diff --git a/windows/manage/set-up-shared-or-guest-pc.md b/windows/manage/set-up-shared-or-guest-pc.md index 3503c0eba5..7caf8b071e 100644 --- a/windows/manage/set-up-shared-or-guest-pc.md +++ b/windows/manage/set-up-shared-or-guest-pc.md @@ -23,7 +23,7 @@ Windows 10, version 1607, introduces *shared PC mode*, which optimizes Windows 1 A Windows 10 PC in shared PC mode is designed to be management- and maintenance-free with high reliability. In shared PC mode, only one user can be signed in at a time. When the PC is locked, the currently signed in user can always be signed out at the lock screen. Users who sign-in are signed in as standard users, not admin users. ###Account models -It is intended that shared PCs are joined to an Active Directory or Azure Active Directory domain by a user with the necessary rights to perform a domain join as part of a setup process. This enables any user that is part of the directory to sign-in to the PC as a standard user. The user who origianlly joined the PC to the domain will have administrative rights when they sign in. If using Azure Active Directory Premium, any domain user can also be configured to sign in with administrative rights. Additionally, shared PC mode can be configured to enable a **Start without an account** option on the sign-in screen, which doesn't require any user credentials or authentication and creates a new local account. +It is intended that shared PCs are joined to an Active Directory or Azure Active Directory domain by a user with the necessary rights to perform a domain join as part of a setup process. This enables any user that is part of the directory to sign-in to the PC as a standard user. The user who originally joined the PC to the domain will have administrative rights when they sign in. If using Azure Active Directory Premium, any domain user can also be configured to sign in with administrative rights. Additionally, shared PC mode can be configured to enable a **Start without an account** option on the sign-in screen, which doesn't require any user credentials or authentication and creates a new local account. ###Account management When the account management service is turned on in shared PC mode, accounts are automatically deleted. Account deletion is done for Active Directory, Azure Active Directory, and local account types. However, only local accounts that are created by the **Start without an account** option are deleted. Account management is performed both at sign-off time (to make sure there is enough disk space for the next user) as well as during system maintenance time periods. Shared PC mode can be configured to delete accounts immediately at sign-out or when disk space is low. @@ -188,7 +188,7 @@ On a desktop computer, navigate to **Settings** > **Accounts** > **Work ac ## Policies set by shared PC mode -Shared pc mode sets local group policies to configure the device. Some of these are configurable by setting the options shared pc mode exposes. +Shared PC mode sets local group policies to configure the device. Some of these are configurable using the shared pc mode options. > **Important**: It is not recommended to set additional policies on PCs configured for **Shared PC Mode**. The shared PC mode has been optimized to be fast and reliable over time with minimal to no manual maintenance required. @@ -197,13 +197,13 @@ Shared pc mode sets local group policies to configure the device. Some of these

Policy name

Value

When set?

-

Admin Templates > Control Panel > Personalization

+

Admin Templates > Control Panel > Personalization

Prevent enabling lock screen slide show

Enabled

Always

Prevent changing lock screen and logon image

Enabled

Always

-

Admin Templates > System > Power Management > Button Settings

+

Admin Templates > System > Power Management > Button Settings

Select the Power button action (plugged in)

Sleep

SetPowerPolicies=True

@@ -215,7 +215,7 @@ Shared pc mode sets local group policies to configure the device. Some of these

Select the lid switch action (on battery)

Sleep

SetPowerPolicies=True

-

Admin Templates > System > Power Management > Sleep Settings

+

Admin Templates > System > Power Management > Sleep Settings

Require a password when a computer wakes (plugged in)

Enabled

SignInOnResume=True

@@ -241,12 +241,12 @@ Shared pc mode sets local group policies to configure the device. Some of these

Specify the system hibernate timeout (on battery)

Enabled, 0

SetPowerPolicies=True

-

Admin Templates>System>Power Management>Video and Display Settings

+

Admin Templates>System>Power Management>Video and Display Settings

Turn off the display (plugged in)

*SleepTimeout*

SetPowerPolicies=True

Turn off the display (on battery

*SleepTimeout*

SetPowerPolicies=True

-

Admin Templates>System>Logon

+

Admin Templates>System>Logon

Show first sign-in animation

Disabled

Always

@@ -262,11 +262,11 @@ Shared pc mode sets local group policies to configure the device. Some of these

Block user from showing account details on sign-in

Enabled

Always

-

Admin Templates>System>User Profiles

+

Admin Templates>System>User Profiles

Turn off the advertising ID

Enabled

SetEduPolicies=True

-

Admin Templates>Windows Components

+

Admin Templates>Windows Components

Do not show Windows Tips

*Only on Pro, Enterprise, and Education*

Enabled

SetEduPolicies=True

@@ -276,7 +276,7 @@ Shared pc mode sets local group policies to configure the device. Some of these

Prevent the usage of OneDrive for file storage

Enabled

Always

-

Admin Templates>Windows Components>Biometrics

+

Admin Templates>Windows Components>Biometrics

Allow the use of biometrics

Disabled

Always

@@ -284,7 +284,7 @@ Shared pc mode sets local group policies to configure the device. Some of these

Allow domain users to log on using biometrics

Disabled

Always

-

Admin Templates>Windows Components>Data Collection and Preview Builds

+

Admin Templates>Windows Components>Data Collection and Preview Builds

Toggle user control over Insider builds

Disabled

Always

@@ -292,11 +292,11 @@ Shared pc mode sets local group policies to configure the device. Some of these

Do not show feedback notifications

Enabled

Always

-

Admin Templates>Windows Components>File Explorer

+

Admin Templates>Windows Components>File Explorer

Show lock in the user tile menu

Disabled

Always

-

Admin Templates>Windows Components>Maintenance Scheduler

+

Admin Templates>Windows Components>Maintenance Scheduler

Automatic Maintenance Activation Boundary

*MaintenanceStartTime*

Always

@@ -304,17 +304,17 @@ Shared pc mode sets local group policies to configure the device. Some of these

Automatic Maintenance WakeUp Policy

Enabled

Always

-

Admin Templates>Windows Components>Microsoft Edge

+

Admin Templates>Windows Components>Microsoft Edge

Open a new tab with an empty tab

Disabled

SetEduPolicies=True

Configure corporate home pages

Enabled, about:blank

SetEduPolicies=True

-

Admin Templates>Windows Components>Search

+

Admin Templates>Windows Components>Search

Allow Cortana

Disabled

SetEduPolicies=True

-

Windows Settings>Security Settings>Local Policies>Security Options

+

Windows Settings>Security Settings>Local Policies>Security Options

Interactive logon: Do not display last user name

Enabled, Disabled when account model is only guest