1

I want to make sure that a user in our domain john.doe@xyz.com does not login to a device that has been assigned to don.king@xyz.com. I have created a configuration profile but not sure what the settings should be and the string value to be for such kind of situation.

Any suggestions and answer would be appreciated.

1 Answers1

0

You can add Allow Local Log On and Deny Local Log On rights from User Rights category from Settings Catalog to the Configuration Profile you created

Username format is AzureAD\user1@contoso.com

Details are here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-userrights#userrights-allowlocallogon

J-M
  • 1,930
  • 1
  • 11
  • 17