2.11.3 (L1) Ensure 'Enable saving passkeys to the password manager' is Explicitly Configured

Information

Google Chrome has a built-in password manager that is configured with the policy PasswordManagerPasskeysEnabled . The password manager allows the user to save and authenticate with passkeys. This policy is based on an organization's needs and must be explicitly set. This guarantees that all instances of the browser within an organization follows the same policy.

This policy can be set to:

- (1) Enabled
- (0) Disabled

If this policy is unset, it is treated as Enabled but can be configured by individual users.

Note: If PasswordManagerEnabled is set to Disabled, then PasswordManagerPasskeysEnabled cannot be Enabled.

The Google Chrome passkey password managed is Enabled by default and each organization should review and determine if they want to allow users to store passkeys in the Chrome Password Manager. If another solution is used instead of the built in Chrome option then an organization should configure the setting to Disabled.

Solution

To establish the recommended configuration via Group Policy, configure the following setting to either Enabled or Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Password manager\Enable saving passkeys to the password manager

Note: Leaving the policy to Not Configured removes the auditable artifact and is a fail.

Impact:

Organizationally dependent.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: bbea93cdd50796eb127cf5298555793c5de9760bfc7251bed7247cdfcc363dac