Sso Admin Control
In brief
The documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.
What Entra admins need to know
Administrators get clearer guidance when reviewing the supported device scope and registry location.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting. In this context, SSO, or single sign-on, refers to using the Microsoft credentials from a user’s Windows sign-in to access other Microsoft apps and services without any prompts. This new capability is available beginning with the July 2026 monthly security update for Windows 11, version 24H2 and 25H2 via the 2026—KB5101650 security update.
Starting with the security update (as stated above) for Windows 11, version 24H2 and 25H2, IT administrators can deploy the following registry policy to automatically accept SSO permissions on managed devices:
Registry Path: HKLM\SOFTWARE\Policies\Microsoft\Windows\AAD
Value: AutoAcceptSsoPermission (DWORD) = 1

Getting started
@@ -18,9 +18,9 @@ manager: asteen IT administrators can now **automatically accept SSO permissions** on managed Windows devices using a supported registry setting. In this context, SSO, or single sign-on, refers to using the Microsoft credentials from a user’s Windows sign-in to access other Microsoft apps and services without any prompts. This new capability is available beginning with the **July 2026 monthly security update** for Windows 11, version 24H2 and 25H2 via the [2026—KB5101650](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875) security update. > [!IMPORTANT]-> - **Scope:** ✅ Applies only to **Windows** **managed enterprise devices** with Microsoft Entra ID accounts -> - **Personal accounts:** ❌ No admin control available — Prompts remain for personal Microsoft accounts (MSA) -> - **Unmanaged devices:** ❌ No admin control available —prompts remain for non-policy-controlled environments +> - **Scope:** ✅ Applies only to **Windows** **managed enterprise devices** with Microsoft Entra ID accounts+> - **Personal accounts:** ❌ No admin control available — Prompts remain for personal Microsoft accounts (MSA)+> - **Unmanaged devices:** ❌ No admin control available —prompts remain for non-policy-controlled environments > - **Supported OS:** Windows 11, version 24H2 and 25H2 (with the [2026—KB5101650](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875) security update) @@ -39,11 +39,11 @@ For managed enterprise environments, some organizations wanted additional flexib Starting with the security update (as stated above) for Windows 11, version 24H2 and 25H2, IT administrators can deploy the following registry policy to automatically accept SSO permissions on managed devices: -> **Registry Path:** HKLM\SOFTWARE\Policies\Microsoft\Windows\AAD +> **Registry Path:** HKLM\SOFTWARE\Policies\Microsoft\Windows\AAD > **Value:** AutoAcceptSsoPermission (DWORD) = 1 -+ ## Getting started 