Windows To Go
A deployment guide
for education
January 2014
Table of
contents
1 Understanding Windows To Go
1 Windows To Go for IT
2 Windows To Go for faculty
2 Windows To Go for students
4 Preparing to use Windows To Go
4 Windows To Go limitations
5 Roaming with Windows To Go
5 Determine user setting storage
6 Determine remote access requirements
6 Determine host computer requirements
7 Select the USB drive for Windows To Go
7 Understand Windows To Go image creation
9 Creating a Windows To Go drive
9 Using the Windows To Go Creator Wizard
10 Using Windows PowerShell cmdlets
12 Starting a Windows To Go drive
13 Enabling the Windows Store
14 Activating Windows To Go workspaces
15 Managing Windows To Go
15 Group Policy settings related to the
Windows To Go workspace
17 Group Policy settings related to the host computer
18 Storing user data and settings
19 UE-V with Folder Redirection
19 Cloud storage
21 Conguring Windows To Go for remote access
22 Securing Windows To Go drives
23 ConguringBitLockerbeforedistribution
23 ConguringBitLockerafterdistribution
25 Building multiple Windows To Go drives
26 Talking about Windows To Go
27 Conclusion
1WINDOWS TO GO
Windows To Go
A deployment guide for education
Windows To Go is a feature of the Windows 8.1 Enterprise operating system that
enables the operating system to run from a USB drive. Using Windows To Go in an
education environment provides numerous benets to faculty and students alike. It
enables faculty and students to use a personalized copy of Windows 8.1 on virtually
any PC, at almost any location. This guide provides an overview of Windows To Go
deployment for schools. It is for IT pros and discusses the benets, limitations, and
processes involved in deploying Windows To Go.
Understanding Windows To Go
WindowsToGocreatesabootableWindows8.1imageonaUSBdrive.Thismeansthatthe
standardizedWindowsimagealreadyusedoninstitution-owneddevicesnowbecomesavailable
withgreatlyincreasedportabilityandconvenience.Usersdonotneedtolugaroundalaptop
orotherdevicetohavetheirWindowsdesktopavailable:Thatdesktopisnowavailableona
USBdrive,andtheycanrunitonanyPCthatiscompatiblewithWindows7,Windows8,or
Windows8.1.
Windows To Go for IT
WindowsToGohelpsITinseveralways:
• Portability WindowsToGoenablesITtooffertheexibilityoffreeseating.Facultyand
studentscanusetheirownWindowsdesktopfromalmostanyPCintheschool.
• Cost savings ITdoesnotneedtodeployindividualcomputersbutrathercandeploythe
WindowsToGoworkspaceonUSBdrivestoprovideaconsistent,personalizedWindows8.1
experience.Itiseasytosetupandcongure,anddistributionissimple.
• Management Today’sITinfrastructureusesGroupPolicyandtechnologieslikeBitLocker
Drive Encryption, Microsoft BranchCache, Application Virtualization, DirectAccess, and other
2WINDOWS TO GO
advancedtechnologiestoensurehighlyreliableandsecureservicestousers.WindowsToGo
supportsallofthosetechnologiesandmore.YoudonotneedtochangeyourITprocesses
andmanagementtoolstoaddWindowsToGotoyourITinfrastructure.
Windows To Go for faculty
WindowsToGogivesfacultyaconsistentWindows8.1experiencefromalmostanywhere.Is
seatingavailableinacomputerlab?Needtomovetoanotherclassroom?Theeducator’spersonal
Windows8.1desktopisavailableatalloftheselocationsbybootingintotheWindowsToGo
workspace.
Facultymembersusenumeroustoolstoprovidethebestlearningexperiencefortheclassroom,
suchasMicrosoftOfceandthespecializedLearningManagementSystem(LMS).Atthesame
time, computers with that specialized software are typically shared among two or more educators,
makingitdifculttondatimetogetclassroom-relatedadministrativeworkdone.
WithaWindowsToGoworkspace,sharingacomputerbecomesathingofthepast.WithWindows
ToGo,anycompatiblecomputer,regardlessoftheoperatingsysteminstalledonit,canbeused.
ThismeansthatfacultymemberscanuseaWindowsToGoworkspaceatwork,fromhome,or
fromanoff-campuslocation,providingthesameexperienceregardlessoflocation.Facultyareno
longertetheredtoaspeciccomputer,room,orbuilding.
Windows To Go for students
Likefaculty,studentscanbenetfromtheWindowsToGoexperience.Studentscanusea
WindowsToGoworkspacetobootintotheirownWindowsworkspacefromhomeorfromafree
seatinschool.TheycanhavethesamepersonalWindows8.1experienceineachclassroom.
Students can also use Windows To Go workspaces to get their homework done and perform
research-relatedtasksbyusingspecializedsoftwarewithoutneedingtoinstallthatsoftwareon
theirowndevice.AlltheyneedisacompatiblecomputerandUSBdrive,andtheworkspaceisup
andrunning.
YoucancustomizeWindowsToGoworkspacesforparticularcurriculums,gradelevels,andso
on,thendistributethemtostudents.Doingsohelpstofacilitatethelearningexperiencewhile
minimizingthetimeinvestedinconguringthetechnology.
