Endpoint Security
Your Browser Is Now Part of Your Security Perimeter
Chrome and Edge now hold sessions, credentials, extensions and access to critical business systems. They deserve the same deliberate management as the devices they run on.
9 min read — Altitude IT Support
The Device Is Managed. The Browser Running on Top of It Is Not.
A business in Greater Manchester has done many things right. Microsoft 365 Business Premium. MFA enforced. BitLocker on every device. Endpoint protection. Microsoft Intune managing the device estate. Management assumes the PCs are secure.
But visit any of those PCs and you may also find: Chrome signed into a personal Google account. Fifteen or twenty browser extensions — some installed years ago, some nobody recognises. Saved passwords, company card details and personal card details stored together. Browser sync quietly passing data to unmanaged personal devices. Mixed personal and work profiles sharing the same browser window.
Nobody has ever reviewed the browser configuration. Not because anyone decided it was acceptable, but because nobody thought of the browser as infrastructure.
The PC can be well managed while the browser sitting on top of it remains largely unmanaged.
The Browser Is Now the Business Workspace
For many employees, the browser is the primary working environment. They open it in the morning and close it at the end of the day. Inside it sits:
- Microsoft 365 — Outlook, Teams web, SharePoint
- CRM systems, accounting platforms, payroll
- Business banking and payment portals
- AI tools, document systems, HR platforms
- Customer portals, supplier portals, admin consoles
- Cloud storage, video conferencing, project management
That means the browser increasingly holds or handles active sessions, saved passwords, payment details, browser extensions, synced data, work profiles, session cookies, business history and account access. Securing the laptop but ignoring the browser leaves part of the business workspace unmanaged.
The Quick Answer
Business browsers should be managed as part of endpoint security.
At minimum, review:
- Browser version and patching
- Browser sign-in and sync
- Password manager settings
- Windows Hello / device verification
- Saved payment details
- Extensions installed and their permissions
- Work vs personal profiles
- Account MFA and passkey adoption
- Central browser policies
- User access and screen locking
The browser should not be treated as "just another app" if it is the main gateway to your business systems.
Chrome, Windows Hello and the Broader Lesson
Google Chrome can use Windows Hello — local device authentication such as PIN, fingerprint or face recognition — before revealing saved passwords, filling saved passwords, copying passwords or editing passwords in the Chrome password manager. Chrome also provides Windows Hello verification for saved payment autofill. This reduces the risk that someone who sits at an unlocked, unattended PC can immediately access saved credentials without additional verification.
This is a useful example of browser-level controls that rely on device identity. But it is one setting among many. The useful lesson is not one Chrome setting. It is that browser security increasingly depends on device identity and policy. A browser can only use Windows Hello on a device that is properly configured and maintained. The setting matters. The foundation matters more.
Chrome and Edge — A Balanced View
Chrome and Edge are both Chromium-based browsers with enterprise management capabilities. Neither is inherently more or less secure as a general statement. Business choice between them may depend on Microsoft 365 integration depth, existing management platform, policy requirements, extension ecosystem, Google Workspace usage and support model.
Edge integrates closely with Microsoft Entra, Intune and the Microsoft security ecosystem. Chrome has a mature enterprise management programme. Both receive frequent security updates. Both can be centrally managed with appropriate configuration. The more important decision is not Chrome versus Edge. It is whether whichever browser you choose is centrally managed.
Windows Hello
Windows Hello provides local device authentication using methods such as PIN, fingerprint or face recognition. Browser features, including credential autofill and payment autofill, can use Windows Hello to verify that the person at the device is authorised before sensitive stored information is used. This adds a local check that helps protect credentials and payment details if a device is left unlocked.
Windows Hello does not replace MFA for online accounts. These solve related but different problems. Windows Hello confirms the person at the device. MFA protects the online account. They solve related but different problems — and a business needs both.
