Deleting Undecryptable Passwords in Microsoft Edge with Intune
In today’s workplace, password management is one of the most critical aspects of both security and productivity. Microsoft Edge, widely used in organizations, includes a built-in password manager that helps users log in quickly without needing to remember every credential.
But what happens when saved passwords become corrupted or unreadable? In these cases, the password manager cannot function properly. Users may notice that saved credentials stop working or that certain websites are no longer auto-filled creating frustration and disruption in daily workflows.
This is where Intune policy control comes in. Through the Settings Catalog, IT administrators can enforce a policy that automatically deletes undecryptable passwords from the Edge database.
✨ The Result?
The password manager’s functionality is immediately restored
Users enjoy smooth, consistent sign-ins with valid credentials
Broken or unusable password entries are cleaned up automatically
Why This Policy Matters
Enabling this policy or even leaving it unset means that any undecryptable passwords saved in Microsoft Edge will be deleted automatically, while valid passwords remain untouched.
This ensures that users always have a functional password manager, free from corrupted entries that could otherwise cause login failures and generate IT support requests.
✅ Key Benefits
Removes corrupted and unreadable password entries automatically
Maintains smooth sign-ins with valid saved credentials
Reduces confusion and lowers IT helpdesk calls
Improves overall user productivity and experience
By keeping the password manager clean and reliable, organizations can balance security, usability, and efficiency more effectively.
Step-by-Step: Deploying the Policy with Intune
Earlier, we explored the importance of managing undecryptable passwords in Microsoft Edge. Now, let’s go through the steps to deploy this policy using the Microsoft Intune Admin Center:
1️⃣ In the Microsoft Intune admin center, go to Devices
2️⃣ Select Windows devices
3️⃣ Under the Policy section, choose Configuration profiles
4️⃣ Click on + Create and then select New Policy
5️⃣ In the Create a profile pane, set Platform = Windows 10 and later
6️⃣ Set the Profile type = Settings catalog
7️⃣ Click Create to proceed

⚠️ Default Behavior By default, Edge deletes undecryptable passwords even if the policy is not configured. Enabling the policy simply gives administrators explicit control, ensuring a consistent and transparent approach to managing these corrupted entries across the organization.
📌 Example Scenario
When organizations enable this policy, any corrupted or undecryptable entries in the password manager are removed, ensuring that all valid passwords remain usable.
👉 For example: An organization with 1,000 employees relies on Microsoft Edge’s built-in password manager for both internal and SaaS logins. Some users start reporting that autofill isn’t working. After investigation, IT discovers corrupted/undecryptable password entries in the database.
By enabling this policy through Intune, IT restores full functionality of the password manager for all staff at once.
Users only lose the broken entries
The password manager works seamlessly again across all devices
This demonstrates how the policy can boost reliability and reduce downtime across large environments.
📝 Define Basic Profile Details
After creating the profile, the next step is to define the basic details of your configuration. This section is important because it ensures the policy can be easily identified and managed later.
Here, you’ll provide a Name, a Description, and confirm the Platform (which defaults to Windows 10 and later).
✅ Suggested Name and Description
Name: Delete Undecryptable Passwords in Microsoft Edge
Description: This policy ensures that undecryptable or corrupted passwords in Microsoft Edge are automatically removed, allowing the password manager to remain functional and reliable for all users.
No changes are needed in the Platform field. Once the Name and Description are filled in, click Next to continue.

Configure the Policy in Intune
After defining the basic details, the next step is to configure the policy using the Settings Catalog. This is where you specify how Microsoft Edge will handle undecryptable passwords.
Follow the instructions below, referring to the screenshot for guidance:
1️⃣ On the Configuration settings page, click + Add settings.
2️⃣ In the Settings picker search bar, type Password Manager and Protection.
3️⃣ Click Search.
4️⃣ From the results, expand Microsoft Edge and select Password Manager and Protection.
5️⃣ Check the box for Enable Deleting undecryptable passwords (User).
6️⃣ In the main configuration pane, toggle the setting to Enabled.
When Enabled: undecryptable passwords are automatically removed, ensuring the password manager continues functioning with valid entries.
When Disabled: behaves the same as Enabled by default undecryptable passwords are still deleted but admins lose the ability to explicitly control the policy.
7️⃣ Finally, click Next to proceed.
⚡ Result: Enabling this setting guarantees that corrupted or unreadable password entries are removed from Microsoft Edge, keeping the password manager reliable and user-friendly across all devices.
✅ Observation
After selecting the Deleting Undecryptable Passwords in Microsoft Edge policy, you will be directed to the Configuration settings page.
Here’s what you need to know:
Policy Disabled by Default By default, the policy appears as Disabled. If you proceed without making changes, simply click Next, and Edge will continue its default behavior of deleting undecryptable passwords automatically.
Disabled (explicitly set) Setting the toggle to Disabled has the same effect as the default state undecryptable passwords will still be removed, but administrators do not gain explicit control.
Enabled Enabling the policy ensures that undecryptable or corrupted password entries are automatically deleted. This provides IT admins with clear visibility and control over how the password manager behaves, ensuring a consistent experience across the organization.
⚡ Key Point: Even though undecryptable passwords are deleted by default, enabling the policy allows administrators to manage and document the behavior explicitly through Intune which is important for governance, compliance, and transparency.