WindowsToGoworkspaceshavelowreplacementcost.IfastudentlosestheUSBdrivewiththe
workspaceonitorifthedrivebecomesdamaged,itcanbereplacedatamuchlowercostthana
PC.
3WINDOWS TO GO
Additionalresources:
• “Windows8EnterpriseinYourPocket”at />enterprise/products-and-technologies/devices/windowstogo.aspx
• “WindowsToGo:FrequentlyAskedQuestions”at />jj592680.aspx
4WINDOWS TO GO
Preparing to use Windows To Go
Thissectiondescribestheinfrastructure-relateditemsthatyoumustconsiderforaWindows
ToGodeploymentandalsoprovidesconsiderationsforthatpreparation.Inadditiontothe
considerationsthatthefollowingsectionsdescribe,seeWindows 8.1 deployment planning: A guide
for education at for considerations
affectinganyWindows8.1deploymentinaneducationalinstitution.
Windows To Go limitations
AlthoughWindowsToGoissimilartoatypicalWindows8.1EnterpriseinstallationonaPC,some
differencesexist:
• No access to internal disks Bydefault,thehostcomputer’sdisksarenotaccessibleby
a Windows To Go installation, and a USB drive with a Windows To Go workspace is not
accessiblebytheWindowsoperatingsysteminstalledonthecomputer.Youcaneliminate
bothoftheselimitationsbyusingGroupPolicy.However,theserestrictionsareinplaceto
protect the security and privacy of the Windows To Go workspace, and to help prevent end-
userconfusion.
• Recovery options are limited TheWindowsRecoveryEnvironment(WindowsRE)isnot
availableinWindowsToGo,norarerefreshandresetoptions.Youshouldre-provisionthe
Windows To Go workspace onto the USB drive in the event a Windows To Go workspace
becomesunrecoverable.Becauserecoveryoptionsarelimited,Microsoftdoesnot
recommendstoringuserdataontheWindowsToGoUSBdrive.Instead,useanetwork-or
cloud-basedsolutionlikeFolderRedirectionorSkyDrive.
• Trusted Platform Module (TPM) is not used TheTPMistiedtoaspecicphysical
computer.Therefore,becauseWindowsToGoworkspacesmoveamongcomputers,theTPM
isnotusedinaWindowsToGoworkspace.Initsplace,apasswordisrequiredforBitLocker
onaWindowsToGoworkspace.
• Windows Store is disabled (Windows 8 only) InWindows8,theWindowsStoreisdisabled
bydefault,becauseappsaretiedtothecomputeritself.YoucanuseGroupPolicytoenable
theWindowsStore.InWindows8.1,thislimitationisgone,andtheWindowsStoreisenabled
bydefault.RegardlessoftheWindowsStorestatus,youcanstillsideloadappsforwhich
youhaveinstallationles.FormoreinformationaboutsideloadingWindowsStoreapps,
see Windows Store apps: A deployment guide for education at />download/details.aspx?id=39685.
5WINDOWS TO GO
• Hibernate is disabled Hibernationexpectstondthesamehardwarewhentheoperating
systemresumes.BecauseWindowsToGoworkspaceswilllikelyroamamongcomputers,
hibernationisdisabled.LiketheWindowsStore,youcanre-enablehibernate,butonly
enablehibernationifyouarecertainthatthedevicewillonlybeusedonthesamephysical
computer.
Roaming with Windows To Go
Duringthebootprocess,WindowsToGoexaminesthehostcomputer’shardwareandinstalls
thenecessarydevicedrivers.Thisprocessgenerallyworkswell,especiallyifpeoplewillbe
usingWindowsToGoonhostcomputerswithsimilarhardwarecongurations.However,ifthe
workspacewillbeusedondifferenthardwarewithdifferentdevicecongurations,thenyoumight
needtoinjectadditionaldriversintotheimage.Testingtheimageonthehardwareisakeystepto
ensurecompatibilityforthedevicestobeusedwithWindowsToGo.
Someapplicationscanbindtospecichardware.Forexample,anapplicationmighttieitslicensing
oractivationtothecomputer’shardware.IftheWindowsToGoworkspacewillbeusedon
multiplehostcomputerswithdifferenthardwarecongurations,theapplicationsmightnotroam.
Ensure that each application you are installing in a Windows To Go workspace supports roaming
or provide for an alternate method of using those applications, such as Windows Server 2012 R2
RemoteApp.
Studentsandfacultyarenotusuallyawareofwhichtypeofrmwaretheircomputershave,and
sotheywilllikelyboottheirworkspacesondifferenttypes.TheycanbootWindowsToGoon
computerswithdifferenttypesofrmware.ComputerscertiedforWindows8.1haveUnied
ExtensibleFirmwareInterface(UEFI),whileWindows7computersusethelegacyBIOSrmware.
Ratherthancreatingseparateworkspacesfordifferentrmwaretypes,WindowsToGocanboot
oneitherrmwaretype.
