Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

There is no universal Intune switch that disables the “Stay signed in to all your apps” prompt for every Windows 365 or Azure Virtual Desktop sign-in. If the endpoint should remain unmanaged, clear Allow my organization to manage my device and choose No, sign in to this app only. This avoids that particular device-management and account-persistence path, although users may need to authenticate more often.

Administrators who want to change the behavior tenant-wide must investigate Microsoft Entra device registration, automatic Intune enrollment, Conditional Access, Windows app protection, licensing, and the endpoint’s existing work-account state.

First identify whether this is Windows 365 or Azure Virtual Desktop

Windows 365 and Azure Virtual Desktop (AVD) are different services:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Windows 365 provides a user’s Cloud PC as a Microsoft-hosted SaaS service.
  • Azure Virtual Desktop is Azure-based virtual desktop infrastructure built around host pools, application groups, workspaces, and session hosts.

The authentication experience can look similar, but the relevant application, client, and Conditional Access path may differ. Identify whether the user is connecting through Windows App, the Remote Desktop client, an AVD web client, or the Windows 365 web experience before changing policy.

#1 Best Overall
Microsoft OEM System Builder | Windоws 11 Pro | Intended use for new systems | Authorized by Microsoft
  • STREAMLIMED AND INTUITIVE UI | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
  • JOIN YOUR BUSINESS OR SCHOOL DOMAIN for easy access to network files, servers, and printers.
  • OEM IS TO BE INSTALLED ON A NEW PC WITH NO PRIOR VERSION of Windows installed and cannot be transferred to another machine.
  • OEM DOES NOT PROVIDE PRODUCT SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.

Fastest way to avoid management of the endpoint

If the computer used to connect to the Cloud PC or AVD session is personal or should not be enrolled, use this sequence when the prompt appears:

  1. Clear Allow my organization to manage my device, if the checkbox is displayed.
  2. Select No, sign in to this app only.
  3. Complete MFA or any other authentication requirement.
  4. Retry the Windows 365 or AVD connection.

Do not select OK merely to dismiss the dialog when the device should remain unmanaged. Microsoft’s Windows enrollment documentation identifies the app-only option as the choice for avoiding unintended device management: Microsoft’s Windows enrollment guidance.

This choice signs the user into the current application rather than broadly associating the account with Windows and other applications. It does not undo an enrollment that already happened, and it cannot override a Conditional Access policy requiring a registered, managed, or compliant device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the prompt appears

The dialog is generally part of the Microsoft identity and Windows account-registration experience, not an Intune-generated setting in isolation. Depending on the tenant configuration, accepting the broader sign-in option can associate the work account with Windows, enable Microsoft Entra device registration, or permit an Intune enrollment flow.

Rank #2
Windows 11 Pro Upgrade, from Windows 11 Home (Digital Download)
  • Instantly productive. Simpler, more intuitive UI and effortless navigation. New features like snap layouts help you manage multiple tasks with ease.
  • Smarter collaboration. Have effective online meetings. Share content and mute/unmute right from the taskbar (1) Stay focused with intelligent noise cancelling and background blur.(2)
  • Reassuringly consistent. Have confidence that your applications will work. Familiar deployment and update tools. Accelerate adoption with expanded deployment policies.
  • Powerful security. Safeguard data and access anywhere with hardware-based isolation, encryption, and malware protection built in.

Clicking OK does not always give an organization unrestricted control of the computer. The result depends on whether the device becomes Microsoft Entra registered or joined, whether automatic MDM enrollment is enabled, licensing, policy scope, and the user’s permissions.

In AVD scenarios, Microsoft documents that this prompt may appear when the Windows endpoint used to connect is not already registered with Microsoft Entra ID. Choosing app-only sign-in can therefore preserve access while avoiding broader endpoint registration, but it may also cause more frequent authentication prompts. See Microsoft’s AVD authentication and Conditional Access guidance.

What administrators should check in Microsoft Entra and Intune

1. Automatic MDM enrollment and MDM user scope

Review the Windows automatic enrollment configuration and its MDM user scope. In the Microsoft Intune admin center, check which users or groups are included and whether the affected user is intentionally targeted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Possible designs include:

  • Excluding a pilot user or group while troubleshooting.
  • Scoping automatic enrollment to users who should have managed devices.
  • Keeping enrollment enabled for corporate endpoints while excluding approved BYOD access.
  • Confirming that targeted users have the required Intune licensing.

