Microsoft Intune admin center showing OneDrive configuration settings
Cloud ComputingIntermediate

How to Configure OneDrive Auto Sign-in Using Microsoft Intune

Set up automatic OneDrive sign-in for users through Microsoft Intune's Settings Catalog policy to eliminate manual login requirements and improve productivity.

Emanuel DE ALMEIDAEmanuel DE ALMEIDA
March 11, 202615 min read9 Steps

What is Microsoft Intune OneDrive Auto Sign-in Configuration?

Microsoft Intune's OneDrive auto sign-in feature eliminates the manual authentication step for users accessing OneDrive for Business. By leveraging the Settings Catalog policy, administrators can configure Windows devices to automatically authenticate users to OneDrive using their existing Windows credentials. This seamless integration improves user productivity by removing friction from the file synchronization process while maintaining security through existing authentication mechanisms.

The configuration uses Intune's modern Settings Catalog approach, which provides granular control over Windows settings with regular updates and enhanced functionality compared to traditional administrative templates.

Why Should You Configure OneDrive Auto Sign-in Through Intune?

Manual OneDrive authentication creates unnecessary friction in modern workplace environments. Users often struggle with multiple authentication prompts, forgotten passwords, and interrupted workflows when accessing cloud storage. The auto sign-in configuration addresses these challenges by:

  • Reducing support tickets: Eliminates common OneDrive login issues
  • Improving user experience: Seamless access to business files
  • Enhancing security: Uses existing Windows authentication rather than separate credentials
  • Streamlining device setup: New devices automatically connect to OneDrive
  • Supporting remote work: Ensures consistent file access across locations

Organizations using Microsoft 365 and Intune can implement this configuration without additional licensing costs, making it an efficient productivity enhancement.

How Do You Access Microsoft Intune Admin Center for OneDrive Configuration?

Begin by accessing the Microsoft Intune admin center, your central hub for device and application management. Open your web browser and navigate to:

https://endpoint.microsoft.com

Sign in using your Intune Administrator or Global Administrator credentials. The admin center provides a unified interface for managing all aspects of your Microsoft Intune environment, including device configuration, application deployment, and compliance policies.

Once logged in, you'll see the main dashboard displaying device enrollment statistics, policy deployment status, and recent administrative activities. The left navigation panel provides access to all major Intune functions, with the "Devices" section containing the configuration policies you'll use for OneDrive setup.

Pro tip: Bookmark this URL and consider using a dedicated browser profile for administrative tasks to avoid session conflicts with your regular Microsoft 365 usage.

Verification: Confirm you can see the "Devices" section in the left navigation menu and that your role permissions allow access to configuration policies. If you encounter access issues, verify your administrator role assignments in Microsoft Entra ID.

How Do You Create a New Configuration Policy in Intune?

Navigate to the configuration policies section where you'll create the OneDrive auto sign-in policy. From the Intune admin center dashboard, follow this navigation path:

DevicesWindowsConfigurationCreateNew policy

This sequence opens the policy creation wizard, which guides you through the process of defining platform compatibility, profile type, and specific configuration settings. The wizard approach ensures you don't miss critical configuration steps and provides context-sensitive help throughout the process.

In the policy creation dialog, you'll need to specify:

  • Platform: Select "Windows 10 and later" to ensure compatibility with modern Windows versions
  • Profile: Choose "Settings catalog" for access to the latest configuration options

The Settings catalog represents Microsoft's modern approach to device configuration, offering more granular control and regular updates compared to traditional administrative templates. This profile type provides access to hundreds of Windows settings through a searchable interface.

Pro tip: Settings catalog policies are more flexible than administrative templates and receive regular updates with new Windows features, making them the preferred choice for new configurations.

Verification: The wizard should advance to the "Basics" tab where you'll name your policy. If you don't see this progression, verify your platform and profile selections are correct.

What Settings Enable OneDrive Auto Sign-in in Intune?

The core OneDrive auto sign-in functionality relies on a specific setting within Intune's Settings Catalog. After naming your policy with a descriptive title like "OneDrive Auto Sign-in Configuration," you'll configure the actual behavioral settings.

Click Add settings to open the settings browser, then search for:

silently sign in users to the OneDrive

From the search results, expand the OneDrive category and locate the setting:

Silently sign in users to the OneDrive Sync app with their Windows credentials

This setting is the key to eliminating manual authentication. When enabled, it instructs Windows to automatically authenticate users to OneDrive using their existing Windows login credentials, creating a seamless experience between device login and cloud storage access.

