Files
firefox-addin-manager/Deploy-FirefoxRegistry.ps1
2026-06-10 21:57:50 +02:00

219 lines
9.8 KiB
PowerShell

#Requires -RunAsAdministrator
# Firefox Policy Deployment - Nur Registry-Werte
# Deployment via Intune: Devices > Scripts > Add > Windows PowerShell
# Run as: System | Run in 64-bit: Yes
$base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox"
# ---------------------------------------------------------------
# 1. JSON-String-Wert loeschen (Konflikt-Quelle aus alter Intune-Policy)
# ---------------------------------------------------------------
Remove-ItemProperty -Path $base -Name "ExtensionSettings" -ErrorAction SilentlyContinue
# ---------------------------------------------------------------
# 2. Firefox Basis-Policies (aus firefox.reg uebernommen)
# ---------------------------------------------------------------
$basePolicies = @{
AppAutoUpdate = 1
AutofillAddressEnabled = 0
AutofillCreditCardEnabled = 0
BackgroundAppUpdate = 1
BlockAboutAddons = 0 # MUSS 0 sein - sonst kein Add-on-Manager
BlockAboutConfig = 1
BlockAboutProfiles = 1
DisableDeveloperTools = 1
DisableFeedbackCommands = 1
DisableFirefoxAccounts = 1
DisableFirefoxScreenshots = 1
DisableFirefoxStudies = 1
DisableForgetButton = 1
DisableMasterPasswordCreation = 1
DisablePasswordReveal = 1
DisablePocket = 1
DisableProfileImport = 1
DisableTelemetry = 1
HardwareAcceleration = 0
LegacyProfiles = 0
NetworkPrediction = 0
OfferToSaveLogins = 0
PasswordManagerEnabled = 0
SearchSuggestEnabled = 0
TranslateEnabled = 0
}
if (-not (Test-Path $base)) { New-Item -Path $base -Force | Out-Null }
foreach ($name in $basePolicies.Keys) {
Set-ItemProperty -Path $base -Name $name -Value $basePolicies[$name] -Type DWord
}
# String-Werte
Set-ItemProperty -Path $base -Name "DisplayBookmarksToolbar" -Value "always" -Type String
Set-ItemProperty -Path $base -Name "OverrideFirstRunPage" -Value "" -Type String
Set-ItemProperty -Path $base -Name "SSLVersionMin" -Value "tls1.2" -Type String
# ---------------------------------------------------------------
# 3. ExtensionSettings als Unterkeys (KEIN JSON-String)
# ---------------------------------------------------------------
$extBase = "$base\ExtensionSettings"
if (-not (Test-Path $extBase)) { New-Item -Path $extBase -Force | Out-Null }
$extensions = @{
# Wildcard: alle nicht gelisteten Add-ons blockieren
"*" = @{
installation_mode = "blocked"
}
# Bestehende Add-ons aus Intune-Policy
"keepassxc-browser@keepassxc.org" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/keepassxc-browser/latest.xpi"
}
"acrobat_reader@adobe.com" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/acrobat-reader/latest.xpi"
}
"foxitreader@foxitsoftware.com" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/foxit-reader/latest.xpi"
}
# Neu hinzugefuegte Add-ons
"addon@darkreader.org" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/darkreader/latest.xpi"
}
"uBlock0@raymondhill.net" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/ublock-origin/latest.xpi"
}
"{446900e4-71c2-419f-a6a7-df9c091e268b}" = @{
installation_mode = "force_installed"
install_url = "https://addons.mozilla.org/firefox/downloads/latest/bitwarden-password-manager/latest.xpi"
}
}
foreach ($id in $extensions.Keys) {
$key = "$extBase\$id"
if (-not (Test-Path $key)) { New-Item -Path $key -Force | Out-Null }
foreach ($prop in $extensions[$id].Keys) {
Set-ItemProperty -Path $key -Name $prop -Value $extensions[$id][$prop] -Type String
}
}
# ---------------------------------------------------------------
# 4. Weitere Policy-Unterkeys (aus firefox.reg)
# ---------------------------------------------------------------
# Authentication
$authBase = "$base\Authentication"
if (-not (Test-Path $authBase)) { New-Item -Path $authBase -Force | Out-Null }
$allowProxies = "$authBase\AllowProxies"
if (-not (Test-Path $allowProxies)) { New-Item -Path $allowProxies -Force | Out-Null }
Set-ItemProperty -Path $allowProxies -Name "NTLM" -Value 1 -Type DWord
Set-ItemProperty -Path $allowProxies -Name "SPNEGO" -Value 1 -Type DWord
$ntlm = "$authBase\NTLM"
if (-not (Test-Path $ntlm)) { New-Item -Path $ntlm -Force | Out-Null }
Set-ItemProperty -Path $ntlm -Name "1" -Value "*.hh.hansemerkur.de" -Type String
Set-ItemProperty -Path $ntlm -Name "2" -Value "*.hanse-merkur.de" -Type String
Set-ItemProperty -Path $ntlm -Name "3" -Value "*.hansemerkur.de" -Type String
Set-ItemProperty -Path $ntlm -Name "4" -Value "hansemerkur.flexopus.com" -Type String
