<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Internet Explorer’s Explicit Security Zone Mappings</title><link>http://blogs.technet.com/b/fdcc/archive/2011/09/22/internet-explorer-s-explicit-security-zone-mappings.aspx</link><description>Documents previously undocumented aspects about how explicit site-to-zone mappings are processed (including bugs), which registry keys contain effective settings and which are ignored, and describes the &amp;ldquo;ZoneMapKey&amp;rdquo; which is often mistakenly</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Internet Explorer’s Explicit Security Zone Mappings</title><link>http://blogs.technet.com/b/fdcc/archive/2011/09/22/internet-explorer-s-explicit-security-zone-mappings.aspx#3475838</link><pubDate>Tue, 17 Jan 2012 14:34:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475838</guid><dc:creator>eoxaal</dc:creator><description>&lt;p&gt;My testing in a Windows Server 2008 terminal server with IE7 contradicts your otherwise excellent article on one point.&lt;/p&gt;
&lt;p&gt;a) I find that a setting for a site in&lt;/p&gt;
&lt;p&gt;HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap&lt;/p&gt;
&lt;p&gt;takes precedence over any setting affecting the same site under&lt;/p&gt;
&lt;p&gt;HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap&lt;/p&gt;
&lt;p&gt;not the other way round as stated in the article.&lt;/p&gt;
&lt;p&gt;E.g. if foo.com is set as &amp;quot;trusted&amp;quot; in the HKLM policy, there is no way to override that zone assignment for foo.com or any sub domains of foo.com under HKCU.&lt;/p&gt;
&lt;p&gt;b) IP-address zone assignment also deserves a mention: Interestingly, making a zone assignment for an IP address in the machine site-to-zone policy precludes making a site-to-zone assignment *for any other* IP address under HKCU.&lt;/p&gt;
&lt;p&gt;However, a workaround (which I can not find documented anywhere) for this limitation is to create a key for the IP address you wish to assign to a zone directly under ZoneMap\Domains (instead of the documented entries under &amp;quot;Ranges&amp;quot;, that is:&lt;/p&gt;
&lt;p&gt;HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\x.y.z.w&lt;/p&gt;
&lt;div class="fdccReply"&gt;
&lt;p&gt;&lt;em&gt;[Aaron Margosis]&amp;nbsp; On&amp;nbsp;(a) you are probably correct - in general HKLM policies do take precedence over HKCU policies.&amp;nbsp; I think I may have copy/pasted lines from non-policy stuff earlier in the document (where HKCU overrides HKLM) and failed to re-order them when typing in the &amp;quot;Policies&amp;quot; part of the key path.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Your (b) finding is interesting - I&amp;#39;ll have to test that.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;15-May-2012: Finally had some time to look at (a) and confirmed what you found.&amp;nbsp; Computer policies do take precedence over User policies, as expected.&amp;nbsp; The bug was in my write-up here AND in IEZoneAnalyzer v3.5.0.3.&amp;nbsp; Both have been fixed.&amp;nbsp; Still need to investigate (b) above.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475838" width="1" height="1"&gt;</description></item><item><title>re: Internet Explorer’s Explicit Security Zone Mappings</title><link>http://blogs.technet.com/b/fdcc/archive/2011/09/22/internet-explorer-s-explicit-security-zone-mappings.aspx#3460455</link><pubDate>Thu, 20 Oct 2011 13:43:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3460455</guid><dc:creator>Ron D</dc:creator><description>&lt;p&gt;Great info Aaron. We are continually &amp;quot;adjusting&amp;quot; how to do our site-to-zone. I might add: one other major factor is if users are pointing to autopac files in IE: sites are assigned to Intranet Zone if the autopac rules states &amp;quot;return direct&amp;quot;.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3460455" width="1" height="1"&gt;</description></item></channel></rss>