Passwords in the Browser
Browser-integrated password managers can provide strong password generation, credential storage, autofill, breach and weak-password checks, and synchronisation. For users who currently reuse passwords, use spreadsheets, write passwords on paper, or maintain short memorable passwords for everything — a browser password manager is likely a meaningful improvement.
But businesses should decide deliberately which credential storage approach suits them: browser password manager, enterprise password manager, single sign-on, or passkeys. Each carries different management implications. The problem is not that passwords are stored in a browser. The problem is unmanaged credential storage — where nobody knows what is stored, who can access it, or what happens when an employee leaves.
Passkeys
Passkeys reduce reliance on reusable passwords and offer phishing-resistant authentication where supported. Windows Hello may act as the local authenticator for a passkey — the device biometric or PIN confirms the user, the passkey handles the authentication with the service. This is a meaningful improvement in security posture for accounts that support it.
Microsoft began retiring SMS and voice MFA in February 2027, which is moving the direction of travel towards stronger authentication. The long-term strategy should be fewer reusable passwords, not increasingly complicated password rules. Passkeys are part of that direction — where services support them, adoption is worth planning.
Browser Sync
Browsers may synchronise passwords, bookmarks, history, tabs, settings, extensions and payment information between devices, depending on account type and configuration. For a user signed into Chrome with a personal Google account, this synchronisation can include business passwords and browsing history flowing to personal devices that are not managed, not patched, and not protected by the company's endpoint controls.
Review whether browser sign-in is permitted, which account types are approved, whether sync is needed for the use case, and which categories of data are permitted to sync. Browser sync is convenient, but it can quietly move business data outside the device you thought you were managing.
Work Profiles and Personal Profiles
Users may mix personal Gmail, work Microsoft 365, personal saved passwords, business card details and personal online accounts inside the same browser profile. This creates confusion, data mixing, account mistakes and support complications.
Where appropriate, separate browser profiles for work and personal use can reduce mixing and help define a clearer work identity within the browser. However: a browser profile is not the same security boundary as a separate Windows account. Separation helps, but browser profiles should not be mistaken for full device-account isolation. Someone with access to the machine can typically still access profile data.
Shared Windows Accounts
If multiple employees share a single Windows login, the browser will also be shared — the same saved passwords, the same history, the same autofill, the same active sessions. There is no individual accountability, no individual audit trail, and no ability to track who accessed which business system at which time.
If five people use one Windows login, browser security is already compromised by design. Shared accounts should be replaced with individual accounts. This is a precondition for managing browser security at an individual level — and it aligns with basic access control principles that also sit within Cyber Essentials requirements.
Browser Extensions
Extensions may request access to websites, page content, clipboard contents, downloads, tabs and browser activity depending on the permissions they request and the user grants. An extension with broad permissions can read the content of pages the user visits — including login forms, banking pages, and business applications.
Businesses should review: which extensions are installed across the device estate, who publishes them, what permissions they hold, what business need they serve, and whether they are kept current. Where appropriate, allowlisting approved extensions and blocking unnecessary ones can significantly reduce exposure. An extension can have more access to your browser than the user realises.
Extension Sprawl
Over time a user may accumulate a grammar tool, a screenshot tool, a coupon extension, a PDF tool, an AI assistant, a password helper, and a note-taking extension. Some become unused. Ownership of extensions can change. Permissions may expand with updates. An extension that was harmless when installed may behave differently later. Browser extensions should have the same lifecycle thinking as installed software: approve, review, remove. The browser often becomes unmanaged because nobody thinks of it as infrastructure.
Saved Payment Details
Business users may save business card details, personal card details, and associated security codes in the browser password manager or payment autofill. A browser storing company payment details should not be treated as purely a convenience feature. Review who needs access to saved payment information, whether device verification is enabled before autofill, whether all saved cards are still appropriate, and whether the employee's purchasing authority matches the access the browser is providing. A browser storing company payment details should be treated as a financial access point, not just a convenience feature.
