From e8b352ef686b7df8c6af773b737a1d71d691df9f Mon Sep 17 00:00:00 2001
From: kevincol
Date: Fri, 4 Oct 2019 17:57:38 -0700
Subject: [PATCH 01/78] Update hololens-calibration.md
---
devices/hololens/hololens-calibration.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens-calibration.md b/devices/hololens/hololens-calibration.md
index 1296d0f4bd..a593ff68d5 100644
--- a/devices/hololens/hololens-calibration.md
+++ b/devices/hololens/hololens-calibration.md
@@ -97,7 +97,7 @@ You can also disable the calibration prompt by following these steps:
1. Turn off **When a new person uses this HoloLens, automatically ask to run eye calibration**.
> [!IMPORTANT]
-> Please understand that this setting may adversely affect hologram rendering quality and comfort.
+> Please understand that this setting may adversely affect hologram rendering quality and comfort. If there is an immersive application that is using eye tracking, for instance text scrolling, then that feature will no longer work.
### HoloLens 2 eye-tracking technology
From 8c3735fb936d3299c212fa5934f15e7a88bb830e Mon Sep 17 00:00:00 2001
From: Daniel Simpson
Date: Tue, 15 Oct 2019 09:48:32 -0700
Subject: [PATCH 02/78] Update hololens-calibration.md
minor edits and including Teresa's change
---
devices/hololens/hololens-calibration.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens-calibration.md b/devices/hololens/hololens-calibration.md
index a593ff68d5..f867bf325c 100644
--- a/devices/hololens/hololens-calibration.md
+++ b/devices/hololens/hololens-calibration.md
@@ -97,7 +97,7 @@ You can also disable the calibration prompt by following these steps:
1. Turn off **When a new person uses this HoloLens, automatically ask to run eye calibration**.
> [!IMPORTANT]
-> Please understand that this setting may adversely affect hologram rendering quality and comfort. If there is an immersive application that is using eye tracking, for instance text scrolling, then that feature will no longer work.
+> This setting may adversely affect hologram rendering quality and comfort. When you turn off this setting, features that depend on eye tracking (such as text scrolling) no longer work in immersive applications.
### HoloLens 2 eye-tracking technology
From 68ec900e076f8601cc17d6ee323bfefb68306471 Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Mon, 11 Nov 2019 14:37:15 -0800
Subject: [PATCH 03/78] Update hololens2-language-support.md
Removed es-MX from support list and corrected some formatting issues.
---
devices/hololens/hololens2-language-support.md | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index 760880135d..e38fbd5569 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -17,7 +17,7 @@ appliesto:
# Supported languages for HoloLens 2
-HoloLens 2 supports the following languages. This support includes voice commands and dictation features.
+HoloLens 2 supports the following languages, including voice commands and dictation features.
- Chinese Simplified (China)
- English (Australia)
@@ -29,17 +29,17 @@ HoloLens 2 supports the following languages. This support includes voice command
- German (Germany)
- Italian (Italy)
- Japanese (Japan)
-- Spanish (Mexico)
- Spanish (Spain)
-Windows Mixed Reality is also available in the following languages. However, this support does not include speech commands or dictation features.
+HoloLens 2 is also available in the following languages. However, this support does not include speech commands or dictation features.
- Chinese Traditional (Taiwan and Hong Kong)
- Dutch (Netherlands)
- Korean (Korea)
-- Changing language or keyboard
> [!NOTE]
> Your speech and dictation language depends on the Windows display language.
>
+# Changing language or keyboard
+
To change the Windows display language, region, or keyboard settings, use the start gesture to open the **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
From 835c65f895bbcdb08cb374e635f5e2647d9215f6 Mon Sep 17 00:00:00 2001
From: DanPandre <54847950+DanPandre@users.noreply.github.com>
Date: Tue, 12 Nov 2019 10:01:40 -0500
Subject: [PATCH 04/78] Clarify impacts of Intune auto-enrollment
---
devices/surface-hub/surface-hub-2s-manage-intune.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface-hub/surface-hub-2s-manage-intune.md b/devices/surface-hub/surface-hub-2s-manage-intune.md
index e71d37def0..dc071e3753 100644
--- a/devices/surface-hub/surface-hub-2s-manage-intune.md
+++ b/devices/surface-hub/surface-hub-2s-manage-intune.md
@@ -28,7 +28,7 @@ Surface Hub 2S allows IT administrators to manage settings and policies using a
### Auto registration — Azure Active Directory Affiliated
-When affiliating Surface Hub 2S with a tenant that has Intune auto enrollment enabled, the device will automatically enroll with Intune. For more information, refer to [Intune enrollment methods for Windows devices](https://docs.microsoft.com/intune/enrollment/windows-enrollment-methods).
+During the initial setup process, when choosing to affiliate with an Azure AD tenant that has Intune auto enrollment enabled, the device will automatically enroll with Intune. For more information, refer to [Intune enrollment methods for Windows devices](https://docs.microsoft.com/intune/enrollment/windows-enrollment-methods). Azure AD affiliation and Intune auto enrollment is required for the Surface Hub to be a "compliant device" in Intune.
## Windows 10 Team Edition settings
From e457ad0cfa1648e21b0ec57f196693c04ba8e1b3 Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Tue, 12 Nov 2019 12:48:54 -0800
Subject: [PATCH 05/78] Update hololens2-language-support.md
Added more verbose instructions for changing language settings and what is impacted by the language settings.
---
.../hololens/hololens2-language-support.md | 27 +++++++++++++++++--
1 file changed, 25 insertions(+), 2 deletions(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index e38fbd5569..091c9dd907 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -17,7 +17,7 @@ appliesto:
# Supported languages for HoloLens 2
-HoloLens 2 supports the following languages, including voice commands and dictation features.
+HoloLens 2 supports the following languages, including voice commands and dictation features, keyboard layouts, and OCR recognition within apps.
- Chinese Simplified (China)
- English (Australia)
@@ -42,4 +42,27 @@ HoloLens 2 is also available in the following languages. However, this support d
>
# Changing language or keyboard
-To change the Windows display language, region, or keyboard settings, use the start gesture to open the **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
+HoloLens is configured for a language and region during set up. You can change the configuration under the “Time & language” section of Settings app.
+
+## To change the Windows display language
+
+1. Go to **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
+2. Choose a language from the **Windows display language** menu.
+
+If the supported language you’re looking for is not in the menu, use the **Add a language button** in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
+
+Changing Windows display language will:
+
+- Change the UI text language for Windows and apps (for apps that support localization).
+- Change the supported speech language for speech features in Windows and apps.
+- Add the default keyboard layout for the language.
+
+## To change the keyboard layout
+
+To add or remove a keyboard layout, go to **Start menu** > **Settings** > **Time & language** > **Keyboard**.
+
+When there is more than one keyboard layout added, you can switch between different keyboard layouts using the Layout key in the lower right corner of the on-screen keyboard.
+
+> [!NOTE]
+> While you can use the on-screen keyboard to enter text that requires Input Method Editor (IME) such as Chinese, using a Bluetooth hardware keyboard with IME is not currently supported. When a on-screen keyboard layout uses IME, you can continue to use a Bluetooth keyboard to type in English. To toggle a hardware keyboard to type in English, press the ~ key.
+>
From 42cf908bdd60cb05a92587fc38239adf285a8666 Mon Sep 17 00:00:00 2001
From: DanPandre <54847950+DanPandre@users.noreply.github.com>
Date: Wed, 13 Nov 2019 09:25:49 -0500
Subject: [PATCH 06/78] Made language closer to original
---
devices/surface-hub/surface-hub-2s-manage-intune.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface-hub/surface-hub-2s-manage-intune.md b/devices/surface-hub/surface-hub-2s-manage-intune.md
index dc071e3753..d17fc2dfb1 100644
--- a/devices/surface-hub/surface-hub-2s-manage-intune.md
+++ b/devices/surface-hub/surface-hub-2s-manage-intune.md
@@ -28,7 +28,7 @@ Surface Hub 2S allows IT administrators to manage settings and policies using a
### Auto registration — Azure Active Directory Affiliated
-During the initial setup process, when choosing to affiliate with an Azure AD tenant that has Intune auto enrollment enabled, the device will automatically enroll with Intune. For more information, refer to [Intune enrollment methods for Windows devices](https://docs.microsoft.com/intune/enrollment/windows-enrollment-methods). Azure AD affiliation and Intune auto enrollment is required for the Surface Hub to be a "compliant device" in Intune.
+During the initial setup process, when affiliating a Surface Hub with an Azure AD tenant that has Intune auto enrollment enabled, the device will automatically enroll with Intune. For more information, refer to [Intune enrollment methods for Windows devices](https://docs.microsoft.com/intune/enrollment/windows-enrollment-methods). Azure AD affiliation and Intune auto enrollment is required for the Surface Hub to be a "compliant device" in Intune.
## Windows 10 Team Edition settings
From f874619783a0bba271b202a3750ce387d2f2c4b5 Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Wed, 13 Nov 2019 17:42:49 -0800
Subject: [PATCH 07/78] Update devices/hololens/hololens2-language-support.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
devices/hololens/hololens2-language-support.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index 091c9dd907..c58b778d48 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -46,7 +46,7 @@ HoloLens is configured for a language and region during set up. You can change t
## To change the Windows display language
-1. Go to **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
+1. Go to the **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
2. Choose a language from the **Windows display language** menu.
If the supported language you’re looking for is not in the menu, use the **Add a language button** in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
From 2b0342a8dbcf19323c382a124d152dc41fb791ff Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Wed, 13 Nov 2019 17:43:10 -0800
Subject: [PATCH 08/78] Update devices/hololens/hololens2-language-support.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
devices/hololens/hololens2-language-support.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index c58b778d48..9e916ea3a5 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -51,7 +51,7 @@ HoloLens is configured for a language and region during set up. You can change t
If the supported language you’re looking for is not in the menu, use the **Add a language button** in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
-Changing Windows display language will:
+Changing the Windows display language will:
- Change the UI text language for Windows and apps (for apps that support localization).
- Change the supported speech language for speech features in Windows and apps.
From 869852022d4750d3a9c7d328c231041f3d4af0f2 Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Wed, 13 Nov 2019 17:43:27 -0800
Subject: [PATCH 09/78] Update devices/hololens/hololens2-language-support.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
devices/hololens/hololens2-language-support.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index 9e916ea3a5..2aad87d133 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -61,7 +61,7 @@ Changing the Windows display language will:
To add or remove a keyboard layout, go to **Start menu** > **Settings** > **Time & language** > **Keyboard**.
-When there is more than one keyboard layout added, you can switch between different keyboard layouts using the Layout key in the lower right corner of the on-screen keyboard.
+When there is more than one keyboard layout added, you can switch between different keyboard layouts using the **Layout** key in the lower right corner of the on-screen keyboard.
> [!NOTE]
> While you can use the on-screen keyboard to enter text that requires Input Method Editor (IME) such as Chinese, using a Bluetooth hardware keyboard with IME is not currently supported. When a on-screen keyboard layout uses IME, you can continue to use a Bluetooth keyboard to type in English. To toggle a hardware keyboard to type in English, press the ~ key.
From ff03f853808631fe17940678a2b436649e7fa6e2 Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Wed, 13 Nov 2019 17:43:42 -0800
Subject: [PATCH 10/78] Update devices/hololens/hololens2-language-support.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
devices/hololens/hololens2-language-support.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index 2aad87d133..d2b5cacedc 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -64,5 +64,5 @@ To add or remove a keyboard layout, go to **Start menu** > **Settings** > **Time
When there is more than one keyboard layout added, you can switch between different keyboard layouts using the **Layout** key in the lower right corner of the on-screen keyboard.
> [!NOTE]
-> While you can use the on-screen keyboard to enter text that requires Input Method Editor (IME) such as Chinese, using a Bluetooth hardware keyboard with IME is not currently supported. When a on-screen keyboard layout uses IME, you can continue to use a Bluetooth keyboard to type in English. To toggle a hardware keyboard to type in English, press the ~ key.
