty -Path $pk -Name "Locked" -Value 1 -Type DWord } # PopupBlocking $popup = "$base\PopupBlocking" if (-not (Test-Path $popup)) { New-Item -Path $popup -Force | Out-Null } Set-ItemProperty -Path $popup -Name "Default" -Value 1 -Type DWord # Proxy $proxy = "$base\Proxy" if (-not (Test-Path $proxy)) { New-Item -Path $proxy -Force | Out-Null } Set-ItemProperty -Path $proxy -Name "Mode" -Value "autoDetect" -Type String # SanitizeOnShutdown $san = "$base\SanitizeOnShutdown" if (-not (Test-Path $san)) { New-Item -Path $san -Force | Out-Null } Set-ItemProperty -Path $san -Name "Cache" -Value 1 -Type DWord Set-ItemProperty -Path $san -Name "Cookies" -Value 0 -Type DWord Set-ItemProperty -Path $san -Name "History" -Value 0 -Type DWord Set-ItemProperty -Path $san -Name "Sessions" -Value 1 -Type DWord Set-ItemProperty -Path $san -Name "SiteSettings" -Value 0 -Type DWord Set-ItemProperty -Path $san -Name "Locked" -Value 1 -Type DWord # SearchEngines $se = "$base\SearchEngines" if (-not (Test-Path $se)) { New-Item -Path $se -Force | Out-Null } Set-ItemProperty -Path $se -Name "Default" -Value "Google" -Type String # UserMessaging $um = "$base\UserMessaging" if (-not (Test-Path $um)) { New-Item -Path $um -Force | Out-Null } Set-ItemProperty -Path $um -Name "ExtensionRecommendations" -Value 0 -Type DWord Set-ItemProperty -Path $um -Name "FeatureRecommendations" -Value 0 -Type DWord Set-ItemProperty -Path $um -Name "FirefoxLabs" -Value 0 -Type DWord Set-ItemProperty -Path $um -Name "Locked" -Value 1 -Type DWord Set-ItemProperty -Path $um -Name "MoreFromMozilla" -Value 0 -Type DWord Set-ItemProperty -Path $um -Name "SkipOnboarding" -Value 1 -Type DWord Set-ItemProperty -Path $um -Name "UrlbarInterventions" -Value 0 -Type DWord Set-ItemProperty -Path $um -Name "WhatsNew" -Value 0 -Type DWord Write-Host "Firefox Registry-Policies erfolgreich gesetzt." -ForegroundColor Green Write-Host "Firefox neu starten damit die Aenderungen wirksam werden." -ForegroundColor Yellow