2.10.1 Ensure 'Allow automatic sign-in to Microsoft cloud identity providers' Is Enabled

Information

This policy setting allows accounts backed by a Microsoft cloud identity provider (i.e., Microsoft Azure Active Directory or the consumer Microsoft account identity provider) can be signed into web properties using that identity automatically. It can be configured to either:

Disabled (0): Disable Microsoft cloud authentication

Enabled (1): Enable Microsoft cloud authentication

If the value for CloudAPAuthEnabled is not changed from the default, it will behave as it is disabled.

Rationale:

Enabling this policy setting allows users to use Microsoft Cloud Authentication for any site that requires CA (Cloud Authentication) and does not require an extension.

Impact:

There should be no impact to the user.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Enable Microsoft cloud authentication:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Microsoft Active Directory management settings\Allow automatic sign-in to Microsoft cloud identity providers

Default Value:

Unset (Disabled)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: 17ca222dada3e81648fedc8082bd886b21dbd006b2fe3c20140893391cc6c6ca