Intune Article

Blocking web push notifications with Endpoint Manager and why you should!

Admit it, we've all fallen foul of that annoying (and scary for some) popup that seems to rear it's ugly head after you've spent the last...

Blocking web push notifications with Endpoint Manager and why you should!

Admit it, we’ve all fallen foul of that annoying (and scary for some) popup that seems to rear it’s ugly head after you’ve spent the last 2 hours scouring the web for some dodgy website hosted in some dodgy area of the world so you can watch that all important boxing match you’ve been desperate to watch, and if you haven’t then you likely work on a service desk and have seen a user fall victim to it.

Migrated image 1

These popups that usually disguise themselves as legitimate anti-virus software notifications are no more than web push notifications, the very same ones like that of Facebook or Twitter, that notify you when someone liked your picture of last nights tea that you spent a good 30 minutes photographing, the only difference is that these ones are designed to scare you and ultimately bait you or your users into clicking a link and either providing personal information or advising them outright that they need to pay a fee to clean their computer or “renew” their anti-virus software.

These notifications only appear if a user has allowed the site to provide notifications, something which they will typically do when hastily searching the web for something they need and not thinking clearly about the consequences of their actions, it’s worth noting that these popups can also appear when browser windows are closed.

But, there is a way to stop this, or at least limit the exposure of your users to this kind of basic attack through Microsoft Endpoint Manager and I recommend you build this into your baselines for your browsers. In this blog post I will go through how to achieve this for Edge and Chrome as the settings are included in the Settings Catalog.

Go ahead and find your browser security baseline profile or create a new one based on the Settings Catalog and search for notification.

The Edge settings will be underneath Microsoft Edge\Content settings in Settings Catalog.

Migrated image 2

The two settings you want are

Migrated image 3

Migrated image 4

With these two settings you can configure the default settings but easily give yourself the option to whitelist specific sites if needed and I would advise configuring them like so.

Migrated image 5

For Google Chrome the settings are in a similar place.

Migrated image 6

Migrated image 7

Migrated image 8

Once pushed down to your devices, users will no longer be able to allow notifications from sites which will help stop these kind of scare tactics towards users.

Just keep in mind that this will stop them from being able to use this functionality for sites so be sure to allow any exceptions for legitimate sites that you allow within the business.

Related writing
Deployment guide 19 September 2023

Deploying MDE to macOS

This guide will get you up and running with MDE for macOS in no time.

8 min read
Intune 1 December 2022

How to manage your Microsoft Edge Enterprise Cloud Site List like a boss 😎

In this article I describe how to enable IE mode on your Intune enabled devices and how you can easily manage a corporate site list!

5 min read
Intune 2 March 2022

How to deploy wallpaper and lockscreen image to Windows Pro edition using Microsoft Endpoint Manager

As most of you may already know the built in configuration settings for deploying a wallpaper and lockscreen image within Microsoft...

5 min read
Site search

Find a practical answer

Start typing to search posts and deployment guides.

    Esc closes · Results are generated locally with Pagefind