diff --git a/windows/manage/set-up-shared-or-guest-pc.md b/windows/manage/set-up-shared-or-guest-pc.md index 3503c0eba5..7caf8b071e 100644 --- a/windows/manage/set-up-shared-or-guest-pc.md +++ b/windows/manage/set-up-shared-or-guest-pc.md @@ -23,7 +23,7 @@ Windows 10, version 1607, introduces *shared PC mode*, which optimizes Windows 1 A Windows 10 PC in shared PC mode is designed to be management- and maintenance-free with high reliability. In shared PC mode, only one user can be signed in at a time. When the PC is locked, the currently signed in user can always be signed out at the lock screen. Users who sign-in are signed in as standard users, not admin users. ###Account models -It is intended that shared PCs are joined to an Active Directory or Azure Active Directory domain by a user with the necessary rights to perform a domain join as part of a setup process. This enables any user that is part of the directory to sign-in to the PC as a standard user. The user who origianlly joined the PC to the domain will have administrative rights when they sign in. If using Azure Active Directory Premium, any domain user can also be configured to sign in with administrative rights. Additionally, shared PC mode can be configured to enable a **Start without an account** option on the sign-in screen, which doesn't require any user credentials or authentication and creates a new local account. +It is intended that shared PCs are joined to an Active Directory or Azure Active Directory domain by a user with the necessary rights to perform a domain join as part of a setup process. This enables any user that is part of the directory to sign-in to the PC as a standard user. The user who originally joined the PC to the domain will have administrative rights when they sign in. If using Azure Active Directory Premium, any domain user can also be configured to sign in with administrative rights. Additionally, shared PC mode can be configured to enable a **Start without an account** option on the sign-in screen, which doesn't require any user credentials or authentication and creates a new local account. ###Account management When the account management service is turned on in shared PC mode, accounts are automatically deleted. Account deletion is done for Active Directory, Azure Active Directory, and local account types. However, only local accounts that are created by the **Start without an account** option are deleted. Account management is performed both at sign-off time (to make sure there is enough disk space for the next user) as well as during system maintenance time periods. Shared PC mode can be configured to delete accounts immediately at sign-out or when disk space is low. @@ -188,7 +188,7 @@ On a desktop computer, navigate to **Settings** > **Accounts** > **Work ac ## Policies set by shared PC mode -Shared pc mode sets local group policies to configure the device. Some of these are configurable by setting the options shared pc mode exposes. +Shared PC mode sets local group policies to configure the device. Some of these are configurable using the shared pc mode options. > **Important**: It is not recommended to set additional policies on PCs configured for **Shared PC Mode**. The shared PC mode has been optimized to be fast and reliable over time with minimal to no manual maintenance required. @@ -197,13 +197,13 @@ Shared pc mode sets local group policies to configure the device. Some of these
Policy name
Value
When set?
Admin Templates > Control Panel > Personalization
Admin Templates > Control Panel > Personalization
Prevent enabling lock screen slide show
Enabled
Always
Prevent changing lock screen and logon image
Enabled
Always
Admin Templates > System > Power Management > Button Settings
Admin Templates > System > Power Management > Button Settings
Select the Power button action (plugged in)
Sleep
SetPowerPolicies=True
Select the lid switch action (on battery)
Sleep
SetPowerPolicies=True
Admin Templates > System > Power Management > Sleep Settings
Admin Templates > System > Power Management > Sleep Settings
Require a password when a computer wakes (plugged in)
Enabled
SignInOnResume=True
Specify the system hibernate timeout (on battery)
Enabled, 0
SetPowerPolicies=True
Admin Templates>System>Power Management>Video and Display Settings
Admin Templates>System>Power Management>Video and Display Settings
Turn off the display (plugged in)
*SleepTimeout*
SetPowerPolicies=True
Turn off the display (on battery
*SleepTimeout*
SetPowerPolicies=True
Admin Templates>System>Logon
Admin Templates>System>Logon
Show first sign-in animation
Disabled
Always
Block user from showing account details on sign-in
Enabled
Always
Admin Templates>System>User Profiles
Admin Templates>System>User Profiles
Turn off the advertising ID
Enabled
SetEduPolicies=True
Admin Templates>Windows Components
Admin Templates>Windows Components
Do not show Windows Tips
*Only on Pro, Enterprise, and Education*Enabled
SetEduPolicies=True
Prevent the usage of OneDrive for file storage
Enabled
Always
Admin Templates>Windows Components>Biometrics
Admin Templates>Windows Components>Biometrics
Allow the use of biometrics
Disabled
Always
Allow domain users to log on using biometrics
Disabled
Always
Admin Templates>Windows Components>Data Collection and Preview Builds
Admin Templates>Windows Components>Data Collection and Preview Builds
Toggle user control over Insider builds
Disabled
Always
Do not show feedback notifications
Enabled
Always
Admin Templates>Windows Components>File Explorer
Admin Templates>Windows Components>File Explorer
Show lock in the user tile menu
Disabled
Always
Admin Templates>Windows Components>Maintenance Scheduler
Admin Templates>Windows Components>Maintenance Scheduler
Automatic Maintenance Activation Boundary
*MaintenanceStartTime*
Always
Automatic Maintenance WakeUp Policy
Enabled
Always
Admin Templates>Windows Components>Microsoft Edge
Admin Templates>Windows Components>Microsoft Edge
Open a new tab with an empty tab
Disabled
SetEduPolicies=True
Configure corporate home pages
Enabled, about:blank
SetEduPolicies=True
Admin Templates>Windows Components>Search
Admin Templates>Windows Components>Search
Allow Cortana
Disabled
SetEduPolicies=True
Windows Settings>Security Settings>Local Policies>Security Options
Windows Settings>Security Settings>Local Policies>Security Options
Interactive logon: Do not display last user name
Enabled, Disabled when account model is only guest