PayloadKit

Brave Browser

com.brave.Browser

Brave Browser Managed Settings

macOS
combined

Configuration Keys (343)

KeyTypeTitle
PFC_SegmentedControl_0required
string
CloudReportingEnabled

Enables Brave Browser cloud reporting. When this policy is left unset or set to False, there is no data collected or uploaded. When this policy is set to True, the data is collected and uploaded to Google Admin console.

booleanEnable Cloud Reporting
CloudExtensionRequestEnabled

Enables Brave Browser extension installation requests. When the policy CloudReportingEnabled is left unset or set to disabled, this policy will be ignored, extension installation requests are not created or uploaded. When this policy is left unset or set to disabled, extension installation requests are not created or uploaded. When this policy is set to enabled, extension installation requests are created and uploaded to Google Admin console.

booleanEnable Cloud Extension Install Requests
ReportSafeBrowsingData

Report Safe Browsing information.

booleanReport Safe Browsing
DefaultClipboardSetting

This policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations.

Default: 3

Range: Do not allow any site to use the clipboard site permission (2), Allow sites to ask the user to grant the clipboard site permission (3)

integerDefault clipboard setting
DefaultCookiesSetting

Allows you to set whether websites are allowed to set local data. Setting local data can be either allowed for all websites or denied for all websites.

Range: Allow all sites to set local data (1), Do not allow any site to set local data (2), Keep cookies for the duration of the session (4)

integerDefault cookies setting
BlockThirdPartyCookies

Enabling this setting prevents cookies from being set by web page elements that are not from the domain that is in the browser's address bar.

booleanBlock third party cookies
CookiesAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to set cookies.

arrayAllow cookies on these sites
CookiesBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to set cookies.

arrayBlock cookies on these sites
CookiesSessionOnlyForUrls

Cookies set by pages matching these URL patterns will be limited to the current session, i.e. they will be deleted when the browser exits.

arrayLimit cookies from matching URLs to the current session
DefaultWebBluetoothGuardSetting

Allows you to set whether websites are allowed to get access to nearby Bluetooth devices. Access can be completely blocked, or the user can be asked every time a website wants to get access to nearby Bluetooth devices.

Range: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API (2), Allow sites to ask the user to grant access to a nearby Bluetooth device (3)

integerControl use of the Web Bluetooth API
DefaultWebUsbGuardSetting

Allows you to set whether websites are allowed to get access to connected USB devices. Access can be completely blocked, or the user can be asked every time a website wants to get access to connected USB devices.

Range: Do not allow any site to request access to USB devices via the WebUSB API (2), Allow sites to ask the user to grant access to a connected USB device (3)

integerControl use of the WebUSB API
DefaultImagesSetting

Allows you to set whether websites are allowed to display images. Displaying images can be either allowed for all websites or denied for all websites.

Range: Allow all sites to show all images (1), Do not allow any site to show images (2)

integerDefault images setting
ImagesAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to display images.

arrayAllow images on these sites
ImagesBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to display images.

arrayBlock images on these sites
DefaultInsecureContentSetting

Control use of insecure content exceptions. Allows you to set whether users can add exceptions to allow mixed content for specific sites. If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.

Range: Do not allow any site to load mixed content (2), Allow users to add exceptions to allow mixed content (3)

integerDefault insecure content setting
InsecureContentAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.

arrayAllow insecure content on these sites
InsecureContentBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.

arrayBlock insecure content on these sites
DefaultJavaScriptSetting

Allows you to set whether websites are allowed to run JavaScript. Running JavaScript can be either allowed for all websites or denied for all websites.

Range: Allow all sites to run JavaScript (1), Do not allow any site to run JavaScript (2)

integerDefault JavaScript setting
JavaScriptAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to run JavaScript.

arrayAllow JavaScript on these sites
JavaScriptBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to run JavaScript.

arrayBlock JavaScript on these sites
LegacySameSiteCookieBehaviorEnabled

Allows you to revert all cookies to legacy SameSite behavior.

Range: Revert to legacy SameSite behavior for cookies on all sites (1), Use SameSite-by-default behavior for cookies on all sites (2)

integerEnable legacy SameSite cookie behavior
LegacySameSiteCookieBehaviorEnabledForDomainList

Cookies set for domains matching these patterns will revert to legacy SameSite behavior. For cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be used either from the LegacySameSiteCookieBehaviorEnabled policy, if it is set, or the user's personal configuration otherwise.

arrayEnable legacy SameSite cookie behavior for list of domains
DefaultPluginsSetting

Allows you to set whether websites are allowed to automatically run the Flash plugin. Automatically running the Flash plugin can be either allowed for all websites or denied for all websites.

Range: Allow all sites to automatically run the Flash plugin (1), Block the Flash plugin (2), Click to play (3)

integerDefault Flash setting
PluginsAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to run the Flash plugin.

arrayAllow the Flash plugin on these sites
DefaultNotificationsSetting

Allows you to set whether websites are allowed to display desktop notifications. Displaying desktop notifications can be allowed by default, denied by default or the user can be asked every time a website wants to show desktop notifications.

Range: Allow sites to show desktop notifications (1), Do not allow any site to show desktop notifications (2), Ask every time a site wants to show desktop notifications (3)

integerDefault notification setting
NotificationsAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to display notifications.

arrayAllow notifications on these sites
NotificationsBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to display notifications.

arrayBlock notifications on these sites
PdfLocalFileAccessAllowedForDomains

Setting this policy allows the domains listed to access file:// URLs in the PDF Viewer.

arrayAllow local file access to file:// URLs on these sites in the PDF Viewer
PluginsBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to run the Flash plugin.

arrayBlock the Flash plugin on these sites
DefaultPopupsSetting

Allows you to set whether websites are allowed to show pop-ups. Showing popups can be either allowed for all websites or denied for all websites.

Range: Allow all sites to show pop-ups (1), Do not allow any site to show popups (2)

integerDefault popups setting
DefaultThirdPartyStoragePartitioningSetting

Third-party storage partitioning is on by default for some users as of M113, but can be disabled via Brave Browser flag. If this policy is set to AllowPartitioning or unset, third-party storage partitioning may be enabled. If this policy is set to BlockPartitioning, third-party storage partitioning cannot be enabled.

Range: Allow third-party storage partitioning to be enabled (1), Block third-party storage partitioning from being enabled (2)

integerDefault Third Party Storage Partitioning Setting
PopupsAllowedForUrls

Allows you to set a list of url patterns that specify sites which are allowed to open popups.

arrayAllow popups on these sites
PopupsBlockedForUrls

Allows you to set a list of url patterns that specify sites which are not allowed to open popups.

arrayBlock popups on these sites
AutoSelectCertificateForUrls

Allows you to specify a list of url patterns that specify sites for which Brave Browser should automatically select a client certificate, if the site requests a certificate.

arrayAutomatically select client certificates for these sites
DefaultGeolocationSetting

Allows you to set whether websites are allowed to track the users' physical location. Tracking the users' physical location can be allowed by default, denied by default or the user can be asked every time a website requests the physical location.

Range: Allow sites to track the users' physical location (1), Do not allow any site to track the users' physical location (2), Ask whenever a site wants to track the users' physical location (3)

integerDefault geolocation setting
DefaultMediaStreamSetting

Allows you to set whether websites are allowed to get access to media capture devices. Access to media capture devices can be allowed by default, or the user can be asked every time a website wants to get access to media capture devices. - Documentation doesn't indicate when this was deprecated, but AudioCaptureAllowed was added in M25, so making an assumption.

Range: Do not allow any site to access the camera and microphone (2), Ask every time a site wants to access the camera and/or microphone (3)

integerDefault mediastream setting
RegisteredProtocolHandlers

Allows you to register a list of protocol handlers. This can only be a recommended policy. The property |protocol| should be set to the scheme such as 'mailto' and the property |url| should be set to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which if present will be replaced by the handled URL.

arrayRegister protocol handlers
ThirdPartyStoragePartitioningBlockedForOrigins

Allows you to set a list of url patterns that specify top-level (the url in the tab's address bar) origins which block third-party storage partitioning (partitioning of cross-origin iframe storage). If this policy is left not set or a top-level origin doesn't match then the value from DefaultThirdPartyStoragePartitioningSetting will be used.

arrayThird Party Storage Partitioning Blocked For Origins
WebUsbAllowDevicesForUrls

Allows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs.

arrayAutomatically grant permission to these sites to connect to USB devices with the given vendor and product IDs
AutoplayAllowed

Allows you to control if videos can play automatically (without user consent) with audio content in Brave Browser.

booleanAllow media autoplay
AutoplayWhitelist

Controls the whitelist of URL patterns that autoplay will always be enabled on.

arrayAllow media autoplay on a whitelist of URL patterns
AutoplayAllowlist

Controls the allow list of URL patterns that autoplay will always be enabled on.

arrayAllow media autoplay on an allow list of URL patterns
DefaultSearchProviderAlternateURLs

Specifies a list of alternate URLs that can be used to extract search terms from the search engine. The URLs should contain the string '{searchTerms}', which will be used to extract the search terms.

arrayList of alternate URLs for the default search provider
DefaultSearchProviderEnabled

Enables the use of a default search provider.

booleanEnable the default search provider
DefaultSearchProviderEncodings

Specifies the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.

arrayDefault search provider encodings
DefaultSearchProviderIconURL

Specifies the favorite icon URL of the default search provider.

stringDefault search provider icon
DefaultSearchProviderImageURL

Specifies the URL of the search engine used to provide image search. Search requests will be sent using the GET method. If the DefaultSearchProviderImageURLPostParams policy is set then image search requests will use the POST method instead.

stringParameter providing search-by-image feature for the default search provider
DefaultSearchProviderImageURLPostParams

Specifies the parameters used when doing image search with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in above example, it will be replaced with real image thumbnail data.

