Password · guide

The Edge password manager, and the profile that decides what it does

By Alberto Gulotta · Updated · 16 min read

The Edge password manager saves to your Microsoft account rather than to the machine, and reaches every device where you sign in to Edge. One condition decides whether you have it: Microsoft says it needs a personal account profile, and on a work or school profile an administrator may take features away.

Which Edge profile you are signed in with decides what the password manager can do On a personal Microsoft account the manager saves, syncs and stores passkeys. On a work or school account Microsoft says the manager is only available with a personal profile, that an administrator may restrict features, and that passkey syncing is not available for Entra accounts. THE PROFILE, NOT THE BROWSER, DECIDES Personal Microsoft account saves and fills passwords syncs them to every device where you sign in to Edge Work or school account “only available if you sign in with a personal account profile”, and an admin may restrict features Microsoft, on the passkey question: “Is syncing passkeys available on mobile or for work or school accounts (Microsoft Entra)? No, this functionality is currently not available for mobile devices or for Microsoft Entra accounts.” AI Tools Primer · figure
The same browser, the same menu, and a different answer depending on which account is signed in. Figure drawn by AI Tools Primer.

Where Edge keeps them, and the condition that decides whether it keeps them at all

The route is short. In Edge, select the three dots at the top right, then Settings, then Passwords and autofill, then Microsoft Password Manager; or type edge://settings/passwords in the address bar. Next to any entry, the right arrow opens it, the eye icon reveals the password, and Edit lets you change it. Microsoft notes that “you may need to enter your device PIN or password” first, which is the machine asking rather than the browser.

What is saved goes to the account, not the laptop: Microsoft’s wording is that a password “is stored securely and can be reused on any device where you sign in to Edge using your Microsoft account”. That is the whole sync story, and it is also the sentence that hides the condition.

Because Microsoft puts a note above it, and repeats the same note further down the page: “Microsoft Password Manager in Edge is only available if you sign in with a personal account profile. If you sign in with a work or school account, your IT Admin may restrict access to certain features.” A summary that says Edge syncs your passwords through your Microsoft account is describing the personal profile, and leaving out the sentence Microsoft prints twice on the same page.

There is a second sentence on that page worth carrying away, because it costs an evening if you learn it the hard way: “Changing the password in Microsoft Edge doesn’t change the password for the website.” The entry is a record of a password, not the password itself. Edit it here and you have edited your own note; the site still expects the old one.

What the Edge password manager does on a personal Microsoft account, and what Microsoft says about a work or school one
Personal Microsoft accountWork or school account
The password manager itself Available “Only available if you sign in with a personal account profile”, and an IT admin “may restrict access to certain features”
Passkeys synced across devices Windows 10 and above, Edge 142 and above “Not available… for Microsoft Entra accounts”
Saving new passwords On unless you turn it off An administrator can disable it; previously saved passwords still work
Exporting to a file On a desktop computer, to CSV Same, where the manager is available at all

The work or school profile, and who is actually deciding

If Edge on your work laptop will not save a password, nothing is broken. Microsoft documents the setting from the other side, in the policy reference an administrator reads, and it is worth knowing exactly what it does: with PasswordManagerEnabled turned off, “users can’t save and add new passwords, but they can still use previously saved passwords”.

That is a precise and slightly unusual shape, and it explains a confusing symptom. Old logins keep filling themselves in, so the manager looks alive; new ones silently refuse to stick. The policy applies per profile, it can be set as a hard rule or a default the user can override, and it has existed since Edge 77 on Windows and macOS, Edge 30 on Android and Edge 84 on iOS.

Passkeys are drawn the same way. Microsoft’s own answer, published on the Edge blog with the feature: “Is syncing passkeys available on mobile or for work or school accounts (Microsoft Entra)? No, this functionality is currently not available for mobile devices or for Microsoft Entra accounts.

None of that is a fault to report, and none of it is fixed by signing out and back in. It is a decision someone else made, written down where they made it. The useful move is to stop trying to repair the browser and either use the personal profile for personal logins or ask whoever manages the machine, with the policy name in hand.

Why this is the fact to lead with, rather than the menu path. Three of the five most visible pages on this question are Microsoft’s own, so the instructions are not what is missing. What is missing is that none of them stands next to the others: the condition on work profiles is in the support article, the passkey limit is in a blog post from November, the policy that stops a laptop saving anything is in a reference written for administrators, and the sentence about exporting from a phone is in a fourth place again. Put them in one page and the product looks different, and more honest, than any single page makes it look. That is the same test being applied across this group of guides: not which manager is best, but what each one does on its worst day, and whether the maker says so.

