Policies can be specified by creating a file called policies.json:
distribution in the same
directory where thunderbird.exe is located.Thunderbird.app/Contents/Resources/distribution.thunderbird/distribution, where thunderbird
is the installation directory for Thunderbird. You can also specify a system-wide
policy by placing the file in /etc/thunderbird/policies.Alternatively, policies can be specified via platform-specific methods:
This document provides examples in these formats for all policies.
The Thunderbird policies are placed in the “Mozilla” category, which is defined
by Mozilla’s mozilla.admx. Both templates are needed. The mozilla.admx
provided here is Mozilla’s unchanged file, and may already be installed together
with the Firefox templates.
Installation:
thunderbird.admx and mozilla.admx into
C:\Windows\PolicyDefinitions (or the Central Store), and
thunderbird.adml and mozilla.adml into its en-US folder.mozilla.admx with
mozilla.adml first, then thunderbird.admx with thunderbird.adml, and
create a profile of type Templates › Imported Administrative templates. To
update, delete the profiles and the imported thunderbird.admx, and import
the new thunderbird.admx with thunderbird.adml. mozilla.admx stays
imported.| Policy Name | Description |
|---|---|
3rdparty |
Set policies that WebExtensions can access via chrome.storage.managed. |
AppAutoUpdate |
Enable or disable automatic application update. |
AppUpdatePin |
Prevent Thunderbird from being updated beyond the specified version. |
AppUpdateURL |
Set custom app update URL. |
Authentication |
Configure integrated authentication for websites that support it. |
BackgroundAppUpdate |
Enable or disable the background updater. |
BlockAboutAddons |
Block access to the Add-ons Manager (about:addons). |
BlockAboutConfig |
Block access to the about:config page. |
BlockAboutProfiles |
Block access to the about:profiles page. |
BlockAboutSupport |
Block access to the about:support page. |
CaptivePortal |
Enable or disable captive portal support. |
Certificates |
Add certificates or use built-in certificates. |
Certificates -> ImportEnterpriseRoots |
Trust certificates that have been added to the operating system certificate store by a user or administrator. |
Certificates -> Install |
Install certificates into the Thunderbird certificate store. |
Cookies |
Allow or deny websites to set cookies. |
DefaultDownloadDirectory |
Set the default download directory. |
DisableAppUpdate |
Prevent Thunderbird from updating. |
DisableBuiltinPDFViewer |
Disable PDF.js, the built-in PDF viewer in Thunderbird. |
DisabledCiphers |
Disable ciphers. |
DisableDeveloperTools |
Block access to the developer tools. |
DisableMasterPasswordCreation |
If true, a master password can’t be created. |
DisablePasswordReveal |
Meant to prevent passwords from being revealed in saved logins. In this version, this policy has no effect. |
DisableSafeMode |
Disable the feature to restart in Safe Mode. Note: the Shift key to enter Safe Mode can only be disabled on Windows using Group Policy. |
DisableSecurityBypass |
Prevent the user from bypassing certain security warnings. |
DisableSystemAddonUpdate |
Prevent Thunderbird from installing and updating system add-ons. |
DisableTelemetry |
Turn off Telemetry. |
DNSOverHTTPS |
Configure DNS over HTTPS. |
DownloadDirectory |
Set and lock the download directory. |
Extensions |
Install, uninstall or lock extensions. The Install option takes URLs or paths as parameters. The Uninstall and Locked options take extension IDs. |
ExtensionSettings |
Manage all aspects of extension installation. |
ExtensionUpdate |
Enable or disable automatic extension updates. |
Handlers |
Configure default application handlers. |
HardwareAcceleration |
If false, turn off hardware acceleration. |
InAppNotification |
Enable or disable notification types. |
InstallAddonsPermission |
Allow certain websites to install add-ons. |
ManualAppUpdateOnly |
Allow manual updates only and do not notify the user about updates. |
NetworkPrediction |
Enable or disable network prediction (DNS prefetching). |
OfferToSaveLogins |
Enforce the setting to allow Thunderbird to offer to remember saved logins and passwords. Both true and false values are accepted. |
OfferToSaveLoginsDefault |
Set the default value for allowing Thunderbird to offer to remember saved logins and passwords. Both true and false values are accepted. |
PasswordManagerEnabled |
Enable saving passwords to the password manager. |
PDFjs |
Disable or configure PDF.js, the built-in PDF viewer in Thunderbird. |
Preferences |
Set and lock the value for a subset of preferences. |
PrimaryPassword |
Require or prevent using a Primary Password. |
PromptForDownloadLocation |
Ask where to save files when downloading. |
Proxy |
Configure proxy settings. |
RequestedLocales |
Set the list of requested locales for the application in order of preference. |
SearchEngines |
Configure search engine settings. |
SearchEngines -> Add |
Add new search engines. |
SearchEngines -> Default |
Set the default search engine, which is used to search the web from Thunderbird. |
SearchEngines -> DefaultPrivate |
Set the default search engine for private browsing. |
SearchEngines -> PreventInstalls |
Prevent installing search engines from webpages. |
SearchEngines -> Remove |
Hide built-in search engines. |
SSLVersionMax |
Set the maximum SSL version. |
SSLVersionMin |
Set the minimum SSL version. |
Set policies that WebExtensions can access via chrome.storage.managed.
Each entry is the managed storage of one extension, which the extension reads with browser.storage.managed and uses as its settings. For more information, see Adding policy support to your extension.
CCK2 Equivalent: N/A
Preferences Affected: N/A
Extensions Managed storage of extensions (object)
The managed storage of each extension, one JSON object per extension ID, which the extension reads with
browser.storage.managed.
[name](JSON) The managed storage entries of one extension. Their format is defined by the extension.
Software\Policies\Mozilla\Thunderbird\3rdparty\Extensions\uBlock0@raymondhill.net (REG_MULTI_SZ) =
{
"adminSettings": {
"selectedFilterLists": ["ublock-privacy", "ublock-badware", "ublock-filters", "user-filters"]
}
}
<dict>
<key>3rdparty</key>
<dict>
<key>Extensions</key>
<dict>
<key>uBlock0@raymondhill.net</key>
<dict>
<key>adminSettings</key>
<dict>
<key>selectedFilterLists</key>
<array>
<string>ublock-privacy</string>
<string>ublock-badware</string>
<string>ublock-filters</string>
<string>user-filters</string>
</array>
</dict>
</dict>
</dict>
</dict>
</dict>
{
"policies": {
"3rdparty": {
"Extensions": {
"uBlock0@raymondhill.net": {
"adminSettings": {
"selectedFilterLists": ["ublock-privacy", "ublock-badware", "ublock-filters", "user-filters"]
}
}
}
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
3rdparty3rdparty_Extensions3rdparty_Extensions_[name] |
78.0 |
Enable or disable automatic application update.
Install application updates automatically. If this policy is enabled, updates are installed without asking the user (the operating system might still ask for approval). If it is disabled, updates are downloaded, and the user chooses when to install them. In both cases, the user can’t change the setting. If updates are turned off with DisableAppUpdate, this policy has no effect.
CCK2 Equivalent: N/A
Preferences Affected: app.update.auto
AppAutoUpdate (boolean)
Software\Policies\Mozilla\Thunderbird\AppAutoUpdate (REG_DWORD) = 0x1
<dict>
<key>AppAutoUpdate</key>
<true/>
</dict>
{
"policies": {
"AppAutoUpdate": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
AppAutoUpdate |
75.0 |
Prevent Thunderbird from being updated beyond the specified version.
You can specify the version as xx. and Thunderbird will be updated with all minor versions, but will not be updated beyond the major version.
You can also specify the version as xx.xx and Thunderbird will be updated with all patch versions, but will not be updated beyond the minor version.
You should specify a version that exists or is guaranteed to exist. If you specify a version that doesn’t end up existing, Thunderbird will update beyond that version.
CCK2 Equivalent: N/A
Preferences Affected: N/A
AppUpdatePin (string)
Software\Policies\Mozilla\Thunderbird\AppUpdatePin (REG_SZ) = 106.
<dict>
<key>AppUpdatePin</key>
<string>106.</string>
</dict>
{
"policies": {
"AppUpdatePin": "106."
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
AppUpdatePin |
104.0 |
Set custom app update URL.
Change the URL for application update if you are providing Thunderbird updates from a custom update server.
CCK2 Equivalent: N/A
Preferences Affected: app.update.url
AppUpdateURL (string, URL)
Software\Policies\Mozilla\Thunderbird\AppUpdateURL (REG_SZ) = https://yoursite.com
<dict>
<key>AppUpdateURL</key>
<string>https://yoursite.com</string>
</dict>
{
"policies": {
"AppUpdateURL": "https://yoursite.com"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
AppUpdateURL |
68.0 |
Configure integrated authentication for websites that support it.
See Integrated authentication for more information.
CCK2 Equivalent: N/A
Preferences Affected: network.negotiate-auth.trusted-uris, network.negotiate-auth.delegation-uris, network.automatic-ntlm-auth.trusted-uris, network.automatic-ntlm-auth.allow-non-fqdn, network.negotiate-auth.allow-non-fqdn, network.automatic-ntlm-auth.allow-proxies, network.negotiate-auth.allow-proxies, network.auth.private-browsing-sso
SPNEGO Sites allowed to use SPNEGO (list of strings)
Websites which may use integrated authentication via SPNEGO (Kerberos).
Delegated Sites allowed to receive delegated credentials (list of strings)
Websites to which Thunderbird may delegate the authorization of the user.
NTLM Sites allowed to use NTLM (list of strings)
Websites which may use integrated authentication via NTLM.
