← Return to topic

F3 users need to edit files on an on-prem SMB share. SharePoint migration not an option yet. any ideas?

fuerza31 · 7 Sep 2026 at 14:30 · permalink

Setting up a shared (multi-user) Entra-joined Windows laptop for healthcare staff (nurses mainly, no doctors) using Autopilot Self-Deploying mode.

No hybrid join, no AD computer object, but on-prem SSO to our file server works fine (hybrid identities, Kerberos/NTLM via the standard "SSO to on-premises resources" mechanism).

Licensing is a mix of F3 and E3 users on the same device. We're using Shared Computer Activation for Microsoft 365 Apps so desktop Office works fine for E3 users, and pointing F3 users to Office for the web (Outlook/Word/Excel Online) via forced Edge webapp installs.

NOW, our issue: our healthcare content isn't in SharePoint/OneDrive yet (separate migration project, not happening soon). F3 users can browse and copy files from the on-prem share fine through Explorer, but Office for the web obviously can't open/edit anything directly from a local/network drive only from SharePoint/OneDrive.

Options I'm aware of so far:

1. Migrate the content to SharePoint (the "real" fix, but a separate project, not happening in the short term)
2. Device-activated Office LTSC via KMS, so it's independent of the signed-in user's license (also on hold also no KMS infra ready yet)
3. Third-party gateway products (e.g. MyWorkDrive) that let Office Online edit files that physically stay on an on-prem file share

Has anyone actually solved this in production? I'm open for suggestions.

Flyingeagle3 · 7 Sep 2026 at 15:01 · permalink

office for the web can't open on-prem smb paths. ltsc on the laptop edits the share like a normal mapped drive.

pengshilong · 7 Sep 2026 at 16:19 · permalink

4. Office LTSC Professional Plus 2024 MAK non-KMS

5. Upgrade F3 users

chroniclesofdoom · 7 Sep 2026 at 16:46 · permalink

6. OpenOffice / LibreOffice / whatever open source flavour is out there now

fuerza31 · 7 Sep 2026 at 16:55 · permalink

Yeah upgrading is easy but alas as a city, money is a sensitive case with politicians :-)

Breakerzote · 7 Sep 2026 at 18:04 · permalink

M365 apps for enterprise standalone license on the user

Atanti-ql-Paneu · 7 Sep 2026 at 18:25 · permalink

u/pelazas1 has it. Office for the web can only open what lives in SharePoint, OneDrive or Teams, so a UNC path is never going to work no matter how you launch Edge.

One catch on the LTSC route though. F3 carries no desktop Office rights at all, so LTSC is a separate perpetual purchase per device and nothing in the F3 SKU covers it. Same reason your Shared Computer Activation setup only helps the E3 users, SCA only comes with Microsoft 365 Apps for enterprise and Business Premium. Its documented at https://learn.microsoft.com/en-us/deployoffice/overview-shared-computer-activation

So you would be running LTSC and Click-to-Run on the same shared laptop, and I am pretty sure those two do not coexist cleanly. Its been a while since I tried it, so double check on that before you buy anything.

If it were us we would pull just that one content library into SharePoint ahead of the big migration instead. One site, one library, and the F3 problem disappears without a license purchase you have to unwind in a year.

Can go deeper on the shared-device Autopilot piece if it helps.

JuneWanwimol · 7 Sep 2026 at 18:28 · permalink

They should have thought of that before taking away people's ability to do their job.

fuerza31 · 7 Sep 2026 at 18:38 · permalink

…. what? the reason this is happening is because WE are replacing old win10 AD devices with Entra/Autopilot ones…

ykhnlmwlp · 7 Sep 2026 at 19:28 · permalink

Youve hit a product boundary rather than an SMB or Entra problem: browser Office cannot edit a UNC path, so more mapped-drive or SSO tuning won’t change that. For a bridge, either give the affected users a properly licensed desktop Office path, or move only the active library ahead of the wider migration. I’d be cautious with a write-through gateway for healthcare data—test locking, coauthoring, versioning, audit logs, offline behavior, and recovery before production. Until one path is validated, keeping the SMB share read-only for web-only users is safer.

Jok3rJB · 7 Sep 2026 at 20:18 · permalink

Spend the $$$, that is your solution

Or take work arounds like open office

ilyakot · 8 Sep 2026 at 00:28 · permalink

We had (still have to some degree) the same issue with our clinical staff.

The solution for us was buying/licensing Microsoft Apps add-on for F3 for some of the clinical users to give them rights to the core thick apps minus Outlook.

Timohah · 8 Sep 2026 at 00:29 · permalink

IT management should have thought about how people would do their jobs before going from AD to Entra-only. There is nothing stopping you going to Win 11 AD/Entra-hybrid except your own planning.