stringParameters for image URL which uses POST
DefaultSearchProviderKeyword

Specifies the keyword, which is the shortcut used in the omnibox to trigger the search for this provider.

stringDefault search provider keyword
DefaultSearchProviderName

Specifies the name of the default search provider. If left empty or not set, the host name specified by the search URL will be used.

stringDefault search provider name
DefaultSearchProviderNewTabURL

Specifies the URL that a search engine uses to provide a new tab page.

stringDefault search provider new tab page URL
DefaultSearchProviderSearchURL

Specifies the URL of the search engine used when doing a default search. The URL should contain the string '{searchTerms}', which will be replaced at query time by the terms the user is searching for.

stringDefault search provider search URL
DefaultSearchProviderSearchURLPostParams

Specifies the parameters used when searching a URL with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {searchTerms} in above example, it will be replaced with real search terms data.

stringParameters for search URL which uses POST
DefaultSearchProviderSuggestURL

Specifies the URL of the search engine used to provide search suggestions. The URL should contain the string '{searchTerms}', which will be replaced at query time by the text the user has entered so far.

stringDefault search provider suggest URL
DefaultSearchProviderSuggestURLPostParams

Specifies the parameters used when doing suggestion search with POST. It consists of comma-separated name/value pairs. If a value is a template parameter, like {searchTerms} in above example, it will be replaced with real search terms data.

stringParameters for suggest URL which uses POST
ExtensionAllowedTypes

Controls which app/extension types are allowed to be installed and limits runtime access.

arrayTypes of extensions/apps that are allowed to be installed
ExtensionInstallSources

Allows you to specify which URLs are allowed to install extensions, apps, and themes.

arrayURL patterns to allow extension, app, and user script installs from
ExtensionInstallBlacklist

Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if denied, without a way for the user to enable them. Once an extension is disabled due to the blacklist being removed, it will automatically get re-enabled. Enter * to deny all extensions.

arrayExtension ID Blacklist
ExtensionInstallBlocklist

Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if denied, without a way for the user to enable them. Once an extension is disabled due to the blocklist being removed, it will automatically get re-enabled. Enter * to deny all extensions.

arrayExtension ID Blocklist
ExtensionInstallWhitelist

Allows you to specify which extensions are not subject to the blacklist.

arrayExtension ID Whitelist
ExtensionInstallAllowlist

Allows you to specify which extensions are not subject to the blocklist.

arrayExtension ID Allowlist
ExtensionManifestV2Availability

Control if Manifest v2 extensions can be used by browser.

Range: Default browser behavior (0), Manifest v2 is disabled (1), Manifest v2 is enabled (2), Manifest v2 is enabled for forced extensions only (3)

integerExtensionManifestV2Availability
ExtensionInstallForcelist

Specifies a list of apps and extensions that are installed silently, without user interaction, and which cannot be uninstalled nor disabled by the user. All permissions requested by the apps/extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the app/extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are not available to apps/extensions that are not force-installed.)

arrayExtension/App IDs and update URLs to be silently installed
ExtensionSettings

Configures extension management settings for Brave Browser. A default configuration can be set for the special ID "*"

dictExtension management settings
BlockExternalExtensions

Blocks external extensions from being installed.

Default: false

booleanBlock external extensions
ExtensionAllowInsecureUpdates

Allow insecure algorithms in integrity checks on extension updates and installs.

Default: false

booleanAllow insecure extension updates
EnableMediaRouter

If this policy is set to true or is not set, Google Cast will be enabled, and users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.

Default: true

booleanEnable Google Cast
ShowCastIconInToolbar

If this policy is set to true, the Cast toolbar icon will always be shown on the toolbar or the overflow menu, and users will not be able to remove it.

Default: false

booleanShow the Google Cast toolbar icon
AllowCrossOriginAuthPrompt

Controls whether third-party sub-content on a page is allowed to pop-up an HTTP Basic Auth dialog box.

Default: false

booleanCross-origin HTTP Basic Auth prompts
AuthNegotiateDelegateByKdcPolicy

Use KDC policy to delegate credentials. Controls whether approval by KDC policy is respected to decide whether to delegate Kerberos tickets.

Default: false

booleanKerberos delegation KDC policy
AuthNegotiateDelegateWhitelist

Servers that Brave Browser may delegate to.

stringKerberos delegation server whitelist
AuthNegotiateDelegateAllowlist

Servers that Brave Browser may delegate to.

stringKerberos delegation server allowlist
AuthSchemes

Specifies which HTTP authentication schemes are supported by Brave Browser. Possible values are 'basic', 'digest', 'ntlm' and 'negotiate'. Separate multiple values with commas.

stringSupported authentication schemes
AuthServerWhitelist

Specifies which servers should be whitelisted for integrated authentication. Integrated authentication is only enabled when Brave Browser receives an authentication challenge from a proxy or from a server which is in this permitted list.

stringAuthentication server whitelist
BasicAuthOverHttpEnabled

Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP. Setting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed.

booleanAllow Basic authentication for HTTP
AuthServerAllowlist

Specifies which servers should be allowed for integrated authentication. Integrated authentication is only enabled when Brave Browser receives an authentication challenge from a proxy or from a server which is in this permitted list.

stringAuthentication server allowlist
DisableAuthNegotiateCnameLookup

Specifies whether the generated Kerberos SPN is based on the canonical DNS name or the original name entered.

Default: false

booleanDisable CNAME lookup when negotiating Kerberos authentication
EnableAuthNegotiatePort

Specifies whether the generated Kerberos SPN should include a non-standard port.

Default: false

booleanInclude non-standard port in Kerberos SPN
NtlmV2Enabled

Controls whether NTLMv2 is enabled.

Default: true

booleanEnable NTLMv2 authentication
BrowserSwitcherEnabled

This policy controls whether to enable Legacy Browser Support. When this policy is set to true, Brave Browser will attempt to launch some URLs in an alternate browser.

Default: false

booleanBrowser Switcher Enabled
AlternativeBrowserParameters

This policy controls command-line parameters to launch to the alternative browser.

arrayAlternative Browser Parameters
AlternativeBrowserPath

This policy controls which command to use to open URLs in an alternative browser.

Range: ${safari}, ${firefox}, ${opera}, ${ie}

stringAlternative Browser Path
BrowserSwitcherDelay

This policy controls how long to wait before launching an alternative browser, in milliseconds. When this policy is set to a number, Brave Browser shows a message for that many milliseconds, and then opens the alternative browser.

integerBrowser Switcher Delay
BrowserSwitcherKeepLastChromeTab

This policy controls whether to close Brave Browser completely when the last tab would switch to another browser.

Default: true

booleanKeep Brave Browser open when the last tab switches to another browser
BrowserSwitcherUrlList

This policy controls the list of websites to open in an alternative browser.

arrayBrowser Switcher URL List
BrowserSwitcherUrlGreylist

This policy controls the list of websites that will never cause a browser switch.

arrayBrowser Switcher URL Greylist
BrowserSwitcherExternalGreylistUrl

This policy is a URL, that points to an XML file in the same format as Internet Explorer's SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer.

stringBrowser Switcher External Greylist URL
BrowserSwitcherExternalSitelistUrl

This policy is a URL, that points to an XML file in the same format as Internet Explorer's SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer.

stringBrowser Switcher External Sitelist URL
AbusiveExperienceInterventionEnforce

Allows you to set whether sites with abusive experiences should be prevented from opening new windows or tabs.

Default: true

booleanAbusive Experience Intervention Enforce
AccessibilityImageLabelsEnabled

Enable Get Image Descriptions from Google. Enables visually-impaired screen reader users to get descriptions of unlabeled images on the web.

booleanAllow accessibility descriptions for Google images
AdsSettingForIntrusiveAdsSites

Allows you to set whether ads should be blocked on sites with intrusive ads.

Range: Allow ads on all sites (1), Do not allow ads on sites with intrusive ads (2)

integerAds setting for sites with intrusive ads
LocalNetworkAccessRestrictionsEnabled

A policy to control whether users are prompted to allow sites to ask for Local Network Access.

Default: false

booleanLocal Network Access Restrictions Enabled
LocalNetworkAccessAllowedForUrls

A policy to automatically grant specific sites Local Network Access.

arrayLocal Network Access Allowed For URLs
LocalNetworkAccessBlockedForUrls

A policy to automatically deny specific sites Local Network Access.

arrayLocal Network Access Blocked For URLs
PrivacySandboxAdMeasurementEnabled

A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.

Default: true

booleanPrivacy Sandbox Ad Measurement Enabled
PrivacySandboxAdTopicsEnabled

A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.

Default: true

booleanPrivacy Sandbox Ad Topics Enabled
PrivacySandboxPromptEnabled

A policy to control whether your users see the Privacy Sandbox prompt.

Depends on: PrivacySandboxAdTopicsEnabled ∈ [false]; PrivacySandboxSiteEnabledAdsEnabled ∈ [false]; PrivacySandboxAdMeasurementEnabled ∈ [false]

Default: true

booleanPrivacy Sandbox Prompt Enabled
PrivacySandboxSiteEnabledAdsEnabled

A policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users.

Default: true

booleanPrivacy Sandbox Site Enabled Ads Enabled
AdvancedProtectionAllowed

Enable additional protections for users enrolled in the Advanced Protection program.

Default: true

booleanEnable Advanced Protection
AdvancedProtectionDeepScanningEnabled

This policy controls whether users enrolled in the Advanced Protection program are allowed to send their downloads to Google for malware scanning. If set to True or not set, enrolled users will be be prompted to send their files to Google for deep scanning. If the user selects 'Scan', their download will be sent to Google. If set to False, users will not be prompted and their downloads will not be sent to Google.

Default: true

booleanAdvanced Protection Deep Scanning
AllowDeletingBrowserHistory

Enables deleting browser history and download history in Brave Browser and prevents users from changing this setting.

