You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/devices/enterprise-state-roaming-enable.md
+14-15Lines changed: 14 additions & 15 deletions
Original file line number
Diff line number
Diff line change
@@ -11,14 +11,13 @@ ms.date: 02/15/2022
11
11
ms.author: joflore
12
12
author: MicrosoftGuyJFlo
13
13
manager: karenhoran
14
-
ms.reviewer: na
14
+
ms.reviewer: guovivian
15
15
ms.custom: references_regions
16
16
ms.collection: M365-identity-device-management
17
17
---
18
18
# Enable Enterprise State Roaming in Azure Active Directory
19
19
20
-
Enterprise State Roaming is available to any organization with an Azure AD Premium or Enterprise Mobility + Security
21
-
(EMS) license. For more information on how to get an Azure AD subscription, see the [Azure AD product page](https://azure.microsoft.com/services/active-directory).
20
+
Enterprise State Roaming is available to any organization with an Azure AD Premium or Enterprise Mobility + Security (EMS) license. For more information on how to get an Azure AD subscription, see the [Azure AD product page](https://azure.microsoft.com/services/active-directory).
22
21
23
22
When you enable Enterprise State Roaming, your organization is automatically granted a free, limited-use license for Azure Rights Management protection from Azure Information Protection. This free subscription is limited to encrypting and decrypting enterprise settings and application data synced by Enterprise State Roaming. You must have [a paid subscription](https://azure.microsoft.com/services/information-protection/) to use the full capabilities of the Azure Rights Management service.
24
23
@@ -27,17 +26,17 @@ When you enable Enterprise State Roaming, your organization is automatically gra
27
26
28
27
## To enable Enterprise State Roaming
29
28
30
-
1. Sign in to [Azure AD admin center](https://aad.portal.azure.com/).
31
-
1.Select**Azure Active Directory** > **Devices** > **Enterprise State Roaming**.
29
+
1. Sign in to the [Azure portal](https://portal.azure.com/).
30
+
1.Browse to**Azure Active Directory** > **Devices** > **Enterprise State Roaming**.
32
31
1. Select **Users may sync settings and app data across devices**. For more information, see [how to configure device settings](./device-management-azure-portal.md).
33
32
34
33

35
34
36
-
For a Windows 10 or newer device to use the Enterprise State Roaming service, the device must authenticate using an Azure AD identity. For devices that are joined to Azure AD, the user’s primary sign-in identity is their Azure AD identity, so no additional configuration is required. For devices that use on-premises Active Directory, the IT admin must [Configure hybrid Azure Active Directory joined devices](./hybrid-azuread-join-plan.md).
35
+
For a Windows 10 or newer device to use the Enterprise State Roaming service, the device must authenticate using an Azure AD identity. For devices that are joined to Azure AD, the user’s primary sign-in identity is their Azure AD identity, so no other configuration is required. For devices that use on-premises Active Directory, the IT admin must [Configure hybrid Azure Active Directory joined devices](./hybrid-azuread-join-plan.md).
37
36
38
37
## Data storage
39
38
40
-
Enterprise State Roaming data is hosted in one or more [Azure regions](https://azure.microsoft.com/regions/) that best align with the country/region value set in the Azure Active Directory instance. Enterprise State Roaming data is partitioned based on three major geographic regions: North America, EMEA, and APAC. Enterprise State Roaming data for the tenant is locally located with the geographical region, and is not replicated across regions. For example:
39
+
Enterprise State Roaming data is hosted in one or more [Azure regions](https://azure.microsoft.com/regions/) that best align with the country/region value set in the Azure Active Directory instance. Enterprise State Roaming data is partitioned based on three major geographic regions: North America, EMEA, and APAC. Enterprise State Roaming data for the tenant is locally located with the geographical region, and isn't replicated across regions. For example:
41
40
42
41
| Country/region value | has their data hosted in |
@@ -46,7 +45,7 @@ Enterprise State Roaming data is hosted in one or more [Azure regions](https://a
46
45
| An APAC country/region such as Australia or New Zealand | One or more of the Azure regions within Asia |
47
46
| South American and Antarctica regions | One or more Azure regions within the US |
48
47
49
-
The country/region value is set as part of the Azure AD directory creation process and cannot be subsequently modified. If you need more details on your data storage location, file a ticket with [Azure support](https://azure.microsoft.com/support/options/).