+> While you can use the on-screen keyboard to enter text that requires Input Method Editor (IME) such as Chinese, using a Bluetooth hardware keyboard with IME is not currently supported. When a on-screen keyboard layout uses IME, you can continue to use a Bluetooth keyboard to type in English. To toggle a hardware keyboard to type in English, press the **~** key.
>
From 60933c03e48c458057e07f1a1544ba2d05568d1f Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Mon, 2 Dec 2019 13:55:41 -0800
Subject: [PATCH 11/78] Update devices/hololens/hololens2-language-support.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
devices/hololens/hololens2-language-support.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index d2b5cacedc..e3b6892dee 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -49,7 +49,7 @@ HoloLens is configured for a language and region during set up. You can change t
1. Go to the **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
2. Choose a language from the **Windows display language** menu.
-If the supported language you’re looking for is not in the menu, use the **Add a language button** in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
+If the supported language you’re looking for is not in the menu, use the **Add a language** button in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
Changing the Windows display language will:
From b19905714ec134edbfa6e08c016702720bc4adea Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Mon, 2 Dec 2019 15:53:40 -0800
Subject: [PATCH 12/78] Update hololens2-language-support.md
Responding to Teresa's feedback
---
.../hololens/hololens2-language-support.md | 29 +++++++++++--------
1 file changed, 17 insertions(+), 12 deletions(-)
diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md
index e3b6892dee..d139119708 100644
--- a/devices/hololens/hololens2-language-support.md
+++ b/devices/hololens/hololens2-language-support.md
@@ -42,27 +42,32 @@ HoloLens 2 is also available in the following languages. However, this support d
>
# Changing language or keyboard
-HoloLens is configured for a language and region during set up. You can change the configuration under the “Time & language” section of Settings app.
+The setup process configures your HoloLens for a region and language. You can change this configuration by using the **Time & language** section of **Settings**.
## To change the Windows display language
-1. Go to the **Start** menu, and then select **Settings** > **Time and Language** > **Language**.
-2. Choose a language from the **Windows display language** menu.
+1. Go to the **Start** menu, and then select **Settings** > **Time and language** > **Language**.
+2. Select **Windows display language**, and then select a language.
-If the supported language you’re looking for is not in the menu, use the **Add a language** button in the **Preferred languages** section on the page to search for and add the language, then check in the **Windows display language menu** again.
+If the supported language you’re looking for is not in the menu, follow these steps:
-Changing the Windows display language will:
+1. Under **Preferred languages** select **Add a language**.
+2. Search for and add the language.
+3. Select the **Windows display language** menu again and choose the language you added.
-- Change the UI text language for Windows and apps (for apps that support localization).
-- Change the supported speech language for speech features in Windows and apps.
-- Add the default keyboard layout for the language.
+The Windows display language affects the following settings for Windows and for apps that support localization:
+
+- The user interface text language.
+- The speech language.
+- The default layout of the on-screen keyboard.
## To change the keyboard layout
-To add or remove a keyboard layout, go to **Start menu** > **Settings** > **Time & language** > **Keyboard**.
+To add or remove a keyboard layout, open the **Start** menu and then select **Settings** > **Time & language** > **Keyboard**.
-When there is more than one keyboard layout added, you can switch between different keyboard layouts using the **Layout** key in the lower right corner of the on-screen keyboard.
+If your HoloLens has more than one keyboard layout, use the **Layout** key to switch between them. The **Layout** key is in the lower right corner of the on-screen keyboard.
> [!NOTE]
-> While you can use the on-screen keyboard to enter text that requires Input Method Editor (IME) such as Chinese, using a Bluetooth hardware keyboard with IME is not currently supported. When a on-screen keyboard layout uses IME, you can continue to use a Bluetooth keyboard to type in English. To toggle a hardware keyboard to type in English, press the **~** key.
->
+> The on-screen keyboard can use Input Method Editor (IME) to enter characters in languages such as Chinese. However, HoloLens does not support external Bluetooth keyboards that use IME.
+>
+> While you use IME with the on-screen keyboard, you can continue to use a Bluetooth keyboard to type in English. To switch between keyboards, press ~.
From 26b785174460fe100b5a1d5a6c21585c4232ddc2 Mon Sep 17 00:00:00 2001
From: Jose Ortega
Date: Wed, 4 Dec 2019 14:27:15 -0600
Subject: [PATCH 13/78] New Note added from #5469
---
.../threat-protection/microsoft-defender-atp/live-response.md | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 151cc9a4d1..1493afdbfe 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -50,6 +50,10 @@ You'll need to enable the live response capability in the [Advanced features set
>[!WARNING]
>Allowing the use of unsigned scripts may increase your exposure to threats.
+
+ > [!ÏMPORTNAT]
+ > The current implementation of the Live Response within Defender ATP the option "Upload file to library" button function is not available to those with only delegated permissions via DATP/RBAC roles.
+
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
- **Ensure that you have the appropriate permissions**
From 42cc42f33a6ef5c5b13e5d1562b6ff8600f2a4f9 Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Wed, 4 Dec 2019 12:54:03 -0800
Subject: [PATCH 14/78] Update live-response.md
---
.../threat-protection/microsoft-defender-atp/live-response.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 1493afdbfe..afa98aa766 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -51,7 +51,7 @@ You'll need to enable the live response capability in the [Advanced features set
>Allowing the use of unsigned scripts may increase your exposure to threats.
- > [!ÏMPORTNAT]
+ > [!ÏMPORTANT]
> The current implementation of the Live Response within Defender ATP the option "Upload file to library" button function is not available to those with only delegated permissions via DATP/RBAC roles.
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
From a271cb85322b4eae59e96fd33cd68d5e3d8b3f82 Mon Sep 17 00:00:00 2001
From: Jose Ortega
Date: Wed, 4 Dec 2019 15:30:16 -0600
Subject: [PATCH 15/78] Suggestion taken
---
.../threat-protection/microsoft-defender-atp/live-response.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 1493afdbfe..3c64fbaaa4 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -52,7 +52,7 @@ You'll need to enable the live response capability in the [Advanced features set
> [!ÏMPORTNAT]
- > The current implementation of the Live Response within Defender ATP the option "Upload file to library" button function is not available to those with only delegated permissions via DATP/RBAC roles.
+ > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
From b0566d36e499f118cd7a71e85598c26cea5b9fbe Mon Sep 17 00:00:00 2001
From: Jose Ortega
Date: Wed, 4 Dec 2019 15:33:11 -0600
Subject: [PATCH 16/78] Suggestion taken
---
.../threat-protection/microsoft-defender-atp/live-response.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index afa98aa766..2c8fd39528 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -52,7 +52,7 @@ You'll need to enable the live response capability in the [Advanced features set
> [!ÏMPORTANT]
- > The current implementation of the Live Response within Defender ATP the option "Upload file to library" button function is not available to those with only delegated permissions via DATP/RBAC roles.
+ > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
From 28b3ebaddf6cdc56fa11c932a9233cac2e174d1a Mon Sep 17 00:00:00 2001
From: Jose Gabriel Ortega Castro
Date: Thu, 5 Dec 2019 10:31:52 -0600
Subject: [PATCH 17/78] Update
windows/security/threat-protection/microsoft-defender-atp/live-response.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../threat-protection/microsoft-defender-atp/live-response.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 2c8fd39528..0b762a0b99 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -51,7 +51,7 @@ You'll need to enable the live response capability in the [Advanced features set
>Allowing the use of unsigned scripts may increase your exposure to threats.
- > [!ÏMPORTANT]
+ > [!IMPORTANT]
> The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
@@ -254,4 +254,3 @@ Each command is tracked with full details such as:
-
From 4bad6d069f5f0bdcc27e54b5b11ddfbf53ff804a Mon Sep 17 00:00:00 2001
From: Todd Lyon <19413953+tmlyon@users.noreply.github.com>
Date: Tue, 10 Dec 2019 16:55:32 -0800
Subject: [PATCH 18/78] Update hololens-cortana.md
Updated phrasing for follow and microphone button to resolve some localization issues with the voice commands.
---
devices/hololens/hololens-cortana.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/devices/hololens/hololens-cortana.md b/devices/hololens/hololens-cortana.md
index 0729485e7d..d7ca664169 100644
--- a/devices/hololens/hololens-cortana.md
+++ b/devices/hololens/hololens-cortana.md
@@ -56,7 +56,7 @@ To use these commands, gaze at a 3D object, hologram, or app window.
| "Face me" | Turn it to face you |
| "Move this" | Move it (follow your gaze) |
| "Close" | Close it |
-| "Follow" / "Stop following" | Make it follow you as you move around |
+| "Follow me" / "Stop following" | Make it follow you as you move around |
### See it, say it
@@ -64,7 +64,7 @@ Many buttons and other elements on HoloLens also respond to your voice—for exa
### Dictation mode
-Tired of typing? Switch to dictation mode any time that the holographic keyboard is active. To get started, select the microphone icon or say "Start dictating." To stop dictating, select **Done** or say "Stop dictating." To delete what you just dictated, say "Delete that."
+Tired of typing? Switch to dictation mode any time that the holographic keyboard is active. To get started, select the microphone button or say "Start dictating." To stop dictating, select the button again or say "Stop dictating." To delete what you just dictated, say "Delete that."
> [!NOTE]
> To use dictation mode, you have to have an internet connection.
From 1fd9c5a9cd785ff6314c71a848dcd1c11a37d1be Mon Sep 17 00:00:00 2001
From: Deland-Han
Date: Wed, 11 Dec 2019 11:25:46 +0800
Subject: [PATCH 19/78] finish
---
devices/surface-hub/TOC.md | 2 ++
devices/surface-hub/index.md | 1 -
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/devices/surface-hub/TOC.md b/devices/surface-hub/TOC.md
index c0de52de12..59d2d76a0d 100644
--- a/devices/surface-hub/TOC.md
+++ b/devices/surface-hub/TOC.md
@@ -7,6 +7,7 @@
### [Surface Hub 2S tech specs](surface-hub-2s-techspecs.md)
### [Operating system essentials (Surface Hub)](differences-between-surface-hub-and-windows-10-enterprise.md)
### [Adjust Surface Hub 2S brightness, volume, and input](surface-hub-2s-onscreen-display.md)
+### [Use Microsoft Whiteboard on a Surface Hub](https://support.office.com/article/use-microsoft-whiteboard-on-a-surface-hub-5c594985-129d-43f9-ace5-7dee96f7621d)
## Plan
### [Surface Hub 2S Site Readiness Guide](surface-hub-2s-site-readiness-guide.md)
@@ -58,6 +59,7 @@
### [Operating system essentials (Surface Hub)](differences-between-surface-hub-and-windows-10-enterprise.md)
### [Technical information for 55” Microsoft Surface Hub](surface-hub-technical-55.md)
### [Technical information for 84” Microsoft Surface Hub](surface-hub-technical-84.md)
+### [Use Microsoft Whiteboard on a Surface Hub](https://support.office.com/article/use-microsoft-whiteboard-on-a-surface-hub-5c594985-129d-43f9-ace5-7dee96f7621d)
## Plan
### [Prepare your environment for Microsoft Surface Hub](prepare-your-environment-for-surface-hub.md)
diff --git a/devices/surface-hub/index.md b/devices/surface-hub/index.md
index e4fa9986f3..f60588a000 100644
--- a/devices/surface-hub/index.md
+++ b/devices/surface-hub/index.md
@@ -30,7 +30,6 @@ Surface Hub 2S is an all-in-one digital interactive whiteboard, meetings platfor
Behind the design: Surface Hub 2S
What's new in Surface Hub 2S
Operating system essentials
- Enable Microsoft Whiteboard on Surface Hub
From 217842d6912a4782bad64c8ea444e4f70c9a1370 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Wed, 11 Dec 2019 14:58:07 +0530
Subject: [PATCH 20/78] removed the word as meeting
as per the user report #5646 .