Passkeys, the separate PIN, and the ten attempts

In November 2025 Microsoft added passkey saving and syncing to the manager, rolling it out “in Microsoft Edge 142 on Windows for Microsoft Accounts”. The prerequisites are stated plainly: a Windows device version 10 or above, Edge 142 or above, and a Microsoft account.

Passkeys are not kept the way passwords are. Microsoft, in the FAQ: they “are stored securely in the cloud in an encrypted format and are additionally protected by a Microsoft Password Manager PIN”. And in the body of the same post, about that PIN: “which you’ll setup while creating passkey for the very first time”. So there is a credential here you did not consciously choose, made on your behalf at the first passkey — the same pattern Google uses, and the reason a new machine can ask you for something you have no memory of setting.

And there is a limit, stated in a single sentence in the FAQ: “For unlocking passkeys on a new device, you will have a maximum of 10 attempts to input the correct PIN.” Ten is the same number Apple applies to its own escrow service, arrived at independently by two companies solving the same problem, which is a decent sign that it is the right order of magnitude rather than an arbitrary one.

The way back is a device you still have: reset the PIN “from a device that already has passkey access”, through Edge Settings, Passwords and autofill, Microsoft Password Manager, Settings. Microsoft adds a detail nobody asked for and everybody should want: “all the unlocking and reset attempts of Microsoft Password Manager PIN are logged and integrity protected in the immutable Azure confidential ledger for added transparency”.

Unlocking Edge passkeys on a new device, and the ten attempts you get A passkey saved in Microsoft Password Manager is protected by a PIN created with the first passkey. On a new device you get a maximum of ten attempts, and Microsoft says every attempt and reset is recorded in an immutable ledger. A NEW DEVICE, AND THE PIN YOU MADE WITH YOUR FIRST PASSKEY Sign in to Edge with the same Microsoft account Enter the Manager PIN a maximum of ten attempts Passkeys unlocked and usable on this device Forgotten it? Reset it from a device that already has passkey access: Edge Settings › Passwords and autofill › Microsoft Password Manager › Settings. Microsoft adds that every unlock and reset attempt is logged “in the immutable Azure confidential ledger”. AI Tools Primer · figure
Ten attempts, the same number Apple sets on its own escrow service, arrived at independently. Figure drawn by AI Tools Primer.

Getting out, and the export that does not exist on a phone

From a desktop it is four steps: press Alt + F or open the three-dot menu, choose Passwords, choose Export passwords, then Export to confirm, and pick a place for the file.

Microsoft’s caution on that page is the standard one and deserves quoting whole: “Passwords exported to a CSV are not protected and will be visible to anyone who can see the exported file.” The advice that follows is more specific than most, and better: “once you have used the exported CSV file, we strongly recommend that you erase it” with SHIFT and DELETE together, which deletes it permanently rather than moving it to the recycle bin, and Microsoft adds that doing so “will not affect your passwords still stored securely in Edge”.

The limit is on the same page, in one line: “It’s not possible to export saved passwords from Edge for Android or iOS.” If the only place you use Edge is a phone, there is no door at all until you sign in to Edge on a computer. That is worth knowing before you decide where to keep a list you may one day want to move, and it is the sort of thing that only shows up when you go looking for the exit rather than the entrance.

Exporting from Edge works on a desktop computer and not on a phone On a desktop the path is Alt plus F, then Passwords, then Export passwords, then Export to confirm, and a CSV file is written. On Edge for Android and iOS Microsoft says exporting saved passwords is not possible. ON A DESKTOP COMPUTER Alt + F or the three dots Passwords the settings page Export passwords · Export to confirm a plain CSV, then SHIFT+DELETE the file ON EDGE FOR ANDROID AND IOS Microsoft: “It’s not possible to export saved passwords from Edge for Android or iOS.” The way out runs through a desktop, or it does not run. AI Tools Primer · figure
One door, and it is only on the desk. Figure drawn by AI Tools Primer.

Where the standard agrees, and where it explains the ten

Quoted from NIST SP 800-63B, Digital Identity Guidelines, read in full on 9 September 2026.

Using the browser’s manager is the expected behaviour “Verifiers SHALL allow the use of password managers and autofill functionality”. A site that fights the fill is the thing out of step.
And the generator is the reason it helps “Password managers have been shown to increase the likelihood that subscribers will choose stronger passwords, particularly if the password managers include password generators”. Edge has one on the same settings page.
A cap on attempts is a requirement, not a courtesy “Verifiers SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account.” That is what ten tries is: the standard asks for a limit, and Microsoft published theirs.

