Admin control for single sign-on prompts in Windows
🚨 The Signal: Microsoft introduced a registry policy to auto-accept SSO prompts on Entra ID-joined Windows 11 24H2/25H2 devices. This removes user interaction for SSO, potentially streamlining access but altering expected authentication flows.
The Impact
Admins are affected by a new configuration option that changes user SSO prompt behavior, potentially reducing user friction but requiring careful security review.
- Security Teams: Must assess if auto-accepting SSO prompts aligns with risk tolerance.
- Admins: Need to evaluate and deploy a new registry setting to enable this behavior.
- End Users: Will experience fewer SSO prompts, potentially reducing security awareness.
- Compliance Teams: Should review if this change impacts existing authentication policy documentation.
The Action
- Review Microsoft's announcement: 'Now available: Admin control for SSO prompts in Windows'.
- Evaluate if automatically accepting SSO prompts aligns with your organisation's security posture.
- Test the registry-based policy on a representative set of managed Windows 11 24H2/25H2 devices.
- Deploy the registry policy to production devices if deemed appropriate after testing.
Domain: Entra · Impact: medium · Workload: Entra ID