There is nothing directly built-in to achieve this today. There are a handful of community provided methods to do this though -- all involve running scripts on the endpoints. A quick web search should net you these methods -- I found these after a few seconds: https://www.inthecloud247.com/restrict-which-users-can-logon-into-a-windows-10-device-with-microsoft-intune/ and https://jannikreinhard.com/2021/09/24/how-to-restrict-the-login-to-dedicated-users-with-intune.
Restrict logon to Primary User
Gareth Roberts
186
Reputation points
Hi,
We have a requirement to only allow the primary users of windows 10 intune enrolled laptops to be able to log in to their device, as well as administrators. The aim is to stop users from sharing laptops between themselves.
However this policy would need to be deployed to the entire user base.
Does anyone have a suggestion of how this could be achieved? I was hoping this scenario might have been documented by someone else in the past but so far I haven't been able to find anything.
1 answer
Sort by: Most helpful
-
Jason Sandys 31,306 Reputation points Microsoft Employee
2022-07-18T14:22:52.55+00:00