And the case where none of this is the real problem. If a saved password has stopped working, the manager is holding an old note and the account at the other end is what changed: changing a Microsoft password is the version of that closest to home, and resetting a Gmail password the commonest one overall. If a password of yours has surfaced in a leak, work through what to do after a data breach.

Every path, limit and quoted sentence above comes from Microsoft’s own pages on the dates below.

Where to start

Three ways in.

“Where are my saved passwords?”
The menu, and the condition on it — where they live
“It will not save anything at work.”
The policy behind that — work account
“It is asking for a PIN.”
Passkeys, and the ten attempts — passkeys and the pin

The same drawer, other lids

Every browser keeps a version of this list, and each answers the same four questions differently.

The accounts behind the saved copies

A password Edge saved is a copy of one that belongs somewhere else. When the copy stops working, the original is what changed.

Questions people also ask

Where is the password manager in Edge?

Three dots at the top right, then Settings, then Passwords and autofill, then Microsoft Password Manager; or type edge://settings/passwords in the address bar. The right arrow opens an entry, and you may be asked for your device PIN or password first.

Does Edge have a built-in password manager?

Yes, on a personal Microsoft account. Microsoft adds a condition worth reading: it is “only available if you sign in with a personal account profile”, and on a work or school account an IT administrator “may restrict access to certain features”.

Why can’t Edge save new passwords on my work laptop?

Most likely a policy rather than a fault. With PasswordManagerEnabled turned off, Microsoft documents that “users can’t save and add new passwords, but they can still use previously saved passwords” — which is exactly the symptom.

What is the Microsoft Password Manager PIN?

A separate credential created for you when you make your first passkey. It protects passkeys stored in your Microsoft account, and on a new device you get “a maximum of 10 attempts to input the correct PIN”. You reset it from a device that already has access.

Do Edge passkeys sync to my phone?

Not yet. Microsoft’s own answer is that syncing is “currently not available for mobile devices or for Microsoft Entra accounts”. Saved passwords are a different matter and do travel with the Microsoft account.

How do I export passwords from Edge?

On a desktop: Alt + F, Passwords, Export passwords, then Export to confirm. The file is an unprotected CSV, and Microsoft recommends erasing it with SHIFT+DELETE afterwards. On Edge for Android or iOS, Microsoft says exporting is not possible.

Not covered here. It does not explain passkeys as a subject, only what the Edge manager does with them; and it does not tell an administrator how to deploy the policy, only who is holding the switch.

It does not rank password managers against each other, which needs paid subscriptions and months of use; the way in from here is the guides on passwords and the ways in. What holds instead is simple: every path, limit and quoted sentence comes from Microsoft’s own support pages, policy reference and Edge blog, each on the date shown, the product page explore.microsoft.com is deliberately not used as a source of fact, and the clauses on managers and rate limiting are quoted from the NIST publication.

Sources

  1. Microsoft Support — View or edit your passwords in Microsoft Password Manager: the menu path and the device PIN prompt, that a saved password can be reused on any device where you sign in to Edge with your Microsoft account, the note that the manager is only available on a personal account profile and that an IT admin may restrict features, and the warning that changing a password in Edge does not change it on the website — support.microsoft.com, read 9 September 2026.
  2. Microsoft Edge Blog — Microsoft Edge introduces passkey saving and syncing with Microsoft Password Manager, 3 November 2025: the rollout in Edge 142 on Windows, the Microsoft Password Manager PIN created with the first passkey, the maximum of ten attempts on a new device, the reset from a device that already has access, the immutable ledger of attempts, and the answer that syncing is not available for mobile devices or Microsoft Entra accounts — blogs.windows.com, read 9 September 2026.
  3. Microsoft Support — Export passwords in Microsoft Edge: the four steps on a desktop, the caution that an exported CSV is unprotected, the SHIFT+DELETE recommendation, and the line that exporting is not possible from Edge for Android or iOS — support.microsoft.com, read 9 September 2026.
  4. Microsoft Edge Browser Policy Documentation — PasswordManagerEnabled: that disabling it stops users saving new passwords while previously saved ones still work, the versions it applies from, and that it works per profile. Last updated 22 May 2026 — learn.microsoft.com, read 9 September 2026.
  5. NIST SP 800-63B, Digital Identity Guidelines: the requirement that verifiers allow password managers and autofill, the finding on password generators, and the requirement that verifiers limit the number of failed authentication attempts — pages.nist.gov, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.