1.43 (L1) Ensure 'Allow importing of saved passwords' is set to 'Disabled'

Information

This policy setting controls whether users can import saved passwords from another browser into Microsoft Edge as well as whether passwords are imported on first use.

The recommended state for this setting is: Disabled.

Saved passwords that are automatically imported or allowing users to import password data from another browser into Microsoft Edge allows for sensitive data to be imported into Edge.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\Allow importing of saved passwords

Impact:

Users will be unable to import saved passwords from other browsers into Microsoft Edge.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 658f9b089ed2ea2dff84ef8f05c3b3d1432ae678bf08ce19d35bca9141de2262