Skip to content

Trusted Sites and Managed Applications

This tab allows you to configure authentication behavior for different browser zones and manage a list of explicitly trusted URLs.


Internet Zone Settings Logon (Intranet Zone) Specifies how user authentication is handled for resources within the corporate intranet zone. Logon (Trusted Zone) Defines the authentication method for trusted sites explicitly added to the Trusted Sites list. Logon (Internet Zone) Determines the login behavior for general internet sites that don’t fall under other zones. Logon (Restricted Zone) Sets the login method for high-risk or limited-access sites in the restricted zone. Each dropdown provides the following options:

  • Do not change – Keeps the existing setting unchanged
  • Automatic logon with current user name and password – Logs in automatically using the current Windows session credentials
  • Prompt for user name and password – Requires manual entry of credentials on each access
  • Automatic logon only in intranet zone – Enables automatic login only when accessing intranet resources
  • Anonymous logon – Connects without providing any user credentials

Trusted Site This section allows you to define a list of trusted URLs and assign them to specific zones. Trusted sites are typically internal company resources that require secure but streamlined authentication. Each trusted site entry contains:

  • Trusted Site – The base URL (e.g., https://cluster.example.local)
  • Comments – Optional notes or description for the resource (e.g., “Virtuworks RDS Cluster”)
  • Zone – Defines which zone the site is assigned to (e.g., Intranet, Trusted, Internet)

You can add a new site by entering the URL, an optional comment, selecting a zone from the dropdown, and clicking Add. To modify an existing record, click Edit, make your changes, and click Update.


This tab defines which software applications should be automatically installed and managed on target devices during policy enforcement. Each application in the list includes two toggles:

  • Enabled – If selected, the system will automatically deploy the application to the device.
  • Allow User Control – If enabled, end-users will have the ability to modify the application state (e.g., uninstall).

The following managed applications are available:

  • Install Azure Monitor – Enables remote monitoring of system performance and health via Azure Monitor.
  • Install ScreenConnect Agent – Installs the remote access tool for IT support and administration.
  • Install Microsoft Office 365 Apps – Installs the Microsoft 365 suite (Word, Excel, Outlook, etc.).
  • Install TerminalWorks TSPrint Client – Adds virtual printing support for remote desktop sessions.
  • Install TerminalWorks TSScan Client – Enables remote desktop scanning capabilities.
  • Install Purview Information Protection – Deploys Microsoft Purview client for data classification and compliance.
  • Install Microsoft Teams Client – Installs Microsoft Teams for collaboration and communication.
  • Install Google Chrome – Installs the Chrome browser.
  • Install Acrobat Reader DC – Adds the PDF reader from Adobe.
  • Install Mimecast Plugin for Outlook – Installs email security and archiving features via Mimecast.
  • Install Phish Alert Outlook Plugin – Adds anti-phishing reporting tools to Outlook.

  • Use a descriptive name for each policy that reflects its intended purpose or target device group (e.g., Remote Workstations – Hardened).
  • Start with the Device Profile tab to set foundational configurations such as disk cleanup and telemetry options.
  • Enable only the Security Hardening policies that match your organization’s risk tolerance and security baseline. Not all systems require maximum lockdown.
  • Review each Trusted Site and zone setting to ensure only internal, secure resources are whitelisted.
  • In the Managed Applications tab, install only the software essential for productivity and security to minimize system bloat.
  • Enable Allow User Control cautiously — only for applications or settings where user intervention is safe and supported.
  • Test each policy in a staging environment before deploying it across production devices.