User data: cloud user data for Windows 365 Cloud PCs

Overview

User data is the files, mail, settings, and shared content a user expects to find wherever they sign in. Windows 365 offers two options for storing it:

  • Cloud user data — recommended deployment option. Data lives in Microsoft 365 services and follows the user across devices and Cloud PCs.
  • Traditional user data locations — for traditional or specialized requirements. Data lives on network drives, roaming profiles, or redirected folders.

At a glance: Cloud user data keeps data independent of the Cloud PC, so the device can be reset or reprovisioned without data loss. Traditional locations keep dependencies on file shares and the infrastructure behind them, and should be used only where required.

Start with cloud user data when deploying Cloud PCs. Data is anchored to the user's Microsoft Entra identity rather than to a device, share, or network, and is surfaced inside the Cloud PC on demand. Only revert to traditional storage after validating that the cloud approach won't meet your needs.

The approach has six parts:

  • OneDrive for Business with Known Folder Move for Desktop, Documents, and Pictures.
  • Files On-Demand, so files download when opened rather than filling the Cloud PC disk.
  • Exchange Online for mail and calendar, with PST creation blocked.
  • SharePoint and Teams for shared content, replacing mapped network drives.
  • Microsoft Edge enterprise sync for favorites, passwords, and browsing data.
  • Windows settings roaming, using either Windows settings backup and restore, or User Experience Sync depending on the Cloud PC type.

Microsoft Purview sensitivity labels and DLP then apply across every endpoint, with no dependency on where the data is stored.

Note

Application settings roam differently depending on the application. Edge sync, User Experience Sync, Windows settings backup and restore, and application-native cloud sync each cover different parts of the experience, so confirm which one carries the settings your users depend on.

Why Microsoft recommends a cloud user data approach

  • The Cloud PC becomes disposable — reset, resize, or reprovision without touching the user's data.
  • Protection follows the data — identity, Conditional Access, DLP, and sensitivity labels apply consistently across Cloud PC, laptop, and mobile.
  • Faster sign-in — no roaming profiles or profile shares to wait on.
  • The same files everywhere — Desktop, Documents, and Pictures appear on the Cloud PC, laptop, tablet, and phone.
  • No file infrastructure to run — no shares, profile permissions, or file servers to size, patch, or back up.
  • Recovery is built in — version history, recycle bin, and retention are native to Microsoft 365, so user files need no separate backup product.

Traditional user data locations: traditional approach

Traditional approaches store user files and profile data on infrastructure you manage — Azure Files, Windows file servers, SMB shares, roaming profiles, or folder redirection. Consider them only where a documented business, technical, regulatory, security, or operational requirement can't be met through Microsoft 365.

Important

Where an alternative may be required, aim to limit its scope only to the affected users or scenarios. The decision should be documented along with the affected users or workloads, the business or technical requirement being addressed, the associated trade-offs, and any future opportunities to move toward the recommended cloud-native model.

Organizations should seek to minimize the scope of exceptions wherever possible. This ensures that the broader deployment can retain the benefits of a cloud-native, Zero Trust approach.

When should you consider it?

  • Applications requiring direct SMB access.
  • Regulatory requirements for a specific storage location.
  • Existing investment in file server infrastructure.
  • Transitional migration scenarios.
  • Workloads not yet compatible with Microsoft 365 storage.

Trade-offs and considerations

  • Implicit network trust — Cloud PCs tied to persistently connected shares grant broad, ongoing access, which conflicts with Zero Trust principles of explicit verification and least privilege.
  • You own the estate — design, sizing, scaling, patching, replication, backup, and disaster recovery all become your responsibility.
  • Slower sign-in — connecting to shares adds delay.
  • Data coupled to infrastructure — losing or rebuilding a share affects every user who depends on it.

Important

Where a traditional location is required, limit it to the affected users or scenarios. Document the workloads involved, the requirement being met, the trade-offs accepted, and the plan to move to the cloud-native model later. Keeping exceptions narrow lets the rest of the deployment retain the benefits of a cloud-native, Zero Trust approach.

Comparison

Capability or requirement Cloud user data Traditional user data locations
Recommended use case Default and preferred option for most users Only for traditional or specific use cases
Where user files live OneDrive for Business; SharePoint and Teams for shared content Azure Files or SMB shares, or folder redirection to on-premises shares
Where mail and calendar live Exchange Online Exchange Server (on-premises)
Windows settings roaming Windows settings backup and restore, User Experience Sync, and Edge sync User State Migration Tool (USMT)
Sign-in time Fast — no shares to connect to Slower — waits on redirection to file shares
Cross-device continuity Native across Cloud PCs, PCs, web, and mobile Possible, but needs extra infrastructure
Infrastructure to manage None — Microsoft-managed services File servers or Azure Files, profile shares, backup, disaster recovery
Line of sight to on-premises Not required Required where shares are on-premises
Alignment with Zero Trust Identity-centric by default Possible, but needs extra network, identity, and data controls

Adoption path

Most of what you need is already in your Microsoft 365 tenant and only has to be turned on and scoped to Cloud PC users.

  1. Redirect files to OneDrive with Known Folder Move, so data is captured in the cloud from day one.

  2. Keep mail and browser data in the cloud with Exchange Online and Edge enterprise sync.

  3. Pick one settings roaming option based on your Cloud PC type.

    • Windows settings backup and restore is for Windows 365 Enterprise Cloud PCs and Windows 365 Flex Cloud PCs in Dedicated mode. Settings, accessibility preferences, and themes follow the user across Cloud PC, laptop and reprovisioning events with regular backups. These are then restored on first sign-in to a new Cloud PC.
    • User Experience Sync is for Windows 365 Flex Cloud PCs in Shared mode and Windows 365 Cloud Apps. Windows personalization, user settings, accessibility preferences, application settings, and application data are all preserved, and available every time they sign in to their Cloud PC or Cloud App.
  4. Migrate shared content to SharePoint and Teams, retiring mapped drives as you go.

  5. Apply labels and DLP in Microsoft Purview so protection travels with the data.

  6. Reach any remaining file shares on demand rather than rebuilding your data model around them.

Next steps

With user data anchored in Microsoft 365, choose how users connect to their Cloud PCs.