Brave Browser
com.brave.Browser
Brave Browser Managed Settings
Configuration Keys (343)
| Key | Type | Title |
|---|---|---|
PFC_SegmentedControl_0required | string | — |
CloudReportingEnabledEnables Brave Browser cloud reporting. When this policy is left unset or set to False, there is no data collected or uploaded. When this policy is set to True, the data is collected and uploaded to Google Admin console. | boolean | Enable Cloud Reporting |
CloudExtensionRequestEnabledEnables Brave Browser extension installation requests. When the policy CloudReportingEnabled is left unset or set to disabled, this policy will be ignored, extension installation requests are not created or uploaded. When this policy is left unset or set to disabled, extension installation requests are not created or uploaded. When this policy is set to enabled, extension installation requests are created and uploaded to Google Admin console. | boolean | Enable Cloud Extension Install Requests |
ReportSafeBrowsingDataReport Safe Browsing information. | boolean | Report Safe Browsing |
DefaultClipboardSettingThis policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations. Default: 3 Range: Do not allow any site to use the clipboard site permission (2), Allow sites to ask the user to grant the clipboard site permission (3) | integer | Default clipboard setting |
DefaultCookiesSettingAllows you to set whether websites are allowed to set local data. Setting local data can be either allowed for all websites or denied for all websites. Range: Allow all sites to set local data (1), Do not allow any site to set local data (2), Keep cookies for the duration of the session (4) | integer | Default cookies setting |
BlockThirdPartyCookiesEnabling this setting prevents cookies from being set by web page elements that are not from the domain that is in the browser's address bar. | boolean | Block third party cookies |
CookiesAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to set cookies. | array | Allow cookies on these sites |
CookiesBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to set cookies. | array | Block cookies on these sites |
CookiesSessionOnlyForUrlsCookies set by pages matching these URL patterns will be limited to the current session, i.e. they will be deleted when the browser exits. | array | Limit cookies from matching URLs to the current session |
DefaultWebBluetoothGuardSettingAllows you to set whether websites are allowed to get access to nearby Bluetooth devices. Access can be completely blocked, or the user can be asked every time a website wants to get access to nearby Bluetooth devices. Range: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API (2), Allow sites to ask the user to grant access to a nearby Bluetooth device (3) | integer | Control use of the Web Bluetooth API |
DefaultWebUsbGuardSettingAllows you to set whether websites are allowed to get access to connected USB devices. Access can be completely blocked, or the user can be asked every time a website wants to get access to connected USB devices. Range: Do not allow any site to request access to USB devices via the WebUSB API (2), Allow sites to ask the user to grant access to a connected USB device (3) | integer | Control use of the WebUSB API |
DefaultImagesSettingAllows you to set whether websites are allowed to display images. Displaying images can be either allowed for all websites or denied for all websites. Range: Allow all sites to show all images (1), Do not allow any site to show images (2) | integer | Default images setting |
ImagesAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to display images. | array | Allow images on these sites |
ImagesBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to display images. | array | Block images on these sites |
DefaultInsecureContentSettingControl use of insecure content exceptions. Allows you to set whether users can add exceptions to allow mixed content for specific sites. If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content. Range: Do not allow any site to load mixed content (2), Allow users to add exceptions to allow mixed content (3) | integer | Default insecure content setting |
InsecureContentAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled. | array | Allow insecure content on these sites |
InsecureContentBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded. | array | Block insecure content on these sites |
DefaultJavaScriptSettingAllows you to set whether websites are allowed to run JavaScript. Running JavaScript can be either allowed for all websites or denied for all websites. Range: Allow all sites to run JavaScript (1), Do not allow any site to run JavaScript (2) | integer | Default JavaScript setting |
JavaScriptAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to run JavaScript. | array | Allow JavaScript on these sites |
JavaScriptBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to run JavaScript. | array | Block JavaScript on these sites |
LegacySameSiteCookieBehaviorEnabledAllows you to revert all cookies to legacy SameSite behavior. Range: Revert to legacy SameSite behavior for cookies on all sites (1), Use SameSite-by-default behavior for cookies on all sites (2) | integer | Enable legacy SameSite cookie behavior |
LegacySameSiteCookieBehaviorEnabledForDomainListCookies set for domains matching these patterns will revert to legacy SameSite behavior. For cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be used either from the LegacySameSiteCookieBehaviorEnabled policy, if it is set, or the user's personal configuration otherwise. | array | Enable legacy SameSite cookie behavior for list of domains |
DefaultPluginsSettingAllows you to set whether websites are allowed to automatically run the Flash plugin. Automatically running the Flash plugin can be either allowed for all websites or denied for all websites. Range: Allow all sites to automatically run the Flash plugin (1), Block the Flash plugin (2), Click to play (3) | integer | Default Flash setting |
PluginsAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to run the Flash plugin. | array | Allow the Flash plugin on these sites |
DefaultNotificationsSettingAllows you to set whether websites are allowed to display desktop notifications. Displaying desktop notifications can be allowed by default, denied by default or the user can be asked every time a website wants to show desktop notifications. Range: Allow sites to show desktop notifications (1), Do not allow any site to show desktop notifications (2), Ask every time a site wants to show desktop notifications (3) | integer | Default notification setting |
NotificationsAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to display notifications. | array | Allow notifications on these sites |
NotificationsBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to display notifications. | array | Block notifications on these sites |
PdfLocalFileAccessAllowedForDomainsSetting this policy allows the domains listed to access file:// URLs in the PDF Viewer. | array | Allow local file access to file:// URLs on these sites in the PDF Viewer |
PluginsBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to run the Flash plugin. | array | Block the Flash plugin on these sites |
DefaultPopupsSettingAllows you to set whether websites are allowed to show pop-ups. Showing popups can be either allowed for all websites or denied for all websites. Range: Allow all sites to show pop-ups (1), Do not allow any site to show popups (2) | integer | Default popups setting |
DefaultThirdPartyStoragePartitioningSettingThird-party storage partitioning is on by default for some users as of M113, but can be disabled via Brave Browser flag. If this policy is set to AllowPartitioning or unset, third-party storage partitioning may be enabled. If this policy is set to BlockPartitioning, third-party storage partitioning cannot be enabled. Range: Allow third-party storage partitioning to be enabled (1), Block third-party storage partitioning from being enabled (2) | integer | Default Third Party Storage Partitioning Setting |
PopupsAllowedForUrlsAllows you to set a list of url patterns that specify sites which are allowed to open popups. | array | Allow popups on these sites |
PopupsBlockedForUrlsAllows you to set a list of url patterns that specify sites which are not allowed to open popups. | array | Block popups on these sites |
AutoSelectCertificateForUrlsAllows you to specify a list of url patterns that specify sites for which Brave Browser should automatically select a client certificate, if the site requests a certificate. | array | Automatically select client certificates for these sites |
DefaultGeolocationSettingAllows you to set whether websites are allowed to track the users' physical location. Tracking the users' physical location can be allowed by default, denied by default or the user can be asked every time a website requests the physical location. Range: Allow sites to track the users' physical location (1), Do not allow any site to track the users' physical location (2), Ask whenever a site wants to track the users' physical location (3) | integer | Default geolocation setting |
DefaultMediaStreamSettingAllows you to set whether websites are allowed to get access to media capture devices. Access to media capture devices can be allowed by default, or the user can be asked every time a website wants to get access to media capture devices. - Documentation doesn't indicate when this was deprecated, but AudioCaptureAllowed was added in M25, so making an assumption. Range: Do not allow any site to access the camera and microphone (2), Ask every time a site wants to access the camera and/or microphone (3) | integer | Default mediastream setting |
RegisteredProtocolHandlersAllows you to register a list of protocol handlers. This can only be a recommended policy. The property |protocol| should be set to the scheme such as 'mailto' and the property |url| should be set to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which if present will be replaced by the handled URL. | array | Register protocol handlers |
ThirdPartyStoragePartitioningBlockedForOriginsAllows you to set a list of url patterns that specify top-level (the url in the tab's address bar) origins which block third-party storage partitioning (partitioning of cross-origin iframe storage). If this policy is left not set or a top-level origin doesn't match then the value from DefaultThirdPartyStoragePartitioningSetting will be used. | array | Third Party Storage Partitioning Blocked For Origins |
WebUsbAllowDevicesForUrlsAllows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. | array | Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs |
AutoplayAllowedAllows you to control if videos can play automatically (without user consent) with audio content in Brave Browser. | boolean | Allow media autoplay |
AutoplayWhitelistControls the whitelist of URL patterns that autoplay will always be enabled on. | array | Allow media autoplay on a whitelist of URL patterns |
AutoplayAllowlistControls the allow list of URL patterns that autoplay will always be enabled on. | array | Allow media autoplay on an allow list of URL patterns |
DefaultSearchProviderAlternateURLsSpecifies a list of alternate URLs that can be used to extract search terms from the search engine. The URLs should contain the string '{searchTerms}', which will be used to extract the search terms. | array | List of alternate URLs for the default search provider |
DefaultSearchProviderEnabledEnables the use of a default search provider. | boolean | Enable the default search provider |
DefaultSearchProviderEncodingsSpecifies the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided. | array | Default search provider encodings |
DefaultSearchProviderIconURLSpecifies the favorite icon URL of the default search provider. | string | Default search provider icon |
DefaultSearchProviderImageURLSpecifies the URL of the search engine used to provide image search. Search requests will be sent using the GET method. If the DefaultSearchProviderImageURLPostParams policy is set then image search requests will use the POST method instead. | string | Parameter providing search-by-image feature for the default search provider |
DefaultSearchProviderImageURLPostParamsSpecifies the parameters used when doing image search with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in above example, it will be replaced with real image thumbnail data. | string | Parameters for image URL which uses POST |
DefaultSearchProviderKeywordSpecifies the keyword, which is the shortcut used in the omnibox to trigger the search for this provider. | string | Default search provider keyword |
DefaultSearchProviderNameSpecifies the name of the default search provider. If left empty or not set, the host name specified by the search URL will be used. | string | Default search provider name |
DefaultSearchProviderNewTabURLSpecifies the URL that a search engine uses to provide a new tab page. | string | Default search provider new tab page URL |
DefaultSearchProviderSearchURLSpecifies the URL of the search engine used when doing a default search. The URL should contain the string '{searchTerms}', which will be replaced at query time by the terms the user is searching for. | string | Default search provider search URL |
DefaultSearchProviderSearchURLPostParamsSpecifies the parameters used when searching a URL with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {searchTerms} in above example, it will be replaced with real search terms data. | string | Parameters for search URL which uses POST |
DefaultSearchProviderSuggestURLSpecifies the URL of the search engine used to provide search suggestions. The URL should contain the string '{searchTerms}', which will be replaced at query time by the text the user has entered so far. | string | Default search provider suggest URL |
DefaultSearchProviderSuggestURLPostParamsSpecifies the parameters used when doing suggestion search with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {searchTerms} in above example, it will be replaced with real search terms data. | string | Parameters for suggest URL which uses POST |
ExtensionAllowedTypesControls which app/extension types are allowed to be installed and limits runtime access. | array | Types of extensions/apps that are allowed to be installed |
ExtensionInstallSourcesAllows you to specify which URLs are allowed to install extensions, apps, and themes. | array | URL patterns to allow extension, app, and user script installs from |
ExtensionInstallBlacklistAllows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if denied, without a way for the user to enable them. Once an extension is disabled due to the blacklist being removed, it will automatically get re-enabled. Enter * to deny all extensions. | array | Extension ID Blacklist |
ExtensionInstallBlocklistAllows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if denied, without a way for the user to enable them. Once an extension is disabled due to the blocklist being removed, it will automatically get re-enabled. Enter * to deny all extensions. | array | Extension ID Blocklist |
ExtensionInstallWhitelistAllows you to specify which extensions are not subject to the blacklist. | array | Extension ID Whitelist |
ExtensionInstallAllowlistAllows you to specify which extensions are not subject to the blocklist. | array | Extension ID Allowlist |
ExtensionManifestV2AvailabilityControl if Manifest v2 extensions can be used by browser. Range: Default browser behavior (0), Manifest v2 is disabled (1), Manifest v2 is enabled (2), Manifest v2 is enabled for forced extensions only (3) | integer | ExtensionManifestV2Availability |
ExtensionInstallForcelistSpecifies a list of apps and extensions that are installed silently, without user interaction, and which cannot be uninstalled nor disabled by the user. All permissions requested by the apps/extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the app/extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are not available to apps/extensions that are not force-installed.) | array | Extension/App IDs and update URLs to be silently installed |
ExtensionSettingsConfigures extension management settings for Brave Browser. A default configuration can be set for the special ID "*" | dict | Extension management settings |
BlockExternalExtensionsBlocks external extensions from being installed. Default: false | boolean | Block external extensions |
ExtensionAllowInsecureUpdatesAllow insecure algorithms in integrity checks on extension updates and installs. Default: false | boolean | Allow insecure extension updates |
EnableMediaRouterIf this policy is set to true or is not set, Google Cast will be enabled, and users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon. Default: true | boolean | Enable Google Cast |
ShowCastIconInToolbarIf this policy is set to true, the Cast toolbar icon will always be shown on the toolbar or the overflow menu, and users will not be able to remove it. Default: false | boolean | Show the Google Cast toolbar icon |
AllowCrossOriginAuthPromptControls whether third-party sub-content on a page is allowed to pop-up an HTTP Basic Auth dialog box. Default: false | boolean | Cross-origin HTTP Basic Auth prompts |
AuthNegotiateDelegateByKdcPolicyUse KDC policy to delegate credentials. Controls whether approval by KDC policy is respected to decide whether to delegate Kerberos tickets. Default: false | boolean | Kerberos delegation KDC policy |
AuthNegotiateDelegateWhitelistServers that Brave Browser may delegate to. | string | Kerberos delegation server whitelist |
AuthNegotiateDelegateAllowlistServers that Brave Browser may delegate to. | string | Kerberos delegation server allowlist |
AuthSchemesSpecifies which HTTP authentication schemes are supported by Brave Browser. Possible values are 'basic', 'digest', 'ntlm' and 'negotiate'. Separate multiple values with commas. | string | Supported authentication schemes |
AuthServerWhitelistSpecifies which servers should be whitelisted for integrated authentication. Integrated authentication is only enabled when Brave Browser receives an authentication challenge from a proxy or from a server which is in this permitted list. | string | Authentication server whitelist |
BasicAuthOverHttpEnabledSetting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP. Setting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed. | boolean | Allow Basic authentication for HTTP |
AuthServerAllowlistSpecifies which servers should be allowed for integrated authentication. Integrated authentication is only enabled when Brave Browser receives an authentication challenge from a proxy or from a server which is in this permitted list. | string | Authentication server allowlist |
DisableAuthNegotiateCnameLookupSpecifies whether the generated Kerberos SPN is based on the canonical DNS name or the original name entered. Default: false | boolean | Disable CNAME lookup when negotiating Kerberos authentication |
EnableAuthNegotiatePortSpecifies whether the generated Kerberos SPN should include a non-standard port. Default: false | boolean | Include non-standard port in Kerberos SPN |
NtlmV2EnabledControls whether NTLMv2 is enabled. Default: true | boolean | Enable NTLMv2 authentication |
BrowserSwitcherEnabledThis policy controls whether to enable Legacy Browser Support. When this policy is set to true, Brave Browser will attempt to launch some URLs in an alternate browser. Default: false | boolean | Browser Switcher Enabled |
AlternativeBrowserParametersThis policy controls command-line parameters to launch to the alternative browser. | array | Alternative Browser Parameters |
AlternativeBrowserPathThis policy controls which command to use to open URLs in an alternative browser. Range: ${safari}, ${firefox}, ${opera}, ${ie} | string | Alternative Browser Path |
BrowserSwitcherDelayThis policy controls how long to wait before launching an alternative browser, in milliseconds. When this policy is set to a number, Brave Browser shows a message for that many milliseconds, and then opens the alternative browser. | integer | Browser Switcher Delay |
BrowserSwitcherKeepLastChromeTabThis policy controls whether to close Brave Browser completely when the last tab would switch to another browser. Default: true | boolean | Keep Brave Browser open when the last tab switches to another browser |
BrowserSwitcherUrlListThis policy controls the list of websites to open in an alternative browser. | array | Browser Switcher URL List |
BrowserSwitcherUrlGreylistThis policy controls the list of websites that will never cause a browser switch. | array | Browser Switcher URL Greylist |
BrowserSwitcherExternalGreylistUrlThis policy is a URL, that points to an XML file in the same format as Internet Explorer's SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer. | string | Browser Switcher External Greylist URL |
BrowserSwitcherExternalSitelistUrlThis policy is a URL, that points to an XML file in the same format as Internet Explorer's SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer. | string | Browser Switcher External Sitelist URL |
AbusiveExperienceInterventionEnforceAllows you to set whether sites with abusive experiences should be prevented from opening new windows or tabs. Default: true | boolean | Abusive Experience Intervention Enforce |
AccessibilityImageLabelsEnabledEnable Get Image Descriptions from Google. Enables visually-impaired screen reader users to get descriptions of unlabeled images on the web. | boolean | Allow accessibility descriptions for Google images |
AdsSettingForIntrusiveAdsSitesAllows you to set whether ads should be blocked on sites with intrusive ads. Range: Allow ads on all sites (1), Do not allow ads on sites with intrusive ads (2) | integer | Ads setting for sites with intrusive ads |
LocalNetworkAccessRestrictionsEnabledA policy to control whether users are prompted to allow sites to ask for Local Network Access. Default: false | boolean | Local Network Access Restrictions Enabled |
LocalNetworkAccessAllowedForUrlsA policy to automatically grant specific sites Local Network Access. | array | Local Network Access Allowed For URLs |
LocalNetworkAccessBlockedForUrlsA policy to automatically deny specific sites Local Network Access. | array | Local Network Access Blocked For URLs |
PrivacySandboxAdMeasurementEnabledA policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users. Default: true | boolean | Privacy Sandbox Ad Measurement Enabled |
PrivacySandboxAdTopicsEnabledA policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users. Default: true | boolean | Privacy Sandbox Ad Topics Enabled |
PrivacySandboxPromptEnabledA policy to control whether your users see the Privacy Sandbox prompt. Depends on: PrivacySandboxAdTopicsEnabled ∈ [false]; PrivacySandboxSiteEnabledAdsEnabled ∈ [false]; PrivacySandboxAdMeasurementEnabled ∈ [false] Default: true | boolean | Privacy Sandbox Prompt Enabled |
