2
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Project Opal が作成する「Opal App Device Policy」の Microsoft Edge ポリシーを調べてみた

2
Last updated at Posted at 2026-08-16

はじめに

Project Opal を利用できるように構成すると、自動的に Opal App Device Policy という Intune 構成ポリシーが作成されて、Cloud PC に適用されるようになっています。

本記事では、この Opal App Device Policy がどのような設定になっているのかをリファレンスとしてまとめました。

これを見ることで、Project Opal が Cloud PC に対してどのような Microsoft Edge ポリシーを適用しているのかを確認できます。

また、後から独自に設定を変更した際に、「もともとの既定値はどうなっていたっけ?」と確認するためのリファレンスとしても活用できると思います。

Opal App Device Policy
image.png

以下のようなポリシーが自動作成されており、Opal App Device Group というグループに自動適用されるようになっています。

[NOTE]
本記事の内容は、2026年8月時点で Project Opal によって自動作成された Opal App Device Policy をもとに確認したものです。将来的なサービス更新により、ポリシーの内容や既定値が変更される可能性があります。

[注意点]
本記事は Intune 設定カタログに登録されている Microsoft Edge ポリシーを整理したものであり、Project Opal の推奨設定やベストプラクティスを示すものではありません。実際の運用環境への適用にあたっては、自組織のセキュリティ要件や運用方針に応じて評価してください。

Project Opal とは
AI が自律的に UI を操作する仕組みのことです。
以下の私の記事を参照してみてください。

AI が Windows を自律操作するって本当? Project Opal (Frontier) を試して分かった「実用的な使いどころ」
https://qiita.com/carol0226/items/a78a888ce0c4d2364232

調査して分かったこと

ポリシー全体を確認してみると、Project Opal は単純に Microsoft Edge を制限するだけではなく、Cloud PC を業務利用することを想定した構成になっているように見受けられます。

特に以下のような特徴がありました。

  • Bing SafeSearch が有効化されている
  • YouTube Restricted Mode が有効化されている
  • SmartScreen が有効化されている
  • Browser Sign-in が有効化されている
  • ファイルシステム API や通知権限などが一部制御されている
  • Microsoft Edge のパスワード マネージャーが無効化されている

特に個人的に興味深かったのは、Microsoft Edge のパスワード マネージャーが無効化されている点です。

一般的な Microsoft Edge の利用ではパスワード保存機能を利用するケースも多いと思いますが、Project Opal では既定で無効化されていました。

Microsoft から理由は公開されていませんが、Cloud PC の運用モデルや認証情報保護の観点を考慮した設定である可能性があります。

また、調査の過程では Deprecated や Obsolete とされているポリシーも複数含まれていることが分かりました。これらについては本記事の後半で補足しています。

Intune 設定カタログ Edge ポリシー リファレンス

概要サマリーと、詳細の2本立てです。

ポリシー概要サマリー

Opal App Device Policy には多数の Microsoft Edge ポリシーが含まれています。主な構成を整理すると以下のようになります。

分類 主な設定
コンテンツ制御 Bing SafeSearch: Strict、Google SafeSearch: Enabled、YouTube Restricted Mode: Strict
セキュリティ Microsoft Defender SmartScreen 有効、警告の回避を禁止
認証 Browser Sign-in 有効
データ同期 Microsoft Edge Sync 無効
認証情報管理 Password Manager 無効
プライバシー InPrivate モード無効、終了時に閲覧データを削除
拡張機能 拡張機能のインストールを全面禁止 (*)
サイト権限 Web サイト通知を禁止、File System API はユーザー承認制
検索 既定の検索プロバイダーは Bing
起動動作 ホームページおよび新しいタブは about:blank
印刷 ブラウザーからの印刷を無効化
キャスト Google Cast を無効化

全体として、Project Opal は Microsoft Edge の利用を許可しつつも、個人データの保存や拡張機能利用を抑制し、セキュリティと管理性を重視した構成になっていることが読み取れます。

ポリシーの詳細

表の見方

  • Intune 設定カタログ: Intune 管理センターで表示される設定名
  • Edge ポリシー名: 公開情報のポリシーリファレンスへのリンク
  • Opal 既定値: Opal App Device Policy で設定されている状態
  • オプション: Microsoft Edge ポリシーで選択可能な値
    • 太字: Opal App Device Policy で選択されている設定値
    • オプションが空欄のものは、Enabled / Disabled のみを持つブール値ポリシー