Sessions, Cookies and MFA
Modern web applications keep users authenticated through session tokens and cookies. Once a user has signed in and passed MFA, the browser holds an authenticated session. This means that access to an already-authenticated browser — on an unlocked, unattended device — can sometimes allow access to business systems without re-entering credentials.
This is why screen lock, endpoint security, browser patching, and extension control still matter even when MFA is in place. MFA protects the sign-in. It does not make an already authenticated browser session worthless to an attacker. The active session requires the same device and physical access controls as everything else on the machine.
Phishing and the Browser
The browser is where phishing links are opened. A user who clicks a link in an email arrives at a malicious page inside the browser, where credential theft attempts typically happen. Controls that reduce risk include browser reputation services (Google Safe Browsing in Chrome, Microsoft Defender SmartScreen in Edge), endpoint security, email security, MFA and passkeys, and user awareness. The browser is often where the phishing email becomes a credential theft attempt. No single control eliminates phishing — defence in depth across email, browser, endpoint and authentication provides better protection than any one layer alone.
Browser Patching
Browsers are internet-facing applications that receive frequent security updates, sometimes addressing actively exploited vulnerabilities within days of discovery. Running an out-of-date browser is running internet-facing software with known vulnerabilities. Businesses should run supported current versions of their approved browsers, permit automatic updates, monitor for update failures, and ensure users restart browsers when updates are available. A browser is internet-facing software. Keeping it current is not optional housekeeping.
Central Management
A security setting is most effective when IT can verify it is applied correctly across every device — rather than hoping each user has configured it correctly themselves. Central browser management policies remove the dependency on individual user configuration.
Google Chrome Enterprise provides policy controls that can cover extension management, browser sign-in permissions, sync controls, password manager settings, autofill behaviour, update management and security configuration. These can be delivered through Chrome Browser Cloud Management or via configuration profiles through supported MDM tools. Verify current policy capabilities and supported delivery methods at the Chrome Enterprise documentation before implementation.
Microsoft Edge can be managed using Microsoft Intune, Group Policy, and Microsoft Edge management policies. Edge policies cover extension management, update settings, password manager, autofill, sync, security features and SmartScreen configuration. Verify current Edge policy documentation at Microsoft Learn before implementation — the available policy set evolves regularly.
Do not invent specific policy names. The documentation should be the source of truth for current capabilities. Central management turns browser security from user preference into business policy.
Microsoft Intune
For managed Microsoft environments, Intune can support browser and device management through device configuration profiles, compliance policies, application deployment, update management, security baselines and — for Edge specifically — Edge browser policies. Chrome can also be managed through Intune using supported configuration profile methods, though the depth of integration differs. Verify current supported methods for both browsers at Microsoft Intune documentation before planning an implementation.
The Microsoft 365 Security Baseline reviewed through Altitude's Microsoft 365 Security Baseline Review covers Entra identity, Conditional Access and endpoint compliance. Browser configuration is a complementary layer. Strong cloud identity is most effective when the browser and device accessing it are also controlled.
The Business Browser Security Stack
The Altitude Business Browser Security Stack
Browser security is a stack, not a single setting.
Business Browser Security Checklist
Review each area for your business:
Device
- ☐ Supported Windows 11, current patches
- ☐ Screen lock enforced
- ☐ BitLocker enabled
- ☐ Endpoint protection active and healthy
Identity
- ☐ Individual Windows account per user (no shared logins)
- ☐ Windows Hello configured
- ☐ MFA / passkeys in use
Browser
- ☐ Current Chrome / Edge version running
- ☐ Automatic updates permitted and working
- ☐ Browser sign-in policy understood and reviewed
- ☐ Sync policy reviewed and controlled
- ☐ Work profile defined and used appropriately
Passwords
- ☐ Password storage strategy documented
- ☐ Windows Hello verification reviewed for autofill
- ☐ Passkeys used where practical
Payments
- ☐ Company card access reviewed per user
- ☐ Payment verification enabled where appropriate
- ☐ Saved cards reviewed and unnecessary cards removed
Extensions
- ☐ All installed extensions inventoried
- ☐ Unnecessary or unknown extensions removed
- ☐ Permissions for remaining extensions reviewed
- ☐ Approved extension list used where appropriate
Management
- ☐ Browser policies documented
- ☐ Devices centrally managed
- ☐ Browser policy reviewed when staff leave
- ☐ Any exceptions to policy are documented
Browser Security Scorecard
Assess each area as Controlled, Partial, Needs Attention, or Unknown:
- Patching — are browsers running current supported versions on all devices?