PrivacySandboxSiteEnabledAdsEnabledA policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users. Default: true | boolean | Privacy Sandbox Site Enabled Ads Enabled |
AdvancedProtectionAllowedEnable additional protections for users enrolled in the Advanced Protection program. Default: true | boolean | Enable Advanced Protection |
AdvancedProtectionDeepScanningEnabledThis policy controls whether users enrolled in the Advanced Protection program are allowed to send their downloads to Google for malware scanning. If set to True or not set, enrolled users will be be prompted to send their files to Google for deep scanning. If the user selects 'Scan', their download will be sent to Google. If set to False, users will not be prompted and their downloads will not be sent to Google. Default: true | boolean | Advanced Protection Deep Scanning |
AllowDeletingBrowserHistoryEnables deleting browser history and download history in Brave Browser and prevents users from changing this setting. Default: true | boolean | Enable deleting browser and download history |
AllowDinosaurEasterEggAllow users to play dinosaur easter egg game when device is offline. | boolean | Allow Dinosaur Easter Egg Game |
AllowFileSelectionDialogsAllows access to local files on the machine by allowing Brave Browser to display file selection dialogs. Default: true | boolean | Allow invocation of file selection dialogs |
AllowOutdatedPluginsIf you enable this setting, outdated plugins are used as normal plugins. | boolean | Allow running plugins that are outdated |
AllowPopupsDuringPageUnloadThis policy allows an admin to specify that a page may show popups during its unloading. Default: false | boolean | Allow a page to show popups during its unloading |
AllowSyncXHRInPageDismissalThis policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal. Default: false | boolean | Allows a page to perform synchronous XHR requests during page dismissal. |
AllowWebAuthnWithBrokenTlsCertsThis policy will allow WebAuthn on sites with invalid TLS certificates. Default: false | boolean | Allow web authentication requests on sites with broken TLS certificates |
AllowedDomainsForAppsEnables Brave Browser's restricted log in feature in G Suite and prevents users from changing this setting. | string | Define domains allowed to access G Suite |
AlternateErrorPagesEnabledEnables the use of alternate error pages that are built into Brave Browser (such as 'page not found') and prevents users from changing this setting. | boolean | Enable alternate error pages |
AlwaysOpenPdfExternallyDisables the internal PDF viewer in Brave Browser. Instead it treats it as download and allows the user to open PDF files with the default application. Default: false | boolean | Always Open PDF files externally |
AmbientAuthenticationInPrivateModesEnabledConfiguring this policy will allow/disallow ambient authenticaiton for Incognito and Guest profiles in Brave Browser. Range: Enable in regular sessions only (0), Enable in incognito and regular sessions (1), Enable in guest and regular sessions (2), Enable in regular, incognito and guest sessions (3) | integer | Ambient Authentication |
AppCacheForceEnabledAllows the AppCache feature to be re-enabled even if it is off by default. | boolean | Force Enable App Cache |
AudioCaptureAllowedIf enabled or not configured (default), the user will be prompted for audio capture access except for URLs configured in the AudioCaptureAllowedUrls list which will be granted access without prompting. Default: true | boolean | Allow or deny audio capture |
AudioSandboxEnabledAllow the audio sandbox to run. If this policy is enabled, the audio process will run sandboxed. If this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process. This leaves users open to security risks related to running the audio subsystem unsandboxed. | boolean | Enable the audio sandbox |
AudioCaptureAllowedUrlsPatterns in this list will be matched against the security origin of the requesting URL. If a match is found, access to audio capture devices will be granted without prompt. | array | URLs that will be granted access to audio capture devices without prompt |
AutoFillEnabledEnable AutoFill. This policy is deprecated in M70, please use AutofillAddressEnabled and AutofillCreditCardEnabled instead. Default: true | boolean | Enable AutoFill |
AutoLaunchProtocolsFromOriginsDefine a list of protocols that can launch an external application from listed origins without prompting the user. If this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. | array | Allow protocols to auto launch external applications |
AutoOpenAllowedForURLsURLs where AutoOpenFileTypes can apply. List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users. | array | Allowed URLs for auto open filetypes |
AutoOpenFileTypesList of file types that should be automatically opened on download. | array | Allow file extensions to auto open |
AutofillAddressEnabledEnables Brave Browser's AutoFill feature and allows users to auto complete address information in web forms using previously stored information. Default: true | boolean | Enable AutoFill for addresses |
AutofillCreditCardEnabledEnables Brave Browser's AutoFill feature and allows users to auto complete credit card information in web forms using previously stored information. Default: true | boolean | Enable AutoFill for credit cards |
BookmarkBarEnabledIf you enable this setting, Brave Browser will show a bookmark bar. | boolean | Enable Bookmark Bar |
BrowserAddPersonEnabledIf this policy is set to true or not configured, Brave Browser will allow Add Person from the user manager. Default: true | boolean | Enable add person in user manager |
BrowserGuestModeEnabledIf this policy is set to true or not configured, Brave Browser will enable guest logins. Guest logins are Brave Browser profiles where all windows are in incognito mode. Default: true | boolean | Enable guest mode in browser |
BrowserGuestModeEnforcedIf this policy is set to enabled, Brave Browser will enforce guest sessions and prevents profile logins. Guest logins are Brave Browser profiles where all windows are in incognito mode. Default: false | boolean | Force guest mode in browser |
BrowserNetworkTimeQueriesEnabledSetting this policy to false stops Brave Browser from occasionally sending queries to a Google server to retrieve an accurate timestamp. These queries will be enabled if this policy is set to True or is not set. Default: true | boolean | Allow queries to a Google time service |
BrowserSigninThis policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Brave Browser with their account and use account related services like Brave Browser sync. Range: Disable browser sign-in (0), Enable browser sign-in (1), Force users to sign-in to use the browser (2) | integer | Browser Signin |
BuiltInDnsClientEnabledControls whether the built-in DNS client is used in Brave Browser. | boolean | Use built-in DNS client |
BuiltinCertificateVerifierEnabledDetermines whether the built-in certificate verifier will be used to verify server certificates. When this setting is enabled, Brave Browser will perform verification of server certificates using the built-in certificate verifier. When this setting is disabled, Brave Browser will perform verification of server certificates using the legacy certificate verifier provided by the platform. When this setting is not set, the built-in or the legacy certificate verifier may be used. | boolean | Use built-in certificate verifier |
CertificateTransparencyEnforcementDisabledForCasDisables enforcing Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes. | array | Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes |
CertificateTransparencyEnforcementDisabledForLegacyCasDisables enforcing Certificate Transparency requirements for a list of Legacy Certificate Authorities. | array | Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities |
CertificateTransparencyEnforcementDisabledForUrlsDisables enforcing Certificate Transparency requirements to the listed URLs. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format. | array | Disable Certificate Transparency enforcement for a list of URLs |
ChromeVariationsDetermine the availability of variations. Default: 0 Range: Enable all variations (0), Enable variations concerning critical fixes only (1), Disable all variations (2) | integer | Brave Browser Variations |
ClickToCallEnabledEnable the Click to Call Feature. Default: true | boolean | Enable Click to Call |
CloudManagementEnrollmentTokenIf this policy is set, Brave Browser will try to register itself and apply associated cloud policy for all profiles. | string | Cloud Management Enrollment Token |
CloudManagementEnrollmentMandatoryIf this policy is set to True, cloud management enrollment is mandatory and blocks Brave Browser launch process if failed. Default: false | boolean | Make cloud managment enrollment mandatory |
CloudPolicyOverridesPlatformPolicyIf the policy is set to true, cloud policy takes precedence if it conflicts with platform policy. If the policy is set to false or not configured, platform policy takes precedence if it conflicts with cloud policy. Default: false | boolean | Cloud Policy Overrides Platform Policy |
CommandLineFlagSecurityWarningsEnabledIf disabled, prevents security warnings from appearing when Brave Browser is launched with some potentially dangerous command-line flags. Default: true | boolean | Command Line Flag Security Warnings Enabled |
ComponentUpdatesEnabledEnables component updates for all components in Brave Browser when not set or set to True. Default: true | boolean | Enable component updates in Brave Browser |
CorsLegacyModeEnabledUse the legacy CORS implementation rather than new CORS. Default: true | boolean | Enable Cross-Origin Resource Sharing legacy mode |
CorsMitigationListEnable CORS check mitigations in the new CORS implementation, allowing Extensions to keep compatible behavior, and allowing Brave Browser to send specified headers without CORS checks. | array | Cross-Origin Resource Sharing mitigation list |
DNSInterceptionChecksEnabledThis policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. Default: true | boolean | DNS Interception Checks |
DefaultBrowserSettingEnabledConfigures the default browser checks in Brave Browser and prevents users from changing them. | boolean | Set Brave Browser as Default Browser |
PromotionsEnabledSetting the policy to True or leaving it unset lets Brave Browser show users product promotional content. Default: true | boolean | Show Promotional Content |
DefaultDownloadDirectoryConfigures the default directory that Brave Browser will use for downloading files. This policy is not mandatory, so the user will be able to change the directory. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used. | string | Set default download directory |
DefaultSearchProviderContextMenuAccessAllowedAllow default search provider context menu search access. Default: true | boolean | Enable default search provider on context menu |
DeveloperToolsAvailabilityAllows you to control where Developer Tools can be used. Range: Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts (0), Allow usage of the Developer Tools (1), Disallow usage of the Developer Tools (2) | integer | Control where Developer Tools can be used |
Disable3DAPIsEnabling this setting prevents web pages from accessing the graphics processing unit (GPU). Specifically, web pages can not access the WebGL API and plugins can not use the Pepper 3D API. Default: false | boolean | Disable support for 3D graphics APIs |