48
+
The country/region value is set as part of the Azure AD directory creation process and can’t be modified later. If you need more details on your data storage location, file a ticket with [Azure support](https://azure.microsoft.com/support/options/).
50
49
51
50
## View per-user device sync status
52
51
@@ -60,27 +59,27 @@ Follow these steps to view a per-user device sync status report.
60
59
61
60
## Data retention
62
61
63
-
Data synced to the Microsoft cloud using Enterprise State Roaming is retained until it is manually deleted or until the data in question is determined to be stale.
62
+
Data synced to the Microsoft cloud using Enterprise State Roaming is retained until it's manually deleted or until the data is determined to be stale.
64
63
65
64
### Explicit deletion
66
65
67
-
Explicit deletion is when an Azure admin deletes a user or a directory or otherwise requests explicitly that data is to be deleted.
66
+
Explicit deletion is when an administrator deletes a user, directory, or requests explicitly that data is to be deleted.
68
67
69
68
***User deletion**: When a user is deleted in Azure AD, the user account roaming data is deleted after 90 to 180 days.
70
69
***Directory deletion**: Deleting an entire directory in Azure AD is an immediate operation. All the settings data associated with that directory is deleted after 90 to 180 days.
71
70
***On request deletion**: If the Azure AD admin wants to manually delete a specific user’s data or settings data, the admin can file a ticket with [Azure support](https://azure.microsoft.com/support/).
72
71
73
72
### Stale data deletion
74
73
75
-
Data that has not been accessed for one year (“the retention period”) will be treated as stale and may be deleted from the Microsoft cloud. The retention period is subject to change but will not be less than 90 days. The stale data may be a specific set of Windows/application settings or all settings for a user. For example:
74
+
Data that hasn't been accessed for one year (“the retention period”) will be treated as stale and may be deleted from the Microsoft cloud. The retention period is subject to change but won't be less than 90 days. The stale data may be a specific set of Windows/application settings or all settings for a user. For example:
76
75
77
-
* If no devices access a particular settings collection (for example, an application is removed from the device, or a settings group such as “Theme” is disabled for all of a user’s devices), then that collection becomes stale after the retention period and may be deleted.
78
-
* If a user has turned off settings sync on all their devices, then none of the settings data will be accessed, and all the settings data for that user will become stale and may be deleted after the retention period.
79
-
* If the Azure AD directory admin turns off Enterprise State Roaming for the entire directory, then all users in that directory will stop syncing settings, and all settings data for all users will become stale and may be deleted after the retention period.
76
+
* If no devices access a particular settings collection like language, then that collection becomes stale after the retention period and may be deleted.
77
+
* If a user has turned off settings sync on all their devices, then none of the settings data will be accessed. All the settings data for that user will become stale and may be deleted after the retention period.
78
+
* If the Azure AD directory admin turns off Enterprise State Roaming for the entire directory, then all users in that directory will stop syncing settings. All settings data for all users will become stale and may be deleted after the retention period.
80
79
81
80
### Deleted data recovery
82
81
83
-
The data retention policy is not configurable. Once the data is permanently deleted, it is not recoverable. However, The settings data is deleted only from the Microsoft cloud, not from the end-user device. If any device later reconnects to the Enterprise State Roaming service, the settings are again synced and stored in the Microsoft cloud.
82
+
The data retention policy isn't configurable. Once the data is permanently deleted, it isn't recoverable. However, The settings data is deleted only from the Microsoft cloud, not from the end-user device. If any device later reconnects to the Enterprise State Roaming service, the settings are again synced and stored in the Microsoft cloud.
