Hi @Naija R C,
Based on your query, here is my understanding: You would like to know the factors of when "Windows sign in" triggers in the sign in logs.
Windows sign in logs mainly triggers when you have Cloud Kerberos working in the background. This includes the services like Windows hello for business, Intune policies applied on the device (Even if it is registered). Entra ID registered device also contains a PRT which triggers SSO for you on the applications, this may not be seen in the logs or the device, but it is the reason for SSO on Entra ID devices. Regardless of your device registration status if the device has any requirement with cloud Kerberos, the device will definitely have windows sign in activities available in sign in logs.
Here is the document which shows key capabilities and device sign in options of Entra ID registered device which are reasons for Windows sign in logs: Microsoft Entra registered devices
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly "upvote it". If you have extra questions about this answer, please click "Comment"