DisableSafeBrowsingProceedAnywayThe Safe Browsing service shows a warning page when users navigate to sites that are flagged as potentially malicious. Enabling this setting prevents users from proceeding anyway from the warning page to the malicious site. Default: false | boolean | Disable proceeding from the Safe Browsing warning page |
DisableScreenshotsIf enabled, screenshots cannot be taken using keyboard shortcuts or extension APIs. Default: false | boolean | Disable taking screenshots |
DisabledPluginsThis policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that are disabled in Brave Browser and prevents users from changing this setting. | array | Disabled Plugins |
DisabledPluginsExceptionsThis policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that user can enable or disable in Brave Browser. | array | Disabled Plugins Exceptions |
DisabledSchemesThis policy is deprecated, please use URLBlocklist instead. Disables the listed protocol schemes in Brave Browser. | array | Disabled URL Protocol Schemes |
DiskCacheDirConfigures the directory that Brave Browser will use for storing cached files on the disk. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used. To avoid data loss or other unexpected errors this policy should not be set to a volume's root directory or to a directory used for other purposes, because Brave Browser manages its contents | string | Set disk cache directory |
DiskCacheSizeConfigures the cache size that Brave Browser will use for storing cached files on the disk. The value specified in this policy is not a hard boundary but rather a suggestion to the caching system, any value below a few megabytes is too small and will be rounded up to a sane minimum. If the value of this policy is 0, the default cache size will be used but the user will not be able to change it. | integer | Set disk cache size |
DnsOverHttpsModeControls the mode of DNS-over-HTTPS Range: Disable DNS-over-HTTPS (off), Enable DNS-over-HTTPS with insecure fallback (automatic), Enable DNS-over-HTTPS without insecure fallback (secure) | string | DNS-over-HTTPS mode |
DnsOverHttpsTemplatesSpecify URI template of desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces. | string | DNS-over-HTTPS mode |
DomainReliabilityAllowedThis policy will allow sending domain reliability data to Google | boolean | Allow reporting of domain reliability related data |
DownloadDirectoryConfigures the directory that Brave Browser will use for downloading files. If you set this policy, Brave Browser will use the provided directory regardless whether the user has specified one or enabled the flag to be prompted for download location every time. If this policy is left not set the default download directory will be used and the user will be able to change it. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used. | string | Set download directory |
DownloadRestrictionsConfigures the type of downloads that Brave Browser will completely block, without letting users override the security decision. Range: No special restrictions (0), Block malicious downloads and dangerous file types (1), Block malicious downloads, uncommon or unwanted downloads and dangerous file types (2), Block all downloads (3), Block malicious downloads (4) | integer | Download restrictions |
EditBookmarksEnabledIf you enable this setting, bookmarks can be added, removed or modified. This is the default also when this policy is not set. Default: true | boolean | Enable or disable bookmark editing |
EnableDeprecatedWebPlatformFeaturesExampleDeprecatedFeature_EffectiveUntil20080902 - Enable ExampleDeprecatedFeature API through 2008/09/02 Specify a list of deprecated web platform features to re-enable temporarily. | array | Enable deprecated web platform features for a limited time |
EnableExperimentalPoliciesAllows Brave Browser to load experimental policies. | array | Enable experimental policies |
EnableOnlineRevocationChecksIn light of the fact that soft-fail, online revocation checks provide no effective security benefit, they are disabled by default in Chromium version 19 and later. By setting this policy to true, the previous behavior is restored and online OCSP/CRL checks will be performed. Default: false | boolean | Whether online OCSP/CRL checks are performed |
EnabledPluginsThis policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that are enabled in Brave Browser and prevents users from changing this setting. | array | Enabled Plugins |
EncryptedClientHelloEnabledThis policy will allow encryption of TLS ClientHello for enhanced privacy. Default: true | boolean | Enable TLS Encrypted ClientHello |
EnterpriseHardwarePlatformAPIEnabledWhen this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API. Default: false | boolean | Enable Managed Extensions to use the Enterprise Hardware API |
EnterpriseProfileCreationKeepBrowsingDataThis policy will allow keeping browsing data in new enterprise profiles Default: false | boolean | Keep browsing data when creating enterprise profile by default |
EnterpriseRealTimeUrlCheckModeThis policy controls checking URLs in real time to identify unsafe URLs. If this policy is left not set or set to ‘Disabled', the consumer Safe Browsing checks will be applied. If this policy is set to ‘Enabled', URLs will be sent to be scanned in real time under enterprise ToS. It will result in Brave Browser sending URLs to Google Cloud or third parties of your choosing to check them in real time. The consumer version of Safe Browsing real time lookup will be switched off. Range: Disabled (0), Enabled (1) | integer | Check Safe Browsing status of URLs in real time |
ExternalProtocolDialogShowAlwaysOpenCheckboxShow an "Always open" checkbox in external protocol dialog. Default: true | boolean | Display "Always open" checkbox in external protocol dialog |
FileOrDirectoryPickerWithoutGestureAllowedForOriginsThis policy will allow file picker APIs without user gesture for specified origins | array | Allow file or directory picker APIs to be called without prior user gesture |
ForceBrowserSigninIf this policy is set to true, user has to sign in to Brave Browser with their profile before using the browser. And the default value of BrowserGuestModeEnabled will be set to false. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article. This policy is deprecated, consider using BrowserSignin instead. Default: false | boolean | Enable force sign in for Brave Browser |
ForceEphemeralProfilesIf set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account. Default: false | boolean | Ephemeral profile |
ForceGoogleSafeSearchForces queries in Google Web Search to be done with SafeSearch set to active and prevents users from changing this setting. Default: false | boolean | Force Google SafeSearch |
ForceSafeSearchThis policy is deprecated, please use ForceGoogleSafeSearch and ForceYouTubeRestrict instead. This policy is ignored if either the ForceGoogleSafeSearch, the ForceYouTubeRestrict or the (deprecated) ForceYouTubeSafetyMode policies are set. Default: false | boolean | Force SafeSearch |
ForceLegacyDefaultReferrerPolicyThis enterprise policy is for short-term adaptation and will be removed in M82. Default: false | boolean | Force Legacy Default Referrer |
GloballyScopeHTTPAuthCacheEnabledThis policy configures a single global per profile cache with HTTP server authentication credentials. Default: false | boolean | Enable globally scoped HTTP auth cache |
GoogleSearchSidePanelEnabledThis policy will allow Google Search Side Panel. Default: true | boolean | Enable Google Search Side Panel |
ForceYouTubeRestrictEnforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode. Range: Do not enforce Restricted Mode on YouTube (0), Enforce at least Moderate Restricted Mode on YouTube (1), Enforce Strict Restricted Mode for YouTube (2) | integer | Force minimum YouTube Restricted Mode |
ForceYouTubeSafetyModeThis policy is deprecated. Consider using ForceYouTubeRestrict, which overrides this policy and allows more fine-grained tuning. Forces YouTube Moderate Restricted Mode and prevents users from changing this setting. Default: false | boolean | Force YouTube Safety Mode |
HardwareAccelerationModeEnabledIf this policy is set to true or left unset, hardware acceleration will be enabled unless a certain GPU feature is blacklisted. Default: true | boolean | Use hardware acceleration when available |
HideWebStoreIconHide the Chrome Web Store app and footer link from the New Tab Page and Brave Browser OS app launcher. Default: false | boolean | Hide the web store from the New Tab Page and app launcher |
HSTSPolicyBypassListList of names that will bypass the HSTS policy check. Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from http to https. | array | HSTS Policy Bypass List |
Http09OnNonDefaultPortsEnabledThis policy enables HTTP/0.9 on ports other than 80 for HTTP and 443 for HTTPS. Default: false | boolean | Enable HTTP/0.9 support on non-default ports |
HttpsUpgradesEnabledThis policy will allow automatic HTTPS upgrades. Default: true | boolean | Enable automatic HTTPS upgrades |
ImportAutofillFormDataThis policy forces the autofill form data to be imported from the previous default browser if enabled. If enabled, this policy also affects the import dialog. | boolean | Import autofill form data from default browser on first run |
ImportBookmarksThis policy forces bookmarks to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog. Default: true | boolean | Import bookmarks from default browser on first run |
ImportHistoryThis policy forces the browsing history to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog. | boolean | Import browsing history from default browser on first run |
ImportHomepageThis policy forces the home page to be imported from the current default browser if enabled. | boolean | Import of homepage from default browser on first run |
ImportSavedPasswordsThis policy forces the saved passwords to be imported from the previous default browser if enabled. If enabled, this policy also affects the import dialog. | boolean | Import saved passwords from default browser on first run |
ImportSearchEngineThis policy forces search engines to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog. | boolean | Import search engines from default browser on first run |
IncognitoEnabledThis policy is deprecated. Please, use IncognitoModeAvailability instead. Enables Incognito mode in Brave Browser. If this setting is enabled or not configured, users can open web pages in incognito mode. Default: true | boolean | Enable Incognito |
IncognitoModeAvailabilitySpecifies whether the user may open pages in Incognito mode in Brave Browser. Range: Incognito mode available (0), Incognito mode disabled (1), Incognito mode forced (2) | integer | Incognito mode availability |
IntensiveWakeUpThrottlingEnabledWhen enabled, the IntensiveWakeUpThrottling feature causes JavaScript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more. | boolean | Enable Intensive Wake Up Throttling |
IsolateOriginsIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process. This will also isolate origins named by subdomains; e.g. specifying https://example.com/ will also cause https://foo.example.com/ to be isolated as part of the https://example.com/ site. If the policy is disabled, no explicit Site Isolation will happen and field trials of IsolateOrigins and SitePerProcess will be disabled. Users will still be able to enable IsolateOrigins manually. If the policy is not configured, the user will be able to change this setting. On Brave Browser OS, it is recommended to also set the DeviceLoginScreenIsolateOrigins device policy to the same value. If the values specified by the two policies don't match, a delay may be incurred when entering a user session while the value specified by user policy is being applied. | string | Enable Site Isolation for specified origins |
JavascriptEnabledThis policy is deprecated, please use DefaultJavaScriptSetting instead. Can be used to disabled JavaScript in Brave Browser. Default: true | boolean | Javascript Enabled |
LocalDiscoveryEnabledThis policy controls access to controllable features in the local discovery UI (chrome://devices) which shows discoverable devices near the user as well as cloud devices registered to them. On all operating systems except for Brave Browser OS, the local discovery UI also allows users to add classic printers connected to their computers to Google Cloud Print. | boolean | Enable chrome://devices |
LookalikeWarningAllowlistDomainsThis policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Brave Browser believes might be trying to spoof another site the user is familiar with. If the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain. If the policy is disabled, not set, or set to an empty list, warnings may appear on any site the user visits. | array | Suppress lookalike domain warnings on domains |
MachineLevelUserCloudPolicyEnrollmentTokenThe enrollment token of cloud policy on desktop. This policy is deprecated in M72. Please use CloudManagementEnrollmentToken instead. | string | The enrollment token of cloud policy on desktop |
ManagedBookmarksConfigures a list of managed bookmarks. | array | Managed Bookmarks |
MaxConnectionsPerProxySpecifies the maximal number of simultaneous connections to the proxy server. Default: 32 | integer | Maximal number of concurrent connections to the proxy server |
MaxInvalidationFetchDelaySpecifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Default: 5000 Range: 1000 – 300000 | integer | Maximum fetch delay after a policy invalidation |
MediaRecommendationsEnabledBy default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user. | boolean | Enable Media Recommendations |
MediaRouterCastAllowAllIPsIf this policy is set to true, Google Cast will connect to Cast devices on all IP addresses, not just RFC1918/RFC4913 private addresses. | boolean | Allow Google Cast to connect to Cast devices on all IP addresses. |
MetricsReportingEnabledEnables anonymous reporting of usage and crash-related data about Brave Browser to Google and prevents users from changing this setting. | boolean | Enable reporting of usage and crash-related data |
NetworkPredictionOptions(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.) Enables network prediction in Brave Browser and prevents users from changing this setting. Range: Predict network actions on any network connection (0), Predict network actions on any network that is not cellular. (1), Do not predict network actions on any network connection (2) | integer | Enable network prediction |
NTPCardsVisibleThis policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior. If the policy is set to Enabled, the New Tab Page will show cards if content is available. If the policy is set to Disabled, the New Tab Page won't show cards. | boolean | Show cards on the New Tab Page |
NTPCustomBackgroundEnabledAllow users to customize the background on the New Tab page Default: true | boolean | Allow New Tab page background customization |
OverrideSecurityRestrictionsOnInsecureOriginThe policy specifies a list of origins (URLs) or hostname patterns (such as "*.example.com") to be treated as secure contexts. The intent is to allow organizations to set up a staging server for internal web development, so that their developers can test out features requiring secure contexts without having to deploy TLS on the staging server. Setting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If the policy is set, it will override the command-line flag. For more information on secure contexts, see https://www.w3.org/TR/secure-contexts/ | array | Origins or hostname patterns to be treated as secure context. |
PaymentMethodQueryEnabledAllows you to set whether websites are allowed to check if the user has payment methods saved. Default: true | boolean | Payment Method Query |
PolicyAtomicGroupsEnabledEnables the concept of policy atomic groups. Default: true | boolean | Enable Policy Atomic Groups |
PolicyDictionaryMultipleSourceMergeListAllows the selected policies to be merged when they come from different sources, with the same scopes and level. Entered strings must match a Brave Browser policy / key name that uses a dictionary for its data type. | array | Allow merging dictionary policies from different sources |
PolicyListMultipleSourceMergeListAllows the selected policies to be merged when they come from different sources, with the same scopes and level. Entered strings must match a Brave Browser policy / key name that use an array (list) of strings for its data type. | array | Allow merging list policies from different sources |
PolicyRefreshRateRefresh rate for user policy. Specifies the period in milliseconds at which the device management service is queried for user policy information. Setting this policy overrides the default value of 3 hours. Valid values for this policy are in the range from 1800000 (30 minutes) to 86400000 (1 day). Default: 10800000 Range: 1800000 – 86400000 | integer | Policy Refresh Rate |
ProfilePickerOnStartupAvailabilitySpecifies whether the profile picker is enabled, disabled or forced at the browser startup. By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true. Range: Profile picker available at startup (0), Profile picker disabled at startup (1), Profile picker forced at startup (2) | integer | Profile picker availabily on startup |
PromotionalTabsEnabledAllows you to control the presentation of full-tab promotional and/or educational content in Brave Browser. Default: true | boolean | Enable showing full-tab promotional content |
PromptForDownloadLocationIf the policy is enabled, the user will be asked where to save each file before downloading. If the policy is disabled, downloads will start immediately, and the user will not be asked where to save the file. If the policy is not configured, the user will be able to change this setting. | boolean | Ask where to save each file before downloading |
QuicAllowedIf this policy is set to true or not set usage of QUIC protocol in Brave Browser is allowed. If this policy is set to false usage of QUIC protocol is disallowed. Default: true | boolean | Allow QUIC protocol |
RelaunchNotificationNotify users that Brave Browser must be relaunched to apply a pending update. Range: Show a recurring prompt to the user indicating that a relaunch is recommended (1), Show a recurring prompt to the user indicating that a relaunch is required (2) | integer | Notify a user that a browser relaunch is recommended or required |
RelaunchNotificationPeriodAllows you to set the time period, in milliseconds, over which users are notified that Brave Browser must be relaunched or that a Brave Browser OS device must be restarted to apply a pending update. | integer | Update time period |
RemoteDebuggingAllowedControls whether users may use remote debugging. Default: true | boolean | Allow remote debugging |
RestrictSigninToPatternContains a regular expression which is used to determine which users can sign in to Brave Browser. | string | Restrict which users are allowed to sign in to Brave Browser |
RunAllFlashInAllowModeIf you enable this setting, all Flash content embedded on websites that have been set to allow Flash in content settings -- either by the user or by enterprise policy -- will be run, including content from other origins or small content. Default: false | boolean | Extend Flash content setting to all content |
SafeBrowsingForTrustedSourcesEnabledSetting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source. Setting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source. Default: true | boolean | Safe Browsing checks |
SafeSitesFilterBehaviorThis policy controls the application of the SafeSites URL filter. This filter uses the Google Safe Search API to classify URLs as pornographic or not. Range: Do not filter sites for adult content (0), Filter top level sites (but not embedded iframes) for adult content (1) | integer | Control SafeSites adult content filtering. |
SavingBrowserHistoryDisabledDisables saving browser history in Brave Browser and prevents users from changing this setting. Default: false | boolean | Disable saving browser history |
ScreenCaptureAllowedIf enabled or not configured (default), a Web page can use screen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API) to prompt the user to select a tab, window or desktop to capture. Default: true | boolean | Screen Capture |
ScrollToTextFragmentEnabledThis feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete. Default: true | boolean | Enable scroll to text fragment |
SearchSuggestEnabledEnables search suggestions in Brave Browser's omnibox and prevents users from changing this setting. | boolean | Enable search suggestions |
SecurityKeyPermitAttestationSpecifies URLs and domains for which no prompt will be shown when attestation certificates from Security Keys are requested. Additionally, a signal will be sent to the Security Key indicating that individual attestation may be used. Without this, users will be prompted in Chromium 65+ when sites request attestation of Security Keys. | array | URLs/domains automatically permitted direct Security Key attestation |
SharedClipboardEnabledEnables the Shared Clipboard feature which allows users to send text between Brave Browser Desktops and an Android device when Sync is enabled and the user is Signed-in. Default: true | boolean | Enable Shared Clipboard |
ShowAppsShortcutInBookmarkBarEnables or disables the apps shortcut in the bookmark bar. | boolean | Show the apps shortcut in the bookmark bar |
ShowFullUrlsInAddressBarThis feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply. | boolean | Show Full URLs |
SignedHTTPExchangeEnabledEnable support for Signed HTTP Exchange (SXG). Default: true | boolean | Enabled Signed HTTP Exchange (SXG) support |
SigninAllowedThis policy is deprecated, consider using BrowserSignin instead. Allows the user to sign in to Brave Browser. | boolean | Allow sign in |
SigninInterceptionEnabledThis settings enables or disables signin interception. When this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile. When this is set to False, the signin interception dialog does not trigger. | boolean | Enable signin interception |
SitePerProcessYou might want to look at the IsolateOrigins policy setting to get the best of both worlds, isolation and limited impact for users, by using IsolateOrigins with a list of the sites you want to isolate. This setting, SitePerProcess, isolates all sites. If the policy is enabled, each site will run in its own process. If the policy is disabled, no explicit Site Isolation will happen and field trials of IsolateOrigins and SitePerProcess will be disabled. Users will still be able to enable SitePerProcess manually. If the policy is not configured, the user will be able to change this setting. On Brave Browser OS, it is recommended to also set the DeviceLoginScreenSitePerProcess device policy to the same value. If the values specified by the two policies don't match, a delay may be incurred when entering a user session while the value specified by user policy is being applied. | boolean | Enable Site Isolation for every site |