I removed the following word which written two times
as meeting
---
windows/security/threat-protection/fips-140-validation.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/security/threat-protection/fips-140-validation.md b/windows/security/threat-protection/fips-140-validation.md
index 32bbf69dc2..c91f55f5cf 100644
--- a/windows/security/threat-protection/fips-140-validation.md
+++ b/windows/security/threat-protection/fips-140-validation.md
@@ -57,7 +57,7 @@ The cadence for starting module validation aligns with the feature updates of Wi
### What is the difference between “FIPS 140 validated” and “FIPS 140 compliant”?
-“FIPS 140 validated” means that the cryptographic module, or a product that embeds the module, has been validated (“certified”) by the CMVP as meeting as meeting the FIPS 140-2 requirements. “FIPS 140 compliant” is an industry term for IT products that rely on FIPS 140 validated products for cryptographic functionality.
+“FIPS 140 validated” means that the cryptographic module, or a product that embeds the module, has been validated (“certified”) by the CMVP as meeting the FIPS 140-2 requirements. “FIPS 140 compliant” is an industry term for IT products that rely on FIPS 140 validated products for cryptographic functionality.
### I need to know if a Windows service or application is FIPS 140-2 validated.
@@ -7191,4 +7191,4 @@ Version 6.3.9600
\[[SP 800-57](http://csrc.nist.gov/publications/pubssps.html#800-57-part1)\] - Recommendation for Key Management – Part 1: General (Revised)
-\[[SP 800-131A](http://csrc.nist.gov/publications/nistpubs/800-131a/sp800-131a.pdf)\] - Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths
\ No newline at end of file
+\[[SP 800-131A](http://csrc.nist.gov/publications/nistpubs/800-131a/sp800-131a.pdf)\] - Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths
From 0792939c1918f90a1305030c2ddc279dd3fb9f96 Mon Sep 17 00:00:00 2001
From: Deland-Han
Date: Wed, 11 Dec 2019 17:39:09 +0800
Subject: [PATCH 21/78] finish
---
mdop/mbam-v25/deploy-mbam.md | 3 ++-
mdop/mbam-v25/troubleshooting-mbam-installation.md | 3 ++-
windows/client-management/introduction-page-file.md | 2 +-
3 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/mdop/mbam-v25/deploy-mbam.md b/mdop/mbam-v25/deploy-mbam.md
index eefee88047..a921105176 100644
--- a/mdop/mbam-v25/deploy-mbam.md
+++ b/mdop/mbam-v25/deploy-mbam.md
@@ -1,13 +1,14 @@
---
title: Deploying MBAM 2.5 in a stand-alone configuration
description: Introducing how to deploy MBAM 2.5 in a stand-alone configuration.
-author: delhan
+author: Deland-Han
ms.reviewer: dcscontentpm
manager: dansimp
ms.author: delhan
ms.sitesec: library
ms.prod: w10
ms.date: 09/16/2019
+manager: dcscontentpm
---
# Deploying MBAM 2.5 in a standalone configuration
diff --git a/mdop/mbam-v25/troubleshooting-mbam-installation.md b/mdop/mbam-v25/troubleshooting-mbam-installation.md
index d58974a50e..b38d7b7818 100644
--- a/mdop/mbam-v25/troubleshooting-mbam-installation.md
+++ b/mdop/mbam-v25/troubleshooting-mbam-installation.md
@@ -1,13 +1,14 @@
---
title: Troubleshooting MBAM 2.5 installation problems
description: Introducing how to troubleshoot MBAM 2.5 installation problems.
-author: delhan
+author: Deland-Han
ms.reviewer: dcscontentpm
manager: dansimp
ms.author: delhan
ms.sitesec: library
ms.prod: w10
ms.date: 09/16/2019
+manager: dcscontentpm
---
# Troubleshooting MBAM 2.5 installation problems
diff --git a/windows/client-management/introduction-page-file.md b/windows/client-management/introduction-page-file.md
index 662ae5f90e..cee81bcd72 100644
--- a/windows/client-management/introduction-page-file.md
+++ b/windows/client-management/introduction-page-file.md
@@ -8,7 +8,7 @@ author: Deland-Han
ms.localizationpriority: medium
ms.author: delhan
ms.reviewer: greglin
-manager: willchen
+manager: dcscontentpm
---
# Introduction to page files
From 214d87b5d68c42773ad84014057f52fce49c8ccc Mon Sep 17 00:00:00 2001
From: Jean-Robert Jean-Simon
Date: Wed, 11 Dec 2019 11:57:56 +0100
Subject: [PATCH 22/78] Add a note about OEM Authorization and Delegated Admin
Permissions (DAP)
It is just a clarification for several customers who are afraid about Delegated Admin Permissions (DAP) could be part of the OEM Authorization.
---
windows/deployment/windows-autopilot/registration-auth.md | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/windows/deployment/windows-autopilot/registration-auth.md b/windows/deployment/windows-autopilot/registration-auth.md
index 9ae9105cbd..3c6dfece7c 100644
--- a/windows/deployment/windows-autopilot/registration-auth.md
+++ b/windows/deployment/windows-autopilot/registration-auth.md
@@ -9,7 +9,8 @@ ms.mktglfcycl: deploy
ms.localizationpriority: medium
ms.sitesec: library
ms.pagetype: deploy
-audience: itpro
author: greg-lindsay
+audience: itpro
+author: greg-lindsay
ms.author: greglin
ms.collection: M365-modern-desktop
ms.topic: article
@@ -75,6 +76,8 @@ Each OEM has a unique link to provide to their respective customers, which the O
4. The OEM can use the Validate Device Submission Data API to verify the consent has completed. This API is discussed in the latest version of the API Whitepaper, p. 14ff [https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx](https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx). **Note**: this link is only accessible by Microsoft Device Partners. As discussed in this whitepaper, it’s a best practice recommendation for OEM partners to run the API check to confirm they’ve received customer consent before attempting to register devices, thus avoiding errors in the registration process.
+ NOTE: During the OEM authorization registration process, no delegated admin permissions are granted to the OEM.
+
## Summary
At this stage of the process, Microsoft is no longer involved; the consent exchange happens directly between the OEM and the customer. And, it all happens instantaneously - as quickly as buttons are clicked.
From d5b401f302f2edbe9cb258153c542cb822ab0039 Mon Sep 17 00:00:00 2001
From: Jean-Robert Jean-Simon
Date: Wed, 11 Dec 2019 12:28:22 +0100
Subject: [PATCH 23/78] Add a Q&A for Delegated Admin Permissions for OEM
It is just a clarification for several customers who are afraid about Delegated Admin Permissions (DAP) could be part of the OEM Authorization.
---
windows/deployment/windows-autopilot/autopilot-faq.md | 1 +
1 file changed, 1 insertion(+)
diff --git a/windows/deployment/windows-autopilot/autopilot-faq.md b/windows/deployment/windows-autopilot/autopilot-faq.md
index b527168e97..94f7002df9 100644
--- a/windows/deployment/windows-autopilot/autopilot-faq.md
+++ b/windows/deployment/windows-autopilot/autopilot-faq.md
@@ -38,6 +38,7 @@ A [glossary](#glossary) of abbreviations used in this topic is provided at the e
| How can I test the Windows Autopilot CSV file in the Partner Center? | Only CSP Partners have access to the Partner Center portal. If you are a CSP, you can create a Sales agent user account which has access to “Devices” for testing the file. This can be done today in the Partner Center.
Go [here](https://msdn.microsoft.com/partner-center/create-user-accounts-and-set-permissions) for more information. |
| Must I become a Cloud Solution Provider (CSP) to participate in Windows Autopilot? | Top volume OEMs do not, as they can use the OEM Direct API. All others who choose to use MPC to register devices must become CSPs in order to access MPC. |
| Do the different CSP levels have all the same capabilities when it comes to Windows Autopilot? | For purposes of Windows Autopilot, there are three different types of CSPs, each with different levels of authority an access:
1. Direct CSP: Gets direct authorization from the customer to register devices.
2. Indirect CSP Provider: Gets implicit permission to register devices through the relationship their CSP Reseller partner has with the customer. Indirect CSP Providers register devices through Microsoft Partner Center.
3. Indirect CSP Reseller: Gets direct authorization from the customer to register devices. At the same time, their indirect CSP Provider partner also gets authorization, which mean that either the Indirect Provider or the Indirect Reseller can register devices for the customer. However, the Indirect CSP Reseller must register devices through the MPC UI (manually uploading CSV file), whereas the Indirect CSP Provider has the option to register devices using the MPC APIs. |
+| Does the OEM authorization grant Delegated Admin Permissions (DAP) on the customer tenant? | No. The OEM authorization gives only the capability to register devices. |
## Manufacturing
From d7feac8adc09688f0f7b5108fc9b9999e1f5facc Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Wed, 11 Dec 2019 20:24:12 +0530
Subject: [PATCH 24/78] Renamed Enteprise to Enterprise
as per user report #5654.
i renamed Enteprise to Enterprise
---
windows/client-management/mdm/device-update-management.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/device-update-management.md b/windows/client-management/mdm/device-update-management.md
index 13a78b2032..414a9c8515 100644
--- a/windows/client-management/mdm/device-update-management.md
+++ b/windows/client-management/mdm/device-update-management.md
@@ -635,7 +635,7 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
> This policy is available on Windows 10 Pro, Windows 10 Enterprise, Windows 10 Education, and Windows 10 Mobile Enterprise
> [!Important]
-> Starting in Windows 10, version 1703 this policy is not supported in Windows 10 Mobile Enteprise and IoT Enterprise.
+> Starting in Windows 10, version 1703 this policy is not supported in Windows 10 Mobile Enterprise and IoT Enterprise.
Allows the device to check for updates from a WSUS server instead of Microsoft Update. This is useful for on-premises MDMs that need to update devices that cannot connect to the Internet.
From 98ee57c44dab201112e3a93f7e76c7b7e09b7491 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Wed, 11 Dec 2019 20:10:13 +0500
Subject: [PATCH 25/78] Content Update
Added a source of information to point users to use custom settings for Windows 10 devices in Intune.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/4482
---
...dows-defender-application-control-policies-using-intune.md | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
index 8a2a80de85..8319156a40 100644
--- a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
+++ b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
@@ -27,7 +27,7 @@ ms.date: 05/17/2018
- Windows 10
- Windows Server 2016
-You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
+You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure Endpoint protection profile for WDAC or a custom profile with an OMA-URI. You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
1. Open the Microsoft Intune portal and click **Device configuration** > **Profiles** > **Create profile**.
@@ -41,3 +41,5 @@ You can use Microsoft Intune to configure Windows Defender Application Control (
- **Trust apps with good reputation**: Select **Enable** to allow reputable apps as defined by the Intelligent Security Graph to run in addition to Windows components and Store apps.

+
+To add a custom profile with an OMA-URI see, [Use custom settings for Windows 10 devices in Intune](https://docs.microsoft.com/en-us/intune/configuration/custom-settings-windows-10).
From c0f9b313e3c707e029293d33b65c786f17858d75 Mon Sep 17 00:00:00 2001
From: Brandon Bray <40039061+BrandonBray@users.noreply.github.com>
Date: Wed, 11 Dec 2019 12:08:32 -0800
Subject: [PATCH 26/78] Add image color and brightness troubleshooting
Adding specific recommendations for improving image quality with HoloLens 2.
---
devices/hololens/hololens2-fit-comfort-faq.md | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/devices/hololens/hololens2-fit-comfort-faq.md b/devices/hololens/hololens2-fit-comfort-faq.md
index 397d61bb67..cbd71f9405 100644
--- a/devices/hololens/hololens2-fit-comfort-faq.md
+++ b/devices/hololens/hololens2-fit-comfort-faq.md
@@ -43,6 +43,15 @@ Try adjusting the position of your device visor so the holographic frame matches
- **If you need to look up to see holograms**. First, shift the back of the headband a bit higher on your head. Then use one hand to hold the headband in place and the other to gently rotate the visor so you have a good view of the holographic frame.
- **If you need to look down to see holograms**. First, shift the back of the headband a bit lower on your head. Then place your thumbs under the device arms and your index fingers on top of the headband, and gently squeeze with your thumbs to rotate the visor so you have a good view of the holographic frame.
