mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 05:17:22 +00:00
3.7 KiB
3.7 KiB
title, description, ms.topic, ms.date
title | description | ms.topic | ms.date |
---|---|---|---|
Disable Winlogon automatic restart sign-on (ARSO) for PDE in Intune | Disable Winlogon automatic restart sign-on (ARSO) for PDE in Intune | how-to | 06/01/2023 |
Disable Winlogon automatic restart sign-on (ARSO) for PDE
Winlogon automatic restart sign-on (ARSO) isn't supported for use with Personal Data Encryption (PDE). For this reason, in order to use PDE, ARSO needs to be disabled.
Disable Winlogon automatic restart sign-on (ARSO) in Intune
To disable ARSO using Intune, follow the below steps:
- Sign in to the Microsoft Intune admin center
- In the Home screen, select Devices in the left pane
- In the Devices | Overview screen, under Policy, select Configuration Profiles
- In the Devices | Configuration profiles screen, make sure Profiles is selected at the top, and then select Create profile
- In the Create profile window that opens:
- Under Platform, select Windows 10 and later
- Under Profile type, select Templates
- When the templates appear, under Template name, select Administrative templates
- Select Create to close the Create profile window.
- The Create profile screen will open. In the Basics page:
- Next to Name, enter Disable ARSO
- Next to Description, enter a description
- Select Next
- In the Configuration settings page:
- On the left pane of the page, make sure Computer Configuration is selected
- Under Setting name, scroll down and select Windows Components
- Under Setting name, scroll down and select Windows Logon Options. You may need to navigate between pages on the bottom right corner before finding the Windows Logon Options option
- Under Setting name of the Windows Logon Options pane, select Sign-in and lock last interactive user automatically after a restart
- In the Sign-in and lock last interactive user automatically after a restart window that opens, select Disabled, and then select OK
- Select Next
- In the Scope tags page, configure if necessary and then select Next
- In the Assignments page:
- Under Included groups, select Add groups
Note
Make sure to select Add groups under Included groups and not under Excluded groups. Accidentally adding the desired device groups under Excluded groups will result in those devices being excluded and they won't receive the configuration profile.
- In the Select groups to include window that opens, select the groups that the configuration profile should be assigned to, and then select Select to close the Select groups to include window
- Under Included groups > Groups, ensure the correct group(s) are selected, and then select Next
- Under Included groups, select Add groups
- In Review + create page, review the configuration to make sure everything is configured correctly, and then select Create
Additional PDE configurations in Intune
The following PDE configurations can also be configured using Intune:
Prerequisites
Security hardening recommendations
- Disable kernel-mode crash dumps and live dumps
- Disable Windows Error Reporting (WER)/user-mode crash dumps
- Disable hibernation
- Disable allowing users to select when a password is required when resuming from connected standby