Block Autofill data types for specific sites
Verified with Google Chrome — updated on September 22, 2026 Supported on: Microsoft Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Google\Google Chrome User Configuration\Administrative Templates\Google\Google Chrome Registry
Software\Policies\Google\Chrome Software\Policies\Google\Chrome Other deployment channels
./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome~Miscellaneous/AutofillSettings OMA-URI published by Google. It requires the Chrome ADMX templates (chrome.admx, google.admx) to be imported in Intune first.
- Google Chrome (Linux) — since version 154
- Google Chrome (Mac) — since version 154
- Google Chrome (Windows) — since version 154
- Google ChromeOS (Google ChromeOS) — since version 154
- Google Chrome (Android) — since version 154
- Google Chrome (iOS) — since version 154
Source: official Chrome policy list, version 154.0.8037.98 Chrome Enterprise policy page
Description
Setting this policy allows you to specify which Autofill data types are blocked on specific URL patterns. The policy is structured as a list of dictionaries. Each dictionary must contain: * "url_pattern": A content setting URL pattern for the main frame (e.g., "https://[*.]example.com"). * "blocked_types": A list of strings representing the categories of Autofill data to block. The supported values for "blocked_types" are: * "contact_info": Blocks filling and saving of contact information. * "payments": Blocks filling and saving of credit cards and payment methods. * "identity_docs": Blocks filling and saving of identity documents (e.g. passport, drivers license, national id). * "travel": Blocks filling and saving of travel information (e.g. flight reservation, vehicle registration). * "shopping": Blocks filling and saving of shopping information (e.g. online orders, shipments). * "all": Blocks filling and saving of all Autofill data types. If a data type is blocked for a site, both the generation of suggestions and the prompt to save/import new data of that type are disabled on that site. If a URL matches multiple pattern entries in the list, the blocked types from all matching entries are combined (union-merged). Invalid URL patterns in the list are ignored. If this policy is unset, no Autofill data types are blocked by domain. For detailed information on valid URL patterns, please see: https://chromeenterprise.google/policies/url-patterns. Wildcard * is supported, this pattern matches any URL, with any scheme, port, and path. See https://chromeenterprise.google/policies/?policy=AutofillSettings for more information about schema and formatting. Example value: [ { "url_pattern": "https://[*.]example.com", "blocked_types": [ "contact_info", "payments" ] }, { "url_pattern": "https://another-example.com", "blocked_types": [ "payments" ] }, { "url_pattern": "*", "blocked_types": [ "identity_docs" ] } ]
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Block Autofill data types for specific sites
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome]
"AutofillSettings"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutofillSettings' -Value '' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome~Miscellaneous/AutofillSettings
Data type: String
Value:
<enabled/>
<data id="AutofillSettings" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'AutofillSettings' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutofillSettings' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'AutofillSettings' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Block Autofill data types for specific sites
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Windows 7 or later
$path = 'HKLM:\Software\Policies\Google\Chrome'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AutofillSettings' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.