AllowNonFQDN Allow integrated authentication for non-FQDN hosts (object)
Allows integrated authentication for hosts which are not given as fully qualified domain names.
SPNEGOAllow SPNEGO (boolean)NTLMAllow NTLM (boolean)
AllowProxies Allow integrated authentication for proxies (object)
Allows integrated authentication for proxy servers.
SPNEGOAllow SPNEGO (boolean)NTLMAllow NTLM (boolean)
Locked Lock the integrated authentication settings (boolean)
Prevents the user from changing the integrated authentication settings. The settings are locked unless this is false.
PrivateBrowsing Integrated authentication in private browsing (boolean)
Enables integrated authentication in private browsing.
Software\Policies\Mozilla\Thunderbird\Authentication\SPNEGO\1 (REG_SZ) = mydomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\SPNEGO\2 (REG_SZ) = https://myotherdomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\Delegated\1 (REG_SZ) = mydomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\Delegated\2 (REG_SZ) = https://myotherdomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\NTLM\1 (REG_SZ) = mydomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\NTLM\2 (REG_SZ) = https://myotherdomain.com
Software\Policies\Mozilla\Thunderbird\Authentication\AllowNonFQDN\SPNEGO (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Authentication\AllowNonFQDN\NTLM (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Authentication\AllowProxies\SPNEGO (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Authentication\AllowProxies\NTLM (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Authentication\Locked (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Authentication\PrivateBrowsing (REG_DWORD) = 0x1
<dict>
<key>Authentication</key>
<dict>
<key>SPNEGO</key>
<array>
<string>mydomain.com</string>
<string>https://myotherdomain.com</string>
</array>
<key>Delegated</key>
<array>
<string>mydomain.com</string>
<string>https://myotherdomain.com</string>
</array>
<key>NTLM</key>
<array>
<string>mydomain.com</string>
<string>https://myotherdomain.com</string>
</array>
<key>AllowNonFQDN</key>
<dict>
<key>SPNEGO</key>
<true/>
<key>NTLM</key>
<true/>
</dict>
<key>AllowProxies</key>
<dict>
<key>SPNEGO</key>
<true/>
<key>NTLM</key>
<true/>
</dict>
<key>Locked</key>
<true/>
<key>PrivateBrowsing</key>
<true/>
</dict>
</dict>
{
"policies": {
"Authentication": {
"SPNEGO": ["mydomain.com", "https://myotherdomain.com"],
"Delegated": ["mydomain.com", "https://myotherdomain.com"],
"NTLM": ["mydomain.com", "https://myotherdomain.com"],
"AllowNonFQDN": {
"SPNEGO": true,
"NTLM": true
},
"AllowProxies": {
"SPNEGO": true,
"NTLM": true
},
"Locked": true,
"PrivateBrowsing": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
AuthenticationAuthentication_SPNEGOAuthentication_DelegatedAuthentication_NTLMAuthentication_AllowNonFQDNAuthentication_AllowNonFQDN_SPNEGOAuthentication_AllowNonFQDN_NTLMAuthentication_AllowProxiesAuthentication_AllowProxies_SPNEGOAuthentication_AllowProxies_NTLMAuthentication_LockedAuthentication_PrivateBrowsing |
78.0 |
Enable or disable the background updater.
Install application updates in the background, also when Thunderbird is not running (only on Windows). If this policy is enabled, updates may be installed in the background without asking the user (the operating system might still ask for approval). If it is disabled, no updates are installed while Thunderbird is not running. In both cases, the user can’t change the setting. If updates are turned off with DisableAppUpdate, or automatic updates with AppAutoUpdate, this policy has no effect. If background updates don’t run, check the requirements in this support article.
CCK2 Equivalent: N/A
Preferences Affected: app.update.background.enabled
BackgroundAppUpdate (boolean)
Software\Policies\Mozilla\Thunderbird\BackgroundAppUpdate (REG_DWORD) = 0x1
{
"policies": {
"BackgroundAppUpdate": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
BackgroundAppUpdate |
92.0 |
Block access to the Add-ons Manager (about:addons).
Users can no longer open it to install, remove, enable or disable add-ons, or to change their options. Add-ons can still be managed with the Extensions and ExtensionSettings policies.
If this policy is disabled or not configured, the Add-ons Manager is available.
CCK2 Equivalent: disableAddonsManager
Preferences Affected: N/A
BlockAboutAddons (boolean)
Software\Policies\Mozilla\Thunderbird\BlockAboutAddons (REG_DWORD) = 0x1
<dict>
<key>BlockAboutAddons</key>
<true/>
</dict>
{
"policies": {
"BlockAboutAddons": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
BlockAboutAddons |
68.0 |
Block access to the about:config page.
Block access to about:config.
CCK2 Equivalent: disableAboutConfig
Preferences Affected: N/A
BlockAboutConfig (boolean)
Software\Policies\Mozilla\Thunderbird\BlockAboutConfig (REG_DWORD) = 0x1
<dict>
<key>BlockAboutConfig</key>
<true/>
</dict>
{
"policies": {
"BlockAboutConfig": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
BlockAboutConfig |
68.0 |
Block access to the about:profiles page.
Block access to About Profiles (about:profiles).
CCK2 Equivalent: disableAboutProfiles
Preferences Affected: N/A
BlockAboutProfiles (boolean)
Software\Policies\Mozilla\Thunderbird\BlockAboutProfiles (REG_DWORD) = 0x1
<dict>
<key>BlockAboutProfiles</key>
<true/>
</dict>
{
"policies": {
"BlockAboutProfiles": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
BlockAboutProfiles |
68.0 |
Block access to the about:support page.
Block access to Troubleshooting Information (about:support).
CCK2 Equivalent: disableAboutSupport
Preferences Affected: N/A
BlockAboutSupport (boolean)
Software\Policies\Mozilla\Thunderbird\BlockAboutSupport (REG_DWORD) = 0x1
<dict>
<key>BlockAboutSupport</key>
<true/>
</dict>
{
"policies": {
"BlockAboutSupport": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
BlockAboutSupport |
68.0 |
Enable or disable captive portal support.
Detect captive portals, the login pages of networks in hotels or airports which have to be passed before the internet can be used. If this policy is enabled, the detection is turned on. If it is disabled, it is turned off. In both cases, the user can’t change the setting. If this policy is not configured, the user can change the setting.
CCK2 Equivalent: N/A
Preferences Affected: network.captive-portal-service.enabled
CaptivePortal (boolean)
Software\Policies\Mozilla\Thunderbird\CaptivePortal (REG_DWORD) = 0x1
<dict>
<key>CaptivePortal</key>
<true/>
</dict>
{
"policies": {
"CaptivePortal": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
CaptivePortal |
78.0 |
Add certificates or use built-in certificates.
CCK2 Equivalent: N/A
Preferences Affected: N/A
Certificates (object)
Software\Policies\Mozilla\Thunderbird\Certificates\ImportEnterpriseRoots (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Certificates\Install\1 (REG_EXPAND_SZ) = cert1.der
Software\Policies\Mozilla\Thunderbird\Certificates\Install\2 (REG_EXPAND_SZ) = C:\Users\username\cert2.pem
<dict>
<key>Certificates</key>
<dict>
<key>ImportEnterpriseRoots</key>
<true/>
<key>Install</key>
<array>
<string>cert1.der</string>
<string>/home/username/cert2.pem</string>
</array>
</dict>
</dict>
{
"policies": {
"Certificates": {
"ImportEnterpriseRoots": true,
"Install": ["cert1.der", "/home/username/cert2.pem"]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
CertificatesCertificates_ImportEnterpriseRootsCertificates_Install |
68.0 |
Trust certificates that have been added to the operating system certificate store by a user or administrator.
Note: This policy only works on Windows and macOS. For Linux discussion, see bug 1600509.
See https://support.mozilla.org/kb/setting-certificate-authorities-firefox for more detail.
CCK2 Equivalent: N/A
Preferences Affected: security.enterprise_roots.enabled
ImportEnterpriseRoots (boolean)
Software\Policies\Mozilla\Thunderbird\Certificates\ImportEnterpriseRoots (REG_DWORD) = 0x1
<dict>
<key>Certificates</key>
<dict>
<key>ImportEnterpriseRoots</key>
<true/>
</dict>
</dict>
{
"policies": {
"Certificates": {
"ImportEnterpriseRoots": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
Certificates_ImportEnterpriseRoots |
68.0 |
Install certificates into the Thunderbird certificate store.
If only a filename is specified, Thunderbird searches for the file in the following locations:
A fully qualified path can be used, including UNC paths. You should use the native path style for your operating system.
If you are specifying the path in the policies.json file on Windows, you need to escape your backslashes (\\) which means that for UNC paths, you need to escape both (\\\\). If you use group policy, you only need one backslash.
Certificates are installed using the trust string CT,CT,.
Binary (DER) and ASCII (PEM) certificates are both supported.
Environment variables like %USERPROFILE% are only expanded when the policy is set via Group Policy.
CCK2 Equivalent: certs.ca
Preferences Affected: N/A
Install (list of strings)
Software\Policies\Mozilla\Thunderbird\Certificates\Install\1 (REG_EXPAND_SZ) = cert1.der
Software\Policies\Mozilla\Thunderbird\Certificates\Install\2 (REG_EXPAND_SZ) = C:\Users\username\cert2.pem
<dict>
<key>Certificates</key>
<dict>
<key>Install</key>
<array>
<string>cert1.der</string>
<string>/home/username/cert2.pem</string>
</array>
</dict>
</dict>
{
"policies": {
"Certificates": {
"Install": ["cert1.der", "/home/username/cert2.pem"]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
Certificates_Install |
68.0 |
Allow or deny websites to set cookies.