公開情報:Microsoft Edge リファレンス(Microsoft Edge - ポリシー)
https://learn.microsoft.com/ja-jp/deployedge/microsoft-edge-policies?wt.mc_id=MVP_407731

Microsoft Edge

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Ads setting for sites with intrusive ads
押し付けがましい広告を表示するサイトに対する広告の設定
AdsSettingForIntrusiveAdsSites Enabled Allow ads on all sites
"Block ads on sites with intrusive ads. (Default value)"
Allow default search provider context menu search access
既定の検索プロバイダーのコンテキスト メニュー検索アクセスを許可する
DefaultSearchProviderContextMenuAccessAllowed Enabled
Allow download restrictions
ダウンロード制限を許可する
DownloadRestrictions Disabled
Allow feature recommendations and browser assistance notifications from Microsoft Edge
Microsoft Edge からの機能のおすすめとブラウザー支援通知を許可する
ShowRecommendationsEnabled Disabled
Allow features to download assets from the Asset Delivery Service
機能が Asset Delivery Service から資産をダウンロードすることを許可する
EdgeAssetDeliveryServiceEnabled Enabled
Allow file selection dialogs
ファイル選択ダイアログを許可する
AllowFileSelectionDialogs Enabled
Allow importing of shortcuts
ショートカットのインポートを許可する
ImportShortcuts Disabled
Allow media autoplay for websites
Web サイトでのメディアの自動再生を許可する
AutoplayAllowed Disabled
Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe
サンドボックス化された iframe 内で外部プロトコルへのナビゲーションを Microsoft Edge がブロックすることを許可する
SandboxExternalProtocolBlocked Enabled
Allow or block audio capture
オーディオ キャプチャを許可またはブロックする
AudioCaptureAllowed Disabled
Allow or block video capture
ビデオ キャプチャを許可またはブロックする
VideoCaptureAllowed Disabled
Allow personalization of ads, search and news by sending browsing history to Microsoft
閲覧履歴を Microsoft に送信して広告、検索、ニュースの個人用設定を許可する
PersonalizationReportingEnabled Disabled
Allow Pin to taskbar wizard
タスク バーにピン留めするウィザードを許可する
PinningWizardAllowed Disabled
Allow suggestions from local providers
ローカル プロバイダーからの候補を許可する
LocalProvidersEnabled Disabled
Allow surf game
サーフ ゲームを許可する
AllowSurfGame Disabled
Allow user feedback
ユーザー フィードバックを許可する
UserFeedbackAllowed Disabled
Allow users to access the games menu
ユーザーがゲーム メニューにアクセスすることを許可する
AllowGamesMenu Disabled
Allow users to configure Family safety
ユーザーがファミリー セーフティを構成することを許可する
FamilySafetySettingsEnabled Disabled
Allow users to proceed from the HTTPS warning page
ユーザーが HTTPS 警告ページから続行することを許可する
SSLErrorOverrideAllowed Disabled
Allow websites to query for available payment methods
Web サイトが利用可能な支払い方法を照会することを許可する
PaymentMethodQueryEnabled Disabled
Allows users to edit favorites
ユーザーがお気に入りを編集することを許可する
EditFavoritesEnabled Disabled
Always open PDF files externally
PDF ファイルを常に外部で開く
AlwaysOpenPdfExternally Disabled
AutoLaunch Protocols Component Enabled
AutoLaunch Protocols コンポーネントを有効にする
AutoLaunchProtocolsComponentEnabled Disabled
Block access to a list of URLs
URL の一覧へのアクセスをブロックする
URLBlocklist Disabled
Block all ads on Bing search results
Bing 検索結果ですべての広告をブロックする
BingAdsSuppression Enabled
Browser sign-in settings
Browser Sign-in の設定
BrowserSignin Enabled ブラウザーサインインを無効にする
"ブラウザーサインインを有効にする"
