iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To hide Windows’ password reveal button on managed devices, configure Microsoft’s DisablePasswordReveal policy and set it to enabled. Microsoft documents both device and user MDM policy paths. The policy applies to Windows 10 version 1703 and later on supported Pro, Enterprise, Education, and IoT Enterprise editions.
What the policy does
The policy’s friendly name is “Do not display the password reveal button.” When enabled, it hides the reveal button after a user types a password in a password-entry box. When disabled or not configured, the button remains displayed by default.
Microsoft says the setting applies to Windows components and applications that use Windows system controls, including Internet Explorer. It does not establish that the policy affects every third-party app or custom password field.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose the device or user scope
Microsoft lists two MDM paths. Choose the scope that matches how you assign and manage the policy:
#1 Best Overall
- Device scope:
./Device/Vendor/MSFT/Policy/Config/CredentialsUI/DisablePasswordRevealapplies at the device level. - User scope:
./User/Vendor/MSFT/Policy/Config/CredentialsUI/DisablePasswordRevealapplies at the user level.
Both paths configure the same policy. The device path is appropriate when the intended configuration follows the managed device; use the user path when it should follow the managed user.
Configure it through Intune
Microsoft’s documentation confirms the policy’s MDM paths and the general use of Windows configuration profiles in Intune, but does not confirm whether the current Intune Settings Catalog exposes this individual setting. Check the live catalog for DisablePasswordReveal or “Do not display the password reveal button.” If it is available, configure it as enabled in the appropriate profile and assign that profile to the intended Windows devices or users.
Rank #2
If the setting is not available in the catalog, the documented MDM policy path can be configured through a custom profile only if the current Intune interface supports the required custom OMA-URI configuration. The precise portal route for this policy is not established in the cited Microsoft documentation, so do not assume a particular menu path or that a custom profile is required.
Custom MDM payload requirements
Microsoft identifies this as an ADMX-backed policy. For an MDM payload, use the selected device or user path above, set the policy to enabled, and follow the CSP’s formatting requirements:
Rank #3
- The data format is
chr(string). - The CSP lists Add, Delete, Get, and Replace as access types.
- The SyncML payload must be XML-encoded unless the MDM supports CDATA.
Microsoft maps the policy to CredUI.admx under Windows Components > Credential User Interface. Its mapped registry value is DisablePasswordReveal under SoftwarePoliciesMicrosoftWindowsCredUI. For deployment, use the documented MDM path and payload requirements rather than treating the registry mapping as a substitute for Intune policy configuration.
Windows versions and editions
Microsoft lists support beginning with Windows 10 version 1703. Supported editions are Pro, Enterprise, Education, and IoT Enterprise, including IoT Enterprise LTSC. Confirm that the target devices meet those requirements before assigning the policy.
Rank #4
Verify the result
- Confirm that the profile targets the intended device or user scope and that the target runs a supported Windows edition.
- After the policy is applied, test a Windows password-entry field that uses Windows system controls.
- Check whether the reveal button is absent after entering a password. A third-party application or custom password field may not follow this policy.
For the policy definition and paths, see Microsoft’s Policy CSP – CredentialsUI. For Intune’s Windows configuration profile context, see Device restriction settings for Windows devices in Microsoft Intune.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

