GPO policy: "Turn on Microsoft Defender Application Guard in Managed Mode" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Application Guard. Controls which Microsoft applications (Edge, Office, or both) use Application Guard hardware isolation for untrusted content. Registry: HKLM\SOFTWARE\Policies\Microsoft\AppHVSI:AllowAppHVSI_ProviderSet (REG_DWORD). Note: Microsoft Defender Application Guard is deprecated as of Windows 11 24H2. Reference: Policy CSP - ApplicationGuard (AllowWindowsDefenderApplicationGuard)
Values
| Enum Value | Description |
|---|---|
|
|
Application Guard isolation disabled (registry value 0). Neither Edge nor Office uses Application Guard containerization. |
|
|
Application Guard enabled for Microsoft Edge only (registry value 1). Untrusted web content in Edge is isolated in the Application Guard container. |
|
|
Application Guard enabled for Microsoft Office only (registry value 2). Untrusted Office documents are opened in the Application Guard container. |
|
|
Application Guard enabled for both Microsoft Edge and Office (registry value 3). Both Edge and Office use the Application Guard container for untrusted content. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"