Configure sign-in and local user data
Device sign-in policy controls who can use a managed device and what remains on it after sign-out. Test access restrictions in a pilot unit so administrators are not locked out.
Choose the session type
| Goal | Configuration area |
|---|---|
| Named users sign in with managed accounts | Device Settings → Sign-in settings |
| Anonymous temporary browsing | Guest mode; organisational policies do not apply to a normal guest session |
| Policy-controlled shared session | Managed Guest Session Settings |
| One full-screen app | Kiosk → Apps and Kiosk → Settings |
Restrict sign-in
- Open Business+ → Device Settings.
- Select a pilot organisational unit.
- Open Sign-in settings.
- Configure Guest mode.
- Configure Sign-in restriction for the users or domains that should be allowed.
- Optionally set Autocomplete domain to reduce typing errors.
- Decide whether the sign-in screen shows user names and photos.
- Review Updated setting entries, then click Save.
Always retain a tested administrator account or recovery unit outside a new restriction until the pilot succeeds.
Control local user data
Use the User data setting to decide whether local user information is kept or erased after sign-out.
- Erasing local data is useful for shared or high-turnover devices.
- Users should store required work in approved network or cloud locations before sign-out.
- Test offline files, Android app data, certificates, and cached credentials.
- This setting is different from a factory reset and does not by itself remove the device from Management Cloud.
Configure sign-in screen behaviour
The same section includes settings such as:
- Sign-in language and keyboard.
- System information on the sign-in screen.
- Device wallpaper; the current console accepts a JPEG up to 16 MB.
- Device off-hours.
- Privacy screen and numeric keyboard options on supported devices.
Apply only the fields required for the use case. Hardware-dependent settings do not take effect on unsupported devices.
Verify
- Restart a pilot device.
- Confirm the correct sign-in choices and allowed accounts.
- Sign in and verify user policy and apps.
- Sign out and check whether local data is retained or erased as intended.
- Test offline and recovery access.
- Confirm the device remains enrolled and reports a recent policy sync.
If access is blocked unexpectedly, move the device to a known recovery organisational unit or restore the previous value from the console.
What's next
- Configure device policies, apply settings through an organisational unit.
- Device inventory and monitoring, find devices and verify their state.
- Troubleshooting checklist, diagnose common device problems.