Skip to main content

Configure sign-in and local user data

Device sign-in policy controls who can use a managed device and what remains on it after sign-out. Test access restrictions in a pilot unit so administrators are not locked out.

Choose the session type​

GoalConfiguration area
Named users sign in with managed accountsDevice Settings → Sign-in settings
Anonymous temporary browsingGuest mode; organisational policies do not apply to a normal guest session
Policy-controlled shared sessionManaged Guest Session Settings
One full-screen appKiosk → Apps and Kiosk → Settings

Restrict sign-in​

  1. Open Business+ → Device Settings.
  2. Select a pilot organisational unit.
  3. Open Sign-in settings.
  4. Configure Guest mode.
  5. Configure Sign-in restriction for the users or domains that should be allowed.
  6. Optionally set Autocomplete domain to reduce typing errors.
  7. Decide whether the sign-in screen shows user names and photos.
  8. Review Updated setting entries, then click Save.

Always retain a tested administrator account or recovery unit outside a new restriction until the pilot succeeds.

Control local user data​

Use the User data setting to decide whether local user information is kept or erased after sign-out.

  • Erasing local data is useful for shared or high-turnover devices.
  • Users should store required work in approved network or cloud locations before sign-out.
  • Test offline files, Android app data, certificates, and cached credentials.
  • This setting is different from a factory reset and does not by itself remove the device from Management Cloud.

Configure sign-in screen behaviour​

The same section includes settings such as:

  • Sign-in language and keyboard.
  • System information on the sign-in screen.
  • Device wallpaper; the current console accepts a JPEG up to 16 MB.
  • Device off-hours.
  • Privacy screen and numeric keyboard options on supported devices.

Apply only the fields required for the use case. Hardware-dependent settings do not take effect on unsupported devices.

Verify​

  1. Restart a pilot device.
  2. Confirm the correct sign-in choices and allowed accounts.
  3. Sign in and verify user policy and apps.
  4. Sign out and check whether local data is retained or erased as intended.
  5. Test offline and recovery access.
  6. Confirm the device remains enrolled and reports a recent policy sync.

If access is blocked unexpectedly, move the device to a known recovery organisational unit or restore the previous value from the console.

What's next​