Determine user setting storage
Users need access to their data and settings within the Windows To Go workspace in addition
totheirusualdevice.Determinehowbesttoprovidethisaccess,whetherthroughauserstate
virtualization(USV)technologyorthroughothermeans.Optionsincludelocalstorage,Microsoft
UserExperienceVirtualization(UE-V)withFolderRedirectionandOfineFiles,SkyDrive,Microsoft
Ofce365,andothercloud-basedstoragesolutions.Windows8.1alsoenableslogonwitha
Microsoftaccount,whichincludestheoptionofroamingformanyusersettings.Thisaspectof
Windows To Go is discussed in the section “Storinguserdataandsettings”onpage18 in this
guide.
6WINDOWS TO GO
Determine remote access requirements
IfWindowsToGoworkspaceswillbeusedfromoff-campuslocations,
thenyoumightprovideamethodforremoteaccess.Youcandoso
byusingDirectAccessorbyusinganexistingvirtualprivatenetwork
(VPN)solution.Moredetailonremoteaccessisgivenin“Conguring
WindowsToGoforremoteaccess”onpage21.
Determine host computer requirements
WindowsToGosupportsmanydifferenttypesofhardware.This
supportenablesuserstorunWindowsToGoworkspaceson
hardwarecertiedforWindows8.1,Windows8,andWindows7alike.
Notethefollowinghostcomputerrequirements:
• Booting ThecomputermustbecapableofbootingfromaUSB
drive,andthedrivemustbedirectlyconnected;USBhubsare
notsupported.
• Firmware ThecomputercanuseUEFIorBIOS.
• Graphics The computer should have Microsoft DirectX 9 with
WindowsDisplayDriverModel1.2orlaterdriver.
• Processor Thecomputershouldhavea1GHzorfaster
processor,andthearchitecturecanbe32or64bit,asdiscussed
laterinthisguide.
• RAM The computer should have at least 2 GB of physical
memory.
• USB port ThecomputershouldhaveatleastoneUSB2.0or
3.0port.
Whenconsideringtheprocessorarchitecture,thermwareis
animportantconsideration.Table1onpage7describesthe
processorarchitectureconsiderationsforWindowsToGo.
NOTE
Windows To Go
workspaces are not
supported on Windows RT
orAppleplatforms.
7WINDOWS TO GO
Host firmware Host processor
arcHitecture
windows to Go
arcHitecture
BIOS 32-bit 32-bitonly
BIOS 64-bit 32-bitand64-bit
UEFI 32-bit 32-bitonly
UEFI 64-bit 64-bitonly
Select the USB drive for Windows To Go
TheUSBdriveusedforWindowsToGomustbeWindowsToGo
certied.WindowsToGo–certieddrivesareoptimizedfortherateof
I/OoperationsnecessaryforWindows.Theyarecapableofbooting
onhardwarecertiedforWindows7,Windows8,andWindows8.1.
Thedriveshavemanufacturerwarrantiesandaremeanttobeused
tosupportatypicalWindowsworkload.Severalhardwarevendors
offerthesedrivesinavarietyofsizes.See“WindowsToGoOverview”
at />hardwareforalistofcurrentlysupporteddrives.
NOTE AWindowsToGoimagerunningWindows8.1can
bootfromadrivethatcontainsabuilt-insmartcard.These
compositedrivescombineamassstoragedriveandsmartcard
inonedevice.Windows8.1canenumeratethesmartcardwhen
bootingfromtheWindowsToGodriveorbyconnectingthe
devicetoanotherhostmachine.Formoreinformation,see
“What’sNewinSmartCards”at />library/hh849637.aspx.
Understand Windows To Go image creation
EaseofdeploymentisakeyfeatureofWindowsToGo.AWindows8.1
releasetomanufacturing(RTM)imageisallthatisneededtobegin
theWindowsToGoimage-creationprocess.Alternately,youcanfully
TABLE 1 Processor
Architecture and
Windows To Go
NOTE
YoucanalsouseMicrosoft
System Center 2012 R2
CongurationManager
todistributeworkspaces.
SeetheMicrosoftTechNet
article“HowtoProvision
Windows To Go in
CongurationManager”
at http://technet.
microsoft.com/en-us/
library/jj651035.aspx for
moreinformation.
8WINDOWS TO GO
customizetheimagetoincludeapplicationsandothersettingsspecictothedeployment.Users
withlocaladministratorprivilegesandaWindows8.1Enterpriseimage(anunlikelyscenarioinan
educationsetting)canalsocreatetheirownWindowsToGoworkspace.Therefore,schoolITpros
willbethelikelysolecreatorsofWindowsToGoworkspaces.
If you do not customize the image, then you will need to provide for the resulting Windows To Go
workspacetobejoinedtothedomainandforapplicationstobeinstalledintheworkspace.You
can use Group Policy to manage the workspace, and you may want to customize certain settings
foryourenvironment.Seethesection“ManagingWindowsToGo”onpage15 or the section
“Imagedeploymentanddriveprovisioningconsiderations”intheTechNetarticle“Deployment
ConsiderationsforWindowsToGo”at />aspx#wtg_imagedep for more information on these Group Policy settings and Windows To Go
deployment.