Default: true

booleanEnable deleting browser and download history
AllowDinosaurEasterEgg

Allow users to play dinosaur easter egg game when device is offline.

booleanAllow Dinosaur Easter Egg Game
AllowFileSelectionDialogs

Allows access to local files on the machine by allowing Brave Browser to display file selection dialogs.

Default: true

booleanAllow invocation of file selection dialogs
AllowOutdatedPlugins

If you enable this setting, outdated plugins are used as normal plugins.

booleanAllow running plugins that are outdated
AllowPopupsDuringPageUnload

This policy allows an admin to specify that a page may show popups during its unloading.

Default: false

booleanAllow a page to show popups during its unloading
AllowSyncXHRInPageDismissal

This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.

Default: false

booleanAllows a page to perform synchronous XHR requests during page dismissal.
AllowWebAuthnWithBrokenTlsCerts

This policy will allow WebAuthn on sites with invalid TLS certificates.

Default: false

booleanAllow web authentication requests on sites with broken TLS certificates
AllowedDomainsForApps

Enables Brave Browser's restricted log in feature in G Suite and prevents users from changing this setting.

stringDefine domains allowed to access G Suite
AlternateErrorPagesEnabled

Enables the use of alternate error pages that are built into Brave Browser (such as 'page not found') and prevents users from changing this setting.

booleanEnable alternate error pages
AlwaysOpenPdfExternally

Disables the internal PDF viewer in Brave Browser. Instead it treats it as download and allows the user to open PDF files with the default application.

Default: false

booleanAlways Open PDF files externally
AmbientAuthenticationInPrivateModesEnabled

Configuring this policy will allow/disallow ambient authenticaiton for Incognito and Guest profiles in Brave Browser.

Range: Enable in regular sessions only (0), Enable in incognito and regular sessions (1), Enable in guest and regular sessions (2), Enable in regular, incognito and guest sessions (3)

integerAmbient Authentication
AppCacheForceEnabled

Allows the AppCache feature to be re-enabled even if it is off by default.

booleanForce Enable App Cache
AudioCaptureAllowed

If enabled or not configured (default), the user will be prompted for audio capture access except for URLs configured in the AudioCaptureAllowedUrls list which will be granted access without prompting.

Default: true

booleanAllow or deny audio capture
AudioSandboxEnabled

Allow the audio sandbox to run. If this policy is enabled, the audio process will run sandboxed. If this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process. This leaves users open to security risks related to running the audio subsystem unsandboxed.

booleanEnable the audio sandbox
AudioCaptureAllowedUrls

Patterns in this list will be matched against the security origin of the requesting URL. If a match is found, access to audio capture devices will be granted without prompt.

arrayURLs that will be granted access to audio capture devices without prompt
AutoFillEnabled

Enable AutoFill. This policy is deprecated in M70, please use AutofillAddressEnabled and AutofillCreditCardEnabled instead.

Default: true

booleanEnable AutoFill
AutoLaunchProtocolsFromOrigins

Define a list of protocols that can launch an external application from listed origins without prompting the user. If this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.

arrayAllow protocols to auto launch external applications
AutoOpenAllowedForURLs

URLs where AutoOpenFileTypes can apply. List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users.

arrayAllowed URLs for auto open filetypes
AutoOpenFileTypes

List of file types that should be automatically opened on download.

arrayAllow file extensions to auto open
AutofillAddressEnabled

Enables Brave Browser's AutoFill feature and allows users to auto complete address information in web forms using previously stored information.

Default: true

booleanEnable AutoFill for addresses
AutofillCreditCardEnabled

Enables Brave Browser's AutoFill feature and allows users to auto complete credit card information in web forms using previously stored information.

Default: true

booleanEnable AutoFill for credit cards
BookmarkBarEnabled

If you enable this setting, Brave Browser will show a bookmark bar.

booleanEnable Bookmark Bar
BrowserAddPersonEnabled

If this policy is set to true or not configured, Brave Browser will allow Add Person from the user manager.

Default: true

booleanEnable add person in user manager
BrowserGuestModeEnabled

If this policy is set to true or not configured, Brave Browser will enable guest logins. Guest logins are Brave Browser profiles where all windows are in incognito mode.

Default: true

booleanEnable guest mode in browser
BrowserGuestModeEnforced

If this policy is set to enabled, Brave Browser will enforce guest sessions and prevents profile logins. Guest logins are Brave Browser profiles where all windows are in incognito mode.

Default: false

booleanForce guest mode in browser
BrowserNetworkTimeQueriesEnabled

Setting this policy to false stops Brave Browser from occasionally sending queries to a Google server to retrieve an accurate timestamp. These queries will be enabled if this policy is set to True or is not set.

Default: true

booleanAllow queries to a Google time service
BrowserSignin

This policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Brave Browser with their account and use account related services like Brave Browser sync.

Range: Disable browser sign-in (0), Enable browser sign-in (1), Force users to sign-in to use the browser (2)

integerBrowser Signin
BuiltInDnsClientEnabled

Controls whether the built-in DNS client is used in Brave Browser.

booleanUse built-in DNS client
BuiltinCertificateVerifierEnabled

Determines whether the built-in certificate verifier will be used to verify server certificates. When this setting is enabled, Brave Browser will perform verification of server certificates using the built-in certificate verifier. When this setting is disabled, Brave Browser will perform verification of server certificates using the legacy certificate verifier provided by the platform. When this setting is not set, the built-in or the legacy certificate verifier may be used.

booleanUse built-in certificate verifier
CertificateTransparencyEnforcementDisabledForCas

Disables enforcing Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.

arrayDisable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes
CertificateTransparencyEnforcementDisabledForLegacyCas

Disables enforcing Certificate Transparency requirements for a list of Legacy Certificate Authorities.

arrayDisable Certificate Transparency enforcement for a list of Legacy Certificate Authorities
CertificateTransparencyEnforcementDisabledForUrls

Disables enforcing Certificate Transparency requirements to the listed URLs. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format.

arrayDisable Certificate Transparency enforcement for a list of URLs
ChromeVariations

Determine the availability of variations.

Default: 0

Range: Enable all variations (0), Enable variations concerning critical fixes only (1), Disable all variations (2)

integerBrave Browser Variations
ClickToCallEnabled

Enable the Click to Call Feature.

Default: true

booleanEnable Click to Call
CloudManagementEnrollmentToken

If this policy is set, Brave Browser will try to register itself and apply associated cloud policy for all profiles.

stringCloud Management Enrollment Token
CloudManagementEnrollmentMandatory

If this policy is set to True, cloud management enrollment is mandatory and blocks Brave Browser launch process if failed.

Default: false

booleanMake cloud managment enrollment mandatory
CloudPolicyOverridesPlatformPolicy

If the policy is set to true, cloud policy takes precedence if it conflicts with platform policy. If the policy is set to false or not configured, platform policy takes precedence if it conflicts with cloud policy.

Default: false

booleanCloud Policy Overrides Platform Policy
CommandLineFlagSecurityWarningsEnabled

If disabled, prevents security warnings from appearing when Brave Browser is launched with some potentially dangerous command-line flags.

Default: true

booleanCommand Line Flag Security Warnings Enabled
ComponentUpdatesEnabled

Enables component updates for all components in Brave Browser when not set or set to True.

Default: true

booleanEnable component updates in Brave Browser
CorsLegacyModeEnabled

Use the legacy CORS implementation rather than new CORS.

Default: true

booleanEnable Cross-Origin Resource Sharing legacy mode
CorsMitigationList

Enable CORS check mitigations in the new CORS implementation, allowing Extensions to keep compatible behavior, and allowing Brave Browser to send specified headers without CORS checks.

arrayCross-Origin Resource Sharing mitigation list
DNSInterceptionChecksEnabled

This policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.

Default: true

booleanDNS Interception Checks
DefaultBrowserSettingEnabled

Configures the default browser checks in Brave Browser and prevents users from changing them.

booleanSet Brave Browser as Default Browser
PromotionsEnabled

Setting the policy to True or leaving it unset lets Brave Browser show users product promotional content.

Default: true

booleanShow Promotional Content
DefaultDownloadDirectory

Configures the default directory that Brave Browser will use for downloading files. This policy is not mandatory, so the user will be able to change the directory. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.

stringSet default download directory
DefaultSearchProviderContextMenuAccessAllowed

Allow default search provider context menu search access.

Default: true

booleanEnable default search provider on context menu
DeveloperToolsAvailability

Allows you to control where Developer Tools can be used.

Range: Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts (0), Allow usage of the Developer Tools (1), Disallow usage of the Developer Tools (2)

integerControl where Developer Tools can be used
Disable3DAPIs

Enabling this setting prevents web pages from accessing the graphics processing unit (GPU). Specifically, web pages can not access the WebGL API and plugins can not use the Pepper 3D API.

Default: false

booleanDisable support for 3D graphics APIs
DisableSafeBrowsingProceedAnyway

The Safe Browsing service shows a warning page when users navigate to sites that are flagged as potentially malicious. Enabling this setting prevents users from proceeding anyway from the warning page to the malicious site.

Default: false

booleanDisable proceeding from the Safe Browsing warning page
DisableScreenshots

If enabled, screenshots cannot be taken using keyboard shortcuts or extension APIs.

