Skip to content

Fine grained control over policies for specific sites.

Admins can use SitePolicies to apply policies to individual sites rather than the whole browser, for example turning the JIT engine off on untrusted sites, disallowing HTTP downgrades, or isolating sites in their own container.

The policy is made up of a list of rules that are evaluated in order. Each rule can contain:

  • Match: a list of sites. An empty list or missing property means to match all sites.
  • Exceptions: a list of sites which when matched bypasses this set of rules.
  • Policies: an object defining the site policies.

Currently the supported site policies are:

  • DisableJit disables the JIT engine for the site when true.

  • HttpsOnly stops the site from being loaded over plain HTTP when true. When it is false, HTTP is explicitly allowed for the site, which is how you carve a site out of a broader rule.

  • DisableServiceWorkers stops the site from registering or using service workers when true. Only http and https sites are affected, and sites relying on service workers for offline support or push notifications will lose those features.

  • Container loads the site in a dedicated container, keeping its cookies, storage, and logins separate from the rest of the browser. Setting Container in a rule turns container support on and locks it, so the user cannot switch it off. (Firefox 158)
    Accepts the following values:

    • id: (required) A non-empty identifier you choose for the container. Every rule that uses the same id shares one container.
    • ephemeral: An optional boolean. When true, the container's data is cleared after its last tab closes, and at shutdown. Defaults to false.

    Navigating to a matching site loads it in a new tab inside the container. These containers are not listed in the containers UI, they have no colored tab indicator, and the user cannot pick them from the container menu. When a container is no longer named by any rule, Firefox deletes it along with its data.

policies.json
{
"policies": {
"SitePolicies": [
{
"Match": [
"*.example.com"
],
"Policies": {
"DisableJit": true
}
},
{
"Exceptions": [
"*.example.org"
],
"Policies": {
"DisableJit": true
}
},
{
"Match": [
"*.example.net"
],
"Policies": {
"HttpsOnly": true
}
},
{
"Match": [
"*.example.com"
],
"Policies": {
"Container": {
"id": "work"
}
}
}
]
}
}
JSON schema
SitePolicies JSON schema
{
"type": "array",
"items": {
"type": "object",
"properties": {
"Match": {
"type": "array",
"items": {
"type": "string"
}
},
"Exceptions": {
"type": "array",
"items": {
"type": "string"
}
},
"Policies": {
"type": "object",
"properties": {
"DisableJit": {
"type": "boolean"
},
"HttpsOnly": {
"type": "boolean"
},
"DisableServiceWorkers": {
"type": "boolean"
},
"Container": {
"type": "object",
"properties": {
"id": {
"type": "string",
"minLength": 1
},
"ephemeral": {
"type": "boolean"
}
},
"required": [
"id"
]
}
}
}
},
"required": [
"Policies"
]
}
}

A wildcard * can be used to refer to all sites. For example this setting would disable the JIT for only *.example.com:

[
{
"Match": ["*.example.com"],
"Policies": {
"DisableJit": true
}
}
]

While this setting would disable the JIT on every site except *.example.org:

[
{
"Exceptions": ["*.example.org"],
"Policies": {
"DisableJit": true
}
}
]

This setting loads *.example.com in a container whose data is cleared once its last tab closes:

[
{
"Match": ["*.example.com"],
"Policies": {
"Container": {
"id": "company",
"ephemeral": true
}
}
}
]
Software\Policies\Mozilla\Firefox\SitePolicies (REG_MULTI_SZ) =
[
{
"Exceptions": ["*.example.com"],
"Policies": {
"DisableJit": true
}
}
]
<dict>
<key>SitePolicies</key>
<array>
<dict>
<key>Exceptions</key>
<array>
<string>*.example.com</string>
</array>
<key>Policies</key>
<dict>
<key>DisableJit</key>
<true/>
</dict>
</dict>
</array>
</dict>
FirefoxFirefox ESRFirefox Enterprise
Available since 150Available since 153Available since 150

CCK2 Equivalent: N/A
OMA-URI: SitePolicies
Preferences Affected: privacy.userContext.enabled, privacy.containers.switchDuringNavigation.enabled (locked on only when a rule uses Container)

  • HttpsOnlyMode policy covers all browsing and can be configured to let the user turn it off.
  • Containers policy sets up the named containers the user sees and can choose between, which are separate from the containers SitePolicies manages.