2.3.1.1 (L1) Ensure 'Accounts: Block Microsoft accounts' is set to 'Users can't add or log on with Microsoft accounts'

Information

This policy setting prevents users from adding new Microsoft accounts on this computer.

The recommended state for this setting is: Users can't add or log on with Microsoft accounts

Note: Due to the way Windows 10 version 1607 (and older) handles the process for adding Microsoft Accounts, this legacy setting will remain in the Windows 10 Benchmarks until extended support for LTSB 1607 ends in

October of 2026

. Applying this setting to newer versions of the OS will not cause an issue, and the OS will ignore the setting. For newer versions of the OS, this setting has been replaced with

Block all consumer Microsoft account user authentication

. For more information please visit:

Accounts Block Microsoft accounts - Windows 10 | Microsoft Learn

.

Organizations that want to effectively implement identity management policies and maintain firm control of what accounts are used to log onto their computers will probably want to block Microsoft accounts. Organizations may also need to block Microsoft accounts in order to meet the requirements of compliance standards that apply to their information systems.

Solution

To establish the recommended configuration via GP, set the following UI path to Users can't add or log on with Microsoft accounts :

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Accounts: Block Microsoft accounts

Impact:

Users will not be able to log onto the computer with their Microsoft account.

See Also

https://workbench.cisecurity.org/benchmarks/21994