+## Hologram image color or brightness does not look right
+
+For HoloLens 2, take the following steps to improve the quality of holograms presented in displays:
+
+- **Increase brightness of the display.** Holograms look best when the display is at its brightest level.
+- **Bring visor closer to your eyes.** Swing the visor down to the closest position to your eyes.
+- **Shift visor down.** Try moving the brow pad on your forehead down, which will result in the visor moving down closer to your nose.
+- **Run eye calibration.** The display uses your IPD and eye gaze to optimize images on the display. If you don't run eye calibration, the image quality may be made worse.
+
## The device slides down when I'm using it, or I need to make the headband too tight to keep it secure
The overhead strap can help keep your HoloLens secure on your head, particularly if you're moving around a lot. The strap may also let you loosen the headband a bit. [Learn how to use it](hololens2-setup.md#adjust-fit).
From b9f6d287451fbceaca63bc997928e594773b2d74 Mon Sep 17 00:00:00 2001
From: Brandon Bray <40039061+BrandonBray@users.noreply.github.com>
Date: Wed, 11 Dec 2019 13:02:31 -0800
Subject: [PATCH 27/78] Editing improvement
---
devices/hololens/hololens2-fit-comfort-faq.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/hololens2-fit-comfort-faq.md b/devices/hololens/hololens2-fit-comfort-faq.md
index cbd71f9405..e97e03f502 100644
--- a/devices/hololens/hololens2-fit-comfort-faq.md
+++ b/devices/hololens/hololens2-fit-comfort-faq.md
@@ -45,7 +45,7 @@ Try adjusting the position of your device visor so the holographic frame matches
## Hologram image color or brightness does not look right
-For HoloLens 2, take the following steps to improve the quality of holograms presented in displays:
+For HoloLens 2, take the following steps to ensure the highest visual quality of holograms presented in displays:
- **Increase brightness of the display.** Holograms look best when the display is at its brightest level.
- **Bring visor closer to your eyes.** Swing the visor down to the closest position to your eyes.
From 1a133a1a2437f0cafb7bbd2b4d45bc8a506b8242 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Thu, 12 Dec 2019 08:39:16 +0530
Subject: [PATCH 28/78] replaced Enteprise to Enterprise
as per user report #5655.
and the good intelligent report from @illfated.
I replaced Enteprise to Enterprise.
---
windows/client-management/mdm/policy-csp-update.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md
index d096ead06d..9d98a92f10 100644
--- a/windows/client-management/mdm/policy-csp-update.md
+++ b/windows/client-management/mdm/policy-csp-update.md
@@ -4248,7 +4248,7 @@ ADMX Info:
> [!IMPORTANT]
-> Starting in Windows 10, version 1703 this policy is not supported in Windows 10 Mobile Enteprise and IoT Mobile.
+> Starting in Windows 10, version 1703 this policy is not supported in Windows 10 Mobile Enterprise and IoT Mobile.
Allows the device to check for updates from a WSUS server instead of Microsoft Update. This is useful for on-premises MDMs that need to update devices that cannot connect to the Internet.
From 1dc00ca8cbeeab7c1806db0d7c481c502b566b08 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Fri, 13 Dec 2019 09:43:40 +0500
Subject: [PATCH 29/78] Update policy-csp-appruntime.md
---
windows/client-management/mdm/policy-csp-appruntime.md | 9 ---------
1 file changed, 9 deletions(-)
diff --git a/windows/client-management/mdm/policy-csp-appruntime.md b/windows/client-management/mdm/policy-csp-appruntime.md
index fce0c40f17..7c7efc8c73 100644
--- a/windows/client-management/mdm/policy-csp-appruntime.md
+++ b/windows/client-management/mdm/policy-csp-appruntime.md
@@ -99,14 +99,5 @@ ADMX Info:
-Footnotes:
-
-- 1 - Added in Windows 10, version 1607.
-- 2 - Added in Windows 10, version 1703.
-- 3 - Added in Windows 10, version 1709.
-- 4 - Added in Windows 10, version 1803.
-- 5 - Added in Windows 10, version 1809.
-- 6 - Added in Windows 10, version 1903.
-
From d704472f3687bb81e742b07091b303d71423aea4 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Fri, 13 Dec 2019 12:26:17 +0500
Subject: [PATCH 30/78] Update
windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
...indows-defender-application-control-policies-using-intune.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
index 8319156a40..d5c25facfc 100644
--- a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
+++ b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
@@ -27,7 +27,7 @@ ms.date: 05/17/2018
- Windows 10
- Windows Server 2016
-You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure Endpoint protection profile for WDAC or a custom profile with an OMA-URI. You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
+You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure the Endpoint protection profile for WDAC or a custom profile with an OMA-URI. You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
1. Open the Microsoft Intune portal and click **Device configuration** > **Profiles** > **Create profile**.
From 23b8259680295f8a15a3e0ad112a057e65098aa8 Mon Sep 17 00:00:00 2001
From: Jean-Robert Jean-Simon
Date: Fri, 13 Dec 2019 10:43:07 +0100
Subject: [PATCH 31/78] Update
windows/deployment/windows-autopilot/autopilot-faq.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
windows/deployment/windows-autopilot/autopilot-faq.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-autopilot/autopilot-faq.md b/windows/deployment/windows-autopilot/autopilot-faq.md
index 94f7002df9..756dbef593 100644
--- a/windows/deployment/windows-autopilot/autopilot-faq.md
+++ b/windows/deployment/windows-autopilot/autopilot-faq.md
@@ -38,7 +38,7 @@ A [glossary](#glossary) of abbreviations used in this topic is provided at the e
| How can I test the Windows Autopilot CSV file in the Partner Center? | Only CSP Partners have access to the Partner Center portal. If you are a CSP, you can create a Sales agent user account which has access to “Devices” for testing the file. This can be done today in the Partner Center.
Go [here](https://msdn.microsoft.com/partner-center/create-user-accounts-and-set-permissions) for more information. |
| Must I become a Cloud Solution Provider (CSP) to participate in Windows Autopilot? | Top volume OEMs do not, as they can use the OEM Direct API. All others who choose to use MPC to register devices must become CSPs in order to access MPC. |
| Do the different CSP levels have all the same capabilities when it comes to Windows Autopilot? | For purposes of Windows Autopilot, there are three different types of CSPs, each with different levels of authority an access:
1. Direct CSP: Gets direct authorization from the customer to register devices.
2. Indirect CSP Provider: Gets implicit permission to register devices through the relationship their CSP Reseller partner has with the customer. Indirect CSP Providers register devices through Microsoft Partner Center.
3. Indirect CSP Reseller: Gets direct authorization from the customer to register devices. At the same time, their indirect CSP Provider partner also gets authorization, which mean that either the Indirect Provider or the Indirect Reseller can register devices for the customer. However, the Indirect CSP Reseller must register devices through the MPC UI (manually uploading CSV file), whereas the Indirect CSP Provider has the option to register devices using the MPC APIs. |
-| Does the OEM authorization grant Delegated Admin Permissions (DAP) on the customer tenant? | No. The OEM authorization gives only the capability to register devices. |
+| Does the OEM authorization grant Delegated Admin Permissions (DAP) on the customer tenant? | No. The OEM authorization only gives the capability to register devices. |
## Manufacturing
From 64b86852b525d2500a32c6495de329a9bdb7a901 Mon Sep 17 00:00:00 2001
From: Evan Miller
Date: Fri, 13 Dec 2019 10:51:41 -0800
Subject: [PATCH 32/78] Release notes link changes to HoloLens section
Link for HoloLens release notes was pointing to Mixed Reality docs instead of HoloLens. Redirected.
@scooley
---
devices/hololens/index.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/hololens/index.md b/devices/hololens/index.md
index 6725da5e81..98835e4ce5 100644
--- a/devices/hololens/index.md
+++ b/devices/hololens/index.md
@@ -55,4 +55,4 @@ appliesto:
## Related resources
* [Documentation for Holographic app development](https://developer.microsoft.com/windows/mixed-reality/development)
-* [HoloLens release notes](https://developer.microsoft.com/windows/mixed-reality/release_notes)
+* [HoloLens release notes](https://docs.microsoft.com/hololens/hololens-release-notes)
From 9088f05210fe0f65fd2f196c28297dcbc0a2cf81 Mon Sep 17 00:00:00 2001
From: John Kaiser <35939694+CoveMiner@users.noreply.github.com>
Date: Fri, 13 Dec 2019 14:45:57 -0800
Subject: [PATCH 33/78] Update surface-pro-arm-app-management.md
---
.../surface/surface-pro-arm-app-management.md | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/devices/surface/surface-pro-arm-app-management.md b/devices/surface/surface-pro-arm-app-management.md
index 3e867c8f49..5ccc5468b3 100644
--- a/devices/surface/surface-pro-arm-app-management.md
+++ b/devices/surface/surface-pro-arm-app-management.md
@@ -62,18 +62,19 @@ Some third-party antivirus software cannot be installed on a Windows 10 PC runni
## Servicing Surface Pro X
-Outside of personal devices that rely on Windows Update, servicing devices in most corporate environments requires downloading and managing the deployment of .MSI files to update target devices. Refer to the following documentation, which will be updated later to include guidance for servicing Surface Pro X:
+Surface Pro X supports Windows 10, version 1903 and later. As an ARM-based device, it has specific requirements for maintaining the latest drivers and firmware.
-- [Deploy the latest firmware and drivers for Surface devices](deploy-the-latest-firmware-and-drivers-for-surface-devices.md).
+Surface Pro X was designed to use Windows Update to simplify the process of keeping drivers and firmware up to date for both home users and small business users. Use the default settings to receive Automatic updates. To verify:
-> [!NOTE]
-> Surface Pro X supports Windows 10, version 1903 and later.
+1. Go to **Start** > **Settings > Update & Security > Windows Update** > **Advanced Options.**
+2. Under **Choose how updates are installed,** select **Automatic (recommended)**.
-### Windows Server Update Services
-Windows Server Update Services (WSUS) does not support the ability to deliver drivers and firmware to Surface Pro X.
-
-For more information, refer to the [Microsoft Endpoint Configuration Manager documentation](https://docs.microsoft.com/configmgr/sum/get-started/configure-classifications-and-products).
+### Recommendations for commercial customers
+- Use Windows Update or Windows Update for Business for maintaining the latest drivers and firmware. For more information, see [Deploy Updates using Windows Update for Business](https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb).
+- If your procedures require using a Windows Installer .msi file contact [Surface for Business support](https://support.microsoft.com/help/4037645).
+- For more information about deploying and managing updates on Surface devices, see [Deploy the latest firmware and drivers for Surface devices](deploy-the-latest-firmware-and-drivers-for-surface-devices.md).
+- Note that Windows Server Update Services (WSUS) does not support the ability to deliver drivers and firmware to Surface Pro X.
## Running apps on Surface Pro X
From fbbf64fb2409ace606116bfba1c147532ad9c6ab Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sat, 14 Dec 2019 05:14:30 +0500
Subject: [PATCH 34/78] information update
As a request, the required information has been updated in the doc.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5261
---
.../mdm/bulk-enrollment-using-windows-provisioning-tool.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
index d17799b5a8..93525461af 100644
--- a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
+++ b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
@@ -36,8 +36,7 @@ On the desktop and mobile devices, you can use an enrollment certificate or enro
> - Bulk-join is not supported in Azure Active Directory Join.
> - Bulk enrollment does not work in Intune standalone environment.
> - Bulk enrollment works in System Center Configuration Manager (SCCM) + Intune hybrid environment where the ppkg is generated from the SCCM console.
-
-
+> - To change bulk enrollment settings, login to **AAD** then **Devices** and then click **Device Settings**. Change the number under **Maximum number of devices per user**.
## What you need
From fc38997abb47008adc8084687c6decfdba596d14 Mon Sep 17 00:00:00 2001
From: Jose Ortega
Date: Fri, 13 Dec 2019 21:19:07 -0600
Subject: [PATCH 35/78] Moved note
---
.../microsoft-defender-atp/live-response.md | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 2c8fd39528..e55674234c 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -50,10 +50,6 @@ You'll need to enable the live response capability in the [Advanced features set
>[!WARNING]
>Allowing the use of unsigned scripts may increase your exposure to threats.
