Does onedrive signing in cause Azure AD joined or registered?

SUIKA-5822 120 Reputation points
2025-05-03T11:25:18.6166667+00:00

If the organiztion enabled the auto MDM enrollment, Does signing in to OneDrive with a work account in a browser or desktop app cause Azure AD joined or registered? (with selecting the "No,this app only")

And would this trigger the auto MDM enrollment?

If possible, could you please help test this? I would be extremely grateful for your help!

Thanks in advance!

Screenshot of the device registration with device management dialog.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,633 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jyotishree Moharana 1,355 Reputation points Microsoft External Staff Moderator
    2025-05-06T12:05:20.37+00:00

    Hello @SUIKA-5822,

    Based on your description Auto MDM enrollment is enabled and you want to know the behavior when User signs into OneDrive with their work or school account and receives a sign-in pop up and select No, this app only. In this scenario since the user has selected only "No, this app only” this prevents the device from being Azure AD registered, or Azure AD joined. The sign-in will only receive a token for the app login (in this case OneDrive). So, the device will not be Azure AD joined or registered. Auto MDM enrollment will not be triggered in this scenario as the user selected "No, this app only” option.

    To understand the prompt more properly we will go through the actions which get executed based on the selections done in the prompt.

    There are 3 selections in the prompt.

    1. Yes, all apps: Allows your work or school account to sign you into other desktop apps and websites you use on this device.
    2. No, this app only: Signs you into the current app only, without affecting other apps.
    3. Allow my organization to manage this device: Enabling this allows your organization to enroll your device in Mobile Device Management (MDM), granting them the ability to manage device settings and security policies.

    The different scenarios based on selections given that Auto MDM enrollment is ON:

    1. Selecting "Yes, all apps" and checking "Allow my organization to manage this device" : Device will get registered to Entra ID (Joined in case of corporate owned device) and will get enrolled in MDM as well. All the device settings, security policies, compliance policies will get enforced. SSO experience across all MS apps.
    2. Selecting "No, this app only" and checking "Allow my organization to manage this device" : Device will not be registered with Entra ID, since registration didn't happen MDM enrollment will also not happen. Only the current app will use your work school account other apps will remain unaffected.
    3. Selecting "Yes, all apps" and leaving "Allow my organization to manage this device" unchecked : Device will be registered with Entra ID but MDM enrollment will not happen even though device is registered as the second option was left unchecked. SSO will work across MS apps.
    4. Selecting "No, this app only" and leaving "Allow my organization to manage this device" unchecked : Device will not be registered with Entra ID, MDM enrollment will also not happen. Only the current app will use your work school account other apps will remain unaffected.

    Document for more information: Add-your-work-or-school-account-to-a-windows-device

    If you have any further questions, please do let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.