Edge iOS – EdgeDisabledFeatures=extensions policy applied but extensions can still be installed

DavidAR 0 Reputation points
2026-03-04T09:53:54.0233333+00:00

Hello,

I am trying to prevent users from installing extensions in Microsoft Edge on iOS using Intune App Configuration (Managed Devices).

Environment

  • Device type: iOS kiosk / shared device

Enrollment: Without User Affinity

Management: MDM (not MAM)

Browser: Microsoft Edge for iOS

Configuration deployed via Intune App Configuration Policy for Managed Devices

Configuration

Configuration key:

EdgeDisabledFeatures

Value:

password|inprivate|autofill|translator|readaloud|drop|coupons|extensions|developertools|UIRAlert|share|sendtodevices|weather|webinspector

Observed behavior

The policy is successfully delivered to the device.

  • In edge://policy the setting appears correctly and includes extensions.

Other features in the list appear to be disabled as expected.

However, users are still able to install Edge extensions from the extensions gallery.

Questions

Is extensions in EdgeDisabledFeatures expected to fully block extension installation on Edge for iOS?

Are there any limitations for shared/kiosk devices (without user affinity) that would cause this setting to be ignored?

Is there an alternative policy to completely disable extensions in Edge on iOS when using Intune with MDM-managed devices?

Any clarification would be appreciated.

Thx!

Microsoft Edge | Browser extensions | iOS
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-04T09:54:15.4966667+00:00

    extensions in EdgeDisabledFeatures is not the mechanism that fully blocks extension installation on Microsoft Edge for iOS.

    From the documented Intune app configuration keys for Edge on iOS/Android, com.microsoft.intune.mam.managedbrowser.disabledFeatures (surfaced as EdgeDisabledFeatures) is used to disable specific in-app features such as:

    • password – disable password save prompts
    • inprivate – disable InPrivate browsing
    • autofill – disable address/payment autofill
    • translator, readaloud, drop, coupons, extensions, developertools, UIRAlert, share, sendtodevices, weather, webinspector, etc.

    The description for extensions is:

    extensions disables extensions

    This setting is designed to disable the extensions feature in the Edge UI (for example, hide or gray out extension-related options), not to enforce a store-level or platform-level block on installing extensions from the gallery. The context does not document that it prevents installation from the gallery on iOS, only that it disables the feature.

    There is no documented alternative MDM app configuration key in the provided context that:

    • specifically targets Edge for iOS, and
    • completely blocks extension installation from the Edge extensions gallery on iOS.

    The policies that provide strong allow/block control over extensions (such as ExtensionInstallBlocklist, ExtensionInstallAllowlist, and ExtensionSettings) are documented for Microsoft Edge on managed desktop platforms via Group Policy/MDM, not for Edge on iOS.

    The context also does not document any special behavior or limitation for kiosk/shared iOS devices without user affinity that would cause extensions in EdgeDisabledFeatures to be ignored. It only confirms that, for iOS app configuration, feature restrictions (including Extensions) are validated by checking that “advanced restrictions (such as Collections, Extensions, Drop, Copilot) [are] enforced” when the user is signed in with an Entra ID account.

    Based on the available documentation in the context:

    • extensions in EdgeDisabledFeatures is intended to disable the extensions feature in the Edge UI, not guaranteed to fully block installation from the gallery on iOS.
    • No alternative MDM policy is documented here that completely blocks extension installation for Edge on iOS.
    • No kiosk/shared-device-specific limitation is documented that explains the behavior beyond the requirement that the user be signed into Edge with a work/school (Entra ID) account for app configuration to apply.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.