YoucancreateaWindowsToGoworkspacebyusingtheWindowsToGoCreatorWizardor
WindowsPowerShellcmdlets.AfteryouhaveprovisionedtheworkspaceontoaUSBdrive,
youcanduplicatetheworkspaceontootherUSBdrives(assumingthattheworkspacehasnot
yetbeenstartedforthersttime).SeetheTechNetarticle“WindowsDeploymentOptions”at
for more information on Windows
DeploymentOptionsandthetopic“WindowsPowerShellequivalentcommands”in“Deploy
WindowsToGoinYourOrganization”at />aspx#BKMK_manualwtgimageformoreinformationonmanualWindowsToGoimagecreation.
Additionalresources:
• “DeploymentConsiderationforWindowsToGo”at />library/jj592685.aspx
• “WindowsToGo:FeatureOverview”at />• “TipsforconguringyourBIOSsettingstoworkwithWindowsToGo”athnet.
microsoft.com/wiki/contents/articles/12911.tips-for-conguring-your-bios-settings-to-work-
with-windows-to-go.aspx
9WINDOWS TO GO
Creating a Windows To Go drive
YoucanuseeitheroftwoprimarymethodstocreateaWindowsTo
Godrive:
• The Windows To Go Creator Wizard
• Windows PowerShell cmdlets
The method you use depends largely on the goals of the deployment
andtheskillsavailableforthedeployment.Regardlessofwhich
method you employ, the result is a USB drive with a Windows To Go
workspaceonit.
Table2 provides considerations to help you decide which method of
WindowsToGoworkspacecreationisrightforyou.
windows to Go
creator wizard
windows powersHell
Number of
workspaces needed
• Few
• USB duplicator
• Many workspaces with
potentially unique
congurationsforeach
Customizations
needed
• None
• Customized
image
• Custom provisioning
(e.g.,ofinedomainjoin,
partitioning,BitLocker)
required
Skills • IT generalist • IT pro with Windows
PowerShellexperience
Using the Windows To Go Creator Wizard
The Windows To Go Creator Wizard is a simple way to create a
WindowsToGoworkspacequickly.Thewizardcreatesafully
functionalworkspacewithjustafewmouseclicks.UsingtheWindows
To Go Creator Wizard involves selecting the USB drive along with the
Windowsimagetobeusedforthedeployment.Tousethewizard,
youmusthave:
TABLE 2 Choosing a
Windows To Go Creation
Strategy
10WINDOWS TO GO
• AWindowsToGo–certiedUSBdriveconnectedtothe
computer prior to starting the wizard
• AWindows8.1Enterpriseimage,eithertheRTMimageora
customizedimagethathasbeengeneralizedwiththeMicrosoft
SystemPreparationTool(Sysprep)
• Localadministratorprivileges
YoucanenableBitLockerduringtheWindowsToGoCreator
Wizard.Ifyouwillbeusingadriveduplicatortomakecopiesofthe
workspace,however,donotenableBitLockerfromthewizardbut
ratherafterdeployment.Seethetopic“EnableBitLockerprotection
foryourWindowsToGodrive”intheTechNetarticle“Deploy
WindowsToGoinYourOrganization”atrosoft.
com/en-us/library/jj721578.aspx#BKMK_4wtgdeploy for more
informationonenablingBitLocker.
The overall process for workspace creation involves the following
tasks:
1. Select the USB drive on which to create the Windows To Go
workspace.
2.Select the Windows image to use as an installation source for the
workspace.
3.Optionally,enableBitLockerontheworkspaceimmediately.
The process of workspace creation takes 20 to 30 minutes, and the
resultisthatyouhaveaWindowsToGoworkspaceontheUSBdrive.
Fromthatpoint,youcaneitherboottheworkspaceorduplicateitto
otherUSBdrives.
Using Windows PowerShell cmdlets
Use Windows PowerShell cmdlets to create Windows To Go
workspaceswhenyouneedadditionalexibility.WindowsPowerShell
enablesyoutocreateacustom,scriptedsolutionforlarge-scale
WindowsToGoworkspacecreation.
NOTE
Always safely eject the
USB drive when the
provisioning process is
complete.Removing
the drive in an unsafe
manner can result in an
unbootableWindowsTo
Goworkspace.
11WINDOWS TO GO
The tools used to create a Windows To Go workspace are essentially the same tools you use to
manuallyprovisionanddeployWindowsimages.Theyinclude:
• Disk partitioning cmdlets such as Clear-Disk, Initialize-Disk, New-Partition, Format-
Volume, and so on
• DeploymentImageServicingandManagement(DISM)
• Bcdboot
YouusethesetoolstoperformthesamestepsmanuallythattheWindowsToGoCreatorWizard
performs.Theprocessincludesthefollowingtasks:
1. PartitiontheUSBdrive,includingFAT32-andNTFSlesystem–formattedpartitions.
2.UseDISMtoapplytheWindowsimage.
3.Use BcdboottoenablethesystemtostartonUEFIandBIOSsystems.
4.UseDISMtoapplyastorageareanetworkpolicytopreventtheinternaldisksfrombeing
used.
5.CreateananswerletodisableWindowsRE.
