Skip to content

Microsoft 365 disable stay signed in prompt

How to disable Microsoft 365 stay signed in prompt? We all have seen it when signing in to Microsoft 365, a prompt shows if you want to stay signed in Microsoft 365. For security reasons, it’s better to turn off Microsoft 365 stay signed in prompt. For the ones that do not want to show that prompt because it’s irritating, that would work too. In this article, you will learn how to turn off Microsoft 365 stay signed in prompt.

Microsoft 365 stay signed in prompt security risk

Why is this a security risk? For example, the user signs in to Microsoft 365 and clicks on Yes when the prompt appears. When finished working, the user did not click the Sign Out button. Most of the users close the browser and quit.

When closing the browser and opening the Microsoft 365 portal, you are still signed in without entering the credentials. What if it’s a public computer? That means another random person will have access to your confidential emails, documents, and more.

Important: Warn the users in the organization about not using a shared computer when accessing the Microsoft 365 portal. If they don’t have many options and have to sign in, use the Sign Out button when done with working. Closing a browser is not the same as signing out.

Microsoft 365 stay signed in prompt

Users sign in to the Microsoft 365 portal. After they enter their credentials, the users get a prompt:

Stay signed in? Do this to reduce the number of times you are asked to sign in. Don’t show this again. No/Yes.

Microsoft 365 disable stay signed in prompt show prompt

Disable Microsoft 365 stay signed in prompt

To turn off the Microsoft 365 stay signed in prompt after a user signs in, follow the below steps:

  1. Sign in to Microsoft Entra admin center using a Global administrator account
  2. Click on Identity > Users > User settings
  3. Go to the setting Show keep user signed in, and set it to No
  4. Click Save
Microsoft 365 disable stay signed in prompt Entra ID

The users will not get the prompt to stay signed in Microsoft 365 after entering their credentials.

Note: The sessions will remain active if the users have already accepted the stay signed in prompt. The best way is to revoke all users’ access by signing them out from all their Microsoft 365 sessions. Read more in the article Force sign-out users in Microsoft 365 with PowerShell.

Disable Microsoft 365 stay signed in prompt with Conditional Access policy

You can disable the stay signed in prompt with a Conditonal Access policy. However, using Conditional Access policies means that you need Microsoft Entra ID P1 or Microsoft Entra ID P2.

To disable Microsoft 365 stay signed in prompt with Conditional Access policy, follow the below steps:

  1. Sign in to Microsoft Entra admin center using a Global administrator account
  2. Click on Protection > Conditional Access
  3. Click on + Create new policy
Microsoft 365 disable stay signed in prompt create new policy
  1. Give the policy the name Disable stay signed in prompt
  2. Select All users
  3. Target All cloud apps
  4. Select Persistent browser session – Never persistent
  5. Enable the policy
  6. Click Create
Configure CA policy

Verify your work

Test it out by clearing the browser cache and starting the browser. You don’t see the stay signed in prompt after entering your credentials, and you have to sign in every time you restart the browser. Another way to test is to open a private window and sign in.

Did it help you to disable the Microsoft 365 stay signed in prompt?

Keep reading: How to Restrict access to Microsoft Entra admin center »

Conclusion

You learned how to disable Microsoft 365 stay signed in prompt. If you have Microsoft Entra ID Free, use the first method. Security-wise, it’s good to turn off Microsoft 365 stay signed in prompt setting, and keep the organization’s security in good shape.

Did you enjoy this article? You may also like Get Office 365 activity alerts when user signs in. Don’t forget to follow us and share this article.

ALI TAJRAN

ALI TAJRAN

ALI TAJRAN is a passionate IT Architect, IT Consultant, and Microsoft Certified Trainer. He started Information Technology at a very young age, and his goal is to teach and inspire others. Read more »

This Post Has 9 Comments

  1. Hi,

    Can this be set to no for a specific Azure AD SSO connection? For example, we use Azure AD (Sorry, trying to get used to Entra) as the authentication source for our VPN software. I want to disable this feature for VPN only.

    Thanks

  2. Is it possible to remove “Keep me signed in” and enable “Always Persistant” on managed devices?
    I tried to include AADJ and set “Always Persistant” in my conditional access policy, but it still prompt for reauthentication after closing the browser… Thank you

    1. If your browser gets a persistent cookie and still asks for reauthentication, then i think there is a problem with your browser settings. Normally managed devices does have a registered work- and schoolaccount which your browser uses, indepently of the cookie. For this, the browser must be able to establish a connection to this account. If it doesn’t, check this:

      https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-conditions#supported-browsers

  3. How can I be 100% sure that all of the users who used the stay sign in functionality, have been logged out after the option has been disabled?

Leave a Reply

Your email address will not be published. Required fields are marked *