Admin control for single sign-on prompts in Windows

🚨 The Signal: Microsoft introduced a registry policy to auto-accept SSO prompts on Entra ID-joined Windows 11 24H2/25H2 devices. This removes user interaction for SSO, potentially streamlining access but altering expected authentication flows.

The Impact

Admins are affected by a new configuration option that changes user SSO prompt behavior, potentially reducing user friction but requiring careful security review.

  • Security Teams: Must assess if auto-accepting SSO prompts aligns with risk tolerance.
  • Admins: Need to evaluate and deploy a new registry setting to enable this behavior.
  • End Users: Will experience fewer SSO prompts, potentially reducing security awareness.
  • Compliance Teams: Should review if this change impacts existing authentication policy documentation.

The Action

  1. Review Microsoft's announcement: 'Now available: Admin control for SSO prompts in Windows'.
  2. Evaluate if automatically accepting SSO prompts aligns with your organisation's security posture.
  3. Test the registry-based policy on a representative set of managed Windows 11 24H2/25H2 devices.
  4. Deploy the registry policy to production devices if deemed appropriate after testing.

Domain: Entra · Impact: medium · Workload: Entra ID