LiketheWindowsToGoCreatorWizard,theresultwhenusingWindowsPowerShellisthat
youhaveaWindowsToGoworkspaceontheUSBdrive.See“DeployWindowsToGoinYour
Organization”at for
moreinformationaboutscriptingWindowsToGoprovisioningbyusingWindowsPowerShell.
Additionalresources:
• “DeployWindowsToGoInYourOrganization”at />jj721578.aspx
• “GettingStartedwithWindowsPowerShell”at />hh857337.aspx
• Windows PowerShell User’s Guide at />aspx
12WINDOWS TO GO
Starting a Windows To Go drive
UsersofWindowsToGoneedtocongurethehostcomputerto
bootfromUSB.FordevicesrunninganearlierversionoftheWindows
operatingsystem,theUSBbootoptioncanbeenabledinthedevice’s
rmware,suchastheBIOS.ForcomputersrunningWindows8or
Windows8.1,theWindowsToGoworkspacecanalsobecongured
tostartusingWindowsToGoStartupOptions.OntheStartscreen,
press the Windows logo key + W, and then search for Windows To
Go startup optionstocongurethecomputertobootfromaUSB
drive.Changingthissettingrequiresadministratorprivileges.Youcan
alsosettheoptiontobootfromaUSBdrivebyusingGroupPolicyfor
Windows8andWindows8.1.
Regardless of whether you are using a Windows 7 host computer or
aWindows8.1hostcomputer,usecautionwhenenablingbootfrom
USBdevices.Doingsomayopenanattackvectorifthecomputeris
bootedfromaUSBdrivecontainingmalware.
WhenpreparingacomputertobootintoaWindowsToGo
workspace, make sure the computer is not currently in a sleep
state.TheUSBdrivewiththeWindowsToGoworkspaceshouldbe
connected directly to a USB port on the computer, not through a USB
hub.
Additionalresources:
• “DeploymentConsiderationsforWindowsToGo”athttp://
technet.microsoft.com/en-us/library/jj592685.aspx
NOTE
Additional considerations
existwhenusinga
computer running
Windows 7 as a host
computer.See“Tipsfor
conguringyourBIOS
settings to work with
WindowsToGo”athttp://
social.technet.microsoft.
com/wiki/contents/
articles/12911.tips-for-
conguring-your-bios-
settings-to-work-with-
windows-to-go.aspx for
moreinformation.
13WINDOWS TO GO
Enabling the Windows Store
TheWindowsStoreisenabledbydefaultonWindowsToGodrivesrunningWindows8.1.Userscan
startthedriveonanynumberofhostcomputers,accesstheWindowsStore,andruntheirapps.
InWindows8,theWindowsStoreisdisabledinaWindowsToGoworkspacebydefault,because
appspurchasedthroughtheWindowsStorearetiedtothedevice’shardwareandcanbeinstalled
onasmanyasvedevices.ThismeansthattheappwillnotruniftheWindowsToGoworkspaceis
bootedfrommorethanvedifferentdevices.
YoucanenabletheWindowsStorebyusingtheAllow Store to install apps on Windows To Go
workspaces GroupPolicysettingfoundat\ComputerConguration\AdministrativeTemplates\
WindowsComponents\Store.Usethispolicysettingwhentheworkspacewillbebootedfromthe
sameoralimitednumberofcomputers.
IftheWindowsStorewillremaindisabled,Microsoftrecommendsthatyouremovethedefault
WindowsStore–relatedapps,suchasSportsorNews,fromtheWindowsToGoworkspaceimage.
TheseappsareupdatedthroughtheWindowsStoreandthereforecannotbeupdatedwiththe
WindowsStoredisabled.Educationalappsthatyousideloadareunaffectedbythispolicyandcan
stillbeloaded,run,andmanagedthroughnormalappmanagementprocesses.
Additionalresources:
• Windows Store apps: A deployment guide for education at />download/details.aspx?id=39685
• “ManagementofWindowsToGousingGroupPolicy”at />library/c598d28c-5829-42ce-8d43-a7a5a4382537#BKMK_wtggp
• “HowtoAddandRemoveApps”at />aspx
• “ManagingClientAccesstotheWindowsStore”at />library/hh832040.aspx
• “PrepareYourOrganizationforWindowsToGo”at />library/0fd52a81-c871-4567-aaaf-bd29c2ee65d4
14WINDOWS TO GO
Activating Windows To Go workspaces
WindowsToGocanuseActiveDirectory-BasedActivation(ADBA)andKeyManagementService
(KMS)activation,similartoatypicalinstallationofWindows8.1.However,WindowsToGocannot
useMultipleActivationKey(MAK)activation,asMAKactivationbindstothehostcomputer’s
hardware.WindowsToGousesastandardWindowslicenseandcountsasaninstallationfor
applicablelicensingagreements.
TheWindowsToGoworkspaceneedstorenewitsactivationevery180days.Itdoesthiswhenever
theworkspaceisbootedwithintheschool’snetworkorwhenusingaremoteconnectionlike
DirectAccessoraVPN.Ifworkspacesarenotusedwithinthe180-dayperiod,youwillneedto
reactivatethembyconnectingthemtothenetworkcontainingtheADBAorKMSservices.