ブラウザーを使用するためにユーザーにサインインを強制する(すべてのプロファイル)
Clear browsing data when Microsoft Edge closes
Microsoft Edge を閉じるときに閲覧データを消去する
ClearBrowsingDataOnExit Enabled
Clear cached images and files when Microsoft Edge closes
Microsoft Edge を閉じるときにキャッシュされた画像とファイルを消去する
ClearCachedImagesAndFilesOnExit Enabled
Configure InPrivate mode availability
InPrivate モードの可用性を構成する
InPrivateModeAvailability Enabled InPrivate モードが利用可能
"無効な InPrivate モード"
InPrivate モードを強制実行しました
Configure Online Text To Speech
オンライン テキスト読み上げを構成する
ConfigureOnlineTextToSpeech Disabled
Configure Related Matches in Find on Page
ページ内検索の関連一致を構成する
RelatedMatchesCloudServiceEnabled Disabled
Configure Speech Recognition
音声認識を構成する
SpeechRecognitionEnabled Disabled
Configures availability of a vertical layout for tabs on the side of the browser
ブラウザーの側面にタブを縦に配置するレイアウトの可用性を構成する
VerticalTabsAllowed Disabled
Control where developer tools can be used
開発者ツールを使用できる場所を制御する
DeveloperToolsAvailability Disabled
Default clipboard site permission
既定のクリップボード サイト権限
DefaultClipboardSetting Enabled Do not allow any site to use the clipboard site permission
"Allow sites to ask the user to grant the clipboard site permission"
Default sensors setting
既定のセンサー設定
DefaultSensorsSetting Disabled
Define a list of allowed URLs
許可する URL の一覧を定義する
URLAllowlist Disabled
Disable synchronization of data using Microsoft sync services
Microsoft 同期サービスを使用したデータの同期を無効にする
SyncDisabled Enabled
Double Click feature in Microsoft Edge enabled (only available in China)
Microsoft Edge のダブルクリック機能を有効にする(中国でのみ使用可能)
DoubleClickCloseTabEnabled Disabled
Enable AutoFill for addresses
住所のオートフィルを有効にする
AutofillAddressEnabled Disabled
Enable AutoFill for payment instruments
支払い手段のオートフィルを有効にする
AutofillCreditCardEnabled Disabled
Enable component updates in Microsoft Edge
Microsoft Edge のコンポーネント更新を有効にする
ComponentUpdatesEnabled Disabled
Enable Drop feature in Microsoft Edge
Microsoft Edge の Drop 機能を有効にする
EdgeEDropEnabled Disabled
Enable ending processes in the Browser task manager
ブラウザー タスク マネージャーでプロセスの終了を有効にする
TaskManagerEndProcessEnabled Disabled
Enable favorites bar
お気に入りバーを有効にする
FavoritesBarEnabled Disabled
Enable guest mode
ゲスト モードを有効にする
BrowserGuestModeEnabled Disabled
Enable Microsoft Search in Bing suggestions in the address bar
アドレス バーの Bing 候補で Microsoft Search を有効にする
AddressBarMicrosoftSearchInBingProviderEnabled Disabled
Enable network prediction
ネットワーク予測を有効にする
NetworkPredictionOptions Enabled 任意のネットワーク接続でのネットワーク操作を予測する
サポートされていません。この値を使用すると、「ネットワーク接続のネットワークアクションを予測する」(0)が設定さ…
"任意のネットワーク接続でのネットワーク操作を予測しない"
Enable open in sidebar
サイドバーで開く機能を有効にする
EdgeOpenInSidebarEnabled Disabled
Enable profile creation from the Identity flyout menu or the Settings page
ID フライアウト メニューまたは設定ページからのプロファイル作成を有効にする
BrowserAddProfileEnabled Disabled
Enable resolution of navigation errors using a web service
Web サービスを使用したナビゲーション エラーの解決を有効にする
AlternateErrorPagesEnabled Disabled
Enable search suggestions
検索候補を有効にする
SearchSuggestEnabled Disabled
