How to Secure OneDrive on Shared or Task-Based PCs
Question details
Organizations need to reduce security risks when OneDrive synchronizes user data on shared, public, or task-based computers.

- Product
- Microsoft OneDrive
- Device & OS
- Windows
- Scenario
- IT administrators need to manage and restrict OneDrive synchronization on shared organizational computers to prevent unauthorized access to cached user files.
- Observed behavior
- OneDrive automatically synchronizes sensitive user-profile data and files onto shared computers, which can remain accessible to subsequent users if synchronization and automated cleanups are not properly enforced.
Ensure you have administrator access to Microsoft Intune, Microsoft Purview, or your organization's designated Mobile Device Management (MDM) solution before configuring shared device policies.
Configure Windows Shared PC Mode via Microsoft Intune
Use Intune device-management policies to block or control OneDrive sync and enforce automatic user account cleanup upon sign-out.
Windows Shared PC mode allows administrators to strictly control how user profiles and applications behave on multi-user computers. By managing this through Intune, you can securely isolate user data and ensure cached OneDrive files are removed when a session ends.
Log in to the Microsoft Intune admin center using your administrator credentials.
Navigate to 'Devices' > 'Configuration profiles'. Select 'Create profile', choose 'Windows 10 and later' as the platform, and select 'Templates' as the profile type.
Select the 'Shared multi-user device' template. Under the configuration settings, toggle 'Shared PC mode' to 'Enable'.
Under 'Account management', configure the deletion policy to remove accounts immediately at sign-out. This ensures no localized OneDrive data or user profiles are left behind.
To allow controlled synchronization, deploy the specific OneDrive shared-PC policy named 'EnableSharedPCModeWithOneDriveSync'. Assign the completed profile to your targeted shared devices and test thoroughly.

Apply Microsoft Purview and SharePoint Access Controls
Restrict unauthorized access and protect sensitive files by configuring SharePoint conditional access and Information Rights Management (IRM).
Securely Handle Your Documents with WPS Office
While configuring device-level security for Microsoft environments, consider WPS Office as a lightweight, secure, and highly compatible alternative for your organization's daily document processing needs. WPS Office offers strong local encryption and a familiar user interface without the heavy synchronization overhead.

Frequently Asked Questions
Can I completely block OneDrive sync on a shared PC?
Yes. By configuring Windows Shared PC mode and intentionally omitting or disabling the 'EnableSharedPCModeWithOneDriveSync' policy in Intune, you can completely block OneDrive from synchronizing data to the local hard drive.
What happens to cached OneDrive files after a user signs out?
If account management and automatic cleanup are properly configured in your Shared PC policy, the entire user profile—including all cached OneDrive data and application settings—is automatically deleted from the computer immediately upon sign-out.
Does OneDrive encrypt data locally on shared computers?
Yes, OneDrive for work or school encrypts data both in transit and at rest on the local device. However, configuring automatic sign-out cleanups and Purview Information Protection adds a necessary layer of security for shared hardware.




