Hi @SM • Thank you for reaching out.
You can restrict users from registering devices in Azure AD by using the below setting:
Azure Portal > Azure Active Directory > Devices > Device settings > Users may register their devices with Azure AD > None
Note: This setting will be greyed-out if you are using Microsoft Intune or mobile device management for Microsoft 365 as in that case, you should be using MDM for this purpose.
Users may register their devices with Azure AD: You need to configure this setting to allow users to register Windows 10 personal, iOS, Android, and macOS devices with Azure AD. If you select None, devices aren't allowed to register with Azure AD. Enrollment with Microsoft Intune or mobile device management for Microsoft 365 requires registration. If you've configured either of these services, ALL is selected and NONE is unavailable.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.