Configure the setting value to Enabled to activate the auto sign-in behavior. This configuration tells the OneDrive sync client to use the current Windows user's authentication token rather than prompting for separate credentials.

Which Additional OneDrive Settings Should You Configure?

While the auto sign-in setting provides the core functionality, several complementary settings enhance security and user experience:

Setting NameRecommended ValuePurpose
Prevent users from syncing personal OneDrive accountsEnabledEnforces business-only OneDrive usage
Use OneDrive Files On-DemandEnabledSaves local storage space
Set the sync app update ringProduction RingControls update deployment timing

The "Prevent users from syncing personal OneDrive accounts" setting is particularly important for organizations with data governance requirements. It ensures users can only sync business content, preventing potential data leakage to personal accounts.

Files On-Demand functionality shows cloud files in File Explorer without downloading them locally until accessed. This approach significantly reduces local storage requirements while maintaining full file visibility and access.

Warning: Be cautious with the personal OneDrive restriction setting in BYOD environments, as it may impact user productivity if they legitimately need access to personal files.

Search for these settings using these terms:

Search terms:
- prevent users from syncing personal
- use onedrive files on-demand
- set the sync app update ring

How Do You Assign OneDrive Policies to Users and Devices?

Policy assignment determines which users or devices receive your OneDrive configuration. Intune provides flexible assignment options to support various organizational structures and deployment strategies.

On the Assignments page, you can configure:

  • Include groups: Specify which Azure AD groups receive the policy
  • Exclude groups: Remove specific groups from policy application
  • Assignment filters: Apply additional criteria for policy targeting

Common assignment strategies include:

  • All Users: Broad deployment for organizations with consistent OneDrive requirements
  • Department Groups: Targeted deployment for specific business units
  • Device Groups: Assignment based on device type, location, or ownership
  • Pilot Groups: Limited deployment for testing and validation

For initial deployment, consider starting with a pilot group of 10-20 users to validate functionality before broader rollout. This approach helps identify compatibility issues or user experience problems in a controlled environment.

Warning: Test with a small pilot group first before deploying to all users to identify any compatibility issues or conflicts with existing policies.

Scope tags provide additional assignment control in large organizations with delegated administration. If your organization uses scope tags for policy management, configure them appropriately. Most environments can skip scope tag configuration.

How Do You Verify OneDrive Auto Sign-in Policy Deployment?

After creating and deploying your OneDrive auto sign-in policy, verification ensures the configuration works as expected across your target devices. Policy monitoring and testing should occur at multiple levels.

Monitor policy deployment status:

Navigate to DevicesWindowsConfiguration and locate your OneDrive policy. Click on the policy name to view detailed deployment information, including:

  • Device assignment status
  • Successful deployments
  • Failed deployments with error details
  • Pending deployments

The policy status typically progresses from "Pending" to "Deploying" to "Succeeded" as devices receive and apply the configuration. Failed deployments require investigation to identify root causes.

Test functionality on target devices:

Select a test device from your pilot group and perform these verification steps:

  1. Sign out of OneDrive completely if currently authenticated
  2. Close the OneDrive application entirely
  3. Force policy synchronization using one of these methods:
gpupdate /force

Or trigger Intune sync through Windows Settings:

Settings → Accounts → Access work or school → [Your organization] → Info → Sync

  1. Restart the OneDrive application or reboot the device
  2. Observe OneDrive behavior - it should automatically sign in without credential prompts
Pro tip: Check the OneDrive system tray icon status. It should display the user's initials or profile picture, indicating successful authentication, rather than showing a sign-in prompt.

Common verification indicators:

  • OneDrive system tray icon shows authenticated status
  • File Explorer displays OneDrive folders without authentication prompts
  • OneDrive sync activity begins automatically
  • No credential prompts appear during the sign-in process

What Are Common OneDrive Auto Sign-in Issues and Solutions?

Despite proper configuration, several common issues can prevent OneDrive auto sign-in from working correctly. Understanding these problems and their solutions helps ensure successful deployment.

Policy not applying to devices:

This issue typically stems from device enrollment or assignment problems. Verify:

  • Devices are properly enrolled in Intune MDM
  • Devices are Azure AD joined or hybrid Azure AD joined
  • Policy assignments target the correct user or device groups
  • No conflicting policies override the OneDrive configuration

Force policy synchronization on affected devices and check Intune compliance status to identify enrollment issues.

