Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Overview
User data is the files, mail, settings, and shared content a user expects to find wherever they sign in. Windows 365 offers two options for storing it:
- Cloud user data — recommended deployment option. Data lives in Microsoft 365 services and follows the user across devices and Cloud PCs.
- Traditional user data locations — for traditional or specialized requirements. Data lives on network drives, roaming profiles, or redirected folders.
At a glance: Cloud user data keeps data independent of the Cloud PC, so the device can be reset or reprovisioned without data loss. Traditional locations keep dependencies on file shares and the infrastructure behind them, and should be used only where required.
Cloud user data: recommended deployment option
Start with cloud user data when deploying Cloud PCs. Data is anchored to the user's Microsoft Entra identity rather than to a device, share, or network, and is surfaced inside the Cloud PC on demand. Only revert to traditional storage after validating that the cloud approach won't meet your needs.
The approach has six parts:
- OneDrive for Business with Known Folder Move for Desktop, Documents, and Pictures.
- Files On-Demand, so files download when opened rather than filling the Cloud PC disk.
- Exchange Online for mail and calendar, with PST creation blocked.
- SharePoint and Teams for shared content, replacing mapped network drives.
- Microsoft Edge enterprise sync for favorites, passwords, and browsing data.
- Windows settings roaming, using either Windows settings backup and restore, or User Experience Sync depending on the Cloud PC type.
Microsoft Purview sensitivity labels and DLP then apply across every endpoint, with no dependency on where the data is stored.
Note
Application settings roam differently depending on the application. Edge sync, User Experience Sync, Windows settings backup and restore, and application-native cloud sync each cover different parts of the experience, so confirm which one carries the settings your users depend on.
Why Microsoft recommends a cloud user data approach
- The Cloud PC becomes disposable — reset, resize, or reprovision without touching the user's data.
- Protection follows the data — identity, Conditional Access, DLP, and sensitivity labels apply consistently across Cloud PC, laptop, and mobile.
- Faster sign-in — no roaming profiles or profile shares to wait on.
- The same files everywhere — Desktop, Documents, and Pictures appear on the Cloud PC, laptop, tablet, and phone.
- No file infrastructure to run — no shares, profile permissions, or file servers to size, patch, or back up.
- Recovery is built in — version history, recycle bin, and retention are native to Microsoft 365, so user files need no separate backup product.
Traditional user data locations: traditional approach
Traditional approaches store user files and profile data on infrastructure you manage — Azure Files, Windows file servers, SMB shares, roaming profiles, or folder redirection. Consider them only where a documented business, technical, regulatory, security, or operational requirement can't be met through Microsoft 365.
Important
Where an alternative may be required, aim to limit its scope only to the affected users or scenarios. The decision should be documented along with the affected users or workloads, the business or technical requirement being addressed, the associated trade-offs, and any future opportunities to move toward the recommended cloud-native model.
Organizations should seek to minimize the scope of exceptions wherever possible. This ensures that the broader deployment can retain the benefits of a cloud-native, Zero Trust approach.
When should you consider it?
- Applications requiring direct SMB access.
- Regulatory requirements for a specific storage location.
- Existing investment in file server infrastructure.
- Transitional migration scenarios.
- Workloads not yet compatible with Microsoft 365 storage.
Trade-offs and considerations
- Implicit network trust — Cloud PCs tied to persistently connected shares grant broad, ongoing access, which conflicts with Zero Trust principles of explicit verification and least privilege.
- You own the estate — design, sizing, scaling, patching, replication, backup, and disaster recovery all become your responsibility.
- Slower sign-in — connecting to shares adds delay.
- Data coupled to infrastructure — losing or rebuilding a share affects every user who depends on it.
Important
Where a traditional location is required, limit it to the affected users or scenarios. Document the workloads involved, the requirement being met, the trade-offs accepted, and the plan to move to the cloud-native model later. Keeping exceptions narrow lets the rest of the deployment retain the benefits of a cloud-native, Zero Trust approach.
Comparison
| Capability or requirement | Cloud user data | Traditional user data locations |
|---|---|---|
| Recommended use case | Default and preferred option for most users | Only for traditional or specific use cases |
| Where user files live | OneDrive for Business; SharePoint and Teams for shared content | Azure Files or SMB shares, or folder redirection to on-premises shares |
| Where mail and calendar live | Exchange Online | Exchange Server (on-premises) |
| Windows settings roaming | Windows settings backup and restore, User Experience Sync, and Edge sync | User State Migration Tool (USMT) |
| Sign-in time | Fast — no shares to connect to | Slower — waits on redirection to file shares |
| Cross-device continuity | Native across Cloud PCs, PCs, web, and mobile | Possible, but needs extra infrastructure |
| Infrastructure to manage | None — Microsoft-managed services | File servers or Azure Files, profile shares, backup, disaster recovery |
| Line of sight to on-premises | Not required | Required where shares are on-premises |
| Alignment with Zero Trust | Identity-centric by default | Possible, but needs extra network, identity, and data controls |
Adoption path
Most of what you need is already in your Microsoft 365 tenant and only has to be turned on and scoped to Cloud PC users.
Redirect files to OneDrive with Known Folder Move, so data is captured in the cloud from day one.
Keep mail and browser data in the cloud with Exchange Online and Edge enterprise sync.
Pick one settings roaming option based on your Cloud PC type.
- Windows settings backup and restore is for Windows 365 Enterprise Cloud PCs and Windows 365 Flex Cloud PCs in Dedicated mode. Settings, accessibility preferences, and themes follow the user across Cloud PC, laptop and reprovisioning events with regular backups. These are then restored on first sign-in to a new Cloud PC.
- User Experience Sync is for Windows 365 Flex Cloud PCs in Shared mode and Windows 365 Cloud Apps. Windows personalization, user settings, accessibility preferences, application settings, and application data are all preserved, and available every time they sign in to their Cloud PC or Cloud App.
Migrate shared content to SharePoint and Teams, retiring mapped drives as you go.
Apply labels and DLP in Microsoft Purview so protection travels with the data.
Reach any remaining file shares on demand rather than rebuilding your data model around them.
Related content
- Redirect and move Windows known folders to OneDrive
- OneDrive policies — Use OneDrive Files On-Demand
- Silently configure user accounts — SharePoint in Microsoft 365
- OneDrive policies — Silently sign in users to the OneDrive sync app with their Windows credentials
- Windows settings backup and restore
- Windows settings backup and restore FAQ
- User Experience Sync for Windows 365 Flex in Shared mode
- Configure Microsoft Edge enterprise sync
- Learn about data loss prevention
Next steps
With user data anchored in Microsoft 365, choose how users connect to their Cloud PCs.