π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed
What this group is forβ
This is a static assigned device group that carves an exception out of the tenant-wide block on Edge's password manager.
It works only as a pair with:
- βοΈπͺπ»CP - Edge - Disable Password Manager: the default baseline this group is excluded from.
- βοΈπͺπ»πCP - Edge - Enable Password Manager: the inverse policy assigned to this group, which switches the manager back on.
A device in this group is dropped from the block and actively handed the manager back, with autofill gated behind the device password. Membership is an exception, not a convenience.
π οΈ Group Configurationβ
| Setting | Value |
|---|---|
| Group name | π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed |
| Group description | Devices explicitly allowed to use Edge's built-in password manager, overriding the default disable baseline. Membership requires documented, approved justification. |
| Group type | Security |
| Membership type | Assigned (Device Group) |
β οΈ Governanceβ
Excluding a device from the baseline is only half the job; the inverse policy is what actually re-enables the manager, so both assignments must be in place. And because you are switching a credential control back on, the bar is high:
- A documented business reason per device.
- Written customer approval.
- A regular membership review (quarterly at least).
Good reason: a niche line-of-business web app that only works with Edge's own credential handling. Bad reason: "someone found it annoying." If you cannot defend a device's place here in an audit, it does not belong here.
π Relatedβ
- βοΈπͺπ»CP - Edge - Disable Password Manager
- βοΈπͺπ»πCP - Edge - Enable Password Manager
Keep it small. An exception group the size of the fleet is not an exception, it is a rollback wearing a disguise. π