From 1eb19fd0e839671ee15dc69b40395ba2e2dc605e Mon Sep 17 00:00:00 2001 From: Jan Kulbe Date: Tue, 15 Jan 2019 18:59:23 +0100 Subject: [PATCH 1/8] Update upgrading-to-mbam-25-sp1-from-mbam-25.md updated article and links to point to the July 2018 hotfix release. Some minor language revisions. --- .../upgrading-to-mbam-25-sp1-from-mbam-25.md | 27 +++++++++++-------- 1 file changed, 16 insertions(+), 11 deletions(-) diff --git a/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md index f650f130b3..a73852f3e2 100644 --- a/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md +++ b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md @@ -13,32 +13,37 @@ ms.date: 2/16/2018 # Upgrading to MBAM 2.5 SP1 from MBAM 2.5 This topic describes the process for upgrading the Microsoft BitLocker Administration and Monitoring (MBAM) Server 2.5 and the MBAM Client from 2.5 to MBAM 2.5 SP1. -### Before you begin, download the September 2017 servicing release -[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=56126) +### Before you begin +#### Download the July 2018 servicing release +[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=57157) +#### Verify the installation documentaion +Verify you have a current documentation of your MBAM environment, including all server names, database names, service accounts and their passwords. + +### Upgrade steps #### Steps to upgrade the MBAM Database (SQL Server) -1. Using the MBAM Configurator; remove the Reports roll from the SQL server, or wherever the SSRS database is housed (Could be on the same server or different one, depending on your environment) +1. Using the MBAM Configurator; remove the Reports role from the SQL server, or wherever the SSRS database is hosted. Depending on your environment, this can be the same server or a separate one. Note: You will not see an option to remove the Databases; this is expected.   2. Install 2.5 SP1 (Located with MDOP - Microsoft Desktop Optimization Pack 2015 from the Volume Licensing Service Center site: 3. Do not configure it at this time  -4. Install the September Rollup: https://www.microsoft.com/en-us/download/details.aspx?id=56126 -5. Using the MBAM Configurator; re-add the Reports rollup +4. Install the July 2018 Rollup: https://www.microsoft.com/en-us/download/details.aspx?id=57157 +5. Using the MBAM Configurator; re-add the Reports role 6. This will configure the SSRS connection using the latest MBAM code from the rollup  -7. Using the MBAM Configurator; re-add the SQL Database roll on the SQL Server. -- At the end, you will be warned that the DBs already exist and weren’t created, but this is  expected. +7. Using the MBAM Configurator; re-add the SQL Database role on the SQL Server. +- At the end, you will be warned that the DBs already exist and weren’t created, but this is expected. - This process updates the existing databases to the current version being installed       #### Steps to upgrade the MBAM Server (Running MBAM and IIS) 1. Using the MBAM Configurator; remove the Admin and Self Service Portals from the IIS server 2. Install MBAM 2.5 SP1 3. Do not configure it at this time   -4. Install the September 2017 Rollup on the IIS server(https://www.microsoft.com/en-us/download/details.aspx?id=56126) +4. Install the July 2018 Rollup on the IIS server(https://www.microsoft.com/en-us/download/details.aspx?id=57157) 5. Using the MBAM Configurator; re-add the Admin and Self Service Portals to the IIS server  -6. This will configure the sites using the latest MBAM code from the June Rollup +6. This will configure the sites using the latest MBAM code from the July 2018 Rollup - Open an elevated command prompt, Type: **IISRESET** and Hit Enter. #### Steps to upgrade the MBAM Clients/Endpoints 1. Uninstall the 2.5 Agent from client endpoints 2. Install the 2.5 SP1 Agent on the client endpoints -3. Push out the September Rollup Client update to clients running the 2.5 SP1 Agent  -4. There is no need to uninstall existing client prior to installing the September Rollup.   +3. Push out the July 2018 Rollup Client update to clients running the 2.5 SP1 Agent  +4. There is no need to uninstall the existing client prior to installing the July 2018 Rollup.   From ba387a0646baf033ac567247669566e35a369e29 Mon Sep 17 00:00:00 2001 From: Still Hsu Date: Wed, 16 Jan 2019 06:30:13 +0800 Subject: [PATCH 2/8] Fix DFM notes and warnings on article --- .../create-a-windows-10-reference-image.md | 22 +++++++++---------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/windows/deployment/deploy-windows-mdt/create-a-windows-10-reference-image.md b/windows/deployment/deploy-windows-mdt/create-a-windows-10-reference-image.md index 3e14e9d06e..29c8f9e1d9 100644 --- a/windows/deployment/deploy-windows-mdt/create-a-windows-10-reference-image.md +++ b/windows/deployment/deploy-windows-mdt/create-a-windows-10-reference-image.md @@ -76,7 +76,7 @@ This section will show you how to populate the MDT deployment share with the Win MDT supports adding both full source Windows 10 DVDs (ISOs) and custom images that you have created. In this case, you create a reference image, so you add the full source setup files from Microsoft. ->[!OTE]   +>[!NOTE]   >Due to the Windows limits on path length, we are purposely keeping the operating system destination directory short, using the folder name W10EX64RTM rather than a more descriptive name like Windows 10 Enterprise x64 RTM.   ### Add Windows 10 Enterprise x64 (full source) @@ -134,8 +134,8 @@ You also can customize the Office installation using a Config.xml file. But we r Figure 5. The Install - Microsoft Office 2013 Pro Plus - x86 application properties. - **Note**   - If you don't see the Office Products tab, verify that you are using a volume license version of Office. If you are deploying Office 365, you need to download the Admin folder from Microsoft. + >[!NOTE]  + >If you don't see the Office Products tab, verify that you are using a volume license version of Office. If you are deploying Office 365, you need to download the Admin folder from Microsoft.   3. In the Office Customization Tool dialog box, select the Create a new Setup customization file for the following product option, select the Microsoft Office Professional Plus 2013 (32-bit) product, and click OK. 4. Use the following settings to configure the Office 2013 setup to be fully unattended: @@ -156,8 +156,8 @@ You also can customize the Office installation using a Config.xml file. But we r - In the **Microsoft Office 2013** node, expand **Privacy**, select **Trust Center**, and enable the Disable Opt-in Wizard on first run setting. 5. From the **File** menu, select **Save**, and save the configuration as 0\_Office2013ProPlusx86.msp in the **E:\\MDTBuildLab\\Applications\\Install - Microsoft Office 2013 Pro Plus - x86\\Updates** folder. - **Note**   - The reason for naming the file with a 0 (zero) at the beginning is that the Updates folder also handles Microsoft Office updates, and they are installed in alphabetical order. The Office 2013 setup works best if the customization file is installed before any updates. + >[!NOTE]  + >The reason for naming the file with a 0 (zero) at the beginning is that the Updates folder also handles Microsoft Office updates, and they are installed in alphabetical order. The Office 2013 setup works best if the customization file is installed before any updates.   6. Close the Office Customization Tool, click Yes in the dialog box, and in the **Install - Microsoft Office 2013 Pro Plus - x86 Properties** window, click **OK**. @@ -333,8 +333,8 @@ The steps below walk you through the process of editing the Windows 10 referenc 2. Select the operating system for which roles are to be installed: Windows 10 3. Select the roles and features that should be installed: .NET Framework 3.5 (includes .NET 2.0 and 3.0) - **Important**   - This is probably the most important step when creating a reference image. Many applications need the .NET Framework, and we strongly recommend having it available in the image. The one thing that makes this different from other components is that .NET Framework 3.5.1 is not included in the WIM file. It is installed from the **Sources\\SxS** folder on the media, and that makes it more difficult to add after the image has been deployed. + >[!IMPORTANT] + >This is probably the most important step when creating a reference image. Many applications need the .NET Framework, and we strongly recommend having it available in the image. The one thing that makes this different from other components is that .NET Framework 3.5.1 is not included in the WIM file. It is installed from the **Sources\\SxS** folder on the media, and that makes it more difficult to add after the image has been deployed.   ![figure 7](../images/fig8-cust-tasks.png) @@ -456,8 +456,8 @@ For that reason, add only a minimal set of rules to Bootstrap.ini, such as which Figure 12. The boot image rules for the MDT Build Lab deployment share. - **Note**   - For security reasons, you normally don't add the password to the Bootstrap.ini file; however, because this deployment share is for creating reference image builds only, and should not be published to the production network, it is acceptable to do so in this situation. + >[!NOTE]   + >For security reasons, you normally don't add the password to the Bootstrap.ini file; however, because this deployment share is for creating reference image builds only, and should not be published to the production network, it is acceptable to do so in this situation.   4. In the **Windows PE** tab, in the **Platform** drop-down list, select **x86**. 5. In the **Lite Touch Boot Image Settings** area, configure the following settings: @@ -514,8 +514,8 @@ So, what are these settings? - **DeployRoot.** This is the location of the deployment share. Normally, this value is set by MDT, but you need to update the DeployRoot value if you move to another server or other share. If you don't specify a value, the Windows Deployment Wizard prompts you for a location. - **UserDomain, UserID, and UserPassword.** These values are used for automatic log on to the deployment share. Again, if they are not specified, the wizard prompts you. - **Note**   - Caution is advised. These values are stored in clear text on the boot image. Use them only for the MDT Build Lab deployment share and not for the MDT Production deployment share that you learn to create in the next topic. + >[!WARNING]   + >Caution is advised. These values are stored in clear text on the boot image. Use them only for the MDT Build Lab deployment share and not for the MDT Production deployment share that you learn to create in the next topic.   - **SkipBDDWelcome.** Even if it is nice to be welcomed every time we start a deployment, we prefer to skip the initial welcome page of the Windows Deployment Wizard. From 11b06a386e339e8ec8f50fecbe2418ca7ee7b9ae Mon Sep 17 00:00:00 2001 From: keithlab86 <42138435+keithlab86@users.noreply.github.com> Date: Wed, 16 Jan 2019 21:07:56 +0000 Subject: [PATCH 3/8] Update deploy-m365.md Spelling mistake on Line 62 - [Modern Destop Deployment Center](https://docs.microsoft.com/microsoft-365/enterprise/desktop-deployment-center-home) Proposed change to amend spelling to "Desktop" --- windows/deployment/deploy-m365.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/deploy-m365.md b/windows/deployment/deploy-m365.md index 125eee189b..e0c769d5e0 100644 --- a/windows/deployment/deploy-m365.md +++ b/windows/deployment/deploy-m365.md @@ -59,7 +59,7 @@ Examples of these two deployment advisors are shown below. ## Related Topics [Windows 10 deployment scenarios](windows-10-deployment-scenarios.md)
-[Modern Destop Deployment Center](https://docs.microsoft.com/microsoft-365/enterprise/desktop-deployment-center-home) +[Modern Desktop Deployment Center](https://docs.microsoft.com/microsoft-365/enterprise/desktop-deployment-center-home) From f92bbff5ee402b00ac746e1d421f3cc3d2a6f72b Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 17 Jan 2019 18:29:44 +0000 Subject: [PATCH 4/8] Merged PR 13833: Update bitlocker / Autopilot info Some edits and additions --- .../deployment/windows-autopilot/bitlocker.md | 23 +++++++++++------- .../images/bitlocker-encryption.png | Bin 14308 -> 23629 bytes .../whats-new-windows-10-version-1809.md | 6 ++--- 3 files changed, 17 insertions(+), 12 deletions(-) diff --git a/windows/deployment/windows-autopilot/bitlocker.md b/windows/deployment/windows-autopilot/bitlocker.md index f530d66f35..ae47150794 100644 --- a/windows/deployment/windows-autopilot/bitlocker.md +++ b/windows/deployment/windows-autopilot/bitlocker.md @@ -18,23 +18,28 @@ With Windows Autopilot, you can configure the BitLocker encryption settings to b The BitLocker encryption