- Identity — individual accounts, Windows Hello, MFA and passkeys in place?
- Passwords — credential storage approach documented and managed?
- Payments — saved payment access reviewed and verified?
- Sync — sync policy understood and controlled?
- Extensions — estate inventoried, permissions reviewed, unnecessary ones removed?
- Central Management — browser policies deployed centrally rather than relying on individual user configuration?
- User Separation — no shared Windows accounts; work and personal profiles appropriately separated?
No invented numerical percentage. The output should identify: Biggest Gap (what creates the most immediate risk), Quickest Win (what can be improved today without major changes), and Next Action (what to tackle first in a planned programme).
Cyber Essentials and Browser Security
Cyber Essentials does not specifically require Chrome Windows Hello autofill verification. Do not treat any single browser setting as the path to Cyber Essentials compliance. However, browser security intersects naturally with several Cyber Essentials requirement areas: supported and patched software, access control, user accounts, secure configuration and authentication. Running a supported, patched, configured browser with appropriate access controls and no shared accounts supports good security practice broadly. Browser settings can support good security practice, but there is no single Chrome switch that makes a device Cyber Essentials compliant.
Operational Heartbeat
Browser risk changes continuously. Browser versions update. New extensions appear. Users change accounts. Sync settings drift. Payment details change. Passkey support expands to new services. Browser policies evolve. Staff join and leave.
A one-time browser review is valuable. A recurring review is more valuable still. Recurring review can cover browser version, patch status, extensions, browser sign-in, sync, password manager, Windows Hello, passkey adoption, shared accounts, and policy exceptions — regularly rather than by exception.
Business browsers need an Operational Heartbeat: versions, extensions, saved credentials, authentication, sync and management policies should be reviewed rather than assumed to remain secure.
Common Mistakes
- Unmanaged Chrome installs with no central policy
- Users signed into personal Google or Microsoft accounts in the work browser
- Shared Windows logins — multiple staff, one account, one browser history
- Saved business payment details for users who do not need them
- Password autofill with no local device verification
- Weak authentication on the Google or Microsoft account that controls browser sync
- Dozens of extensions across the estate, with no inventory and no review
- Extensions nobody remembers installing and nobody is responsible for
- Browser updates disabled because they cause a prompt mid-meeting
- Inconsistent Chrome and Edge use across the team with no documented policy for either
- Assuming MFA solves browser session risk — it protects the sign-in, not the open session
- No central browser policy — security depends entirely on individual user choices
- No off-boarding process for browser access — saved passwords and sessions not reviewed when staff leave
- Mixing personal and work browser profiles with no separation
- Believing browser profiles provide full device-level isolation
What Should Management Ask IT?
- Which browsers are approved for business use?
- Are they centrally managed with policy, or individually configured?
- Are they fully patched on every device?
- Can staff sign into personal browser accounts on work devices?
- What sync is permitted, and where does synced data go?
- Where are passwords stored, and who manages that approach?
- Are passkeys being used where services support them?
- Are saved payment cards allowed, and who has reviewed access?
- Which extensions are installed across the business?
- Can extensions be centrally controlled?
- Are any shared Windows accounts in use?
- Are browser policies and saved access reviewed when staff leave?
If nobody knows which extensions are installed across the company, browser security is probably not being managed yet.
