Microsoft Enables Registry Policy to Auto‑Accept Windows SSO Prompts on Managed Windows 11 Devices
What Happened — Microsoft released a new registry‑based policy that lets IT administrators automatically accept Windows Single Sign‑On (SSO) permission prompts on Windows 11 24H2 and 25H2 devices that are managed with Microsoft Entra ID. The change applies only to corporate‑managed devices; personal accounts and unmanaged devices continue to see the prompt.
Why It Matters for Compliance & Audit Readiness
- The ability to centrally suppress SSO prompts is a concrete control for SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Provisioning), helping you demonstrate consistent enforcement of sign‑in policies.
- Automated acceptance must be documented and continuously monitored; the policy provides audit‑ready evidence that the organization’s access‑control decisions are enforced across the fleet.
- Aligns with privacy‑by‑design requirements in the EEA by preserving user choice on unmanaged devices while giving enterprises the flexibility to enforce trusted sign‑in flows.
Who Is Affected – Enterprises that manage Windows 11 endpoints via Microsoft Entra ID, including technology, financial services, and other regulated sectors that rely on Windows SSO for internal applications.
Recommended Actions –
- Add the new registry key (HKLM\Software\Policies\Microsoft\Windows\System\EnableAutoAcceptSSOPrompt) to your access‑control configuration baseline.
- Update your SOC 2 access‑control policies and evidence‑collection scripts (e.g., Intune compliance reports) to capture the deployment status of this setting.
- Conduct a validation sweep across the managed device fleet to confirm expected SSO behavior and document any exceptions.
Source: Help Net Security
Technical Notes – The policy is deployed via Group Policy, Microsoft Intune, or any MDM that can push registry values. It affects Windows 11 24H2/25H2 devices enrolled in Microsoft Entra ID; personal Microsoft accounts remain unaffected. No CVEs or vulnerabilities are disclosed. Source: same as above