10 KiB
title, description, author, manager, ms.author, ms.date, ms.localizationpriority, ms.prod, ms.technology, ms.topic
title | description | author | manager | ms.author | ms.date | ms.localizationpriority | ms.prod | ms.technology | ms.topic |
---|---|---|---|---|---|---|---|---|---|
CloudDesktop CSP | Learn more about the CloudDesktop CSP. | vinaypamnani-msft | aaroncz | vinpa | 08/10/2023 | medium | windows-client | itpro-manage | reference |
CloudDesktop CSP
[!INCLUDE Windows Insider tip]
The following list shows the CloudDesktop configuration service provider nodes:
- ./Device/Vendor/MSFT/CloudDesktop
EnableBootToCloudSharedPCMode
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ❌ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows Insider Preview [10.0.22631.2050] |
./Device/Vendor/MSFT/CloudDesktop/EnableBootToCloudSharedPCMode
Setting this node to "true" configures boot to cloud for Shared PC mode. Boot to cloud mode enables users to seamlessly sign-in to a Cloud PC. Shared PC mode allows multiple users to sign-in on the device and use for shared purpose. For enabling boot to cloud shared pc feature, Cloud Provider application must be installed on the PC and the user must have a Cloud PC provisioned.
Description framework properties:
Property name | Property value |
---|---|
Format | bool |
Access Type | Add, Delete, Get, Replace |
Default Value | false |
Allowed values:
Value | Description |
---|---|
false (Default) | Not configured. |
true | Boot to cloud shared pc mode enabled. |
EnableBootToCloudSharedPCMode technical reference
EnableBootToCloudSharedPCMode setting is used to configure Boot to Cloud feature for shared user mode. When you enable this setting, multiple policies are applied to achieve the intended behavior.
Note
It is recommended not to set any of the policies enforced by this setting to different values, as these policies help provide a smooth UX experience for the Boot to Cloud feature for shared user mode.
MDM Policies
When this mode is enabled, these MDM policies are applied for the Device scope (all users):
Setting | Value | Value Description |
---|---|---|
CloudDesktop/BootToCloudMode | 1 | Enable Boot to Cloud Desktop |
WindowsLogon/OverrideShellProgram | 1 | Apply Lightweight Shell |
ADMX_CredentialProviders/DefaultCredentialProvider | Enabled | Configures default credential provider to password provider |
ADMX_Logon/DisableExplorerRunLegacy_2 | Enabled | Don't process the computer legacy run list |
TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode | 1 | When no keyboard is attached |
Group Policies
When this mode is enabled, these local group policies are configured for all users:
Policy setting | Status |
---|---|
Security Settings/Local Policies/Security Options/User Account Control: Behavior of elevation prompt for standard user | Automatically deny elevation requests |
Security Settings/Local Policies/Security Options/Interactive logon: Don't display last signed-in | Enabled |
Control Panel/Personalization/Prevent enabling lock screen slide show | Enabled |
System/Logon/Block user from showing account details on sign-in | Enabled |
System/Logon/Enumerate local users on domain-joined computers | Disabled |
System/Logon/Hide entry points for Fast User Switching | Enabled |
System/Logon/Show first sign-in animation | Disabled |
System/Logon/Turn off app notifications on the lock screen | Enabled |
System/Logon/Turn off picture password sign-in | Enabled |
System/Logon/Turn on convenience PIN sign-in | Disabled |
Windows Components/App Package Deployment/Allow a Windows app to share application data between users | Enabled |
Windows Components/Biometrics/Allow the use of biometrics | Disabled |
Windows Components/Biometrics/Allow users to log on using biometrics | Disabled |
Windows Components/Biometrics/Allow domain users to log on using biometrics | Disabled |
Windows Components/File Explorer/Show lock in the user tile menu | Disabled |
Windows Components/File History/Turn off File History | Enabled |
Windows Components/OneDrive/Prevent the usage of OneDrive for file storage | Enabled |
Windows Components/Windows Hello for Business/Use biometrics | Disabled |
Windows Components/Windows Hello for Business/Use Windows Hello for Business | Disabled |
Windows Components/Windows Logon Options/Sign-in and lock last interactive user automatically after a restart | Disabled |
Windows Components/Microsoft Passport for Work | Disabled |
System/Ctrl+Alt+Del Options/Remove Task Manager | Enabled |
System/Ctrl+Alt+Del Options/Remove Change Password | Enabled |
Start Menu and Taskbar/Notifications/Turn off toast notifications | Enabled |
Start Menu and Taskbar/Notifications/Remove Notifications and Action Center | Enabled |
System/Logon/Do not process the legacy run list | Enabled |
Registry
When this mode is enabled, these registry changes are performed:
Registry setting | Status |
---|---|
Software\Policies\Microsoft\PassportForWork\Remote\Enabled (Phone sign-in/Use phone sign-in) | 0 |
Software\Policies\Microsoft\PassportForWork\Enabled (Use Microsoft Passport for Work) | 0 |