You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VBA中Late Binding与Early Binding对比:IE对象实例化差异咨询

Differences Between InternetExplorer.Application and InternetExplorerMedium in VBA

Great question! Let's break down the core differences between these two IE automation objects, and why they behave differently with ADFS-protected web apps:

Key Differences

  • Process Integrity Level & Protected Mode

    • CreateObject("InternetExplorer.Application") launches IE in Low Integrity Level (Low IL) mode, which is IE's default "Protected Mode". This sandboxed environment restricts access to system resources (like local files, registry keys) and isolates site sessions to reduce security risks from malicious web content.
    • New InternetExplorerMedium launches IE in Medium Integrity Level (Medium IL) mode, bypassing Protected Mode entirely. This matches the behavior of older, non-protected IE instances, granting more access to local system resources and removing session isolation restrictions.
  • Authentication & Credential Access

    • Low IL (default IE) instances are blocked from accessing Windows' credential store (like saved AD domain credentials) and often can't leverage Windows Integrated Authentication seamlessly—critical for ADFS flows that rely on domain credentials to auto-authenticate users.
    • Medium IL instances have full access to system-level credentials, making them compatible with ADFS and other enterprise authentication systems that depend on Windows' built-in identity providers.
  • Cross-Site & Resource Access Restrictions

    • Protected Mode enforces strict cross-origin resource sharing (CORS) rules and limits interactions between sites from different security zones.
    • Medium IL mode relaxes these rules, which is necessary for older internal web apps or ADFS workflows that require cross-site redirects and resource access that would be blocked in Protected Mode.

Why Different Sites Require Different Objects

  • Public Internet Sites: Most modern public web apps are designed to work with IE's Protected Mode. They don't need access to local system resources, so InternetExplorer.Application works perfectly while maintaining a secure sandbox.
  • ADFS/Enterprise Internal Apps: These systems often rely on Windows Integrated Authentication, access to domain credentials, or cross-site redirects that Protected Mode blocks. The Medium IL environment of InternetExplorerMedium removes these restrictions, allowing the ADFS authentication flow to complete successfully (including redirects and credential lookup).
  • Legacy Web Apps: Older internal applications built before IE's Protected Mode was introduced often assume full access to system resources and shared session data. These apps will fail or behave unpredictably in Low IL mode, requiring InternetExplorerMedium to mimic the legacy IE behavior they were designed for.

内容的提问来源于stack exchange,提问作者zanza67

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:55:23