logo
search
Data Protection Issues

How to Secure OneDrive on Shared or Task-Based PCs

Ayan MasoodAyan Masood Sep 29, 2026 869 views

Question details

Organizations need to reduce security risks when OneDrive synchronizes user data on shared, public, or task-based computers.

How to Secure OneDrive on Shared or Task-Based PCs
Product
Microsoft OneDrive
Device & OS
Windows
Scenario
IT administrators need to manage and restrict OneDrive synchronization on shared organizational computers to prevent unauthorized access to cached user files.
Observed behavior
OneDrive automatically synchronizes sensitive user-profile data and files onto shared computers, which can remain accessible to subsequent users if synchronization and automated cleanups are not properly enforced.
Before you start

Ensure you have administrator access to Microsoft Intune, Microsoft Purview, or your organization's designated Mobile Device Management (MDM) solution before configuring shared device policies.

Solution 1Recommended

Configure Windows Shared PC Mode via Microsoft Intune

Use Intune device-management policies to block or control OneDrive sync and enforce automatic user account cleanup upon sign-out.

Windows Shared PC mode allows administrators to strictly control how user profiles and applications behave on multi-user computers. By managing this through Intune, you can securely isolate user data and ensure cached OneDrive files are removed when a session ends.

1
Access Microsoft Intune

Log in to the Microsoft Intune admin center using your administrator credentials.

2
Create a Configuration Profile

Navigate to 'Devices' > 'Configuration profiles'. Select 'Create profile', choose 'Windows 10 and later' as the platform, and select 'Templates' as the profile type.

3
Enable Shared PC Mode

Select the 'Shared multi-user device' template. Under the configuration settings, toggle 'Shared PC mode' to 'Enable'.

4
Configure Account Deletion

Under 'Account management', configure the deletion policy to remove accounts immediately at sign-out. This ensures no localized OneDrive data or user profiles are left behind.

5
Control OneDrive Sync

To allow controlled synchronization, deploy the specific OneDrive shared-PC policy named 'EnableSharedPCModeWithOneDriveSync'. Assign the completed profile to your targeted shared devices and test thoroughly.

Configure Windows Shared PC Mode via Microsoft Intune
Testing Deployment: Always deploy and test these configuration profiles on a small group of shared PCs before rolling them out broadly across the organization.
Free Microsoft Office alternative

Securely Handle Your Documents with WPS Office

While configuring device-level security for Microsoft environments, consider WPS Office as a lightweight, secure, and highly compatible alternative for your organization's daily document processing needs. WPS Office offers strong local encryption and a familiar user interface without the heavy synchronization overhead.

Excellent compatibility with Microsoft Word, Excel, and PowerPoint formatsBuilt-in document encryption and password protection features for local securityLightweight application footprint ideal for shared, public, or older computersFamiliar user interface requiring zero learning curve for users migrating from Microsoft OfficeFree to download and use for essential office tasks
microsoft office alternative - wps office

Frequently Asked Questions

Can I completely block OneDrive sync on a shared PC?

Yes. By configuring Windows Shared PC mode and intentionally omitting or disabling the 'EnableSharedPCModeWithOneDriveSync' policy in Intune, you can completely block OneDrive from synchronizing data to the local hard drive.

What happens to cached OneDrive files after a user signs out?

If account management and automatic cleanup are properly configured in your Shared PC policy, the entire user profile—including all cached OneDrive data and application settings—is automatically deleted from the computer immediately upon sign-out.

Does OneDrive encrypt data locally on shared computers?

Yes, OneDrive for work or school encrypts data both in transit and at rest on the local device. However, configuring automatic sign-out cleanups and Purview Information Protection adds a necessary layer of security for shared hardware.