Emergency server help: get in touch

Proxy Settings Group Policy: 6 Reliable Methods for Windows 11

Push a proxy server, bypass list or PAC file to Windows 11 and Windows Server with Group Policy Preferences, registry values, WinHTTP, Edge and Chrome policies and Intune, then stop users changing it and verify every layer.

Published Updated 13 min read

A proxy settings Group Policy setup sends every Windows 11 and Windows Server user through the same proxy server, bypass list or PAC file, and stops them changing it. The work is split across three proxy stacks: WinINET (Edge, Chrome, Office and most desktop apps), WinHTTP (services such as Windows Update, Defender and many agents) and the browsers’ own policies. This guide covers each one, with the registry values behind them, the Intune equivalent and a way to check what a machine is really using.

Short answer: In a GPO linked to the user OU, go to User Configuration » Preferences » Control Panel Settings » Internet Settings, create an Internet Explorer 10 item, set the proxy on the Connections tab under LAN settings and press F5 so every field is applied. Enable “Prevent changing proxy settings” to lock it. If services also need the proxy, run netsh winhttp set proxy from a startup script, because WinHTTP does not read the user settings.

Which method to use

No single proxy settings Group Policy item covers every stack, so most domains combine two or three of these.

MethodStackScopeProsCons
GPP Internet Settings (IE 10 item)WinINETUserFull GUI; fixed proxy, PAC URL, auto-detect and bypass in one itemF5/F6 underline rules confuse people
GPP Registry valuesWinINETUserExact values; easy to targetYou must know the value names
PAC file or WPADWinINET, browsersUser or machinePer-URL logic; laptops go direct off-sitePAC server must be reachable; WPAD has security risks
netsh winhttp via startup scriptWinHTTPMachineCovers services running as SYSTEMNo ADMX; fixed proxy only
Edge and Chrome ProxySettings policyBrowser onlyMachine or userCannot be changed in the browserDoes not affect other apps
Intune NetworkProxy CSPWinINETDeviceCloud-managed devicesSeparate from GPO; test for conflicts

Prerequisites

  • Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
  • The proxy address and port (for example proxy.contoso.com:8080), the bypass list, and the PAC URL if you use one. Host PAC files on HTTP or HTTPS: WinINET no longer accepts file:// PAC paths by default.
  • Edge and Chrome ADMX files in the Central Store for the browser policies. Our guide on importing ADMX templates covers this.
  • A test OU with one user and one computer.

Where WinINET stores the settings

By default proxy settings are per user, under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:

ValueTypeMeaning
ProxyEnableREG_DWORD1 = use the fixed proxy, 0 = do not
ProxyServerREG_SZproxy.contoso.com:8080, or per protocol: http=proxy:8080;https=proxy:8080
ProxyOverrideREG_SZBypass list separated by semicolons; <local> means host names without a dot
AutoConfigURLREG_SZURL of the PAC file

Windows also keeps a binary copy in ...\Internet Settings\Connections\DefaultConnectionSettings, which the Settings app and Internet Options write. The GPP Internet Settings item keeps both in step, which is why we prefer it.

How WinINET chooses a proxy

When several options are ticked, WinINET works through them in a fixed order, which explains many “wrong proxy” tickets:

  1. Automatically detect settings (WPAD) is tried first.
  2. Use automatic configuration script (the PAC URL) is tried next.
  3. Use a proxy server for your LAN (the fixed proxy) is used only if the first two are off or fail.

Settings on an active VPN or dial-up connection override the LAN settings. So if a laptop on VPN ignores your fixed proxy, check the VPN connection’s own proxy page and the PAC logic before you blame the proxy settings Group Policy object. In most domains the cleanest design is one of these two: a fixed proxy with a bypass list and auto-detect off, or a PAC URL with auto-detect off. Mixing all three makes troubleshooting slow, because each client may stop at a different step.

Plan the GPOs

Keep user-side and computer-side work in separate objects so each can be filtered on its own:

  • USR – Proxy, linked to user OUs: the GPP Internet Settings item and the “Prevent changing proxy settings” lock.
  • CMP – Proxy WinHTTP, linked to computer OUs: the WinHTTP startup script and, where needed, per-machine mode.
  • CMP – Browser policies: Edge and Chrome ProxySettings, next to your other browser settings.

Name them clearly; when a proxy settings Group Policy change breaks access, the service desk needs to find the right object quickly.

Method 1: GPP Internet Settings item

  1. Create a GPO such as USR – Proxy and link it to the OU that holds the user accounts. For computer OUs, use loopback processing in merge mode.
  2. Go to User Configuration » Preferences » Control Panel Settings » Internet Settings, right-click and choose New » Internet Explorer 10. This item also applies to the WinINET settings on Windows 11.
  3. Open the Connections tab and click LAN settings.
  4. For a fixed proxy, tick Use a proxy server for your LAN, enter the address and port, tick Bypass proxy server for local addresses, then click Advanced and add exceptions such as *.contoso.com;10.*;192.168.*.
  5. For a PAC file, tick Use automatic configuration script and enter the URL, for example http://pac.contoso.com/proxy.pac. Untick Automatically detect settings unless you use WPAD.
  6. Press F5 on each tab you changed. A red dotted underline means the field will not be written; green means it will. F6 enables the current field, F7 disables it and F8 disables all fields on the tab.
  7. Click OK, run gpupdate /force on the test machine, sign out and sign in again.

