password
2 Topics"Never save password websites" group policy needed
We just deployed Edge to 1000+ devices in our organization but have discovered unwanted save password suggestions from the Password Manager. When users access an internal webpage that uses some kind of integrated windows authentication/SSO/NTLM/Kerberos etc. meaning the user is not prompted for a username and password - the password manager still suggests to save the username and password! There could be many other scenarios in an enterprise where you do not wish passwords on certain internal (or external) websites to be saved, but allow it for others. It looks like Edge automatically populates a list of websites or URL's where passwords are "never saved" and when a website is on that list Edge doesn't prompt if the user want to save the password. It would be very useful for an enterprise to have a Group Policy where we could prepopulate this list with websites we do not want the browser to save passwords for. The browser should of course still fill websites on this list that the user clicks "Never" to save, but so that the list could consist of both websites populated from the group policy and websites added by the user.15KViews4likes8CommentsIs this really an expected behavior? Edge automatically adds MSFT account to Windows 10
So yesterday I grabbed the latest Windows 10 ISO file and did a clean install of Windows 10 20H2. After installation finished and I entered the desktop for the first time, saw Edge stable (version 84) preinstalled; it was nice. I went ahead and clicked on sign in on Edge to start syncing and access my data (favorites, passwords etc.) I used my personal Microsoft account Email and Pass (SMS code for 2FA) and successfully signed in. I also clicked on the option that said allow this account to be used by other apps in Windows. after a minute or two, I watched my desktop background change, Windows theme change from default white to dark, so then I went to Windows 10 settings and saw the account I used to login into Edge was set as the main administrator account in Windows 10 and in fact Windows 10 used it to bring back my synced data, OneDrive used it to bring back my data. so far so good, it's all what I expected, this is what I was going to do anyway after all, but here is the worrying part and I don't think is right. Windows 10 used my Microsoft account from Edge for sign in, but my Microsoft password wasn't automatically set on Windows 10! If I wanted to manually sign into Windows 10 myself, It would ask me to login to my Microsoft account (same process as in Edge) and then Set my Microsoft account password as my Windows 10 password. so my Windows 10 was left password less and Pin less. I went to the Windows 10 settings to set a Pin and then It asked me to set a password first! I wanted Windows 10 password to be automatically tied to my Microsoft account password, as always, so that whenever I change my MSFT account password, my Windows 10 password changes too. but now I had to enter a custom password for Windows 10 manually that is not tied to my MSFT account password. so, I think this is clearly wrong and shouldn't happen. if Edge wants to pass over my MSFT account credentials to Windows 10 for sign in, it should do it properly and pass over my Password to Windows 10 as well to be used as my Windows password, do not only pass over my Email address to Windows 10 and leave my Windows 10 unprotected, while my account is set as an administrator.1.5KViews0likes5Comments