Click to Do is a Windows 11 AI feature that lets users act on selected text, images, and other on-screen content through right-click, AI-powered options. Many organizations need to switch it off for security, compliance, or policy reasons, particularly where content might be processed by AI services in ways that conflict with data governance requirements. Microsoft Intune manages this centrally through device configuration profiles, and the Settings Catalog exposes the relevant Windows AI controls that map to the underlying Windows policy settings. In this tutorial you will build a Settings Catalog profile that targets the Click to Do setting, assign it to your Windows 11 devices, and enforce it so users cannot re-enable the feature locally. You will then trigger a sync and verify enforcement on both the device and in the Intune admin center. The exact setting name your tenant exposes may vary slightly, so the guide covers how to interpret and configure whichever variant appears in your catalog.
Before you start
What you will learn
- You will learn how to create and deploy a Microsoft Intune Settings Catalog policy that disables the Click to Do AI feature on Windows 11 devices. You will also learn how to scope the policy to the right groups and confirm it is enforced on both the device and in the Intune console.
- Click to Do can process user content through Windows AI capabilities, which may conflict with data governance rules in regulated industries like healthcare, finance, and government. Managing the feature centrally through Intune ensures consistent enforcement across your fleet regardless of individual user settings.
Requirements
- You need access to the Microsoft Intune admin center (https://intune.microsoft.com) with an account that can create and assign device configuration profiles, plus a set of Azure AD security groups scoping the Windows 11 devices or users you intend to manage.
- Intune Administrator (or a role with device configuration profile create/assign permissions)
Good to know
- Roughly 20-40 minutes, including 15-30 minutes for the policy to deploy to devices.
- Steps reflect the Microsoft Intune admin center at https://intune.microsoft.com and Windows 11 devices that support Windows AI settings; UI labels and setting names can differ by tenant catalog version.
Quick answer
In the Microsoft Intune admin center, create a Settings Catalog configuration profile for Windows 10 and later, add the Windows AI Click to Do setting, and configure it to disable the feature (set a 'Disable Click to Do' setting to Enabled, or an 'Allow Click to Do' setting to Disabled). Assign the profile to your Windows 11 device groups, then sync and verify enforcement.
Microsoft Intune admin center > Devices > Configuration > Create profileStep-by-step tutorial
9 stepsSign in to the Microsoft Intune admin center
Reach the Intune console with an account that has the privileges to create configuration profiles.
https://intune.microsoft.comOpen a browser and go to https://intune.microsoft.com. Sign in with an account that holds the Intune Administrator role (or a role with rights to create and assign device configuration profiles).
Alternatively, you can reach Intune from the Microsoft 365 admin center at https://admin.microsoft.com by selecting Show all and then the Endpoint Manager / Intune entry.
Once signed in, confirm the left navigation shows the core management areas you'll use in this guide.
Bookmark https://intune.microsoft.com for faster access. If sign-in fails or menu items are missing, your account likely lacks the required Intune role — ask a Global or Intune Administrator to grant access.
Start a new Settings Catalog configuration profile
Open the profile creation wizard for the correct platform and profile type.
Devices > Configuration > Create > New PolicyIn the left navigation pane, select Devices, then Configuration (labeled Configuration profiles in some tenants).
Click + Create > New Policy (or + Create profile). In the wizard, set:
- Platform: Windows 10 and later
- Profile type: Settings catalog
Click Create to open the profile builder.
Settings catalog is the recommended method for managing Windows AI features. The exact button labels (Create vs. Create profile) vary slightly by tenant UI version.
Name and describe the policy
Make the policy easy to identify during administration, troubleshooting, and audits.
Devices > Configuration > (new profile) > BasicsOn the Basics page, enter identifying details:
- Name:
Disable Click to Do - Windows AI Policy - Description:
Disables the Click to Do feature on targeted Windows 11 devices via Windows AI policy settings. Prevents users from enabling AI-powered click actions.
Using an Action - Feature - Technology naming convention keeps policies sortable in large environments. Click Next to move to the Configuration settings page.
Keep names consistent across your Intune estate so related policies group together alphabetically.
Add the Windows AI Click to Do setting
Locate the relevant Windows AI catalog setting and add it to the profile.
Devices > Configuration > (new profile) > Configuration settings > Add settingsOn the Configuration settings page, click + Add settings to open the settings picker.
In the search box, type Click to Do or Windows AI to filter the catalog. Expand the Windows category, then Windows AI, and locate the Click to Do setting. Depending on your tenant's catalog version, it may appear as Disable Click to Do, Allow Click to Do, or Turn off Click to Do.
