2023-07-21 12:36:49 -04:00

10 KiB

title, description, author, manager, ms.author, ms.date, ms.localizationpriority, ms.prod, ms.technology, ms.topic
title description author manager ms.author ms.date ms.localizationpriority ms.prod ms.technology ms.topic
CloudDesktop CSP Learn more about the CloudDesktop CSP. vinaypamnani-msft aaroncz vinpa 07/21/2023 medium windows-client itpro-manage reference

CloudDesktop CSP

[!INCLUDE Windows Insider tip]

The following list shows the CloudDesktop configuration service provider nodes:

EnableBootToCloudSharedPCMode

Scope Editions Applicable OS
Device
User
Pro
Enterprise
Education
Windows SE
Windows Insider Preview [10.0.22631.2050]
./Device/Vendor/MSFT/CloudDesktop/EnableBootToCloudSharedPCMode

Setting this node to "true" configures boot to cloud for Shared PC mode. This mode enables users to seamlessly sign-in to a Cloud PC. For using this mode, users must install and configure a Cloud Provider application on their PC and must have a Cloud PC provisioned.

Description framework properties:

Property name Property value
Format bool
Access Type Add, Delete, Get, Replace
Default Value false

Allowed values:

Value Description
false (Default) Not configured.
true Boot to cloud Shared PC mode enabled.

EnableBootToCloudSharedPCMode technical reference

EnableBootToCloudSharedPCMode setting is used to configure Boot to Cloud feature for shared user mode. When you enable this setting, multiple policies are applied to achieve the intended behavior.

Note

It is recommended not to set any of the policies enforced by this setting to different values, as these policies help provide a smooth UX experience for the Boot to Cloud feature for shared user mode.

MDM Policies

When this mode is enabled, these MDM policies are applied for the Device scope (all users):

Setting Value Value Description
WindowsLogon/OverrideShellProgram 1 Apply Lightweight Shell
ADMX_CredentialProviders/DefaultCredentialProvider Enabled Configures default credential provider to password provider
ADMX_Logon/DisableExplorerRunLegacy_2 Enabled Don't process the computer legacy run list
TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode 1 When no keyboard is attached

Group Policies

When this mode is enabled, these local group policies are configured for all users:

Policy setting Status
Security Settings/Local Policies/Security Options/User Account Control: Behavior of elevation prompt for standard user Automatically deny elevation requests
Security Settings/Local Policies/Security Options/Interactive logon: Don't display last signed-in Enabled
Control Panel/Personalization/Prevent enabling lock screen slide show Enabled
System/Logon/Block user from showing account details on sign-in Enabled
System/Logon/Enumerate local users on domain-joined computers Disabled
System/Logon/Hide entry points for Fast User Switching Enabled
System/Logon/Show first sign-in animation Disabled
System/Logon/Turn off app notifications on the lock screen Enabled
System/Logon/Turn off picture password sign-in Enabled
System/Logon/Turn on convenience PIN sign-in Disabled
Windows Components/App Package Deployment/Allow a Windows app to share application data between users Enabled
Windows Components/Biometrics/Allow the use of biometrics Disabled
Windows Components/Biometrics/Allow users to log on using biometrics Disabled
Windows Components/Biometrics/Allow domain users to log on using biometrics Disabled
Windows Components/File Explorer/Show lock in the user tile menu Disabled
Windows Components/File History/Turn off File History Enabled
Windows Components/OneDrive/Prevent the usage of OneDrive for file storage Enabled
Windows Components/Windows Hello for Business/Use biometrics Disabled
Windows Components/Windows Hello for Business/Use Windows Hello for Business Disabled
Windows Components/Windows Logon Options/Sign-in and lock last interactive user automatically after a restart Disabled
Windows Components/Microsoft Passport for Work Disabled
System/Ctrl+Alt+Del Options/Remove Task Manager Enabled
System/Ctrl+Alt+Del Options/Remove Change Password Enabled
Start Menu and Taskbar/Notifications/Turn off toast notifications Enabled
Start Menu and Taskbar/Notifications/Remove Notifications and Action Center Enabled
System/Logon/Do not process the legacy run list Enabled

Registry

When this mode is enabled, these registry changes are performed:

Registry setting Status
Software\Policies\Microsoft\PassportForWork\Remote\Enabled (Phone sign-in/Use phone sign-in) 0
Software\Policies\Microsoft\PassportForWork\Enabled (Use Microsoft Passport for Work) 0

Configuration service provider reference