Forum Discussion
Shared PC Mode Scope Change
We have the “Shared multi-user device” configuration profile scoped to “All Devices” with “Shared PC mode” turned on. As we are approaching our 5th or 6th year with Intune and continually trying to work on better cybersecurity standards, we have desire to change this to where our staff have
- Shared PC mode off on staff machines to where they are the “sole owner” of their device
- Students remain with Shared PC mode enabled since we don’t individually assign devices to them
- Our lab and presenter room environments set to Shared PC mode enabled with domain/guest mode enabled so that we are no longer having to deal legacy local accounts (we shamefully use legacy standard local accounts that auto login, obviously we want it changed).
That brings me to this question - if we un-scope the profile from “All Devices”, what impact will this have? Will the Entra-cached staff accounts be suddenly removed from their computer? If we set a new staff “Shared multi-user device” policy with Shared PC mode “not configured”, will they then have their own profile “bubble” on the login screen? I presume we’ll have to assign the user to the device in Intune, correct?
My fear is it being a destructive configuration profile change where we now have to reconfigure the staff computers.