SpellCheckServiceEnabledBrave Browser can use a Google web service to help resolve spelling errors. If this setting is enabled, then this service is always used. If this setting is disabled, then this service is never used. | boolean | Enable or disable spell checking web service |
SpellcheckEnabledIf this policy is not set or enabled, the user is allowed to use spellcheck. | boolean | Enable spellcheck |
SSLErrorOverrideAllowedBrave Browser shows a warning page when users navigate to sites that have SSL errors. By default or when this policy is set to true, users are allowed to click through these warning pages. Setting this policy to false disallows users to click through any warning page. Default: true | boolean | Allow proceeding from the SSL warning page |
SSLVersionMinIf this policy is not configured then Brave Browser uses a default minimum version which is TLS 1.0. Range: TLS 1.0 (tls1), TLS 1.1 (tls1.1), TLS 1.2 (tls1.2) | string | Minimum SSL version enabled |
StrictMimetypeCheckForWorkerScriptsEnabledThis policy enables strict MIME type checking for worker scripts. Default: true | boolean | Enable strict MIME type checking for worker scripts |
StricterMixedContentTreatmentEnabledThis policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser. If the policy is set to true or unset, audio and video mixed content will be autoupgraded to HTTPS (i.e. the URL will be rewritten as HTTPS, without a fallback if the resource is not available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content. If the policy is set to false, autoupgrades will be disabled for audio and video, and no warning will be shown for images. This policy does not affect other types of mixed content other than audio, video, and images. This policy will no longer take effect starting in Chromium 84. Default: true | boolean | Stricter Mixed Content Treatment |
SuppressUnsupportedOSWarningSuppresses the warning that appears when Brave Browser is running on a computer or operating system that is no longer supported. | boolean | Suppress the unsupported OS warning |
SyncDisabledDisables data synchronization in Brave Browser using Google-hosted synchronization services and prevents users from changing this setting. | boolean | Disable synchronization of data with Google |
SyncTypesListDisabledIf this policy is set, all specified data types will be excluded from synchronization both for Google Sync as well as for roaming profile synchronization. | array | Sync types to disable |
TargetBlankImpliesNoOpenerSetting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup. Setting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel="opener". Default: true | boolean | Do not set window.opener for links targeting _blank |
TaskManagerEndProcessEnabledIf set to false, the 'End process' button is disabled in the Task Manager. Default: true | boolean | Enable ending processes in Task Manager |
TLS13HardeningForLocalAnchorsEnabledEnable a TLS 1.3 security feature for local trust anchors. This policy controls a security feature in TLS 1.3 which protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible. Default: true | boolean | Enable TLS 1.3 hardening for local anchors |
TotalMemoryLimitMbConfigures the amount of memory that a single Brave Browser instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory. The minimum allowed value is 1024. Range: 1024 – — | integer | Total Memory Limit |
TranslateEnabledEnables the integrated Google Translate service on Brave Browser. | boolean | Enable Translate |
URLBlacklistThis policy prevents the user from loading web pages from blacklisted URLs. The denylist provides a list of URL patterns that specify which URLs will be denied. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format. | array | URL Blacklist |
URLBlocklistThis policy prevents the user from loading web pages from blocked URLs. The blocklist provides a list of URL patterns that specify which URLs will be denied. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format. | array | URL Blocklist |
URLWhitelistAllows access to the listed URLs, as exceptions to the URL denylist. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format. | array | Allow access to a list of URLs |
URLAllowlistAllows access to the listed URLs, as exceptions to the URL block list. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format. | array | Allow access to a list of URLs |
UnsafelyTreatInsecureOriginAsSecureDeprecated in M69. Use OverrideSecurityRestrictionsOnInsecureOrigin instead. The policy specifies a list of origins (URLs) or hostname patterns (such as "*.example.com") for which security restrictions on insecure origins will not apply. | array | Origins or hostname patterns for which restrictions on insecure origins should not apply |
UrlKeyedAnonymizedDataCollectionEnabledEnable URL-keyed anonymized data collection in Brave Browser and prevents users from changing this setting. | boolean | Enable URL-keyed anonymized data collection |
UserAgentClientHintsEnabledWhen enabled the User-Agent Client Hints feature sends granular request headers providing information about the user browser and environment. | boolean | Enable user agent client hints |
UserFeedbackAllowedAllow user feedback. If the policy is set to false, users can not send feedback to Google. Default: true | boolean | Allow user feedback |
UserDataDirConfigures the directory that Brave Browser will use for storing user data. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used. | string | Set user data directory |
UserDataSnapshotRetentionLimitLimits the number of user data snapshots retained for use in case of emergency rollback. If this policy is not set, the default value of 3 is used. If the policy is set to 0, no snapshots will be taken. Default: 3 | integer | User data snapshot retention limit |
VideoCaptureAllowedIf enabled or not configured (default), the user will be prompted for video capture access except for URLs configured in the VideoCaptureAllowedUrls list which will be granted access without prompting. Default: true | boolean | Allow or deny video capture |
VideoCaptureAllowedUrlsPatterns in this list will be matched against the security origin of the requesting URL. If a match is found, access to audio capture devices will be granted without prompt. | array | URLs that will be granted access to video capture devices without prompt |
WebAppInstallForceListSpecifies a list of websites that are installed silently, without user interaction, and which cannot be uninstalled nor disabled by the user. | array | WebApp Force Install List |
WebComponentsV0EnabledThe Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84. Default: false | boolean | Re-enable Web Components v0 API until M84 |
WebDriverOverridesIncompatiblePoliciesThis policy allows users of the WebDriver feature to override policies which can interfere with its operation. Default: false | boolean | Allow WebDriver to Override Incompatible Policies |
WebRtcAllowLegacyTLSProtocolsf enabled, WebRTC peer connections can downgrade to obsolete versions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols. When this policy is disabled or not set, these TLS/DTLS versions are disabled. | boolean | Allow legacy TLS/DTLS downgrade in WebRTC |
WebRtcEventLogCollectionAllowedIf the policy is set to true, Brave Browser is allowed to collect WebRTC event logs from Google services (e.g. Google Meet), and upload those logs to Google. | boolean | Allow collection of WebRTC event logs from Google services |
WebRtcLocalIpsAllowedUrlsPatterns in this list will be matched against the security origin of the requesting URL. If a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates. Otherwise, local IP addresses are concealed with mDNS hostnames. | array | Allowed WebRTC local IP URLs |
WebRtcUdpPortRangeIf the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included). | string | Restrict the range of local UDP ports used by WebRTC |
WPADQuickCheckEnabledAllows to turn off WPAD (Web Proxy Auto-Discovery) optimization in Brave Browser. Default: true | boolean | Enable WPAD optimization |
NativeMessagingBlacklistAllows you to specify which native messaging hosts that should not be loaded. A blacklist value of '*' means all native messaging hosts are denied unless they are explicitly listed in the allowlist. | array | Native Messaging Host Blacklist |
NativeMessagingBlocklistAllows you to specify which native messaging hosts that should not be loaded. A block list value of '*' means all native messaging hosts are denied unless they are explicitly listed in the allow list. | array | Native Messaging Host Blocklist |
NativeMessagingUserLevelHostsEnables user-level installation of Native Messaging hosts. | boolean | Allow user-level Native Messaging hosts (installed without admin permissions) |
NativeMessagingWhitelistAllows you to specify which native messaging hosts are not subject to the blacklist. A blacklist value of * means all native messaging hosts are denied and only native messaging hosts listed in the whitelist will be loaded. | array | Native Messaging Host Whitelist |
NativeMessagingAllowlistAllows you to specify which native messaging hosts are not subject to the block list. A block list value of * means all native messaging hosts are denied and only native messaging hosts listed in the allow list will be loaded. | array | Native Messaging Host Allowlist |
PasswordLeakDetectionEnabledThis policy can be used to force enable or force disable credential leak checking in Brave Browser. | boolean | Enable password leak detection |
PasswordManagerEnabledIf this setting is enabled, users can have Brave Browser memorize passwords and provide them automatically the next time they log in to a site. | boolean | Enable saving passwords to the password manager |
CloudPrintProxyEnabledEnables Brave Browser to act as a proxy between Google Cloud Print and legacy printers connected to the machine. Default: true | boolean | Enable Google Cloud Print proxy |
CloudPrintSubmitEnabledEnables Brave Browser to submit documents to Google Cloud Print for printing. NOTE: This only affects Google Cloud Print support in Brave Browser. It does not prevent users from submitting print jobs on web sites. Default: true | boolean | Enable submission of documents to Google Cloud Print |
DefaultPrinterSelectionOverrides Brave Browser default printer selection rules. | string | Default printer selection rules |
DisablePrintPreviewShow the system print dialog instead of print preview. Default: false | boolean | Disable Print Preview |
PrintHeaderFooterForce 'headers and footers' to be on or off in the printing dialog. | boolean | Print Headers & Footers |
PrinterTypeDenyListThe printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched. | array | Printer Type Deny List |
PrintingAllowedBackgroundGraphicsModesRestricts background graphics printing mode. Unset policy is treated as no restriction. Range: Allow printing both with and without background graphics (any), Allow printing only with background graphics (enabled), Allow printing only without background graphics (disabled) | string | Background graphics printing mode |
