Introduction

Welcome to this Knowledge Base article about Multi-User Devices and Cloud!

On this page you will find interesting facts about the topic "Multi-User Devices and Cloud".

What are multi-user devices?

In everyday business, there are various scenarios in which a device is used by different users. Frequently occurring scenarios for this are, for example, classroom PCs, front desk PCs or laboratory devices. Especially in the cloud environment, various restrictions must be considered; different licences are also available. This article aims to document various aspects to help users and admins with different questions.

The documentation currently comprises the following sections:
  1. Introduction (this section)
  2. Business Scenarios - listing of various business scenarios.
  3. Licences - Device Licences, Shared Licences and "Normal Licences" - advantages and disadvantages / Other articles on its.ethz.ch/help on the topic of licences and the Cloud
  4. Original Versions - Different Windows versions as a starting point
  5. Identity-Authentication-MFA - Accounts, Authentication und MFA
Project Team

Reinhard Hess, Apon Dunkl, Filip Centowski, Luca de Stefani, Stefan Geissler, Ourania Vagia


Operational Scenarios

Listing of different operational scenarios

Scenario 1 Course PCs

One possible operational scenario is, for example, the use of course PCs.
These are impersonal PCs that are used throughout the duration of a course (usually 1-2 days).

If the course is an internal ETH course, the participants can log in with their personal ethz account without any problems.
The prerequisite is that the user has an account in AAD (this is the case for ETH staff and students, but not for guest accounts, for example).
The procedure is therefore the same as with Active Directory and the login to the domain.

However, this will not work for external participants in the future, since for security reasons no impersonal course accounts with the corresponding licences can be created.

The previous solution with a local user will no longer be possible.

Scenario 2 Switch PCs

Another operating scenario is the use of counter PCs.
These PCs are impersonal workstations that are shared within a predefined group.
In contrast to course PCs, it is not intended here that everyone can log in, but only the users who are assigned to this group.

A personal login is necessary. This means that several users can log on to the PC at the same time. It is possible to switch back and forth between the registered accounts. However, it is advisable to log off after use.

It is recommended to create a configuration group for counter PCs in Intune and to assign a profile to the device group.

Further information on this topic:
https://learn.microsoft.com/en-us/mem/intune/configuration/shared-user-device-settings

Scenario 3 Laboratory devices

The use of laboratory devices is basically the same as for counter PCs.

These are workstations in a lab with impersonal PCs, which are used by several lab technicians.
Again, it is recommended to create a configuration group for the PCs and assign the respective group to the lab technicians.

In contrast to the counter PCs, however, it is sometimes forbidden for MFA to take a cell phone into the lab. As a substitute for a cell phone, a small card with a display can be ordered from the service desk, which shows the 2FA code.

To enable a quick change of accounts, the "Change user" function known in Windows would be useful to allow the next user to log in.
However, this function is not possible with the "Shared multi-user device" option.

After the end of the work, only a logout is possible. All user specific settings will be deleted.

Further information about the MFA card:
MFA Hardtoken


Licensing

Personal licensing

The end-user has a license Microsoft 365 A5 and logs into a computer where Microsoft 365 software is installed.
The software verifies if the user has a valid license before allowing usage. During this process one user license from the remaining pool will be assigned to the device.
If the user does not have Microsoft 365 A5 License, or if the user closed the Activate Office dialog box Microsoft 365 Apps will work in view only mode.

Advantage: 

- User can activate up to 5 desktops/laptops, 5 tablets, and 5 mobile device
- Easy to use. Additional configuration is not needed

Disadvantage:

- Once license limit is reach user will be automatically signed out of devices to stay within your sign-in limit

Shared device activation

The end-user has a license Microsoft 365 A5 and logs into a computer where Microsoft 365 software is installed.
The software verifies if the user has a valid license before allowing usage. During this process user will not loose any personal licenses.
If the user does not have Microsoft 365 A5 License, or if the user closed the Activate Office dialog box Microsoft 365 Apps will work in view only mode.

Advantage: 

-The user can work with Microsoft 365 Apps on many PCs where Shared device activation is used without loosing his Personal licenses

Disadvantage:

- cannot be used with impersonal accounts (e.g. kursaccounts)
- licensed user can activate Microsoft 365 Apps only on a limited number of Computers in a given time period

-requires additional configuration via GPO or XML file created in Office Customization Tool

  • Using GPO Computer Configuration\Policies\Administrative Templates\Microsoft Office 2016 (Machine)\Licensing Settings -> “Use shared computer activation”
  • Using XML File <Property Name="SharedComputerLicensing" Value="1" />

Device based licensing

The device is licensed, and anyone who uses that device is automatically entitled to use the software installed.
The device must be AAD joined or hybrid joined.

Advantage:

- The user does not need any license
- Works with local accounts

Disadvantage: 

- Expensive for large quantities (200.-/year per Device, according to license group in PPF; this is ETH-specific)
- More than Windows Home is necessary to log in with Work- or School Account

Microsoft Volume Activation Management Tool

Microsoft Volume Activation Management Tool is part of the Microsoft Assessment and Deployment KIT (ADK).

ADK installation Download and install the Windows ADK | Microsoft Learn

VAMT Technical documentation VAMT technical reference - Windows Deployment | Microsoft Learn

Key points:

  • VAMT can activate Windows Client, Server and Office
  • Activation Keys needs to be purchased separately and added to VAMT manually
  • Activation Clients can de discovered from AD or can de added manually using their IP addresses
  • VAMT can send a license to the target PC, such license will not be activated unless you order VAMT to activate it
  • VAMT can change license type on the existing PC from example from Windows Pro to Windows Enterprise
  • Once license is assigned to the target PC you can not rollback or revert it (if you reinstall a PC you need to send a new license)
  • If you run out of Licenses in VAMT you need to buy more from Microsoft or ask Microsoft to grant you a few more Licenses providing Business reason (for example PCs previously licensed using VAMT were replaced or re-installed)

Weitere Ressourcen zum Thema Lizenzen

You find more informationen in regard to "M365 Licences" here:
https://unlimited.ethz.ch/display/itwdb/M365+Lizenzen+-+Service+Plans


Initial versions

Different Windows versions as a starting point
For a multi-user device, the Windows Home version is not sufficient.

The wizard for logging in with a "work or school account" after a new installation is missing and makes the setup unnecessarily complicated.

The possibility of a local login, an upgrade to a higher Windows version and then an AAD Join does exist, but a new installation of a higher Windows version such as Pro, Education or Enterprise is recommended.

The same applies to a "reJoin" of the devices. In this case, too, a new installation seems more advisable.

It should be noted that in the Microsoft Azure Administrator Center it is possible to activate the option "Windows Enterprise" for the device. In this case, the device automatically upgrades to Windows Enterprise, but it is not licensed.

However, licensing via the Key Management Service Server (KMS) is possible without any problems. The following two methods were tested:

  • During the installation, a Generic Volume License Keys (GVLK) can already be entered for the corresponding version.
  • After the installation, the KMS server can be entered via the command prompt.

Both methods were successful and Windows has been activated.


Identity - Authentication - MFA

Impersonal accounts and access to cloud applications

In principle, "impersonal accounts" should not have access to cloud applications for security reasons. Cloud applications should always be accessed with a personal account.
Personal accounts must also be used on multi-user devices. With personal accounts, the respective MFA processes are used. This also applies to external guests, e.g. in Microsoft Teams.