Startseite > Next Generation Sync Client, OneDrive for Business, SharePoint Online > OneDrive | Update for GPO team site libraries to sync automatically

OneDrive | Update for GPO team site libraries to sync automatically


Group Policy: Configure team site libraries to sync automatically

I have written an article about “OneDrive GPO: Configure team site libraries to sync automatically” and I must update this article.

First, and that is important: If we are looking inside the OneDrive Group Policies, you will see, there is a Group Policy in both parts (Machine and User) with the same name

Configure team site libraries to sync automatically

I have described the GPO, which is a Machine policy. But there are other Scenario’s with more than one user and Microsoft has decided, to have the same Group Policy also in the Users Section.

Local Group Policy Editor: Computer

Local Group Policy Editor: User

The name is the same. The group Policy looks like the same. The Functionality is the same. Only the Key in the Regedit is different

Machine

[HKLM\SOFTWARE\Policies\Microsoft\OneDrive\TenantAutoMount] "LibraryName"="LibraryID"

User

[HKCU\Software\Policies\Microsoft\OneDrive\TenantAutoMount]"LibraryName"="LibraryID"

 

Why Microsoft decided to have the same Group Policy in the Users section?

Its very easy, because if you look for devices, where different people from different departments will login, then there is the answer. If you have a machine policy, you are only may connect to team sites, where all possible users have the rights. Changing that to a User Policy, you may have to rollout several different GPOs, that will only work with this subset of AD.

Other questions received me, thank you, and I try to give you the right answer:

Why do we have the limit of 1000 devices?

We have to know, how OneDrive is working. Microsoft uses Windows Push Notification Services (WNS) to sync files in real time. The main important part is: WNS informs the sync client whenever a change actually happens, eliminating redundant polling and saving on unnecessary computing power. So on the Server side:

  • A change occurs in Office 365.
  • WNS alerts the OneDrive sync client of the change.
  • OneDrive adds it to the Internal Server Changes Queue.
  • – Any metadata changes happen immediately, like renaming or deleting files.
  • – Downloading content also starts a specific session with the client.
  • Office 365 has metadata pointers directing it through Microsoft Azure.
  • The changes are processed in the order they are received.

The previous OneDrive for Business sync client (Groove.exe) used a polling service to check for changes on a predetermined schedule. Polling can lead to system lag and slowness because it requires a lot of computing power. Using WNS is a significant enhancement.

Now back to our question: WNS has one limit: 1000.

This is the current limit of devices that can subscribe through the WNS pipeline to get notifications from the service about file changes. After that limit is reached, the remaining clients will go into polling mode, which means they will poll the service every few minutes to see if there are any changes.

Why does take up to 8 hours, until the client machine receives the files?

This is because of the potential spike of requests of mounting a team site both on the customer’s network as well as on the backend service.

This Group Policy is in Preview. Microsoft will see on telemetry data, how this Group policy will be used. In other words. It could be change in the future

  1. Sasa
    8. April 2020 um 19:53

    I don’t see you mentioned another limitation and that is 5000 file/folders per library. https://docs.microsoft.com/en-us/onedrive/use-group-policy#AutoMountTeamSites

    • 9. April 2020 um 17:43

      No, why? Thats one of other limitationa and has nothing to do with the description of this group policy

  2. Alex
    17. Dezember 2019 um 10:30

    Mr. Brender,

    Do you know, can I add many Sharepoint sites with the different access lists into one GPO in order to apply it to the group of the local users with the different access rights to each site? May it cause any problem with the network performance, denial of service, or lock the users because of the continious tries to sync the forbidden site?
    Thank you.

    • 17. Dezember 2019 um 15:14

      Yes, You can specify different document libraries into the GPO. But
      1) It may take up to 8 hours
      2) You must be aware of the max 1000 devices for each doc lib
      3) To access the data, the user must be a member of the doc lib

      better do it, have different departments of the User in Azure AD, and deploy the right doc libs to the right users

  3. Tad Amore
    3. Mai 2019 um 18:13

    I have followed your post but I am not seeing the “TenantAutoMount” folder get created under “HKLM\SOFTWARE\Policies\Microsoft\OneDrive” or “HKCU\Software\Policies\Microsoft\OneDrive” what am I missing?

    • Tad Amore
      3. Mai 2019 um 18:15

      I can confirm the GP is running, after running a gpupdate /force I run GPRESULT /H GPReport.html and in the report, I see my policy run.

      Also, I am assuming if this runs on a user that does not have access to the document library nothing will sync?

      • 3. Mai 2019 um 18:50

        sure, that makes no sense

    • 3. Mai 2019 um 18:49

      You have to wait up to 8 hours

  4. romhill
    25. April 2019 um 14:59

    hi
    and how it looks in explorer does it map as G:\ our? our under the Intranet House

    • 28. April 2019 um 11:22

      No, you find it in the explorer, jast as any other regular doc lib, you have synced manually

  5. Heeb Sven
    5. April 2019 um 06:57

    Hallo Hans, gibt es das ganze auch für Intune OMA uri oder GPO in Preview?

  1. 27. April 2020 um 18:43
  2. 4. April 2019 um 16:56

Kommentar verfassen

Trage deine Daten unten ein oder klicke ein Icon um dich einzuloggen:

WordPress.com-Logo

Du kommentierst mit Deinem WordPress.com-Konto. Abmelden /  Ändern )

Google Foto

Du kommentierst mit Deinem Google-Konto. Abmelden /  Ändern )

Twitter-Bild

Du kommentierst mit Deinem Twitter-Konto. Abmelden /  Ändern )

Facebook-Foto

Du kommentierst mit Deinem Facebook-Konto. Abmelden /  Ändern )

Verbinde mit %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d Bloggern gefällt das: