A default browser Group Policy sets which browser opens web links, .htm and .html files and, if you choose, PDF files on every domain computer, by pointing Windows at one XML file of default associations that it applies when a user signs in. It is the supported way to make Chrome, Edge or Firefox the default on Windows 10 and Windows 11, because Windows protects the per-user association keys against direct edits.
Short answer: Set the browser as default on a reference PC, run Dism /Online /Export-DefaultAppAssociations:C:\Temp\DefaultApps.xml, delete every line except .htm, .html, http and https, and copy the file to a share every computer can read. Enable Computer Configuration » Policies » Administrative Templates » Windows Components » File Explorer » "Set a default associations configuration file" with the UNC path. Users get the browser at their next sign-in.
Table of Contents
How it works
Windows stores each user’s default app for a protocol or file type under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ext\UserChoice (and ...\Shell\Associations\UrlAssociations\https\UserChoice for protocols), protected by a hash. Values written by scripts fail the hash check and Windows resets them to the built-in default. The default associations configuration file policy is the supported way around this: at sign-in, Windows reads the XML and sets the listed associations for that user itself.
Recent Windows 10 and Windows 11 builds also include the User Choice Protection Driver (UCPD.sys), which blocks non-Microsoft processes from writing the UserChoice keys for common browser associations such as http, https and .pdf. Scripts and tools that used to edit those keys stop working; the default browser Group Policy method is not affected, because Windows applies the XML itself.
Which method to use
A default browser Group Policy is the right choice for domain-joined PCs; Intune uses the same XML for cloud-managed devices. The other options are there for completeness.
| Method | Scope | When it applies | Pros | Cons |
|---|---|---|---|---|
| GPO “Set a default associations configuration file” | Computer (every user) | Each sign-in | Supported; one file for the domain | Users cannot keep their own choice for listed types |
Intune ApplicationDefaults/DefaultAssociationsConfiguration | Device | Each sign-in | Same XML for Entra-joined devices | File must be base64 encoded |
Dism /Import-DefaultAppAssociations in the image | New profiles on that image | First sign-in of new users | No ongoing policy | Existing users unchanged; not enforced |
| UserChoice registry scripts | User | n/a | None | Unsupported, blocked by hash checks and UCPD |
Prerequisites
Before you build a default browser Group Policy, check the following:
- Windows 10 version 1703 or later, or Windows 11, in Pro, Enterprise or Education edition, joined to the domain.
- The browser installed on every target computer before the policy applies. An association pointing to a ProgId that does not exist is ignored.
- A reference PC with the same browser version and install location as your fleet.
- A share readable by all computers, for example
\\contoso.com\NETLOGONor a DFS path.
Step 1: Export the associations
- On the reference PC, sign in with a test account and open Settings » Apps » Default apps.
- Select the browser and click Set default, which assigns its common link and file types at once. For PDF files, set the PDF handler you want here too.
- Export from an elevated command prompt, running in the same user session:
mkdir C:\Temp
Dism /Online /Export-DefaultAppAssociations:C:\Temp\DefaultApps.xml
The file lists every association for that user, often more than a hundred entries.
Step 2: Trim the XML to the browser entries
Keep only the lines you want to enforce. Leaving the full export in place resets photos, mail, video and every other type to the reference PC’s choices at each sign-in. A trimmed file for Chrome:
<?xml version="1.0" encoding="UTF-8"?>
<DefaultAssociations>
<Association Identifier=".htm" ProgId="ChromeHTML" ApplicationName="Google Chrome" />
<Association Identifier=".html" ProgId="ChromeHTML" ApplicationName="Google Chrome" />
<Association Identifier="http" ProgId="ChromeHTML" ApplicationName="Google Chrome" />
<Association Identifier="https" ProgId="ChromeHTML" ApplicationName="Google Chrome" />
</DefaultAssociations>
Common ProgIds:
| Browser | http, https | .htm, .html | .pdf |
|---|---|---|---|
| Google Chrome | ChromeHTML | ChromeHTML | Copy from export if used |
| Microsoft Edge | MSEdgeHTM | MSEdgeHTM | MSEdgePDF |
| Mozilla Firefox | FirefoxURL- plus a hash | FirefoxHTML- plus a hash | Copy from export if used |
The same file for Edge or Firefox only changes the ProgId and application name:
<Association Identifier="https" ProgId="MSEdgeHTM" ApplicationName="Microsoft Edge" />
<Association Identifier="https" ProgId="FirefoxURL-308046B0AF4A39CB" ApplicationName="Firefox" />
<Association Identifier=".html" ProgId="FirefoxHTML-308046B0AF4A39CB" ApplicationName="Firefox" />
Firefox appends a hash that depends on the install path (the value above is only an example), so copy the exact ProgIds from your own export. The same applies to any PDF reader: take the ProgId from the exported line rather than typing it.
