Skip to main content

โš™๏ธ๐ŸชŸ๐Ÿ’ปCP - Edge - Scareware Blocker

The full-screen 'YOUR PC IS INFECTED, CALL THIS NUMBER' page has a countermeasure now. This turns it on for every managed device.

โš™๏ธType Configuration profile๐ŸชŸPlatform Windows๐Ÿ’ปTarget Devices
reference-build ยท edge-scareware-blockerGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Windows, all devices
Reversibility
clean-revert

What this policy is about ๐Ÿšจโ€‹

Scareware is the scam that hijacks the full screen, blares a fake virus warning, disables the usual keys, and screams at the user to call a "Microsoft" number. Edge's Scareware Blocker uses a local machine-learning model to recognize those pages by how they look and behave, then breaks the takeover and warns the user before they panic.

This policy simply switches it on for every managed device. It runs on-device, so the page content never leaves the machine to be checked.

๐Ÿค” It catches the ones SmartScreen has not seen

SmartScreen blocks known-bad sites from its reputation list. Scareware Blocker is the complementary layer: it judges a page by its scam-like behavior in the moment, so a brand-new scare page with no reputation yet still gets caught.

Why this matters ๐Ÿ•ต๏ธโ€‹

Scareware does not exploit the computer; it exploits the person. A locked screen and a scary countdown are engineered to bypass judgment, and the user who calls the number hands over remote access or a credit card in minutes. It is one of the most effective attacks precisely because it needs no vulnerability, just a fright.

Turning the blocker on gives users a real chance to catch their breath. The takeover breaks, a warning appears, and the moment of manufactured panic loses its grip.

๐Ÿ› ๏ธ Configurationโ€‹

Where: Intune admin center โ†’ Devices โ†’ Configuration โ†’ Create โ†’ Windows โ†’ Settings catalog โ†’ Microsoft Edge \ Scareware Blocker settings.

SettingValue
Configure Edge Scareware Blocker ProtectionEnabled
Assignment, includeAll devices
Assignment, excludeNone (standard exclusions only)

Caveats โš ๏ธโ€‹

It is a recent Edge feature. Scareware Blocker needs a current Edge version to exist as a policy. On an old build the setting simply does nothing, so keep Edge updated for it to apply.

On-device detection, so it is not perfect. The local model catches the classic full-screen scare pattern; a cleverly disguised variant may still slip through. It is a strong extra layer, not a reason to drop user awareness or SmartScreen.

License and reversibility. Included in Business Premium. Clean-revert: unassign and the feature returns to its default state on the next policy refresh.


It's a trap, and now the browser says so first. One less panicked call to a fake helpdesk. ๐Ÿšจ