Manual sign-in prompts still appear:

When users continue seeing authentication prompts despite policy deployment:

  1. Completely sign out of OneDrive and close the application
  2. Restart the OneDrive client or reboot the device
  3. Verify the Windows primary account matches the OneDrive for Business license
  4. Check for conflicting Group Policy Objects in hybrid environments
Warning: In hybrid Active Directory environments, Group Policy Objects can conflict with Intune policies. Ensure Intune takes precedence for MDM-enrolled devices or remove conflicting GPOs.

OneDrive sync issues after policy application:

If auto sign-in works but sync fails:

  • Verify network connectivity to Microsoft 365 services
  • Confirm user licenses include OneDrive for Business
  • Check OneDrive client version and update if necessary
  • Review device compliance status in Intune

Hybrid environment considerations:

Organizations using both Group Policy and Intune should prioritize Intune Settings Catalog policies for MDM-enrolled devices. The modern management approach provides better visibility and control compared to traditional GPO management.

Test policy inheritance carefully in hybrid environments to ensure Intune configurations take precedence over conflicting Group Policy settings.

Step-by-Step Guide

1
Step 1 / 9

Access Microsoft Intune Admin Center

Open your web browser and navigate to the Microsoft Intune admin center. Sign in with your Intune Administrator or Global Administrator credentials.

https://endpoint.microsoft.com

Once logged in, you'll see the main dashboard with various management options. The admin center provides centralized control for all your Intune policies and device management tasks.

Pro tip: Bookmark this URL and consider using a dedicated browser profile for administrative tasks to avoid session conflicts.

Verification: Confirm you can see the "Devices" section in the left navigation menu and that your role permissions allow access to configuration policies.

2
Step 2 / 9

Navigate to Configuration Policies

From the Intune admin center dashboard, navigate to the configuration policies section where you'll create the OneDrive auto sign-in policy.

Click through this navigation path:

  • DevicesWindowsConfigurationCreateNew policy

This opens the policy creation wizard where you'll define the platform and profile type for your OneDrive configuration.

Verification: You should see the "Create a profile" dialog with platform and profile type selection options.

3
Step 3 / 9

Select Platform and Profile Type

In the policy creation dialog, configure the following settings:

  • Platform: Select "Windows 10 and later"
  • Profile: Select "Settings catalog"

The Settings catalog is Microsoft's modern approach to device configuration, replacing traditional administrative templates. It provides granular control over Windows settings with a searchable interface.

Pro tip: Settings catalog policies are more flexible than administrative templates and receive regular updates with new Windows features.

Click Create to proceed to the policy configuration wizard.

Verification: The wizard should advance to the "Basics" tab where you'll name your policy.

4
Step 4 / 9

Configure Policy Basics

On the Basics tab, provide clear identification for your policy:

  • Name: OneDrive Auto Sign-in Configuration
  • Description: Enables automatic sign-in to OneDrive using Windows credentials for enrolled devices

Use descriptive names that clearly indicate the policy's purpose. This helps with policy management as your environment grows.

Warning: Avoid generic names like "OneDrive Policy" as they become confusing when you have multiple OneDrive-related policies.

Click Next to proceed to the configuration settings.

Verification: The policy name appears in the breadcrumb navigation at the top of the page.

5
Step 5 / 9

Add OneDrive Auto Sign-in Setting

This is the core step where you configure the actual OneDrive auto sign-in behavior. Click Add settings to open the settings browser.

In the search box, type:

silently sign in users to the OneDrive

From the search results, expand the OneDrive category and locate:

Silently sign in users to the OneDrive Sync app with their Windows credentials

Select this setting and configure it:

  • Setting value: Enabled

This setting instructs Windows to automatically authenticate users to OneDrive using their existing Windows login credentials, eliminating the need for separate OneDrive authentication.

Click Add to include this setting in your policy, then click Next.

Verification: The setting should appear in your policy configuration with "Enabled" status clearly visible.

6
Step 6 / 9

Configure Optional OneDrive Settings

While the auto sign-in setting is sufficient for basic functionality, consider adding these complementary settings for better security and management:

Search for and add these optional settings:

  • "Prevent users from syncing personal OneDrive accounts" - Set to Enabled to enforce business-only OneDrive usage
  • "Use OneDrive Files On-Demand" - Set to Enabled to save local storage space
  • "Set the sync app update ring" - Choose appropriate update cadence
Search terms:
- prevent users from syncing personal
- use onedrive files on-demand
- set the sync app update ring
Pro tip: Files On-Demand is particularly useful for devices with limited storage, as it shows cloud files without downloading them locally until accessed.

After adding desired settings, click Next to continue.

Verification: Review that all selected settings show their configured values in the policy summary.

7
Step 7 / 9

Configure Scope Tags and Assignments

On the Scope tags page, add scope tags if your organization uses them for policy management. For most environments, you can skip this step by clicking Next.