Default: false

booleanDisable taking screenshots
DisabledPlugins

This policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that are disabled in Brave Browser and prevents users from changing this setting.

arrayDisabled Plugins
DisabledPluginsExceptions

This policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that user can enable or disable in Brave Browser.

arrayDisabled Plugins Exceptions
DisabledSchemes

This policy is deprecated, please use URLBlocklist instead. Disables the listed protocol schemes in Brave Browser.

arrayDisabled URL Protocol Schemes
DiskCacheDir

Configures the directory that Brave Browser will use for storing cached files on the disk. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used. To avoid data loss or other unexpected errors this policy should not be set to a volume's root directory or to a directory used for other purposes, because Brave Browser manages its contents

stringSet disk cache directory
DiskCacheSize

Configures the cache size that Brave Browser will use for storing cached files on the disk. The value specified in this policy is not a hard boundary but rather a suggestion to the caching system, any value below a few megabytes is too small and will be rounded up to a sane minimum. If the value of this policy is 0, the default cache size will be used but the user will not be able to change it.

integerSet disk cache size
DnsOverHttpsMode

Controls the mode of DNS-over-HTTPS

Range: Disable DNS-over-HTTPS (off), Enable DNS-over-HTTPS with insecure fallback (automatic), Enable DNS-over-HTTPS without insecure fallback (secure)

stringDNS-over-HTTPS mode
DnsOverHttpsTemplates

Specify URI template of desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.

stringDNS-over-HTTPS mode
DomainReliabilityAllowed

This policy will allow sending domain reliability data to Google

booleanAllow reporting of domain reliability related data
DownloadDirectory

Configures the directory that Brave Browser will use for downloading files. If you set this policy, Brave Browser will use the provided directory regardless whether the user has specified one or enabled the flag to be prompted for download location every time. If this policy is left not set the default download directory will be used and the user will be able to change it. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.

stringSet download directory
DownloadRestrictions

Configures the type of downloads that Brave Browser will completely block, without letting users override the security decision.

Range: No special restrictions (0), Block malicious downloads and dangerous file types (1), Block malicious downloads, uncommon or unwanted downloads and dangerous file types (2), Block all downloads (3), Block malicious downloads (4)

integerDownload restrictions
EditBookmarksEnabled

If you enable this setting, bookmarks can be added, removed or modified. This is the default also when this policy is not set.

Default: true

booleanEnable or disable bookmark editing
EnableDeprecatedWebPlatformFeatures

ExampleDeprecatedFeature_EffectiveUntil20080902 - Enable ExampleDeprecatedFeature API through 2008/09/02 Specify a list of deprecated web platform features to re-enable temporarily.

arrayEnable deprecated web platform features for a limited time
EnableExperimentalPolicies

Allows Brave Browser to load experimental policies.

arrayEnable experimental policies
EnableOnlineRevocationChecks

In light of the fact that soft-fail, online revocation checks provide no effective security benefit, they are disabled by default in Chromium version 19 and later. By setting this policy to true, the previous behavior is restored and online OCSP/CRL checks will be performed.

Default: false

booleanWhether online OCSP/CRL checks are performed
EnabledPlugins

This policy is deprecated. Please use the DefaultPluginsSetting to control the avalability of the Flash plugin and AlwaysOpenPdfExternally to control whether the integrated PDF viewer should be used for opening PDF files. Specifies a list of plugins that are enabled in Brave Browser and prevents users from changing this setting.

arrayEnabled Plugins
EncryptedClientHelloEnabled

This policy will allow encryption of TLS ClientHello for enhanced privacy.

Default: true

booleanEnable TLS Encrypted ClientHello
EnterpriseHardwarePlatformAPIEnabled

When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.

Default: false

booleanEnable Managed Extensions to use the Enterprise Hardware API
EnterpriseProfileCreationKeepBrowsingData

This policy will allow keeping browsing data in new enterprise profiles

Default: false

booleanKeep browsing data when creating enterprise profile by default
EnterpriseRealTimeUrlCheckMode

This policy controls checking URLs in real time to identify unsafe URLs. If this policy is left not set or set to ‘Disabled', the consumer Safe Browsing checks will be applied. If this policy is set to ‘Enabled', URLs will be sent to be scanned in real time under enterprise ToS. It will result in Brave Browser sending URLs to Google Cloud or third parties of your choosing to check them in real time. The consumer version of Safe Browsing real time lookup will be switched off.

Range: Disabled (0), Enabled (1)

integerCheck Safe Browsing status of URLs in real time
ExternalProtocolDialogShowAlwaysOpenCheckbox

Show an "Always open" checkbox in external protocol dialog.

Default: true

booleanDisplay "Always open" checkbox in external protocol dialog
FileOrDirectoryPickerWithoutGestureAllowedForOrigins

This policy will allow file picker APIs without user gesture for specified origins

arrayAllow file or directory picker APIs to be called without prior user gesture
ForceBrowserSignin

If this policy is set to true, user has to sign in to Brave Browser with their profile before using the browser. And the default value of BrowserGuestModeEnabled will be set to false. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article. This policy is deprecated, consider using BrowserSignin instead.

Default: false

booleanEnable force sign in for Brave Browser
ForceEphemeralProfiles

If set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account.

Default: false

booleanEphemeral profile
ForceGoogleSafeSearch

Forces queries in Google Web Search to be done with SafeSearch set to active and prevents users from changing this setting.

Default: false

booleanForce Google SafeSearch
ForceSafeSearch

This policy is deprecated, please use ForceGoogleSafeSearch and ForceYouTubeRestrict instead. This policy is ignored if either the ForceGoogleSafeSearch, the ForceYouTubeRestrict or the (deprecated) ForceYouTubeSafetyMode policies are set.

Default: false

booleanForce SafeSearch
ForceLegacyDefaultReferrerPolicy

This enterprise policy is for short-term adaptation and will be removed in M82.

Default: false

booleanForce Legacy Default Referrer
GloballyScopeHTTPAuthCacheEnabled

This policy configures a single global per profile cache with HTTP server authentication credentials.

Default: false

booleanEnable globally scoped HTTP auth cache
GoogleSearchSidePanelEnabled

This policy will allow Google Search Side Panel.

Default: true

booleanEnable Google Search Side Panel
ForceYouTubeRestrict

Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.

Range: Do not enforce Restricted Mode on YouTube (0), Enforce at least Moderate Restricted Mode on YouTube (1), Enforce Strict Restricted Mode for YouTube (2)

integerForce minimum YouTube Restricted Mode
ForceYouTubeSafetyMode

This policy is deprecated. Consider using ForceYouTubeRestrict, which overrides this policy and allows more fine-grained tuning. Forces YouTube Moderate Restricted Mode and prevents users from changing this setting.

Default: false

booleanForce YouTube Safety Mode
HardwareAccelerationModeEnabled

If this policy is set to true or left unset, hardware acceleration will be enabled unless a certain GPU feature is blacklisted.

Default: true

booleanUse hardware acceleration when available
HideWebStoreIcon

Hide the Chrome Web Store app and footer link from the New Tab Page and Brave Browser OS app launcher.

Default: false

booleanHide the web store from the New Tab Page and app launcher
HSTSPolicyBypassList

List of names that will bypass the HSTS policy check. Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from http to https.

arrayHSTS Policy Bypass List
Http09OnNonDefaultPortsEnabled

This policy enables HTTP/0.9 on ports other than 80 for HTTP and 443 for HTTPS.

Default: false

booleanEnable HTTP/0.9 support on non-default ports
HttpsUpgradesEnabled

This policy will allow automatic HTTPS upgrades.

Default: true

booleanEnable automatic HTTPS upgrades
ImportAutofillFormData

This policy forces the autofill form data to be imported from the previous default browser if enabled. If enabled, this policy also affects the import dialog.

booleanImport autofill form data from default browser on first run
ImportBookmarks

This policy forces bookmarks to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog.

Default: true

booleanImport bookmarks from default browser on first run
ImportHistory

This policy forces the browsing history to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog.

booleanImport browsing history from default browser on first run
ImportHomepage

This policy forces the home page to be imported from the current default browser if enabled.

booleanImport of homepage from default browser on first run
ImportSavedPasswords

This policy forces the saved passwords to be imported from the previous default browser if enabled. If enabled, this policy also affects the import dialog.

booleanImport saved passwords from default browser on first run
ImportSearchEngine

This policy forces search engines to be imported from the current default browser if enabled. If enabled, this policy also affects the import dialog.

booleanImport search engines from default browser on first run
IncognitoEnabled

This policy is deprecated. Please, use IncognitoModeAvailability instead. Enables Incognito mode in Brave Browser. If this setting is enabled or not configured, users can open web pages in incognito mode.

Default: true

booleanEnable Incognito
IncognitoModeAvailability

Specifies whether the user may open pages in Incognito mode in Brave Browser.

Range: Incognito mode available (0), Incognito mode disabled (1), Incognito mode forced (2)

integerIncognito mode availability
IntensiveWakeUpThrottlingEnabled

When enabled, the IntensiveWakeUpThrottling feature causes JavaScript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.

booleanEnable Intensive Wake Up Throttling
IsolateOrigins

If the policy is enabled, each of the named origins in a comma-separated list will run in its own process. This will also isolate origins named by subdomains; e.g. specifying https://example.com/ will also cause https://foo.example.com/ to be isolated as part of the https://example.com/ site. If the policy is disabled, no explicit Site Isolation will happen and field trials of IsolateOrigins and SitePerProcess will be disabled. Users will still be able to enable IsolateOrigins manually. If the policy is not configured, the user will be able to change this setting. On Brave Browser OS, it is recommended to also set the DeviceLoginScreenIsolateOrigins device policy to the same value. If the values specified by the two policies don't match, a delay may be incurred when entering a user session while the value specified by user policy is being applied.

stringEnable Site Isolation for specified origins
JavascriptEnabled

This policy is deprecated, please use DefaultJavaScriptSetting instead. Can be used to disabled JavaScript in Brave Browser.

Default: true

booleanJavascript Enabled
LocalDiscoveryEnabled

This policy controls access to controllable features in the local discovery UI (chrome://devices) which shows discoverable devices near the user as well as cloud devices registered to them. On all operating systems except for Brave Browser OS, the local discovery UI also allows users to add classic printers connected to their computers to Google Cloud Print.

booleanEnable chrome://devices
LookalikeWarningAllowlistDomains

This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Brave Browser believes might be trying to spoof another site the user is familiar with. If the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain. If the policy is disabled, not set, or set to an empty list, warnings may appear on any site the user visits.

arraySuppress lookalike domain warnings on domains
MachineLevelUserCloudPolicyEnrollmentToken

The enrollment token of cloud policy on desktop. This policy is deprecated in M72. Please use CloudManagementEnrollmentToken instead.

stringThe enrollment token of cloud policy on desktop
ManagedBookmarks

Configures a list of managed bookmarks.

arrayManaged Bookmarks
MaxConnectionsPerProxy

Specifies the maximal number of simultaneous connections to the proxy server.