-
- > [!ÏMPORTANT]
- > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
-
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
- **Ensure that you have the appropriate permissions**
@@ -61,6 +57,9 @@ You'll need to enable the live response capability in the [Advanced features set
Depending on the role that's been granted to you, you can run basic or advanced live response commands. Users permission are controlled by RBAC custom role.
+ > [!IMPORTANT]
+ > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
+
## Live response dashboard overview
When you initiate a live response session on a machine, a dashboard opens. The dashboard provides information about the session such as:
From 98f5095e45b56eccc466f807ef1306aa1c175aa2 Mon Sep 17 00:00:00 2001
From: Jose Ortega
Date: Fri, 13 Dec 2019 21:44:41 -0600
Subject: [PATCH 36/78] Update
---
.../microsoft-defender-atp/live-response.md | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/live-response.md b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
index 0b762a0b99..3003c707b4 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/live-response.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/live-response.md
@@ -50,15 +50,14 @@ You'll need to enable the live response capability in the [Advanced features set
>[!WARNING]
>Allowing the use of unsigned scripts may increase your exposure to threats.
-
- > [!IMPORTANT]
- > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
-
Running unsigned scripts is generally not recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the [Advanced features settings](advanced-features.md) page.
- **Ensure that you have the appropriate permissions**
Only users who have been provisioned with the appropriate permissions can initiate a session. For more information on role assignments see, [Create and manage roles](user-roles.md).
+ > [!IMPORTANT]
+ > The option to upload a file to the library is only available to those with the appropriate RBAC permissions. The button is greyed out for users with only delegated permissions.
+
Depending on the role that's been granted to you, you can run basic or advanced live response commands. Users permission are controlled by RBAC custom role.
## Live response dashboard overview
From a3dc2db13293718a05e0b838c928d2733d608c96 Mon Sep 17 00:00:00 2001
From: illfated
Date: Sat, 14 Dec 2019 20:28:51 +0100
Subject: [PATCH 37/78] Deploy WDAC/Intune: update intro description
As discussed in issue ticket #4482 (Custom WDAC policy in Intune), it
would be useful to add a detail on implementing a custom WDAC policy
in Intune. Without this detail, the implication is that you can ONLY
use the Endpoint Protection template to configure WDAC in Intune.
Thank you to Air-Git for following up on this topic and the content.
Proposed change:
- add details missed in the previous PR #5659 (Content Update)
issue ticket closure or reference:
Ref. #4482 (already closed)
---
...indows-defender-application-control-policies-using-intune.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
index d5c25facfc..0b5a8c1c75 100644
--- a/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
+++ b/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
@@ -27,7 +27,7 @@ ms.date: 05/17/2018
- Windows 10
- Windows Server 2016
-You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure the Endpoint protection profile for WDAC or a custom profile with an OMA-URI. You can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
+You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can either configure an Endpoint Protection profile for WDAC, or create a custom profile with an OMA-URI setting. Using an Endpoint Protection profile, you can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph.
1. Open the Microsoft Intune portal and click **Device configuration** > **Profiles** > **Create profile**.
From fc4c9e8950221df28d98c157a289b5a8f5e24caa Mon Sep 17 00:00:00 2001
From: jcjveraa <3942301+jcjveraa@users.noreply.github.com>
Date: Mon, 16 Dec 2019 09:11:50 +0100
Subject: [PATCH 38/78] Typo fix
Cloud clipboard helps users copy content between devices. It also manages the clipboard
histroy -> history
so that you can paste your old copied data. You can access it by using **Windows+V**. Set up Cloud clipboard:
---
windows/whats-new/whats-new-windows-10-version-1809.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/whats-new/whats-new-windows-10-version-1809.md b/windows/whats-new/whats-new-windows-10-version-1809.md
index d5b5e148ca..e5ab713e82 100644
--- a/windows/whats-new/whats-new-windows-10-version-1809.md
+++ b/windows/whats-new/whats-new-windows-10-version-1809.md
@@ -162,7 +162,7 @@ Onboard supported versions of Windows machines so that they can send sensor data
## Cloud Clipboard
-Cloud clipboard helps users copy content between devices. It also manages the clipboard histroy so that you can paste your old copied data. You can access it by using **Windows+V**. Set up Cloud clipboard:
+Cloud clipboard helps users copy content between devices. It also manages the clipboard history so that you can paste your old copied data. You can access it by using **Windows+V**. Set up Cloud clipboard:
1. Go to **Windows Settings** and select **Systems**.
2. On the left menu, click on **Clipboard**.
From 813cb6a18290ecf4101211763d16fc5bbc810476 Mon Sep 17 00:00:00 2001
From: amorrowbellarmine <46689625+amorrowbellarmine@users.noreply.github.com>
Date: Mon, 16 Dec 2019 11:27:10 -0500
Subject: [PATCH 39/78] Corrected AUMID for the Kiosk Browser
The AUMID shown in this guide is incorrect. Per the instructions found at https://docs.microsoft.com/en-us/windows/configuration/find-the-application-user-model-id-of-an-installed-app, the AUMID should be the "packagefamilyname"+"!"+"package.applications.application.id". In the case of the Kiosk Bowser, the AUMID is "Microsoft.KioskBrowser_8wekyb3d8bbwe!App". Failure to include the "!App" will result in an error when the kiosk account tries to load the app.
---
windows/configuration/setup-digital-signage.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/configuration/setup-digital-signage.md b/windows/configuration/setup-digital-signage.md
index e902d0cfe2..7741d3ba98 100644
--- a/windows/configuration/setup-digital-signage.md
+++ b/windows/configuration/setup-digital-signage.md
@@ -58,7 +58,7 @@ This procedure explains how to configure digital signage using Kiosk Browser on
- Enter a user name and password, and toggle **Auto sign-in** to **Yes**.
- Under **Configure the kiosk mode app**, enter the user name for the account that you're creating.
- For **App type**, select **Universal Windows App**.
- - In **Enter the AUMID for the app**, enter `Microsoft.KioskBrowser_8wekyb3d8bbwe`.
+ - In **Enter the AUMID for the app**, enter `Microsoft.KioskBrowser_8wekyb3d8bbwe!App`.
11. In the bottom left corner of Windows Configuration Designer, select **Switch to advanced editor**.
12. Go to **Runtime settings** > **Policies** > **KioskBrowser**. Let's assume that the URL for your digital signage content is contoso.com/menu.
- In **BlockedUrlExceptions**, enter `https://www.contoso.com/menu`.
From 5e168b9e7f2ff9bd22d686fefc48b6a91def62f9 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Mon, 16 Dec 2019 23:52:09 +0500
Subject: [PATCH 40/78] Update
windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../mdm/bulk-enrollment-using-windows-provisioning-tool.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
index 93525461af..c5b559cf50 100644
--- a/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
+++ b/windows/client-management/mdm/bulk-enrollment-using-windows-provisioning-tool.md
@@ -36,7 +36,7 @@ On the desktop and mobile devices, you can use an enrollment certificate or enro
> - Bulk-join is not supported in Azure Active Directory Join.
> - Bulk enrollment does not work in Intune standalone environment.
> - Bulk enrollment works in System Center Configuration Manager (SCCM) + Intune hybrid environment where the ppkg is generated from the SCCM console.
-> - To change bulk enrollment settings, login to **AAD** then **Devices** and then click **Device Settings**. Change the number under **Maximum number of devices per user**.
+> - To change bulk enrollment settings, login to **AAD**, then **Devices**, and then click **Device Settings**. Change the number under **Maximum number of devices per user**.
## What you need
@@ -168,4 +168,3 @@ Here are links to step-by-step provisioning topics in Technet.
-
From 38df0e98d07b9639fdddb02107c63cde187f790f Mon Sep 17 00:00:00 2001
From: Manuel Hauch
Date: Mon, 16 Dec 2019 20:21:23 +0100
Subject: [PATCH 41/78] Misnamed automation level
The protection level is called "No automated response" in the UI, not "Not protected".
---
.../microsoft-defender-atp/automated-investigations.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md
index 28d3920de1..a4990b44f7 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md
@@ -68,7 +68,7 @@ You can configure the following levels of automation:
|Automation level | Description|
|---|---|
-|Not protected | Machines do not get any automated investigations run on them. |
+|No automated response | Machines do not get any automated investigations run on them. |
|Semi - require approval for any remediation | This is the default automation level.
An approval is needed for any remediation action. |
|Semi - require approval for non-temp folders remediation | An approval is required on files or executables that are not in temporary folders.
Files or executables in temporary folders, such as the user's download folder or the user's temp folder, will automatically be remediated if needed.|
|Semi - require approval for core folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.
Files or executables in all other folders will automatically be remediated if needed.|
From a79f1eba424566d14791299610472c7733b01967 Mon Sep 17 00:00:00 2001
From: coffeemade <39417823+coffeemade@users.noreply.github.com>
Date: Tue, 17 Dec 2019 10:21:18 -0500
Subject: [PATCH 42/78] Update
on-premises-deployment-surface-hub-device-accounts.md
[!IMPORTANT] ActiveSync Virtual Directory Basic Authentication is required to be enabled as the Surface Hub is unable to authenticate using other authentication methods.
[PS] C:\windows\system32>Get-ActiveSyncVirtualDirectory | fl name,BasicAuthEnabled
Name : Microsoft-Server-ActiveSync (Default Web Site)
BasicAuthEnabled : True
---
.../on-premises-deployment-surface-hub-device-accounts.md | 1 +
1 file changed, 1 insertion(+)
diff --git a/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md b/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
index d3fdb628ab..7f3793ed3f 100644
--- a/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
+++ b/devices/surface-hub/on-premises-deployment-surface-hub-device-accounts.md
@@ -49,6 +49,7 @@ If you have a single-forest on-premises deployment with Microsoft Exchange 2013
```PowerShell
New-Mailbox -UserPrincipalName HUB01@contoso.com -Alias HUB01 -Name "Hub-01" -Room -EnableRoomMailboxAccount $true -RoomMailboxPassword (ConvertTo-SecureString -String -AsPlainText -Force)
```
+[!IMPORTANT] ActiveSync Virtual Directory Basic Authentication is required to be enabled as the Surface Hub is unable to authenticate using other authentication methods.
3. After setting up the mailbox, you will need to either create a new Exchange ActiveSync policy, or use a compatible existing policy.
From 3712d5eea92d37c03ac677bad59986b56d825aa4 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Wed, 18 Dec 2019 15:42:20 +0500
Subject: [PATCH 43/78] Update recommended-network-definitions-for-wip.md
---
.../recommended-network-definitions-for-wip.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md b/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md
index b11eab1f7d..c3e7e88640 100644
--- a/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md
+++ b/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md
@@ -35,7 +35,7 @@ This table includes the recommended URLs to add to your Enterprise Cloud Resourc
|-----------------------------|---------------------------------------------------------------------|
|Office 365 for Business |- contoso.sharepoint.com
- contoso-my.sharepoint.com
- contoso-files.sharepoint.com
- tasks.office.com
- protection.office.com
- meet.lync.com
- teams.microsoft.com
|
|Yammer |- www.yammer.com
- yammer.com
- persona.yammer.com
|
-|Outlook Web Access (OWA) |attachments.office.net |
+|Outlook Web Access (OWA) |- outlook.office.com
- outlook.office365.com
- attachments.office.net
|
|Microsoft Dynamics |contoso.crm.dynamics.com |
|Visual Studio Online |contoso.visualstudio.com |
|Power BI |contoso.powerbi.com |
From afe5b13e0eec9466f8a57cf8af5b8ac726f78a9e Mon Sep 17 00:00:00 2001
From: Bill Mcilhargey <19168174+computeronix@users.noreply.github.com>
Date: Wed, 18 Dec 2019 08:36:03 -0500
Subject: [PATCH 44/78] Added Central Store Consideration for GPOs
For anyone using Central Store, added information for where to deploy the GPO templates in this setup.