The Altitude IT View
The browser used to be a way to view websites. For most business users in 2026, it is the main application platform — the place where Microsoft 365, CRM, banking, accounting, AI tools and cloud services are all accessed and managed throughout the working day.
That change in what the browser does has not always been matched by a change in how it is managed. Endpoint security received attention. Microsoft 365 configuration received attention. The browser — running in between them, holding sessions, extensions, passwords and payment details — sometimes did not.
Businesses should not panic about Chrome or Edge. They should patch them, standardise them, manage extensions, control sync, protect credentials, use Windows Hello, adopt passkeys where practical, and use central policies where possible.
The browser is no longer just where employees browse. It is where employees work.
If the browser is the doorway to Microsoft 365, banking, CRM, accounting and AI tools, it deserves the same deliberate management as the laptop underneath it. For Manchester and North West businesses building that broader security approach, Altitude supports endpoint management, Microsoft Intune, Entra identity, Windows 11 device management and Microsoft 365 security as an integrated managed service — not as separate one-off reviews.
Related Reading
- Microsoft 365 Security Baseline Review — browser security complements Entra identity and Conditional Access
- Passkey Migration for Microsoft 365 — moving from SMS MFA to passkeys
- Microsoft SMS MFA Retirement 2027 — what the retirement means and how to prepare
- Slow Windows 11 PCs? Optimise, Upgrade or Replace — device lifecycle and the managed device foundation browser security depends on
- Altitude Security Services — broader cyber security and endpoint protection
- Cyber Essentials Manchester — supported software, access control and authentication requirements
- Our Approach and Operational Heartbeat — how Altitude delivers proactive managed IT support
- IT Support Manchester — managed IT support for Manchester businesses
Frequently Asked Questions
Why does browser security matter for businesses?
The browser is now the primary workspace for most business users — Microsoft 365, banking, CRM, accounting, AI tools and cloud storage are all accessed through it. That means the browser holds active sessions, saved passwords, payment details, extensions with broad access permissions, and synced data. An unmanaged browser represents an unmanaged part of the business workspace, even when the device underneath it is well managed.
Is Chrome safe for business use?
Chrome receives frequent security updates, supports enterprise management policies, and has comprehensive security features including Safe Browsing and Windows Hello integration. Whether Chrome is appropriately safe for business use depends on how it is configured and managed, not on the browser alone.
Is Edge safe for business use?
Edge receives frequent security updates, integrates with Microsoft Intune and Entra, supports SmartScreen and a range of enterprise management policies. As with Chrome, whether Edge is appropriately safe for business use depends on how it is configured and centrally managed.
Is Edge more secure than Chrome?
This is not a question with a simple universal answer. Both are Chromium-based, both receive regular security updates, and both can be centrally managed. Edge integrates more deeply with the Microsoft security ecosystem. Chrome has mature Chrome Enterprise management. The more important question for most businesses is whether whichever browser is in use is centrally managed — not which badge is on the browser.
Can Chrome use Windows Hello?
Yes. Chrome can use Windows Hello before revealing, filling, copying or editing saved passwords, and before filling saved payment details. This requires Windows Hello to be configured on the device. Verify current Chrome settings and rollout status at Google Chrome Help.
Can Edge use Windows Hello?
Yes. Edge supports Windows Hello for credential and payment autofill verification. Verify current settings and capabilities at Microsoft Learn.
Should businesses save passwords in browsers?
Businesses should decide deliberately what credential storage approach to use: browser password manager, enterprise password manager, SSO, or passkeys. A browser password manager is often better than reused simple passwords or spreadsheets. The key issue is that credential storage should be managed deliberately, not left to accumulate by default.
Are browser password managers secure?
They offer meaningful protections including strong password generation, breach alerts, autofill and sync. The risk is primarily about what happens when credentials are unmanaged — no review when staff leave, no understanding of what is stored, weak authentication on the browser account itself. Windows Hello verification before autofill reduces some exposure from unattended devices.
Should businesses use passkeys?