On the Common tab you can add item-level targeting, for example by IP range or AD site, so each branch gets its local proxy from the same proxy settings Group Policy object.

Method 2: Registry values through GPP

If you only need a fixed proxy or a PAC URL, registry items are simpler to read in a report. Under User Configuration » Preferences » Windows Settings » Registry, create one Update item per value in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings: ProxyEnable (REG_DWORD 1), ProxyServer and ProxyOverride (REG_SZ), or AutoConfigURL for a PAC file.

The same values from PowerShell, for one user session:

$k = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Set-ItemProperty -Path $k -Name ProxyEnable -Value 1 -Type DWord
Set-ItemProperty -Path $k -Name ProxyServer -Value 'proxy.contoso.com:8080'
Set-ItemProperty -Path $k -Name ProxyOverride -Value '*.contoso.com;10.*;<local>'

Test Settings and a browser after a sign-in. If a value is not picked up, use Method 1, which also updates the binary copy.

Method 3: Per-machine proxy

On kiosks, shared PCs and RDS hosts you may want one proxy for every user. Enable Computer Configuration » Policies » Administrative Templates » Windows Components » Internet Explorer » "Make proxy settings per-machine (rather than per user)". It writes ProxySettingsPerUser = 0 (REG_DWORD) under HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings. After that, all users share one set of settings and only administrators can change them.

The Intune NetworkProxy CSP has the same switch (ProxySettingsPerUser, where 0 = machine-wide and 1 = per user, the default). Test this mode on one machine before a wide rollout: user-side GPP items no longer decide the proxy once it is on.

Method 4: PAC file and WPAD

For laptops that move between office and home, a PAC URL is usually the best proxy settings Group Policy option. A PAC file is JavaScript with a FindProxyForURL(url, host) function. It lets you send internal names direct and everything else to the proxy, and return DIRECT when a laptop is off the corporate network.

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || dnsDomainIs(host, ".contoso.com")) return "DIRECT";
  if (isInNet(dnsResolve(host), "10.0.0.0", "255.0.0.0")) return "DIRECT";
  return "PROXY proxy.contoso.com:8080; DIRECT";
}

Deploy the URL with Method 1 or AutoConfigURL. Serve the file with the MIME type application/x-ns-proxy-autoconfig.

WPAD (Automatically detect settings) finds the PAC file through DHCP option 252 or a DNS lookup of wpad.<domain>. Windows DNS Server blocks the name wpad by default through its global query block list, so a DNS-based WPAD record will not resolve until you change that list:

Get-DnsServerGlobalQueryBlockList
Set-DnsServerGlobalQueryBlockList -List "isatap"

Only do this if you understand the risk: anyone who can answer the WPAD lookup can proxy your traffic. An explicit PAC URL in a proxy settings Group Policy item is safer.

Method 5: WinHTTP proxy for services

WinHTTP is used by services running as SYSTEM: Windows Update, Defender for Endpoint, many backup and monitoring agents. It has its own machine-wide setting and no Administrative Template. Set it with netsh:

netsh winhttp set proxy proxy-server="proxy.contoso.com:8080" bypass-list="*.contoso.com;10.*;<local>"
netsh winhttp show proxy
netsh winhttp reset proxy

netsh winhttp import proxy source=ie copies the fixed proxy of the user running it, but not a PAC URL or auto-detect, so it is of little use in a startup script that runs as SYSTEM. To deploy WinHTTP settings:

  1. Save the set proxy line in \\contoso.com\NETLOGON\Proxy\winhttp.cmd.
  2. In a computer GPO, add it under Computer Configuration » Policies » Windows Settings » Scripts (Startup/Shutdown) » Startup. See logon and startup scripts with Group Policy.
  3. Restart a test server and run netsh winhttp show proxy.

Method 6: Edge and Chrome proxy policies

Browsers can take a proxy from their own policy, which overrides the system setting and cannot be changed by the user. In Edge the setting is Administrative Templates » Microsoft Edge » Proxy server » "Proxy settings", stored as ProxySettings (REG_SZ) under HKLM\SOFTWARE\Policies\Microsoft\Edge. Chrome uses the same JSON under HKLM\SOFTWARE\Policies\Google\Chrome.

{"ProxyMode": "fixed_servers", "ProxyServer": "proxy.contoso.com:8080", "ProxyBypassList": "*.contoso.com,10.*"}
{"ProxyMode": "pac_script", "ProxyPacUrl": "http://pac.contoso.com/proxy.pac"}
{"ProxyMode": "system"}

ProxyMode accepts direct, system, auto_detect, fixed_servers and pac_script. ProxySettings overrides the older separate policies (ProxyMode, ProxyServer, ProxyPacUrl, ProxyBypassList). Use system if you want the browser to follow the WinINET proxy you set above but stop users changing it inside the browser. Our guides on setting the default browser and the Edge and Chrome homepage use the same ADMX files.

