# Default Browser Group Policy: Set Chrome, Edge or Firefox on Windows 11

Source: https://srvscripts.com/guides/default-browser-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A default browser Group Policy sets which browser opens web links, `.htm` and `.html` files and, if you choose, PDF files on every domain computer, by pointing Windows at one XML file of default associations that it applies when a user signs in. It is the supported way to make Chrome, Edge or Firefox the default on Windows 10 and Windows 11, because Windows protects the per-user association keys against direct edits.

**Short answer:** Set the browser as default on a reference PC, run `Dism /Online /Export-DefaultAppAssociations:C:\Temp\DefaultApps.xml`, delete every line except `.htm`, `.html`, `http` and `https`, and copy the file to a share every computer can read. Enable `Computer Configuration » Policies » Administrative Templates » Windows Components » File Explorer » "Set a default associations configuration file"` with the UNC path. Users get the browser at their next sign-in.

In short: Set the browser as default on a reference PC, run Dism /Online /Export-DefaultAppAssociations:C:\Temp\DefaultApps.xml, delete every line except .htm, .html, http and https, and copy the file to a share every computer can read.

## How it works

Windows stores each user’s default app for a protocol or file type under `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ext\UserChoice` (and `...\Shell\Associations\UrlAssociations\https\UserChoice` for protocols), protected by a hash. Values written by scripts fail the hash check and Windows resets them to the built-in default. The default associations configuration file policy is the supported way around this: at sign-in, Windows reads the XML and sets the listed associations for that user itself.

Recent Windows 10 and Windows 11 builds also include the User Choice Protection Driver (`UCPD.sys`), which blocks non-Microsoft processes from writing the UserChoice keys for common browser associations such as `http`, `https` and `.pdf`. Scripts and tools that used to edit those keys stop working; the default browser Group Policy method is not affected, because Windows applies the XML itself.

## Which method to use

A default browser Group Policy is the right choice for domain-joined PCs; Intune uses the same XML for cloud-managed devices. The other options are there for completeness.

| Method | Scope | When it applies | Pros | Cons |
| --- | --- | --- | --- | --- |
| GPO “Set a default associations configuration file” | Computer (every user) | Each sign-in | Supported; one file for the domain | Users cannot keep their own choice for listed types |
| Intune ApplicationDefaults/DefaultAssociationsConfiguration | Device | Each sign-in | Same XML for Entra-joined devices | File must be base64 encoded |
| Dism /Import-DefaultAppAssociations in the image | New profiles on that image | First sign-in of new users | No ongoing policy | Existing users unchanged; not enforced |
| UserChoice registry scripts | User | n/a | None | Unsupported, blocked by hash checks and UCPD |

## Prerequisites

Before you build a default browser Group Policy, check the following:

- Windows 10 version 1703 or later, or Windows 11, in Pro, Enterprise or Education edition, joined to the domain.

- The browser installed on every target computer before the policy applies. An association pointing to a ProgId that does not exist is ignored.

- A reference PC with the same browser version and install location as your fleet.

- A share readable by all computers, for example `\\contoso.com\NETLOGON` or a DFS path.

## Step 1: Export the associations

- On the reference PC, sign in with a test account and open **Settings » Apps » Default apps**.

- Select the browser and click **Set default**, which assigns its common link and file types at once. For PDF files, set the PDF handler you want here too.

- Export from an elevated command prompt, running in the same user session:

```
mkdir C:\Temp
Dism /Online /Export-DefaultAppAssociations:C:\Temp\DefaultApps.xml
```

The file lists every association for that user, often more than a hundred entries.

## Step 2: Trim the XML to the browser entries

Keep only the lines you want to enforce. Leaving the full export in place resets photos, mail, video and every other type to the reference PC’s choices at each sign-in. A trimmed file for Chrome:

```

```

Common ProgIds:

| Browser | http, https | .htm, .html | .pdf |
| --- | --- | --- | --- |
| Google Chrome | ChromeHTML | ChromeHTML | Copy from export if used |
| Microsoft Edge | MSEdgeHTM | MSEdgeHTM | MSEdgePDF |
| Mozilla Firefox | FirefoxURL- plus a hash | FirefoxHTML- plus a hash | Copy from export if used |

The same file for Edge or Firefox only changes the ProgId and application name:

```

```

Firefox appends a hash that depends on the install path (the value above is only an example), so copy the exact ProgIds from your own export. The same applies to any PDF reader: take the ProgId from the exported line rather than typing it.

### Windows 11 Version and Suggested attributes

From Windows 11 version 22H2, the XML supports two optional attributes. `Version` on the root element, and `Suggested="true"` on an association, make Windows apply that association once per version number instead of at every sign-in, so users can change it afterwards. Associations without `Suggested` (or with `"false"`) are applied at each sign-in.

```

```

Increase `Version` when you want Windows to apply suggested entries again.

