Skip to main content

Frequently Asked Questions

Secure Download Manager doesn't delete or quarantine blocked files

No. Secure Download Manager only prevents direct execution of a downloaded file from the browser. The file remains in the user's Downloads folder, and the user can open it from there. The policy stops impulsive execution directly from the browser prompt, not access to the file itself.

Supported browsers

Secure Download Manager supports:

  • Google Chrome
  • Microsoft Edge
  • Opera
  • Mozilla Firefox

Secure Download Manager doesn't intercept downloads in other browsers.

Global Settings apply on the Computer side only

No. Global Settings are supported on the Computer side only. They apply to all users of the machines that receive the GPO. You can configure Exclusions Policies on either the Computer or User side.

Intranet downloads are blocked unless excluded

Yes, unless you add those sites to an Exclusions Policy. The block applies to all downloads in supported browsers, regardless of whether the source is an internet or intranet address. Add your internal download sites to the URL Pattern field of an Exclusions Policy if you want their files to execute normally.

Exclusions Policies can apply to computers

Yes. You can configure Exclusions Policies under Computer Configuration as well as User Configuration. Computer-side policies apply to every user who logs on to the machine. Global Settings, however, are always Computer-side only.

Customizing the user notification

Yes. Open Specify Global Settings P... and go to the General tab. Under Text Customization, enable any combination of the three fields: window title, notification title, and message body.

Custom text fields also support variables, including:

  • %DOWNLOADED_FILE_NAME% — the name of the blocked file
  • %DOWNLOADED_FILE_SOURCE_URL% — the URL the file was downloaded from
  • %DOWNLOADED_FILE_ZONE_ID% — the Windows Security Zone ID of the file

All standard PolicyPak process variables are also supported.

Secure Download Manager uses the existing PolicyPak CSE

No. Secure Download Manager uses the same PolicyPak client-side extension (CSE) already deployed for other components. Keep the CSE up to date to ensure Secure Download Manager support is included.

Behavior when a user runs a blocked file

Secure Download Manager blocks the execution attempt. If Show Management Notifications is set to YES, the user sees a notification dialog. The notification auto-closes after the configured number of seconds (default: 60), or the user can dismiss it manually. The file remains in the Downloads folder.

Sending email alerts for blocked files

Yes. Open Specify Global Settings P..., go to the Email tab, and configure the Use of email dropdown and the Send To field. The alert contains extended information about the process and the blocked network activity.

Support for non-domain-joined machines

Yes, when policies are delivered through PolicyPak Cloud or an MDM service such as Microsoft Intune. Group Policy delivery requires domain membership. See the MDM & UEM Tools topics for details.

Secure Download Manager in the ADM report

Yes. Both Global Settings and Exclusions Policies are included in the ADM report generated by PolicyPak. All configured values — including URL patterns, file extensions, and Item Level Targeting conditions — appear in the report alongside other component settings.

Difference between User processes and User and System processes scope

The Scope setting in the Exclusions Policy Editor controls which execution contexts the exclusion applies to:

  • User processes — covers only executions initiated by the logged-on user.
  • User and System processes — covers both user-initiated and system-initiated executions. This is the default and is recommended for most environments.