Stop users changing the proxy

  • “Prevent changing proxy settings” in User Configuration » Policies » Administrative Templates » Windows Components » Internet Explorer (also available under Computer Configuration). It locks the proxy fields; the registry value is Proxy = 1 under HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel.
  • “Disable changing Automatic Configuration settings” in the same folder locks the PAC and auto-detect options.
  • Edge and Chrome ProxySettings, which users cannot override.

Standard users cannot change WinHTTP or per-machine settings anyway. Local administrators can change anything, so a proxy settings Group Policy lock is a control for standard users, not a security boundary; enforce egress at the firewall as well.

Exceptions and targeting

  • Item-level targeting on the GPP item: IP address range or Site for branch proxies, Security group for users who need a different proxy, Operating system to skip servers.
  • Security filtering on the whole GPO: deny Apply to a group such as Proxy-Exempt. See GPO security filtering.
  • Bypass list: always include internal DNS suffixes, Microsoft 365 endpoints you want direct if your network design allows it, and the PAC host itself.

Verify it works

  1. Confirm the GPO applied with gpresult /r /scope user (and /scope computer for WinHTTP and per-machine settings).
  2. Read the user values:
    reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer
    reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v AutoConfigURL
  3. Open Settings » Network & internet » Proxy. The manual proxy or script address should match what you deployed.
  4. Ask Windows which proxy it would use for a URL:
    $p = [System.Net.WebRequest]::GetSystemWebProxy()
    $p.GetProxy('https://www.microsoft.com')
  5. Check WinHTTP with netsh winhttp show proxy. “Direct access (no proxy server)” means the startup script did not run.
  6. In the browser, open edge://policy or chrome://policy to see ProxySettings, and edge://net-internals/#proxy for the effective proxy.

Troubleshooting

SymptomLikely causeFix
GPP item applied but fields are blankFields not enabled with F5/F6 (red underline)Edit the item, press F5 on each tab, save
Browser works, Windows Update or Defender failsWinHTTP still directDeploy netsh winhttp set proxy at startup
PAC file ignoredfile:// path, wrong MIME type, or server unreachableHost on HTTP(S); check the URL from the client
Internal sites go through the proxyMissing bypass entries or FQDN not matched by <local>Add *.contoso.com to the bypass list
Settings differ between users on one PCPer-user mode with targeting differencesCheck item-level targeting, or enable per-machine mode
Edge ignores the system proxyProxySettings policy set to another modeCheck edge://policy; use system mode
Nothing appliesGPO not processedSee Group Policy not applying

Roll back or undo

  1. GPP items leave their values behind when the GPO is removed. Before unlinking, change the item’s action to Delete (registry items) or clear the proxy tick box and press F5 (Internet Settings item), let it apply once, then remove the GPO. Ticking “Remove this item when it is no longer applied” on the Common tab does this automatically for registry items.
  2. Administrative Template settings such as “Prevent changing proxy settings” and per-machine mode are removed on the next refresh after you set them to Not Configured.
  3. WinHTTP: replace the startup script with netsh winhttp reset proxy for one boot cycle.
  4. Browser policy: set ProxySettings to Not Configured; Edge and Chrome pick up the change without a restart.

Roll out any proxy settings Group Policy change to a pilot group first and keep a direct-access admin account so you can recover if the proxy or PAC host goes down.

Proxy settings Group Policy at a glance

Proxy Settings Group Policy summary card: In a GPO linked to the user OU, go to User Configuration » Preferences » Control Panel Settings » Internet Settings…
In short: In a GPO linked to the user OU, go to User Configuration » Preferences » Control Panel Settings » Internet Settings, create an Internet Explorer 10 item, set the proxy on the Connections tab under LAN settings and press F5 so every field is applied.

Official documentation: netsh winhttp, Microsoft Edge ProxySettings policy, NetworkProxy CSP.

Related guides: Deploy registry settings with Group Policy Preferences · Default Browser Group Policy: Set Chrome or Edge on Windows 11 · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.

Frequently asked questions

What is the best way to deploy proxy settings with Group Policy on Windows 11?

Use a Group Policy Preferences Internet Settings item (Internet Explorer 10) under User Configuration, set the proxy on the Connections tab and press F5 so every field is applied. Add WinHTTP settings with a startup script if services need the proxy.

Why does Windows Update ignore my proxy GPO?

Windows Update and many services use WinHTTP, which does not read the user’s WinINET proxy. Set it with netsh winhttp set proxy from a computer startup script and check it with netsh winhttp show proxy.

Does netsh winhttp import proxy source=ie copy PAC files?

No. It copies only a fixed proxy and bypass list from the user who runs it. PAC URLs and automatic detection are not imported.

How do I stop users changing the proxy?

Enable “Prevent changing proxy settings” and “Disable changing Automatic Configuration settings” under Windows Components, Internet Explorer. For Edge and Chrome, set the ProxySettings policy, which users cannot override in the browser.

How do I make the proxy the same for every user on a PC?

Enable “Make proxy settings per-machine (rather than per user)”, which sets ProxySettingsPerUser to 0. All users then share one proxy configuration that only administrators can change.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.