Enable split screen feature in Microsoft Edge
Microsoft Edge の分割画面機能を有効にする
SplitScreenEnabled Disabled
Enable the Collections feature
コレクション機能を有効にする
EdgeCollectionsEnabled Disabled
Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge
Microsoft Edge のスクリーンショット(以前の Web キャプチャ)機能を有効にする
WebCaptureEnabled Disabled
Enable Translate
翻訳を有効にする
TranslateEnabled Disabled
Enables Microsoft Edge mini menu
Microsoft Edge ミニ メニューを有効にする
QuickSearchShowMiniMenu Disabled
Enforce Bing SafeSearch
Bing セーフサーチを強制する
ForceBingSafeSearch Enabled Bing で検索制限を構成しない
Bingで中程度の検索制限を構成する
"Bing で厳密な検索制限を構成する"
Enforce Google SafeSearch
Google セーフサーチを強制する
ForceGoogleSafeSearch Enabled
Enhance the security state in Microsoft Edge (obsolete)
Microsoft Edge のセキュリティ状態を強化する(廃止)
EnhanceSecurityMode Enabled Standard mode
Balanced mode
"Strict mode"
Force minimum YouTube Restricted Mode
最小 YouTube 制限付きモードを強制する
ForceYouTubeRestrict Enabled YouTube で厳格な制限モードを強制しない
YouTube で少なくとも中程度の制限モードを強制する
"YouTube に厳格な制限モードを強制する"
Hide the First-run experience and splash screen
初回実行エクスペリエンスとスプラッシュ画面を非表示にする
HideFirstRunExperience Enabled
In-app support Enabled
アプリ内サポートを有効にする
InAppSupportEnabled Disabled
Let screen reader users get image descriptions from Microsoft
スクリーン リーダー ユーザーが Microsoft から画像の説明を取得できるようにする
AccessibilityImageLabelsEnabled Disabled
Microsoft Edge Insider Promotion Enabled
Microsoft Edge Insider プロモーションを有効にする
MicrosoftEdgeInsiderPromotionEnabled Disabled
Search Filters Enabled
検索フィルターを有効にする
SearchFiltersEnabled Disabled
Search in Sidebar enabled
サイドバー内検索を有効にする
SearchInSidebarEnabled Disabled
Set download directory
ダウンロード ディレクトリを設定する
DownloadDirectory Enabled /home/msft/share
Shopping in Microsoft Edge Enabled
Microsoft Edge のショッピングを有効にする
EdgeShoppingAssistantEnabled Disabled
Show an "Always open" checkbox in external protocol dialog
外部プロトコル ダイアログに「常に開く」チェック ボックスを表示する
ExternalProtocolDialogShowAlwaysOpenCheckbox Enabled
Show Hubs Sidebar
Hubs サイドバーを表示する
HubsSidebarEnabled Disabled
Show links shared from Microsoft 365 apps in History
Microsoft 365 アプリから共有されたリンクを履歴に表示する
SharedLinksEnabled Disabled
Show Microsoft Office shortcut in favorites bar
お気に入りバーに Microsoft Office ショートカットを表示する
ShowOfficeShortcutInFavoritesBar Disabled
Show Microsoft Rewards experiences
Microsoft Rewards エクスペリエンスを表示する
ShowMicrosoftRewards Disabled
Spell checking provided by Microsoft Editor
Microsoft Editor によるスペル チェック
MicrosoftEditorProofingEnabled Disabled
Suggest similar pages when a webpage can’t be found
Web ページが見つからない場合に類似ページを提案する
ResolveNavigationErrorsUseWebService Disabled
Synonyms are provided when using Microsoft Editor spell checker
Microsoft Editor のスペル チェック使用時に類義語を提供する
MicrosoftEditorSynonymsEnabled Disabled
Text prediction enabled by default
テキスト予測を既定で有効にする
TextPredictionEnabled Disabled
Use hardware acceleration when available
使用可能な場合はハードウェア アクセラレータを使用する
HardwareAccelerationModeEnabled Enabled
Wallet Donation Enabled
ウォレット寄付を有効にする
WalletDonationEnabled Disabled