Configure cookie preferences.
CCK2 Equivalent: N/A
Preferences Affected: network.cookie.cookieBehavior, network.cookie.cookieBehavior.pbmode
Allow Sites which may always set cookies (list of origins)
A list of origins (not domains) where cookies are always allowed. You must include http or https.
Block Sites which may never set cookies (list of origins)
A list of origins (not domains) where cookies are always blocked. You must include http or https.
Default Accept cookies (boolean)
Determines whether cookies are accepted at all.
AcceptThirdParty Accept third-party cookies (string: always, never or from-visited)
Determines how third-party cookies are handled.\
always: Accept all third-party cookies.\never: Reject all third-party cookies.\from-visited: Accept third-party cookies only from sites the user has visited.
ExpireAtSessionEnd Keep cookies only until the end of the session (boolean) Deprecated.
This setting has no effect anymore.
Locked Lock the cookie preferences (boolean)
Prevents the user from changing cookie preferences.
Software\Policies\Mozilla\Thunderbird\Cookies\Allow\1 (REG_SZ) = http://example.org/
Software\Policies\Mozilla\Thunderbird\Cookies\Block\1 (REG_SZ) = http://example.edu/
Software\Policies\Mozilla\Thunderbird\Cookies\Default (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Cookies\AcceptThirdParty (REG_SZ) = always
Software\Policies\Mozilla\Thunderbird\Cookies\Locked (REG_DWORD) = 0x1
<dict>
<key>Cookies</key>
<dict>
<key>Allow</key>
<array>
<string>http://example.org/</string>
</array>
<key>Block</key>
<array>
<string>http://example.edu/</string>
</array>
<key>Default</key>
<true/>
<key>AcceptThirdParty</key>
<string>always</string>
<key>Locked</key>
<true/>
</dict>
</dict>
{
"policies": {
"Cookies": {
"Allow": ["http://example.org/"],
"Block": ["http://example.edu/"],
"Default": true,
"AcceptThirdParty": "always",
"Locked": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
CookiesCookies_AllowCookies_BlockCookies_DefaultCookies_AcceptThirdPartyCookies_ExpireAtSessionEndCookies_Locked |
78.0 |
Set the default download directory.
You can use ${home} for the native home directory.
Environment variables like %USERPROFILE% are only expanded when the policy is set via Group Policy.
CCK2 Equivalent: N/A
Preferences Affected: browser.download.dir, browser.download.folderList
DefaultDownloadDirectory (string)
Software\Policies\Mozilla\Thunderbird\DefaultDownloadDirectory (REG_EXPAND_SZ) = ${home}\Downloads
<dict>
<key>DefaultDownloadDirectory</key>
<string>${home}/Downloads</string>
</dict>
{
"policies": {
"DefaultDownloadDirectory": "${home}/Downloads"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DefaultDownloadDirectory |
78.0 |
Prevent Thunderbird from updating.
Turn off application updates within Thunderbird.
CCK2 Equivalent: disableFirefoxUpdates
Preferences Affected: N/A
DisableAppUpdate (boolean)
Software\Policies\Mozilla\Thunderbird\DisableAppUpdate (REG_DWORD) = 0x1
<dict>
<key>DisableAppUpdate</key>
<true/>
</dict>
{
"policies": {
"DisableAppUpdate": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableAppUpdate |
68.0 |
Disable PDF.js, the built-in PDF viewer in Thunderbird.
Disable the built in PDF viewer. PDF files are downloaded and sent externally.
CCK2 Equivalent: disablePDFjs
Preferences Affected: pdfjs.disabled
DisableBuiltinPDFViewer (boolean)
Software\Policies\Mozilla\Thunderbird\DisableBuiltinPDFViewer (REG_DWORD) = 0x1
<dict>
<key>DisableBuiltinPDFViewer</key>
<true/>
</dict>
{
"policies": {
"DisableBuiltinPDFViewer": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableBuiltinPDFViewer |
92.0 |
Disable ciphers.
Disable specific cryptographic ciphers.
CCK2 Equivalent: N/A
Preferences Affected: security.ssl3.ecdhe_rsa_aes_128_gcm_sha256, security.ssl3.ecdhe_ecdsa_aes_128_gcm_sha256, security.ssl3.ecdhe_ecdsa_chacha20_poly1305_sha256, security.ssl3.ecdhe_rsa_chacha20_poly1305_sha256, security.ssl3.ecdhe_ecdsa_aes_256_gcm_sha384, security.ssl3.ecdhe_rsa_aes_256_gcm_sha384, security.ssl3.ecdhe_rsa_aes_128_sha, security.ssl3.ecdhe_ecdsa_aes_128_sha, security.ssl3.ecdhe_rsa_aes_256_sha, security.ssl3.ecdhe_ecdsa_aes_256_sha, security.ssl3.dhe_rsa_aes_128_sha, security.ssl3.dhe_rsa_aes_256_sha, security.ssl3.rsa_aes_128_gcm_sha256, security.ssl3.rsa_aes_256_gcm_sha384, security.ssl3.rsa_aes_128_sha, security.ssl3.rsa_aes_256_sha, security.ssl3.deprecated.rsa_des_ede3_sha
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 Disable TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (boolean)
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 Disable TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (boolean)
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 Disable TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 (boolean)
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 Disable TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (boolean)
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 Disable TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (boolean)
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 Disable TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (boolean)
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Disable TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (boolean)
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Disable TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (boolean)
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Disable TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (boolean)
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Disable TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (boolean)
TLS_DHE_RSA_WITH_AES_128_CBC_SHA Disable TLS_DHE_RSA_WITH_AES_128_CBC_SHA (boolean)
TLS_DHE_RSA_WITH_AES_256_CBC_SHA Disable TLS_DHE_RSA_WITH_AES_256_CBC_SHA (boolean)
TLS_RSA_WITH_AES_128_GCM_SHA256 Disable TLS_RSA_WITH_AES_128_GCM_SHA256 (boolean)
TLS_RSA_WITH_AES_256_GCM_SHA384 Disable TLS_RSA_WITH_AES_256_GCM_SHA384 (boolean)
TLS_RSA_WITH_AES_128_CBC_SHA Disable TLS_RSA_WITH_AES_128_CBC_SHA (boolean)
TLS_RSA_WITH_AES_256_CBC_SHA Disable TLS_RSA_WITH_AES_256_CBC_SHA (boolean)
TLS_RSA_WITH_3DES_EDE_CBC_SHA Disable TLS_RSA_WITH_3DES_EDE_CBC_SHA (boolean)
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_DHE_RSA_WITH_AES_128_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_DHE_RSA_WITH_AES_256_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_RSA_WITH_AES_128_GCM_SHA256 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_RSA_WITH_AES_256_GCM_SHA384 (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_RSA_WITH_AES_128_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_RSA_WITH_AES_256_CBC_SHA (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisabledCiphers\TLS_RSA_WITH_3DES_EDE_CBC_SHA (REG_DWORD) = 0x1
<dict>
<key>DisabledCiphers</key>
<dict>
<key>TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</key>
<true/>
<key>TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256</key>
<true/>
<key>TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256</key>
<true/>
<key>TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256</key>
<true/>
<key>TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384</key>
<true/>
<key>TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</key>
<true/>
<key>TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA</key>
<true/>
<key>TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA</key>
<true/>
<key>TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA</key>
<true/>
<key>TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA</key>
<true/>
<key>TLS_DHE_RSA_WITH_AES_128_CBC_SHA</key>
<true/>
<key>TLS_DHE_RSA_WITH_AES_256_CBC_SHA</key>
<true/>
<key>TLS_RSA_WITH_AES_128_GCM_SHA256</key>
<true/>
<key>TLS_RSA_WITH_AES_256_GCM_SHA384</key>
<true/>
<key>TLS_RSA_WITH_AES_128_CBC_SHA</key>
<true/>
<key>TLS_RSA_WITH_AES_256_CBC_SHA</key>
<true/>
<key>TLS_RSA_WITH_3DES_EDE_CBC_SHA</key>
<true/>
</dict>
</dict>
{
"policies": {
"DisabledCiphers": {
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": true,
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": true,
"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256": true,
"TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256": true,
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": true,
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": true,
"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA": true,
"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA": true,
"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA": true,
"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA": true,
"TLS_DHE_RSA_WITH_AES_128_CBC_SHA": true,
"TLS_DHE_RSA_WITH_AES_256_CBC_SHA": true,
"TLS_RSA_WITH_AES_128_GCM_SHA256": true,
"TLS_RSA_WITH_AES_256_GCM_SHA384": true,
"TLS_RSA_WITH_AES_128_CBC_SHA": true,
"TLS_RSA_WITH_AES_256_CBC_SHA": true,
"TLS_RSA_WITH_3DES_EDE_CBC_SHA": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisabledCiphersDisabledCiphers_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256DisabledCiphers_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256DisabledCiphers_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHADisabledCiphers_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHADisabledCiphers_TLS_DHE_RSA_WITH_AES_128_CBC_SHADisabledCiphers_TLS_DHE_RSA_WITH_AES_256_CBC_SHADisabledCiphers_TLS_RSA_WITH_AES_128_CBC_SHADisabledCiphers_TLS_RSA_WITH_AES_256_CBC_SHADisabledCiphers_TLS_RSA_WITH_3DES_EDE_CBC_SHA |
76.0 | |
DisabledCiphers_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256DisabledCiphers_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256DisabledCiphers_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384DisabledCiphers_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384DisabledCiphers_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHADisabledCiphers_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA |
102.0 | |
DisabledCiphers_TLS_RSA_WITH_AES_128_GCM_SHA256DisabledCiphers_TLS_RSA_WITH_AES_256_GCM_SHA384 |
92.0 |
Block access to the developer tools.
Remove access to all developer tools.
CCK2 Equivalent: removeDeveloperTools
Preferences Affected: devtools.policy.disabled, devtools.chrome.enabled
DisableDeveloperTools (boolean)
Software\Policies\Mozilla\Thunderbird\DisableDeveloperTools (REG_DWORD) = 0x1
<dict>
<key>DisableDeveloperTools</key>
<true/>
</dict>
{
"policies": {
"DisableDeveloperTools": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableDeveloperTools |
68.0 |
If true, a master password can’t be created.
Remove the master password functionality.
If this value is true, it works the same as setting PrimaryPassword to false and removes the primary password functionality.
If both DisableMasterPasswordCreation and PrimaryPassword are used, DisableMasterPasswordCreation takes precedence.
CCK2 Equivalent: noMasterPassword
Preferences Affected: N/A
DisableMasterPasswordCreation (boolean)
Software\Policies\Mozilla\Thunderbird\DisableMasterPasswordCreation (REG_DWORD) = 0x1
<dict>
<key>DisableMasterPasswordCreation</key>
<true/>
</dict>
{
"policies": {
"DisableMasterPasswordCreation": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableMasterPasswordCreation |
68.0 |
Meant to prevent passwords from being revealed in saved logins. In this version, this policy has no effect.
Meant to prevent passwords from being shown in saved logins. In this version, this policy has no effect, because the saved passwords dialog of Thunderbird does not check it.
CCK2 Equivalent: N/A
Preferences Affected: N/A
DisablePasswordReveal (boolean)
Software\Policies\Mozilla\Thunderbird\DisablePasswordReveal (REG_DWORD) = 0x1
<dict>
<key>DisablePasswordReveal</key>
<true/>
</dict>
{
"policies": {
"DisablePasswordReveal": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisablePasswordReveal |
78.0 |
Disable the feature to restart in Safe Mode. Note: the Shift key to enter Safe Mode can only be disabled on Windows using Group Policy.
Disable safe mode within the browser.
On Windows, this disables safe mode via the command line as well.
CCK2 Equivalent: disableSafeMode
Preferences Affected: N/A
DisableSafeMode (boolean)
Software\Policies\Mozilla\Thunderbird\DisableSafeMode (REG_DWORD) = 0x1
<dict>
<key>DisableSafeMode</key>
<true/>
</dict>
{
"policies": {
"DisableSafeMode": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableSafeMode |
78.0 |
Prevent the user from bypassing certain security warnings.
Prevent the user from bypassing security in certain cases.
These policies only affect what happens when an error is shown. They do not affect any settings in preferences.
CCK2 Equivalent: N/A
Preferences Affected: security.certerror.hideAddException, browser.safebrowsing.allowOverride
InvalidCertificate Prevent exceptions for invalid certificates (boolean)
Prevents adding an exception when an invalid certificate is shown.
SafeBrowsing Prevent visiting harmful sites anyway (boolean)
Prevents selecting “ignore the risk” and visiting a harmful site anyway.
Software\Policies\Mozilla\Thunderbird\DisableSecurityBypass\InvalidCertificate (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DisableSecurityBypass\SafeBrowsing (REG_DWORD) = 0x1
<dict>
<key>DisableSecurityBypass</key>
<dict>
<key>InvalidCertificate</key>
<true/>
<key>SafeBrowsing</key>
<true/>
</dict>
</dict>
{
"policies": {
"DisableSecurityBypass": {
"InvalidCertificate": true,
"SafeBrowsing": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableSecurityBypassDisableSecurityBypass_InvalidCertificateDisableSecurityBypass_SafeBrowsing |
68.0 |
Prevent Thunderbird from installing and updating system add-ons.
Prevent system add-ons from being installed or updated.
CCK2 Equivalent: N/A
Preferences Affected: N/A
DisableSystemAddonUpdate (boolean)
Software\Policies\Mozilla\Thunderbird\DisableSystemAddonUpdate (REG_DWORD) = 0x1
<dict>
<key>DisableSystemAddonUpdate</key>
<true/>
</dict>
{
"policies": {
"DisableSystemAddonUpdate": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableSystemAddonUpdate |
77.0 |
Turn off Telemetry.
Prevent the upload of telemetry data.
Local storage of telemetry data is disabled as well.
Mozilla recommends that you do not disable telemetry. Information collected through telemetry helps us build a better product for businesses like yours.
CCK2 Equivalent: disableTelemetry
Preferences Affected: datareporting.healthreport.uploadEnabled, datareporting.policy.dataSubmissionEnabled, toolkit.telemetry.archive.enabled
DisableTelemetry (boolean)
Software\Policies\Mozilla\Thunderbird\DisableTelemetry (REG_DWORD) = 0x1
<dict>
<key>DisableTelemetry</key>
<true/>
</dict>
{
"policies": {
"DisableTelemetry": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DisableTelemetry |
78.0 |
Configure DNS over HTTPS.
With DNS over HTTPS, host names are resolved through an encrypted connection to a DNS over HTTPS provider, instead of the DNS resolver of the operating system. The user can change these settings, unless the Locked setting is used.
CCK2 Equivalent: N/A
Preferences Affected: network.trr.mode, network.trr.uri, network.trr.excluded-domains
Enabled Enable DNS over HTTPS (boolean)
Determines whether DNS over HTTPS is enabled.
ProviderURL DNS over HTTPS provider (string, URL)
The URL of another DNS over HTTPS provider.
ExcludedDomains Domains excluded from DNS over HTTPS (list of strings)
Domains which are resolved without DNS over HTTPS.
Locked Lock the DNS over HTTPS settings (boolean)
Prevents the user from changing DNS over HTTPS preferences.
Software\Policies\Mozilla\Thunderbird\DNSOverHTTPS\Enabled (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\DNSOverHTTPS\ProviderURL (REG_SZ) = https://dns.example.com/dns-query
Software\Policies\Mozilla\Thunderbird\DNSOverHTTPS\ExcludedDomains\1 (REG_SZ) = example.com
Software\Policies\Mozilla\Thunderbird\DNSOverHTTPS\Locked (REG_DWORD) = 0x1
<dict>
<key>DNSOverHTTPS</key>
<dict>
<key>Enabled</key>
<true/>
<key>ProviderURL</key>
<string>https://dns.example.com/dns-query</string>
<key>ExcludedDomains</key>
<array>
<string>example.com</string>
</array>
<key>Locked</key>
<true/>
</dict>
</dict>
{
"policies": {
"DNSOverHTTPS": {
"Enabled": true,
"ProviderURL": "https://dns.example.com/dns-query",
"ExcludedDomains": ["example.com"],
"Locked": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DNSOverHTTPSDNSOverHTTPS_EnabledDNSOverHTTPS_ProviderURLDNSOverHTTPS_ExcludedDomainsDNSOverHTTPS_Locked |
92.0 |
Set and lock the download directory.
You can use ${home} for the native home directory.
Environment variables like %USERPROFILE% are only expanded when the policy is set via Group Policy.
CCK2 Equivalent: N/A
Preferences Affected: browser.download.dir, browser.download.folderList, browser.download.useDownloadDir
DownloadDirectory (string)
Software\Policies\Mozilla\Thunderbird\DownloadDirectory (REG_EXPAND_SZ) = ${home}\Downloads
<dict>
<key>DownloadDirectory</key>
<string>${home}/Downloads</string>
</dict>
{
"policies": {
"DownloadDirectory": "${home}/Downloads"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
DownloadDirectory |
78.0 |
Install, uninstall or lock extensions. The Install option takes URLs or paths as parameters. The Uninstall and Locked options take extension IDs.
Control the installation, uninstallation and locking of extensions.
We strongly recommend that you use the ExtensionSettings policy. It has the same functionality and adds more. It does not support native paths, though, so you’ll have to use file:/// URLs.
CCK2 Equivalent: addons
Preferences Affected: N/A
Install Extensions to install (list of strings)
A list of URLs or native paths of extensions to be installed. Environment variables like %USERPROFILE% are only expanded when the policy is set via Group Policy.
Uninstall Extensions to uninstall (list of strings)
A list of extension IDs which are uninstalled if found.
Locked Extensions which can’t be disabled or removed (list of strings)
A list of extension IDs which the user can’t disable or uninstall.
Software\Policies\Mozilla\Thunderbird\Extensions\Install\1 (REG_EXPAND_SZ) = https://addons.thunderbird.net/thunderbird/downloads/somefile.xpi
Software\Policies\Mozilla\Thunderbird\Extensions\Install\2 (REG_EXPAND_SZ) = //path/to/xpi
Software\Policies\Mozilla\Thunderbird\Extensions\Uninstall\1 (REG_SZ) = bad_addon_id@mozilla.org
Software\Policies\Mozilla\Thunderbird\Extensions\Locked\1 (REG_SZ) = addon_id@mozilla.org
<dict>
<key>Extensions</key>
<dict>
<key>Install</key>
<array>
<string>https://addons.thunderbird.net/thunderbird/downloads/somefile.xpi</string>
<string>//path/to/xpi</string>
</array>
<key>Uninstall</key>
<array>
<string>bad_addon_id@mozilla.org</string>
</array>
<key>Locked</key>
<array>
<string>addon_id@mozilla.org</string>
</array>
</dict>
</dict>
{
"policies": {
"Extensions": {
"Install": ["https://addons.thunderbird.net/thunderbird/downloads/somefile.xpi", "//path/to/xpi"],
"Uninstall": ["bad_addon_id@mozilla.org"],
"Locked": ["addon_id@mozilla.org"]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
ExtensionsExtensions_InstallExtensions_UninstallExtensions_Locked |
68.0 |
Manage all aspects of extension installation.