On the Assignments page, specify which users or devices will receive this policy:

  • Include: Select "Add groups" and choose your target groups
  • Exclude: Optionally exclude specific groups if needed

Common assignment strategies:

  • All Users: Apply to everyone with OneDrive licenses
  • Department Groups: Target specific departments for phased rollout
  • Device Groups: Apply based on device type or location
Warning: Test with a small pilot group first before deploying to all users to identify any compatibility issues.

Click Next after configuring assignments.

Verification: Confirm your selected groups appear in the assignment summary with the correct inclusion/exclusion settings.

8
Step 8 / 9

Review and Create Policy

On the Review + create page, carefully verify all policy settings:

  • Policy name: OneDrive Auto Sign-in Configuration
  • Platform: Windows 10 and later
  • Profile type: Settings catalog
  • Key setting: Silently sign in users to OneDrive - Enabled
  • Assignments: Verify correct groups are targeted

Review the configuration summary to ensure all settings match your requirements. Pay special attention to the assignment scope to avoid unintended policy application.

Click Create to deploy the policy.

Verification: The policy should appear in your configuration policies list with a "Pending" or "Deploying" status initially, then change to "Succeeded" as devices receive the policy.

9
Step 9 / 9

Verify Policy Deployment and Test Auto Sign-in

After creating the policy, monitor its deployment and test the functionality on target devices.

Check policy status:

Navigate to DevicesWindowsConfiguration and locate your policy. Click on it to view deployment status and any errors.

Test on a target device:

  1. On a test device, sign out of OneDrive completely if currently signed in
  2. Close the OneDrive application
  3. Force a policy sync by opening Command Prompt as administrator and running:
gpupdate /force

Or trigger Intune sync from Settings → Accounts → Access work or school → [Your organization] → Info → Sync.

  1. Restart the OneDrive application or restart the device
  2. OneDrive should automatically sign in without prompting for credentials
Pro tip: Check the OneDrive system tray icon - it should show as signed in with the user's business account without any authentication prompts.

Verification: Open File Explorer and confirm OneDrive folders are accessible and syncing without manual authentication. The OneDrive icon in the system tray should display the user's initials or profile picture.

Frequently Asked Questions

What Windows versions support OneDrive auto sign-in through Intune?
OneDrive auto sign-in through Microsoft Intune requires Windows 10 version 1903 or later, or Windows 11. Devices must be Azure AD joined or hybrid Azure AD joined and enrolled in Intune MDM. The OneDrive sync client is pre-installed on modern Windows versions and receives automatic updates through Windows Update.
Can I use Group Policy instead of Intune for OneDrive auto sign-in?
Yes, Group Policy can configure OneDrive auto sign-in using the same setting, but Microsoft recommends Intune Settings Catalog for modern device management. Intune provides better visibility, reporting, and cloud-based management compared to traditional GPO. In hybrid environments, ensure Intune policies take precedence over conflicting Group Policy Objects for MDM-enrolled devices.
Why does OneDrive still prompt for credentials after applying the policy?
Common causes include incomplete OneDrive sign-out, conflicting policies, or device enrollment issues. Completely sign out of OneDrive, close the application, restart the device, and force policy sync. Verify the device is properly enrolled in Intune and Azure AD joined. Check for conflicting Group Policy Objects in hybrid Active Directory environments.
What licenses are required for OneDrive auto sign-in configuration?
You need Microsoft Intune subscription for device management and Microsoft 365 licenses that include OneDrive for Business for end users. Common qualifying licenses include Microsoft 365 Business Premium, Enterprise E3/E5, or standalone OneDrive for Business plans. Both administrator and end-user licensing must be in place for the configuration to work properly.
How long does it take for OneDrive auto sign-in policy to apply?
Intune policies typically apply within 8 hours during normal sync cycles, but can be faster with manual sync triggers. Force immediate policy application using 'gpupdate /force' command or through Windows Settings → Accounts → Access work or school → Sync. Device restart may be required for some settings to take effect. Monitor policy deployment status in the Intune admin center for real-time updates.

About the Author

Emanuel DE ALMEIDA

Emanuel DE ALMEIDA

Senior IT Journalist & Cloud Architect

Microsoft MCSA-certified Cloud Architect | Fortinet-focused. I modernize cloud, hybrid & on-prem infrastructure for reliability, security, performance and cost control - sharing field-tested ops & troubleshooting.

Last updated March 11, 2026

Discussion

Share your thoughts and insights

You must be logged in to comment.

Loading comments...