Configuring the 'Allow updates to status bar via script' Intranet Zone policy enables Microsoft Entra Seamless SSO via GPO
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. You plan to implement single sign-on (SSO) for Azure AD resources. You need to configure an Intranet Zone setting for all users by using a Group Policy Object (GPO). Which setting should you configure?
Community Votes
80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Seamless SSO relies on the AZUREADSSOACC computer account and a Kerberos ticket; the GPO step that matters here is the Intranet Zone policy permitting status-bar script updates, not MFA or Conditional Access.
To roll out Microsoft Entra Seamless SSO to all domain-joined users, you deploy a GPO that adds the autologon URL to the Local Intranet zone and enables the 'Allow updates to status bar via script' setting so the browser can update the status bar during silent sign-in.
Candidates confuse 'Logon options' (automatic logon with current credentials) with the specific Seamless SSO rollout policy; the question asks which Intranet Zone setting must be configured, and that is 'Allow updates to status bar via script'.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra Seamless SSO lets users sign in silently with their on-premises credentials. The documented GPO rollout adds https://autologon.microsoftazuread-sso.com to the Local Intranet zone and enables the 'Allow updates to status bar via script' policy so the browser can perform the silent token exchange. Without this Intranet Zone setting the status bar cannot be updated during the scripted sign-in and SSO fails. (Option B)Why the Other Options Are Wrong
- Option A (Logon options) controls automatic logon with the current username and password but is not the specific Seamless SSO rollout policy the question targets.
- Option C (Allow active scripting) governs script execution in the browser and is unrelated to the SSO status-bar update.
- Option D (Access data sources across domains) controls cross-domain data access and has no role in Seamless SSO.