Manage all aspects of extensions. This policy is based heavily on the Chrome policy of the same name.
This policy maps an extension ID to its configuration. With an extension ID, the configuration will be applied to the specified extension only. A default configuration can be set for the special ID “*”, which will apply to all extensions that don’t have a custom configuration set in this policy.
To obtain an extension ID, install the extension and go to about:support. You will see the ID in the Extensions section.
Installing a theme makes it the default.
CCK2 Equivalent: N/A
Preferences Affected: N/A
* (object)
The default settings for all extensions which have no entry of their own. Its
installation_modeandallowed_typesalso apply to an extension whose own entry has noinstallation_mode.
installation_mode(string:allowedorblocked) Whether extensions can be installed.\allowed: Users can install extensions.\blocked: No extension can be installed. An extension is only exempt if its own entry in this policy setsinstallation_modetoallowed,force_installedornormal_installed.allowed_types(list of strings:extension,dictionary,localeortheme) The types of add-ons which can be installed.\extension: Ordinary extensions.\dictionary: Spell-checking dictionaries.\locale: Language packs that translate the Thunderbird interface.\theme: Themes that change the appearance of Thunderbird.blocked_install_message(string) A message shown to the user when the installation of an extension is blocked.install_sources(list of strings) The sources from which extensions can be installed, as URL match patterns (e.g.https://addons.thunderbird.net/*).restricted_domains(list of strings) The domains on which content scripts of extensions can’t run.
[name] (object)
The settings of one extension, by its ID. They take precedence over the default settings.
installation_mode(string:allowed,blocked,force_installedornormal_installed) How the extension is installed.\allowed: The extension may be installed, even when extensions are blocked by default.\blocked: The extension cannot be installed, and is uninstalled if already present.\force_installed: The extension is installed automatically and the user can neither disable nor remove it.\normal_installed: The extension is installed automatically. The user can disable it but cannot remove it.install_url(string) The URL from which the extension is installed withforce_installedandnormal_installed, e.g. from addons.thunderbird.net or afile:///URL. It is required for these modes. Without it, this extension and the ones which follow it in this policy are neither installed nor removed.blocked_install_message(string) A message shown to the user when the installation of this extension is blocked.updates_disabled(boolean) If true, the extension is not updated automatically.private_browsing(boolean) If true, the extension is allowed to run in private browsing. If false, it is not.
Software\Policies\Mozilla\Thunderbird\ExtensionSettings (REG_MULTI_SZ) =
{
"*": {
"blocked_install_message": "Custom error message.",
"install_sources": ["about:addons", "https://addons.thunderbird.net/"],
"installation_mode": "blocked",
"allowed_types": ["extension"]
},
"uBlock0@raymondhill.net": {
"installation_mode": "force_installed",
"install_url": "https://addons.thunderbird.net/thunderbird/downloads/latest/ublock-origin/latest.xpi"
},
"https-everywhere@eff.org": {
"installation_mode": "allowed"
}
}
<dict>
<key>ExtensionSettings</key>
<dict>
<key>*</key>
<dict>
<key>blocked_install_message</key>
<string>Custom error message.</string>
<key>install_sources</key>
<array>
<string>about:addons</string>
<string>https://addons.thunderbird.net/</string>
</array>
<key>installation_mode</key>
<string>blocked</string>
<key>allowed_types</key>
<array>
<string>extension</string>
</array>
</dict>
<key>uBlock0@raymondhill.net</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>install_url</key>
<string>https://addons.thunderbird.net/thunderbird/downloads/latest/ublock-origin/latest.xpi</string>
</dict>
<key>https-everywhere@eff.org</key>
<dict>
<key>installation_mode</key>
<string>allowed</string>
</dict>
</dict>
</dict>
{
"policies": {
"ExtensionSettings": {
"*": {
"blocked_install_message": "Custom error message.",
"install_sources": ["about:addons", "https://addons.thunderbird.net/"],
"installation_mode": "blocked",
"allowed_types": ["extension"]
},
"uBlock0@raymondhill.net": {
"installation_mode": "force_installed",
"install_url": "https://addons.thunderbird.net/thunderbird/downloads/latest/ublock-origin/latest.xpi"
},
"https-everywhere@eff.org": {
"installation_mode": "allowed"
}
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
ExtensionSettingsExtensionSettings_[name]ExtensionSettings_[name]_blocked_install_message |
68.0 | |
ExtensionSettings_*ExtensionSettings_*_installation_modeExtensionSettings_*_allowed_typesExtensionSettings_*_blocked_install_messageExtensionSettings_*_install_sourcesExtensionSettings_*_restricted_domainsExtensionSettings_[name]_installation_modeExtensionSettings_[name]_install_url |
89.0 | |
ExtensionSettings_[name]_updates_disabled |
92.0 | |
ExtensionSettings_[name]_private_browsing |
136.0 |
Enable or disable automatic extension updates.
Turn off automatic updates of extensions. If this policy is disabled, extensions are no longer updated automatically, and the user can’t turn it on. If it is enabled or not configured, the user’s setting applies.
CCK2 Equivalent: N/A
Preferences Affected: extensions.update.enabled
ExtensionUpdate (boolean)
Software\Policies\Mozilla\Thunderbird\ExtensionUpdate (REG_DWORD) = 0x1
<dict>
<key>ExtensionUpdate</key>
<true/>
</dict>
{
"policies": {
"ExtensionUpdate": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
ExtensionUpdate |
68.0 |
Configure default application handlers.
This policy is based on the internal format of handlers.json.
You can configure handlers based on a mime type (mimeTypes), a file’s extension (extensions), or a protocol (schemes).
Within each handler type, you specify the given mimeType/extension/scheme as a key.
CCK2 Equivalent: N/A
Preferences Affected: N/A
(mimeTypes|extensions|schemes) (object)
How content is matched: by its MIME type (
mimeTypes), by the extension of its file name (extensions), or by its protocol (schemes).
[name](object) One MIME type, file extension or protocol, with how its content is handled.
action(string:saveToDisk,useHelperApporuseSystemDefault)What happens with the content.\
saveToDisk: Download the file instead of opening it.\useHelperApp: Open the content with an application listed inhandlers.\useSystemDefault: Open the content with the application the operating system associates with that type.ask(boolean)If true, the user is asked what to do with the content. If false, the action is taken without asking.
handlers(list of objects)The applications which can handle the content. The first one is the default. Each entry has either a
pathor auriTemplate.
name(string)The name of the application.
path(string)The path of the executable of the application.
uriTemplate(string)The URL of a web application. It has to use https and contain %s, which is replaced by the URL of the content.
Software\Policies\Mozilla\Thunderbird\Handlers (REG_MULTI_SZ) =
{
"mimeTypes": {
"application/msword": {
"action": "useSystemDefault",
"ask": false
}
},
"schemes": {
"mailto": {
"action": "useHelperApp",
"ask": true,
"handlers": [
{
"name": "Gmail",
"uriTemplate": "https://mail.google.com/mail/?extsrc=mailto&url=%s"
}
]
}
},
"extensions": {
"pdf": {
"action": "useHelperApp",
"ask": true,
"handlers": [
{
"name": "Adobe Acrobat",
"path": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe"
}
]
}
}
}
<dict>
<key>Handlers</key>
<dict>
<key>mimeTypes</key>
<dict>
<key>application/msword</key>
<dict>
<key>action</key>
<string>useSystemDefault</string>
<key>ask</key>
<false/>
</dict>
</dict>
<key>schemes</key>
<dict>
<key>mailto</key>
<dict>
<key>action</key>
<string>useHelperApp</string>
<key>ask</key>
<true/>
<key>handlers</key>
<array>
<dict>
<key>name</key>
<string>Gmail</string>
<key>uriTemplate</key>
<string>https://mail.google.com/mail/?extsrc=mailto&url=%s</string>
</dict>
</array>
</dict>
</dict>
<key>extensions</key>
<dict>
<key>pdf</key>
<dict>
<key>action</key>
<string>useHelperApp</string>
<key>ask</key>
<true/>
<key>handlers</key>
<array>
<dict>
<key>name</key>
<string>Adobe Acrobat</string>
<key>path</key>
<string>/usr/bin/acroread</string>
</dict>
</array>
</dict>
</dict>
</dict>
</dict>
{
"policies": {
"Handlers": {
"mimeTypes": {
"application/msword": {
"action": "useSystemDefault",
"ask": false
}
},
"schemes": {
"mailto": {
"action": "useHelperApp",
"ask": true,
"handlers": [
{
"name": "Gmail",
"uriTemplate": "https://mail.google.com/mail/?extsrc=mailto&url=%s"
}
]
}
},
"extensions": {
"pdf": {
"action": "useHelperApp",
"ask": true,
"handlers": [
{
"name": "Adobe Acrobat",
"path": "/usr/bin/acroread"
}
]
}
}
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
HandlersHandlers_mimeTypesHandlers_mimeTypes_[name]Handlers_mimeTypes_[name]_actionHandlers_mimeTypes_[name]_askHandlers_mimeTypes_[name]_handlersHandlers_extensionsHandlers_extensions_[name]Handlers_extensions_[name]_actionHandlers_extensions_[name]_askHandlers_extensions_[name]_handlersHandlers_schemesHandlers_schemes_[name]Handlers_schemes_[name]_actionHandlers_schemes_[name]_askHandlers_schemes_[name]_handlers |
92.0 |
If false, turn off hardware acceleration.
Control hardware acceleration.
CCK2 Equivalent: N/A
Preferences Affected: layers.acceleration.disabled
HardwareAcceleration (boolean)
Software\Policies\Mozilla\Thunderbird\HardwareAcceleration (REG_DWORD) = 0x1
<dict>
<key>HardwareAcceleration</key>
<true/>
</dict>
{
"policies": {
"HardwareAcceleration": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
HardwareAcceleration |
78.0 |
Enable or disable notification types.
Configure TOAST, browser, and tab notifications within the context of the application.
CCK2 Equivalent: N/A
Preferences Affected: mail.inappnotifications.donation_enabled, mail.inappnotifications.blog_enabled, mail.inappnotifications.message_enabled, mail.inappnotifications.enabled
DonationEnabled Donation notifications (boolean)
Enables or disables notifications asking for a donation.
SurveyEnabled Survey notifications (boolean)
Enables or disables notifications inviting to a survey.
MessageEnabled Message notifications (boolean)
Enables or disables notifications with messages.
Disabled Disable all in-app notifications (boolean)
If set to true, no in-app notifications are shown.
Software\Policies\Mozilla\Thunderbird\InAppNotification\DonationEnabled (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\InAppNotification\SurveyEnabled (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\InAppNotification\MessageEnabled (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\InAppNotification\Disabled (REG_DWORD) = 0x1
<dict>
<key>InAppNotification</key>
<dict>
<key>DonationEnabled</key>
<true/>
<key>SurveyEnabled</key>
<true/>
<key>MessageEnabled</key>
<true/>
<key>Disabled</key>
<true/>
</dict>
</dict>
{
"policies": {
"InAppNotification": {
"DonationEnabled": true,
"SurveyEnabled": true,
"MessageEnabled": true,
"Disabled": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
InAppNotificationInAppNotification_DonationEnabledInAppNotification_SurveyEnabledInAppNotification_MessageEnabledInAppNotification_Disabled |
139.0 |
Allow certain websites to install add-ons.
Configure the default extension install policy and the origins from which extensions can be installed. This policy does not override turning off all extension installs.
CCK2 Equivalent: permissions.install
Preferences Affected: xpinstall.enabled
Allow Sites allowed to install extensions (list of origins)
A list of origins where extension installs are allowed.
Default Allow extension installs by default (boolean)
Determines whether or not extension installs are allowed by default.
Software\Policies\Mozilla\Thunderbird\InstallAddonsPermission\Allow\1 (REG_SZ) = http://example.org/
Software\Policies\Mozilla\Thunderbird\InstallAddonsPermission\Allow\2 (REG_SZ) = http://example.edu/
Software\Policies\Mozilla\Thunderbird\InstallAddonsPermission\Default (REG_DWORD) = 0x1
<dict>
<key>InstallAddonsPermission</key>
<dict>
<key>Allow</key>
<array>
<string>http://example.org/</string>
<string>http://example.edu/</string>
</array>
<key>Default</key>
<true/>
</dict>
</dict>
{
"policies": {
"InstallAddonsPermission": {
"Allow": ["http://example.org/", "http://example.edu/"],
"Default": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
InstallAddonsPermissionInstallAddonsPermission_AllowInstallAddonsPermission_Default |
68.0 |
Allow manual updates only and do not notify the user about updates.
Switch to manual updates only.
If this policy is enabled:
This policy is primarily intended for advanced end users, not for enterprises, but it is available via GPO.
CCK2 Equivalent: N/A
Preferences Affected: N/A
ManualAppUpdateOnly (boolean)
Software\Policies\Mozilla\Thunderbird\ManualAppUpdateOnly (REG_DWORD) = 0x1
<dict>
<key>ManualAppUpdateOnly</key>
<true/>
</dict>
{
"policies": {
"ManualAppUpdateOnly": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
ManualAppUpdateOnly |
92.0 |
Enable or disable network prediction (DNS prefetching).
With network prediction, Thunderbird resolves the host names of links in advance, so they load faster.
If this policy is enabled, network prediction is turned on. If it is disabled, network prediction is turned off. In both cases, the user can’t change the setting. If this policy is not configured, the user can change the setting.
CCK2 Equivalent: N/A
Preferences Affected: network.dns.disablePrefetch, network.dns.disablePrefetchFromHTTPS
NetworkPrediction (boolean)
Software\Policies\Mozilla\Thunderbird\NetworkPrediction (REG_DWORD) = 0x1
<dict>
<key>NetworkPrediction</key>
<true/>
</dict>
{
"policies": {
"NetworkPrediction": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
NetworkPrediction |
92.0 |
Enforce the setting to allow Thunderbird to offer to remember saved logins and passwords. Both true and false values are accepted.
Control whether or not Thunderbird offers to save passwords.
CCK2 Equivalent: dontRememberPasswords
Preferences Affected: signon.rememberSignons
OfferToSaveLogins (boolean)
Software\Policies\Mozilla\Thunderbird\OfferToSaveLogins (REG_DWORD) = 0x1
<dict>
<key>OfferToSaveLogins</key>
<true/>
</dict>
{
"policies": {
"OfferToSaveLogins": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
OfferToSaveLogins |
92.0 |
Set the default value for allowing Thunderbird to offer to remember saved logins and passwords. Both true and false values are accepted.
Sets the default value of signon.rememberSignons without locking it.
CCK2 Equivalent: dontRememberPasswords
Preferences Affected: signon.rememberSignons
OfferToSaveLoginsDefault (boolean)
Software\Policies\Mozilla\Thunderbird\OfferToSaveLoginsDefault (REG_DWORD) = 0x1
<dict>
<key>OfferToSaveLoginsDefault</key>
<true/>
</dict>
{
"policies": {
"OfferToSaveLoginsDefault": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
OfferToSaveLoginsDefault |
92.0 |
Enable saving passwords to the password manager.
Remove access to the password manager via the settings, and block about:logins.
CCK2 Equivalent: N/A
Preferences Affected: pref.privacy.disable_button.view_passwords, signon.rememberSignons
PasswordManagerEnabled (boolean)
Software\Policies\Mozilla\Thunderbird\PasswordManagerEnabled (REG_DWORD) = 0x1
<dict>
<key>PasswordManagerEnabled</key>
<true/>
</dict>
{
"policies": {
"PasswordManagerEnabled": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
PasswordManagerEnabled |
78.0 |
Disable or configure PDF.js, the built-in PDF viewer in Thunderbird.
Disable or configure PDF.js, the built-in PDF viewer.
Note: DisableBuiltinPDFViewer has not been deprecated. You can either continue to use it, or switch to using PDFjs->Enabled to disable the built-in PDF viewer.
CCK2 Equivalent: N/A
Preferences Affected: pdfjs.disabled, pdfjs.enablePermissions
Enabled Enable the built-in PDF viewer (boolean)
If set to false, the built-in PDF viewer is disabled.
EnablePermissions Honor the permissions of PDF documents (boolean)
Meant to make the built-in PDF viewer honor document permissions like preventing the copying of text. In this version, the value of this setting is ignored. If it is set, document permissions are honored unless
Enabledis set to true.
Software\Policies\Mozilla\Thunderbird\PDFjs\Enabled (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\PDFjs\EnablePermissions (REG_DWORD) = 0x1
<dict>
<key>PDFjs</key>
<dict>
<key>Enabled</key>
<true/>
<key>EnablePermissions</key>
<true/>
</dict>
</dict>
{
"policies": {
"PDFjs": {
"Enabled": true,
"EnablePermissions": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
PDFjsPDFjs_EnabledPDFjs_EnablePermissions |
92.0 |
Set and lock the value for a subset of preferences.
Set and lock preferences.
You can also set default preferences and user preferences, and clear the user value of a preference.
Using the preference as the key, set the Value to the corresponding preference value.
Default preferences can be modified by the user.
If a value is locked, it is also set as the default.
User preferences persist across invocations of Thunderbird. It is the equivalent of a user setting the preference. They are most useful when a preference is needed very early in startup so it can’t be set as default by policy.
User preferences persist even if the policy is removed, so if you need to remove them, set their Status to clear.
IMPORTANT: Make sure you’re only setting a particular preference using this mechanism and not some other way.
Only these preferences can be set:
accessibility.*app.update.* (except app.update.channel, app.update.lastUpdateTime and app.update.migrated)browser.*calendar.*chat.*datareporting.policy.*dom.*extensions.*general.autoScroll*general.smoothScroll*geo.*gfx.*intl.*layers.*layout.*mail.*mailnews.*media.*network.*pdfjs.*places.*print.*security.default_personal_certsecurity.insecure_connection_text.enabledsecurity.insecure_connection_text.pbmode.enabledsecurity.insecure_field_warning.contextual.enabledsecurity.mixed_content.block_active_contentsecurity.osclientcerts.autoloadsecurity.ssl.errorReporting.enabledsecurity.tls.hello_downgrade_checksecurity.tls.version.enable-deprecatedsecurity.warn_submit_secure_to_insecuresignon.*spellchecker.*ui.*widget.*CCK2 Equivalent: preferences
Preferences Affected: Many
[name] (number, boolean, string or object)
One preference, by its name, as an object with
ValueandStatus. A value alone (e.g.true) sets and locks the default value of the preference.
Value(number, boolean or string) The value of the preference.Status(string:default,locked,userorclear) How the value is set.\default: Change the preference’s default value. A value the user has already set still wins.\locked: Change the preference’s default value and prevent the user from changing it.\user: Set the preference as though the user had set it, so the value is written to the profile.\clear: Remove any value the user has set, reverting the preference to its default.
