Skip to main content

βš™οΈπŸͺŸπŸ’»CP - Edge - Disable Password Manager

The browser is not a vault. This stops Edge from offering to remember corporate passwords, so credentials live where you actually manage them.

βš™οΈType Configuration profileπŸͺŸPlatform WindowsπŸ’»Target Devices
reference-build Β· edge-disable-password-managerGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Windows, all devices
Reversibility
clean-revert, paired inverse

What this policy is about πŸ”β€‹

Edge offers to save every password a user types and then syncs it through their profile. That turns the browser into a credential store you do not govern, protected by nothing more than the Windows session. This policy switches saving off, and turns off Password Monitor alongside it because the manager it feeds is gone.

This is the default baseline. It goes to everyone, and the one team that genuinely needs Edge's manager gets it back through the paired inverse and its exception group, not by loosening this.

πŸ€” Off, so users reach for the right tool

The aim is not to make life harder. It is to stop the browser from quietly becoming the password vault. With saving off, passwords go where you can govern them: SSO, or the managed password manager the customer standardized on.

Why this matters πŸ•΅οΈβ€‹

Passwords saved in Edge ride along with the browser profile and its sync. Sign into a personal or second identity and those logins can travel to a device you do not manage. Hand a laptop to the next employee without a wipe and the credentials are still there behind an unlocked session. A vault with the door propped open is not a vault.

Keeping credentials out of the browser and inside a real password manager means one governed store, one set of controls, and no corporate logins quietly replicating elsewhere.

πŸ› οΈ Configuration​

Where: Intune admin center β†’ Devices β†’ Configuration β†’ Create β†’ Windows β†’ Settings catalog β†’ Microsoft Edge \ Password manager and protection.

SettingValue
Enable saving passwords to the password managerDisabled
Allow users to be alerted if their passwords are found to be unsafeDisabled
Assignment, includeAll devices
Assignment, excludeπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Edge Password Manager Allowed

Caveats βš οΈβ€‹

Exclusion is not the same as re-enabling. This writes a value that can persist on a device that already received it. Pulling a device out stops new enforcement; it does not necessarily switch the manager back on. That is exactly why the Enable inverse exists and is assigned to the exception group.

Give users somewhere to put passwords first. Disabling the browser manager only works if a sanctioned alternative is already in place, or users invent their own vault, and it is usually a spreadsheet named passwords_final_v2.

Password Monitor goes off too. That is deliberate: it belongs to the manager you are switching off. A tenant that genuinely keeps Edge as its manager wants monitoring on, which is what the Enable inverse restores.

License and reversibility. Included in Business Premium. Clean-revert on its own, though the exception path is the paired inverse rather than plain unassignment.


I'm sorry, Dave, I'm afraid I can't save that password. Send it to the vault you manage, and keep this the default for everyone else. πŸ”