What and why
Microsoft has introduced a new administrative control for single sign-on (SSO) prompts on Windows. A new registry-based policy now allows IT admins to automatically accept SSO permissions on managed devices, removing this prompt for users.
This control applies only to managed devices with Microsoft Entra ID accounts running Windows 11, version 24H2 or 25H2.
Rollout schedule
Available now.
Impact on your organization
Organizations that manage Windows devices should review whether this control aligns with existing authentication policies and sign-in experiences.
Depending on configuration choices, SSO prompt behavior might differ from the current experience on managed devices.
Action required/recommendations
No immediate action is required. Organizations that want to adopt this control should:
- Review the announcement: Now available: Admin control for SSO prompts in Windows.
- Evaluate whether to adopt the new control in your environment.
- Test the configuration on a representative set of managed devices before broader deployment.
Compliance considerations
No compliance considerations are identified. Review as appropriate for your organization.