Software\Policies\Mozilla\Thunderbird\Preferences (REG_MULTI_SZ) =
{
"accessibility.force_disabled": {
"Value": 1,
"Status": "default"
},
"browser.cache.disk.parent_directory": {
"Value": "SOME_NATIVE_PATH",
"Status": "user"
}
}
<dict>
<key>Preferences</key>
<dict>
<key>accessibility.force_disabled</key>
<dict>
<key>Value</key>
<integer>1</integer>
<key>Status</key>
<string>default</string>
</dict>
<key>browser.cache.disk.parent_directory</key>
<dict>
<key>Value</key>
<string>SOME_NATIVE_PATH</string>
<key>Status</key>
<string>user</string>
</dict>
</dict>
</dict>
{
"policies": {
"Preferences": {
"accessibility.force_disabled": {
"Value": 1,
"Status": "default"
},
"browser.cache.disk.parent_directory": {
"Value": "SOME_NATIVE_PATH",
"Status": "user"
}
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
Preferences |
68.0 | |
Preferences_[name]Preferences_[name]_ValuePreferences_[name]_Status |
92.0 | |
Preferences_accessibility.force_disabledPreferences_browser.cache.disk.enablePreferences_browser.safebrowsing.phishing.enabledPreferences_browser.safebrowsing.malware.enabledPreferences_browser.search.updatePreferences_datareporting.policy.dataSubmissionPolicyBypassNotificationPreferences_dom.allow_scripts_to_close_windowsPreferences_dom.disable_window_flipPreferences_dom.disable_window_move_resizePreferences_dom.event.contextmenu.enabledPreferences_dom.keyboardevent.keypress.hack.dispatch_non_printable_keys.addlPreferences_dom.keyboardevent.keypress.hack.use_legacy_keycode_and_charcode.addlPreferences_extensions.blocklist.enabledPreferences_geo.enabledPreferences_intl.accept_languagesPreferences_network.dns.disableIPv6Preferences_places.history.enabledPreferences_print.save_print_settingsPreferences_security.default_personal_certPreferences_security.mixed_content.block_active_contentPreferences_security.osclientcerts.autoloadPreferences_security.ssl.errorReporting.enabledPreferences_security.tls.hello_downgrade_checkPreferences_widget.content.gtk-theme-override |
78.0 | 89.0 |
Preferences_browser.cache.disk.parent_directoryPreferences_network.IDN_show_punycode |
68.0 | 89.0 |
Preferences_browser.fixup.dns_first_for_single_wordsPreferences_browser.urlbar.suggest.openpagePreferences_browser.urlbar.suggest.historyPreferences_browser.urlbar.suggest.bookmark |
68.0 | 77.0 |
Require or prevent using a Primary Password.
Require or prevent using a primary (formerly master) password.
If this value is true, a primary password is required. If this value is false, it works the same as if DisableMasterPasswordCreation was true and removes the primary password functionality.
If both DisableMasterPasswordCreation and PrimaryPassword are used, DisableMasterPasswordCreation takes precedence.
CCK2 Equivalent: noMasterPassword
Preferences Affected: N/A
PrimaryPassword (boolean)
Software\Policies\Mozilla\Thunderbird\PrimaryPassword (REG_DWORD) = 0x1
<dict>
<key>PrimaryPassword</key>
<true/>
</dict>
{
"policies": {
"PrimaryPassword": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
PrimaryPassword |
92.0 |
Ask where to save files when downloading.
Ask where to save each file before downloading.
CCK2 Equivalent: N/A
Preferences Affected: browser.download.useDownloadDir
PromptForDownloadLocation (boolean)
Software\Policies\Mozilla\Thunderbird\PromptForDownloadLocation (REG_DWORD) = 0x1
<dict>
<key>PromptForDownloadLocation</key>
<true/>
</dict>
{
"policies": {
"PromptForDownloadLocation": true
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
PromptForDownloadLocation |
78.0 |
Configure proxy settings.
These settings correspond to the connection settings in Thunderbird preferences. To specify ports, append them to the hostnames with a colon (:).
Unless you lock this policy, changes the user already has in place will take effect.
CCK2 Equivalent: networkProxy*
Preferences Affected: network.proxy.type, network.proxy.autoconfig_url, network.proxy.socks_remote_dns, signon.autologin.proxy, network.proxy.socks_version, network.proxy.no_proxies_on, network.proxy.share_proxy_settings, network.proxy.http, network.proxy.http_port, network.proxy.ssl, network.proxy.ssl_port, network.proxy.socks, network.proxy.socks_port
Mode Proxy method (string: none, system, manual, autoDetect or autoConfig)
The proxy method being used.\
none: Connect directly, without a proxy.\system: Use the proxy configured in the operating system.\manual: Use the proxy hosts given inHTTPProxy,SSLProxy, andSOCKSProxy.\autoDetect: Discover the proxy settings for this network automatically.\autoConfig: Use the proxy auto-configuration file atAutoConfigURL.
Locked Lock the proxy settings (boolean)
Prevents the user from changing the proxy settings.
AutoConfigURL Automatic proxy configuration URL (string, URL)
The URL of a proxy configuration file (only used if the proxy method is
autoConfig).
FTPProxy FTP proxy (string) Deprecated.
This setting has no effect, because support for FTP proxies was removed.
HTTPProxy HTTP proxy (string)
The HTTP proxy server.
SSLProxy SSL proxy (string)
The SSL proxy server.
SOCKSProxy SOCKS proxy (string)
The SOCKS proxy server.
SOCKSVersion SOCKS version (number: 4 or 5)
The SOCKS version.\
4: Use version 4 of the SOCKS protocol to reachSOCKSProxy.\5: Use version 5 of the SOCKS protocol to reachSOCKSProxy.
UseHTTPProxyForAllProtocols Use the HTTP proxy for all protocols (boolean)
Whether the HTTP proxy is also used for all other protocols.
Passthrough No proxy for (string)
Hostnames or IP addresses which are not proxied, separated by commas. Use
<local>to bypass proxying for all hostnames which do not contain periods.
UseProxyForDNS Proxy DNS when using SOCKS v5 (boolean)
Use the proxy for DNS requests when using SOCKS v5.
AutoLogin Don’t prompt for authentication if the password is saved (boolean)
Don’t prompt for authentication if the password is saved. If the proxy requires authentication and its password is saved, Thunderbird logs in without asking. If that login fails, the user is asked again.
Software\Policies\Mozilla\Thunderbird\Proxy\Mode (REG_SZ) = none
Software\Policies\Mozilla\Thunderbird\Proxy\Locked (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Proxy\AutoConfigURL (REG_SZ) = https://proxy.example.com/proxy.pac
Software\Policies\Mozilla\Thunderbird\Proxy\HTTPProxy (REG_SZ) = hostname
Software\Policies\Mozilla\Thunderbird\Proxy\SSLProxy (REG_SZ) = hostname
Software\Policies\Mozilla\Thunderbird\Proxy\SOCKSProxy (REG_SZ) = hostname
Software\Policies\Mozilla\Thunderbird\Proxy\SOCKSVersion (REG_DWORD) = 0x4
Software\Policies\Mozilla\Thunderbird\Proxy\UseHTTPProxyForAllProtocols (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Proxy\Passthrough (REG_SZ) = <local>, .example.com, 192.168.1.0/24
Software\Policies\Mozilla\Thunderbird\Proxy\UseProxyForDNS (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\Proxy\AutoLogin (REG_DWORD) = 0x1
<dict>
<key>Proxy</key>
<dict>
<key>Mode</key>
<string>none</string>
<key>Locked</key>
<true/>
<key>AutoConfigURL</key>
<string>https://proxy.example.com/proxy.pac</string>
<key>HTTPProxy</key>
<string>hostname</string>
<key>SSLProxy</key>
<string>hostname</string>
<key>SOCKSProxy</key>
<string>hostname</string>
<key>SOCKSVersion</key>
<integer>4</integer>
<key>UseHTTPProxyForAllProtocols</key>
<true/>
<key>Passthrough</key>
<string><local>, .example.com, 192.168.1.0/24</string>
<key>UseProxyForDNS</key>
<true/>
<key>AutoLogin</key>
<true/>
</dict>
</dict>
{
"policies": {
"Proxy": {
"Mode": "none",
"Locked": true,
"AutoConfigURL": "https://proxy.example.com/proxy.pac",
"HTTPProxy": "hostname",
"SSLProxy": "hostname",
"SOCKSProxy": "hostname",
"SOCKSVersion": 4,
"UseHTTPProxyForAllProtocols": true,
"Passthrough": "<local>, .example.com, 192.168.1.0/24",
"UseProxyForDNS": true,
"AutoLogin": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
ProxyProxy_ModeProxy_LockedProxy_AutoConfigURLProxy_FTPProxyProxy_HTTPProxyProxy_SSLProxyProxy_SOCKSProxyProxy_SOCKSVersionProxy_UseHTTPProxyForAllProtocolsProxy_PassthroughProxy_UseProxyForDNSProxy_AutoLogin |
68.0 |
Set the list of requested locales for the application in order of preference.
The corresponding language packs become active.
Note: This policy can also be a string, so that you can specify an empty value.
CCK2 Equivalent: N/A
Preferences Affected: N/A
RequestedLocales (string or array)
Software\Policies\Mozilla\Thunderbird\RequestedLocales (REG_SZ) = de,en-US
<dict>
<key>RequestedLocales</key>
<string>de,en-US</string>
</dict>
{
"policies": {
"RequestedLocales": "de,en-US"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
RequestedLocales |
68.0 |
Configure search engine settings.