Narrowing the MDM user scope can prevent automatic enrollment, but it may not remove every Microsoft sign-in prompt. It can also prevent users from receiving compliance policies and cause access failures if Conditional Access requires a compliant device. Microsoft Q&A discussions commonly identify MDM scope and licensing as areas to investigate when sign-in unexpectedly enters enrollment; treat those reports as troubleshooting evidence, not a universal diagnosis: Microsoft Q&A enrollment discussion.

Rank #3
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
  • MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE

2. Conditional Access policies

In the Microsoft Entra admin center, inspect Conditional Access policies assigned to the affected users and applications. Look for requirements involving:

  • Azure Virtual Desktop
  • Windows Cloud Login
  • Office 365
  • Browser clients
  • Mobile and desktop clients
  • Device compliance or device management
  • Approved or protected applications

For AVD, Microsoft’s guidance explains how to target the Azure Virtual Desktop application and choose applicable client types. AVD web-client sign-ins may appear in sign-in logs under application ID a85cf173-4192-42f8-81fa-777a763e6e2c.

Use Conditional Access Report-only mode and a pilot group when validating policy changes. Review the resulting sign-in logs before making a production policy less restrictive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Determine whether this is MAM rather than MDM

Windows app protection is separate from full-device Intune management:

Rank #4
DEOY Market Compatible with Windows 11 Pro OEM Activation Key – 1 PC – Digital Delivery
  • DIGITAL OEM ACTIVATION KEY – Digital activation key compatible with Windows 11 Pro for one PC. This is an OEM-type license intended for activation on a compatible Windows PC.
  • FAST DIGITAL DELIVERY – Activation key and setup information are delivered electronically through Amazon Buyer-Seller Messaging after purchase. Maximum delivery time is 4 hours.
  • FOR WINDOWS 11 PRO – Designed for compatible PCs running or installing Windows 11 Pro. Internet access is required during the activation process.
  • OEM LICENSE FOR 1 PC – This OEM license is intended for a single computer and becomes associated with the device on which it is activated. It is not intended for transfer between multiple PCs.
  • CUSTOMER SUPPORT INCLUDED – DEOY Market provides assistance with activation and basic setup questions. Digital product only; no physical box, DVD, USB drive, or physical shipment is included.
  • MDM manages the Windows device, its configuration, compliance, applications, and security settings.
  • MAM/app protection protects organizational data inside supported applications without requiring full-device management.

Microsoft documents a Windows MAM flow involving Microsoft Edge in which users may see the “Stay signed in to all your apps” experience during app-protection enrollment. Read the current requirements and limitations in Microsoft’s Windows app protection documentation.

That documentation also states that MAM enrollment is blocked when the device is already MDM-managed, so app protection is not a drop-in replacement for device enrollment. The page describes a preview capability related to hiding the device-management user interface; treat it as preview, not as a stable, tenant-wide prompt-suppression control.

4. Check enrollment restrictions and licensing

Before removing a user from enrollment scope, verify:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Intune license assignment.
  • Microsoft Entra licensing required by the organization’s Conditional Access design.
  • Windows platform enrollment restrictions.
  • Device limits.
  • Personally owned device restrictions.
  • User and device group assignments.

A scope or licensing mismatch can look like an authentication problem. For example, an enrollment-related error such as CAA50024 is a reason to investigate configuration, not proof that disabling Intune enrollment is the correct fix.

Best Value
Sale
Microsoft Windows 11 (USB)
  • Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
  • Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
  • Make the most of your screen space with snap layouts, desktops, and seamless redocking.
  • Widgets makes staying up-to-date with the content you love and the news you care about, simple.
  • Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When you should not disable enrollment

Keep enrollment enabled when the endpoint is intentionally managed or when access depends on management signals. This commonly includes:

  • Corporate Windows endpoint management.
  • Device compliance enforcement.
  • Conditional Access requiring a compliant or managed device.
  • Corporate provisioning and application deployment.
  • Security configurations delivered through Intune.
  • A properly designed Windows MAM or app-protection scenario.

Suppressing or avoiding the prompt may allow app-only sign-in but still result in an access-denied message if the organization requires a compliant, registered, or managed device. It does not disable MFA, authentication-strength requirements, or sign-in-frequency controls.

