PDFSecureMode

Secure mode and Certificate-based Digital Signature validation in native PDF reader

Supported versions

  • Windows: ≥ 100
  • macOS: ≥ 100
  • Android: Not supported
  • iOS: Not supported

Description

This policy controls whether the native PDF reader validates certificate-based digital signatures in PDF files in a secure environment and displays the validation status. Starting with Microsoft Edge version 154, this capability is enabled by default on Windows. It remains disabled by default on macOS and on Windows in earlier versions.

If you enable this policy, the native PDF reader validates certificate-based digital signatures and provides an option to view the validation status.

If you don't configure this policy, the default behavior described above applies.

If you disable this policy, the native PDF reader doesn't validate certificate-based digital signatures or provide an option to view the validation status.

Supported features

  • Can be mandatory: Yes
  • Can be recommended: No
  • Dynamic Policy Refresh: No - Requires browser restart
  • Per Profile: Yes
  • Applies to a profile that is signed in with a Microsoft account: No

Data type

  • Boolean

Windows information and settings

Group Policy (ADMX) info

  • GP unique name: PDFSecureMode
  • GP name: Secure mode and Certificate-based Digital Signature validation in native PDF reader
  • GP path (Mandatory): Administrative Templates/Microsoft Edge
  • GP path (Recommended): N/A
  • GP ADMX file name: MSEdge.admx

Example value

Enabled

Registry settings

  • Path (Mandatory): SOFTWARE\Policies\Microsoft\Edge
  • Path (Recommended): N/A
  • Value name: PDFSecureMode
  • Value type: REG_DWORD

Example registry value

0x00000001

Mac information and settings

  • Preference Key name: PDFSecureMode
  • Example value:
<true/>

See also