Select the checkbox next to the setting, then close the picker with the X in the upper-right corner. Note the exact name your tenant shows — you'll need it in the next step.
If no Windows AI or Click to Do settings appear, your tenant may not yet have the catalog entry, or the search term differs. Confirm you are managing Windows 11 devices that support the feature and check back after Intune service updates.
Configure the setting to disable the feature
Set the correct value so the policy enforces the restriction.
Devices > Configuration > (new profile) > Configuration settingsIn the profile's configuration area, find the Windows AI section that now holds your Click to Do setting, and set the value according to its name:
- If named Disable Click to Do — set it to Enabled (this turns on the restriction).
- If named Allow Click to Do — set it to Disabled (this blocks the feature).
This follows standard Windows policy logic: 'Disable' policies are set to Enabled to enforce the block, while 'Allow' policies are set to Disabled to prevent the action. Once the value is set, click Next to reach the Assignments page.
Choosing the wrong value can leave the feature available. Re-read the setting name carefully — a 'Disable' setting left as Disabled does not enforce anything.
Assign the policy to target groups
Scope the policy to the correct devices or users.
Devices > Configuration > (new profile) > AssignmentsOn the Assignments page, under Included groups, click + Add groups and select one or more Azure AD security groups.
For a device-level restriction like this, device groups (for example, Prod-Win11-Workstations) are generally preferred so the policy applies regardless of who signs in. User groups also work if you want the policy to follow specific users.
Select your groups and click Select. Optionally, add exclusion groups under the Exclude section. Click Next to continue to review.
Start with a small pilot group (for example, IT-Test-Devices) to validate behavior before assigning to your whole fleet. You can broaden the assignment later.
Review and create the policy
Validate all settings before deployment begins.
Devices > Configuration > (new profile) > Review + createOn the Review + create page, confirm each detail:
- Platform: Windows 10 and later
- Profile type: Settings catalog
- Name: Disable Click to Do - Windows AI Policy
- Configuration: Click to Do setting set to the correct value from the previous step
- Assignments: the intended Azure AD groups
When everything is correct, click Create. To change anything, use Previous to step back. Deployment to assigned devices begins immediately after creation.
Once you click Create, the policy starts deploying right away — double-check assignments first. Devices typically receive and apply the policy within 15-30 minutes on the automatic cycle.
Force a policy sync on target devices
Apply the policy immediately instead of waiting for the automatic sync cycle.
Devices > Windows > (device) > ... > SyncTrigger a manual sync using any of these methods:
From the Intune admin center: Go to Devices > Windows, select a target device, click the ... (More actions) button, and choose Sync.
From the Windows device: Open Settings > Accounts > Access work or school, select the organization account, click Info, then click Sync.
From Company Portal: Open the Company Portal app, go to Settings, and click Sync; wait for the Last sync timestamp to update.
If a sync appears stuck, wait a few minutes and retry. Manual sync only speeds up delivery; the policy still applies on its own within the normal 15-30 minute window.
Verify enforcement on devices and in Intune
Confirm Click to Do is disabled on the device and the policy reports success.
Devices > Windows > (device) > Device configurationOn the Windows 11 device: Press Windows + I to open Settings, go to Privacy & security, and look for Click to Do. When enforced, its toggle is Off and grayed out, a message notes the setting is managed by your organization, or the option no longer appears.
In the Intune admin center: Go to Devices > Windows, select a target device, open Device configuration (or Configuration profiles), find your Disable Click to Do policy, and confirm the Status column shows Succeeded.
Optionally, from an elevated command prompt on the device, query the Windows AI policy registry key to inspect the applied value.
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsAI"Run the registry query as Administrator. If the policy shows Pending, wait 15-30 minutes and refresh, or trigger another manual sync. Exact registry values may differ by Windows build and catalog version.
Confirming Click to Do Is Disabled and the Policy Is Enforced
A successful deployment means the Windows AI Click to Do control is being enforced by Intune, not just present in the console. There are two places to confirm this: the Intune admin center, where the policy reports its per-device deployment result, and the Windows 11 device itself, where the Click to Do control should be locked to the enforced state.
In Intune, open Devices > Windows, select a target device, open its Configuration profiles (or device configuration) view, and locate your Disable Click to Do - Windows AI Policy. The Status column reflects whether the device successfully applied the setting. On the device, open Settings > Privacy & security and check the Click to Do entry: when enforcement is working the toggle is off and greyed out, a 'managed by your organization' message appears, or the option is absent entirely. Optionally, from an elevated prompt you can query the underlying policy key with reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsAI" to confirm the value landed.
