Skip to main content

πŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Chrome Password Manager Allowed

What this group is for​

This is a static assigned device group that carves an exception out of the tenant-wide block on Chrome's password manager.

It works only as a pair with:

A device in this group is dropped from the block and actively handed the manager back. Membership is an exception, not a convenience.

πŸ› οΈ Group Configuration​

SettingValue
Group nameπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Chrome Password Manager Allowed
Group descriptionDevices explicitly allowed to use Chrome's built-in password manager, overriding the default disable baseline. Membership requires documented, approved justification.
Group typeSecurity
Membership typeAssigned (Device Group)

⚠️ Governance​

Excluding a device from the baseline is only half the job; the inverse policy is what actually re-enables the manager, so both assignments must be in place. And because you are switching a credential control back on, the bar is high:

  • A documented business reason per device.
  • Written customer approval.
  • A regular membership review (quarterly at least).

Good reason: a niche line-of-business web app that only works with Chrome's own credential handling. Bad reason: "someone found it annoying." If you cannot defend a device's place here in an audit, it does not belong here.


Keep it small. An exception group the size of the fleet is not an exception, it is a rollback wearing a disguise. πŸ”“