Applicationstobeusedwithintheworkspacemightalsoneedtobeactivated.Ofce2013usesthe
sameactivationmethodsasWindowsToGo,butsoftwarefromothervendors,suchasLMSsand
othereducationalapplications,mighthavedifferentlicensing.VerifytheWindowsToGousage
scenariowiththeappropriatevendorstoensurelicensingcompliance.
Additionalresources:
• “PlanforVolumeActivation”at />• “UnderstandingKMS”at />• “ActiveDirectory-BasedActivationOverview”at />hh852637.aspx
• “VolumeactivationofOfce2013”at />aspx
15WINDOWS TO GO
Managing Windows To Go
YoucanusethesameWindowsmanagementtoolswithwhichyouarealreadyfamiliartomanage
WindowsToGodrives.YoudonotneedtolearnanynewtoolstomanageWindowsToGowithin
yourinstitution.Forexample,youcanmanageWindowsToGoworkspacesbyusing:
• Group Policy See“GroupPolicy”at />aspxformoreinformation.
• Windows Intune See“WindowsIntune”at />aspxformoreinformation.
• System Center 2012 Conguration Manager See“SystemCenterCongurationManager”
at />YoucanalsouseGroupPolicytomanageWindowsToGo,andMicrosoftrecommendsthatyou
createaseparateorganizationalunit(OU)fortheWindowsToGoworkspacesandoneforhost
computers.YoucanusetheOUforWindowsToGoworkspaceto:
• Change settings for the Windows Store
• Changestandbysleepstates
• Changehibernatesettings
YoucanusetheOUforhostcomputerstoprovidegranularcontrolovertheWindowsToGo
StartupOptionssothatonlycertaincomputerswillbeconguredtobootfromtheUSBdrive.
Group Policy settings related to the Windows To Go workspace
ThesettingsinthefollowinglistareparticulartoWindowsToGoworkspaces:
• Allow hibernate (S4) when started from a Windows To Go workspace This policy setting
specieswhetherthePCcanusethehibernationsleepstate(S4)whenstartedfroma
WindowsToGoworkspace.Bydefault,hibernationisdisabledwhenusingWindowsToGo
workspaces,soenablingthissettingexplicitlyturnstheabilitybackon.Whenacomputer
entershibernation,thecontentsofmemoryarewrittentodisk.Whenthediskisresumed,itis
importantthatthehardwareattachedtothesystemaswellasthediskitselfareunchanged.
ThisisinherentlyincompatiblewithroamingbetweenPChosts.Hibernationshouldonlybe
usedwhentheWindowsToGoworkspaceisnotbeingusedtoroambetweenhostPCs.
16WINDOWS TO GO
• Disallow standby sleep states (S1–S3) when starting from
a Windows To Go workspace Thispolicysettingspecies
whetherthePCcanusestandbysleepstates(S1–S3)when
startedfromaWindowsToGoworkspace.Thesleepstatealso
presentsauniquechallengetoWindowsToGousers.When
acomputergoestosleep,itappearsasifitwereshutdown.
ItwouldbeeasyforausertothinkthataWindowsToGo
workspace in sleep mode were actually shut down, and the
usercouldremovetheWindowsToGodriveandtakeithome.
Removing the drive in this scenario is equivalent to an unclean
shutdown, which may result in the loss of unsaved user data or
thecorruptionofthedrive.
Moreover,iftheusernowbootsthedriveonanotherPCand
bringsitbacktotherstPC,whichstillhappenstobeinthe
sleepstate,itwillleadtoanarbitrarycrash,andeventually
corruptionofthedriveresultsintheworkspacebeingunusable.
Ifyouenablethispolicysetting,theWindowsToGoworkspace
cannotusethestandbystatestocausethePCtoentersleep
mode.Ifyoudisableordonotcongurethispolicysetting,the
WindowsToGoworkspacecanplacethePCinsleepmode.
• Allow Store to install apps on Windows To Go
workspaces This policy setting allows or denies access
to the Store application from a Windows To Go workspace
runningWindows8.(Thispolicydoesnotapplytodevices
runningWindows8.1.)Ifyouenablethissetting,accessto
the Store application is allowed from the Windows To Go
workspace.EnablethispolicysettingonlywhentheWindows
ToGoworkspacewillbeusedwithasinglePC.Whenroaming
Windows To Go devices to multiple PCs, installing applications
fromtheWindowsStoreisnotasupportedscenario.However,
sideloaded Windows Store apps can run in Windows To Go
workspacesevenwhenroamedamongmultiplePCs.Ifyou
disableordonotcongurethispolicysetting,accesstothe
Windows Store application is denied on the Windows To Go
workspace.
NOTE
For the host PC to resume
correctlywhenhibernation
isenabled,theWindows
To Go workspace must
continue to use the same
USBport.
