<- Chrome Settings Library

DeviceLoginScreenPromptOnMultipleMatchingCertificates

Prompt when multiple certificates match on the sign-in screen
Last updated October 8, 2024

This policy controls whether the user is prompted to select a client certificate on the sign-in screen in the frame hosting the SAML flow when more than one certificate matches DeviceLoginScreenAutoSelectCertificateForUrls. If this policy is set to Enabled, the user is asked to select the client certificate whenever the auto-selection policy matches multiple certificates. If this policy is set to Disabled or not set, the user is never prompted to select a client certificate on the sign-in screen. Note: This policy is in general not recommended, since it imposes potential privacy risks (in case device-wide TPM-backed certificates are used) and presents poor user experience.

Supported On:
Platform Start End
ChromeOS 96
Example value:

true

Features: