1.21.1 (L1) Ensure 'Enable saving passwords to the password manager' is set to 'Disabled'

Information

This policy setting controls the ability for users to save their passwords in Microsoft Edge.

The recommended state for this setting is: Disabled.

Saving passwords in Edge could lead to a user's web passwords being breached if an attacker were to gain access to their web browser especially in the case of an unattended and unlocked workstation.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\Password manager and protection\Enable saving passwords to the password manager

Impact:

Users will be unable to utilize the Microsoft Edge built-in password manager.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 84ff37198e33d81c5350e88679e1acb8fbf4d432c8e80d453ce7d7e502089ed9