Default: 32

integerMaximal number of concurrent connections to the proxy server
MaxInvalidationFetchDelay

Specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service.

Default: 5000

Range: 1000 – 300000

integerMaximum fetch delay after a policy invalidation
MediaRecommendationsEnabled

By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.

booleanEnable Media Recommendations
MediaRouterCastAllowAllIPs

If this policy is set to true, Google Cast will connect to Cast devices on all IP addresses, not just RFC1918/RFC4913 private addresses.

booleanAllow Google Cast to connect to Cast devices on all IP addresses.
MetricsReportingEnabled

Enables anonymous reporting of usage and crash-related data about Brave Browser to Google and prevents users from changing this setting.

booleanEnable reporting of usage and crash-related data
NetworkPredictionOptions

(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.) Enables network prediction in Brave Browser and prevents users from changing this setting.

Range: Predict network actions on any network connection (0), Predict network actions on any network that is not cellular. (1), Do not predict network actions on any network connection (2)

integerEnable network prediction
NTPCardsVisible

This policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior. If the policy is set to Enabled, the New Tab Page will show cards if content is available. If the policy is set to Disabled, the New Tab Page won't show cards.

booleanShow cards on the New Tab Page
NTPCustomBackgroundEnabled

Allow users to customize the background on the New Tab page

Default: true

booleanAllow New Tab page background customization
OverrideSecurityRestrictionsOnInsecureOrigin

The policy specifies a list of origins (URLs) or hostname patterns (such as "*.example.com") to be treated as secure contexts. The intent is to allow organizations to set up a staging server for internal web development, so that their developers can test out features requiring secure contexts without having to deploy TLS on the staging server. Setting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If the policy is set, it will override the command-line flag. For more information on secure contexts, see https://www.w3.org/TR/secure-contexts/

arrayOrigins or hostname patterns to be treated as secure context.
PaymentMethodQueryEnabled

Allows you to set whether websites are allowed to check if the user has payment methods saved.

Default: true

booleanPayment Method Query
PolicyAtomicGroupsEnabled

Enables the concept of policy atomic groups.

Default: true

booleanEnable Policy Atomic Groups
PolicyDictionaryMultipleSourceMergeList

Allows the selected policies to be merged when they come from different sources, with the same scopes and level. Entered strings must match a Brave Browser policy / key name that uses a dictionary for its data type.

arrayAllow merging dictionary policies from different sources
PolicyListMultipleSourceMergeList

Allows the selected policies to be merged when they come from different sources, with the same scopes and level. Entered strings must match a Brave Browser policy / key name that use an array (list) of strings for its data type.

arrayAllow merging list policies from different sources
PolicyRefreshRate

Refresh rate for user policy. Specifies the period in milliseconds at which the device management service is queried for user policy information. Setting this policy overrides the default value of 3 hours. Valid values for this policy are in the range from 1800000 (30 minutes) to 86400000 (1 day).

Default: 10800000

Range: 1800000 – 86400000

integerPolicy Refresh Rate
ProfilePickerOnStartupAvailability

Specifies whether the profile picker is enabled, disabled or forced at the browser startup. By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true.

Range: Profile picker available at startup (0), Profile picker disabled at startup (1), Profile picker forced at startup (2)

integerProfile picker availabily on startup
PromotionalTabsEnabled

Allows you to control the presentation of full-tab promotional and/or educational content in Brave Browser.

Default: true

booleanEnable showing full-tab promotional content
PromptForDownloadLocation

If the policy is enabled, the user will be asked where to save each file before downloading. If the policy is disabled, downloads will start immediately, and the user will not be asked where to save the file. If the policy is not configured, the user will be able to change this setting.

booleanAsk where to save each file before downloading
QuicAllowed

If this policy is set to true or not set usage of QUIC protocol in Brave Browser is allowed. If this policy is set to false usage of QUIC protocol is disallowed.

Default: true

booleanAllow QUIC protocol
RelaunchNotification

Notify users that Brave Browser must be relaunched to apply a pending update.

Range: Show a recurring prompt to the user indicating that a relaunch is recommended (1), Show a recurring prompt to the user indicating that a relaunch is required (2)

integerNotify a user that a browser relaunch is recommended or required
RelaunchNotificationPeriod

Allows you to set the time period, in milliseconds, over which users are notified that Brave Browser must be relaunched or that a Brave Browser OS device must be restarted to apply a pending update.

integerUpdate time period
RemoteDebuggingAllowed

Controls whether users may use remote debugging.

Default: true

booleanAllow remote debugging
RestrictSigninToPattern

Contains a regular expression which is used to determine which users can sign in to Brave Browser.

stringRestrict which users are allowed to sign in to Brave Browser
RunAllFlashInAllowMode

If you enable this setting, all Flash content embedded on websites that have been set to allow Flash in content settings -- either by the user or by enterprise policy -- will be run, including content from other origins or small content.

Default: false

booleanExtend Flash content setting to all content
SafeBrowsingForTrustedSourcesEnabled

Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source. Setting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.

Default: true

booleanSafe Browsing checks
SafeSitesFilterBehavior

This policy controls the application of the SafeSites URL filter. This filter uses the Google Safe Search API to classify URLs as pornographic or not.

Range: Do not filter sites for adult content (0), Filter top level sites (but not embedded iframes) for adult content (1)

integerControl SafeSites adult content filtering.
SavingBrowserHistoryDisabled

Disables saving browser history in Brave Browser and prevents users from changing this setting.

Default: false

booleanDisable saving browser history
ScreenCaptureAllowed

If enabled or not configured (default), a Web page can use screen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API) to prompt the user to select a tab, window or desktop to capture.

Default: true

booleanScreen Capture
ScrollToTextFragmentEnabled

This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.

Default: true

booleanEnable scroll to text fragment
SearchSuggestEnabled

Enables search suggestions in Brave Browser's omnibox and prevents users from changing this setting.

booleanEnable search suggestions
SecurityKeyPermitAttestation

Specifies URLs and domains for which no prompt will be shown when attestation certificates from Security Keys are requested. Additionally, a signal will be sent to the Security Key indicating that individual attestation may be used. Without this, users will be prompted in Chromium 65+ when sites request attestation of Security Keys.

arrayURLs/domains automatically permitted direct Security Key attestation
SharedClipboardEnabled

Enables the Shared Clipboard feature which allows users to send text between Brave Browser Desktops and an Android device when Sync is enabled and the user is Signed-in.

Default: true

booleanEnable Shared Clipboard
ShowAppsShortcutInBookmarkBar

Enables or disables the apps shortcut in the bookmark bar.

booleanShow the apps shortcut in the bookmark bar
ShowFullUrlsInAddressBar

This feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply.

booleanShow Full URLs
SignedHTTPExchangeEnabled

Enable support for Signed HTTP Exchange (SXG).

Default: true

booleanEnabled Signed HTTP Exchange (SXG) support
SigninAllowed

This policy is deprecated, consider using BrowserSignin instead. Allows the user to sign in to Brave Browser.

booleanAllow sign in
SigninInterceptionEnabled

This settings enables or disables signin interception. When this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile. When this is set to False, the signin interception dialog does not trigger.

booleanEnable signin interception
SitePerProcess

You might want to look at the IsolateOrigins policy setting to get the best of both worlds, isolation and limited impact for users, by using IsolateOrigins with a list of the sites you want to isolate. This setting, SitePerProcess, isolates all sites. If the policy is enabled, each site will run in its own process. If the policy is disabled, no explicit Site Isolation will happen and field trials of IsolateOrigins and SitePerProcess will be disabled. Users will still be able to enable SitePerProcess manually. If the policy is not configured, the user will be able to change this setting. On Brave Browser OS, it is recommended to also set the DeviceLoginScreenSitePerProcess device policy to the same value. If the values specified by the two policies don't match, a delay may be incurred when entering a user session while the value specified by user policy is being applied.

booleanEnable Site Isolation for every site
SpellCheckServiceEnabled

Brave Browser can use a Google web service to help resolve spelling errors. If this setting is enabled, then this service is always used. If this setting is disabled, then this service is never used.

booleanEnable or disable spell checking web service
SpellcheckEnabled

If this policy is not set or enabled, the user is allowed to use spellcheck.

booleanEnable spellcheck
SSLErrorOverrideAllowed

Brave Browser shows a warning page when users navigate to sites that have SSL errors. By default or when this policy is set to true, users are allowed to click through these warning pages. Setting this policy to false disallows users to click through any warning page.

Default: true

booleanAllow proceeding from the SSL warning page
SSLVersionMin

If this policy is not configured then Brave Browser uses a default minimum version which is TLS 1.0.

Range: TLS 1.0 (tls1), TLS 1.1 (tls1.1), TLS 1.2 (tls1.2)

stringMinimum SSL version enabled
StrictMimetypeCheckForWorkerScriptsEnabled

This policy enables strict MIME type checking for worker scripts.

Default: true

booleanEnable strict MIME type checking for worker scripts
StricterMixedContentTreatmentEnabled

This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser. If the policy is set to true or unset, audio and video mixed content will be autoupgraded to HTTPS (i.e. the URL will be rewritten as HTTPS, without a fallback if the resource is not available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content. If the policy is set to false, autoupgrades will be disabled for audio and video, and no warning will be shown for images. This policy does not affect other types of mixed content other than audio, video, and images. This policy will no longer take effect starting in Chromium 84.

Default: true

booleanStricter Mixed Content Treatment
SuppressUnsupportedOSWarning

Suppresses the warning that appears when Brave Browser is running on a computer or operating system that is no longer supported.

booleanSuppress the unsupported OS warning
SyncDisabled

Disables data synchronization in Brave Browser using Google-hosted synchronization services and prevents users from changing this setting.

booleanDisable synchronization of data with Google
SyncTypesListDisabled

If this policy is set, all specified data types will be excluded from synchronization both for Google Sync as well as for roaming profile synchronization.

arraySync types to disable
TargetBlankImpliesNoOpener

Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup. Setting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel="opener".

Default: true

booleanDo not set window.opener for links targeting _blank
TaskManagerEndProcessEnabled

If set to false, the 'End process' button is disabled in the Task Manager.

Default: true

booleanEnable ending processes in Task Manager
TLS13HardeningForLocalAnchorsEnabled

Enable a TLS 1.3 security feature for local trust anchors. This policy controls a security feature in TLS 1.3 which protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.

Default: true

booleanEnable TLS 1.3 hardening for local anchors
TotalMemoryLimitMb

Configures the amount of memory that a single Brave Browser instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory. The minimum allowed value is 1024.

Range: 1024 – —

integerTotal Memory Limit
TranslateEnabled

Enables the integrated Google Translate service on Brave Browser.

booleanEnable Translate
URLBlacklist

This policy prevents the user from loading web pages from blacklisted URLs. The denylist provides a list of URL patterns that specify which URLs will be denied. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format.

arrayURL Blacklist
URLBlocklist

This policy prevents the user from loading web pages from blocked URLs. The blocklist provides a list of URL patterns that specify which URLs will be denied. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format.

arrayURL Blocklist
URLWhitelist

Allows access to the listed URLs, as exceptions to the URL denylist. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format.

arrayAllow access to a list of URLs
URLAllowlist

Allows access to the listed URLs, as exceptions to the URL block list. A URL pattern is formatted according to https://www.chromium.org/administrators/url-blacklist-filter-format.

arrayAllow access to a list of URLs
UnsafelyTreatInsecureOriginAsSecure

Deprecated in M69. Use OverrideSecurityRestrictionsOnInsecureOrigin instead. The policy specifies a list of origins (URLs) or hostname patterns (such as "*.example.com") for which security restrictions on insecure origins will not apply.

arrayOrigins or hostname patterns for which restrictions on insecure origins should not apply
UrlKeyedAnonymizedDataCollectionEnabled

Enable URL-keyed anonymized data collection in Brave Browser and prevents users from changing this setting.

booleanEnable URL-keyed anonymized data collection
UserAgentClientHintsEnabled

When enabled the User-Agent Client Hints feature sends granular request headers providing information about the user browser and environment.

booleanEnable user agent client hints
UserFeedbackAllowed

Allow user feedback. If the policy is set to false, users can not send feedback to Google.

Default: true

booleanAllow user feedback
UserDataDir

Configures the directory that Brave Browser will use for storing user data. See https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.

stringSet user data directory
UserDataSnapshotRetentionLimit

Limits the number of user data snapshots retained for use in case of emergency rollback. If this policy is not set, the default value of 3 is used. If the policy is set to 0, no snapshots will be taken.

Default: 3

integerUser data snapshot retention limit
VideoCaptureAllowed

If enabled or not configured (default), the user will be prompted for video capture access except for URLs configured in the VideoCaptureAllowedUrls list which will be granted access without prompting.

Default: true

booleanAllow or deny video capture
VideoCaptureAllowedUrls

Patterns in this list will be matched against the security origin of the requesting URL. If a match is found, access to audio capture devices will be granted without prompt.

arrayURLs that will be granted access to video capture devices without prompt
WebAppInstallForceList

Specifies a list of websites that are installed silently, without user interaction, and which cannot be uninstalled nor disabled by the user.

arrayWebApp Force Install List
WebComponentsV0Enabled

The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.

Default: false

booleanRe-enable Web Components v0 API until M84
WebDriverOverridesIncompatiblePolicies

This policy allows users of the WebDriver feature to override policies which can interfere with its operation.

Default: false

booleanAllow WebDriver to Override Incompatible Policies
WebRtcAllowLegacyTLSProtocols

f enabled, WebRTC peer connections can downgrade to obsolete versions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols. When this policy is disabled or not set, these TLS/DTLS versions are disabled.

booleanAllow legacy TLS/DTLS downgrade in WebRTC
WebRtcEventLogCollectionAllowed

If the policy is set to true, Brave Browser is allowed to collect WebRTC event logs from Google services (e.g. Google Meet), and upload those logs to Google.

booleanAllow collection of WebRTC event logs from Google services
WebRtcLocalIpsAllowedUrls

Patterns in this list will be matched against the security origin of the requesting URL. If a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates. Otherwise, local IP addresses are concealed with mDNS hostnames.

arrayAllowed WebRTC local IP URLs
WebRtcUdpPortRange

If the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included).

stringRestrict the range of local UDP ports used by WebRTC
WPADQuickCheckEnabled

Allows to turn off WPAD (Web Proxy Auto-Discovery) optimization in Brave Browser.

Default: true

booleanEnable WPAD optimization
NativeMessagingBlacklist

Allows you to specify which native messaging hosts that should not be loaded. A blacklist value of '*' means all native messaging hosts are denied unless they are explicitly listed in the allowlist.

arrayNative Messaging Host Blacklist
NativeMessagingBlocklist

Allows you to specify which native messaging hosts that should not be loaded. A block list value of '*' means all native messaging hosts are denied unless they are explicitly listed in the allow list.

arrayNative Messaging Host Blocklist
NativeMessagingUserLevelHosts

Enables user-level installation of Native Messaging hosts.

booleanAllow user-level Native Messaging hosts (installed without admin permissions)
NativeMessagingWhitelist

Allows you to specify which native messaging hosts are not subject to the blacklist. A blacklist value of * means all native messaging hosts are denied and only native messaging hosts listed in the whitelist will be loaded.

arrayNative Messaging Host Whitelist
NativeMessagingAllowlist

Allows you to specify which native messaging hosts are not subject to the block list. A block list value of * means all native messaging hosts are denied and only native messaging hosts listed in the allow list will be loaded.

arrayNative Messaging Host Allowlist
PasswordLeakDetectionEnabled

This policy can be used to force enable or force disable credential leak checking in Brave Browser.

booleanEnable password leak detection
PasswordManagerEnabled

If this setting is enabled, users can have Brave Browser memorize passwords and provide them automatically the next time they log in to a site.

booleanEnable saving passwords to the password manager
CloudPrintProxyEnabled

Enables Brave Browser to act as a proxy between Google Cloud Print and legacy printers connected to the machine.

Default: true

booleanEnable Google Cloud Print proxy
CloudPrintSubmitEnabled

Enables Brave Browser to submit documents to Google Cloud Print for printing. NOTE: This only affects Google Cloud Print support in Brave Browser. It does not prevent users from submitting print jobs on web sites.

Default: true

booleanEnable submission of documents to Google Cloud Print
DefaultPrinterSelection

Overrides Brave Browser default printer selection rules.

stringDefault printer selection rules
DisablePrintPreview

Show the system print dialog instead of print preview.

Default: false

booleanDisable Print Preview
PrintHeaderFooter

Force 'headers and footers' to be on or off in the printing dialog.

booleanPrint Headers & Footers
PrinterTypeDenyList

The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched.

arrayPrinter Type Deny List
PrintingAllowedBackgroundGraphicsModes

Restricts background graphics printing mode. Unset policy is treated as no restriction.

Range: Allow printing both with and without background graphics (any), Allow printing only with background graphics (enabled), Allow printing only without background graphics (disabled)

stringBackground graphics printing mode
PrintingBackgroundGraphicsDefault

Overrides default background graphics printing mode.

Range: Enabled (enabled), Disabled (disabled)

stringDefault background graphics printing mode
PrintingEnabled

Enables printing in Brave Browser and prevents users from changing this setting.

Default: true

booleanEnable printing
PrintPreviewUseSystemDefaultPrinter

Causes Brave Browser to use the system default printer as the default choice in Print Preview instead of the most recently used printer.

Default: false

booleanUse System Default Printer as Default
PrinterPaperSizeDefault

Overrides default printing page size. If 'custom' is provided, custom size width and height keys must also be included.

dictDefault printer paper size
ProxyBypassList

Brave Browser will bypass any proxy for the list of hosts given here.

stringComma-separated list of proxy bypass rules
ProxySettings

Configures the proxy settings for Brave Browser. These proxy settings will be available for ARC-apps too. If you enable this setting, Brave Browser and ARC-apps ignore all proxy-related options specified from the command line.

dictProxy Settings
ProxyMode

Allows you to specify the proxy server used by Brave Browser and prevents users from changing proxy settings.

Range: Never use a proxy (direct), Auto detect proxy settings (auto_detect), Use a .pac proxy script (pac_script), Use fixed proxy servers (fixed_servers), Use system proxy settings (system)

stringChoose how to specify proxy server settings
ProxyPacUrl

You can specify a URL to a proxy .pac file here.

stringURL to a proxy .pac file
ProxyServer

You can specify the URL of the proxy server here.

stringAddress or URL of proxy server
ProxyServerMode

This policy is deprecated, use ProxyMode instead. Allows you to specify the proxy server used by Brave Browser and prevents users from changing proxy settings.

Range: Never use a proxy (0), Auto detect proxy settings (1), Manually specify proxy settings (2), Use system proxy settings (3)

integerProxy server settings
RemoteAccessHostAllowClientPairing

If this setting is enabled or not configured, then users can opt to pair clients and hosts at connection time, eliminating the need to enter a PIN every time.

Default: true

booleanEnable or disable PIN-less authentication for remote access hosts
RemoteAccessHostAllowFileTransfer

Controls the ability of a user connected to a remote access host to transfer files between the client and the host. This does not apply to remote assistance connections, which do not support file transfer.

booleanAllow remote access file transfer
RemoteAccessHostAllowGnubbyAuth

If this setting is enabled, then gnubby authentication requests will be proxied across a remote host connection.

