Allow files to download and save to the host operating
Do remember that once you or the IT admin enable this feature, all files that the user downloads will be available in the Downloads Folder. You will be able to open all files on the host and install it if applicable. This feature is available with Windows Enterprise with Microsoft Defender Application Guard feature installed, and Network Isolation policies configured.
After this, all files which you download will be available in a folder called Untrusted files nested inside the Downloads folder. WDAG creates this folder when you download the first file post-policy activation.
When this feature is off, and you try to run an EXE Application Guard will block it. This is applicable to any file from the internet. Application Guard makes sure that enterprise devices are not breached by any malware or untrusted software. Specially designed for Windows 11/10 and Microsoft Edge, it makes sure only trusted websites, and resources have access. However, with this option, users will have to be responsible for any risks of opening the files on the host. Read:
How to Enable Microsoft Defender Application Guard on Windows 11Windows Defender Application Guard Extension for Chrome, Edge, & Firefox.