Admin ConsoleDeploy Client Apps

Deactivate Browser Password Managers Using Device Management

This article will direct you on how to disable various web browser's built-in password managers using group policy. These steps will help prevent corporate logins from being saved and synchronized to personal accounts. You may also consider deploying the Bitwarden browser extension to all browsers as part of this same policy.

Disable with Windows GPO

  1. Open Group Policy Management Editor on your managing Windows server.

  2. Download the appropriate Edge Policy Template.

  3. In Group Policy Editor, create a new GPO for Edge and provide an appropriate name.

  4. Choose your desired scope.

  5. Right-click the new Group Policy ObjectEdit.

  6. On the Group Policy Management Editor, go to User ConfigurationPoliciesAdministrative Templates Microsoft Edge.

  7. Set the following policies:

    • Open "Password manager and protection," disable the policy Enable saving passwords to the password manager.

    • Disable the policy Enable AutoFill for addresses.

    • Disable the policy Enable AutoFill for payment instruments.

    • Optionally, you can enable the policy Disable synchronization of data using Microsoft sync services.

    Once complete, the GPO settings should show the following:

    Edge Settings
    Edge Settings

  8. Ensure the GPO link is enabled.

How to check if it worked?

Check that the previous steps worked correctly for your setup:

  1. On a user's computer, Open the command line, and run:
    gpupdate /force.

  2. Open Edge, then click the three dots for settings ...SettingsPasswords.

  3. Ensure "Offer to save passwords" is turned off and managed by the organization.

note

Sign-in automatically is still checked because there is no policy setting to turn this off.

Any logins previously saved in Edge will not be removed and will continue to be displayed to the user, despite autofill being disabled. Be sure to instruct the user to import any saved logins into Bitwarden before deleting them from Edge.

Disable on Linux

To disable the Chrome Password Manager via group policy:

  1. Download the Google Chrome .deb or .rpm for Linux.

  2. Download the Chrome Enterprise Bundle.

  3. Unzip the Enterprise Bundle (GoogleChromeEnterpriseBundle64.zip or GoogleChromeEnterpriseBundle32.zip) and open the /Configuration folder.

  4. Make a copy of the master_preferences.json (in Chrome 91+, initial_preferences.json) and rename it managed_preferences.json.

  5. To disable Chrome's built-in password manager, add the following to managed_preferences.json inside of "policies": { }:

    Plain Text
    { "PasswordManagerEnabled": false }
  6. Create the following directories if they do not already exist:

    Plain Text
    mkdir /etc/opt/chrome/policies mkdir /etc/opt/chrome/policies/managed
  7. Move managed_preferences.json into /etc/opt/chrome/policies/managed.

  8. As you will need to deploy these files to users' machines, we recommend making sure only admins can write files in the /managed directory.

    Plain Text
    chmod -R 755 /etc/opt/chrome/policies
  9. Additionally, we recommend admins should add the following to files to prevent modifications to the files themselves:

    Plain Text
    chmod 644 /etc/opt/chrome/policies/managed/managed_preferences.json

  10. Using your preferred software distribution or MDM tool, deploy the following to users' machines:

    1. Google Chrome Browser

    2. /etc/opt/chrome/policies/managed/managed_preferences.json

note

For more help, refer to Google's Chrome Browser Quick Start for Linux guide.

Disable on MacOS

  1. Download the Google Chrome .dmg or .pkg for macOS.

  2. Download the Chrome Enterprise Bundle.

  3. Unzip the Enterprise Bundle (GoogleChromeEnterpriseBundle64.zip or GoogleChromeEnterpriseBundle32.zip).

  4. Open the /Configuration/com.Google.Chrome.plist file with any text editor.

  5. To disable Chrome's built-in password manager, add the following to com.Google.Chrome.plist:

    Plain Text
    <key>PasswordManagerEnabled</key> <false />
  6. Convert the com.Google.Chrome.plist file to a configuration profile using a conversion tool of your choice.

  7. Deploy the Chrome .dmg or .pkg and the configuration profile using your software distribution or MDM tool to all managed computers.

note

For more help, refer to Google's Chrome Browser Quick Start for Mac guide.

For additional information, see Chrome's documentation for setting up Chrome browser on Mac.

Suggest changes to this page

How can we improve this page for you?
For technical, billing, and product questions, please contact support