Skip to main content

βš™οΈπŸͺŸπŸ’»πŸ”“CP - Edge - Enable Password Manager

The counter-policy to the block. It does not just remove the restriction, it says the opposite out loud, and puts the device password in front of every autofill.

βš™οΈType Configuration profile (inverse)πŸͺŸPlatform WindowsπŸ”“Action Re-enable, exception group
reference-build Β· edge-enable-password-managerGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Assigned exception group only
Reversibility
clean-revert

What this policy is about πŸ”“β€‹

This is the deliberate exception to βš™οΈπŸͺŸπŸ’»CP - Edge - Disable Password Manager, and it exists because of one Intune fact that trips everyone up: exclusion is not the same as re-enabling.

Disable the manager everywhere (good), one team genuinely relies on it (fine), so you pull their devices out of the block. Still off. The value already applied, and removing the assignment does not flip it back. To actually switch it on again you assign a policy that sets the opposite value, explicitly. This is that policy.

It re-enables saving and Password Monitor, and adds one thing the plain default never had: autofill is gated behind the device password, so a saved credential does not fill just because a screen was left unlocked.

πŸ€” This is the paired inverse

Whenever a device-scoped setting has an exception group, it needs a matching policy that resets the value. Assign this to the πŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Edge Password Manager Allowed group and the manager comes back cleanly, no reimaging, no registry surgery.

πŸ› οΈ Configuration​

Where: Intune admin center β†’ Devices β†’ Configuration β†’ Create β†’ Windows β†’ Settings catalog β†’ Microsoft Edge \ Password manager and protection.

SettingValue
Enable saving passwords to the password managerEnabled
Allow users to be alerted if their passwords are found to be unsafeEnabled
Ask users to enter their device password while using password autofillWith device password
Assignment, includeπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Edge Password Manager Allowed
Assignment, excludeNone (only the approved exception group receives this)

Setting saving back to Enabled is what actively overrides the disabled state, which is the only thing that truly lifts it. The device-password gate is what makes re-enabling defensible.

Caveats βš οΈβ€‹

Assign it narrowly or you have unblocked the fleet. This belongs on the approved exception group only. Point it any wider and you have re-enabled the browser vault for everyone, undoing the baseline.

It is only half the pair. This does nothing useful without the Disable baseline in place; the two are designed and reviewed together.

Governance is the real control. Every member of the group needs a documented reason, written customer approval, and a place in a regular review, or it becomes shadow IT with extra steps.

License and reversibility. Included in Business Premium. Clean-revert: unassign and those devices fall back under the disable baseline.


Want control? Start with the disable baseline. Want an exception? Use this, narrowly, gated behind the device password, with the paperwork to back it up. πŸ”“