Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
Verified with Microsoft Edge 152.0.4191.53 — updated on July 10, 2026
Supported on: Microsoft Edge version 81, Windows 7 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Microsoft Edge User Configuration\Administrative Templates\Microsoft Edge Description
Enables the use of Azure Active Directory (Azure AD) accounts for automatic sign in if your users' machines are Domain Joined and if your environment isn't hybrid joined. If you want users automatically signed in with their Azure AD accounts instead, Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment. On every launch, Microsoft Edge tries to sign in using this policy, as long as the first profile being launched isn't signed in or an auto sign in doesn't happen before. If you configure the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy doesn't take any effect. If you enable this policy and set it to 'SignInAndMakeDomainAccountNonRemovable', Microsoft Edge automatically signs in users that are on domain-joined machines using their Azure AD accounts. If you set this policy to 'Disabled' or don't set it, Microsoft Edge doesn't automatically sign in users that are on domain-joined machines with Azure AD accounts. From Microsoft Edge version 89, if there's an existing on-premises profile with 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy disabled, and if the machine is now hybrid joined, that is, it has an Azure AD account, it autoupgrades the on-premises profile to Azure AD profile to get full Azure AD sync facilities. From Microsoft Edge version 93, if policy 'ImplicitSignInEnabled' (Enable implicit sign-in) is disabled, this policy doesn't take any effect. From Microsoft Edge version 94, if policy 'OnlyOnPremisesImplicitSigninEnabled' (Only on-premises account enabled for implicit sign-in) is enabled, and this policy is set to 'SignInAndMakeDomainAccountNonRemovable', it takes effect even on hybrid-joined environment. Microsoft Edge automatically signs in users using their Azure AD domain account even if there are Microsoft Account (MSA) or Azure AD accounts. Policy options mapping: * Disabled (0) = Disabled * SignInAndMakeDomainAccountNonRemovable (1) = Sign in and make domain account non-removable Use the preceding information when configuring this policy.
Registry
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Applying both scopes creates an ambiguous configuration (computer takes precedence over user). Only do this intentionally.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 81, Windows 7 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"ConfigureOnPremisesAccountAutoSignIn"=dword:00000000 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ConfigureOnPremisesAccountAutoSignIn' -Value 0 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'ConfigureOnPremisesAccountAutoSignIn' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ConfigureOnPremisesAccountAutoSignIn' -Value 0 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'ConfigureOnPremisesAccountAutoSignIn' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 81, Windows 7 or later
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ConfigureOnPremisesAccountAutoSignIn' -Value 0 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.