The configuration should be saved on the SaveServer.
We don't want everyone to be forced to use the same settings(Or do we?). There should be a default set of settings but users should be able to edit the settings to their liking as well. All of this should be stored on the SaveServer. The default set should be the admin's settings.
There should be some sort of system in place for the storage of sensitive information like passwords which I imagine should be stored in an encrypted fashion with the respective user's password. The default set should not include this information.