9.6 Configure 'Do not display the reveal password button'

Information



This policy setting allows you to hide the reveal password button when Internet Explorer
prompts users for a password. The reveal password button is displayed during password
entry. When the user clicks the button, the current password value is visible until the
mouse button is released (or until the tap ends).
If you enable this policy setting, the reveal password button will be hidden for all password
fields. Users and developers will not be able to depend on the reveal password button
being displayed in any web form or web application.
If you disable or do not configure this policy setting, the reveal password button can be
shown by the application as a user types in a password. The reveal password button is
visible by default.
On Windows 8 and later, if the 'Do not display the reveal password button' policy setting
located in

Computer Configuration\Administrative Templates\Windows
Components\Credential User Interface is enabled for the system, it will override this policy
setting. Configure this setting in a manner that is consistent with security and operational
requirements of your organization.

*Rationale*

This is a useful feature when entering a long and complex password, especially when using
a touchscreen. The potential risk is that someone else may see your password while
surreptitiously observing your screen.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Not Configured.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\Do not display the reveal password button

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|CM-6b., 800-53|IA-5, CSCv6|3.1

Plugin: Windows

Control ID: 99cd0e29bcb87a30b9200bac0be8c87ff4e0920037e1e348772a8902138581bf