UCF STIG Viewer Logo

The password manager function in the Edge browser must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-63709 WN10-CC-000245 SV-78199r1_rule Medium
Description
Passwords save locally for re-use when browsing may be subject to compromise. Disabling the Edge password manager will prevent this for the browser.
STIG Date
Windows 10 Security Technical Implementation Guide 2016-06-24

Details

Check Text ( C-64457r1_chk )
If the following registry value does not exist or is not configured as specified, this is a finding.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\MicrosoftEdge\Main\

Value Name: FormSuggest Passwords

Type: REG_SZ
Value: no
Fix Text (F-69637r2_fix)
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Edge >> "Turn off Password Manager" to "Disabled".

Note: This setting is incorrectly worded in Group Policy. Configuring to "Disabled" turns off the password manager. Configuring to "Enabled" turns it on.