PrintingBackgroundGraphicsDefaultOverrides default background graphics printing mode. Range: Enabled (enabled), Disabled (disabled) | string | Default background graphics printing mode |
PrintingEnabledEnables printing in Brave Browser and prevents users from changing this setting. Default: true | boolean | Enable printing |
PrintPreviewUseSystemDefaultPrinterCauses Brave Browser to use the system default printer as the default choice in Print Preview instead of the most recently used printer. Default: false | boolean | Use System Default Printer as Default |
PrinterPaperSizeDefaultOverrides default printing page size. If 'custom' is provided, custom size width and height keys must also be included. | dict | Default printer paper size |
ProxyBypassListBrave Browser will bypass any proxy for the list of hosts given here. | string | Comma-separated list of proxy bypass rules |
ProxySettingsConfigures the proxy settings for Brave Browser. These proxy settings will be available for ARC-apps too. If you enable this setting, Brave Browser and ARC-apps ignore all proxy-related options specified from the command line. | dict | Proxy Settings |
ProxyModeAllows you to specify the proxy server used by Brave Browser and prevents users from changing proxy settings. Range: Never use a proxy (direct), Auto detect proxy settings (auto_detect), Use a .pac proxy script (pac_script), Use fixed proxy servers (fixed_servers), Use system proxy settings (system) | string | Choose how to specify proxy server settings |
ProxyPacUrlYou can specify a URL to a proxy .pac file here. | string | URL to a proxy .pac file |
ProxyServerYou can specify the URL of the proxy server here. | string | Address or URL of proxy server |
ProxyServerModeThis policy is deprecated, use ProxyMode instead. Allows you to specify the proxy server used by Brave Browser and prevents users from changing proxy settings. Range: Never use a proxy (0), Auto detect proxy settings (1), Manually specify proxy settings (2), Use system proxy settings (3) | integer | Proxy server settings |
RemoteAccessHostAllowClientPairingIf this setting is enabled or not configured, then users can opt to pair clients and hosts at connection time, eliminating the need to enter a PIN every time. Default: true | boolean | Enable or disable PIN-less authentication for remote access hosts |
RemoteAccessHostAllowFileTransferControls the ability of a user connected to a remote access host to transfer files between the client and the host. This does not apply to remote assistance connections, which do not support file transfer. | boolean | Allow remote access file transfer |
RemoteAccessHostAllowGnubbyAuthIf this setting is enabled, then gnubby authentication requests will be proxied across a remote host connection. Default: false | boolean | Allow gnubby authentication for remote access hosts |
RemoteAccessHostAllowRelayedConnectionEnables usage of relay servers when remote clients are trying to establish a connection to this machine. Default: true | boolean | Enable the use of relay servers by the remote access host |
RemoteAccessHostClientDomainConfigure the required domain name for remote access clients. This policy is deprecated. Please use RemoteAccessHostClientDomainList instead. | array | Configure the required domain names for remote access clients |
RemoteAccessHostClientDomainListConfigures the required client domain names that will be imposed on remote access clients and prevents users from changing it. | array | Configure the required domain names for remote access clients |
RemoteAccessHostDomainConfigure the required domain name for remote access hosts. This policy is deprecated. Please use RemoteAccessHostDomainList instead. | array | Configure the required domain names for remote access hosts |
RemoteAccessHostDomainListConfigures the required host domain names that will be imposed on remote access hosts and prevents users from changing it. | array | Configure the required domain names for remote access hosts |
RemoteAccessHostFirewallTraversalEnables usage of STUN servers when remote clients are trying to establish a connection to this machine. Default: false | boolean | Enable firewall traversal from remote access host |
RemoteAccessHostMatchUsernameIf this setting is enabled, then the remote access host compares the name of the local user (that the host is associated with) and the name of the Google account registered as the host owner (i.e. "johndoe" if the host is owned by "johndoe@example.com" Google account). The remote access host will not start if the name of the host owner is different from the name of the local user that the host is associated with. RemoteAccessHostMatchUsername policy should be used together with RemoteAccessHostDomain to also enforce that the Google account of the host owner is associated with a specific domain (i.e. "example.com"). Default: false | boolean | Require that the name of the local user and the remote access host owner match |
RemoteAccessHostRequireCurtainEnables curtaining of remote access hosts while a connection is in progress. Default: false | boolean | Enable curtaining of remote access hosts |
RemoteAccessHostTalkGadgetPrefixConfigures the TalkGadget prefix that will be used by remote access hosts and prevents users from changing it. | string | Configure the TalkGadget prefix for remote access hosts |
RemoteAccessHostTokenUrlIf this policy is set, the remote access host will require authenticating clients to obtain an authentication token from this URL in order to connect. Must be used in conjunction with RemoteAccessHostTokenValidationUrl. | string | URL where remote access clients should obtain their authentication token |
RemoteAccessHostTokenValidationCertificateIssuerIf this policy is set, the host will use a client certificate with the given issuer CN to authenticate to RemoteAccessHostTokenValidationUrl. Set it to "*" to use any available client certificate. | string | Client certificate for connecting to RemoteAccessHostTokenValidationUrl |
RemoteAccessHostTokenValidationUrlIf this policy is set, the remote access host will use this URL to validate authentication tokens from remote access clients, in order to accept connections. Must be used in conjunction with RemoteAccessHostTokenUrl. | string | URL for validating remote access client authentication token |
RemoteAccessHostUdpPortRangeRestricts the UDP port range used by the remote access host in this machine. | string | Restrict the UDP port range used by the remote access host |
PasswordProtectionChangePasswordURLConfigure the change password URL (HTTP and HTTPS schemes only). Password protection service will send users to this URL to change their password after seeing a warning in the browser. In order for Brave Browser to correctly capture the new password fingerprint on this change password page, please make sure your change password page follows the guidelines on https://www.chromium.org/developers/design-documents/create-amazing-password-forms. | string | Configure the change password URL. |
PasswordProtectionLoginURLsConfigure the list of enterprise login URLs (HTTP and HTTPS schemes only). Fingerprint of password will be captured on these URLs and used for password reuse detection. In order for Brave Browser to correctly capture password fingerprints, please make sure your login pages follow the guidelines on https://www.chromium.org/developers/design-documents/create-amazing-password-forms. | array | Configure the list of enterprise login URLs where password protection service should capture fingerprint of password. |
PasswordProtectionWarningTriggerAllows you to control the triggering of passwore protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites. Range: Password protection warning is off (0), Password protection warning is triggered by password reuse (1), Password protection warning is triggered by password reuse on phishing page (2) | integer | Password protection warning trigger |
SafeBrowsingEnabledEnables Brave Browser's Safe Browsing feature and prevents users from changing this setting. | boolean | Enable Safe Browsing |
SafeBrowsingExtendedReportingEnabledEnables Brave Browser's Safe Browsing Extended Reporting and prevents users from changing this setting. | boolean | Enable Safe Browsing Extended Reporting |
SafeBrowsingProtectionLevelAllows you to control whether Brave Browser's Safe Browsing feature is enabled and the mode it operates in. Safe Browsing 'enhanced' mode provides better security, but requires sharing more browsing information with Google. Default: 1 Range: Safe Browsing is never active (0), Safe Browsing is active in the standard mode (1), Safe Browsing is active in the enhanced mode (2) | integer | Safe Browsing protection level |
SafeBrowsingWhitelistDomainsConfigure the list of domains which Safe Browsing will trust. This means: Safe Browsing will not check for dangerous resources (e.g. phishing, malware, or unwanted software) if their URLs match these domains. Safe Browsing's download protection service will not check downloads hosted on these domains. Safe Browsing's password protection service will not check for password reuse if the page URL matches these domains. | array | Configure the list of domains on which Safe Browsing will not trigger warnings. |
SafeBrowsingAllowlistDomainsConfigure the list of domains which Safe Browsing will trust. This means: Safe Browsing will not check for dangerous resources (e.g. phishing, malware, or unwanted software) if their URLs match these domains. Safe Browsing's download protection service will not check downloads hosted on these domains. Safe Browsing's password protection service will not check for password reuse if the page URL matches these domains. | array | Configure the list of domains on which Safe Browsing will not trigger warnings. |
SafeBrowsingExtendedReportingOptInAllowedThis setting is deprecated, use SafeBrowsingExtendedReportingEnabled instead. Enabling or disabling SafeBrowsingExtendedReportingEnabled is equivalent to setting SafeBrowsingExtendedReportingOptInAllowed to False. Default: true | boolean | Allow users to opt in to Safe Browsing extended reporting |
HomepageIsNewTabPageConfigures the type of the default home page in Brave Browser and prevents users from changing home page preferences. The home page can either be set to a URL you specify or set to the New Tab Page. | boolean | Use New Tab Page as homepage |
HomepageLocationConfigures the default home page URL in Brave Browser and prevents users from changing it. | string | Home page URL |
NewTabPageLocationConfigures the default New Tab page URL and prevents users from changing it. | string | New Tab page URL |
RestoreOnStartupAllows you to specify the behavior on startup. Range: Open New Tab Page (5), Restore the last session (1), Open a list of URLs (4), Open a list of URLs and restore the last session (6) | integer | Action on startup |
RestoreOnStartupURLsIf 'Open a list of URLs' is selected as the startup action, this allows you to specify the list of URLs that are opened. If left not set no URL will be opened on start up. | array | URLs to open on startup |
ShowHomeButtonShows the Home button on Brave Browser's toolbar. | boolean | Show Home button on toolbar |
WebUsbAskForUrlsAllows you to set a list of url patterns that specify sites which are allowed to ask the user to grant them access to a USB device. | array | Allow WebUSB on these sites |
WebUsbBlockedForUrlsAllows you to set a list of url patterns that specify sites which are prevented from asking the user to grant them access to a USB device. | array | Block WebUSB on these sites |
DeveloperToolsDisabledDisables the Developer Tools and the JavaScript console. This policy is deprecated in M68, please use DeveloperToolsAvailability instead. Default: false | boolean | Control where Developer Tools can be used |
TorDisabledIf 'true', Tor is disabled. Default: false | boolean | Disable Tor |
IPFSEnabledIf 'false', IPFS is disabled. Default: true | boolean | Enable IPFS |
BraveRewardsDisabledIf 'true', Brave Rewards are disabled. Default: false | boolean | Disable Brave Rewards |
BraveWalletDisabledIf 'true', Brave Wallet is disabled. Default: false | boolean | Disable Brave Wallet |
BraveShieldsDisabledForUrlsArray of websites (each as a string) for which you want to enable Brave shields. Once enabled, the user can’t override and disable. Wildcards are not supported. | array | Brave Shields Disabled for URLs |
BraveShieldsEnabledForUrlsArray of websites (each as a string) for which you want to enable Brave shields. Once enabled, the user can’t override and disable. Wildcards are not supported. | array | Brave Shields Enabled for URLs |
BraveVPNDisabledIf 'true', Brave VPN is disabled. Default: false | boolean | Disable Brave VPN |
BraveAIChatEnabledIf 'false', Brave AI Chat is disabled. Default: true | boolean | Enable Brave AI Chat |
SUFeedURLSetting this to a non-existent URL will disable the ability for users to manually check for updates. Useful when you intend to use your own software distribution mechanism to deploy updates. | string | Sparkle Feed URL |
SUEnableAutomaticChecksControls automatic update checks. Default: true | boolean | Enable Automatic Update Checks |
SUScheduledCheckIntervalControls the automatic update check interval. The default is 1 day (86400 seconds). Setting to 0 disables updates. Default: 86400 | integer | Automatic Update Check Interval |
SUAllowsAutomaticUpdatesControls the automatic update install prompt. When enabled, presents users with the option to allow automatic download and install of available updates. If disabled, disallows automatic updates and requires manual installation every time. Default: true | boolean | Automatic Update Install Prompt |
SUAutomaticallyUpdateControls automatic silent updates. If enabled, users will not be informed about updates and updates will be silently installed when the app quits. Default: false | boolean | Enable Automatic Silent Updates |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | Domains |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
RegisteredProtocolDictionary | dict | — |
defaultDefault: true | boolean | — |
protocol | string | — |
url | string | — |
ThirdPartyStoragePartitioningBlockedForOriginsElement | string | — |
| dict | — |
urls | array | URLs |
devices | array | Devices |
| string | — |
| dict | — |
product_id | integer | — |
vendor_id | integer | — |
| string | — |
| string | — |
| string | — |
| string | — |
Range: Extension (extension), Hosted App (hosted_app), Legacy Packaged App (legacy_packaged_app), Platform App (platform_app), Theme (theme), User Script (user_script) | string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
{{key}} | string | Extension ID |
{{value}} | dict | — |
installation_modeMaps to a string indicating the installation mode for the extension. Range: Allowed (allowed), Blocked (blocked), Force Installed (force_installed), Normal Installed (normal_installed) | string | — |
update_urlMaps to a string indicating where Brave Browser can download a force_installed or normal_installed extension. | string | — |
blocked_permissionsMaps to a list of strings indicating the blocked API permissions for the extension. | array | — |
minimum_version_requiredMaps to a version string. | string | — |
ExtensionUnpublishedAvailabilityIf this policy is enabled, extensions that are unpublished on the Chrome Web Store will be disabled in Brave Browser Default: 0 Range: Allow unpublished extensions (0), Disable unpublished extensions (1) | integer | Control availability of extensions unpublished on the Brave Browser Web Store. |
install_sourcesEach item in this list is an extension-style match pattern. | array | — |
allowed_typesThis setting whitelists the allowed types of extension/apps that can be installed in Brave Browser. | array | — |
blocked_install_messageThis maps to a string specifying the error message to display to users if they're blocked from installing an extension. | string | — |
runtime_blocked_hostsMaps to a list of strings representing hosts whose webpages the extension will be blocked from modifying. | array | — |
runtime_allowed_hostsMaps to a list of strings representing hosts that an extension can interact with regardless of whether they are listed in "runtime_blocked_hosts". | array | — |
Range: activeTab, alarms, background, bookmarks, browsingData, certificateProvider, clipboardRead, clipboardWrite, contentSettings, contextMenus, cookies, debugger, declarativeContent, declarativeNetRequest, declarativeWebRequest, desktopCapture, displaySource, dns, documentScan, downloads, enterprise.deviceAttributes, enterprise.hardwarePlatform, enterprise.platformKeys, experimental, fileBrowserHandler, fileSystemProvider, fontSettings, gcm, geolocation, history, identity, idle, idltest, management, nativeMessaging, networking.config, notifications, pageCapture, platformKeys, power, printerProvider, privacy, processes, proxy, sessions, signedInDevices, storage, system.cpu, system.display, system.memory, system.storage, tabCapture, tabs, topSites, tts, ttsEngine, unlimitedStorage, vpnProvider, wallpaper, webNavigation, webRequest, webRequestBlocking | string | — |
| string | — |
Range: extension, theme, user_script, hosted_app, legacy_packaged_app, platform_app | string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| dict | — |
allowed_originsA list of allowed origin patterns for the specified protocol. | array | Allowed Origins |
protocol | string | Protocol |
allowed_originsItem | string | — |
| string | URL |
| string | File Extension |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | Preference Key Name |
| string | — |
| string | — |
| string | Hostname |
| string | Domain |
| dict | — |
The top-level managed bookmarks folder name. | dict | Managed Bookmarks Folder Name |
nameName of the bookmark. | string | — |
urlURL for the bookmark. | string | — |
toplevel_name | string | Top Level Name |
| string | — |
| string | — |
| string | — |
| string | — |
Range: Apps (apps), Autofill (autofill), Bookmarks (bookmarks), Extensions (extensions), Passwords (passwords), Preferences (preferences), Tabs (tabs), Themes (themes), Typed URLs (typedUrls), Wifi Configuration (wifiConfiguration) | string | Data Types |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| dict | — |
url | string | URL |
create_desktop_shortcut | boolean | Create Desktop Shortcut |
default_launch_containerRange: Window (window), Tab (tab) | string | Default Launch Container |
fallback_app_name | string | Fallback App Name |
custom_name | string | Custom Name |
custom_icon | dict | Custom Icon |
install_as_shortcut | boolean | Install as Shortcut |
hash | string | Custom Icon Hash |
url | string | Custom Icon URL |
| string | URL |
| string | — |
| string | — |
| string | — |
| string | — |
Range: Zeroconf-based (mDNS + DNS-SD) protocol destinations (privet), Extension-based destinations (extension), The 'Save as PDF' destination (pdf), Local printer destinations (local), Google Cloud Print and 'Save to Google Drive' destinations (cloud) | string | Printer Type |
custom_sizeDepends on: PrinterPaperSizeDefault.name ∈ [custom] | dict | Custom Size |
nameRange: custom, asme_f_28x40in, iso_2a0_1189x1682mm, iso_a0_841x1189mm, iso_a1_594x841mm, iso_a2_420x594mm, iso_a3_297x420mm, iso_a4-extra_235.5x322.3mm, iso_a4-tab_225x297mm, iso_a4_210x297mm, iso_a5-extra_174x235mm, iso_a5_148x210mm, iso_a6_105x148mm, iso_a7_74x105mm, iso_a8_52x74mm, iso_a9_37x52mm, iso_a10_26x37mm, iso_b0_1000x1414mm, iso_b1_707x1000mm, iso_b2_500x707mm, iso_b3_353x500mm, iso_b4_250x353mm, iso_b5-extra_201x276mm, iso_b5_176x250mm, iso_b6_125x176mm, iso_b6c4_125x324mm, iso_b7_88x125mm, iso_b8_62x88mm, iso_b9_44x62mm, iso_b10_31x44mm, iso_c0_917x1297mm, iso_c1_648x917mm, iso_c2_458x648mm, iso_c3_324x458mm, iso_c4_229x324mm, iso_c5_162x229mm, iso_c6_114x162mm, iso_c6c5_114x229mm, iso_c7_81x114mm, iso_c7c6_81x162mm, iso_c8_57x81mm, iso_c9_40x57mm, iso_c10_28x40mm, iso_dl_110x220mm, jis_exec_216x330mm, jpn_chou2_111.1x146mm, jpn_chou3_120x235mm, jpn_chou4_90x205mm, jpn_hagaki_100x148mm, jpn_kahu_240x322.1mm, jpn_kaku2_240x332mm, jpn_oufuku_148x200mm, jpn_you4_105x235mm, na_10x11_10x11in, na_10x13_10x13in, na_10x14_10x14in, na_10x15_10x15in, na_11x12_11x12in, na_11x15_11x15in, na_12x19_12x19in, na_5x7_5x7in, na_6x9_6x9in, na_7x9_7x9in, na_9x11_9x11in, na_a2_4.375x5.75in, na_arch-a_9x12in, na_arch-b_12x18in, na_arch-c_18x24in, na_arch-d_24x36in, na_arch-e_36x48in, na_b-plus_12x19.17in, na_c5_6.5x9.5in, na_c_17x22in, na_d_22x34in, na_e_34x44in, na_edp_11x14in, na_eur-edp_12x14in, na_f_44x68in, na_fanfold-eur_8.5x12in, na_fanfold-us_11x14.875in, na_foolscap_8.5x13in, na_govt-legal_8x13in, na_govt-letter_8x10in, na_index-3x5_3x5in, na_index-4x6-ext_6x8in, na_index-4x6_4x6in, na_index-5x8_5x8in, na_invoice_5.5x8.5in, na_ledger_11x17in, na_legal-extra_9.5x15in, na_legal_8.5x14in, na_letter-extra_9.5x12in, na_letter-plus_8.5x12.69in, na_letter_8.5x11in, na_number-10_4.125x9.5in, na_number-11_4.5x10.375in, na_number-12_4.75x11in, na_number-14_5x11.5in, na_personal_3.625x6.5in, na_super-a_8.94x14in, na_super-b_13x19in, na_wide-format_30x42in, om_dai-pa-kai_275x395mm, om_folio-sp_215x315mm, om_invite_220x220mm, om_italian_110x230mm, om_juuro-ku-kai_198x275mm, om_large-photo_200x300, om_pa-kai_267x389mm, om_postfix_114x229mm, om_small-photo_100x150mm, prc_10_324x458mm, prc_16k_146x215mm, prc_1_102x165mm, prc_2_102x176mm, prc_32k_97x151mm, prc_3_125x176mm, prc_4_110x208mm, prc_5_110x220mm, prc_6_120x320mm, prc_7_160x230mm, prc_8_120x309mm, roc_16k_7.75x10.75in, roc_8k_10.75x15.5in, jis_b0_1030x1456mm, jis_b1_728x1030mm, jis_b2_515x728mm, jis_b3_364x515mm, jis_b4_257x364mm, jis_b5_182x257mm, jis_b6_128x182mm, jis_b7_91x128mm, jis_b8_64x91mm, jis_b9_45x64mm, jis_b10_32x45mm | string | Name |
widthWidth of the page Depends on: PrinterPaperSizeDefault.name ∈ [custom] | integer | Width |
heightHeight of the page Depends on: PrinterPaperSizeDefault.name ∈ [custom] | integer | Height |
ProxyModeSpecifies the proxy server Brave Browser uses and prevents users from changing proxy settings. Range: Never use proxy (ignores other fields) (direct), System (ignores other fields) (system), Auto Detect (ignores other fields) (auto_detect), Fixed (Uses ProxyServer & ProxyBypassList) (fixed_servers), Pac Script (Uses ProxyPacUrl & ProxyBypassList) (pac_script) | string | Proxy Mode |
ProxyServerSpecifies the URL of the proxy server | string | Proxy Server URL |
ProxyBypassListDefines a comma-separated list of hosts for which Brave Browser bypasses any proxy. | string | Proxy Bypass List |
ProxyPacUrlSpecifies the URL for a proxy auto-config (PAC) file. | string | Proxy PAC URL |
ProxyPacMandatoryPrevents the network stack from falling back to direct connections with invalid or unavailable PAC script. | boolean | Proxy PAC Mandatory |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
| string | — |
URL | string | — |
| string | — |
| string | — |
BraveShieldsDisabledForUrlsElement | string | — |
BraveShieldsDisabledForUrlsElement | string | — |