I want to make sure that a user in our domain [email protected] does not login to a device that has been assigned to [email protected]. I have created a configuration profile but not sure what the settings should be and the string value to be for such kind of situation.
Any suggestions and answer would be appreciated.
You can add Allow Local Log On and Deny Local Log On rights from User Rights category from Settings Catalog to the Configuration Profile you created
Username format is
AzureAD\[email protected]
Details are here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-userrights#userrights-allowlocallogon