Edge ワークスペースの設定

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Enable Workspaces
ワークスペースを有効にする
EdgeWorkspacesEnabled Disabled

SmartScreen 設定

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Configure Microsoft Defender SmartScreen
Microsoft Defender SmartScreen を構成する
SmartScreenEnabled Enabled
Prevent bypassing Microsoft Defender SmartScreen prompts for sites
サイトに対する Microsoft Defender SmartScreen のプロンプトのバイパスを防止する
PreventSmartScreenPromptOverride Enabled
Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads
ダウンロードに関する Microsoft Defender SmartScreen の警告のバイパスを防止する
PreventSmartScreenPromptOverrideForFiles Enabled

キャスト

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Enable Google Cast
Google Cast を有効にする
EnableMediaRouter Disabled
Show the cast icon in the toolbar
ツールバーにキャスト アイコンを表示する
ShowCastIconInToolbar Disabled

コンテンツ設定

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Allow notifications to set Microsoft Edge as default PDF reader
通知によって Microsoft Edge を既定の PDF リーダーとして設定することを許可する
ShowPDFDefaultRecommendationsEnabled Disabled
Configure cookies
Cookie を構成する
DefaultCookiesSetting Enabled "すべてのサイトに Cookie の作成を許可する"
任意のサイトに Cookie の作成を許可しない
セッションの継続時に Cookie を保持する ("SaveCookiesOnExit" に記載されているものを除く)
Control use of the File System API for reading
読み取り用の File System API の使用を制御する
DefaultFileSystemReadGuardSetting Enabled Don't allow any site to request read access to files and directories via the File System API
"Allow sites to ask the user to grant read access to files and directories via the File System API"
Control use of the File System API for writing
書き込み用の File System API の使用を制御する
DefaultFileSystemWriteGuardSetting Enabled Don't allow any site to request write access to files and directories
"Allow sites to ask the user to grant write access to files and directories"
Default geolocation setting
既定の位置情報設定
DefaultGeolocationSetting Disabled
Default notification setting
既定の通知設定
DefaultNotificationsSetting Enabled デスクトップ通知の表示をサイトに許可する
"どのサイトに対してもデスクトップ通知の表示を許可しない"
サイトでデスクトップ通知を表示することを毎回確認する

スリープ タブの設定

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Configure Sleeping Tabs
スリープ タブを構成する
SleepingTabsEnabled Disabled

パスワード マネージャーと保護

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Enable saving passwords to the password manager
パスワード マネージャーへのパスワード保存を有効にする
PasswordManagerEnabled Disabled

パフォーマンス

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Pin browser essentials toolbar button
ブラウザー Essentials ツールバー ボタンをピン留めする
PinBrowserEssentialsToolbarButton Disabled

プライベート ネットワーク要求の設定

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Specifies whether to allow insecure websites to make requests to more-private network endpoints
安全でない Web サイトからよりプライベートなネットワーク エンドポイントへの要求を許可するかどうかを指定する
InsecurePrivateNetworkRequestsAllowed Disabled

印刷

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Enable printing
印刷を有効にする
PrintingEnabled Disabled
Print using system print dialog
システム印刷ダイアログを使用して印刷する
UseSystemPrintDialog Disabled

拡張機能

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Control which extensions cannot be installed
インストールできない拡張機能を制御する
ExtensionInstallBlocklist Enabled *

既定の検索プロバイダー

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Default search provider keyword
既定の検索プロバイダーのキーワード
DefaultSearchProviderKeyword Enabled bing.com
Default search provider search URL
既定の検索プロバイダーの検索 URL
DefaultSearchProviderSearchURL Enabled https://www.bing.com/search?q={searchTerms}
Default search provider URL for suggestions
既定の検索プロバイダーの候補 URL
DefaultSearchProviderSuggestURL Enabled https://www.bing.com/osjson.aspx?query={searchTerms}
Enable the default search provider
既定の検索プロバイダーを有効にする
DefaultSearchProviderEnabled Enabled
Parameters for an image URL that uses POST
POST を使用する画像 URL のパラメーター
DefaultSearchProviderImageURLPostParams Enabled https://www.bing.com/sa/simg/bing_p_rr_teal_min.ico

起動、ホーム ページおよび新しいタブ ページ

Intune 設定カタログ
(下段は和訳)
Edge ポリシー名 Opal
既定値
オプション
Action to take on Microsoft Edge startup
Microsoft Edge 起動時の動作
RestoreOnStartup Enabled "Open a new tab"
Restore the last session
Open a list of URLs
Open a list of URLs and restore the last session
Configure the home page URL
ホーム ページ URL を構成する
HomepageLocation Enabled about:blank
Configure the new tab page URL
新しいタブ ページ URL を構成する
NewTabPageLocation Enabled about:blank
Hide App Launcher on Microsoft Edge new tab page
Microsoft Edge の新しいタブ ページでアプリ ランチャーを非表示にする
NewTabPageAppLauncherEnabled Disabled
Show Home button on toolbar
ツールバーにホーム ボタンを表示する
ShowHomeButton Disabled

備考(非推奨・廃止予定ポリシーについて)

本記事で紹介しているポリシーの一部には、Microsoft Learn 上で Deprecated(非推奨)Obsolete(廃止予定) とされているものが含まれます。Project Opal が生成した構成にも含まれていましたが、今後の Microsoft Edge のバージョンでは削除または無効化される可能性があるため注意してください。

