IT Admins - In order to use our Pin Protected App
You must disable Autofill for https://businesscentral.dynamics.com
Disable Browser Password Autofill for Business Central
Why is this required?
This application uses an authorised User ID and PIN for security-sensitive approval and posting processes.
Modern browsers such as Microsoft Edge and Google Chrome may automatically remember and re-enter User IDs and PIN numbers. This can undermine internal controls by allowing:
• PIN numbers to be stored on shared devices
• Users to unintentionally use another employee's credentials
• Sensitive authorisation processes to be bypassed
For maximum security we recommend that your IT department disables password manager and autofill functionality for Microsoft Dynamics 365 Business Central.
Microsoft Edge (Recommended)
Microsoft Edge supports an enterprise policy called PasswordManagerBlocklist which prevents passwords being saved or automatically completed for specific websites.
Using Group Policy
Open:
Group Policy Management
Navigate to:
Computer Configuration
Administrative Templates
Microsoft Edge
Password manager and protection
Enable:
Configure the list of domains for which the password manager UI (Save and Fill) will be disabled
Add:
https://businesscentral.dynamics.com
If your organisation uses a custom Business Central URL, add that URL as well.
Example:
https://businesscentral.dynamics.com
https://mybusinesscentral.contoso.com
Result
Users will no longer be able to:
• Save PIN numbers
• Save passwords
• Use browser autofill
• Automatically complete stored credentials
for Business Central pages.
Source: Microsoft Edge PasswordManagerBlocklist policy. [learn.microsoft.com]
Google Chrome
Google Chrome provides a similar enterprise policy called: PasswordManagerBlocklist
Using Group Policy or Chrome Enterprise
Configure:
PasswordManagerBlocklist
Add:
https://businesscentral.dynamics.com
Add any additional Business Central URLs used by your organisation.
Result
Chrome will not:
• Save passwords
• Save PIN numbers
• Autofill credentials
for the specified Business Central websites.
Source: Chrome Enterprise PasswordManagerBlocklist policy. [chromeenterprise.google]
Alternative: Disable Password Saving Completely
Some organisations may prefer to disable browser password managers across all websites.
Microsoft Edge
Set policy:
PasswordManagerEnabled = Disabled
Source: Microsoft Edge Enterprise Policy Documentation. [learn.microsoft.com]
Google Chrome
Set policy:
Enable saving passwords to the password manager = Disabled
Source: Chrome Enterprise Administration Documentation. [support.google.com], [activedirectorypro.com]
⚠️ This affects all websites and may generate support requests from users.
Verify the Configuration
After the policy has been applied:
• Close all browser windows.
• Re-open Business Central.
• Enter an Authorising User ID and PIN.
• Complete the transaction.
• Sign out and return to the page.
The browser should:
• Not offer to save the PIN.
• Not automatically populate the PIN.
• Not suggest stored credentials.
Recommended Configuration
✅ Disable Password Manager and Autofill only for Business Central URLs
This provides the best balance between:
• Security
• User experience
• Regulatory compliance
• Segregation of duties
while allowing users to continue using secure password management for other websites.
This is the approach I would personally recommend for your approval/PIN extension.