algorithm is used when BitLocker is first enabled, and sets the strength to which full volume encryption should occur. Available encryption algorithms are: AES-CBC 128-bit, AES-CBC 256-bit, XTS-AES 128-bit or XTS-AES 256-bit encryption. The default value is XTS-AES 128-bit encryption. See [BitLocker CSP](https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp) for information about the recommended encryption algorithms to use. -An example of encryption settings is shown below. - - ![BitLocker encryption settings](images/bitlocker-encryption.png) - -Note that a device which is encrypted automatically will need to be decrypted prior to changing the encyption algorithm. - To ensure the desired BitLocker encryption algorithm is set before automatic encryption occurs for Autopilot devices: 1. Configure the [encryption method settings](https://docs.microsoft.com/intune/endpoint-protection-windows-10#windows-encryption) in the Windows 10 Endpoint Protection profile to the desired encryption algorithm. 2. [Assign the policy](https://docs.microsoft.com/intune/device-profile-assign) to your Autopilot device group. - **IMPORTANT**: The encryption policy must be assigned to **devices** in the group, not users. -3. Enable the Autopilot [Enrollment Status Page](https://docs.microsoft.com/windows/deployment/windows-autopilot/enrollment-status) (ESP) for these devices. This is a critical step because if the ESP is not enabled, the policy will not apply when the device boots. - +3. Enable the Autopilot [Enrollment Status Page](https://docs.microsoft.com/windows/deployment/windows-autopilot/enrollment-status) (ESP) for these devices. + - **IMPORTANT**: If the ESP is not enabled, the policy will not apply before encryption starts. + +An example of Microsoft Intune Windows Encryption settings is shown below. + + ![BitLocker encryption settings](images/bitlocker-encryption.png) + +Note that a device which is encrypted automatically will need to be decrypted prior to changing the encyption algorithm. + +The settings are available under Device Configuration -> Profiles -> Create profile -> Platform = Windows 10 and later, Profile type = Endpoint protection -> Configure -> Windows Encryption -> BitLocker base settings, Configure encryption methods = Enable. + +Note: It is also recommended to set Windows Encryption -> Windows Settings -> Encrypt = **Require**. + ## Requirements Windows 10, version 1809 or later. ## See also -[Bitlocker overview](https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview) +[Bitlocker overview](https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview) \ No newline at end of file diff --git a/windows/deployment/windows-autopilot/images/bitlocker-encryption.png b/windows/deployment/windows-autopilot/images/bitlocker-encryption.png index f2766e12d2415d8a70a8443f9b858ae51b6f924f..96e2d94fb39c82c9dbf3cf9958b045c1a35cf4d8 100644 GIT binary patch literal 23629 zcmc$`2T)UA*Z+$J6{&&ROzRWP2oSd`IK6~%8_gbIzT|_HOv7sa+syCFW{+8WO68B6(4@@31Qe1oYd7A@ zIpW&dig=Vrr60NjVdk=hZ)|pQ|uu7nrq$_|=J2-(lu zwlL-fA4`=nMzUPo$(1r+zvZwRPMWyayaj>N0`eXH*EckO`;w98|F7~LJz#GoesVlf z(s$3N-^SN4)ZJY7**c2Xy$JqYps&c?NzA)(#WQ(btLX~Iz8kEQlGwmyyFpGTF+pe1 z$ZXwPk8_>omAxV}-{p$(`fU=wef{&fi?VL(_t#y3M>UVJO?xQW%`pUMQ_BXI)VSHO zHsw}3y=VY&lYkC(=9_ zUi$L4wC-~edZoQx9a!4vXw87>Y$l37)kb)kkrRw?UuE4T=`TBinCWqb0V5Nuf~)-_ zCN`|v*|JAd-v7EwjB@;KvC^1KV}tm!Pc+=c?yr*adLnVc#`FNr(bd2z_Uu99*znc; zsMoq-34^*WEa|E&E-@^VA|+}Q2NH=dG$Wq{7uaXlLJ1pI z83XBUDBr?{$#CvSCW}{mzIv=@fd`oPq5J z#oJcZJjWP?GZ2sCGG59Udy3jR)fFI4>F2H#=GbKuZUgS&D6#0PHo8$X7%r2@C|MZ1 zos7@edz#xPK5^PubT8aN1?5vXVbm?l6WSt~6>ZvTku~!Q6E}zMFq`^d<=ro_87DQPUO+r6_Esdz z!-suqUnH&)SN+#{l>b`%$^IwG*w~{}y@Vgn^D2!l7P{Ao2wellE0T(BHM7Q~7t6b9 zr;LUz#n@G{$q)ME z+VG-%4K!X-F*d*ndFa5Nt~ZSWO7Si^{z@C!t8;ra%1UDK{ofU**aEu|-7+`sCO@UV zmjmy3(=O$2$iGiziWRbBRzYpLR@x#a`>O_kYZa|$fk)kXA!3Y>LT{3?-v6v4nuS&( zIsF`vK@FKt*Bz<{<19jcIRuI z4_`NGjhG6%$lzqW@!tKxny>{xkbKLXn~vdwWpbp^WUkpZTt*H`Pjp+B5Ns)>+4lSuFsw zfS9Ukws3(zTZ=?00yZ1joFsU2Zpp_xS^t51W0aS#SKADTq?RJh;NtAg=PZ8ZOh1Wh zU)6VxpmhZD?atrjribLKz<-W_0N8FmCMs91yh~$9ZYA+ql+ni+jo9QnJcY(>@k`## znJgz&>Vb-VUEKGd>KWOA`yxsPTwd1VpLc=G@Q!O+s$Zi zck6M4vF`mqE3r>d3dP1?On}3T5B*pU#-0+E1ygztFrp@c3vK#Q$oTLQr{MQv9ZifC zEx6T-b*o`jz<(jdq{RE#wbw>weEcu0{i_ms?Dy==&kGFZRLp?y?41=bo1+hs|)^xSAv%|2%Z}beA)t{e4BF%_0a~G+mT|rW(5k{=~t%ovtmz|Et@Ccg}K; z&o3Rzxfac0(fUB}!&{IZnL!mGap>238fyAcm|DCukK~so27a*iyRMbp*3`OPFO#g! z05*S#vp8@r>^cXSX#2_WywJ^(Szv?g>-)z4Ge1bG@L}off zM!ikS*I`>_;mOFPSiu2--8srmDjllUCcekpPh&N?znnb~1TTXK`8*#wl*o5Q?8pfs zgfGfe9H%=6CDd;VFtkXw&~mSQZ~gnJyz^r&9EP|YbmV@0D&QOPZlF95DPZdg?!_QWJPJg>rOl&K(z`oFL8(kY{xn_X0;w*BHm@vg@#M4TA zdPOi)NLgqamzH{7dO5M`+8n=Ph{5Ie5dqV87~gksEPE_ig1dRlrUsp4u77X17U=gyB|cc@+uz%nbG~l>c}-b2f@Z9)%lTVXLszkinH7pz8C65un)(ASxVjbo zI_Eo_-i1p!3556x@y_vSDWZI z($%+?x2(O=g5{FfZFhi(J39Wq_Q;{atAn4$N-jK$?_I=E4|}nypvL#-ldi-8xI(<`YyJO`k_(gBy645{ z`m9Fa!ku|2X09=RpLxuEG+pT*`#`dr-S^65zl`^di)M2D3L=_5B5-+6_ zQT4f;G2jR!h5ra%^?RSyOig-st^4x`8<_~dI<*ZpQ!e1QRVd+LGZ}W8-*~#)JDu9H z&qMTFi+$){|Lpj8Z35uK6+YLJ< zMr*gg8sW?LlqvKMWB06_Tt}`8&euG+A!RjuN25FR4oG3|a;R0jMP#_0`obb-%`@GT zj}G3Ak932r+9$Th?`YOo?pxvD$S>1s4|WL#y<_$EU$)KRoXvlwdMP09hsnlnE06J60d4_B@rS-lQG;#;cw;0hy=Gu zD@(5qdb7a~Rz%lvq+TR=j=cC0NyIyy-O{n8Rzl$Jr{g)+esIi&%n^aX+JE+ZW3)P< z(IRAds(YXo?$$H9h=5MR40f=X>;oF9uEgZi_^8 z+k8q!uYxNF0{gUQ-SX$Yf?_m0)dAI~>kD{pCYH0@|L%?~F6Igz7LZu$1(TyiBYJ)sPew&XICt0hCy zdcOCsorTJor80l%LiDSYZH*}FZp`AM9B|eqJ4YU4k!tLaXIYKM^D#dINT|r6SQF7m z7DXC>RQ=XiK4sz%xw0-b$9PwmUiZtp2|pzg%kS&g(A5AoX#gBMJ@#q~;M_bg&q{cW z^n>KDd9cl^-DAh%!l5gs)lg?Lav3RKahsM$ic463$9Yj3G>8{sFkA5O!+|}ZjZJ*9 zX(i9KaayenS2Lf_Vgh{e;KVfKFsxD)OA{#f=x}71$Wx4>GRIv%X}Ro*&r*tqL&xXpt5T%PLN7 zmZFwW;dV|`u^;0&TBHH4h~1}4ej4nS6WS2pEorl+o)IRqNef^b`E)vusFzIF)k><# z4ZCrf|0HL(-`;tCNjgxO>K06lo1E~1Jcb4yE%*tltD<1f^O6r~8@%XJlkL{Xs^vSg z-;GLL&7)8Cd9dGTfeqtYQ2I24#xf*~oK6Dhrvlf?H3v--mGlBP8(bI_RNmxi>Ds%b z5p=1@v+vtyd)0=4xiu&3@*^2&0WHzA@+xB=!Ppo=Al^+R8k}|D>Q>pc^WiBC3=nnw z4OdvCfJxL1GAp_#+_$dAzv84jEyCO{tcyRHp{$0kktNcFMbXP?MYAZpA8%zL=d5MG z+|T8`NwgFc?UI-MY{Rbzx73haDt&At>8S6$QH^d8gg1$?56z-3{rQT}2%%pKO&apj zZsYEF+>VPw8^J<(75cjmbfzO|hKuerl7;LrC4yAqSTUZ{=)?s%Nt6+B+2;V?4TG)r%4P_^yP84&hz0;%teJH8 zCSn2&8p(aZg?$Ii1?jUQ{o`4jGlI%k8g1iy!XZ}GCW*=6W=$WmyF448p_+DAX#uP| z#=s}AodzO){{H@=cdBN)Z7&V+gOgrGHErsiJyqz=0jWmwEey0&nxA;=y|921xet%m zfr>5H%VTr#mFxPpYbw7!48$Co&;qjWeH??