Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to Manifest V3. The transition is intended to strengthen browser security, improve performance, and reduce the risks linked to legacy extension code.
Microsoft announced the change in Message Center notification MC1467356, published on September 4, 2026. The company plans to begin the enterprise rollout in early January 2027 and complete it by late April 2027.
The retirement will affect Microsoft Edge desktop users on Windows, macOS, and Linux across Canary, Dev, Beta, and Stable channels. Manifest files define an extension’s capabilities, permissions, background processes, and other operating behavior.
Microsoft to Retire Manifest V2 and Switch to V3
Browser extensions have widely used Manifest V2 for years, and it provides developers with more flexible access to browser resources. That flexibility can also create security concerns when extensions request broad permissions or load code remotely.
Manifest V3 introduces stricter controls designed to limit those risks. Microsoft said the newer extension framework enforces tighter permissions, prevents the execution of remotely hosted code, and reduces the attack surface associated with older Manifest V2 extensions.
The model also changes how extensions run background tasks, helping reduce unnecessary resource usage and improve browser performance.
During the consumer deprecation phase, Manifest V2 extensions will display warnings on the Edge Manage Extensions page at edge://extensions and on extension product pages in the Microsoft Edge Add-ons store.
Microsoft will also remove Manifest V2 extensions from Add-ons search results and block new installations from the store. Initially, consumer users may be able to re-enable disabled Manifest V2 extensions manually.
However, Microsoft said this option will gradually disappear as the retirement process progresses. Extensions that remain on Manifest V2 will eventually stop functioning in Edge.
Enterprise devices will receive a temporary exception during the consumer rollout. Administrators can use the ExtensionManifestV2Availability policy to maintain Manifest V2 support on managed endpoints if required.
This policy will be removed once enterprise deprecation begins, meaning Manifest V2 extensions will no longer work even on devices previously configured to allow them.
The change will affect organizations that deploy extensions through policies such as ExtensionInstallForcelist and ExtensionInstallAllowlist.
Administrators should identify deployed Manifest V2 extensions, determine whether Manifest V3 replacements are available, and update their deployment policies before the deadline.
Microsoft also advised developers to migrate internal and commercial extensions to Manifest V3. The Microsoft Partner Center will no longer accept updates for Manifest V2 extensions.
However, updates that convert an existing extension from Manifest V2 to Manifest V3 will continue to be accepted. New Manifest V2 extension submissions have already been blocked since July 2022.
Organizations should notify affected users early, especially when a legacy extension has no direct Manifest V3 replacement. Security teams and helpdesk staff should also prepare for support requests as older extensions are disabled.
Microsoft’s message states that all Manifest V2 migration work must be completed before enterprise deprecation, as no policy-based exception will remain afterward.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance appeared first on Cyber Security News.
