Set an organization policy in the dashboard
Use the TwinPane dashboard to set one policy for every Client and Server: allowed file types, maximum file size, Defender scan, Mirror Mode, network drives and folder access.
An organization policy is one set of rules for every TwinPane Client and Server in your organization. When the policy is enforced, devices use its settings and users can't change them.
The video shows the dashboard and TwinPane 1.0.53. The Windows desktops in it are illustrations.
Before you start
- Sign in to the TwinPane dashboard with the account that owns your organization's license.
- Devices need TwinPane 1.0.45 or later to follow a policy. Older devices show Update TwinPane to apply.
Read the video transcript
0:00 — Sign in and click Policy
Sign in to the TwinPane dashboard and click Policy in the sidebar. A new policy is not enforced until you switch it on.
0:07 — Switch the policy on, then set each rule
Switch on the policy, then set allowed file types, maximum file size, Defender scan, Mirror Mode, network drive sharing and folder access.
0:20 — Click Save policy, then watch devices pick it up
Click Save policy. Each device card shows when it will apply the policy, and changes to Policy applied once it has.
0:30 — Managed settings are locked for users
On each PC and session host, TwinPane shows that your organization manages its settings, and those switches can't be changed.
0:39 — Users see why a file was blocked
If a user opens a file type you didn't allow, or a file larger than your limit, their PC shows File type blocked or File too large.
Step 1: Open Policy
In the dashboard sidebar, click Policy. A new policy is not enforced until you switch it on.
Step 2: Switch the policy on
At the top of the policy card, switch on the policy. The card changes to Policy enforced.
While the policy is off, each device uses its own local settings. You can still edit the rules and save them.
Step 3: Set the rules
- Allowed file types: other file types are blocked. Click Add and type a file type such as
.vsdx. Separate several with spaces or commas; the dot is added for you. Click × on a file type to remove it. At least one file type is required. The defaults are.doc,.docx,.xlsx,.xls,.ppt,.pptx,.pdf,.txt,.csv,.png,.jpgand.jpeg. - Maximum file size: from 1 to 50 MB. Larger files are blocked.
- Microsoft Defender scan: when Required, files are scanned before they open on the user's PC, and users can't turn the scan off.
- Mirror Mode: maps the user's PC folders into the remote session. See Save to your PC from a remote app.
- Network drive sharing: lets sessions reach network drives mapped on the user's PC.
- Folder access: All drives lets sessions open files from any drive on the user's PC. User folders only allows only Desktop, Documents, Downloads, Pictures, Music and Videos.
Step 4: Save the policy
Click Save policy in the bar at the bottom of the page. The dashboard confirms Policy saved. Devices pick it up at their next license check.
Discard undoes changes you haven't saved yet.
Step 5: Check that devices pick it up
The device panel next to the policy lists your session hosts and user PCs. Each card shows its status:
- Policy applied: the device uses the policy.
- Applies by a date: the device picks up the policy at its next license check, by that date.
- Applies at next check: the device picks it up the next time it checks its license.
- Using local settings: the policy is switched off, and the device uses its own settings.
- Update TwinPane to apply: the device runs a version older than 1.0.45.
Devices get the policy with their license check, within 7 days. Session hosts get it each time TwinPane Server connects.
What users see
- A notice in TwinPane: Your organization manages some TwinPane settings on this PC (or on this server).
- Locked switches marked Managed by your organization or Required by your organization.
- A notification, Organization policy applied, listing what changed.
When a rule blocks a file, the user's PC shows why:
- File type blocked: the file isn't one of the allowed file types.
- File too large: the file is larger than your maximum file size.
- Location blocked: the session tried to open a file outside the user folders while User folders only is set.
Change or stop the policy
To change the policy, edit the rules and click Save policy again. Devices pick up the change at their next license check.
To stop managing devices, switch the policy off and save. Devices show Using local settings and go back to their own settings at their next check.
Policy and local settings
While the policy is enforced, it overrides the matching local settings on each device, including defaults set through the registry or Group Policy. It doesn't change those local settings. When you switch the policy off, they apply again. See Group Policy rollout for registry defaults.