Shared Windows workstations can accumulate user-initiated changes over time, causing them to drift from their intended configuration and from one another. This configuration drift can affect consistency across a shared workstation environment.
Reimaging restores a workstation to a standard system image, but requires it to be taken out of service while the image is rebuilt. Once the workstation returns to use, configuration drift can begin again. Read on as we explore five methods for maintaining consistent Windows workstations without resorting to reimaging.
5 Methods for Maintaining Consistent Windows Endpoints
The five methods below maintain consistency across shared Windows workstations without reimaging. For each one, we explain how it works and how Faronics solutions support it.
-
Reboot-to-Restore
Reboot-to-Restore software returns a workstation to an administrator-defined baseline every time it restarts. Anything a user installs, changes, or saves on a protected drive is discarded at the next restart. You can undo an unwanted change with a simple restart, not a whole rebuild.
Deep Freeze applies Reboot-to-Restore at the disk level. It redirects data written to a protected drive to a separate allocation table, leaving the original data intact. On restart, Deep Freeze stops referencing the redirected data, returning the system to its original state.
Each workstation is either Frozen or Thawed:
- Frozen: The workstation is protected, and changes are discarded at restart.
- Thawed: Changes persist across restarts, allowing administrators to install software or change settings permanently.
Deep Freeze can also restart workstations at log-off, so each new user starts from the baseline.
-
Centralized Configuration Enforcement
Centralized configuration enforcement applies settings defined in a central management system to workstations in a group and reapplies them on a schedule to reverse local changes. On Windows, this can be managed through Group Policy or mobile device management. Administrators can update the standard by modifying the applicable policy.
Deep Freeze Cloud, Faronics’ cloud-based management console, manages settings through policies. Each group can have an enforced policy, which applies to every computer in it, including computers added later. Managed computers check in with the console at a set interval to pick up policy changes. A policy can include WINSelect, which restricts what users can change on the workstation, such as by disabling Task Manager or hiding Control Panel applets.
-
Scheduled Maintenance Windows
A maintenance window is a recurring period for updates and other planned changes, scheduled when workstations are not in use. Workstations updated in the same window receive each new configuration together. With updates installed in place, the baseline can remain current without building a new image.
On Frozen workstations, approved changes are made permanent during the maintenance window. Deep Freeze handles this through scheduled Workstation Tasks.
A Windows Update task runs as follows:
- With caching enabled, updates download ahead of time, even while the workstation is Frozen.
- At the scheduled time, the workstation restarts, thaws and installs the updates.
- When the update process completes, the workstation returns to a Frozen state with the updates now part of its baseline.
Batch File and Thawed Period tasks follow the same pattern for running scripts and installing software.
-
Application Allowlisting
Application allowlisting (also called whitelisting) permits only approved applications to run and blocks all others by default. A program a user downloads or installs cannot run unless it has been approved. The software permitted to run on a workstation therefore remains consistent across users. Unwanted software is blocked at launch.
Anti-Executable provides allowlisting for Windows workstations. During installation, it can scan the system and approve existing executable files, allowing the baseline software to run immediately. New software can be approved through Maintenance Mode, which adds new or modified executables to the approved list. Anti-Executable can also switch to Maintenance Mode when Deep Freeze runs a maintenance task, automatically approving software installed or updated during the task.
-
Drift Detection
Drift detection compares each workstation’s current configuration with its baseline and reports any differences. Identifying which workstation has drifted and how allows an administrator to correct the specific change without reimaging the entire machine. It also shows whether the other methods are working as intended.
Changes on a Frozen workstation do not survive a restart. A workstation can still drift from its group if it remains Thawed or misses a scheduled update. Deep Freeze reports which workstations are Frozen or Thawed, and how long they have been Thawed. Deep Freeze Cloud can also alert administrators when a computer remains Thawed beyond a defined period. Its Workstation Task Summary report shows the status of each computer’s scheduled tasks, helping identify missed updates.
Discover Deep Freeze
Deep Freeze keeps shared Windows workstations consistent by restoring their baseline configuration at every restart. Scheduled maintenance tasks allow IT teams to update the baseline without reimaging, reducing downtime and administrative effort.