EnhanceSecurityMode

Edge Policy Name: EnhanceSecurityMode

Microsoft Learn では Microsoft Edge のセキュリティ状態を強化するポリシーとして提供されていますが、Intune 側では "(obsolete)" 表記が付与されています。Project Opal では Strict mode が設定されていました。

✅ Project Opal 設定値: Strict mode
⚠️ Intune 表示上は obsolete 扱い

公開情報:EnhanceSecurityMode
https://learn.microsoft.com/ja-jp/deployedge/microsoft-edge-policies/EnhanceSecurityMode?wt.mc_id=MVP_407731

WalletDonationEnabled

Edge Policy Name: WalletDonationEnabled

このポリシーは Microsoft Edge の Wallet Donation 機能を制御するものでしたが、Microsoft Learn では Deprecated(非推奨) と明記されています。機能自体が Microsoft Edge から削除されたため、将来的には不要になる可能性があります。

✅ Project Opal 設定値: Disabled
⚠️ Microsoft Learn: Deprecated

公開情報:WalletDonationEnabled
https://learn.microsoft.com/ja-jp/deployedge/microsoft-edge-policies/walletdonationenabled?wt.mc_id=MVP_407731

InsecurePrivateNetworkRequestsAllowed

Edge Policy Name: InsecurePrivateNetworkRequestsAllowed

安全でない Web サイトから、よりプライベートなネットワーク エンドポイントへのアクセスを許可するかどうかを制御するポリシーです。Microsoft Learn では 廃止 (Deprecated) とされており、Microsoft Edge 137 以降では機能しない と説明されています。

✅ Project Opal 設定値: Disabled
⚠️ Microsoft Edge 137 以降では機能しない

公開情報:InsecurePrivateNetworkRequestsAllowed
https://learn.microsoft.com/ja-jp/deployedge/microsoft-edge-policies/insecureprivatenetworkrequestsallowed?wt.mc_id=MVP_407731

SandboxExternalProtocolBlocked

Edge Policy Name: SandboxExternalProtocolBlocked

サンドボックス化された iframe から外部プロトコルへの遷移を Edge がブロックするかどうかを制御するポリシーです。

Microsoft Learn の説明では、このポリシーは Enterprise 向けの一時的な互換性ポリシー とされており、Microsoft Edge 117 以降で削除予定と記載されています。

✅ Project Opal 設定値: Enabled
⚠️ 一時的な互換性ポリシー(将来的に削除予定)

公開情報:SandboxExternalProtocolBlocked
https://learn.microsoft.com/ja-jp/deployedge/microsoft-edge-policies/sandboxexternalprotocolblocked?wt.mc_id=MVP_407731

まとめ

今回は、Project Opal を有効化した際に自動作成される Opal App Device Policy に含まれる Microsoft Edge ポリシーを整理してみました。

調査の結果、Opal App Device Policy では単なるブラウザー制御にとどまらず、

  • SafeSearch や YouTube Restricted Mode によるコンテンツ制御
  • Microsoft Defender SmartScreen による保護
  • 拡張機能のインストール制限
  • パスワード マネージャーの無効化
  • Browser Sign-in の有効化
  • InPrivate モードの無効化

など、多岐にわたる設定があらかじめ適用されていることが確認できました。

特に興味深かったのは、Browser Sign-in は有効化されている一方で、Sync は無効化され、さらに Password Manager も無効化されている点です。

この構成からは、ユーザー認証そのものは前提としながらも、ブラウザーへの個人データ保存や端末間同期を抑制することを意図した構成であるように見受けられます。Microsoft から設計意図は公開されていませんが、Cloud PC 環境における認証情報保護や運用管理を考慮した既定構成である可能性があります。

今回確認した内容を見る限り、Project Opal は Cloud PC 上で AI やユーザーがブラウザーを利用できる柔軟性を残しつつ、セキュリティや管理性を重視した構成になっているように見受けられました。

Project Opal は今後も継続的な機能追加や構成変更が行われることが予想されるため、本記事の内容も将来的には変化する可能性があります。

Opal App Device Policy の既定値を確認したい場合や、独自のポリシーへカスタマイズした後に元の設定を参照したい場合には、本記事をリファレンスとして活用していただければ幸いです。

2
1
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
2
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?