For headless servers, ensure Edge is not launched interactively except for admin tasks. Use AppLocker or WDAC to restrict execution to admins only if needed.
Using PowerShell (on the server or a trusted machine):
If Edge updates an existing component, a reboot may still be required. Check %WINDIR%\Temp\MicrosoftEdgeSetup.log .
MicrosoftEdgeSetup-x64.exe /quiet /install
| Browser | Offline Installer | Enterprise Support | Chromium-based | Headless support | |---------|------------------|--------------------|----------------|------------------| | Microsoft Edge (Chromium) | Yes | Yes (GPO, Intune) | Yes | Yes (via --headless ) | | Google Chrome | Yes (via Chrome for Business) | Yes (GPO) | Yes | Yes | | Firefox ESR | Yes | Yes (policies.json) | No (Gecko) | Yes | | Internet Explorer 11 | Built-in | Legacy only | No | Limited |
Use a clean, internet-connected management workstation to download the installer. Then sign the hash (see section 4) and transfer via USB or secured share.