Information
This policy setting allows organizations to list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system via the File System API.
Note: Leaving the policy unset means DefaultFileSystemWriteGuardSetting (Control use of the File System API for writing) applies for all sites, if it is set. If not, users' personal settings apply.
Note #2: URL patterns can't conflict with FileSystemWriteBlockedForUrls (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.
The recommended state for this setting is: Disabled.
This API allows web apps to save changes directly to files and folders on user devices, beyond writing files. Allowing web apps the ability to save changes directly to files and folders opens the organization to malicious content to be saved directly onto user devices.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Disabled :
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Allow write access via the File System API on these sites
Impact:
Users with creative roles that require write access to files and directories via the File System API may need additional permissions granted for said roles.