Skip to main content

โš™๏ธ๐ŸชŸ๐Ÿ’ปCP - Edge - Browser Experience

Edge opens already signed into the work account, syncing quietly, with no first-run tour and no consumer feed. The same managed browser on every device.

โš™๏ธType Configuration profile๐ŸชŸPlatform Windows๐Ÿ’ปTarget Devices
reference-build ยท edge-browser-experienceGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Windows, device and user
Reversibility
clean-revert

What this policy is about ๐ŸชŸโ€‹

Left to itself, Edge greets a new user with a first-run tour, an import prompt, an MSN-flavored new tab page, and a nudge to sign in. This policy skips all of that and hands them a managed browser instead: automatically signed into the work account, a default work profile, and sync enforced without a consent prompt so favorites and settings follow the user across devices.

The result is that Edge behaves the same on every managed machine, and it does so on first launch, not after a user clicks through five prompts.

๐Ÿค” Sync scope is governed elsewhere

Forcing sync makes Edge consistent, but what syncs still respects your other policies. Password storage, for example, is decided by the Disable Password Manager baseline, not by this one. This profile handles the profile and the experience; the credential rules live in their own policy.

Why this matters ๐Ÿ•ต๏ธโ€‹

A browser that each user sets up by hand is a browser configured differently on every device. One imports a personal profile, another skips sign-in, a third pins the MSN feed. Support becomes guesswork, and a personal identity in a corporate browser is a data path nobody chose.

Enforcing the work profile and sync removes that variance. The browser is signed into the identity you manage, its settings roam with the user, and the consumer surface is off. New starters get a browser that already works, and the helpdesk gets one configuration to reason about.

๐Ÿ› ๏ธ Configurationโ€‹

Where: Intune admin center โ†’ Devices โ†’ Configuration โ†’ Create โ†’ Windows โ†’ Settings catalog โ†’ Microsoft Edge.

SettingValue
Configure whether a user always has a default profile automatically signed in with their work or school accountEnabled
Default Profile Setting EnabledDefault
Browser sign-in settingsEnable browser sign-in
Force synchronization of browser data and do not show the sync consent promptEnabled
Hide the First-run experience and splash screenEnabled
Automatically import another browser's data and settings at first runDisabled (import section skipped)
Allow Microsoft content on the new tab pageDisabled
New tab page experience (default, user can override)Office 365 feed experience

Assignment: include All devices; exclude standard exclusion groups only.

Caveats โš ๏ธโ€‹

Forced sync is a per-tenant decision. Enforcing sync without a consent prompt is convenient and consistent, but some customers have a reason to keep sync opt-in. Confirm it fits before you enforce it, rather than assuming.

The new tab page is a default, not a lock. That setting sits in the overridable namespace, so users can still change their new tab experience. If a customer wants it fixed, set it in the mandatory namespace instead.

Automatic import is off on purpose. New devices start clean rather than dragging a previous browser's bookmarks and saved data across. If a migration genuinely needs that import, this is the setting to revisit.

License and reversibility. Included in Business Premium. Clean-revert: unassign and Edge returns to its default first-run and sync behavior on the next policy refresh.


You will remember nothing of the first-run tour. Edge just opens, signed in and synced, the same on every device. ๐ŸชŸ