How to Prevent Additional Microsoft 365 Account Sign-Ins on Domain-Joined Devices
Question details
IT administrators need to restrict users from adding secondary Microsoft 365 work or school accounts on managed devices using single sign-on.

- Product
- Microsoft Entra ID / Microsoft 365
- Device & OS
- not provided
- Scenario
- Managing enterprise domain-joined devices with single sign-on enabled to ensure security compliance.
- Observed behavior
- Users are able to add or sign in with secondary Microsoft 365 Outlook or SharePoint accounts on managed devices, bypassing intended account restrictions.
Ensure you have global administrator or security administrator privileges in the Microsoft Entra admin center before modifying device registration policies. Test these policy changes on a small group of devices first to avoid disrupting organization-wide single sign-on access.
Restrict Account Additions via Microsoft Entra ID Device Settings
Update device management settings in the Microsoft Entra admin center to control device registration and block the addition of secondary work or school accounts.
By adjusting device enrollment restrictions in Azure Active Directory (now Microsoft Entra ID), administrators can lock down domain-joined devices so that users are prevented from authenticating secondary enterprise accounts.
Log in to the Microsoft Entra admin center (or Azure portal) using an account with administrator credentials.
Go to 'Identity', select 'Devices' from the left-hand menu, and then click on 'Device settings'.
Locate the settings that determine who may join or register devices to the organization. Adjust these settings to restrict unauthorized account enrollments.
Configure the applicable policies to block users from adding new work or school accounts onto already managed, domain-joined devices.
Save your configuration changes. Deploy the policy to a targeted test group before rolling it out across your entire organization.

Empower Your Organization with WPS Office
While Microsoft 365 requires strict tenant and device management policies for secure deployment, WPS Office provides a lightweight, highly compatible alternative for businesses. It delivers essential productivity tools with a familiar interface, allowing teams to seamlessly edit documents, spreadsheets, and presentations without complex account management overhead.

Frequently Asked Questions
Why do users add additional Microsoft 365 accounts on domain-joined devices?
Users often add secondary accounts, such as personal Microsoft accounts or secondary tenant accounts, to access different Outlook inboxes or SharePoint sites. This can pose data leakage risks on managed enterprise devices if not restricted.
Will restricting new accounts affect existing single sign-on (SSO) setups?
If misconfigured, strict device enrollment policies can interfere with primary SSO authentication and workplace joins. Always apply policies to a small test group of devices first to ensure primary credentials authenticate properly.
Can I block personal Microsoft accounts while allowing secondary work accounts?
Yes. Through Microsoft Intune and Endpoint Manager configuration profiles, administrators can explicitly block the addition of consumer Microsoft Accounts (MSA) while maintaining specific controls over organizational Entra ID accounts.




