GPO policy: "Configure Microsoft Defender Application Guard clipboard settings" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Application Guard. Controls clipboard data transfer between the Application Guard (HVSI) container and the host operating system. Registry: HKLM\SOFTWARE\Policies\Microsoft\AppHVSI:AppHVSIClipboardSettings (REG_DWORD). Note: Microsoft Defender Application Guard is deprecated as of Windows 11 24H2. Reference: Policy CSP - ApplicationGuard (ClipboardSettings)
Values
| Enum Value | Description |
|---|---|
|
|
Clipboard operations completely disabled (registry value 0). No copy/paste is allowed between the Application Guard container and the host. Most secure. |
|
|
Clipboard operations from host to Application Guard container only (registry value 1). Users can paste content from the host into the isolated container, but not the reverse. |
|
|
Clipboard operations from Application Guard container to host only (registry value 2). Users can paste content from the isolated container to the host. Microsoft notes this direction may pose a security risk and is not recommended. |
|
|
Clipboard operations allowed in both directions (registry value 3). Both host-to-container and container-to-host clipboard operations are enabled. Least secure. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"