Copy file name to clipboardExpand all lines: articles/active-directory/devices/enterprise-state-roaming-group-policy-settings.md
+5-5Lines changed: 5 additions & 5 deletions
Original file line number
Diff line number
Diff line change
@@ -11,13 +11,13 @@ ms.date: 02/15/2022
11
11
ms.author: joflore
12
12
author: MicrosoftGuyJFlo
13
13
manager: karenhoran
14
-
ms.reviewer: na
14
+
ms.reviewer: guovivian
15
15
16
16
ms.collection: M365-identity-device-management
17
17
---
18
18
# Group Policy and MDM settings
19
19
20
-
Use these group policy and mobile device management (MDM) settings only on corporate-owned devices because these policies are applied to the user’s entire device. Applying an MDM policy to disable settings sync for a personal, user-owned device will negatively impact the use of that device. Additionally, other user accounts on the device will also be affected by the policy.
20
+
Use these Group Policy and mobile device management (MDM) settings only on corporate-owned devices because these policies are applied to the user’s entire device. Applying an MDM policy to disable settings sync for a personal, user-owned device will negatively impact the use of that device. Additionally, other user accounts on the device will also be affected by the policy.
21
21
22
22
Enterprises that want to manage roaming for personal (unmanaged) devices can use the Azure portal to enable or disable roaming, rather than using Group Policy or MDM.
23
23
The following tables describe the policy settings available.
@@ -34,11 +34,11 @@ The MDM policy settings apply to Windows 10 or newer. Refer to [Devices and endp
34
34
| Allow Microsoft Account Connection |Allows users to authenticate using a Microsoft account on the device |
35
35
| Allow Sync My Settings |Allows users to roam Windows settings and app data; Disabling this policy will disable sync as well as backups on mobile devices |
36
36
37
-
## Group policy settings
37
+
## Group Policy settings
38
38
39
-
The group policy settings apply to Windows 10 or newer devices that are joined to an Active Directory domain. The table also includes legacy settings that would appear to manage sync settings, but that do not work for Enterprise State Roaming for Windows 10 or newer, which are noted with ‘Do not use’ in the description.
39
+
The Group Policy settings apply to Windows 10 or newer devices that are joined to an Active Directory domain. The table also includes legacy settings that would appear to manage sync settings. Legacy settings that don't work for Enterprise State Roaming for Windows 10 or newer are noted with ‘Do not use’ in the description.
40
40
41
-
These settings are located at: `Computer Configuration > Administrative Templates > Windows Components > Sync your settings`
41
+
These settings are located in Group Policy under: **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Sync your settings**.
Copy file name to clipboardExpand all lines: articles/active-directory/devices/enterprise-state-roaming-overview.md
+9-11Lines changed: 9 additions & 11 deletions
Original file line number
Diff line number
Diff line change
@@ -11,27 +11,25 @@ ms.date: 02/15/2022
11
11
ms.author: joflore
12
12
author: MicrosoftGuyJFlo
13
13
manager: karenhoran
14
-
ms.reviewer: na
14
+
ms.reviewer: guovivian
15
15
16
16
ms.collection: M365-identity-device-management
17
17
---
18
18
# What is enterprise state roaming?
19
19
20
20
With Windows 10 or newer, [Azure Active Directory (Azure AD)](../fundamentals/active-directory-whatis.md) users gain the ability to securely synchronize their user settings and application settings data to the cloud. Enterprise State Roaming provides users with a unified experience across their Windows devices and reduces the time needed for configuring a new device. Enterprise State Roaming operates similar to the standard [consumer settings sync](https://go.microsoft.com/fwlink/?linkid=2015135) that was first introduced in Windows 8. Additionally, Enterprise State Roaming offers:
21
21
22
-
***Separation of corporate and consumer data** – Organizations are in control of their data, and there is no mixing of corporate data in a consumer cloud account or consumer data in an enterprise cloud account.
23
-
***Enhanced security** – Data is automatically encrypted before leaving the user’s Windows 10 or newer device by using Azure Rights Management (Azure RMS), and data stays encrypted at rest in the cloud. All content stays encrypted at rest in the cloud, except for the namespaces, like settings names and Windows app names.
