βοΈπͺπ»πCP - Edge - Enable Password Manager
The counter-policy to the block. It does not just remove the restriction, it says the opposite out loud, and puts the device password in front of every autofill.
What this policy is about πβ
This is the deliberate exception to βοΈπͺπ»CP - Edge - Disable Password Manager, and it exists because of one Intune fact that trips everyone up: exclusion is not the same as re-enabling.
Disable the manager everywhere (good), one team genuinely relies on it (fine), so you pull their devices out of the block. Still off. The value already applied, and removing the assignment does not flip it back. To actually switch it on again you assign a policy that sets the opposite value, explicitly. This is that policy.
It re-enables saving and Password Monitor, and adds one thing the plain default never had: autofill is gated behind the device password, so a saved credential does not fill just because a screen was left unlocked.
Whenever a device-scoped setting has an exception group, it needs a matching policy that resets the value. Assign this to the π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed group and the manager comes back cleanly, no reimaging, no registry surgery.
π οΈ Configurationβ
Where: Intune admin center β Devices β Configuration β Create β Windows β Settings catalog β Microsoft Edge \ Password manager and protection.
| Setting | Value |
|---|---|
| Enable saving passwords to the password manager | Enabled |
| Allow users to be alerted if their passwords are found to be unsafe | Enabled |
| Ask users to enter their device password while using password autofill | With device password |
| Assignment, include | π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed |
| Assignment, exclude | None (only the approved exception group receives this) |
Setting saving back to Enabled is what actively overrides the disabled state, which is the only thing that truly lifts it. The device-password gate is what makes re-enabling defensible.
Caveats β οΈβ
Assign it narrowly or you have unblocked the fleet. This belongs on the approved exception group only. Point it any wider and you have re-enabled the browser vault for everyone, undoing the baseline.
It is only half the pair. This does nothing useful without the Disable baseline in place; the two are designed and reviewed together.
Governance is the real control. Every member of the group needs a documented reason, written customer approval, and a place in a regular review, or it becomes shadow IT with extra steps.
License and reversibility. Included in Business Premium. Clean-revert: unassign and those devices fall back under the disable baseline.
π Relatedβ
- βοΈπͺπ»CP - Edge - Disable Password Manager: the default this policy carves an exception out of.
- π‘οΈπͺπ»ππβοΈGroup - Edge Password Manager Allowed: the documented group this is assigned to.
Want control? Start with the disable baseline. Want an exception? Use this, narrowly, gated behind the device password, with the paperwork to back it up. π