Where services support passkeys, adoption is worth planning. Passkeys are phishing-resistant and reduce reliance on reusable passwords. Windows Hello may serve as the local authenticator. The direction of travel from Microsoft and major services is toward passkeys and away from SMS MFA. Planning adoption is a reasonable near-term priority for most managed businesses.
Can Chrome sync work passwords to personal devices?
If a user is signed into Chrome with a personal Google account and sync is enabled, saved passwords may sync to that user's personal devices — which are not managed, patched or protected by the business's endpoint controls. This is one reason to review browser sign-in and sync policy as part of endpoint management.
Should employees sign into personal Chrome accounts on work devices?
This is a policy decision that businesses should make deliberately. Signing into a personal Chrome account on a work device can cause work data, including passwords and history, to sync to personal devices. Central Chrome Enterprise policies can restrict sign-in to approved account types where this is the preferred approach.
Are browser profiles secure?
Browser profiles provide useful separation of passwords, extensions, history and saved data. They are not the same as separate Windows user accounts. Someone with physical access to the device, or access to the Windows account, can typically access profile data. Browser profiles should not be treated as strong security boundaries.
Should employees share Windows accounts?
No. Shared Windows accounts mean shared browser sessions, shared history, shared saved passwords and no individual audit trail. They should be replaced with individual accounts per user. This is also a basic access control requirement within Cyber Essentials.
Are browser extensions a security risk?
Extensions can request access to page content, clipboard, downloads, tabs and browsing activity. An extension with broad permissions has significant access to what the user does in the browser. Extensions should be inventoried, reviewed for business need and permissions, and removed where unnecessary. Extension ownership can change — an extension that was harmless may behave differently later.
Can businesses block Chrome extensions?
Yes. Chrome Enterprise policies can be used to allowlist approved extensions and block others. This requires Chrome to be under central management. Verify current Chrome Enterprise policy capabilities at the Chrome Enterprise documentation.
Can Intune manage Edge?
Yes. Microsoft Intune can manage Edge through configuration profiles, Edge browser policies, update management and security settings. This includes extension management, autofill controls, sync, SmartScreen, and password manager settings. Verify current policy capabilities at Microsoft Intune documentation.
Can Intune manage Chrome?
Intune can push Chrome configuration using configuration profiles. The depth of Chrome management through Intune differs from Edge's native integration. Chrome Browser Cloud Management and Chrome Enterprise policies provide the primary management path for Chrome. Verify current supported methods before implementation.
Should browsers update automatically?
Yes. Browsers are internet-facing software that receive frequent security updates. Keeping browsers current on every device is a basic security requirement. Businesses using central management can control update timing without disabling updates.
Does MFA protect browser sessions?
MFA protects the sign-in. Once a user is authenticated and the browser holds an active session, that session may be usable without re-entering credentials. Screen lock, endpoint security and browser patching help protect active sessions from local access risks. MFA is an essential control — it does not eliminate session risk entirely.
Can saved payment cards be protected?
Yes. Chrome and Edge both support Windows Hello verification before payment autofill on devices where Windows Hello is configured. Review who has access to saved payment details, whether device verification is enabled, and whether saved cards are still appropriate for each user.
Is browser security part of Cyber Essentials?
Cyber Essentials covers areas that intersect with browser security — supported and patched software, access control, user accounts and authentication. Running a current, patched, centrally configured browser with appropriate access controls supports these requirements. No single browser setting creates Cyber Essentials compliance.
How often should browser policies be reviewed?
Browser risk changes continuously — new extensions, new browser versions, staff changes, account changes and evolving passkey support. Altitude recommends incorporating browser review into an ongoing Operational Heartbeat rather than treating it as a one-time task.
Can Altitude manage business browsers?
Yes. Altitude's Managed IT Support for Manchester and North West businesses includes endpoint management through Microsoft Intune, Entra identity, Windows 11 device management, Edge and Chrome configuration review, extension review, passkey planning and browser policy deployment — as part of an integrated managed service.