โ๏ธ๐ช๐ปCP - Edge - Browser Experience
Edge opens already signed into the work account, syncing quietly, with no first-run tour and no consumer feed. The same managed browser on every device.
What this policy is about ๐ชโ
Left to itself, Edge greets a new user with a first-run tour, an import prompt, an MSN-flavored new tab page, and a nudge to sign in. This policy skips all of that and hands them a managed browser instead: automatically signed into the work account, a default work profile, and sync enforced without a consent prompt so favorites and settings follow the user across devices.
The result is that Edge behaves the same on every managed machine, and it does so on first launch, not after a user clicks through five prompts.
Forcing sync makes Edge consistent, but what syncs still respects your other policies. Password storage, for example, is decided by the Disable Password Manager baseline, not by this one. This profile handles the profile and the experience; the credential rules live in their own policy.
Why this matters ๐ต๏ธโ
A browser that each user sets up by hand is a browser configured differently on every device. One imports a personal profile, another skips sign-in, a third pins the MSN feed. Support becomes guesswork, and a personal identity in a corporate browser is a data path nobody chose.
Enforcing the work profile and sync removes that variance. The browser is signed into the identity you manage, its settings roam with the user, and the consumer surface is off. New starters get a browser that already works, and the helpdesk gets one configuration to reason about.
๐ ๏ธ Configurationโ
Where: Intune admin center โ Devices โ Configuration โ Create โ Windows โ Settings catalog โ Microsoft Edge.
| Setting | Value |
|---|---|
| Configure whether a user always has a default profile automatically signed in with their work or school account | Enabled |
| Default Profile Setting Enabled | Default |
| Browser sign-in settings | Enable browser sign-in |
| Force synchronization of browser data and do not show the sync consent prompt | Enabled |
| Hide the First-run experience and splash screen | Enabled |
| Automatically import another browser's data and settings at first run | Disabled (import section skipped) |
| Allow Microsoft content on the new tab page | Disabled |
| New tab page experience (default, user can override) | Office 365 feed experience |
Assignment: include All devices; exclude standard exclusion groups only.
Caveats โ ๏ธโ
Forced sync is a per-tenant decision. Enforcing sync without a consent prompt is convenient and consistent, but some customers have a reason to keep sync opt-in. Confirm it fits before you enforce it, rather than assuming.
The new tab page is a default, not a lock. That setting sits in the overridable namespace, so users can still change their new tab experience. If a customer wants it fixed, set it in the mandatory namespace instead.
Automatic import is off on purpose. New devices start clean rather than dragging a previous browser's bookmarks and saved data across. If a migration genuinely needs that import, this is the setting to revisit.
License and reversibility. Included in Business Premium. Clean-revert: unassign and Edge returns to its default first-run and sync behavior on the next policy refresh.
๐ Relatedโ
- โ๏ธ๐ช๐ปCP - Edge - Block non-company accounts: keeps the enforced sign-in tied to your own domain.
- โ๏ธ๐ช๐ปCP - Edge - Security Baseline: the hardening that sits under this experience.
You will remember nothing of the first-run tour. Edge just opens, signed in and synced, the same on every device. ๐ช