Information
Firefox allows for credentials to be stored in its credential store for certain websites.
The recommended state for this setting is: Disabled
Stored credentials may be harvested by an adversary that gains local privileges equal to or greater than the principal running Firefox, which may increase the scope and impact of a breach. However, preventing Firefox from storing credentials will not prevent such an adversary from harvesting credentials used while compromised.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled :
Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Offer to save logins
Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this
link
.
Impact:
Credentials will not be stored on websites.