24
-
***Better management and monitoring** – Provides control and visibility over who syncs settings in your organization and on which devices through the Azure AD portal integration.
25
-
26
-
Enterprise State Roaming is available in multiple Azure regions. You can find the updated list of available regions on the [Azure Services by Regions](https://azure.microsoft.com/regions/#services) page under Azure Active Directory.
22
+
-**Separation of corporate and consumer data** – Organizations are in control of their data, and there is no mixing of corporate data in a consumer cloud account or consumer data in an enterprise cloud account.
23
+
-**Enhanced security** – Data is automatically encrypted before leaving the user’s Windows 10 or newer device by using Azure Rights Management (Azure RMS), and data stays encrypted at rest in the cloud. All content stays encrypted at rest in the cloud, except for the namespaces, like settings names and Windows app names.
24
+
-**Better management and monitoring** – Provides control and visibility over who syncs settings in your organization and on which devices through the Azure AD portal integration.
27
25
28
26
| Article | Description |
29
27
| --- | --- |
30
-
|[Enable Enterprise State Roaming in Azure Active Directory](enterprise-state-roaming-enable.md)|Enterprise State Roaming is available to any organization with a Premium Azure Active Directory (Azure AD) subscription. For more information on how to get an Azure AD subscription, see the [Azure AD product](https://azure.microsoft.com/services/active-directory) page. |
31
-
|[Settings and data roaming FAQ](enterprise-state-roaming-faqs.yml)|This article answers some questions IT administrators might have about settings and app data sync. |
32
-
|[Group policy and MDM settings for settings sync](enterprise-state-roaming-group-policy-settings.md)|Windows 10 or newer provides Group Policy and mobile device management (MDM) policy settings to limit settings sync. |
33
-
|[Windows 10 roaming settings reference](enterprise-state-roaming-windows-settings-reference.md)|A list of settings that will be roamed and/or backed-up in Windows 10 or newer. |
34
-
|[Troubleshooting](enterprise-state-roaming-troubleshooting.md)|This article goes through some basic steps for troubleshooting, and contains a list of known issues. |
28
+
|[Enable Enterprise State Roaming in Azure Active Directory](enterprise-state-roaming-enable.md)|Enterprise State Roaming is available to any organization with a Premium Azure Active Directory (Azure AD) subscription. |
29
+
|[Settings and data roaming FAQ](enterprise-state-roaming-faqs.yml)|This article answers some questions IT administrators might have about settings and app data sync. |
30
+
|[Group policy and MDM settings for settings sync](enterprise-state-roaming-group-policy-settings.md)|Windows 10 or newer provides Group Policy and mobile device management (MDM) policy settings to limit settings sync. |
31
+
|[Windows 10 roaming settings reference](enterprise-state-roaming-windows-settings-reference.md)|A list of settings that will be roamed and/or backed-up in Windows 10 or newer. |
32
+
|[Troubleshooting](enterprise-state-roaming-troubleshooting.md)|This article goes through some basic steps for troubleshooting, and contains a list of known issues. |
Copy file name to clipboardExpand all lines: articles/active-directory/devices/enterprise-state-roaming-troubleshooting.md
+1-19Lines changed: 1 addition & 19 deletions
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.date: 02/15/2022
11
11
ms.author: joflore
12
12
author: MicrosoftGuyJFlo
13
13
manager: karenhoran
14
-
ms.reviewer: tanning
14
+
ms.reviewer: guovivian
15
15
16
16
ms.collection: M365-identity-device-management
17
17
---
@@ -103,15 +103,6 @@ Make sure the Windows 10 v1511 client has the July 2016 Cumulative Update ([KB31
103
103
104
104
---
105
105
106
-
### Theme is not syncing, as well as data protected with Windows Information Protection
107
-
108
-
To prevent data leakage, data that is protected with [Windows Information Protection](/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) will not sync through Enterprise State Roaming for devices using the Windows 10 Anniversary Update.
109
-
110
-
**Recommended action**
111
-
None. Future updates to Windows may resolve this issue.