17WINDOWS TO GO
Group Policy settings related to the host computer
The Windows To Go Default Startup Options policy setting
controlswhetherthehostcomputerbootstoWindowsToGoifa
USB device containing a Windows To Go workspace is connected and
controls whether users can make changes using the Windows To
Go Startup Options settingsdialogbox.Ifyouenablethispolicy
setting,bootingtoWindowsToGowhenaUSBdeviceisconnected
willbeenabled,anduserswillnotbeabletomakechangesusingthe
Windows To Go Startup Options settingsdialogbox.Ifyoudisable
thispolicysetting,bootingtoWindowsToGowhenaUSBdeviceis
connectedwillnotbeenabledunlessausercongurestheoption
manuallyinthermware.Ifyoudonotcongurethispolicysetting,
userswhoaremembersofthelocalAdministratorsgroupcanenable
ordisablebootingfromUSBbyusingtheWindows To Go Startup
Options settingsdialogbox.
Additionalresources:
• “PrepareYourOrganizationforWindowsToGo”athttp://
technet.microsoft.com/en-us/library/jj592678.aspx
• “DeploymentConsiderationsforWindowsToGo”athttp://
technet.microsoft.com/en-us/library/jj592685.aspx
NOTE
Enablingthispolicy
setting causes PCs running
Windows8.1toattemptto
bootfromanyUSBdevice
that is inserted into the PC
beforeitisstarted.
18WINDOWS TO GO
Storing user data and settings
InatypicalWindowsinstallation,userdataandsettingsarestoredonthecomputer’sinternaldisk.
However,withWindowsToGo,accesstotheinternaldiskisdisabled.Dataandsettingsareinstead
storedwithintheworkspaceitselfontheUSBdrive.Microsoftdoesnotrecommendthisscenario.
TheUSBdrivewiththeWindowsToGoworkspacecontainsnorecoveryoptions;therefore,ifthe
driveislostordamaged,theuserwilllosetheirdataandsettings.Withthisinmind,usersneeda
method to access their data and settings from multiple locations when using the Windows To Go
workspace.
MultipleoptionsareavailableforaccesstodataandsettingsfromwithinaWindowsToGo
workspace.Forexample,UE-VwithFolderRedirectionandOfineFilesisanexcellentwayto
separatedataandsettingsfromtheworkspaceandenablethemtoroam.Thesetechnologies
requirelittleinfrastructureandareveryeasytocongure.
Iftheinfrastructureorexpertiseisnotavailableforthesetechnologies,SkyDriveisalsoanoption.
SkyDrivecanbeusedtosynchronizebothdataandsomeWindows8.1settings(e.g.,Internet
ExplorerFavorites,desktopwallpaper,andsoon)whenloggingontotheWindowsToGo
workspacewithaMicrosoftaccount.
Table3describestheoptionsfordataandsettingstorage.
TABLE 3 Options for Data and Setting Storage in Windows To Go
local storaGe in tHe
windows to Go
workspace
ue-V witH folder
redirection
skydriVe
Conguration
Requires no additional
conguration
Requires agent
installation in the
workspace and Group
Policy infrastructure
Requires minimal
conguration;must
log on with a Microsoft
account for settings to
besynchronized
IT expertise None IT pro End user
Backup None
Usesbackupmethods
already in place in the
infrastructure
Cloud-basedservice
thatisbackedupinthe
datacenter
Data and settings
roaming
None Yes
Yes,aslongasa
Microsoft account is
used
Bandwidth used None Intranet Internet
19WINDOWS TO GO
UE-V with Folder Redirection
UE-V with Folder Redirection provides access to data and settings for a consistent desktop
experiencenomatterwheretheuserlogson.Itistherecommendedmethodforprovidingaccess
todataandsettingswithWindowsToGo,becauseitprovidesthebestcombinationofexibility
andmanageabilityformostinfrastructures.
UE-VwithFolderRedirectionconsistsofseveralcomponentsthatcombinetoprovideaseamless
virtualizedexperience:
• UE-V UE-Vsynchronizesusers’settingswithasimplenetworkleshare.Changesmadeto
Windowsandapplicationsettingswillbesynchronizedwiththeleshareandavailablewhen
userslogontotheirWindowsToGoworkspaceoranydomain-joinedPC.
• Folder Redirection Folder Redirection stores user data and application-related data on a
lesharesothatusercanaccessthedataregardlessoflogonlocation.
• Ofine Files OfineFilesensurethatlesandfoldersareaccessibleevenifthedeviceis
currentlydisconnectedfromthenetwork.ThisincludestheUE-Vsettingsstoreandany
redirectedfolders.ConguringOfineFilesisessentialifstudentsareallowedtotaketheir
WindowsToGoworkspaceshomewiththem.
Cloud storage
CloudstorageisaviableoptionforkeepinguserdatainaWindowsToGodeployment.When
consideringcloudstorage,SkyDriveandOfce365providemanyoptions.
AnyonecanobtainSkyDrivestorage,andMicrosoftprovidesupto7GBofspaceatnocost.Users
canpurchaseadditionalspace,ifnecessary.Visit
formoreinformationonSkyDrive.SkyDriverequiresaMicrosoftaccount,andstudentsunder
theageof13requireparentauthorization.Formoreinformation,seeWindows 8.1 deployment
planning: A guide for education at />Ofce365alsooffersafullversionofOfce,withstorageavailableinthecloud.Thisisaviable
optionifOfcewillbetheprimarytoolusedintheWindowsToGodeployment.Ofce365offers
educationalinstitutionplans,includingafreetierforstudentsandfaculty.