### Check the XML before you deploy it

A typo in a ProgId makes Windows skip that line silently. Parse the file and confirm every ProgId is registered on a target PC:

```
$x = [xml](Get-Content -Path C:\Temp\DefaultApps.xml -Raw)
$x.DefaultAssociations.Association | Format-Table Identifier, ProgId, ApplicationName
$x.DefaultAssociations.Association | ForEach-Object {
  "{0,-8} {1,-30} registered: {2}" -f $_.Identifier, $_.ProgId, (Test-Path "Registry::HKEY_CLASSES_ROOT\$($_.ProgId)")
}
```

Every line should report `registered: True`. A `False` means the browser is missing or the ProgId is wrong.

## Step 3: Store the file and set the policy

- Copy the trimmed file to the share, for example `\\contoso.com\NETLOGON\DefaultApps.xml`. Grant Domain Computers and Authenticated Users read access.

- Create a GPO, for example CMP – Default Browser, and link it to the OU that holds the computers.

- Go to `Computer Configuration » Policies » Administrative Templates » Windows Components » File Explorer`.

- Open **“Set a default associations configuration file”**, choose **Enabled** and enter the UNC path in **Default Associations Configuration File**.

- Click **OK**.

The default browser Group Policy setting writes `DefaultAssociationsConfiguration` (REG_SZ) with the path under `HKLM\SOFTWARE\Policies\Microsoft\Windows\System`. A local path such as `C:\ProgramData\Contoso\DefaultApps.xml` also works if you copy the file there first, for example with a Group Policy Preferences Files item; this avoids problems when the share is unreachable at sign-in.

Two optional settings in the same folder reduce noise: **“Do not show the ‘new application installed’ notification”** stops the prompt that appears when a new browser registers itself. In the browser templates, **“Set Google Chrome as Default Browser”** and **“Set Microsoft Edge as default browser”** set to Disabled stop each browser from asking to become the default. Both browser vendors state that on Windows 10 and later, the associations file, not these settings, decides the default.

## Step 4: Choose a PDF handler deliberately

If the XML does not include `.pdf`, the user’s current choice stays. Decide one of three options:

- **Browser opens PDFs:** add the browser’s PDF line (`MSEdgePDF` for Edge).

- **A dedicated reader opens PDFs:** install the reader first, set it as default on the reference PC, export and copy its `.pdf` line.

- **Leave it to users:** omit `.pdf`, or add it with `Suggested="true"` on Windows 11 22H2 and later.

## Intune: DefaultAssociationsConfiguration

Intune has no separate default browser Group Policy, but the same XML works for Intune-managed devices, base64 encoded:

```
$xml = Get-Content -Path C:\Temp\DefaultApps.xml -Raw -Encoding UTF8
$b64 = [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes($xml))
$b64 | Set-Clipboard
```

- In the Intune admin center, create **Devices » Configuration » Create » New policy**, platform **Windows 10 and later**, profile **Settings catalog**.

- Search for default associations and add **Application Defaults » Default Associations Configuration**.

- Paste the base64 string and assign the profile to a device group.

With a custom profile instead, use the OMA-URI `./Device/Vendor/MSFT/Policy/Config/ApplicationDefaults/DefaultAssociationsConfiguration`, data type String, with the base64 value. Microsoft documents that this MDM policy takes precedence over the Group Policy setting even when MDMWinsOverGP is not configured, so co-managed devices use the Intune file.

## Per-user and first sign-in behaviour

- The policy is a computer setting, but it is applied per user at sign-in. Existing users get the new default at their next sign-in, not at `gpupdate`.

- New users get it at their first sign-in. If the first sign-in happens before the computer has received the GPO (for example on a freshly joined laptop using fast logon), the association arrives at the following sign-in.

- Users can change the default in Settings, but listed associations without `Suggested="true"` are set back at the next sign-in.

- If a browser update changes its ProgId or the browser is uninstalled, Windows skips that entry and falls back to its own default.

## Install the browser before the policy applies

The associations file only works when the ProgIds exist, so order matters on new machines:

- Deploy the browser as a computer-assigned package, an Intune required app or part of the image, so it is installed at startup before the first user signs in. See [deploying software with Group Policy](/guides/deploy-software-with-group-policy/).

- Use the enterprise (system-level) installer. Per-user installs in the profile register their ProgIds only for that user and break the file for everyone else.

- Keep the browser updating itself or through your patching tool. Browser updates keep the same ProgIds, so the XML does not need to change for version updates.

- If you replace one browser with another, deploy the new browser first, then switch the XML, then remove the old browser.

## RDS hosts and Windows Server

The setting is also supported on Windows Server, so RDS session hosts can use the same approach. A few points differ:

- Link the GPO to the OU of the session hosts. Because it is a computer setting, every user on a host gets the same browser, whatever GPOs apply to their user account.