---
.../microsoft-defender-atp/configure-endpoints-gp.md | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md
index a5cb971e01..367c0685a8 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md
@@ -80,6 +80,13 @@ You can use Group Policy (GP) to configure settings, such as settings for the sa
b. Copy _AtpConfiguration.adml_ into _C:\\Windows\\PolicyDefinitions\\en-US_
+ If you are using a [Central Store for Group Policy Administrative Templates](https://support.microsoft.com/help/3087759/how-to-create-and-manage-the-central-store-for-group-policy-administra), copy the following files from the
+ configuration package:
+
+ a. Copy _AtpConfiguration.admx_ into _\\\\\\\SysVol\\\\\Policies\\PolicyDefinitions_
+
+ b. Copy _AtpConfiguration.adml_ into _\\\\\\\SysVol\\\\\Policies\\PolicyDefinitions\\en-US_
+
2. Open the [Group Policy Management Console](https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/group-policy-and-group-policy-mgmt-console-ie11), right-click the GPO you want to configure and click **Edit**.
3. In the **Group Policy Management Editor**, go to **Computer configuration**.
From 12befda4f5b299867f5436921b2495aac103e633 Mon Sep 17 00:00:00 2001
From: cchapin2020 <49560354+cchapin2020@users.noreply.github.com>
Date: Wed, 18 Dec 2019 10:57:02 -0500
Subject: [PATCH 45/78] Edit table of default values
Edited table of default settings based on Windows Server 2016 domain defaults. The right on a domain controller is set in the local security policy and is not defined in the Default Domain Controller policy.
---
.../allow-log-on-through-remote-desktop-services.md | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/security-policy-settings/allow-log-on-through-remote-desktop-services.md b/windows/security/threat-protection/security-policy-settings/allow-log-on-through-remote-desktop-services.md
index 4725c3e9ba..d1dd82ef56 100644
--- a/windows/security/threat-protection/security-policy-settings/allow-log-on-through-remote-desktop-services.md
+++ b/windows/security/threat-protection/security-policy-settings/allow-log-on-through-remote-desktop-services.md
@@ -52,7 +52,8 @@ The following table lists the actual and effective default policy values. Defaul
| Server type or GPO | Default value |
| - | - |
| Default Domain Policy | Not Defined |
-| Default Domain Controller Policy | Administrators |
+| Default Domain Controller Policy | Not Defined |
+| Domain Controller Local Security Policy | Administrators |
| Stand-Alone Server Default Settings | Administrators
Remote Desktop Users |
| Domain Controller Effective Default Settings | Administrators |
| Member Server Effective Default Settings | Administrators
Remote Desktop Users |
From d02139df5fce91e8ea531fb31c74876bbd3d417c Mon Sep 17 00:00:00 2001
From: tx5westmt <45113913+tx5westmt@users.noreply.github.com>
Date: Wed, 18 Dec 2019 11:36:29 -0600
Subject: [PATCH 46/78] Grammar/Punctuation Corrections
Minor grammar/punctuation updates.
---
.../hello-for-business/feature-multifactor-unlock.md | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/windows/security/identity-protection/hello-for-business/feature-multifactor-unlock.md b/windows/security/identity-protection/hello-for-business/feature-multifactor-unlock.md
index 3da855c332..4ddcb35964 100644
--- a/windows/security/identity-protection/hello-for-business/feature-multifactor-unlock.md
+++ b/windows/security/identity-protection/hello-for-business/feature-multifactor-unlock.md
@@ -31,7 +31,7 @@ ms.reviewer:
Windows, today, natively only supports the use of a single credential (password, PIN, fingerprint, face, etc.) for unlocking a device. Therefore, if any of those credentials are compromised (shoulder surfed), an attacker could gain access to the system.
-Windows 10 offers Multi-factor device unlock by extending Windows Hello with trusted signals, administrators can configure Windows 10 to request a combination of factors and trusted signals to unlock their devices.
+Windows 10 offers Multi-factor device unlock by extending Windows Hello with trusted signals. Administrators can configure Windows 10 to request a combination of factors and trusted signals to unlock their devices.
Which organizations can take advantage of Multi-factor unlock? Those who:
* Have expressed that PINs alone do not meet their security needs.
@@ -101,7 +101,7 @@ Each rule element has a **signal** element. All signal elements have a **type**
| type| "wifi" (Windows 10, version 1803)
#### Bluetooth
-You define the bluetooth signal with additional attribute in the signal element. The bluetooth configuration does not use any other elements. You can end the signal element with short ending tag "\/>".
+You define the bluetooth signal with additional attributes in the signal element. The bluetooth configuration does not use any other elements. You can end the signal element with short ending tag "\/>".
|Attribute|Value|Required|
|---------|-----|--------|
@@ -117,7 +117,7 @@ Example:
```
-The **classofDevice** attribute defaults Phones and uses the values from the following table
+The **classofDevice** attribute defaults to Phone and uses the values from the following table:
|Description|Value|
|:-------------|:-------:|
@@ -138,7 +138,7 @@ The **rssiMin** attribute value signal indicates the strength needed for the dev
RSSI measurements are relative and lower as the bluetooth signals between the two paired devices reduces. Therefore a measurement of 0 is stronger than -10, which is stronger than -60, which is an indicator the devices are moving further apart from each other.
>[!IMPORTANT]
->Microsoft recommends using the default values for this policy settings. Measurements are relative, based on the varying conditions of each environment. Therefore, the same values may produce different results. Test policy settings in each environment prior to broadly deploying the setting. Use the rssiMIN and rssiMaxDelta values from the XML file created by the Group Policy Management Editor or remove both attributes to use the default values.
+>Microsoft recommends using the default values for this policy setting. Measurements are relative, based on the varying conditions of each environment. Therefore, the same values may produce different results. Test policy settings in each environment prior to broadly deploying the setting. Use the rssiMIN and rssiMaxDelta values from the XML file created by the Group Policy Management Editor or remove both attributes to use the default values.
#### IP Configuration
You define IP configuration signals using one or more ipConfiguration elements. Each element has a string value. IpConfiguration elements do not have attributes or nested elements.
@@ -198,7 +198,7 @@ The IPv6 DNS server represented in Internet standard hexadecimal encoding. An IP
21DA:00D3:0000:2F3B:02AA:00FF:FE28:9C5A%2
```
##### dnsSuffix
-The fully qualified domain name of your organizations internal DNS suffix where any part of the fully qualified domain name in this setting exists in the computer's primary DNS suffix. The **signal** element may contain one or more **dnsSuffix** elements.
+The fully qualified domain name of your organization's internal DNS suffix where any part of the fully qualified domain name in this setting exists in the computer's primary DNS suffix. The **signal** element may contain one or more **dnsSuffix** elements.
**Example**
```
corp.contoso.com
From d2da2e934f152e35cf6159228b0924355224de6e Mon Sep 17 00:00:00 2001
From: John Kaiser <35939694+CoveMiner@users.noreply.github.com>
Date: Wed, 18 Dec 2019 12:24:49 -0800
Subject: [PATCH 47/78] Update surface-pro-arm-app-management.md
---
devices/surface/surface-pro-arm-app-management.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface/surface-pro-arm-app-management.md b/devices/surface/surface-pro-arm-app-management.md
index 5ccc5468b3..fee3cc0671 100644
--- a/devices/surface/surface-pro-arm-app-management.md
+++ b/devices/surface/surface-pro-arm-app-management.md
@@ -72,7 +72,7 @@ Surface Pro X was designed to use Windows Update to simplify the process of keep
### Recommendations for commercial customers
- Use Windows Update or Windows Update for Business for maintaining the latest drivers and firmware. For more information, see [Deploy Updates using Windows Update for Business](https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb).
-- If your procedures require using a Windows Installer .msi file contact [Surface for Business support](https://support.microsoft.com/help/4037645).
+- If your procedures require using a Windows Installer .msi file, contact [Surface for Business support](https://support.microsoft.com/help/4037645).
- For more information about deploying and managing updates on Surface devices, see [Deploy the latest firmware and drivers for Surface devices](deploy-the-latest-firmware-and-drivers-for-surface-devices.md).
- Note that Windows Server Update Services (WSUS) does not support the ability to deliver drivers and firmware to Surface Pro X.
From 599b8e27ae35e3d9869fe5a1d5bbb87576634bf4 Mon Sep 17 00:00:00 2001
From: John Kaiser <35939694+CoveMiner@users.noreply.github.com>
Date: Wed, 18 Dec 2019 14:28:28 -0800
Subject: [PATCH 48/78] Update surface-pro-arm-app-management.md
---
devices/surface/surface-pro-arm-app-management.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface/surface-pro-arm-app-management.md b/devices/surface/surface-pro-arm-app-management.md
index fee3cc0671..26e145c547 100644
--- a/devices/surface/surface-pro-arm-app-management.md
+++ b/devices/surface/surface-pro-arm-app-management.md
@@ -71,7 +71,7 @@ Surface Pro X was designed to use Windows Update to simplify the process of keep
### Recommendations for commercial customers
-- Use Windows Update or Windows Update for Business for maintaining the latest drivers and firmware. For more information, see [Deploy Updates using Windows Update for Business](https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb).
+- Use Windows Update or Windows Update for Business for maintaining the latest drivers and firmware. For more information, see [Deploy Updates using Windows Update for Business](https://docs.microsoft.com/windows/deployment/update/waas-manage-updates-wufb).
- If your procedures require using a Windows Installer .msi file, contact [Surface for Business support](https://support.microsoft.com/help/4037645).
- For more information about deploying and managing updates on Surface devices, see [Deploy the latest firmware and drivers for Surface devices](deploy-the-latest-firmware-and-drivers-for-surface-devices.md).
- Note that Windows Server Update Services (WSUS) does not support the ability to deliver drivers and firmware to Surface Pro X.
From 33635c9386aed5ee5b831be081e4650232473a8a Mon Sep 17 00:00:00 2001
From: VLG17 <41186174+VLG17@users.noreply.github.com>
Date: Thu, 19 Dec 2019 17:37:56 +0200
Subject: [PATCH 49/78] Remove false information about winHTTP
https://github.com/MicrosoftDocs/windows-itpro-docs/issues/2230
---
windows/deployment/upgrade/upgrade-readiness-data-sharing.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/upgrade/upgrade-readiness-data-sharing.md b/windows/deployment/upgrade/upgrade-readiness-data-sharing.md
index af934eec08..58e8a9e6c2 100644
--- a/windows/deployment/upgrade/upgrade-readiness-data-sharing.md
+++ b/windows/deployment/upgrade/upgrade-readiness-data-sharing.md
@@ -33,7 +33,7 @@ In order to use the direct connection scenario, set the parameter **ClientProxy=
### Connection through the WinHTTP proxy
-This is the first and most simple proxy scenario. The WinHTTP stack was designed for use in services and does not support proxy autodetection, PAC scripts or authentication.
+This is the first and most simple proxy scenario.
In order to set the WinHTTP proxy system-wide on your computers, you need to
- Use the command netsh winhttp set proxy \:\
From dbc99ea38edc57df9629ae4ed8cc7734da41eabc Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Thu, 19 Dec 2019 23:34:12 +0500
Subject: [PATCH 50/78] Updated information for Office 2003
Added information for office 2003 and earlier file formats to be avoided to open when sent as an attachment.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/4425
---
.../threat-protection/intelligence/prevent-malware-infection.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/windows/security/threat-protection/intelligence/prevent-malware-infection.md b/windows/security/threat-protection/intelligence/prevent-malware-infection.md
index 3659eaeffb..884759126a 100644
--- a/windows/security/threat-protection/intelligence/prevent-malware-infection.md
+++ b/windows/security/threat-protection/intelligence/prevent-malware-infection.md
@@ -85,6 +85,8 @@ To further ensure that data is protected from malware as well as other threats:
* Do not use untrusted devices to log on to email, social media, and corporate accounts.
+* Do not downlaod or run old Binary / Office 2003 and ealier file formats like .doc, .ppt, .xls. These file formats allow macros to be included. This can be a security risk.
+
## Software solutions
Microsoft provides comprehensive security capabilities that help protect against threats. We recommend:
From ce2db075fdfe0d8117f77eccf432d694c7706ece Mon Sep 17 00:00:00 2001
From: Daniel Simpson
Date: Thu, 19 Dec 2019 13:33:25 -0800
Subject: [PATCH 51/78] Update prevent-malware-infection.md
Edits
---
.../threat-protection/intelligence/prevent-malware-infection.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/intelligence/prevent-malware-infection.md b/windows/security/threat-protection/intelligence/prevent-malware-infection.md
index 884759126a..7bce69882c 100644
--- a/windows/security/threat-protection/intelligence/prevent-malware-infection.md
+++ b/windows/security/threat-protection/intelligence/prevent-malware-infection.md
@@ -85,7 +85,7 @@ To further ensure that data is protected from malware as well as other threats:
* Do not use untrusted devices to log on to email, social media, and corporate accounts.
-* Do not downlaod or run old Binary / Office 2003 and ealier file formats like .doc, .ppt, .xls. These file formats allow macros to be included. This can be a security risk.
+* Avoid downloading or running older apps. Some of these apps might have vulnerabilities. Also, older file formats for Office 2003 (.doc, .pps, and .xls) allow macros or run. This could be a security risk.
## Software solutions
From d89b0b9b58287ebb894945d84ff6da23532881fb Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sat, 21 Dec 2019 16:26:04 +0530
Subject: [PATCH 52/78] Added particular file name
added the particular file name **Surface_Brightness_Control_v1.16.137.0.msi** which will be used to control the surface brightness
---
devices/surface/microsoft-surface-brightness-control.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/devices/surface/microsoft-surface-brightness-control.md b/devices/surface/microsoft-surface-brightness-control.md
index 8c512f48c2..1765b71f55 100644
--- a/devices/surface/microsoft-surface-brightness-control.md
+++ b/devices/surface/microsoft-surface-brightness-control.md
@@ -22,8 +22,7 @@ kiosk scenarios, you can optimize power management using the new Surface
Brightness Control app.
Available for download with [Surface Tools for
-IT](https://www.microsoft.com/download/details.aspx?id=46703), Surface Brightness Control is
-designed to help reduce thermal load and lower the overall carbon
+IT](https://www.microsoft.com/download/details.aspx?id=46703), Download only this file **Surface_Brightness_Control_v1.16.137.0.msi**. Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon
footprint for deployed Surface devices. The tool automatically dims the screen when not in use and
includes the following configuration options:
From 311fa6a79a4259ab89c192b73ecf82dc16357d17 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sat, 21 Dec 2019 19:12:33 +0500
Subject: [PATCH 53/78] Missing Windows Version
Added missing Windows version in the document.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5511
---
.../smart-card-certificate-requirements-and-enumeration.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/identity-protection/smart-cards/smart-card-certificate-requirements-and-enumeration.md b/windows/security/identity-protection/smart-cards/smart-card-certificate-requirements-and-enumeration.md
index a408a47cf2..17564fc13b 100644
--- a/windows/security/identity-protection/smart-cards/smart-card-certificate-requirements-and-enumeration.md
+++ b/windows/security/identity-protection/smart-cards/smart-card-certificate-requirements-and-enumeration.md
@@ -185,7 +185,7 @@ Certificate requirements are listed by versions of the Windows operating system.
The smart card certificate has specific format requirements when it is used with Windows XP and earlier operating systems. You can enable any certificate to be visible for the smart card credential provider.
-| **Component** | **Requirements for Windows 8.1, Windows 8, Windows 7, and Windows Vista** | **Requirements for Windows XP** |
+| **Component** | **Requirements for Windows 8.1, Windows 8, Windows 7, Windows Vista, and Windows 10** | **Requirements for Windows XP** |
|--------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CRL distribution point location | Not required | The location must be specified, online, and available, for example:
\[1\]CRL Distribution Point
Distribution Point Name:
Full Name:
URL= |
| Key usage | Digital signature | Digital signature |
From f370b45fcc9411c59007f88dc1e27a1185be548c Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sat, 21 Dec 2019 21:22:23 +0500
Subject: [PATCH 54/78] Information update
Deleting old information and redirecting the user to the current and updated document.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5514
---
.../microsoft-cloud-app-security-config.md | 20 +++++--------------
1 file changed, 5 insertions(+), 15 deletions(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
index 996ac58a26..3010803ba6 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
@@ -31,6 +31,10 @@ To benefit from Microsoft Defender Advanced Threat Protection (ATP) cloud app di
>[!NOTE]
>This feature will be available with an E5 license for [Enterprise Mobility + Security](https://www.microsoft.com/cloud-platform/enterprise-mobility-security) on machines running Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/help/4493441)), Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/help/4493464)), Windows 10, version 1809 (OS Build 17763.379 with [KB4489899](https://support.microsoft.com/help/4489899)) or later Windows 10 versions.
+> See [Microsoft Defender Advanced Threat Protection integration with Microsoft Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration) for detailed integration of Microsoft Defender ATP with Microsoft Cloud App Security.
+
+## Enable Microsoft Cloud App Security in Microsoft Defender ATP
+
1. In the navigation pane, select **Preferences setup** > **Advanced features**.
2. Select **Microsoft Cloud App Security** and switch the toggle to **On**.
3. Click **Save preferences**.
@@ -39,21 +43,7 @@ Once activated, Microsoft Defender ATP will immediately start forwarding discove
## View the data collected
-1. Browse to the [Cloud App Security portal](https://portal.cloudappsecurity.com).
-
-2. Navigate to the Cloud Discovery dashboard.
-
- 
-
-3. Select **Win10 Endpoint Users report**, which contains the data coming from Microsoft Defender ATP.
-
- 
-
-This report is similar to the existing discovery report with one major difference: you can now benefit from visibility to the machine context.
-
-Notice the new **Machines** tab that allows you to view the data split to the device dimensions. This is available in the main report page or any subpage (for example, when drilling down to a specific cloud app).
-
-
+To view and access Microsoft Defender ATP data in Microsoft Cloud Apps Security see [Investigate machines in Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration#investigate-machines-in-cloud-app-security).
For more information about cloud discovery, see [Working with discovered apps](https://docs.microsoft.com/cloud-app-security/discovered-apps).
From 3de268961dcf2ea1f20cb56d4533172c323717ad Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sat, 21 Dec 2019 21:59:11 +0500
Subject: [PATCH 55/78] Sentence correction
There was confusion in the sentence and its updated now.
Probolem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5515
---
.../system-guard-secure-launch-and-smm-protection.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
index 5b92c4240f..18526e6918 100644
--- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
+++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
@@ -66,8 +66,7 @@ To verify that Secure Launch is running, use System Information (MSInfo32). Clic
>[!NOTE]
>To enable System Guard Secure launch, the platform must meet all the baseline requirements for [Device Guard](https://docs.microsoft.com/windows/security/threat-protection/device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control), [Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-requirements), and [Virtualization Based Security](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity).
-## Requirements Met by System Guard Enabled Machines
-Any machine with System Guard enabled will automatically meet the following low-level hardware requirements:
+## System requirments for System Guard
|For Intel® vPro™ processors starting with Intel® Coffeelake, Whiskeylake, or later silicon|Description|
|--------|-----------|
From ac7ad5f086bb1535bc9f06189cf01f7bb8655221 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sat, 21 Dec 2019 22:58:08 +0530
Subject: [PATCH 56/78] Added support link and hotfix package link
as per the user report, i added the download link for Microsoft Desktop Optimization Pack March 2017 Servicing Release
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index c19488dbb0..a0340871f3 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -39,3 +39,16 @@ This section lists common issues that you may encounter when you upgrade your Ad
- Install the required hotfix.
- Connect to AGPM using an AGPM client to test that your difference reports are now functioning.
+
+ ## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
+
+ AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs)
+ install the latest version of Microsoft Desktop Optimization Pack (March 2017 Servicing Release). See KB 4014009 for more information.
+
+ Download the Microsoft Desktop Optimization Pack March 2017 Servicing Release from below link
+ https://www.microsoft.com/en-us/download/details.aspx?id=54967
+
+
+ ## Reference link
+ https://support.microsoft.com/en-us/help/3127165/hotfix-package-1-for-microsoft-advanced-group-policy-management-4-0-sp
+
From c1f869dec54af1355275c6898dab60dc12981a73 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:06:09 +0530
Subject: [PATCH 57/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
accepted
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index a0340871f3..99f67155ee 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -40,7 +40,7 @@ This section lists common issues that you may encounter when you upgrade your Ad
- Connect to AGPM using an AGPM client to test that your difference reports are now functioning.
- ## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
+## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs)
install the latest version of Microsoft Desktop Optimization Pack (March 2017 Servicing Release). See KB 4014009 for more information.
From 65bae3e61bffe98ca2d21e1f4c5fce06769a8062 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:06:37 +0530
Subject: [PATCH 58/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
looks good
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 99f67155ee..a06d29828b 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -42,7 +42,8 @@ This section lists common issues that you may encounter when you upgrade your Ad
## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
- AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs)
+**Issue fixed in this hotfix**
+AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
install the latest version of Microsoft Desktop Optimization Pack (March 2017 Servicing Release). See KB 4014009 for more information.
Download the Microsoft Desktop Optimization Pack March 2017 Servicing Release from below link
From 2f85c29582d9d0008a9678e2b847b53a995b2424 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:06:59 +0530
Subject: [PATCH 59/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
looks ok
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index a06d29828b..7b77f69f0b 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -44,7 +44,11 @@ This section lists common issues that you may encounter when you upgrade your Ad
**Issue fixed in this hotfix**
AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
- install the latest version of Microsoft Desktop Optimization Pack (March 2017 Servicing Release). See KB 4014009 for more information.
+
+**How to get this update**
+Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
+
+More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
Download the Microsoft Desktop Optimization Pack March 2017 Servicing Release from below link
https://www.microsoft.com/en-us/download/details.aspx?id=54967
From bfdfe7d8e6d3ce3ee5d99bbb3e542198a510bd74 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:08:58 +0530
Subject: [PATCH 60/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
this redirects to
https://www.microsoft.com/en-us/download/details.aspx?id=54967
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 7b77f69f0b..ae6378eb4f 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -51,7 +51,7 @@ Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 S
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
Download the Microsoft Desktop Optimization Pack March 2017 Servicing Release from below link
- https://www.microsoft.com/en-us/download/details.aspx?id=54967
+https://www.microsoft.com/download/details.aspx?id=54967
## Reference link
From 6154e207a288ff6eae98661c976cba8fd4d4c2ef Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:10:11 +0530
Subject: [PATCH 61/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
this redirects to
https://support.microsoft.com/en-in/help/3127165/hotfix-package-1-for-microsoft-advanced-group-policy-management-4-0-sp
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index ae6378eb4f..4301d3b355 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -55,5 +55,5 @@ https://www.microsoft.com/download/details.aspx?id=54967
## Reference link
- https://support.microsoft.com/en-us/help/3127165/hotfix-package-1-for-microsoft-advanced-group-policy-management-4-0-sp
+https://support.microsoft.com/help/3127165/hotfix-package-1-for-microsoft-advanced-group-policy-management-4-0-sp
From 7ac69c996aaae9da629c9fb70fb327caf78bf337 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:10:38 +0530
Subject: [PATCH 62/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
looks good
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 4301d3b355..f372d6c288 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -50,7 +50,7 @@ Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 S
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
- Download the Microsoft Desktop Optimization Pack March 2017 Servicing Release from below link
+Download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing Release) is shown below:
https://www.microsoft.com/download/details.aspx?id=54967
From 7e813f3428b2059c954aca7ad3f882f7c55dcb16 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 07:10:52 +0530
Subject: [PATCH 63/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index f372d6c288..1449ec5728 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -54,6 +54,6 @@ Download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing R
https://www.microsoft.com/download/details.aspx?id=54967
- ## Reference link
+## Reference link
https://support.microsoft.com/help/3127165/hotfix-package-1-for-microsoft-advanced-group-policy-management-4-0-sp
From 1a351dbbf13c91a8ca551f975118cc2efee891a7 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:25:42 +0530
Subject: [PATCH 64/78] Update
devices/surface/microsoft-surface-brightness-control.md
ok
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
devices/surface/microsoft-surface-brightness-control.md | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/devices/surface/microsoft-surface-brightness-control.md b/devices/surface/microsoft-surface-brightness-control.md
index 1765b71f55..f83886b181 100644
--- a/devices/surface/microsoft-surface-brightness-control.md
+++ b/devices/surface/microsoft-surface-brightness-control.md
@@ -22,7 +22,8 @@ kiosk scenarios, you can optimize power management using the new Surface
Brightness Control app.
Available for download with [Surface Tools for
-IT](https://www.microsoft.com/download/details.aspx?id=46703), Download only this file **Surface_Brightness_Control_v1.16.137.0.msi**. Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon
+Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon footprint for deployed Surface devices.
+If you plan to get only this tool from the download page, select the file **Surface_Brightness_Control_v1.16.137.0.msi** in the available list.
footprint for deployed Surface devices. The tool automatically dims the screen when not in use and
includes the following configuration options:
From 428b6e7af86fd2f6e831b6abc1a85dcea1bc3685 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:26:08 +0530
Subject: [PATCH 65/78] Update
devices/surface/microsoft-surface-brightness-control.md
ok
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
devices/surface/microsoft-surface-brightness-control.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface/microsoft-surface-brightness-control.md b/devices/surface/microsoft-surface-brightness-control.md
index f83886b181..eb63185e2d 100644
--- a/devices/surface/microsoft-surface-brightness-control.md
+++ b/devices/surface/microsoft-surface-brightness-control.md
@@ -24,7 +24,7 @@ Brightness Control app.
Available for download with [Surface Tools for
Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon footprint for deployed Surface devices.
If you plan to get only this tool from the download page, select the file **Surface_Brightness_Control_v1.16.137.0.msi** in the available list.
-footprint for deployed Surface devices. The tool automatically dims the screen when not in use and
+The tool automatically dims the screen when not in use and includes the following configuration options:
includes the following configuration options:
- Period of inactivity before dimming the display.
From 1b00d183a32b1270c69cb10d510f1f07337685ce Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:26:34 +0530
Subject: [PATCH 66/78] Update
devices/surface/microsoft-surface-brightness-control.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
devices/surface/microsoft-surface-brightness-control.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/devices/surface/microsoft-surface-brightness-control.md b/devices/surface/microsoft-surface-brightness-control.md
index eb63185e2d..fff81efcd4 100644
--- a/devices/surface/microsoft-surface-brightness-control.md
+++ b/devices/surface/microsoft-surface-brightness-control.md
@@ -21,7 +21,7 @@ When deploying Surface devices in point of sale or other “always-on”
kiosk scenarios, you can optimize power management using the new Surface
Brightness Control app.
-Available for download with [Surface Tools for
+Available for download with [Surface Tools for IT](https://www.microsoft.com/download/details.aspx?id=46703).
Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon footprint for deployed Surface devices.
If you plan to get only this tool from the download page, select the file **Surface_Brightness_Control_v1.16.137.0.msi** in the available list.
The tool automatically dims the screen when not in use and includes the following configuration options:
From 9cd7fc1d4b4cf28e93a9595cb9fe22768e7dd138 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:26:56 +0530
Subject: [PATCH 67/78] Update
devices/surface/microsoft-surface-brightness-control.md
good
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
devices/surface/microsoft-surface-brightness-control.md | 1 -
1 file changed, 1 deletion(-)
diff --git a/devices/surface/microsoft-surface-brightness-control.md b/devices/surface/microsoft-surface-brightness-control.md
index fff81efcd4..47c2ffed10 100644
--- a/devices/surface/microsoft-surface-brightness-control.md
+++ b/devices/surface/microsoft-surface-brightness-control.md
@@ -25,7 +25,6 @@ Available for download with [Surface Tools for IT](https://www.microsoft.com/dow
Surface Brightness Control is designed to help reduce thermal load and lower the overall carbon footprint for deployed Surface devices.
If you plan to get only this tool from the download page, select the file **Surface_Brightness_Control_v1.16.137.0.msi** in the available list.
The tool automatically dims the screen when not in use and includes the following configuration options:
-includes the following configuration options:
- Period of inactivity before dimming the display.
From 15bfda0dcc72b4dde8f248f1b8a281507704306a Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:27:35 +0530
Subject: [PATCH 68/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 1449ec5728..46d606b246 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -42,7 +42,7 @@ This section lists common issues that you may encounter when you upgrade your Ad
## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
-**Issue fixed in this hotfix**
+**Issue fixed in this hotfix**: AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
**How to get this update**
From 1da0b3d5edde9f4ef8a4a882a64f027aea68e5ff Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:27:56 +0530
Subject: [PATCH 69/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 1 -
1 file changed, 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 46d606b246..cc3a54124e 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -43,7 +43,6 @@ This section lists common issues that you may encounter when you upgrade your Ad
## Install Hotfix Package 1 for Microsoft Advanced Group Policy Management 4.0 SP3
**Issue fixed in this hotfix**: AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
-AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
**How to get this update**
Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
From d294d4dce96263faed89819ccb43fa3b00867f77 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:28:13 +0530
Subject: [PATCH 70/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index cc3a54124e..81eeaea9cf 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -44,7 +44,7 @@ This section lists common issues that you may encounter when you upgrade your Ad
**Issue fixed in this hotfix**: AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
-**How to get this update**
+**How to get this update**: Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
From a0849a5ac51a3a7f16820eaa5406712a09a80811 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:28:28 +0530
Subject: [PATCH 71/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 1 -
1 file changed, 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 81eeaea9cf..cc4fa92c83 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -45,7 +45,6 @@ This section lists common issues that you may encounter when you upgrade your Ad
**Issue fixed in this hotfix**: AGPM can't generate difference reports when it controls or manages new Group Policy Objects (GPOs).
**How to get this update**: Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
-Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
From 816b26c6603e274f9bef04eb3bef1083ecaaba5d Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:28:55 +0530
Subject: [PATCH 72/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index cc4fa92c83..721be58506 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -46,7 +46,7 @@ This section lists common issues that you may encounter when you upgrade your Ad
**How to get this update**: Install the latest version of Microsoft Desktop Optimization Pack ([March 2017 Servicing Release](https://www.microsoft.com/download/details.aspx?id=54967)). See [KB 4014009](https://support.microsoft.com/help/4014009/) for more information.
-More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe` from the list presented after pressing the download button.
+More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe`, from the list presented after pressing the download button.
Download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing Release) is shown below:
https://www.microsoft.com/download/details.aspx?id=54967
From 6627a1647024f32062f2dabd8de2799918999586 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:29:17 +0530
Subject: [PATCH 73/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index 721be58506..aa0459b438 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -48,7 +48,7 @@ This section lists common issues that you may encounter when you upgrade your Ad
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe`, from the list presented after pressing the download button.
-Download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing Release) is shown below:
+The download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing Release) can be found [here](https://www.microsoft.com/download/details.aspx?id=54967).
https://www.microsoft.com/download/details.aspx?id=54967
From 1ee6d78ec02fc7db69955eb1fb3026b071b17c1c Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Sun, 22 Dec 2019 15:29:39 +0530
Subject: [PATCH 74/78] Update mdop/agpm/troubleshooting-agpm40-upgrades.md
ok
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
mdop/agpm/troubleshooting-agpm40-upgrades.md | 1 -
1 file changed, 1 deletion(-)
diff --git a/mdop/agpm/troubleshooting-agpm40-upgrades.md b/mdop/agpm/troubleshooting-agpm40-upgrades.md
index aa0459b438..0275e8dc91 100644
--- a/mdop/agpm/troubleshooting-agpm40-upgrades.md
+++ b/mdop/agpm/troubleshooting-agpm40-upgrades.md
@@ -49,7 +49,6 @@ This section lists common issues that you may encounter when you upgrade your Ad
More specifically, you can choose to download only the first file, `AGPM4.0SP1_Server_X64_KB4014009.exe`, from the list presented after pressing the download button.
The download link to the Microsoft Desktop Optimization Pack (March 2017 Servicing Release) can be found [here](https://www.microsoft.com/download/details.aspx?id=54967).
-https://www.microsoft.com/download/details.aspx?id=54967
## Reference link
From 97216a50616cc5a9ed5231ba92193cf3951deebc Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 22 Dec 2019 21:31:16 +0500
Subject: [PATCH 75/78] Update
windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../system-guard-secure-launch-and-smm-protection.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
index 18526e6918..05dc390aef 100644
--- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
+++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
@@ -66,7 +66,7 @@ To verify that Secure Launch is running, use System Information (MSInfo32). Clic
>[!NOTE]
>To enable System Guard Secure launch, the platform must meet all the baseline requirements for [Device Guard](https://docs.microsoft.com/windows/security/threat-protection/device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control), [Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-requirements), and [Virtualization Based Security](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity).
-## System requirments for System Guard
+## System requirements for System Guard
|For Intel® vPro™ processors starting with Intel® Coffeelake, Whiskeylake, or later silicon|Description|
|--------|-----------|
From 9d4826fe2360a80d9f72a71f92c922758855932a Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 22 Dec 2019 21:32:43 +0500
Subject: [PATCH 76/78] Update
windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../microsoft-cloud-app-security-config.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
index 3010803ba6..0373464307 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
@@ -43,7 +43,7 @@ Once activated, Microsoft Defender ATP will immediately start forwarding discove
## View the data collected
-To view and access Microsoft Defender ATP data in Microsoft Cloud Apps Security see [Investigate machines in Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration#investigate-machines-in-cloud-app-security).
+To view and access Microsoft Defender ATP data in Microsoft Cloud Apps Security, see [Investigate machines in Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration#investigate-machines-in-cloud-app-security).
For more information about cloud discovery, see [Working with discovered apps](https://docs.microsoft.com/cloud-app-security/discovered-apps).
From 749bf1778ec8ed3a9c89ae2b90056fdc28291146 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 22 Dec 2019 21:32:53 +0500
Subject: [PATCH 77/78] Update
windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../microsoft-cloud-app-security-config.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
index 0373464307..7b474d5228 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
@@ -31,7 +31,7 @@ To benefit from Microsoft Defender Advanced Threat Protection (ATP) cloud app di
>[!NOTE]
>This feature will be available with an E5 license for [Enterprise Mobility + Security](https://www.microsoft.com/cloud-platform/enterprise-mobility-security) on machines running Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/help/4493441)), Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/help/4493464)), Windows 10, version 1809 (OS Build 17763.379 with [KB4489899](https://support.microsoft.com/help/4489899)) or later Windows 10 versions.
-> See [Microsoft Defender Advanced Threat Protection integration with Microsoft Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration) for detailed integration of Microsoft Defender ATP with Microsoft Cloud App Security.
+> See [Microsoft Defender Advanced Threat Protection integration with Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/wdatp-integration) for detailed integration of Microsoft Defender ATP with Microsoft Cloud App Security.
## Enable Microsoft Cloud App Security in Microsoft Defender ATP
From 1fcddb19408c66437552377b33b5c7d396fe4ddb Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 22 Dec 2019 21:34:06 +0500
Subject: [PATCH 78/78] Removed language locale
Removed language locale
---
.../microsoft-cloud-app-security-config.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
index 7b474d5228..5779992a72 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md
@@ -43,7 +43,7 @@ Once activated, Microsoft Defender ATP will immediately start forwarding discove
## View the data collected
-To view and access Microsoft Defender ATP data in Microsoft Cloud Apps Security, see [Investigate machines in Cloud App Security](https://docs.microsoft.com/en-us/cloud-app-security/wdatp-integration#investigate-machines-in-cloud-app-security).
+To view and access Microsoft Defender ATP data in Microsoft Cloud Apps Security, see [Investigate machines in Cloud App Security](https://docs.microsoft.com/cloud-app-security/wdatp-integration#investigate-machines-in-cloud-app-security).
For more information about cloud discovery, see [Working with discovered apps](https://docs.microsoft.com/cloud-app-security/discovered-apps).