Intune CSP / OMA-URI Lookup Paste policy. Get context.
DisablePasswordReveal

Disable the password-reveal control in Windows credential entry experiences.

OMA-URI
./Device/Vendor/MSFT/Policy/Config/CredentialsUI/DisablePasswordReveal
Deployment playbook

Assign it, sync it, prove it

A correct OMA-URI can still fail because of scope, format, applicability, targeting, conflict, or device state.

1

Likely causes

  • The path, device scope, integer format, or configured value does not match this CSP record.
  • The setting is not applicable to the device edition, Windows build, management mode, or hardware.
  • Assignment filters, exclusions, stale check-in, or another policy source changed the effective configuration.
2

Recommended fix

  1. Confirm the setting applies to the credential surfaces in scope.
  2. Test accessibility and support implications.
  3. Check for Group Policy or security baseline conflicts.
3

Verify

  1. Trigger a device sync, then wait for a new check-in rather than reading the previous report state.
  2. Review the per-setting status and compare the profile, assignment, filter evaluation, and conflict details.
  3. On Windows, correlate the fresh sync with DMEDP/Admin events and the MDM diagnostic report.
  4. Verify the operating-system effect directly; a successful policy report is not always proof of the desired outcome.
4

Escalate when

  • The current Microsoft CSP documentation lists the path/value as applicable but a freshly synced supported device still rejects it.
  • Multiple devices fail with the same event or SyncML status after targeting and conflicts are eliminated.
  • You can provide the policy JSON, assignments/filters, device build/edition, UTC sync time, per-setting status, and redacted diagnostics.
Copy this OMA-URI
./Device/Vendor/MSFT/Policy/Config/CredentialsUI/DisablePasswordReveal

Use scope Device, format Integer, and a value allowed by the current Microsoft documentation.

Read recent Windows MDM events
Get-WinEvent -LogName 'Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin' -MaxEvents 50 | Select-Object TimeCreated,Id,LevelDisplayName,Message

Read-only. Run on the affected Windows device and correlate the output with the latest sync time.

Collect an MDM diagnostic archive
mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "C:\Users\Public\Documents\MDMDiagReport.zip"

Creates a local archive. Redact tenant, user, device, certificate, and network identifiers before sharing.

Deployment values

Scope
Device
Format
Integer
Values
0 allows the reveal control; 1 disables it where supported.

Operational checks

  1. Confirm the setting applies to the credential surfaces in scope.
  2. Test accessibility and support implications.
  3. Check for Group Policy or security baseline conflicts.
Advertisement