Default: false

booleanAllow gnubby authentication for remote access hosts
RemoteAccessHostAllowRelayedConnection

Enables usage of relay servers when remote clients are trying to establish a connection to this machine.

Default: true

booleanEnable the use of relay servers by the remote access host
RemoteAccessHostClientDomain

Configure the required domain name for remote access clients. This policy is deprecated. Please use RemoteAccessHostClientDomainList instead.

arrayConfigure the required domain names for remote access clients
RemoteAccessHostClientDomainList

Configures the required client domain names that will be imposed on remote access clients and prevents users from changing it.

arrayConfigure the required domain names for remote access clients
RemoteAccessHostDomain

Configure the required domain name for remote access hosts. This policy is deprecated. Please use RemoteAccessHostDomainList instead.

arrayConfigure the required domain names for remote access hosts
RemoteAccessHostDomainList

Configures the required host domain names that will be imposed on remote access hosts and prevents users from changing it.

arrayConfigure the required domain names for remote access hosts
RemoteAccessHostFirewallTraversal

Enables usage of STUN servers when remote clients are trying to establish a connection to this machine.

Default: false

booleanEnable firewall traversal from remote access host
RemoteAccessHostMatchUsername

If this setting is enabled, then the remote access host compares the name of the local user (that the host is associated with) and the name of the Google account registered as the host owner (i.e. "johndoe" if the host is owned by "johndoe@example.com" Google account). The remote access host will not start if the name of the host owner is different from the name of the local user that the host is associated with. RemoteAccessHostMatchUsername policy should be used together with RemoteAccessHostDomain to also enforce that the Google account of the host owner is associated with a specific domain (i.e. "example.com").

Default: false

booleanRequire that the name of the local user and the remote access host owner match
RemoteAccessHostRequireCurtain

Enables curtaining of remote access hosts while a connection is in progress.

Default: false

booleanEnable curtaining of remote access hosts
RemoteAccessHostTalkGadgetPrefix

Configures the TalkGadget prefix that will be used by remote access hosts and prevents users from changing it.

stringConfigure the TalkGadget prefix for remote access hosts
RemoteAccessHostTokenUrl

If this policy is set, the remote access host will require authenticating clients to obtain an authentication token from this URL in order to connect. Must be used in conjunction with RemoteAccessHostTokenValidationUrl.

stringURL where remote access clients should obtain their authentication token
RemoteAccessHostTokenValidationCertificateIssuer

If this policy is set, the host will use a client certificate with the given issuer CN to authenticate to RemoteAccessHostTokenValidationUrl. Set it to "*" to use any available client certificate.

stringClient certificate for connecting to RemoteAccessHostTokenValidationUrl
RemoteAccessHostTokenValidationUrl

If this policy is set, the remote access host will use this URL to validate authentication tokens from remote access clients, in order to accept connections. Must be used in conjunction with RemoteAccessHostTokenUrl.

stringURL for validating remote access client authentication token
RemoteAccessHostUdpPortRange

Restricts the UDP port range used by the remote access host in this machine.

stringRestrict the UDP port range used by the remote access host
PasswordProtectionChangePasswordURL

Configure the change password URL (HTTP and HTTPS schemes only). Password protection service will send users to this URL to change their password after seeing a warning in the browser. In order for Brave Browser to correctly capture the new password fingerprint on this change password page, please make sure your change password page follows the guidelines on https://www.chromium.org/developers/design-documents/create-amazing-password-forms.

stringConfigure the change password URL.
PasswordProtectionLoginURLs

Configure the list of enterprise login URLs (HTTP and HTTPS schemes only). Fingerprint of password will be captured on these URLs and used for password reuse detection. In order for Brave Browser to correctly capture password fingerprints, please make sure your login pages follow the guidelines on https://www.chromium.org/developers/design-documents/create-amazing-password-forms.

arrayConfigure the list of enterprise login URLs where password protection service should capture fingerprint of password.
PasswordProtectionWarningTrigger

Allows you to control the triggering of passwore protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.

Range: Password protection warning is off (0), Password protection warning is triggered by password reuse (1), Password protection warning is triggered by password reuse on phishing page (2)

integerPassword protection warning trigger
SafeBrowsingEnabled

Enables Brave Browser's Safe Browsing feature and prevents users from changing this setting.

booleanEnable Safe Browsing
SafeBrowsingExtendedReportingEnabled

Enables Brave Browser's Safe Browsing Extended Reporting and prevents users from changing this setting.

booleanEnable Safe Browsing Extended Reporting
SafeBrowsingProtectionLevel

Allows you to control whether Brave Browser's Safe Browsing feature is enabled and the mode it operates in. Safe Browsing 'enhanced' mode provides better security, but requires sharing more browsing information with Google.

Default: 1

Range: Safe Browsing is never active (0), Safe Browsing is active in the standard mode (1), Safe Browsing is active in the enhanced mode (2)

integerSafe Browsing protection level
SafeBrowsingWhitelistDomains

Configure the list of domains which Safe Browsing will trust. This means: Safe Browsing will not check for dangerous resources (e.g. phishing, malware, or unwanted software) if their URLs match these domains. Safe Browsing's download protection service will not check downloads hosted on these domains. Safe Browsing's password protection service will not check for password reuse if the page URL matches these domains.

arrayConfigure the list of domains on which Safe Browsing will not trigger warnings.
SafeBrowsingAllowlistDomains

Configure the list of domains which Safe Browsing will trust. This means: Safe Browsing will not check for dangerous resources (e.g. phishing, malware, or unwanted software) if their URLs match these domains. Safe Browsing's download protection service will not check downloads hosted on these domains. Safe Browsing's password protection service will not check for password reuse if the page URL matches these domains.

arrayConfigure the list of domains on which Safe Browsing will not trigger warnings.
SafeBrowsingExtendedReportingOptInAllowed

This setting is deprecated, use SafeBrowsingExtendedReportingEnabled instead. Enabling or disabling SafeBrowsingExtendedReportingEnabled is equivalent to setting SafeBrowsingExtendedReportingOptInAllowed to False.

Default: true

booleanAllow users to opt in to Safe Browsing extended reporting
HomepageIsNewTabPage

Configures the type of the default home page in Brave Browser and prevents users from changing home page preferences. The home page can either be set to a URL you specify or set to the New Tab Page.

booleanUse New Tab Page as homepage
HomepageLocation

Configures the default home page URL in Brave Browser and prevents users from changing it.

stringHome page URL
NewTabPageLocation

Configures the default New Tab page URL and prevents users from changing it.

stringNew Tab page URL
RestoreOnStartup

Allows you to specify the behavior on startup.

Range: Open New Tab Page (5), Restore the last session (1), Open a list of URLs (4), Open a list of URLs and restore the last session (6)

integerAction on startup
RestoreOnStartupURLs

If 'Open a list of URLs' is selected as the startup action, this allows you to specify the list of URLs that are opened. If left not set no URL will be opened on start up.

arrayURLs to open on startup
ShowHomeButton

Shows the Home button on Brave Browser's toolbar.

booleanShow Home button on toolbar
WebUsbAskForUrls

Allows you to set a list of url patterns that specify sites which are allowed to ask the user to grant them access to a USB device.

arrayAllow WebUSB on these sites
WebUsbBlockedForUrls

Allows you to set a list of url patterns that specify sites which are prevented from asking the user to grant them access to a USB device.

arrayBlock WebUSB on these sites
DeveloperToolsDisabled

Disables the Developer Tools and the JavaScript console. This policy is deprecated in M68, please use DeveloperToolsAvailability instead.

Default: false

booleanControl where Developer Tools can be used
TorDisabled

If 'true', Tor is disabled.

Default: false

booleanDisable Tor
IPFSEnabled

If 'false', IPFS is disabled.

Default: true

booleanEnable IPFS
BraveRewardsDisabled

If 'true', Brave Rewards are disabled.

Default: false

booleanDisable Brave Rewards
BraveWalletDisabled

If 'true', Brave Wallet is disabled.

Default: false

booleanDisable Brave Wallet
BraveShieldsDisabledForUrls

Array of websites (each as a string) for which you want to enable Brave shields. Once enabled, the user can’t override and disable. Wildcards are not supported.

arrayBrave Shields Disabled for URLs
BraveShieldsEnabledForUrls

Array of websites (each as a string) for which you want to enable Brave shields. Once enabled, the user can’t override and disable. Wildcards are not supported.

arrayBrave Shields Enabled for URLs
BraveVPNDisabled

If 'true', Brave VPN is disabled.

Default: false

booleanDisable Brave VPN
BraveAIChatEnabled

If 'false', Brave AI Chat is disabled.

Default: true

booleanEnable Brave AI Chat
SUFeedURL

Setting this to a non-existent URL will disable the ability for users to manually check for updates. Useful when you intend to use your own software distribution mechanism to deploy updates.

stringSparkle Feed URL
SUEnableAutomaticChecks

Controls automatic update checks.

Default: true

booleanEnable Automatic Update Checks
SUScheduledCheckInterval

Controls the automatic update check interval. The default is 1 day (86400 seconds). Setting to 0 disables updates.

Default: 86400

integerAutomatic Update Check Interval
SUAllowsAutomaticUpdates

Controls the automatic update install prompt. When enabled, presents users with the option to allow automatic download and install of available updates. If disabled, disallows automatic updates and requires manual installation every time.

Default: true

booleanAutomatic Update Install Prompt
SUAutomaticallyUpdate

Controls automatic silent updates. If enabled, users will not be informed about updates and updates will be silently installed when the app quits.

