I have an Entra-joined Windows device managed through Intune, with a few basic configuration profiles and the Windows Security Baseline enabled. I need it to automatically sign in with a local account at startup because the device is being used as a till server and must launch an application that cannot run as a service.
Sysinternals Autologon successfully writes the username, password, and AutoAdminLogon value to the registry. However, after reboot, AutoAdminLogon is changed from 1 back to 0, so automatic sign-in does not occur. I have tried different formats for the username, including .\localuser, the computer name, and leaving the domain blank.
There does not appear to be an obvious related setting in the security baseline. Has anyone identified which Intune, Windows security, or Entra setting resets AutoAdminLogon? Is automatic sign-in with a local account supported on an Entra-joined device, and is there a reliable way to configure it without removing the device from Autopilot and Intune?
2 Answers
The security baseline is the first thing I would suspect. Exclude the device from that baseline, force an Intune sync, and then test again. Credential Guard or related credential protection settings may also interfere with Sysinternals Autologon, so check whether those are enabled for the device. If you were using an Entra account, the expected format would generally be the full UPN with the domain set to AzureAD, but that is separate from using a local account.
Something is almost certainly applying a policy after the Autologon tool writes the registry values. Group Policy, MDM policy, security hardening, or a credential-protection setting can reset AutoAdminLogon to 0 during startup. Check the effective Intune policies and event logs around the reboot, and compare the registry before shutdown and after startup. If the baseline exclusion does not help, look for another policy that disables automatic sign-in rather than assuming the Entra join itself is the cause.
There is no known legacy Group Policy in this environment, but the devices were previously managed in a fairly inconsistent way. It feels like an MDM or Windows security setting, so I will compare the policies and registry state after an Intune sync and reboot.

The account is definitely local and I am using the .\localuser format. I have excluded the device from the baseline and will retest after Intune applies the change. If that fixes it, I will investigate which credential-protection setting is responsible.