112
-
113
-
---
114
-
115
106
### Date, Time, and Region settings do not sync on domain-joined device
116
107
117
108
Devices that are domain-joined will not experience sync for the setting Date, Time, and Region: automatic time. Using automatic time may override the other Date, Time, and Region settings and cause those settings not to sync.
@@ -121,15 +112,6 @@ None.
121
112
122
113
---
123
114
124
-
### UAC Prompts when syncing passwords
125
-
126
-
Affects devices running the Windows 10 November Update (Version 1511) with a wireless NIC that is configured to sync passwords.
127
-
128
-
**Recommended action**
129
-
Make sure the Windows 10 v1511 client has the Cumulative Update ([KB3140743](https://support.microsoft.com/kb/3140743) OS Build 10586.494).
130
-
131
-
---
132
-
133
115
### Sync does not work on devices that use smart card for login
134
116
135
117
If you attempt to sign in to your Windows device using a smart card or virtual smart card, settings sync will stop working.
The following is a list of the settings that will be roamed or backed up in Windows 10 or newer.
21
21
22
-
## Devices and endpoints
23
-
24
-
See the following table for a summary of the devices and account types that are supported by the sync, backup, and restore framework in Windows 10 or newer.
25
-
26
-
| Account type and operation | Desktop | Mobile |
27
-
| --- | --- | --- |
28
-
| Azure Active Directory: sync |Yes |No |
29
-
| Azure Active Directory: backup/restore |No |No |
30
-
| Microsoft account: sync |Yes |Yes |
31
-
| Microsoft account: backup/restore |No |Yes |
32
-
33
-
## What is backup?
34
-
35
-
Windows settings generally sync by default, but some settings are only backed up, such as the list of installed applications on a device. Backup is for mobile devices only and currently not available for Enterprise State Roaming users. Backup uses a Microsoft account and stores the settings and application data into OneDrive. If a user disables sync on the device using the Settings app, application data that normally syncs becomes backup only. Backup data can only be accessed through the restore operation during the first run experience of a new device. Backups can be disabled via the device settings, and can be managed and deleted through the user’s OneDrive account.
36
-
37
22
## Windows Settings overview
38
23
39
24
The following settings groups are available for end users to enable/disable settings sync on Windows 10 or newer devices.
40
25
41
-
* Theme: desktop background, user tile, taskbar position, etc.
42
-
* Internet Explorer Settings: browsing history, typed URLs, favorites, etc.
43
-
* Passwords: Windows credential manager, including Wi-Fi profiles
44
-
* Language Preferences: spelling dictionary, system language settings
45
-
* Ease of Access: narrator, on-screen keyboard, magnifier
46
-
* Other Windows Settings: see Windows Settings details
47
-
* Microsoft Edge browser setting: Microsoft Edge favorites, reading list, and other settings
26
+
- Ease of Access
27
+
- Internet Explorer Settings
28
+
- Language Preferences
29
+
- Microsoft Edge browser setting
30
+
- Other Windows Settings
31
+
- Passwords
48
32
49
33

50
34
@@ -64,122 +48,45 @@ For Windows 10 version 1803 or later, Internet Explorer setting group (favorites
64
48
In the following table, Other entries in the Settings Group column refer to settings that can be disabled by going to Settings > Accounts > Sync your settings > Other Windows settings.
65
49
66
50
Internal entries in the Settings Group column refer to settings and apps that can only be disabled from syncing within the app itself or by disabling sync for the entire device using mobile device management (MDM) or Group Policy settings.
67
-
Settings that don't roam or sync will not belong to a group.
68
-
69
-
| Settings | Desktop | Mobile | Group |
70
-
| --- | --- | --- | --- |
71
-
|**Accounts**: account picture |sync |X |Theme |
72
-
|**Accounts**: other account settings |X |X ||
73
-
|**Advanced mobile broadband**: Internet connection sharing network name (enables autodiscovery of mobile Wi-Fi hotspots via Bluetooth) |X |X |Passwords |
74
-
|**App data**: individual apps can sync data |sync backup |sync backup |internal |
75
-
|**App list**: list of installed apps |X |backup |Other |
0 commit comments