หมายเหตุ
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลอง ลงชื่อเข้าใช้หรือเปลี่ยนไดเรกทอรีได้
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลองเปลี่ยนไดเรกทอรีได้
IT Admins can use group policy objects (GPO) to configure policy settings for WebView2, to manage WebView2 applications and the WebView2 Runtime. The following policies are relevant to WebView2.
Many policies are about updating the WebView2 Runtime. A developer can integrate the WebView2 component into their app, and then deploy the self-updating Evergreen WebView2 Runtime (along with the app) onto user devices, to power the latest WebView2 features of the app and get the latest security improvements.
Detailed contents:
- Update policies
- WebView2-specific policies
- Browser policies vs. WebView2 policies
- Windows Server Update Services (WSUS)
- Providing feedback
- See also
Update policies
Microsoft Edge update policies are available for IT Admins to manage the installing and updating aspects of the WebView2 Runtime. The Microsoft Edge browser and WebView2 Runtime are updated using the same update mechanism.
A Microsoft Edge update policy applies to both Microsoft Edge and the WebView2 Runtime, unless the policy is channel-specific, such as:
- Update, in Microsoft Edge - Update policies.
- Update (WebView), in Microsoft Edge - Update policies.
To configure update policies for Microsoft Edge and the WebView2 Runtime, see:
- Configure Microsoft Edge policy settings on Windows devices, in the Microsoft Edge Enterprise documentation.
See:
- Microsoft Edge - Update policies, in the Microsoft Edge Enterprise documentation.
Evergreen Runtime is recommended, rather than a fixed version
Using the Evergreen WebView2 Runtime is recommended, unless business-critical requirements necessitate using a fixed version of the WebView2 Runtime. Using the Evergreen WebView2 Runtime:
- Helps minimize exposure to known vulnerabilities.
- Ensures timely security improvements.
- Ensures that WebView2 benefits from continuous security updates that are delivered through Microsoft Edge releases.
See:
For details about security fixes in Microsoft Edge (which also apply to WebView2), see:
- Release notes for Microsoft Edge Security Updates, in the Microsoft Edge Enterprise documentation.
Rapid response to Chromium vulnerabilities
To help maintain a secure browsing environment, Microsoft Edge addresses vulnerabilities in the Chromium browser engine soon after the vulnerabilities are disclosed.
Security fixes in the Chromium browser engine address vulnerabilities such as:
- Remote code execution – Mitigates risks of arbitrary code execution via malicious content.
- Privilege escalation – Reduces chances of unauthorized system access.
- Information disclosure and spoofing – Protects sensitive data, and helps prevent phishing attacks.
For details about security fixes in Microsoft Edge (which also apply to WebView2), see:
- Release notes for Microsoft Edge Security Updates, in the Microsoft Edge Enterprise documentation.
Microsoft Edge Lifecycle Policy
Microsoft WebView2 follows the Modern Lifecycle Policy.
See:
- Modern Lifecycle Policy, in the Modern Lifecycle Policy documentation.
- Microsoft Edge Lifecycle Policy, in the Microsoft Edge Enterprise documentation.
Suppressing WebView2 Runtime updates (UpdatesSuppressed)
An IT Admin can suppress updating of the WebView2 Runtime, if auto-updating needs to be suppressed for a short time. After the time period, updating of the WebView2 Runtime resumes. The UpdatesSuppressed policy allows an IT Admin to set the time during each day at which to suppress auto-update for both Microsoft Edge and the WebView2 Runtime. This enables an IT Admin to configure preferences and proxies once for both the browser and the WebView2 Runtime, to control their network bandwidth and traffic, or for other purposes.
Microsoft Edge - Policies doesn't apply to WebView2 applications. This is by design, because apps and browsers have different use cases, and IT admins might not be aware of what applications use WebView2.
However, users should not stop updating their WebView2 Runtime; users should not remain on an older version of the WebView2 Runtime. Using older versions of the WebView2 Runtime isn't recommended. Security updates and servicing updates are only available on the latest Stable channel release (Edge Stable) and the latest Beta channel release (Edge Beta). If you use older releases of the Microsoft WebView2 Runtime, you won't receive the latest quality and security updates.
See:
- UpdatesSuppressed, in Microsoft Edge - Update policies.
WebView2-specific policies
Policies that are specific to the WebView2 Runtime are available to the IT Admin, to manage the WebView2 Runtime directly. In most cases, we recommend that the WebView2 app developer implement their own group policies to manage the use of the WebView2 Runtime, because it's easier for the IT Admin to manage a WebView2 app, rather than managing the WebView2 Runtime directly.
See:
- Microsoft Edge WebView2 - Policies, in the Microsoft Edge Enterprise documentation.
Downgrading the WebView Runtime to an earlier version (DowngradeVersion)
Enterprise Downgrade is a temporary, IT Admin-controlled capability that allows a specific WebView2 app to revert to using an earlier version of the WebView2 Runtime, if there's a critical regression in the WebView2 app when using the latest version of the WebView2 Runtime.
The Enterprise Downgrade feature is controlled via the DowngradeVersion policy.
See:
- Downgrade the WebView2 Runtime to an earlier version, in the Microsoft Edge Enterprise documentation.
- DowngradeVersion in Microsoft Edge WebView2 - Policies.
Browser policies vs. WebView2 policies
Browser policies are separate from WebView2 policies. Policies for Microsoft Edge don't apply to the WebView2 Runtime and WebView2 apps. This is by design, because apps and browsers have different use cases, and an IT Admin might not know which apps use WebView2.
Applying browser policies on the WebView2 Runtime would have unintended consequences. For example, the IT Admin can block JavaScript in the browser, and that would break WebView2 apps that use JavaScript. To prevent that, browser policies are separate from WebView2 policies.
See:
- Microsoft Edge - Policies, in the Microsoft Edge Enterprise documentation.
- Microsoft Edge WebView2 - Policies, in the Microsoft Edge Enterprise documentation.
Windows Server Update Services (WSUS)
Windows Server Update Services (WSUS) enables IT Admins to deploy the latest Microsoft product updates. You can use WSUS to fully manage the distribution of updates of WebView2 that are released through Microsoft Update to computers on your network.
See:
The recommended way of receiving WebView2 updates is by using the default Microsoft Edge updater. Any modification of update and servicing paths should be done with caution.
WebView2 deployment and update using Configuration Manager
In Configuration Manager, WebView2 options exist under the Microsoft Edge Management node.
See:
- Update Microsoft Edge in Microsoft Edge Management, in the App management documentation.
Providing feedback
Feedback from IT Admins and developers is welcome, through the WebView2Feedback repo.
See also:
See also
- Distribute your app and the WebView2 Runtime - Evergreen vs. fixed version of the WebView2 Runtime.
- Contact the WebView2 team
Microsoft Edge Enterprise documentation:
- Microsoft Edge Lifecycle Policy
- Microsoft Edge release schedule
- Release notes for Microsoft Edge Security Updates
- Configure Microsoft Edge policy settings on Windows devices
- Downgrade the WebView2 Runtime to an earlier version
- Microsoft Edge - Policies
- Microsoft Edge - Update policies
- Microsoft Edge WebView2 - Policies
Modern Lifecycle Policy documentation:
App management documentation:
- Update Microsoft Edge in Microsoft Edge Management.
Windows Server Management documentation:
GitHub:
- WebView2Feedback repo.