Windows 11 Version and Suggested attributes
From Windows 11 version 22H2, the XML supports two optional attributes. Version on the root element, and Suggested="true" on an association, make Windows apply that association once per version number instead of at every sign-in, so users can change it afterwards. Associations without Suggested (or with "false") are applied at each sign-in.
<DefaultAssociations Version="1">
<Association Identifier=".pdf" ProgId="MSEdgePDF" ApplicationName="Microsoft Edge" Suggested="true" />
</DefaultAssociations>
Increase Version when you want Windows to apply suggested entries again.
Check the XML before you deploy it
A typo in a ProgId makes Windows skip that line silently. Parse the file and confirm every ProgId is registered on a target PC:
$x = [xml](Get-Content -Path C:\Temp\DefaultApps.xml -Raw)
$x.DefaultAssociations.Association | Format-Table Identifier, ProgId, ApplicationName
$x.DefaultAssociations.Association | ForEach-Object {
"{0,-8} {1,-30} registered: {2}" -f $_.Identifier, $_.ProgId, (Test-Path "Registry::HKEY_CLASSES_ROOT\$($_.ProgId)")
}
Every line should report registered: True. A False means the browser is missing or the ProgId is wrong.
Step 3: Store the file and set the policy
- Copy the trimmed file to the share, for example
\\contoso.com\NETLOGON\DefaultApps.xml. Grant Domain Computers and Authenticated Users read access. - Create a GPO, for example CMP – Default Browser, and link it to the OU that holds the computers.
- Go to
Computer Configuration » Policies » Administrative Templates » Windows Components » File Explorer. - Open “Set a default associations configuration file”, choose Enabled and enter the UNC path in Default Associations Configuration File.
- Click OK.
The default browser Group Policy setting writes DefaultAssociationsConfiguration (REG_SZ) with the path under HKLM\SOFTWARE\Policies\Microsoft\Windows\System. A local path such as C:\ProgramData\Contoso\DefaultApps.xml also works if you copy the file there first, for example with a Group Policy Preferences Files item; this avoids problems when the share is unreachable at sign-in.
Two optional settings in the same folder reduce noise: “Do not show the ‘new application installed’ notification” stops the prompt that appears when a new browser registers itself. In the browser templates, “Set Google Chrome as Default Browser” and “Set Microsoft Edge as default browser” set to Disabled stop each browser from asking to become the default. Both browser vendors state that on Windows 10 and later, the associations file, not these settings, decides the default.
Step 4: Choose a PDF handler deliberately
If the XML does not include .pdf, the user’s current choice stays. Decide one of three options:
- Browser opens PDFs: add the browser’s PDF line (
MSEdgePDFfor Edge). - A dedicated reader opens PDFs: install the reader first, set it as default on the reference PC, export and copy its
.pdfline. - Leave it to users: omit
.pdf, or add it withSuggested="true"on Windows 11 22H2 and later.
Intune: DefaultAssociationsConfiguration
Intune has no separate default browser Group Policy, but the same XML works for Intune-managed devices, base64 encoded:
$xml = Get-Content -Path C:\Temp\DefaultApps.xml -Raw -Encoding UTF8
$b64 = [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes($xml))
$b64 | Set-Clipboard
- In the Intune admin center, create Devices » Configuration » Create » New policy, platform Windows 10 and later, profile Settings catalog.
- Search for default associations and add Application Defaults » Default Associations Configuration.
- Paste the base64 string and assign the profile to a device group.
With a custom profile instead, use the OMA-URI ./Device/Vendor/MSFT/Policy/Config/ApplicationDefaults/DefaultAssociationsConfiguration, data type String, with the base64 value. Microsoft documents that this MDM policy takes precedence over the Group Policy setting even when MDMWinsOverGP is not configured, so co-managed devices use the Intune file.
Per-user and first sign-in behaviour
- The policy is a computer setting, but it is applied per user at sign-in. Existing users get the new default at their next sign-in, not at
gpupdate. - New users get it at their first sign-in. If the first sign-in happens before the computer has received the GPO (for example on a freshly joined laptop using fast logon), the association arrives at the following sign-in.
- Users can change the default in Settings, but listed associations without
Suggested="true"are set back at the next sign-in. - If a browser update changes its ProgId or the browser is uninstalled, Windows skips that entry and falls back to its own default.
Install the browser before the policy applies
The associations file only works when the ProgIds exist, so order matters on new machines:
- Deploy the browser as a computer-assigned package, an Intune required app or part of the image, so it is installed at startup before the first user signs in. See deploying software with Group Policy.
- Use the enterprise (system-level) installer. Per-user installs in the profile register their ProgIds only for that user and break the file for everyone else.
- Keep the browser updating itself or through your patching tool. Browser updates keep the same ProgIds, so the XML does not need to change for version updates.