- Install the browser machine-wide on each host, in the same path on every host, so a Firefox hash or a ProgId matches on all of them.

- Sign-in time matters more on busy hosts. A local copy of the XML (copied with a GPP Files item) avoids a network read for every session.

- User profile disks and FSLogix containers keep the UserChoice keys between sessions, which is fine: the policy simply sets the same values again at each sign-in.

For servers that nobody browses from, leave the policy unlinked. A default browser Group Policy adds nothing on a domain controller or file server.

## Exceptions and targeting

- Different browsers for different teams need different XML files and GPOs, filtered by computer groups, because the policy is a computer setting. See [GPO security filtering](/guides/group-policy-security-filtering/).

- On RDS hosts every user of the host gets the same file. Build a host-specific XML if needed.

- Test machines can be excluded with a Deny on Apply group policy for a computer group.

- To set Chrome homepages and startup pages at the same time, see [setting the Edge and Chrome homepage](/guides/set-the-edge-and-chrome-homepage/).

## Verify it works

Test the default browser Group Policy with a user who has signed in before and with a brand-new user:

- Run `gpupdate /force`, then check the policy value:

```
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DefaultAssociationsConfiguration
```

- Confirm the computer can read the file: `type \\contoso.com\NETLOGON\DefaultApps.xml`.

- Sign out and sign in, then check the current user’s choice:

```
Get-ItemProperty "HKCU:\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice" | Select-Object ProgIdGet-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice" | Select-Object ProgId
```

- Open a link from Outlook or Teams and an `.html` file from Explorer; both should open in the chosen browser.

- Open **Settings » Apps » Default apps** and check the browser shows as the default for HTTP, HTTPS and .htm/.html.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Nothing changes after gpupdate | Associations apply at sign-in | Sign out and in |
| Browser not default for new users on new laptops | GPO not yet applied at first sign-in | Second sign-in; enable “Always wait for the network at computer startup and logon” |
| Photos, mail or video defaults changed | Full export deployed | Trim the XML to browser entries |
| Firefox entry ignored | ProgId hash differs because of a different install path | Export from a PC with the standard install path |
| Works on some PCs only | Browser missing, or share not readable at sign-in | Install the browser first; copy the XML locally with GPP |
| Intune value rejected or ignored | XML pasted instead of base64, or wrong encoding | Encode the UTF-8 file with the PowerShell above |
| Chrome or Edge keeps asking to become the default | Browser default-check prompt still enabled | Set “Set Google Chrome as Default Browser” or “Set Microsoft Edge as default browser” to Disabled |
| Script that set UserChoice stopped working | Hash protection and UCPD | Replace the script with the associations file policy |

The Application event log and **Settings » Apps » Default apps** rarely say why an entry was skipped, so test a new XML file on one PC before linking it widely.

## Roll back or undo

- Set “Set a default associations configuration file” to **Not Configured** (or unlink the GPO) and run `gpupdate /force`. The registry value is removed.

- Users keep the association they last received; Windows does not revert it. They can now change it in Settings, or you can deploy a new XML with the new browser first and remove the policy later.

- In Intune, remove the profile assignment and sync the device.

Keep the XML files in version control with a short note per change. A default browser Group Policy is easy to break with a stray line in the file, and the history shows which change caused it.

## Default browser Group Policy at a glance

**Official documentation:** [Policy CSP – ApplicationDefaults](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-applicationdefaults), [Export or import default application associations](https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/export-or-import-default-application-associations).

**Related guides:** [Set the Edge and Chrome Homepage with Group Policy: Easy Guide](/guides/set-the-edge-and-chrome-homepage/) · [Deploy Software with Group Policy: MSI Install Step by Step](/guides/deploy-software-with-group-policy/) · [Import ADMX templates (Office, Chrome, Edge) into Intune and the AD Central Store](/guides/import-admx-templates-intune/).

## Frequently asked questions

### Does the default browser Group Policy apply to existing users?

Yes. Windows applies the associations file at each sign-in, so existing users get the new default the next time they sign in. Running gpupdate alone does not change it.

### Can users still change their default browser?

They can change it in Settings, but associations listed in the file are applied again at the next sign-in. On Windows 11 22H2 and later, entries marked Suggested=”true” are applied once per Version value and users keep their own choice afterwards.

### Why not set UserChoice in the registry with a script?

UserChoice values are protected by a hash, and the User Choice Protection Driver blocks non-Microsoft processes from writing browser associations. Windows resets unsupported values, so the associations file policy is the supported method.

### Do I need to include PDF in the XML?

Only if you want to control which app opens PDF files. Leave .pdf out to keep each user’s choice, or add the line for your chosen reader copied from an export.

### Can Intune use the same XML file?

Yes. Encode the XML in base64 and set it in the Settings catalog under Application Defaults, or with the DefaultAssociationsConfiguration OMA-URI. The Intune policy takes precedence over the GPO.