If the device already accepted the prompt

Choosing app-only sign-in later does not necessarily unregister or unenroll a device that was previously connected. First determine the intended final state: app-only access, Microsoft Entra registered, Microsoft Entra joined, or Intune-enrolled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. In Windows, open Settings > Accounts > Access work or school.
  2. Identify whether the work account is connected and whether the device shows organization-management information.
  3. If the computer should not be connected, disconnect the relevant work account only after confirming that corporate access will not be disrupted.
  4. In the Microsoft Entra admin center, check the device object and its registration or join state.
  5. In the Intune admin center, check whether the device is managed, compliant, or assigned policies.
  6. Remove stale device records only through the organization’s normal retirement or cleanup process.
  7. Close Office, Edge, Windows App, Remote Desktop, and other Microsoft identity clients before retrying.
  8. Authenticate again and choose No, sign in to this app only.

Do not begin by deleting broker caches, credentials, or device objects indiscriminately. Those actions can create additional registration and sign-in failures and may require local or administrative privileges.

Blank dialog or repeated authentication loop

A blank or looping prompt is not proof that Intune enrollment should be disabled. Investigate the local authentication path and policy results as well.

  • Install current Windows cumulative updates.
  • Update Windows App, Remote Desktop, Edge, or the relevant AVD client.
  • Review Microsoft Entra sign-in logs and Conditional Access results.
  • Check whether the local Web Account Manager or Microsoft identity broker has a stale or partially registered account.
  • Verify that firewalls, proxies, endpoint security, and network filtering are not blocking Microsoft authentication content.
  • Confirm that the Windows endpoint’s date, time, and connectivity are correct.
  • Test the same user with the web and desktop clients where permitted.

Microsoft Q&A reports have associated blank “Stay signed in to all your apps” dialogs with endpoint updates and blocked authentication resources. Those are community troubleshooting observations, so verify them in the affected environment rather than treating them as a guaranteed Microsoft fix: Microsoft Q&A blank-dialog discussion.

Decision checklist

Goal Recommended approach Trade-off
Use AVD or Windows 365 from a personal endpoint without enrollment Choose No, sign in to this app only More frequent sign-ins; device-based access rules may block access
Manage corporate Windows endpoints Keep automatic enrollment enabled for intended users and devices Devices become managed and users may see the prompt
Support BYOD without full MDM Evaluate supported Windows MAM/app protection Application, platform, and policy limitations apply
Prevent accidental enrollment Narrow MDM scope and educate users Excluded users cannot receive required MDM policies
Require compliant devices for AVD Keep Conditional Access requirements and enroll qualifying endpoints Unmanaged personal endpoints may be denied
Stop repeated prompts Investigate registration, sign-in frequency, policy, client, update, and network causes Changing enrollment scope alone may not fix the symptom

Windows 365 and AVD administration checklist

Windows 365

  • Confirm that the user is accessing a Cloud PC rather than an AVD host pool.
  • Identify the client being used and the application shown in sign-in logs.
  • Check whether the physical endpoint or the Cloud PC is the device intended for Intune management.
  • Review Conditional Access requirements separately for the endpoint and Cloud PC access flow.

Azure Virtual Desktop web client

  • Check the Azure Virtual Desktop application and browser-client targeting.
  • Review sign-in logs for the AVD web-client application ID.
  • Test whether app-only sign-in succeeds but causes expected reauthentication.

AVD Remote Desktop or Windows App client

  • Update the client.
  • Check Windows account registration on the local endpoint.
  • Compare desktop-client and web-client Conditional Access results.

Personal endpoint

  • Use app-only sign-in if organizational policy permits access without enrollment.
  • Do not accept device management solely to dismiss the prompt.
  • Expect access to fail if compliance or management is mandatory.

Corporate managed endpoint

  • Keep the user within the intended enrollment scope.
  • Confirm licensing, enrollment restrictions, compliance, and policy assignments.
  • Use pilot groups and Report-only Conditional Access testing before broad changes.

Bottom line

To access Windows 365 or AVD without enrolling the local endpoint, clear Allow my organization to manage my device and choose No, sign in to this app only. To change the behavior for an organization, investigate the underlying Microsoft Entra registration, Intune MDM scope, MAM policy, Conditional Access, licensing, and existing device state. There is no universal supported Intune command or configuration switch that simply hides this prompt in every sign-in flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 3
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE
SaleBestseller No. 5
Microsoft Windows 11 (USB)
Microsoft Windows 11 (USB)
Make the most of your screen space with snap layouts, desktops, and seamless redocking.; FPP is boxed product that ships with USB for installation
$128.38

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.