diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md
index 1dda28b5c8..ec5e0b87bc 100644
--- a/windows/client-management/mdm/policy-configuration-service-provider.md
+++ b/windows/client-management/mdm/policy-configuration-service-provider.md
@@ -6643,6 +6643,14 @@ dfsdiscoverdc">ADMX_DFS/DFSDiscoverDC
+### FederatedAuthentication policies
+
+
+ -
+ FederatedAuthentication/EnableWebSignInForPrimaryUser
+
+
+
### Feeds policies
-
diff --git a/windows/client-management/mdm/policy-csp-federatedauthentication.md b/windows/client-management/mdm/policy-csp-federatedauthentication.md
new file mode 100644
index 0000000000..6933fd3afe
--- /dev/null
+++ b/windows/client-management/mdm/policy-csp-federatedauthentication.md
@@ -0,0 +1,81 @@
+---
+title: Policy CSP - FederatedAuthentication
+description: Use the Policy CSP - Represents the enablement state of the Web Sign-in Credential Provider for device sign-in.
+ms.author: v-nsatapathy
+ms.topic: article
+ms.prod: w10
+ms.technology: windows
+author: nimishasatapathy
+ms.localizationpriority: medium
+ms.date: 09/07/2022
+ms.reviewer:
+manager: dansimp
+---
+
+# Policy CSP - FederatedAuthentication
+
+
+
+
+
+## FederatedAuthentication policies
+
+
+ -
+ FederatedAuthentication/EnableWebSignInForPrimaryUser
+
+
+
+
+
+
+
+**FederatedAuthentication/EnableWebSignInForPrimaryUser**
+
+
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|No|No|
+|Business|No|No|
+|Enterprise|No|No|
+|Education|No|No|
+|Windows SE|Yes|No|
+
+> [!NOTE]
+> Only available on Windows SE edition when Education/IsEducationEnvironment policy is also set to "1".
+
+
+
+
+
+
+[Scope](./policy-configuration-service-provider.md#policy-scope):
+
+> [!div class = "checklist"]
+> * Machine
+
+
+
+
+
+This policy specifies whether Web Sign-in can be used for device sign-in in a single-user environment.
+
+> [!NOTE]
+> Web Sign-in is only supported on Azure AD Joined PCs.
+
+
+
+
+Value type is integer:
+- 0 - (default): Feature defaults as appropriate for edition and device capabilities.
+- 1 - Enabled: Web Sign-in Credential Provider will be enabled for device sign-in.
+- 2 - Disabled: Web Sign-in Credential Provider won't be enabled for device sign-in.
+
+
+
+
+
+
+
diff --git a/windows/client-management/mdm/toc.yml b/windows/client-management/mdm/toc.yml
index eaea592be5..888db084cb 100644
--- a/windows/client-management/mdm/toc.yml
+++ b/windows/client-management/mdm/toc.yml
@@ -408,6 +408,8 @@ items:
href: policy-csp-experience.md
- name: ExploitGuard
href: policy-csp-exploitguard.md
+ - name: Federated Authentication
+ href: policy-csp-federatedauthentication.md
- name: Feeds
href: policy-csp-feeds.md
- name: FileExplorer