βοΈπͺπ»CP - Edge - Disable Password Manager
The browser is not a vault. This stops Edge from offering to remember corporate passwords, so credentials live where you actually manage them.
What this policy is about πβ
Edge offers to save every password a user types and then syncs it through their profile. That turns the browser into a credential store you do not govern, protected by nothing more than the Windows session. This policy switches saving off, and turns off Password Monitor alongside it because the manager it feeds is gone.
This is the default baseline. It goes to everyone, and the one team that genuinely needs Edge's manager gets it back through the paired inverse and its exception group, not by loosening this.
The aim is not to make life harder. It is to stop the browser from quietly becoming the password vault. With saving off, passwords go where you can govern them: SSO, or the managed password manager the customer standardized on.
Why this matters π΅οΈβ
Passwords saved in Edge ride along with the browser profile and its sync. Sign into a personal or second identity and those logins can travel to a device you do not manage. Hand a laptop to the next employee without a wipe and the credentials are still there behind an unlocked session. A vault with the door propped open is not a vault.
Keeping credentials out of the browser and inside a real password manager means one governed store, one set of controls, and no corporate logins quietly replicating elsewhere.
π οΈ Configurationβ
Where: Intune admin center β Devices β Configuration β Create β Windows β Settings catalog β Microsoft Edge \ Password manager and protection.
| Setting | Value |
|---|---|
| Enable saving passwords to the password manager | Disabled |
| Allow users to be alerted if their passwords are found to be unsafe | Disabled |
| Assignment, include | All devices |
| Assignment, exclude | π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed |
Caveats β οΈβ
Exclusion is not the same as re-enabling. This writes a value that can persist on a device that already received it. Pulling a device out stops new enforcement; it does not necessarily switch the manager back on. That is exactly why the Enable inverse exists and is assigned to the exception group.
Give users somewhere to put passwords first. Disabling the browser manager only works if a sanctioned alternative is already in place, or users invent their own vault, and it is usually a spreadsheet named passwords_final_v2.
Password Monitor goes off too. That is deliberate: it belongs to the manager you are switching off. A tenant that genuinely keeps Edge as its manager wants monitoring on, which is what the Enable inverse restores.
License and reversibility. Included in Business Premium. Clean-revert on its own, though the exception path is the paired inverse rather than plain unassignment.
π Relatedβ
- βοΈπͺπ»πCP - Edge - Enable Password Manager: the paired inverse that switches the manager back on for the approved exception group.
- π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed: the documented group the inverse is assigned to.
I'm sorry, Dave, I'm afraid I can't save that password. Send it to the vault you manage, and keep this the default for everyone else. π