MC1438491 Medium

Admin control for single sign-on prompts in Windows

  • User
  • Admin

Summary AI-generated

Admins can now use a registry-based policy to automatically accept SSO prompts on Windows 11 managed devices, removing the user prompt for Entra ID accounts.

Suggested actions AI-generated

  • Review announcement
  • Evaluate adoption of new SSO control
  • Test configuration on managed devices

Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.

Original post from Microsoft

What and why
Microsoft has introduced a new administrative control for single sign-on (SSO) prompts on Windows. A new registry-based policy now allows IT admins to automatically accept SSO permissions on managed devices, removing this prompt for users.
 
This control applies only to managed devices with Microsoft Entra ID accounts running Windows 11, version 24H2 or 25H2.
 
Rollout schedule
Available now. 
 
Impact on your organization
Organizations that manage Windows devices should review whether this control aligns with existing authentication policies and sign-in experiences.

Depending on configuration choices, SSO prompt behavior might differ from the current experience on managed devices.
 
Action required/recommendations
No immediate action is required. Organizations that want to adopt this control should:
 
Compliance considerations
No compliance considerations are identified. Review as appropriate for your organization.