~<`HV0o;wVUFf5IL^{=9PuaD(gUQrM& z0`?DNH)<{=ifaaDKcI~DU8MQzcfZ%!RhxdS^QvSB=iX29w;M04hcWKZVM>~v19P_2 z)q_dT|8*Rze2x5C4fKDz`nz8hisi{)W8|v_+qFr*e>`|1f}s5eS^oEyj7%n{od*xc zzWj&5L&VE}nWz{I;JNl+BHQ&C`&#r;V$}yLDd>7#R+imRK*J*v;^tplHTQaPXl$U{ zRVr)T{SXve6Mgcn@!ZEvY_F8%H4&jR($N6OITFRa-gO@}ic5_T-!k{;@U$to0A@s zDKn=m`t>$)5g#WQ#P2xx>}07if;~h!<+2h9=k-{!$joq`sLXokruK9ut@@h8C+PwB zm1T)RpG7*B=9>+FwD&SzpLX~?sRyvG;Wz-h0FPm|=4gI+N?)nOt*1g#B4`T@k%#KG?o;?Z%t-}SFU8V zcQULN9A5G2dot}f?z0|8C~f(e9GKZ=>eF8F!TVFEP)Zy~GzPfL(xGE#&hSK|kCr_tf4 zZri3X^l6|Rm2c$;GoK^PvV2flcixt=_VeWyAJg8fpsPJ70I1siQf+#niF* zyU{{#+XDj1HQ4}jX#;Z~AcOs%GpQphB@0n;Wv55@buBP<*1C5=hy6y2>Ou5p?K^@J zi*GuoKIIJ&IMpo81$fD`OrE@ zb?iaP%DJ;7X9tCRHNbB@4L`L6EJ6*5GG6QD4S#rUoA@yZmhWFK90OMZ3fNe!g{DZx z!YdCcgLbFck~1nG!QW1n)f84+a3k=-JV~Fd9^uQJP8?P-gAeAxQ>iQm0XBTxqGzEp zF1_9M==9@n39s+Fc+ei`aOGS)#46vf27T;qA@x<8wbU-ohQayo-M(fc6&V8Sb)8J;dR%Fh7PmKkHAyc%PXz=nzx=dH8|~;pEpXQp`h!?jrVghYSe^floo|gw?w7)yhCBvhh?o zHo@r3-{;s;;wJUQURihgdRy5gMD|{N;AgSf<4&nS6%;9h{6Kv0}zzs1gD5DCW+bSt^Z5my4V1(vW zmmlmgmV$)n2#I#C^2vY5k=L93IcH+Bl>*M*EXO3oK9LFR;nC74U#{4-Qb=dd8g6l#Ja(f*(V{z zw>#rtBU|@q!=NSRzWuThTdGJ!ewPO1Wi{z-?gz$~E-Zk@j#>F6-v?h`#6&+3fdJ_8 z-=o+5ZafzeN2Y)FEaG4G_rTxN{?8NNCtaqH&49sV9>b(QpxJ#Iu`kBBH)U~^Jj+N*E@)12lgVqNun067?U{}div7v+gCz! zX~>_mlO4k!%ig6FldO$!9ytETl#ajORDA7)39;8#G&hCv$<}3&+vD$$@DeMNN6329 zt^TxMH1_ox+&={LM`aW_m{zk@d9n=MoyhgFPLWoS-K44QIP*#ivaT*i4^14ssUG*O z>JDjth=o)sKxVRZ+T`Gs?RA@T72)q3zH%zf7MvwVI zj>-Jr<@@RvdiDEOQk87vL}&KT%(^O2rw$`ode8O)91^R-k9Kt)nkMccpfJ~H`kGeX z6+*H7-0b0!xx+Yc6S7HdfQ?l7=q}SMEO03Lka#|Y0oJsn8gVY=(gI*}y*vZ+mA^f2 z&OC3(-<;hU#6ETosd_{X8+Cu5qJqla{q>45zbjxT&Od{*V}erQ75|9moOfw#wV_7~ z^rdT3T7Pz}N-AWD*L#KKQ9(drMuZ``M z9|}zPdK+YKbB%(_H=S0vW(WDor44PgSPB*9uN5GH=Jc&h?84mbdVZBG3I389CT!m9 z{=nJ9kFJpTaa4-*VqJ;MCn zd*|aACcpWjnjWLli$qOcQWl1otSNmO5FHb}4;pQ4A(tsm2_VzSH&qHMakJL*$}SZh z7z-E;0aR?BeJGHr*;-ATj3U%RmSh68drkS1Y#i)nSF0c3%Rtm_V1usX= zWUsxn!piQprnH^tja49>Uq5!G#_OufQER=s^0}K(4s0ZiXI9dE4!N1kSeky`8OVC~ z-E9DRX77pN=Wpw+8HC>FpI!-O6bJN8ak>d48#d20aNY-`*ug50gnYdak41Lvc5QajC;@W(#Y> zg_p4K+o9V(L<3{u!d-IWqY?>Apu?ezEjH{cBi}v*+kj^-AFud~rDTW6Nsp&|_Ff?6 z7m1#bj{a)SlwaPr)=KNE-Hbpi#f!h&KX-nFq)D^^eerW)+tUhnwBQ~q;sftuMMm`9 zifRm|UiQ&D^e+O1SUe7Y5}d0&5)Mo~XBVcFXPwLHVDo{>M=_Iw-cIx6=>0LL-B-H- z;?x3ELpE#4y3qmT{-i%k?qiqwXq{}qQ1 zoJ+0vwuFq!4s@z5QVG^V0lQ9dlu1&rt+*Y3VnLwX5S{7wme>Gq#=JvJwQ0qkBbS2K zt35_&-{Q$NO~+DFnYF;~=aPvH{8#%Ji~GB!ay>aMsi8(8i)W^Ll>4}cA9r$J@w&?t z)DgUP+2^Z4NCGNL)El|bxHuULU8Tl9Lds=NU6*Z)VnkPN={YFY%Ak?ey;Y0p%(;I@X{XZk<&4nj&{iQ56Jcoh72IjKnE+zC%wfNg7>!K12SA zn$W6%8WjM=1$(eH9``%O2$oIU>!$=*frGsXv8lG_zWrMVa}aBO6D14QHV)?(YjyyGKKuH?%+ z1#gAUGx6GfW^??b{KKEJU4}i63#}*y6+KBA@Tme0Jfk||L z9=y_yV^7GCjYq5&eb#@EF5h*SSVZuHSbq63iaPCPI8RoPH>%bLdsFnEjx{uOYS+Cn zl?+kfv|OsQ4;ZO&FP(PE&4#Tv-t~~Jm2+GfE8~+lZpeB$wd?DJ!jm7#Y9M8X2|{~H zqNrtYbTWZkyN?2oXvrY-WAc$x49go;8Fb9ok9ylxzOuIzj_NE;{kpz3)b3*UWmFqP zQHnn$Vao41Sz~~}`Ja|$1urZWtL7VZ-aVO-^Yc>MRqc)`amBu{yL7ARMstTiO_N#I zIQ*W7ve?=0v=?gMZfUn?N+mSi8tX?w958z&R${xhJrm3nLuD58bG*ZjpL~yd1B*oh zrovOULFa4C49p2BY(aQZjkspTNsx>KQoobGvuDP$FN3p3Zp5qGCBRaXra*5UT@g{@ znjy}da90grOmK;xGLh1wd&ijjHqNlWI;(2lB2G=lrW)3@$AO%x(JH)rdyUWULGY%v zjRW<5g@=~)mLo7sVYX;aTiuyk-`SDb z&DgbT`DJV<0O-WrLr4WVE+uIvSVYCGj(}W1z5Nr?b%aimWeL{uGATXuRCREMXfg6v z8I#3K1@w}bdg9)e@QI$Z+`;OM3f0LqlGo8bS3Gzqe5vdkI)-YJuSTomT556EZ+)dF z?$D=BFubkdXVV}eTaIDbC0aY5(!NgWJt6|JSYvE{0Git19=IlvIFWljf(nV_A%BFE z{nvO9tJV%_npGdA0W`6s8BMVEJ)fl1t2>f96WGOz$Zn#}JLy{b1dI1C*_}=Ks@rF_ z|At9Xf1(4Q1X29bd^;aTe{LW6E$POIb9haf^g(iFh(fTHg-P3p!%%XPkl1gSaVq*U zukp>_qv@7^P>&8Y+aADSCBU?u(S;ZhJl~+!`KvPfb+^Rtz^Er@8rGZmO^m zQ^W9?gE<7`nH{Qvz0&WL*m2LsWfH~J!Sj-Ow+(19p@Lz_Fzv`o6|e`MPhul7`|RdN zfzgpq9a6fS@!e#S4k`~OX#qRtC43+W0?O{*@%_sx^?gy3(HX|FQ?+VL?OdF z)yQ{CkAH8PL>B|DO)a&Y+~9i#4RrUln$+EQnD{GqBvnRT8|>B?gxZto>UL+4Y4iFe zx39d^vs*s|!2`6*Na?tktA9kL%05W0Y3}@n>h%_gCnZQk&3=O8zD#T~+@h853}mTh zZ*kP=+I_z)XEXG~vc{!cvmbvdQYuKIEr+7AYMCs1YmAnixQ#i~h(k#)= zdMa-Gm79HT%o>!jq}A$}qcGJ#$z8xh&!>;E zu9tN;B^3|3MN>X%za1gd;xo#+e=;$n60iBCzD&C$*6p2c|5Pkc@YkP2&InNV2A^xz zRixo+MAgQb!!6rn`BXi$Y^Tl1d;{|>z%aK}GDiBSO*mvUL{5G!PrT)6J=gpAdQzfK za+By~{<#Vh!sfPccWT54g_4=@YU)0>A``wF>Rg>thbQue!y(<+1|hS)Y6vG^=2OJ` zJyuS&c(wXxwHEUU+i9J9mMwA`{OG)tGvCM?z&l?P7*ko*FcB#3oS|`ECcqj!U{0AW z`MH>+Z(M5{E2xAx5x(Cd<#g(eBGchJOHn67zf5??9ew4br09+?u{*z45+7e&UXT6o znu4vgvS=bM7Y6)`QcYPSGu?hR-LWwHGiJgO!OPt)SiCAqd!aLXJ@R*;Nxt9zpD14^ zdUbeMQooDq`M1dI((9Z{7xChIR}!yuUj5rfihnWP3m1zhcIB7MD$=_0++Wg5mYM1W zFpiMf=Qos2pRR{V({Xff`612UQee4(nrg3Yb`<$kRNH(3W~UmIZhjB>r%u!pbu7hw zz=r?)Oxihtxwbz#ld>~lFt_9#l09?^vgr-;z7YAyo}cbb6UC7WA=~fR^Giwg|Lf{| zVB;&COAqS^hm+I)3K^H(13ze3&fQL5f6werl=m(FbSt^!iggg^T6sJaMLWID<`dPn#N*aY+M?|VmH++9O!_aw2qcI zZw*~LWjOex4%?lljQ1bBTRT#G`#TvS+n~Cu1xr=-%-(#i`2_Hu1{0+oDjJvXmzTq zC$x1yKsTICYLaclNP$eBlbX|jv07;(UA18%ORrxp9TDwTxidAgr-k?gUb%ZB<{LCA z?uP&E(A?$HG7F~s=$9AnQoOMkO!lB2OUv`Zy?)`-SH*>TqEKEc<=W@|N)3+nLY&&8)#l$*2eq!)|8nUdk z@`d>#0wMgQF|yaopSETRlJ#Nz_R&vx&9FO9!<@!0YC2FWCtgjR$$hs{$a{#Ne8sSU`MB(Ur&S z7tA)K$a=kYljlJG{o!{z#Di`H^=J5E7mv+m%4R7HuutJdq-3$eY2b`?sRnT6ETsp1 z#J;Mut1?=9lE64i*z}(cn#IrP<|r+#$fQ_YRYpC*Ng9qbu1X8J1_=Mww6mof=+WC# z9<$H=tU2gdmCCF!^>CD$eUe!haz*nZW?(_!U-mNGKzJf@A4g|X#Fa|3_f$_7NUqm) zFzc_Ywd60VAz%ep4#N4dUMVpybG|2Js-W!I24$_>_kX1~AKzri#|+V}mez01TZp#YH8w;7zv>A4L~0IrKkv}>F7rx5y9iu( zC?PL~UM7fMnm8i1$x@m*HgY6`{ls*T%+Q~!tEF%%DbhRAXq#4?<8`$NhvX+3INv9H zIF@1&dU(a&;2CAUpELzp`I3-4S--e@@oH7wkZYeCLu(v z(rC^Bl4Pe8^W5x{=FLS79v)BVwngsaJI*8B&-9*<1+=cyT-T~mTx!ht^rcAZb}}s= zD^oW>R5p?HoQxz3Rk97ud8rO+f)YDW*_on0$lN2X?}WoEN8kwcKik6WBKnF3Rg3o(NHU;~)B+og_4kJc>U z2Ib$FXu5CGWfG+;|KCvSe=u3in-9m*{t0jrwNaY?%6<87D{FMIO}ImmDFua)9>{hB za%z@9V6O{3N=CjTOwWei&&+dqc9B6vq6RI$1%L<4fq%i|SNworw1KKa@!u?@cwP$* zuzLuW{>bAD69ly@9QcCjPiV>{TH_=nf9{LEO7tG_hq>KMYaVlI#ar%PRQEcs?XwC> zD)bn9fnICTz*YBv{gmhX7p$`|;%F}l_1{ij!=+}tT5&r;8AS5B18dIuFY;Pc?{x)IPJ`qmG-Cv-`OnPcE2i z*V5TNm3UL-mBOm2Ts!tF#G7;x4-}X)<3p^eVtTm;drE3zR380MSelj({KC>emYJr}MZtmrN@-}PI1Q~I-*=oES8 zSs&?Jw=n|2ba9_(RkrNPA;nN;k9K>GxdWalO#&1+CUY2E+8pgSo%xaPG_u;V6mN#> zlG@i0L=B^9BUTdX6ju-l#vLA=YUE@)$yq{3Ojg`t3UUgWHQ>+9V*vxzc=N;qDoWxH zI(+x)mc25yi#S_2E!Ryu&L#oTYYm!pj&WET?m~(IC6|g3mg2JxNw+L zvpaX2t&e9L5;Km*nxv1_2A1~%*T$5fQ+hN0?8m}KZ#?_X?5E@ki(M-pia0jeH8u={ zS&0WUxUu}0Ab3ToI7Z;PJ6|rgBCI1i@2Q~Jrw)QIkgG!dZq5aA zZCu=BFc5?)&pd5+vNm<*SZ0o^H(TfcNrjokVtbEMmLiR`f1bQe2tmzmpx zq*1-^eK)dGnUK*yS>Ls{_)v8N>4LCa>Q@c4z()ui=d} zQ3GhQhw_|q9h+q7X&(Wx$h>@Ddmp2+qdn!L>4nE&71~{p@%SuR&|-YAe}65L)Cl{b zb9{hYJ+)u3F9q(JRmTt`bvEpUoS&RpQ$>BIbu!QUyAMEdtIGku$x1SQDz60toN!hL zh69FWeDkRb8^N#aCu7i3$rG`xhi-b)AMN&$ztjXrjWZ8SKZ*+O4av_;@a3FNAPkTM zG6kfI&Nuq6ZeK#c%%j23zev%ZSq4Q)s14#qDnTlcW(OUei510lv?F6t4b$FBy=FwV zzsy)F@$(?g2qg26m>YBUvzPq^kt*)9LPNp5-LBz`dPI*Og==)IZj0c%6BpL>5O*{y{rxJ z)&}l1jH1^VU*dX}Yor%nSrV~y0Pu*f;#_W^61JlZDvuh&E&d!rAN8c(v)-HUJck8G zfH?dNa(?@X|C>u!sjkHCyC5}L*Zgp3YwG4b{UaX35v@my>NpA;g)ULy<<@B~foxS* zFG_{nigM?3B)3duWHkN(|Ll zG5E!SPZk+7P7uBUap|5{5U!^o%5^BO?%fi%Y2(HLWqE~he~B4C_kh0N2s6FFG9THI zx`nm*%p-hq{ai=xo&Ps`Ig8I6xl{!&9JAg;OaF~V<`p1?D2%;bU%+8gU&?Plf?DXC1% ziy~Ft=G?ziI=1V`;ne!JiKhEl3zWl1gWktK3VL1=9mK0BkcYr$b>Ec~eqX0_}&2_K;v(2_6aI9Ef1? zo_vsg^Jy7utbV&b2$CW{*w`W*&ad7QA63+B%u^OetN zpKp~ja#r5xUFXhxHnl28*MLU%Ys5Vl1wV)JWnAu+BR-`y7aiv zLe5QA<8x&GR#0gu%_WN;#Ir*~4u0yqvFksRc~u%K@&ATg2ZEjIL*c9S=mVRF?kR}F zblGg3f=eXdli9bVk|dOMMKE-Lg_LLVOEiGVi*_VfpY{?*@bL5|QRm9gt3Y}IPham4 zk+9O~DD1S3-ynZHG^WHzb>e&-Ld;ws`Sao;qMOHnKmVaq32Q!a7hrWxNjx0m|4;6! zfS)1PL9`wIw&;z?RA_KgI0O96&ZbCFjA5C_oZB4Ph@DmIO>LbWZm|uF3Md`!Kw;W5 zRB2bve{+U9yB~)(J`erVs)gXO37h(ZW88x8UMBgzN@0zq34P^%PL~D5|7?WmSyR3F zNefV0oIF4DFdGgHc6pkA@F7%~{=#5BOev=Uv?~p?EC63kgLF8C#00c_sZy>m0MsbX z)}R)gtGP56xasvfI~Qdt@A(y}X$8Wl;idwil?{A8%5&tPuLN6RvC0#>9)IGE=1BCS z)e4=FGu7={*b-G1B#WjqK22WvrOAmcqMxvvAJzlo2;07HR%9lrI(nLwUFxCcR@UTc zru^y_PT)7PL&Jh(jZGmXxaXY~sUj`wu*V_<3?d0pt8y7XxR-Y3)$WrS9-~&v1ThBb z&82!&W;_~myLPzC-27X1u;H%!I$QcuLN;msh1Qda$g^b zW~0u&qS0u>U%1HV3BxaPWj=LVtsn7qll_(IeBsHE+@=9AKj!08^hn~72JpD>K1?6e zp)D$vk3vi)G%t!G?r6ul4qxN5-mKG}IJ`R~BQj7dePTQHb*k5Xs@-5u~g+2t;LpJhDe&)nUQ&|x*Zz~Z65I4IL9UQJx}R6p-Kl8IhbT^dJw4vO;VS+4>$xjR-;y^=|I3S}PBhekMotEpcH*YUt?h5H-1queXVs+-%*Cw_WNV*nm2~d*Egs`;VcU z-nDuo?6QwFg!+TiS?}@zQwc@hKUzIpQ0N}UWpE;R26~sltfG(UKsJ@Zp=9Svg;%K0 zxomh?=2r2RzqRQOUA$GrNSzh4#$U}Z`(g1*EJrOI$%*7%yZJ)F zCUB)dk(eAqOc0-IlJg%iG70y7e!R}lALjeh#p>SC6*KFBKm{SLU5lXbr}zT;cjiM@ zK_*j9ZcIbhSxeW|@;0=4=vLGXH&33Q6PaeDhCzUSVgHZDx01?EzvIGmiX|IO|2$JT ziH4eZEH?eHx4RjU`2my(=IRODQT?&eQQ5BpCkj7@38MMT+U`HwHw25$3U?M@;aih(AC$5h%^bUL)RPXl={-|t8{U#p?>f`;O@S#v<)DbOLVjd6IJ496 z*@G6J(|Q7`eq|Xx_v1QypWXXDV7Kj+$sg89m&`4={ufL$h z%Dc@<;DwfVC6yAmNC=*vpTQ_qUci{ zJzo`5OBCf&LF z5%R!?jvR}Rr=At-M#c0*N~$nTpO2oVH~hHk@}ssKk`7F7@pd($81~n%*qe& zyw6(-V((Suv~n;*N4I{wt$WnlS&2k20oZYa5pC3(5F)-M#uoky-vS$7^?I4?!Uym& z9B;PIhs-Q=dCzojeTH0BHiJGbz1n-hJ{xgN554?m8T*d?4ikFDp(;#!yW`n(Eh-eg z=UVa-h2tht)gr(6UK;MJ#iy635$?E+07>HzLLqAhC5usOn(UOJ(KJv7SyqR$(}8o# zC?;H`D2I(n;+u`XL;1B^&q0~h1DdVkk$T-ja*ic^RK{7U&qlzMA2OttR$$ zDBV!JN7q2;dUAZ?sQN%$z0;Hg78z@H=+Zfqw-i;ON01)JHR#4!ZG{sR`leCo%pOgm znMEQjy?f7PO(pri_&S7#tFIc(FS_iWJ=KSUw8jSN<0>UbS|+Yw|F3q=Gpea{QNySp z!!QF13L*#^N~DRP5~StOR1kG zP=l0E5|f-AJ$LS(d)GPt&RTb!U&&h8dwnT;XMg+o-uEeegKG?G4P+n-P^B65YZ#W| z_LnJ+?76=n?=y^V_k$?`Z#a{wqW~eKX`k`lUq{||x8*YQwM-Ljj#+#)F2;K4_Z)58 zJlxn$4rH&q7BgI%)nXf=Ki4if0>O@a89-#!z2iuC>5f0k?OGM#Cn>}pC5Co6z{~#mOP?!wBcxz`^m4 zD_v~RHi<~eWF<7(uim^OoYVBH%w7=foyWsYGpzLEmk2=g6SUSQDQIK@^Ci?y#eWmH zr>j(Ef-(_&D0o>>K-nT{mNj(MI1gGTc<{?~%Q$!gu`_8ToZ#bm@K4j&Y|vG)Cgju3 z>yi?>ZrO--pq{t~?fudaI4%PIk8=c4v*|!dODRi1|O4RNz_Xm8*|GwBP%;^?1tzK(sY{P9OkPSpyv@PA-vm}_ckuyK(w@p&|>8~TP`HlN>Lhww~x$W0I<$0TVAew zm&2I79mKr`-=Ej_R_h^)W$H#R)YJ3n7y-;7pF-vae0|(>VPFy5Zu(S~j?@s2l2a$d zxU1#=re4QAl$AYa+B=|CawFxsPO``E-u*hI7TNe?L9rt)T%C^wrPQG%j}_K?Do`=L z2X#5JP8`M?u6|Owi*vZ{a%6p4Gm3*Q;frcFX zy+(@Lb*}an#2F5?@sX`fmp2@7R?Gix&&4`gj+3Q0rY%vnmg#+VyD z^@d&{!Abh4USRRV^?|Ggeftp0UdOB>Iz%xO6*#q*zP}ql9MBygg7u$Z?!Oky&6pSksgO{ZqR{C&6X4HV}jm+{D3m%%MM(p+{x&$hk#`C@u? z?zSMzN#EctdLF6dT>9YzGI}s zMpvHABkA=yoGP-(YWNpqmn}mq>3phT3t809QkV(fj*Txmh)wJQAo@ZrhzHS;VFl~g zlj4%gZk)O8s^iN8=!}%HfkP*UmYvT6WbHqh+<%_Q9ri@~uRmW`oiPPk8Ng~IuF+;a zS4H}KmgC>}HH_h9@#=61zb(~HVRRzttP=I0H@~V9^Ps6%uEc&lyB{C zIlGh*Tq{)d;{GvCxzplh*`T|M-zi*Xdt19}LC1K6(N$OY=Piu&Fd`ihUsev0sVI!q zf(6`K2a3sJrVHY%s->4I*tw7GdF?jIcHAua?ZMuG*5lEy?o8YId(%pG?5EM699F>V z;hmZ_E2*#f+L&=U!uSTV!|=YQrIA!}!wb<#Sj}7VH3xhTMhI%!5u6#=wOIGbb>6Df zYAksr%#@Jl{k2GALAvUxl`a4@r|R z)as(@Qt!aIAa(o$%SFUlul9_Zr3a6BS4_c7=x5+4!-WQ{f?~q=@%_!L{*M~5Xk9_A zu_=!c^Sx#Y$cdZmC%;gB#QL5 zaUiZI&0FIbEt`#a`n`@kVSWz8Tl@j$K=; zrl2@f8_yhoHTh9~ zYv8gd{&dp!mW!jP%`nkgXZDW4hxs!(KyqR3y(WsTtDt4=ve1VW>=CN_ZV>IRXoP5v zM`;<{Fpv6PX?)W%n`v%Mk|Pq{s!lGJFPNK4NG-tL^my$NR~7JBvOMMMmKCaaHDy~Mg!c8-2w24lFmL!JKMf81kRwe5?{KDz%z zc$9dtl|fBC!5hrfTH%4#$3TsD-~5ciyj3|rxaeLlzmj-^`P8E-ux22ujI6IT6d8w3 zqJC}dIhJWY;^caRHhcbXMRh2TeQ+rsjVeh@vu~kg@w|G#i)X`V(av9 z?^V!6#V@z)mF(K9jfx)lT);nf|8@!8QZ};%7~CSKl^HF=f!y-gcU`!iqNQWgrQwLN zq*xixR6-XbJ8V({>IKE&82wVtuSO4=bc_N^6gI%gcFi{uCgEq}EH<5QmO+YA6;}km zBSc9gkt(ScqwI(sN0tZp!tD&TIjSLA-1?Pc%dQAoz9a8e@re4`#bC?nkWgR=rX^Gj4_-tQLiuq|NY<;`)$7D@A;6V5q3!vZG)~G^p zu0?*7S5=3RSlb`rgVz!ORLytiIzWG4;EF`Up5RZ*XA|8_82YV`?OpG4UaO6%?2cn9qjc?lBHr&=SyKV zzaKv1Cm*8Sc}SsQI$3WtP8>W6IFjg2!IJ{p0B%;3I1hMSMFh+buh8lBg0jKy$3kd1 zbPdjw#wdieYZU~jfTM!$qL@XfUjYL%;76`ry-@$e$p$$sJ>iSmazoAeG%@Uh$hU*) zVq`-**_%bs06=x>2Pf{%xu8u}E5-rq%azG4F#b`B{`#e0nMcbM%^=oFjbO*-eYt-K zoS$ehMMRo%bHO?azVj!3LoVzr6yXCkNZEpY-M_ct>f7#9rs zC1(}IWzjjT)u8S1F!)ZcD4Qzr!xDX(5+S`Hq7^#-BNWIV!!Kfx7y|H{F`iqwQW#l- zsr)U?OvFg?6`w)x%MQc*#QCa0Kr8u#@{;VZss6z4x1S$0@Yw}tEhTm1tSH>qXYWH8 zgAOh5=#4kUPG}Q>d4wnu5+logrVH@u%;qIkri*BtY-sbozji$uRr!mDSm*&0l8xEk z7*s&^Bg>-B6ZxNCT5RqBR%xWvi)=Ld+dq`kdY4>}0pnB(c^nFjG}+r>*mgn%ZSoG- z_?|*=r;wD;Utg5=5a?dMReo*R-Wd0InMljvD)aP6~I}@XKrR~N-(|?`FEKvs(1hZ literal 14308 zcmcJ$cUV(TwD%hoLj%Pd+#54cJ|&gvuAc$Yd-6{Ci1nq!o9l>?*agTdrFG3S^&U} zLEMkv&TZTg=40$`z@8gqJ%tRPASi)q%;Pb z11!AN0WYN)@INbVlLPVa$qQ&^dRJ~Q&?)Y``b zUK--tq0Zk=G@pWZHq5YSy_(=FWbQvl3zS|mmyr#bcCJPDq0W|qmjccfKtsYy0pkIf z6WC%0dW++_cBjy=K2&kM19NIr>B?E~bUEu8*x%oOh&1Tn*5C6D!yV@<(eMEt$ng{9 zpGuiBR6|*L=10Scbk`l4yS+Jwxj4&=lR%e<`)H2Bvzadl0gk;9cK_s+jnW_S0F%p?XJH258Z@81*NVG$T&(Y8sNO^r*KPFG)h` zUkjQvyBGT6hMH;A=z=m~ZO=s=EX!bTe7Ow7U3Uy=bcYppC!NENcMH=@-^!@woaeX1rKL48c=MUiTvs;Vrz^qV16hlzOl9+F(gD%o`^RaMKCNOTi?{DFXO#1{K zblswHdRBJh?_N3nJ0oIZ0^B9dSF1nT;{J!=-F?=t3uXhBF^8-ROM}cz?W`xO8Wm-^p76hPZZ<7SBHHOWz}FkJa87@GU1`>Tjp$56irY zodqUirWVyF2p_~ZDuj{%ZO^gheWgW{z1`-XvrCcPwpmX@>(!s)&Lb2KokgCFfH-5* z=W3>oa?_$_5nNesw^zy%`^6@A;tI^09^GjfK7I;XsZiC7^PN@xdi0uZuQwDK9W?4S zv{F(I>NDG-KB7Px0_|p%YV>nNJ$j21^!s7v7yoiIr0%kEWm(cYyIIEbR9zLCy)iJi zccX^7jGl&bvh)*h9r0D(e<*#|)^Nv$K@YCKcBYR|sn+!4)(xvsG;cW}-jpCM^vFIJ zJ9?pKL};C(e&xgbx|Ac$;Cbn{9g!q`{z$QNJN5Tq!-WN>0?8F3 zkXa+{CF+Z)&vsR2(A5Ac@MPL}9_XZgd7zFoJ6myt9$$X&!<2kI`o<6^=}|1|hROuD zNK6?lb?)(wTXJr2=Cs)lgw2k^x9{5S$?USorR$2BWO~b6&nUa(@N}m_mo@piO$r}; z8`SIP87DdsM2ZcHykUrC?ugpuudN7kS9V+9{Duj{eEU3on^x=bX1hv=S<;7v$JFU! z9wDfyK<4(bPwe1e|KC|YV}ukvR7pi6i;*7R0FgVjxlrmdyCbJZ1Nr8*fobOPA)C~5 zbwIMFp2_*_2XbFHz_a1gsQ5S*;?v=z%cJTr-;M`Hy3}#((IVi_nSF0|taUyoFO)zG zMx;#@xZg0O6mx>xy|_}eqf`o`gDm)iiQ6^$Rumb}ne2-RJLkDLzot8XGM6V)1tvFH z4S@150)4~G_aL+*FLJ{jsj8a4(6CnwfV5`Zp>msjjnqoCX%);&$XZARDFIij`V5svaHW ziRU_eIEW53-tb*64ik=iRY!qEn&^M2ZA;z@8{^vB;xR!SsZ-B;4Tnv0X&JwP)UD=a zhWf;Q5%VECZXF|F(j*_(!CPCEoYVNi!MJDp0rvbkkRC~rgs+LZ6S9k6p}^bxz1_zh z_wokiLSFD1cLuQhRv!zR5WX`}F^~{>-=4{Bjr1aZ)IZZ4RQ1ueAq51!6pPFUrV8*7 z7PU!GD7WY)r0F<#Ffmrj-^kNfdbL(D-nGJ9N#=P3EHN#LYwEI|bzG=O!WV!KVU#UY zEjRu&*|f|qBx)L^U4H+tK%q)bzqoL`V;D=d=xk$2(uwy&mMd>k_r5CIA?Dsc6|7a0Ogvdh-F=uOV*9f*#P@=t z(JIQJ?$5<`w?Ei@*|swq1`p{T=}CD^MjofEL%hPrDyci{3RSuA=3>A`0Y4TnW^&Q%WYf(!GaA0jN4WuxyTLSorN9yWAz73HWSZ2NuU*<9Zio(0}wYtdn^3EEb{H!nb5cY-V;B*Hs-JJ|9XNiH?N%q;Pnk$ z(*QupKThDkcHsZ1n)zz8&*2l|hANY$cTBMbLAV0%W5TIk0;tx<3RMnE82>tjZzczT zs*?8QS*^}2q1Evch2h#j&vV zE?>YJ$FSc5Wg<3aH#`KJR{|c)O00|K_E=9y^~hY!tKEU>-ZvCbpP}lgFbH^~US38U z8tg2&`&g63jSh&l8_79w@Kp8Qn-|4CJPxI2)xW*NyLz+7l7foM^pE}MgUx3BW_&)b z<2^7VBmv+nrPCqp$3f*rW_yFl%+jK$r*2!OJO4g#Fp-hAtf17`kCu_gy^X2b_c9$Q zx8xZEa-M8_!$V1WqS4sV$Fo||H`kE_jr#CM?3a&Nbxi0NC1p3Q78;8A#_Vc~?%$E3 zI2Zaz>9K*}CeJQ^-w!8SE}sbkcZrWM!~)G9uMjTC;a0Fp_~i!Deb=FK_l&JV2^rJN zX2uMUV(emCpwsqT6d8@7P^{`2Bv2EIw+9^F+@ThWG(P^7#@KE7VTj--Sr#wg$+F$Q=x` zOO7#C*^NuU`E=pl*N$cH4y2}v5_&0$GT z;ky4})$tc;Q|77B`K#vqF03xEFX&YiUnj}#E>2Tl{JJbAwCK*q8y@HGmXkCnkL+-- zoqm?xzkg2Fq3z$dTHaCk=mu7+M}{c*DVS_IfBcjfq3IhVR^oFUVio26OnsE<2;9$7 zodg_GCsv&j8pKT?lSCvi$Kw*a3X%f6w9`Q9jLojgFY(V(AhvDtIWrm0Xx-Du{XAP>^?p zIo_!{Pipw4TwbSdAXT#ndC-q&CAg_J!9hM*`wy**OuC=p$GJzR-Q!R2#x2l&R+JA0 z3R_piU-mEzvZ*ZXiJ(@Hx`ELriB}3khpSMarJQelaBj(LN2Wrz`J_~jHWRo|!~_$I z-O>H^WUdFwMxEWWixlT=g^z zo6a`jzya@E zj=nsS-KnFQSa74J{=~I2O;E-m%G9b?S-Z-ZUVeN z&Ek^+i2gPvvl~M29^V^hd9!Z-RjY{qp2t~|PJW#21WeObb>R)Xr^ijs?Y`j0$tGRx z9r0l*xoTD6X~CQGzptj&(ofQYh`W_Xw#{z+AGm=3jpuOsY|g;IASBrl(0Xm^ZC%Bk zPlJx+(HGMil`o2U+8=pb16i3JGahpCOyVqWLyljVYQ%oLaSvLCJMn&!&!@8>+lo7? z9e!llh+|9hNn%4@HlC#yatRCri)|N$jiYNn24!FspF@=dX6GDFPt{+HgC|s>dncx~ z!MF*nxd46Zc2)$B9B1y9iP~q^3dgC)IJ=3ay|M0=p|=VnPj+8fJAXwN)G#6}o(3+4 zQew@~&Ed?EMybruS@BgD16>`M9284lUO3XmXvM`&HlVY;PsXR;Dc%IKzsod3O65j66yFQzYb3sH zL4EZ#bEyp)v0i-do7VL+?dI==DRhvOe;dJZa;Po;!(kuBa&w8RL3(YxzBOi8El;pH zoC$bUYs3dj?Ec_~KHhA|UzHvJm0YQRzD+%2ztSS=Em$08P&&3T8`{TC?^v^)9Tu54 z{*CL>(aiR9Xsp%XPTIhsZbaDj1Uw=6C@w?$Vh7lu#%Wa8)0V%+yvS8562o63$lq?> zjjXvE1uas2`#w!Q$v5RIxFSXas+JFw_TNHhT+#bEi7&6No!Zasy%A7HdCq+le9qxW zbW}MTw@Qwn^f+c(9}etkSP58dTlnT;D>)L|S`jllee)!6Kl7&u{D`77c41n@D$(0y z3VeWCcS{LYYUFgJ|FaF>7XY;-N)SoN_yz{Tc?XzVylVQ{(*`zQ?6%N^J{SxqWz4wA z9@8B^D8{yX%En>O&Nq7en8@L6UQe~bt&Ey0=gNaqFj40wwt1bf6 zz4bn*#$she%4YA8EE4Y?FT;CU-JSW{9TnB$m?l;d!{_=v=1_wQqeglbXQ%4+cF1e* zVlEL<;odvb<5|8qvs7o(IetAx!wzdx1ta0nsjZg# zj`kz&^E%FNHZmL3M$$+>Xba3wU)pBFbdOAn=nm$U+!Ul8I%F&nO@lo>Tx&^GR6InJeU^Ei zflclhU*U+NLmra}+Ic#&AIB5~*^M*;R=s=3Gy>O}--=Hv?U~7nDaQ@+>BT7GwHFa2n62XeQs>9Gt$iW!EPj zXpc^G^OL@+cH9=+ONJa7$Ge3$HI++0ikyD17&o9je%9+|he(*L_Ev3h7RsMbzdFhI zGottXR&fS0bIdO6sJuZP*h3=|+p0TQ^%zy0V$0 zb?#~{PzTyx*({U?rB0kN@m!_z=#0EN=yOAV6pGtHq`QsSGpAQXY`zFI6HB%B%Cb{6 z+{~_deyO5tld{^sm7JnL=bKB}UppsFWEPfL| zxp#9qHXXzHZC?ia{H$>HIr+F&W)G~dDHro>xr}u$XPRYsHmZY%UPbJBC{(>4Im`MX z1#eOV7vzr(s>RFH`PANgG2Ro$eO`~6yOKi;Y9HYP$_XK_BZ0p4=6e85SxzQK&elac zmFtj7WsLp`vslnX}OtG~|T*i})!Fda+ zqsley8k`mP&cVe%q!|6G@Z!r)6F5=0Ljc`QbNr+)m82{;9sqwm?A!@Bxjw2NB1OcC z(Jg=a>G+u;no)J5t(n4WrRDUD8{>hU#Dsi&f?o6-J!Kq*lg4>R3RP2uH$aPY9(ui)uxl&Nnl*@ zYu#r;DW*~P09BJt$>t1{?l;sU@C~`kvvNN3pV#d@ndgR+G~Xd|OTRGuF#F8c!;Aeq z(?sFPT5vK%W@hHafH;3gY_P){U8=ZJqdAho>9@0w096aGcscG^{)~3)Hhy;zq)^YI z<#%`%{VvR$s*-Y}M{;btvNHAqi##U-e;hfvX0Y^xQV+K!drwik@8_D$>2eSQuCYau z!qd_92EJNGzz?BYo#iZq_y+nZJ<{ns<;fbCSH&Zagi^-ceQW!&x_4|34dv#U+&UKZ zH7oCS?1zW41+~Y${A5ykSNCA-D*& zH{Sm_0sl|aAE6u~YVIHAM015IX)B6b1b?HYZ>hxroQi^u*FY|mb3KiV#?5P^u=Gna z)x{OiV+ClZbzP!6Di~|F7JQ6w)Y#>r9`F>uz_yn6)v~AV>(sjrUq_nD^eWMWA58|} z?>lY|RILJ4*}&Ua#+26I!CP%(?xY!gJ}XxyA8jfoIk~_p4Fh65`qI*(3~|?NEQAYc zJF4eO?3yJ-gjoCwcp~vhT7Klj^$$VM0Z&26|#SS)g4u%X}fO$;jaz_wU)8%gbM>6>4hjM$m#mYPUZP zmE(_$&{wm5gb4=uWL3prd>o)7Ik~{6zv3i#pdf!|h@_hu9b~vRg6q*LU!^bU7A$2i z(k1KF&CazOze0yd1sQwSIFo_~Uu_-aD*#21fWi zuuRiGVz$!RaO|>Pb}tG1`STSb@qH7RAsDW%OSS&Ovh0`4?n>=1Z?b~Z!DpzV<2JMN zN@f&=gK@E?0okHS%_xa>$L+2n+wd8QZ||&>hiEgX-6Zb6y*%N=VQ0YDb~rNI3^=ef zu^^&AAXq6gB`*I{d4PSezPlU=yvxuB4}J28z3qJl(Kq9F@WJ8pRP%S^w(c#rum2)ItS<6F&Nx)@B z09D|CU(+guhQyc9hG1EvYDrh7JFwv6*~Q5*de&%WjT`~H;d9t=1Ql^+DgDhD8DU-4 z>_bkt&@v*z$K*+@!b4XFpK%{2GrYGL(f+)>ck81*#H%fTMn>u{H`BVHex`%%Ej~ho z8O6db^AVMTg2kJxO?ckmsV|fc4w~M#zImKcv)%OIr4^NsqO9sM2dA;@6)8kL9 zhPXeBF_F;^k}xvr*s4Zn&?+D}YX4KI)B48KTU|xo;jgS@hVub2)vB-TvkEe~GFe>S zs`fpS=5u|1x#`Ap8PS|Ee9e{WMlKmd+z_l04R#I?IQ4#(13P#lCdLXHi)u7ce#Prs zCCah8Fb3%dUPDEJ@6TW)(&%%O4FUhMq6vvShC$>BpT%0Wt*P%V-gE=JGR{!jwaMEjai ztE>*7HZQR)j}J>!z_^NK+LHN9$R;A_%0AirMpT{U6c4xvGN?yFRAd;g4EsH6{Svcs z39Rx?&`-1DEkWZIxhOF;>Gky{kQRsK1ZiDd}s*0Rx>+-K-6SjMtw11)X7DHyJ z%?}b>d{bb8+XtZkA5j%|iu2Zg&$RZP%%d!=K8Gv4^aJO5Zi5|2NB~3diCN9V{}iJ9 zpA7WBNt6FWHFGOGBz%D<(@Mj{^%`BP4(l-6JCZplvs{Af84E!u^C^3N*m zi=@!=j7YD{$=DpZ*$=;FrB9S>B!|0{(QO1AS87d4;)zW*qVDBG0(+@8I$kE8mpq+@ z=)nuVsSxsNsgk7(7PkrnmEZ~;xo=KZ#mh@ZqRZ#7Ei|v@-7e4X!)ZY>%L$dY9Jgwl z@sMBAKYtQfB;WwEs7@%R(j2|t^tT>pAYXa)G7#-KH|q9vJ?I!@DcJN&o&q*hoiEBY zsFfn0bYjl049(c_v-`RzmhC-uRnH^PD+P6T`%-2px_GzxUG}VaqSlqB$J^XMXhWn; zSsfUZ9MIh=M~RR^%9_fj$`?_8rb#OgK3;H+E?4{ZTOY9sje~lwa!-|L*lU<9O;BeE zH&}q2&SirG=e&zE-1>{>SPL`_8!O06m?m+l-LanE-CELt45;8}jzkfIu!kaaVW1KC)xmG1wR?x<#@+d(MP{qYSq zOp0Swo*}rG_&O)|buY{M2X#-3IN8TY0`pHg+>IYNH6$w{LxlvhBBbgPB5I9=7f4!& zJ1V|QrgW`LIuH$a#qiaVBsNHVRi(eCo@hi{ut9}eIW*KBDjsCe@OG8kJa`n;8jV~c!*3uoW#X_y*9ir+c?RrP_4(7h#hRDa#A9ii zE_-J1MzjIH2IFnB00d*ge*jm#`h*CzWlWPe4(&wXBQicUV#5Ng(N@w7dgpP);#UFd zV(%8WuuP{0U&ULwti@~lzq`WZW^mYpBqq#D36GHwsS|YnK~e3|6gnZR87fOEvM}@E z-R@_4+iOnsMTCD?l@rf2b`E$F6u!%Le|WQJY|vFbmc!!yg@`O>{XG?hS+9Xht_#rK za;Dx z`hAx-f846v4mFo_cxTH8S{=Y-=~V(l=btz7ii%K)A(o02eS1#C4Ro?}7nFCu5T1+^ z5jCn+bIBSnXT9tkLesdVU#&YPQ1wq9qP3ssw$2Y?2d|0yYjDbimNR9f!?&T8ZR`1w ztKtSSHKNKP>=~SI{Gp*+X9WKo1a{U~gVleCT*W92SZe}w*cTc9H~k{&@!!ZPou&V>aFV{UM6Cx1-P3E z_uD?4yPen1YjR3cjoiia$d{lc1n6gU60yp}S#W)@&Nq3AiRf%$=xSJsjE?5s2g_$M zKsFeu$K$Caec?z$NF_K>?^pU#y)0u8U+(Jc-pvZ+@kPGnuGnqhdazs=L|`4{=t+lp zxwZ7w3HiClwdzP=9qISzu)DCF=2z0WbJOqX201v%FuEmPlt-QVC+tYSDz)@^h_zmp)mEh*tJDI9@T|eoA8OT>cJIgOzhWz1(odhWaBo5T&tlh+AcPU7`M3;?P$Zj&el%ykaeBaLgVp$8{` z_h4i9cc!&rR_JSq%uuQM5`x_~yJ9VJx_=z(ZHU!Gc(%QsQ-$W+Vu#Kxd-OZ>Cc{N> z#Be}yj1y_E_HhKeN?XM~Z4qLFQ(THD22ZeY{U*vct9kz=*N5Hl{@_aRn|ABDGqfp_ zUZts*mB&sD>oW{4+oyn9vr6Q;>U(o|bg|iMwjt{WpqzZ&2z$29YiRW#LjU5j&TrQg zVCc&ZN2neM1HC|{l-5tX+Kq*&8B?Q}A=RMqhTe_f?s$2MFlpm|O2KEG$ z1|02or(2OZ!?==;B88YFbup+c9fc^aQf;;hV&9-FSuP&ODaS|SjZTfz;cu2$ioSKo z?|5>jIxgJ*t)AGE=$+P$)1b8<>Sq}MRV8DQZZ9R4Vo}ysOKHwadxh0+rGk!qMRDn1 z7nn%LF|o&Rt1K*2Grd)w7+27+mxkvmULqpLpPS*NwmqcpRy;u_qrLdS&%E3*k7{?K z!uqE1FUXM6fG|(UtNzY@Si--7EO#~t{8W-(H&PV@b+`dqzg7-Rg4j~4?2l7?an>uq z@GXUu8PF}W1hQ-$p_12MEV0`_hB`JV;Uwd*>OtV()^pUQBWJI&4Ye%vYfi97>(w4N z%8e89$(&nZh~#Tv)E~6b5G@~^@P!Z>EOg?1@VQ<}CEF7o&K`c7%&ITi8SGuH-1XX*j=fKR4d@Z&G*uX-x-F*kRrcA93PWkg zSKS&rymtiUH|q5R@GtMAer99G^LX)w%STY&SQ01nT6WK~vYUM+rL?4Ll!3*hoXUNf z%FXB8BGF@rN#cdyy}A_V%_%_Xk3{=wQjf4oxjHAiWa0AAU_j`B;?%>sCtO@$m&aav zS7Xw&*Lg*etwgH8FCvE`3N0MTHdS$hkaXN5_;Z6v@u?(tJ0<8t$t_gs$zjRS$y)LX zE|2GN?y-nwRE;5p5Vzrmw3iID&W(;NisJrW$mFrm`AAr+z(q zWVJFY)z=T*H|2;#5hn&~c}muy@z>(7 zKjH3=!bk-Nmm@;PvEcqW3XSOds^Ob#aVeUcbb7qO-=0GrgRiF9lMbApP|@m{_Otc# z&OPfXTIJu)9gfSu&8fqi%4@V1f1fTOMQxV8Ev!{nRt8Ac%@qYnZF33CZzdj$E#bI` zFn_{pwRSv}0 zIBWQT1`a`?xKH-mG8<7>bD48anqmk*Di4*#Ojs+*$>E3C-%O~>yF-To{LTe+}wjR4Kp>AsWvKAi#Q2NuY40Z^Ud z>GWal!VyptSIayFr{F4`GhA%G(5AtzrejZRvzc2leZr#ycSUgdJ-7rR*ZnsFF-k+8 zJEr?DF48Ur(qk9AT+Uh_RA1sKJdTjE`yAe4n|Dl_%YSov&Xy*<+1><~} zVAi38erLe)u0{Z}fu)G3z0oW};3$5y87B{K;rzo~Y%CGiSw4g!zf(>qqsb+feh8QN zS1OoMPLQN2Hbp0>@$0X88~FQPXz=d9XSd(g#&jE{`mv4DoW{jMak9{HIOB`r(;1Lc zrhbERw68*+LYvVWw}&>?4%U915hw8{aUHGB7RO5ENL<#2Rf`+7;{;n>afRy^(eR_W zDxgq69;Cy$ReMNeecYL1tb~&}XflW{O{5Z>Px=hB$I(EEc!bzhhyI&B@{LBwFvk)NZeAntQ7mNb~5C=QcB?F|C7>;i)|7u+b^5ZnjlYSS0$i z+hkHctb-7ydm6Z@Z#h+Mry6xx%20^Y|H1`s4A>c^E~J&J|JNAI!c^BiA_$AO^%F#U z?vDMs!3cB^%p)QEzstA1Fi*{FPS&W+u3S*4{X^`STz2R80e(!k6oRXFFd4bs$-!p+ zuiC9n?~F8%z3GZVuh)Kl=OWB}Wo5GgADX^JZIyx$yNW@VM9!^BPDIX`P8c_Su0yMQ;N7d=r1VCD1o6A|IoI{uJwI=f0)p0TtW+e7}hc;R3r=z>S zo2}MsOfY@LkWaBQXqBmfny%C=(^Vx zv9Mh7>e+SME4$O$f(}wl*?ijDGDTGtXDTzc)u7YjkChos{+3A}9XZe)o}8N#ZaI7g zG!%csOj-t~UXMoYdXCD)dIU8;xHlu~wk@4<%v++yeQl>)k{3sC5y$^VzCCW0XZxHA zNL2b?^sIZNNCk)=UF!NbLsM=}UbqzXooui^cp55sHnK>hPdN%Y+os42 z!wNnUeqBDU*#WcaseO&@Ir}cu9t;2=`RqGcHiRua_zJ?J@Dc{aG>U@u-qLsDgLEXD z>jJyux+>RWEy-$pbRUBso%AUJevA>D@)DBEt32Q`f(_ST)QycjeW8LY$LDg`Ch(`a z^FD!G7&@?Lr&W6Rvf?TFAR0vn^QL~6UA)9d=?LSSeum|EewqCYVwAtSv9F0GvB|XK z3<^z=e4Y!Ni(s4jJ|0XW(9otnj0*+tP(5M-HkVxVfv`-G+~De@M(LMV=qQn{?AOW}a!>C*yi2KhM{$ub^OLTau}v2kYZ`ZU+?8 zWTR|tD|(PA3+Ib9!W!W4@~(|Rwbz(cP%sxRFKe2n(^^qvv+T*S1U!ys>GX*b<9$N} z^K_N|DW<|!UtdEU^|+8NpIG8M$NgQ)z4+*=`)SRUlqK1T!fa3QgSD*5OJik!NrIQY zCLelTs^r(y{KeNTh?dif-Ftv(7a?`txRA%JZB6o@@f)$AH!4pGse>VR^scqm52lyQ z?N{h68b!dGLT|cr7#sP5VbBQZ)y0PqeHz{ zdP{@QtVaEaE|)ZNub$pW8lG_Y3@hJG|D3^hx7_>AH*bFqN!$XL+aaP4lJy7s_+i7* zJSsbj3^p?Wz`KvHc;gbAI93)0ja!rdKT&YU8WFj{41d?X9N+k7&C=sQ|K%|13=X{t zL0E-}BMAvfhX2`~Z|CLdoGXH2uo80h@VdM?2W|z;VGs4S5G&-`fwD#JweEBCfd5&? zl&@Ai4xiLBb9R|;8ofk~1iS1lL6!ng>uE?rR+|F5CbNLUFwnuG|NaYM*F`5&|J@hZ zwlmzCo+Bdzzblno{*X>{UK*zj`3yOE;DFiHQQ8nkW!u>0)fvQfG3a6!j)RmToXnGf zONkP~t?kJsSIN`kRkBcW=Zv=<^fTB5}hr`F(>c zGz@YI91vdg$!`wAv|xXXEM1*8!jm*44s(~%Re1Y0Zu)Wh`}l0+ZZCEO&PBt&8#M;p zV97b|d-Bifs~*MHjh8B8e6t3L`eQ{0`Ee3&C9szsSkIG-eMlvRY6$<>1-NbC@_1YW zlRtx7#|1&*2C=e4SE%toQ|g~vl$a1SY7}!!lj@zylA0TMYT!qwf)-9QAG0#hGSD(2 zS93o-gfjX=S#s*OS@QS4|M=T|!roaqF?m=##WHX`=x1!m@R=2}a?l;04sCILVFeHP>2KQ-fDr^rvs{r74SSZVxHa Date: Thu, 17 Jan 2019 10:55:23 -0800 Subject: [PATCH 5/8] update ios and permissions in add role box --- ...dows-windows-defender-advanced-threat-protection.md | 3 +-- ...oles-windows-defender-advanced-threat-protection.md | 10 ++++------ 2 files changed, 5 insertions(+), 8 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md index 3702b187d3..597bef65e8 100644 --- a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md @@ -10,7 +10,6 @@ ms.sitesec: library ms.pagetype: security author: mjcaparas ms.localizationpriority: medium -ms.date: 10/03/2018 --- # Onboard non-Windows machines @@ -37,7 +36,7 @@ You'll need to take the following steps to onboard non-Windows machines: 1. In the navigation pane, select **Settings** > **Onboarding**. Make sure the third-party solution is listed. -2. Select Mac and Linux as the operating system. +2. Select **Linux, macOS, iOS and Android** as the operating system. 3. Turn on the third-party solution integration. diff --git a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md index 505e031a5a..64d6fd0116 100644 --- a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md @@ -1,6 +1,6 @@ --- title: Create and manage roles for role-based access control -description: Create roles and define the permissions assigned to the role as part of the role-based access control implimentation +description: Create roles and define the permissions assigned to the role as part of the role-based access control implementation keywords: user roles, roles, access rbac search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -11,7 +11,6 @@ ms.pagetype: security ms.author: macapara author: mjcaparas ms.localizationpriority: medium -ms.date: 09/03/2018 --- # Create and manage roles for role-based access control @@ -25,7 +24,7 @@ ms.date: 09/03/2018 ## Create roles and assign the role to an Azure Active Directory group The following steps guide you on how to create roles in Windows Defender Security Center. It assumes that you have already created Azure Active Directory user groups. -1. In the navigation pane, select **Settings > Role based access control > Roles**. +1. In the navigation pane, select **Settings > Roles**. 2. Click **Add role**. @@ -37,9 +36,8 @@ The following steps guide you on how to create roles in Windows Defender Securit - **Permissions** - **View data** - Users can view information in the portal. - - **Investigate alerts** - Users can manage alerts, initiate automated investigations, collect investigation packages, manage machine tags, and export machine timeline. - - **Approve or take action** - Users can take response actions and approve or dismiss pending remediation actions. - - **Manage system settings** - Users can configure settings, SIEM and threat intel API settings, advanced settings, preview features, and automated file uploads. + - **Alerts investigation** - Users can manage alerts, initiate automated investigations, collect investigation packages, manage machine tags, and export machine timeline. + - **Active remediation actions** - Users can take response actions and approve or dismiss pending remediation actions. - **Manage security settings** - Users can configure alert suppression settings, manage allowed/blocked lists for automation, manage folder exclusions for automation, onboard and offboard machines, and manage email notifications. 4. Click **Next** to assign the role to an Azure AD group. From e81fcf2c08ba1af48ab6b909f34fa4152a21c1ab Mon Sep 17 00:00:00 2001 From: Christopher Yoo Date: Fri, 18 Jan 2019 00:59:49 +0000 Subject: [PATCH 6/8] Updated Microsoft-DiagnosticDataViewer.md --- windows/privacy/Microsoft-DiagnosticDataViewer.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/privacy/Microsoft-DiagnosticDataViewer.md b/windows/privacy/Microsoft-DiagnosticDataViewer.md index f50049e9bc..014cf520b8 100644 --- a/windows/privacy/Microsoft-DiagnosticDataViewer.md +++ b/windows/privacy/Microsoft-DiagnosticDataViewer.md @@ -148,6 +148,9 @@ By default, the tool will show you up to 1GB or 30 days of data (whichever comes >[!IMPORTANT] >Modifying the maximum amount of diagnostic data viewable by the tool may come with performance impacts to your machine. + >[!IMPORTANT] + >If you modify the maximum data history size from a larger value to a lower value, you must turn off data viewing and turn it back on in order to reclaim disk space. + You can change the maximum data history size (in megabytes) that you can view. For example, to set the maximum data history size to 2048MB (2GB), you can run the following command. ```powershell @@ -174,6 +177,7 @@ To reset the maximum data history size back to its original 1GB default value, r PS C:\> Set-DiagnosticStoreCapacity -Size 1024 -Time 720 ``` +When resetting the size of your data history to a lower value, be sure to turn off data viewing and turn it back on in order to reclaim disk space. ## Related Links - [Module in PowerShell Gallery](https://www.powershellgallery.com/packages/Microsoft.DiagnosticDataViewer) From c6c4021695fa61e3cb1e23e84730093513592d96 Mon Sep 17 00:00:00 2001 From: Liza Poggemeyer Date: Fri, 18 Jan 2019 13:45:25 +0000 Subject: [PATCH 7/8] Merged PR 13845: New video and blog post for WaaS landing page --- windows/deployment/update/windows-as-a-service.md | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/windows/deployment/update/windows-as-a-service.md b/windows/deployment/update/windows-as-a-service.md index 00e3d4fd12..9412c8eaa1 100644 --- a/windows/deployment/update/windows-as-a-service.md +++ b/windows/deployment/update/windows-as-a-service.md @@ -6,6 +6,7 @@ ms.topic: landing-page ms.manager: elizapo author: lizap ms.author: elizapo +ms.date: 01/17/2019 ms.localizationpriority: high --- # Windows as a service @@ -16,13 +17,14 @@ Find the tools and resources you need to help deploy and support Windows as a se Find the latest and greatest news on Windows 10 deployment and servicing. -**Windows 10 monthly updates** -> [!VIDEO https://www.youtube-nocookie.com/embed/BwB10v55WSk] +**Working to WIndows updates clear and transparent** +> [!VIDEO https://www.youtube-nocookie.com/embed/u5P20y39DrA] -Windows 10 is the most secure version of Windows yet. Learn what updates we release and when we release them, so you understand the efforts we take to keep your digital life safe and secure. +Everyone wins when transparency is a top priority. We want you to know when updates are available, as well as alert you to any potential issues you may encounter during or after you install an update. The Windows update history page is for anyone looking to gain an immediate, precise understanding of particular Windows update issues. The latest news:
    +
  • Application compatibility in the Windows ecosystem - January 15, 2019
  • Windows monthly security and quality updates overview - January 10, 2019
  • Driver quality in the Windows ecosystem - December 19, 2018
  • Modern Desktop Podcast - Episode 001 – Windows 10 Monthly Quality Updates - December 18, 2018
  • @@ -40,6 +42,7 @@ The latest news:
  • Helping customers shift to a modern desktop - September 6, 2018
  • Windows Update for Business & Windows Analytics: a real-world experience - September 5, 2018
  • What's next for Windows 10 and Windows Server quality updates - August 16, 2018 +
  • Windows 10 monthly updates - August 1, 2018 (**video**)
  • Windows 10 update servicing cadence - August 1, 2018
  • Windows 10 quality updates explained and the end of delta updates - July 11, 2018
  • AI Powers Windows 10 April 2018 Update Rollout - June 14, 2018 From 3a467f5d4a01a7e276a5e4d8030c74904419bd2f Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Fri, 18 Jan 2019 05:48:59 -0800 Subject: [PATCH 8/8] remove en-us from URLs --- mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md index a73852f3e2..8cf42399fe 100644 --- a/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md +++ b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md @@ -15,7 +15,7 @@ This topic describes the process for upgrading the Microsoft BitLocker Administr ### Before you begin #### Download the July 2018 servicing release -[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=57157) +[Desktop Optimization Pack](https://www.microsoft.com/download/details.aspx?id=57157) #### Verify the installation documentaion Verify you have a current documentation of your MBAM environment, including all server names, database names, service accounts and their passwords. @@ -26,7 +26,7 @@ Verify you have a current documentation of your MBAM environment, including all Note: You will not see an option to remove the Databases; this is expected.   2. Install 2.5 SP1 (Located with MDOP - Microsoft Desktop Optimization Pack 2015 from the Volume Licensing Service Center site: 3. Do not configure it at this time  -4. Install the July 2018 Rollup: https://www.microsoft.com/en-us/download/details.aspx?id=57157 +4. Install the July 2018 Rollup: https://www.microsoft.com/download/details.aspx?id=57157 5. Using the MBAM Configurator; re-add the Reports role 6. This will configure the SSRS connection using the latest MBAM code from the rollup  7. Using the MBAM Configurator; re-add the SQL Database role on the SQL Server. @@ -37,7 +37,7 @@ Note: You will not see an option to remove the Databases; this is expected.   1. Using the MBAM Configurator; remove the Admin and Self Service Portals from the IIS server 2. Install MBAM 2.5 SP1 3. Do not configure it at this time   -4. Install the July 2018 Rollup on the IIS server(https://www.microsoft.com/en-us/download/details.aspx?id=57157) +4. Install the July 2018 Rollup on the IIS server(https://www.microsoft.com/download/details.aspx?id=57157) 5. Using the MBAM Configurator; re-add the Admin and Self Service Portals to the IIS server  6. This will configure the sites using the latest MBAM code from the July 2018 Rollup - Open an elevated command prompt, Type: **IISRESET** and Hit Enter.