ADMX Guide

Configure Application Guard container precreation

Category

User Configuration > Administrative Templates > Microsoft Office 2016 > Security Settings > Trust Center > Application Guard

Scope

User

Registry Key

HKCU\software\policies\microsoft\office\16.0\common\security\applicationguard

Description

This policy setting determines if the Application Guard container, for isolating untrusted files, is pre-created for improved run time performance. If you enable this policy setting, you can specify the number of days to continue pre-creating an Application Guard container if the user has not opened a file with Application Guard. Pre-creating a container when the user logs in will decrease the wait time when opening an untrusted file. “65535” will configure Office to always create an Application Guard container when a user logs into Windows. "20" will configure Office to pre-create the container each time a user logs into Windows for up to 20 days after the last time the user opened an untrusted file using Application Guard. “0” will configure Office to never pre-create the container. Instead the container will only be created when a user opens their first untrusted file after logging into Windows. Note: if you configure Office to never pre-create a container then users will experience a longer wait when opening an untrusted file after logging into Windows. If you disable or don’t configure this setting, Office will use a built-in heuristic to pre-create the container. Note: This policy setting only applies to Microsoft 365 Apps for enterprise.