Login user allow list

Defines the list of users that are allowed to login to the device. Entries are of the form user@domain, such as [email protected]. To allow arbitrary users on a domain, use entries of the form *@domain.

If this policy is not configured, there are no restrictions on which users are allowed to sign in. Note that creating new users still requires the DeviceAllowNewUsers policy to be configured appropriately.
If DeviceFamilyLinkAccountsAllowed is enabled, Family Link users will be allowed additionally to the accounts defined in this policy.

Example value:

[email protected]

Supported on: At least Microsoft Windows 7 or Windows Server 2008 family

Login user allow list

Registry PathSoftware\Policies\Google\ChromeOS\DeviceUserAllowlist
Value Name{number}
Value TypeREG_SZ
Default Value


Administrative Templates (Computers)

Administrative Templates (Users)