- If you replace one browser with another, deploy the new browser first, then switch the XML, then remove the old browser.
RDS hosts and Windows Server
The setting is also supported on Windows Server, so RDS session hosts can use the same approach. A few points differ:
- Link the GPO to the OU of the session hosts. Because it is a computer setting, every user on a host gets the same browser, whatever GPOs apply to their user account.
- Install the browser machine-wide on each host, in the same path on every host, so a Firefox hash or a ProgId matches on all of them.
- Sign-in time matters more on busy hosts. A local copy of the XML (copied with a GPP Files item) avoids a network read for every session.
- User profile disks and FSLogix containers keep the UserChoice keys between sessions, which is fine: the policy simply sets the same values again at each sign-in.
For servers that nobody browses from, leave the policy unlinked. A default browser Group Policy adds nothing on a domain controller or file server.
Exceptions and targeting
- Different browsers for different teams need different XML files and GPOs, filtered by computer groups, because the policy is a computer setting. See GPO security filtering.
- On RDS hosts every user of the host gets the same file. Build a host-specific XML if needed.
- Test machines can be excluded with a Deny on Apply group policy for a computer group.
- To set Chrome homepages and startup pages at the same time, see setting the Edge and Chrome homepage.
Verify it works
Test the default browser Group Policy with a user who has signed in before and with a brand-new user:
- Run
gpupdate /force, then check the policy value:reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DefaultAssociationsConfiguration - Confirm the computer can read the file:
type \\contoso.com\NETLOGON\DefaultApps.xml. - Sign out and sign in, then check the current user’s choice:
Get-ItemProperty "HKCU:\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice" | Select-Object ProgId
Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice" | Select-Object ProgId - Open a link from Outlook or Teams and an
.htmlfile from Explorer; both should open in the chosen browser. - Open Settings » Apps » Default apps and check the browser shows as the default for HTTP, HTTPS and .htm/.html.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
Nothing changes after gpupdate | Associations apply at sign-in | Sign out and in |
| Browser not default for new users on new laptops | GPO not yet applied at first sign-in | Second sign-in; enable “Always wait for the network at computer startup and logon” |
| Photos, mail or video defaults changed | Full export deployed | Trim the XML to browser entries |
| Firefox entry ignored | ProgId hash differs because of a different install path | Export from a PC with the standard install path |
| Works on some PCs only | Browser missing, or share not readable at sign-in | Install the browser first; copy the XML locally with GPP |
| Intune value rejected or ignored | XML pasted instead of base64, or wrong encoding | Encode the UTF-8 file with the PowerShell above |
| Chrome or Edge keeps asking to become the default | Browser default-check prompt still enabled | Set “Set Google Chrome as Default Browser” or “Set Microsoft Edge as default browser” to Disabled |
| Script that set UserChoice stopped working | Hash protection and UCPD | Replace the script with the associations file policy |
The Application event log and Settings » Apps » Default apps rarely say why an entry was skipped, so test a new XML file on one PC before linking it widely.
Roll back or undo
- Set “Set a default associations configuration file” to Not Configured (or unlink the GPO) and run
gpupdate /force. The registry value is removed. - Users keep the association they last received; Windows does not revert it. They can now change it in Settings, or you can deploy a new XML with the new browser first and remove the policy later.
- In Intune, remove the profile assignment and sync the device.
Keep the XML files in version control with a short note per change. A default browser Group Policy is easy to break with a stray line in the file, and the history shows which change caused it.
Default browser Group Policy at a glance

Official documentation: Policy CSP – ApplicationDefaults, Export or import default application associations.
Related guides: Set the Edge and Chrome Homepage with Group Policy: Easy Guide · Deploy Software with Group Policy: MSI Install Step by Step · Import ADMX templates (Office, Chrome, Edge) into Intune and the AD Central Store.
Frequently asked questions
Does the default browser Group Policy apply to existing users?
Yes. Windows applies the associations file at each sign-in, so existing users get the new default the next time they sign in. Running gpupdate alone does not change it.
Can users still change their default browser?
They can change it in Settings, but associations listed in the file are applied again at the next sign-in. On Windows 11 22H2 and later, entries marked Suggested=”true” are applied once per Version value and users keep their own choice afterwards.
Why not set UserChoice in the registry with a script?
UserChoice values are protected by a hash, and the User Choice Protection Driver blocks non-Microsoft processes from writing browser associations. Windows resets unsupported values, so the associations file policy is the supported method.
Do I need to include PDF in the XML?
Only if you want to control which app opens PDF files. Leave .pdf out to keep each user’s choice, or add the line for your chosen reader copied from an export.
Can Intune use the same XML file?
Yes. Encode the XML in base64 and set it in the Settings catalog under Application Defaults, or with the DefaultAssociationsConfiguration OMA-URI. The Intune policy takes precedence over the GPO.