WithSkyDrive,bothdataandsettingscanbestoredinthecloud.Thesesettingscanincludethings
likeInternetExplorerfavorites,desktop,andothersettings.IfSkyDriveisdisabledthroughGroup
Policy,itwouldalsobedisabledforbothdataandsettingsstorage.However,ifyoucreateanew
OUfortheWindowsToGodrives,thenSkyDrivecouldbeenabledforthatOUspecically.
20WINDOWS TO GO
Additionalresources:
• Windows User State Virtualization at />aspx
• “UserExperienceVirtualization”at />aspx
• SkyDrivewebsiteat />• “Ofce365Deployment”at />• “SecurityandDataProtectionConsiderationsforWindowsToGo”atrosoft.
com/en-us/library/jj592679.aspx
• “SupportingInformationWorkerswithReliableFileServicesandStorage”athttp://technet.
microsoft.com/en-us/library/hh831495
• “FolderRedirection,OfineFiles,andRoamingUserProlesOverview”athttp://technet.
microsoft.com/library/hh848267
• “OverviewofuserandroamingsettingsforOfce2013”at />us/library/jj733593.aspx
21WINDOWS TO GO
Conguring Windows To Go for remote access
Enablinguserstoaccessnetworkresourcesfromoff-campuslocationssuchasathomeisan
importantaspectoftheWindowsToGousagescenario.Toprovideaccesstonetworkresources,
youmightdeployaremoteaccesssolution.WindowsToGocanusesuchalready-supported
remoteaccesssolutionsas:
• DirectAccess DirectAccessprovidesanadvancedremoteaccesssolutionthatenablesbuilt-
insecurity,monitoring,andintegrationwithotherMicrosoftenterpriseservices.
• Traditional VPN-based solution AVPNisalsosupportedasameanstoenableremote
accessfromWindowsToGo.Windows8.1addssupportforawidervarietyofVPNclients.
• Auto-triggered VPN UseanapporresourcethatneedsaccessthroughtheinboxVPN(e.g.,
acompany’sintranetsite)andWindows8.1automaticallypromptstosigninwithoneclick.
ThisfeatureisavailablewithMicrosoftandthird-partyinboxVPNclients.
Seethesection“CongureWindowsToGoworkspaceforremoteaccess”intheDeploy Windows
To Go in Your Organization guide at for
moreinformation,includingWindowsPowerShellscriptsrelatedtotheremoteaccessdeployment.
Additionalresources:
• “RemoteAccess(DirectAccess,RoutingandRemoteAccess)Overview”athttp://technet.
microsoft.com/library/hh831416
• “DeployWindowsToGoinYourOrganization”at />jj721578.aspx
• Ofine Domain Join (Djoin.exe) Step-by-Step Guide at />library/dd392267(WS.10).aspx
• “What’sNewinRemoteAccessinWindowsServer2012R2”at />en-us/library/dn383589.aspx
22WINDOWS TO GO
Securing Windows To Go drives
AkeysecurityconsiderationforWindowsToGodeploymentistheuseofBitLocker.BitLockerhelps
toprotectthedatawithintheworkspaceiftheUSBdriveislost.UsingBitLockercanhelpprotect
students’securityandprivacyintheeventofalostWindowsToGoworkspace.
Asdescribedearlier,BitLockerinaWindowsToGoworkspacedoesnotusetheTPM.Theuser
insteadispromptedforapasswordtounlockthedrive.Youcancontrolthepasswordpolicy
throughGroupPolicy;bydefault,passwordsareeightcharactersinlength.
Whenrstinsertedintotheprovisioningcomputer,theUSBdrivetobeusedfortheworkspace
isconsideredanormalremovabledatadrive.Thedrivemusthaveoneormorevolumesalready
dened.Inaddition,youmayneedtochangeGroupPolicysettingsrelatedtoBitLockertouse
theWindowsToGoCreatorWizardwithBitLocker.Thesepolicies,whicharefoundinComputer
Conguration\Policies\AdministrativeTemplates\WindowsComponents\BitLockerDrive
Encryption,include:
• Control use of BitLocker on removable drives ControlswhetherBitLockercanbeusedon
removabledrives.Thispolicymustbeenabled.
• Congure use of smart cards on removable data drives Ifthispolicyisenabled,signin
withyoursmartcardpriortobeginningtheWindowsToGoCreatorWizard.
• Congure use of passwords for removable data drives The computer on which you run
theWindowsToGoCreatorWizardmustbeabletoconnecttoadomaincontrollerwhenthis
setting, along with the Require password complexityoption,areenabled.
• Require additional authentication at startup This setting, which you must also change,
enablestheuseofpasswordswithanoperatingsystemdrivesothatBitLockercanbe
conguredwithintheworkspace.EnablethesettingbyselectingtheAllow BitLocker
without a compatible TPMoption.
AnoptionthatenableseasiermanagementofBitLockerisMicrosoftBitLockerAdministrationand
Monitoring(MBAM).MBAM,whichispartoftheMicrosoftDesktopOptimizationPack,isavailable
withMicrosoftSoftwareAssurancelicensing.Visit />enterprise/products-and-technologies/mdop/mbam.aspxformoreinformationonMBAM.