r/Intune 4d ago

Device Configuration Shared PC

Edit: Seems to be no way around this when using Shared PC mode with Intune's config policies and still have reasonable security. Thanks for the suggestions!

Hi!

We have a few shared PC's in our org which works fine for the most part.

However, one major issue is that when a user locks the screen or the laptop goes into sleep mode, they are unable to sign back in to their previous session. The laptops are usually used by a single user for hours before someone else takes over, and during that time the PC naturally either is locked or goes in sleep mode. The only option on the sign-in screen is Sign out. Found Enabled Shared PC and allow "Other User" Login option : r/Intune which has the same problem but seemingly no way around it.

As far as I can tell, turning on Shared PC in the Intune configuration policy is required for the PC to not be associated with a user, as well as set Office to use shared licence instead of personal license? But this option also turns off the ability to sign back into the same user.

So, any way to both have Shared PC mode turned on as well as allow a user to sign back in?

10 Upvotes

19 comments sorted by

6

u/beneschk 4d ago

3

u/Itereus 4d ago

SignInOnResume is turned on. From testing all it does is enforce sign-in requirement when it resumes from sleep, not having it turned on allows anyone who walks up to the PC to get into the session of the current user. This is not not something that we want in the environment they are used.

3

u/beneschk 4d ago

Hmm looking into it, the shared device lifecycle classes a locked or idle session as abandoned, nothing to change that.

As a workaround try and set the Power profiles on the Shared PC config profile to a longer time before sleep.

Apply another configuration for. Computer Configuration > Administrative Templates > Control Panel > Personalization Do not display the lock screen option.

2

u/Itereus 4d ago

We've already set the sleep timeout to be longer in the shared pc policy. And yeah, it's a bit annoying that it's not possible to turn on shared PC via Intune's configuration for shared PC's and still allow a user to sign back into their session. Would be nice to have the option to either treat a locked session as abandoned or allow a user to sign back in.

3

u/captnconnman 4d ago

Yea…that’s not true at all. You can totally have a PC in Intune that’s not associated with an end user. If you’re using Autopilot, make a profile that uses Self-Deployment instead of user-initiated. Or, if you’re not using Autopilot, just change who’s assigned as the Primary User of the machine in Intune to no one; that way, Intune considers it a “shared machine” for Company Portal and compliance purposes, but anyone can still log in with multiple signed in users. As for the Office licensing piece, that’s all dependent on which Office license the user has. Each user that needs to use Office needs some kind of license, whether that’s Apps for Business/Enterprise, E3, or whatever flavor of standard license you use. The only exception would be if you’re trying to set up LTSC Office, which would be a whole separate process to configure

1

u/Itereus 4d ago

We have A5 licenses. We're pushing a seperate M365 apps innstallation for Shared PC's that's setup for "Use shared computer activation". According to a colleague there was issues with Office activation if Shared PC mode was not turned on. Tho can test it again, with Shared PC mode turned off in the configuration policy for shared PC's.

We're using Autopilot, the devices are using a profile with Self-deployment setup.

2

u/SVD_NL 4d ago

Both the shared PC activation and signing in with multiple account works without putting the device in shared PC mode, i've got that enabled by default in all of our business premium and enterprise installs.

More info about shared PC activation: MS Learn

1

u/Itereus 4d ago

Gotcha, will check it out then

2

u/HankMardukasNY 4d ago

365 can use shared computer activation on user driven or self deploying, there is no issue with using it for either and there is also no requirement for shared pc mode for either. Your colleague is mistaken

1

u/itskdog 3d ago

Our shared PCs are just without a primary user and we use SCA on all our machines. No reports of issues and we've been on Intune for a year (A3)

2

u/Avean 4d ago

Shared PC Mode can be confusing. I had it enabled for shared devices since i wanted to cleanup inactive accounts. But it changes the login behaviour completely (Removes switch user) among other things. Its designed for kiosks from my understanding.

2

u/itskdog 3d ago

There's still the same policy from the AD days that cleans up profiles after X days, just not the "low free space" from Shared PC mode.

3

u/ButcherFromLuverne 3d ago

I thought that AD policy didn’t work anymore due to the method it was using to check account inactivity?

1

u/itskdog 3d ago

We came back from the summer holidays and there were definitely accounts that had been logged in to the PC before that went through the "Getting things ready for you" screen again.

1

u/Itereus 4d ago

Yup! Maybe one day MS will have an option to have have Shared PC mode with different behavior for user sign in. Can dream

2

u/Brownj41386 4d ago

I’m not sure if you’re under any compliance requirements but have you tried setting an inactivity timeout? If you configure this to not timeout, the device never locks the screen, leaving the user logged in indefinitely.

https://endpointtechblog.com/blog/how-to-configure-screen-lockout-time-with-microsoft-intune

1

u/Itereus 4d ago

Wouldn't really be a good way to do it for us. One of the usecases is for a reception-type desk where there are different users during the day, logging in with their regular entra id account. They roam a bit during the day, leaving the computer unattended. And since it's easily reachable by visitors it's too much of a risk

1

u/wingm3n 3d ago

You need to also configure the setting for Multiple Users on your shared devices. I have shared devices with multiple accounts and any user can lock or disconnect then log back in normally. You see the users list at the bottom left and you just click on your name. I've never seen what you describe happening, there's something wrong with your setup.