Endpoint configuration · GraphQL enum

AllowAppHVSIProviderSet enum

GPO policy: "Turn on Microsoft Defender Application Guard in Managed Mode" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Application Guard. Controls which Microsoft applications (Edge, Office, or both) use Application Guard hardware isolation for untrusted content. Registry: HKLM\SOFTWARE\Policies\Microsoft\AppHVSI:AllowAppHVSI_ProviderSet (REG_DWORD). Note: Microsoft Defender Application Guard is deprecated as of Windows 11 24H2. Reference: Policy CSP - ApplicationGuard (AllowWindowsDefenderApplicationGuard)

Values

Enum Value Description

DISABLED

Application Guard isolation disabled (registry value 0). Neither Edge nor Office uses Application Guard containerization.

ENABLED_EDGE

Application Guard enabled for Microsoft Edge only (registry value 1). Untrusted web content in Edge is isolated in the Application Guard container.

ENABLED_OFFICE

Application Guard enabled for Microsoft Office only (registry value 2). Untrusted Office documents are opened in the Application Guard container.

ENABLED_BOTH

Application Guard enabled for both Microsoft Edge and Office (registry value 3). Both Edge and Office use the Application Guard container for untrusted content.

Used by

Example

Example

"DISABLED"