Configure Scope Tags (Optional)
The next step is the Scope tags tab. Scope tags are typically used to associate policies with specific groups or administrative units within your organization, especially in larger or delegated environments.
For this particular policy, scope tags are not required. If you don’t need to assign the policy to a custom scope, you can simply leave this section blank.
Click Next to continue to the Assignments step.

Assign the Policy to Target Devices
In the Assignments section, you'll define who will receive this policy. This step is essential, as it determines which users or devices the configuration will apply to.
To deploy this policy to a specific group:
Click on Add groups under the Include groups section. A list of available groups will appear use the search bar to quickly find the target group.
Once you've selected the appropriate group(s), confirm your choice. Click Next to move forward to the final step: Review + Create.

Review and Create the Policy
After completing the Assignments step, you'll land on the final tab: Review + Create.
This is your chance to review a full summary of the configuration including the basic details, selected settings, and group assignments. Take a moment to carefully review all entries to ensure everything is accurate and aligned with your intent.
If you need to make any changes, you can easily navigate back to the previous tabs and update the information as needed.
Once everything looks good, click Create to deploy the policy.
Your configuration will now be saved and pushed to the assigned devices based on the group you selected.

📊 Monitor Policy Deployment Status
After creating and assigning the Deleting Undecryptable Passwords in Microsoft Edge policy, it’s important to monitor whether the configuration has been successfully deployed to all targeted devices.
By default, Intune policy deployment can take up to 8 hours. To speed up the process, you can manually trigger a device sync using the Company Portal app or initiate a sync via the Intune Management Extension.
✅ How to Verify Deployment Status 1️⃣ In the Microsoft Intune Admin Center, navigate to: Devices ➝ Configuration profiles. 2️⃣ Use the search bar to locate the profile you created (e.g., Deleting Undecryptable Passwords – Microsoft Edge). 3️⃣ Click on the policy name to open its Overview page. 4️⃣ Review key deployment metrics such as:
Success
In progress
Error
Not applicable
This visibility ensures that the policy has been properly applied and allows administrators to take corrective actions if devices are non-compliant or experiencing deployment issues.

Client-Side Verification via Event Viewer
After manually syncing the device or waiting for Intune to automatically apply the policy, you can confirm that the Deleting Undecryptable Passwords in Microsoft Edge policy has been successfully enforced using Event Viewer on the client device.
This step is especially useful for troubleshooting or auditing deployments in compliance-focused environments.
✅ Steps to Verify Policy Application
1️⃣ Open Event Viewer on the target Windows device.
2️⃣ Navigate to: Applications and Services Logs ➝ Microsoft ➝ Windows ➝ DeviceManagement-Enterprise-Diagnostics-Provider ➝ Admin
3️⃣ In the right-hand pane, click Filter Current Log.
4️⃣ Look for Event ID 813 or 814 these indicate successful processing of Intune configuration profiles.
5️⃣ In the event details, verify that the setting “Delete undecryptable passwords (Microsoft Edge)” was applied successfully.
You may also see additional fields such as Enrollment ID, User SID, and Scope, depending on how the device was enrolled and how the policy was assigned.
💡 Pro Tip: Always ensure that the Event ID matches the correct timestamp and status. This is one of the most reliable ways to confirm whether the policy has been successfully applied, especially when troubleshooting delayed or failed deployments.
🔚 Conclusion
Managing passwords effectively is essential for both security and productivity in today’s workplace. The Deleting Undecryptable Passwords in Microsoft Edge policy, deployed via Intune, ensures that corrupted or unreadable entries are automatically removed keeping the browser’s password manager clean, reliable, and user-friendly.
By leveraging Intune’s Settings Catalog, IT administrators can take explicit control of this behavior, providing consistency, reducing helpdesk calls, and improving the end-user experience across the organization.
🔑 Key takeaway: Even though Edge deletes undecryptable passwords by default, enabling the policy through Intune gives administrators visibility, governance, and centralized control which are critical for compliance-driven environments.
🔍 More Information
DeletingUndecryptablePasswordsEnabled – Microsoft Learnhttps://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/deletingundecryptablepasswordsenabled
Microsoft Edge Browser Policy Documentation Complete reference list of all Microsoft Edge policies, including Password Manager and Protection. https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies
Configure Microsoft Edge Policy Settings with Microsoft Intune Step-by-step guide for creating configuration profiles for Microsoft Edge using Intune. https://learn.microsoft.com/en-us/deployedge/configure-edge-with-intune
Settings Catalog in Intune – Microsoft Learn Documentation on the Intune Settings Catalog for creating and assigning device policies. https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog
Thank you!
🖥️ Ricardo Barbosa
🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)
☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com
