HRNET passwords being stored on users PC due to “Autocomplete for Forms” setting in IE

This is a security issue with Internet Explorer that can cause user passwords to be stored on a users PC.

When a user types in their user name into the HR.Net User Name dialog the password is automatically populated. This is a known feature of Internet Explorer which can be disabled on a per user basis or globally using a policy on the domain controller.  This issue has also been raised in Vizual as an enhancement request for the HR.Net software.

Per User Setting:

  1. Open Internet Explorer.
  2. Open Tools – Internet Options.
  3. Click Content tab.
  4. Click AutoComplete button.
  5. Disable the “Prompt me to save passwords” setting

If you have a domain of computer in your control, this feature of IE can be disabled via policy – refer to MSDN for full details

This entry was posted in Web Appplication and tagged , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *