With new Sync Bookmarks/Favorites on-Prem without Cloud

%3CLINGO-SUB%20id%3D%22lingo-sub-1626898%22%20slang%3D%22en-US%22%3EWith%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1626898%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-on-premises-sync%22%20rel%3D%22noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-on-premises-sync%3C%2FA%3E%3C%2FP%3E%3CP%3EQuestion%3A%3CBR%20%2F%3EIs%20it%20only%20for%20beginning%20that%20only%20Favorites%20and%20Settings%20will%20be%20stored%20in%20the%20profile.pb%20file%3F%3CBR%20%2F%3EWill%20in%20the%20Future%20also%20be%20the%20possibility%20to%20sync%20the%20other%20settings%3F%20Like%20Extension%2C%20collections%20and%20so%20on.%3CBR%20%2F%3EIf%20folder%20redirection%20is%20used%20to%20share%20a%20single%20profile.pb%20file%20between%20different%20computers%2C%20then%20only%20one%20instance%20of%20Microsoft%20Edge%20using%20that%20file%20can%20be%20started.%20Because%20of%20this%20Information%20folder%20redirection%20isn't%20a%20possibility.%20Do%20we%20have%20the%20Option%20to%20sync%20with%20UE-V%20(User%20Experience%20Virtualisation)%3F%3CBR%20%2F%3EIf%20the%20on%20Prem%20sync%20is%20activated%2C%20does%20the%20user%20has%20the%20possibility%20to%20sin-in%20with%20a%20Private%20Microsoft%20Account%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1628931%22%20slang%3D%22en-US%22%3ERe%3A%20With%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1628931%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F526597%22%20target%3D%22_blank%22%3E%40re_bl%3C%2FA%3E%26nbsp%3B%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20can%20consider%20adding%20support%20for%20more%20data%20types%20based%20on%20feedback.%20When%20we%20were%20planning%20this%20feature%20we%20found%20that%20favorites%20and%20settings%20were%20by%20far%20the%20most%20highly%20requested%20types%20so%20we%20started%20there.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20cannot%20directly%20advise%20on%20UE-V.%20However%20I%20do%20know%20that%20some%20customers%20have%20successfully%20used%20UE-V%20for%20this.%20My%20suggestion%20is%20to%20try%20it%20out%20in%20an%20isolated%20environment%20and%20see%20if%20it%20meets%20your%20needs.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnd%20yes%2C%20you%20can%20still%20use%20cloud%20profiles%20in%20Edge%20even%20when%20on-prem%20is%20active.%20On-prem%20only%20impacts%20AD%20profiles.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1631407%22%20slang%3D%22en-US%22%3ERe%3A%20With%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1631407%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F565401%22%20target%3D%22_blank%22%3E%40scottbo_msft%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20done%20some%20more%20tests%20with%20on-Prem%20and%20cloud%20profile%3A%20(Microsoft%20Edge%2085.0.564.44)%3C%2FP%3E%3CP%3E%3CSTRONG%3EScenario%201%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3ECustomer%20allows%20to%20login%20with%20Private%20User.%20Work%20as%20expected.%3C%2FP%3E%3CP%3E%22ConfigureOnPremisesAccountAutoSignIn%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileSupportEnabled%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22HideFirstRunExperience%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileLocation%22%3D%22%24%7Blocal_app_data%7D%5C%5CMicrosoft%5C%5CEdge%5C%5Cedge-profile%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECustomer%20doesn%E2%80%99t%20allow%20to%20login%20with%20a%20Private%20User.%3C%2FP%3E%3CP%3EThe%20deactivation%20I%20have%20done%20with%20GPO%20Browser%20Sign-in%20%3D%26gt%3B%20If%20you%20have%20configured%20the%20'BrowserSignin'%20policy%20to%20disabled%2C%20this%20policy%20'*ConfigureOnPremisesAccountAutoSignIn'%20will%20not%20take%20any%20effect.%20Then%20the%20on-prem%20login%20will%20not%20function%20anymore.%20Works%20as%20is%20written%20in%20the%20GPO%20*description.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22ConfigureOnPremisesAccountAutoSignIn%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileSupportEnabled%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22HideFirstRunExperience%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileLocation%22%3D%22%24%7Blocal_app_data%7D%5C%5CMicrosoft%5C%5CEdge%5C%5Cedge-profile%22%3C%2FP%3E%3CP%3E%22BrowserSignin%22%3Ddword%3A00000000%3C%2FP%3E%3CP%3E%22NonRemovableProfileEnabled%22%3Ddword%3A00000000%3C%2FP%3E%3CP%3E%3CSTRONG%3ESecond%3C%2FSTRONG%3E%20test%20if%20I%20set%20a%20Primary%20account%20that%20does%20not%20exist%20over%20the%20GPO%20RestrictSigninToPattern%2C%20then%20also%20the%20on-prem%20login%20doesn't%20function%20and%20you%20couldn't%20login%20with%20another%20Account.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22image.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F216295i9441418955EEDDCB%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22image.png%22%20alt%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%22ConfigureOnPremisesAccountAutoSignIn%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileSupportEnabled%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22HideFirstRunExperience%22%3Ddword%3A00000001%3C%2FP%3E%3CP%3E%22RoamingProfileLocation%22%3D%22%24%7Blocal_app_data%7D%5C%5CMicrosoft%5C%5CEdge%5C%5Cedge-profile%22%3C%2FP%3E%3CP%3E%22RestrictSigninToPattern%22%3D%22%40contoso.com%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20you%20explain%20how%20to%20configure%20that%20also%20the%20scenario%202%20is%20working.%20Only%20allow%20to%20login%20to%20AD%20domain%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1637473%22%20slang%3D%22en-US%22%3ERe%3A%20With%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1637473%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F526597%22%20target%3D%22_blank%22%3E%40re_bl%3C%2FA%3E%26nbsp%3B--%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20may%20need%20to%20change%20your%20RestrictSignonToPattern%20value.%20It%20should%20match%20the%20format%20of%20an%20on-prem%20AD%20account%20like%20COMPANY%5Cuser.%20Or%20you%20can%20try%20unsetting%20it%20to%20eliminate%20it%20as%20a%20cause%20of%20the%20problem.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1643265%22%20slang%3D%22en-US%22%3ERe%3A%20With%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1643265%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F565401%22%20target%3D%22_blank%22%3E%40scottbo_msft%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20set%20the%26nbsp%3B%3CSPAN%3ERestrictSignonToPattern%20to%26nbsp%3B%26nbsp%3BCOMPANY%5C%24%7Bprofile%7D%2C%20it%20won't%20login%20the%20user%20with%20AD%20Account.%20If%20I%20unsetting%20the%26nbsp%3BRestrictSignonToPattern%20then%20the%26nbsp%3BAD%20Account%20will%26nbsp%3Blogin%20but%20you%20also%20could%20login%20with%20a%20Private%20Microsoft%20Account.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20have%20some%20customers%20they%20do%20not%20have%20O365%20because%20of%20the%20Cloud%20strategies%26nbsp%3Band%20they%20also%20do%20not%20want%20that%20the%20User%20could%20login%20with%20a%20Private%20Microsoft%20Account%20on%20they're%20work%20client.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1643266%22%20slang%3D%22en-US%22%3ERe%3A%20With%20new%20Sync%20Bookmarks%2FFavorites%20on-Prem%20without%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1643266%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F526597%22%20target%3D%22_blank%22%3E%40re_bl%3C%2FA%3E%26nbsp%3BSorry%20Copy%20%2FPaste%20mistake%26nbsp%3B%3CSPAN%3ERestrictSignonToPattern%20to%26nbsp%3B%26nbsp%3BCOMPANY%5C%24%7Buser_name%7D%20and%20not%26nbsp%3BCOMPANY%5C%24%7Bprofile%7D.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

https://docs.microsoft.com/en-us/deployedge/microsoft-edge-on-premises-sync

Question:
Is it only for beginning that only Favorites and Settings will be stored in the profile.pb file?
Will in the Future also be the possibility to sync the other settings? Like Extension, collections and so on.
If folder redirection is used to share a single profile.pb file between different computers, then only one instance of Microsoft Edge using that file can be started. Because of this Information folder redirection isn't a possibility. Do we have the Option to sync with UE-V (User Experience Virtualisation)?
If the on Prem sync is activated, does the user has the possibility to sin-in with a Private Microsoft Account?

5 Replies
Highlighted

Hello @re_bl :

 

We can consider adding support for more data types based on feedback. When we were planning this feature we found that favorites and settings were by far the most highly requested types so we started there. 

 

I cannot directly advise on UE-V. However I do know that some customers have successfully used UE-V for this. My suggestion is to try it out in an isolated environment and see if it meets your needs.

 

And yes, you can still use cloud profiles in Edge even when on-prem is active. On-prem only impacts AD profiles.

Highlighted

Hello @scottbo_msft 

I have done some more tests with on-Prem and cloud profile: (Microsoft Edge 85.0.564.44)

Scenario 1:

Customer allows to login with Private User. Work as expected.

"ConfigureOnPremisesAccountAutoSignIn"=dword:00000001

"RoamingProfileSupportEnabled"=dword:00000001

"HideFirstRunExperience"=dword:00000001

"RoamingProfileLocation"="${local_app_data}\\Microsoft\\Edge\\edge-profile"

 

Customer doesn’t allow to login with a Private User.

The deactivation I have done with GPO Browser Sign-in => If you have configured the 'BrowserSignin' policy to disabled, this policy '*ConfigureOnPremisesAccountAutoSignIn' will not take any effect. Then the on-prem login will not function anymore. Works as is written in the GPO *description.

 

"ConfigureOnPremisesAccountAutoSignIn"=dword:00000001

"RoamingProfileSupportEnabled"=dword:00000001

"HideFirstRunExperience"=dword:00000001

"RoamingProfileLocation"="${local_app_data}\\Microsoft\\Edge\\edge-profile"

"BrowserSignin"=dword:00000000

"NonRemovableProfileEnabled"=dword:00000000

Second test if I set a Primary account that does not exist over the GPO RestrictSigninToPattern, then also the on-prem login doesn't function and you couldn't login with another Account.

image.png

"ConfigureOnPremisesAccountAutoSignIn"=dword:00000001

"RoamingProfileSupportEnabled"=dword:00000001

"HideFirstRunExperience"=dword:00000001

"RoamingProfileLocation"="${local_app_data}\\Microsoft\\Edge\\edge-profile"

"RestrictSigninToPattern"="@contoso.com"

 

Could you explain how to configure that also the scenario 2 is working. Only allow to login to AD domain?

Highlighted

Hello @re_bl --

 

You may need to change your RestrictSignonToPattern value. It should match the format of an on-prem AD account like COMPANY\user. Or you can try unsetting it to eliminate it as a cause of the problem.

Highlighted

Hello @scottbo_msft 

If I set the RestrictSignonToPattern to  COMPANY\${profile}, it won't login the user with AD Account. If I unsetting the RestrictSignonToPattern then the AD Account will login but you also could login with a Private Microsoft Account. 

We have some customers they do not have O365 because of the Cloud strategies and they also do not want that the User could login with a Private Microsoft Account on they're work client.

Highlighted

@re_bl Sorry Copy /Paste mistake RestrictSignonToPattern to  COMPANY\${user_name} and not COMPANY\${profile}.