Turn off the XDomainRequest object
Jump to overview

Policy overview

Key metadata and intent for this policy.

Category
Windows Components > Internet Explorer > Security Features > AJAX
Supported on
At least Internet Explorer 8.0

This policy setting allows you to choose whether websites can request data across domains by using the XDomainRequest object. Note that this policy setting does not block client-side communication across domains through other features in Internet Explorer 8, and it does not prevent a site from requesting cross-domain data through a server. If you enable this policy setting, websites cannot request data across domains by using the XDomainRequest object. If you disable or do not configure this policy setting, websites can request data across domains by using the XDomainRequest object.

Internal name
IESF_DisableXDR
Policy ID
2b7d0026fd70
Elements
0

Registry values

How enabled and disabled states update the registry.

ScopeRegistry locationTypeEnabled valueDisabled valueCopy
Path
Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST
Value name
iexplore.exe
REG_DWORD
HKLM
0
HKCU
0
HKLM
1
HKCU
1
Registry location
Type REG_DWORD · Both
Path
Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST
Value name
iexplore.exe
Hive
HKLM
Enabled value
0
Disabled value
1
Hive
HKCU
Enabled value
0
Disabled value
1

Policy elements

Inputs and configuration options exposed by this policy.

This policy has no additional user input fields.