Remember the direction of the setting: a Disable Click to Do setting is enforced when set to Enabled, whereas an Allow Click to Do setting is enforced when set to Disabled. Both produce the same end result — users cannot turn the feature on.
- In Intune the policy shows a Succeeded status against the target device, and on the device the Click to Do control is off and unchangeable (greyed out, shown as managed by your organization, or not present). Users cannot enable Click to Do even by toggling it in Settings.
- The policy shows Pending, Error, or Conflict, or the Click to Do toggle on the device is still user-changeable. Pending usually resolves within 15-30 minutes or after another manual sync. A persistent error or conflict points to the setting not being applied — recheck the setting name and value, confirm the device is in an assigned group, and verify the device supports the Windows AI feature. If the setting never appeared in the catalog, the policy is not actually enforcing Click to Do.
- Shown in Devices > Windows > (device) > Configuration profiles for the Disable Click to Do policy once the device has applied the setting.
- Standard Windows policy logic: enabling a 'Disable' setting turns the feature off.
- If your tenant exposes an 'Allow' setting instead, set it to Disabled to prevent the feature.
- Confirms the user cannot re-enable the feature locally.
- Run from an elevated prompt to confirm the Windows AI policy value was written to the device.
Troubleshooting
Windows AI or Click to Do settings do not appear in the Settings Catalog search.
Cause: The tenant's Settings Catalog has not received the latest policy definitions, or the search term does not match how the setting is exposed in your tenant's catalog version.
Try alternate search terms such as Windows AI, Click to Do, or expand the Windows category and drill into Windows AI manually instead of relying on search. Confirm you are managing Windows 11 devices that support the feature and that your tenant is on a current Intune release. If the setting is still absent, wait for the catalog to update and re-check before building the profile.
Unsure whether to set the value to Enabled or Disabled to actually block the feature.
Cause: Windows policy naming follows opposite conventions: a 'Disable' policy enforces the restriction when Enabled, while an 'Allow' policy enforces it when Disabled.
Read the exact setting name your tenant exposes. If it reads Disable Click to Do, set it to Enabled. If it reads Allow Click to Do, set it to Disabled. Both configurations result in users being unable to use Click to Do.
Policy status shows Pending and Click to Do is still usable on the device.
Cause: The device has not yet completed an automatic or manual sync cycle, so the new policy has not been downloaded and applied.
Force a sync from Devices > Windows, select the device, choose ... > Sync, or trigger it on the device via Settings > Accounts > Access work or school > (org account) > Info > Sync. Wait 15-30 minutes and refresh the Intune status; sync itself typically completes in 2-5 minutes.
Policy reports a failed or error status on some target devices.
Cause: The assigned group targets devices or an OS build that does not support the Windows AI Click to Do setting, or the device has not checked in.
Confirm the assignment scope contains only Windows 11 devices that support the feature, verify the device has recently synced, and review the per-setting status under the device's Configuration profiles. Re-scope the assignment to exclude unsupported devices if needed.
Frequently asked questions
What is Click to Do in Windows 11 and why disable it?
Click to Do is a Windows 11 AI feature that lets users right-click text, images, and other content to run AI-powered actions. Organizations disable it because it can send user content to Microsoft's AI services, which may conflict with data governance requirements in regulated sectors such as healthcare, finance, and government.
Which Intune platform and profile type should I use to disable Click to Do?
Create a device configuration profile using Windows 10 and later as the platform and Settings catalog as the profile type. The Settings Catalog is the recommended method because it exposes the Windows AI controls that map directly to the underlying Group Policy settings.
Should I assign the Click to Do policy to device groups or user groups?
Device groups are typically preferred for this device-level policy because they apply the restriction consistently regardless of who signs in. User groups also work if you need to scope the policy to specific people's devices.
How long does it take for the Intune Click to Do policy to apply?
Automatic deployment to assigned devices typically takes 15-30 minutes. If you force a manual sync from Intune, the device, or the Company Portal app, the sync itself usually completes within 2-5 minutes.
Why don't I see the Windows AI or Click to Do settings in the Settings Catalog?
The setting may be missing if your tenant has not received the latest Intune catalog updates or if you are not targeting Windows 11 devices that support the feature. Try searching for both Windows AI and Click to Do, or expand the Windows > Windows AI category manually, and re-check after the catalog updates.
How do I verify that Click to Do has been disabled on a device?
On the Windows 11 device, open Settings > Privacy & security and confirm the Click to Do toggle is off, grayed out, or marked as managed by your organization. In Intune, check that the policy shows a Succeeded status for the device, and optionally run reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsAI" to confirm the registry value.