Default: false

booleanEnable Automatic Silent Updates
string
string
string
string
string
string
string
string
string
stringDomains
string
string
string
string
string
string
string
string
RegisteredProtocolDictionary
dict
default

Default: true

boolean
protocol
string
url
string
ThirdPartyStoragePartitioningBlockedForOriginsElement
string
dict
urls
arrayURLs
devices
arrayDevices
string
dict
product_id
integer
vendor_id
integer
string
string
string
string

Range: Extension (extension), Hosted App (hosted_app), Legacy Packaged App (legacy_packaged_app), Platform App (platform_app), Theme (theme), User Script (user_script)

string
string
string
string
string
string
string
{{key}}
stringExtension ID
{{value}}
dict
installation_mode

Maps to a string indicating the installation mode for the extension.

Range: Allowed (allowed), Blocked (blocked), Force Installed (force_installed), Normal Installed (normal_installed)

string
update_url

Maps to a string indicating where Brave Browser can download a force_installed or normal_installed extension.

string
blocked_permissions

Maps to a list of strings indicating the blocked API permissions for the extension.

array
minimum_version_required

Maps to a version string.

string
ExtensionUnpublishedAvailability

If this policy is enabled, extensions that are unpublished on the Chrome Web Store will be disabled in Brave Browser

Default: 0

Range: Allow unpublished extensions (0), Disable unpublished extensions (1)

integerControl availability of extensions unpublished on the Brave Browser Web Store.
install_sources

Each item in this list is an extension-style match pattern.

array
allowed_types

This setting whitelists the allowed types of extension/apps that can be installed in Brave Browser.

array
blocked_install_message

This maps to a string specifying the error message to display to users if they're blocked from installing an extension.

string
runtime_blocked_hosts

Maps to a list of strings representing hosts whose webpages the extension will be blocked from modifying.

array
runtime_allowed_hosts

Maps to a list of strings representing hosts that an extension can interact with regardless of whether they are listed in "runtime_blocked_hosts".

array

Range: activeTab, alarms, background, bookmarks, browsingData, certificateProvider, clipboardRead, clipboardWrite, contentSettings, contextMenus, cookies, debugger, declarativeContent, declarativeNetRequest, declarativeWebRequest, desktopCapture, displaySource, dns, documentScan, downloads, enterprise.deviceAttributes, enterprise.hardwarePlatform, enterprise.platformKeys, experimental, fileBrowserHandler, fileSystemProvider, fontSettings, gcm, geolocation, history, identity, idle, idltest, management, nativeMessaging, networking.config, notifications, pageCapture, platformKeys, power, printerProvider, privacy, processes, proxy, sessions, signedInDevices, storage, system.cpu, system.display, system.memory, system.storage, tabCapture, tabs, topSites, tts, ttsEngine, unlimitedStorage, vpnProvider, wallpaper, webNavigation, webRequest, webRequestBlocking

string
string

Range: extension, theme, user_script, hosted_app, legacy_packaged_app, platform_app

string
string
string
string
string
string
string
string
string
dict
allowed_origins

A list of allowed origin patterns for the specified protocol.

arrayAllowed Origins
protocol
stringProtocol
allowed_originsItem
string
stringURL
stringFile Extension
string
string
string
string
string
string
string
string
stringPreference Key Name
string
string
stringHostname
stringDomain
dict

The top-level managed bookmarks folder name.

dictManaged Bookmarks Folder Name
name

Name of the bookmark.

string
url

URL for the bookmark.

string
toplevel_name
stringTop Level Name
string
string
string
string

Range: Apps (apps), Autofill (autofill), Bookmarks (bookmarks), Extensions (extensions), Passwords (passwords), Preferences (preferences), Tabs (tabs), Themes (themes), Typed URLs (typedUrls), Wifi Configuration (wifiConfiguration)

stringData Types
string
string
string
string
string
string
dict
url
stringURL
create_desktop_shortcut
booleanCreate Desktop Shortcut
default_launch_container

Range: Window (window), Tab (tab)

stringDefault Launch Container
fallback_app_name
stringFallback App Name
custom_name
stringCustom Name
custom_icon
dictCustom Icon
install_as_shortcut
booleanInstall as Shortcut
hash
stringCustom Icon Hash
url
stringCustom Icon URL
stringURL
string
string
string
string

Range: Zeroconf-based (mDNS + DNS-SD) protocol destinations (privet), Extension-based destinations (extension), The 'Save as PDF' destination (pdf), Local printer destinations (local), Google Cloud Print and 'Save to Google Drive' destinations (cloud)

stringPrinter Type
custom_size

Depends on: PrinterPaperSizeDefault.name ∈ [custom]

dictCustom Size
name

Range: custom, asme_f_28x40in, iso_2a0_1189x1682mm, iso_a0_841x1189mm, iso_a1_594x841mm, iso_a2_420x594mm, iso_a3_297x420mm, iso_a4-extra_235.5x322.3mm, iso_a4-tab_225x297mm, iso_a4_210x297mm, iso_a5-extra_174x235mm, iso_a5_148x210mm, iso_a6_105x148mm, iso_a7_74x105mm, iso_a8_52x74mm, iso_a9_37x52mm, iso_a10_26x37mm, iso_b0_1000x1414mm, iso_b1_707x1000mm, iso_b2_500x707mm, iso_b3_353x500mm, iso_b4_250x353mm, iso_b5-extra_201x276mm, iso_b5_176x250mm, iso_b6_125x176mm, iso_b6c4_125x324mm, iso_b7_88x125mm, iso_b8_62x88mm, iso_b9_44x62mm, iso_b10_31x44mm, iso_c0_917x1297mm, iso_c1_648x917mm, iso_c2_458x648mm, iso_c3_324x458mm, iso_c4_229x324mm, iso_c5_162x229mm, iso_c6_114x162mm, iso_c6c5_114x229mm, iso_c7_81x114mm, iso_c7c6_81x162mm, iso_c8_57x81mm, iso_c9_40x57mm, iso_c10_28x40mm, iso_dl_110x220mm, jis_exec_216x330mm, jpn_chou2_111.1x146mm, jpn_chou3_120x235mm, jpn_chou4_90x205mm, jpn_hagaki_100x148mm, jpn_kahu_240x322.1mm, jpn_kaku2_240x332mm, jpn_oufuku_148x200mm, jpn_you4_105x235mm, na_10x11_10x11in, na_10x13_10x13in, na_10x14_10x14in, na_10x15_10x15in, na_11x12_11x12in, na_11x15_11x15in, na_12x19_12x19in, na_5x7_5x7in, na_6x9_6x9in, na_7x9_7x9in, na_9x11_9x11in, na_a2_4.375x5.75in, na_arch-a_9x12in, na_arch-b_12x18in, na_arch-c_18x24in, na_arch-d_24x36in, na_arch-e_36x48in, na_b-plus_12x19.17in, na_c5_6.5x9.5in, na_c_17x22in, na_d_22x34in, na_e_34x44in, na_edp_11x14in, na_eur-edp_12x14in, na_f_44x68in, na_fanfold-eur_8.5x12in, na_fanfold-us_11x14.875in, na_foolscap_8.5x13in, na_govt-legal_8x13in, na_govt-letter_8x10in, na_index-3x5_3x5in, na_index-4x6-ext_6x8in, na_index-4x6_4x6in, na_index-5x8_5x8in, na_invoice_5.5x8.5in, na_ledger_11x17in, na_legal-extra_9.5x15in, na_legal_8.5x14in, na_letter-extra_9.5x12in, na_letter-plus_8.5x12.69in, na_letter_8.5x11in, na_number-10_4.125x9.5in, na_number-11_4.5x10.375in, na_number-12_4.75x11in, na_number-14_5x11.5in, na_personal_3.625x6.5in, na_super-a_8.94x14in, na_super-b_13x19in, na_wide-format_30x42in, om_dai-pa-kai_275x395mm, om_folio-sp_215x315mm, om_invite_220x220mm, om_italian_110x230mm, om_juuro-ku-kai_198x275mm, om_large-photo_200x300, om_pa-kai_267x389mm, om_postfix_114x229mm, om_small-photo_100x150mm, prc_10_324x458mm, prc_16k_146x215mm, prc_1_102x165mm, prc_2_102x176mm, prc_32k_97x151mm, prc_3_125x176mm, prc_4_110x208mm, prc_5_110x220mm, prc_6_120x320mm, prc_7_160x230mm, prc_8_120x309mm, roc_16k_7.75x10.75in, roc_8k_10.75x15.5in, jis_b0_1030x1456mm, jis_b1_728x1030mm, jis_b2_515x728mm, jis_b3_364x515mm, jis_b4_257x364mm, jis_b5_182x257mm, jis_b6_128x182mm, jis_b7_91x128mm, jis_b8_64x91mm, jis_b9_45x64mm, jis_b10_32x45mm

stringName
width

Width of the page

Depends on: PrinterPaperSizeDefault.name ∈ [custom]

integerWidth
height

Height of the page

Depends on: PrinterPaperSizeDefault.name ∈ [custom]

integerHeight
ProxyMode

Specifies the proxy server Brave Browser uses and prevents users from changing proxy settings.

Range: Never use proxy (ignores other fields) (direct), System (ignores other fields) (system), Auto Detect (ignores other fields) (auto_detect), Fixed (Uses ProxyServer & ProxyBypassList) (fixed_servers), Pac Script (Uses ProxyPacUrl & ProxyBypassList) (pac_script)

stringProxy Mode
ProxyServer

Specifies the URL of the proxy server

stringProxy Server URL
ProxyBypassList

Defines a comma-separated list of hosts for which Brave Browser bypasses any proxy.

stringProxy Bypass List
ProxyPacUrl

Specifies the URL for a proxy auto-config (PAC) file.

stringProxy PAC URL
ProxyPacMandatory

Prevents the network stack from falling back to direct connections with invalid or unavailable PAC script.

booleanProxy PAC Mandatory
string
string
string
string
string
string
string
URL
string
string
string
BraveShieldsDisabledForUrlsElement
string
BraveShieldsDisabledForUrlsElement
string