Information
This setting controls the Device Bound Session Credentials (DBSC) capability within Google Chrome. When enabled, the browser uses hardware-backed cryptographic keys (such as the TPM on Windows or Secure Enclave on macOS) to bind web authentication sessions directly to the physical device and verifies device possession during token refreshes. This will allow Chrome to actively participate in cryptographic handshake protocols with compatible identity and SaaS providers (e.g., Google Workspace, Okta) to hardware-bind active sessions.
Session cookie theft via malware represents a critical vector for bypassing Multi-Factor Authentication (MFA) and gaining unauthorized access to enterprise environments. Left unconfigured or disabled, authentication cookies remain exposed and can be exfiltrated and reused from an unauthorized external device. Enforcing this policy ensures that short-lived session tokens cannot be used outside the context of the originating hardware. Setting this configuration can minimize the utility of stolen browser credentials.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Enables Device Bound Session Credentials :
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Sign-in Settings\Bind Google credentials to a device
Impact:
There should be no impact on the user.