CCK2 Equivalent: N/A
Preferences Affected: N/A
SearchEngines (object)
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Name (REG_SZ) = Example1
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\IconURL (REG_SZ) = https://www.example.org/favicon.ico
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Alias (REG_SZ) = example
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Description (REG_SZ) = Description
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Encoding (REG_SZ) = UTF-8
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Method (REG_SZ) = GET
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\URLTemplate (REG_SZ) = https://www.example.org/q={searchTerms}
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\PostData (REG_SZ) = name=value&q={searchTerms}
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\SuggestURLTemplate (REG_SZ) = https://www.example.org/suggestions/q={searchTerms}
Software\Policies\Mozilla\Thunderbird\SearchEngines\Default (REG_SZ) = NAME_OF_SEARCH_ENGINE
Software\Policies\Mozilla\Thunderbird\SearchEngines\DefaultPrivate (REG_SZ) = NAME_OF_SEARCH_ENGINE
Software\Policies\Mozilla\Thunderbird\SearchEngines\PreventInstalls (REG_DWORD) = 0x1
Software\Policies\Mozilla\Thunderbird\SearchEngines\Remove\1 (REG_SZ) = NAME_OF_SEARCH_ENGINE
<dict>
<key>SearchEngines</key>
<dict>
<key>Add</key>
<array>
<dict>
<key>Name</key>
<string>Example1</string>
<key>IconURL</key>
<string>https://www.example.org/favicon.ico</string>
<key>Alias</key>
<string>example</string>
<key>Description</key>
<string>Description</string>
<key>Encoding</key>
<string>UTF-8</string>
<key>Method</key>
<string>GET</string>
<key>URLTemplate</key>
<string>https://www.example.org/q={searchTerms}</string>
<key>PostData</key>
<string>name=value&q={searchTerms}</string>
<key>SuggestURLTemplate</key>
<string>https://www.example.org/suggestions/q={searchTerms}</string>
</dict>
</array>
<key>Default</key>
<string>NAME_OF_SEARCH_ENGINE</string>
<key>DefaultPrivate</key>
<string>NAME_OF_SEARCH_ENGINE</string>
<key>PreventInstalls</key>
<true/>
<key>Remove</key>
<array>
<string>NAME_OF_SEARCH_ENGINE</string>
</array>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"Add": [
{
"Name": "Example1",
"IconURL": "https://www.example.org/favicon.ico",
"Alias": "example",
"Description": "Description",
"Encoding": "UTF-8",
"Method": "GET",
"URLTemplate": "https://www.example.org/q={searchTerms}",
"PostData": "name=value&q={searchTerms}",
"SuggestURLTemplate": "https://www.example.org/suggestions/q={searchTerms}"
}
],
"Default": "NAME_OF_SEARCH_ENGINE",
"DefaultPrivate": "NAME_OF_SEARCH_ENGINE",
"PreventInstalls": true,
"Remove": ["NAME_OF_SEARCH_ENGINE"]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEnginesSearchEngines_AddSearchEngines_DefaultSearchEngines_DefaultPrivateSearchEngines_PreventInstallsSearchEngines_Remove |
108.0 |
Add new search engines.
Although there are only five engines available in the ADMX template, there is no limit. To add more in the ADMX template, you can duplicate the XML.
CCK2 Equivalent: searchplugins
Preferences Affected: N/A
Name Name (string)
The name of the search engine (required).
IconURL Icon URL (string, URL)
A URL for the icon to use.
Alias Alias (string)
A keyword to use for the engine.
Description Description (string)
A description of the search engine.
Encoding Encoding (string)
The query charset for the engine. It defaults to UTF-8.
Method Method (string: GET or POST)
The HTTP method.\
GET: Send the search terms as part of the URL.\POST: Send the search terms in the request body, usingPostData.
URLTemplate Search URL (string)
The search URL with {searchTerms} to substitute for the search term (required).
PostData POST data (string)
The POST data as name value pairs separated by &.
SuggestURLTemplate Suggestions URL (string)
A search suggestions URL with {searchTerms} to substitute for the search term.
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Name (REG_SZ) = Example1
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\IconURL (REG_SZ) = https://www.example.org/favicon.ico
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Alias (REG_SZ) = example
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Description (REG_SZ) = Description
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Encoding (REG_SZ) = UTF-8
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\Method (REG_SZ) = GET
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\URLTemplate (REG_SZ) = https://www.example.org/q={searchTerms}
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\PostData (REG_SZ) = name=value&q={searchTerms}
Software\Policies\Mozilla\Thunderbird\SearchEngines\Add\1\SuggestURLTemplate (REG_SZ) = https://www.example.org/suggestions/q={searchTerms}
<dict>
<key>SearchEngines</key>
<dict>
<key>Add</key>
<array>
<dict>
<key>Name</key>
<string>Example1</string>
<key>IconURL</key>
<string>https://www.example.org/favicon.ico</string>
<key>Alias</key>
<string>example</string>
<key>Description</key>
<string>Description</string>
<key>Encoding</key>
<string>UTF-8</string>
<key>Method</key>
<string>GET</string>
<key>URLTemplate</key>
<string>https://www.example.org/q={searchTerms}</string>
<key>PostData</key>
<string>name=value&q={searchTerms}</string>
<key>SuggestURLTemplate</key>
<string>https://www.example.org/suggestions/q={searchTerms}</string>
</dict>
</array>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"Add": [
{
"Name": "Example1",
"IconURL": "https://www.example.org/favicon.ico",
"Alias": "example",
"Description": "Description",
"Encoding": "UTF-8",
"Method": "GET",
"URLTemplate": "https://www.example.org/q={searchTerms}",
"PostData": "name=value&q={searchTerms}",
"SuggestURLTemplate": "https://www.example.org/suggestions/q={searchTerms}"
}
]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEngines_Add |
108.0 |
Set the default search engine, which is used to search the web from Thunderbird.
The search engine is given by its name, either a built-in search engine or one added with Add. It is set when the policy is applied for the first time and whenever the name changes, so the user can choose another default search engine in the meantime.
CCK2 Equivalent: defaultSearchEngine
Preferences Affected: N/A
Default (string)
Software\Policies\Mozilla\Thunderbird\SearchEngines\Default (REG_SZ) = NAME_OF_SEARCH_ENGINE
<dict>
<key>SearchEngines</key>
<dict>
<key>Default</key>
<string>NAME_OF_SEARCH_ENGINE</string>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"Default": "NAME_OF_SEARCH_ENGINE"
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEngines_Default |
108.0 |
Set the default search engine for private browsing.
This setting has no effect in Thunderbird.
CCK2 Equivalent: N/A
Preferences Affected: N/A
DefaultPrivate (string)
Software\Policies\Mozilla\Thunderbird\SearchEngines\DefaultPrivate (REG_SZ) = NAME_OF_SEARCH_ENGINE
<dict>
<key>SearchEngines</key>
<dict>
<key>DefaultPrivate</key>
<string>NAME_OF_SEARCH_ENGINE</string>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"DefaultPrivate": "NAME_OF_SEARCH_ENGINE"
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEngines_DefaultPrivate |
108.0 |
Prevent installing search engines from webpages.
This setting has no effect in Thunderbird.
CCK2 Equivalent: disableSearchEngineInstall
Preferences Affected: N/A
PreventInstalls (boolean)
Software\Policies\Mozilla\Thunderbird\SearchEngines\PreventInstalls (REG_DWORD) = 0x1
<dict>
<key>SearchEngines</key>
<dict>
<key>PreventInstalls</key>
<true/>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"PreventInstalls": true
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEngines_PreventInstalls |
108.0 |
Hide built-in search engines.
The search engines are given by their names. They are hidden when the policy is applied for the first time and whenever the list changes.
CCK2 Equivalent: removeDefaultSearchEngines (removed all built-in engines)
Preferences Affected: N/A
Remove (list of strings)
Software\Policies\Mozilla\Thunderbird\SearchEngines\Remove\1 (REG_SZ) = NAME_OF_SEARCH_ENGINE
<dict>
<key>SearchEngines</key>
<dict>
<key>Remove</key>
<array>
<string>NAME_OF_SEARCH_ENGINE</string>
</array>
</dict>
</dict>
{
"policies": {
"SearchEngines": {
"Remove": ["NAME_OF_SEARCH_ENGINE"]
}
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SearchEngines_Remove |
108.0 |
Set the maximum SSL version.
Set and lock the maximum version of TLS. (Thunderbird defaults to a maximum of TLS 1.3.)
CCK2 Equivalent: N/A
Preferences Affected: security.tls.version.max
SSLVersionMax (string: tls1, tls1.1, tls1.2 or tls1.3)
Software\Policies\Mozilla\Thunderbird\SSLVersionMax (REG_SZ) = tls1
<dict>
<key>SSLVersionMax</key>
<string>tls1</string>
</dict>
{
"policies": {
"SSLVersionMax": "tls1"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SSLVersionMax |
68.0 |
Set the minimum SSL version.
Set and lock the minimum version of TLS. (Thunderbird defaults to a minimum of TLS 1.2.)
CCK2 Equivalent: N/A
Preferences Affected: security.tls.version.min
SSLVersionMin (string: tls1, tls1.1, tls1.2 or tls1.3)
Software\Policies\Mozilla\Thunderbird\SSLVersionMin (REG_SZ) = tls1
<dict>
<key>SSLVersionMin</key>
<string>tls1</string>
</dict>
{
"policies": {
"SSLVersionMin": "tls1"
}
}
| Policy/Property Name | Thunderbird | Removed after |
|---|---|---|
SSLVersionMin |
68.0 |