# Certificates
$cert = "$base\Certificates"
if (-not (Test-Path $cert)) { New-Item -Path $cert -Force | Out-Null }
Set-ItemProperty -Path $cert -Name "ImportEnterpriseRoots" -Value 1 -Type DWord
# Cookies
$cookies = "$base\Cookies"
if (-not (Test-Path $cookies)) { New-Item -Path $cookies -Force | Out-Null }
Set-ItemProperty -Path $cookies -Name "Behavior" -Value "accept" -Type String
# DNSOverHTTPS
$dns = "$base\DNSOverHTTPS"
if (-not (Test-Path $dns)) { New-Item -Path $dns -Force | Out-Null }
Set-ItemProperty -Path $dns -Name "Enabled" -Value 1 -Type DWord
Set-ItemProperty -Path $dns -Name "Fallback" -Value 1 -Type DWord
# EnableTrackingProtection
$tp = "$base\EnableTrackingProtection"
if (-not (Test-Path $tp)) { New-Item -Path $tp -Force | Out-Null }
Set-ItemProperty -Path $tp -Name "Value" -Value 1 -Type DWord
Set-ItemProperty -Path $tp -Name "Cryptomining" -Value 1 -Type DWord
Set-ItemProperty -Path $tp -Name "Fingerprinting"-Value 1 -Type DWord
Set-ItemProperty -Path $tp -Name "Locked" -Value 1 -Type DWord
Set-ItemProperty -Path $tp -Name "EmailTracking" -Value 1 -Type DWord
# FirefoxHome
$home = "$base\FirefoxHome"
if (-not (Test-Path $home)) { New-Item -Path $home -Force | Out-Null }
Set-ItemProperty -Path $home -Name "Search" -Value 1 -Type DWord
Set-ItemProperty -Path $home -Name "TopSites" -Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "SponsoredTopSites"-Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "Highlights" -Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "Pocket" -Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "SponsoredPocket" -Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "Snippets" -Value 0 -Type DWord
Set-ItemProperty -Path $home -Name "Locked" -Value 0 -Type DWord
# FlashPlugin
$flash = "$base\FlashPlugin"
if (-not (Test-Path $flash)) { New-Item -Path $flash -Force | Out-Null }
Set-ItemProperty -Path $flash -Name "Default" -Value 0 -Type DWord
Set-ItemProperty -Path $flash -Name "Locked" -Value 1 -Type DWord
# InstallAddonsPermission
$iap = "$base\InstallAddonsPermission"
if (-not (Test-Path $iap)) { New-Item -Path $iap -Force | Out-Null }
Set-ItemProperty -Path $iap -Name "Default" -Value 0 -Type DWord
# Permissions
foreach ($perm in @("Autoplay","Camera","Location","Microphone","VirtualReality")) {
$pk = "$base\Permissions\$perm"
if (-not (Test-Path $pk)) { New-Item -Path $pk -Force | Out-Null }
if ($perm -ne "Autoplay") {
Set-ItemProperty -Path $pk -Name "BlockNewRequests" -Value 1 -Type DWord
}
Set-ItemProperty -Path $pk -Name "Locked" -Value 1 -Type DWord
}
# PopupBlocking
$popup = "$base\PopupBlocking"
if (-not (Test-Path $popup)) { New-Item -Path $popup -Force | Out-Null }
Set-ItemProperty -Path $popup -Name "Default" -Value 1 -Type DWord
# Proxy
$proxy = "$base\Proxy"
if (-not (Test-Path $proxy)) { New-Item -Path $proxy -Force | Out-Null }
Set-ItemProperty -Path $proxy -Name "Mode" -Value "autoDetect" -Type String
# SanitizeOnShutdown
$san = "$base\SanitizeOnShutdown"
if (-not (Test-Path $san)) { New-Item -Path $san -Force | Out-Null }
Set-ItemProperty -Path $san -Name "Cache" -Value 1 -Type DWord
Set-ItemProperty -Path $san -Name "Cookies" -Value 0 -Type DWord
Set-ItemProperty -Path $san -Name "History" -Value 0 -Type DWord
Set-ItemProperty -Path $san -Name "Sessions" -Value 1 -Type DWord
Set-ItemProperty -Path $san -Name "SiteSettings" -Value 0 -Type DWord
Set-ItemProperty -Path $san -Name "Locked" -Value 1 -Type DWord
# SearchEngines
$se = "$base\SearchEngines"
if (-not (Test-Path $se)) { New-Item -Path $se -Force | Out-Null }
Set-ItemProperty -Path $se -Name "Default" -Value "Google" -Type String
# UserMessaging
$um = "$base\UserMessaging"
if (-not (Test-Path $um)) { New-Item -Path $um -Force | Out-Null }
Set-ItemProperty -Path $um -Name "ExtensionRecommendations" -Value 0 -Type DWord
Set-ItemProperty -Path $um -Name "FeatureRecommendations" -Value 0 -Type DWord
Set-ItemProperty -Path $um -Name "FirefoxLabs" -Value 0 -Type DWord
Set-ItemProperty -Path $um -Name "Locked" -Value 1 -Type DWord
Set-ItemProperty -Path $um -Name "MoreFromMozilla" -Value 0 -Type DWord
Set-ItemProperty -Path $um -Name "SkipOnboarding" -Value 1 -Type DWord
Set-ItemProperty -Path $um -Name "UrlbarInterventions" -Value 0 -Type DWord
Set-ItemProperty -Path $um -Name "WhatsNew" -Value 0 -Type DWord
Write-Host "Firefox Registry-Policies erfolgreich gesetzt." -ForegroundColor Green
Write-Host "Firefox neu starten damit die Aenderungen wirksam werden." -ForegroundColor Yellow