mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 05:47:23 +00:00
Merge branch 'master' into App-v-revision
This commit is contained in:
commit
1147ad1ad9
@ -30,6 +30,8 @@ Organizations might want to deploy a customized Start and taskbar configuration
|
|||||||
>Start and taskbar configuration can be applied to devices running Windows 10 Pro, version 1703.
|
>Start and taskbar configuration can be applied to devices running Windows 10 Pro, version 1703.
|
||||||
>
|
>
|
||||||
>Using the layout modification XML to configure Start is not supported with roaming user profiles. For more information, see [Deploy Roaming User Profiles](https://technet.microsoft.com/library/jj649079.aspx).
|
>Using the layout modification XML to configure Start is not supported with roaming user profiles. For more information, see [Deploy Roaming User Profiles](https://technet.microsoft.com/library/jj649079.aspx).
|
||||||
|
>
|
||||||
|
>Using CopyProfile for Start menu customization in Windows 10 isn't supported. For more information [Customize the Default User Profile by Using CopyProfile](https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/customize-the-default-user-profile-by-using-copyprofile)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
@ -229,7 +229,7 @@ The deployment script displays the following exit codes to let you know if it wa
|
|||||||
</tr>
|
</tr>
|
||||||
<tr>
|
<tr>
|
||||||
<td>32 - Appraiser version on the machine is outdated. </td>
|
<td>32 - Appraiser version on the machine is outdated. </td>
|
||||||
<td>The configuration script detected a version of the compatibility update module that is older than the minimum required to correctly collect the data required by Upgrade Readiness solution. Use the latest version of the [compatibility update](https://technet.microsoft.com/en-us/itpro/windows/deploy/upgrade-readiness-get-started#deploy-the-compatibility-update-and-related-kbs) for Windows 7 SP1/Windows 8.1.</td>
|
<td>The configuration script detected a version of the compatibility update module that is older than the minimum required to correctly collect the data required by Upgrade Readiness solution. Use the latest version of the [compatibility update](https://docs.microsoft.com/en-us/windows/deployment/update/windows-analytics-get-started#deploy-the-compatibility-update-and-related-updates) for Windows 7 SP1/Windows 8.1.</td>
|
||||||
</tr>
|
</tr>
|
||||||
<tr>
|
<tr>
|
||||||
<td>33 - **CompatTelRunner.exe** exited with an exit code </td>
|
<td>33 - **CompatTelRunner.exe** exited with an exit code </td>
|
||||||
|
@ -7,7 +7,7 @@ ms.sitesec: library
|
|||||||
ms.localizationpriority: high
|
ms.localizationpriority: high
|
||||||
ms.pagetype: mobile
|
ms.pagetype: mobile
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
ms.date: 06/07/2018
|
ms.date: 06/15/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Windows 10 downgrade paths
|
# Windows 10 downgrade paths
|
||||||
@ -77,9 +77,9 @@ Downgrading from any edition of Windows 10 to Windows 7, 8, or 8.1 by entering a
|
|||||||
<tr>
|
<tr>
|
||||||
<td>Pro for Workstations</td>
|
<td>Pro for Workstations</td>
|
||||||
<td></td>
|
<td></td>
|
||||||
<td align="center">✔</td>
|
|
||||||
<td></td>
|
<td></td>
|
||||||
<td align="center">✔</td>
|
<td></td>
|
||||||
|
<td></td>
|
||||||
<td></td>
|
<td></td>
|
||||||
<td></td>
|
<td></td>
|
||||||
<td></td>
|
<td></td>
|
||||||
|
@ -10,7 +10,7 @@ ms.pagetype: security
|
|||||||
ms.author: macapara
|
ms.author: macapara
|
||||||
author: mjcaparas
|
author: mjcaparas
|
||||||
ms.localizationpriority: high
|
ms.localizationpriority: high
|
||||||
ms.date: 04/24/2018
|
ms.date: 06/13/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Query data using Advanced hunting in Windows Defender ATP
|
# Query data using Advanced hunting in Windows Defender ATP
|
||||||
@ -54,6 +54,8 @@ We then add a filter on the _FileName_ to contain only instances of _powershell
|
|||||||
Afterwards, we add a filter on the _ProcessCommandLine_
|
Afterwards, we add a filter on the _ProcessCommandLine_
|
||||||
Finally, we project only the columns we're interested in exploring and limit the results to 100 and click **Run query**.
|
Finally, we project only the columns we're interested in exploring and limit the results to 100 and click **Run query**.
|
||||||
|
|
||||||
|
You have the option of expanding the screen view so you can focus on your hunting query and related results.
|
||||||
|
|
||||||
### Use operators
|
### Use operators
|
||||||
The query language is very powerful and has a lot of available operators, some of them are -
|
The query language is very powerful and has a lot of available operators, some of them are -
|
||||||
|
|
||||||
|
@ -10,7 +10,7 @@ ms.pagetype: security
|
|||||||
ms.author: macapara
|
ms.author: macapara
|
||||||
author: mjcaparas
|
author: mjcaparas
|
||||||
ms.localizationpriority: high
|
ms.localizationpriority: high
|
||||||
ms.date: 04/24/2018
|
ms.date: 06/14/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Manage automation allowed/blocked lists
|
# Manage automation allowed/blocked lists
|
||||||
@ -38,30 +38,29 @@ You can define the conditions for when entities are identified as malicious or s
|
|||||||
## Create an allowed or blocked list
|
## Create an allowed or blocked list
|
||||||
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
||||||
|
|
||||||
2. Select the type of entity you'd like to create an exclusion for. You can choose any of the following entities:
|
2. Select the tab of the type of entity you'd like to create an exclusion for. You can choose any of the following entities:
|
||||||
- File hash
|
- File hash
|
||||||
- Certificate
|
- Certificate
|
||||||
|
- IP address
|
||||||
|
- DNS
|
||||||
|
|
||||||
3. Click **Add system exclusion**.
|
3. Click **Add system exclusion**.
|
||||||
|
|
||||||
4. For each attribute specify the exclusion type, details, and the following required values:
|
4. For each attribute specify the exclusion type, details, and their corresponding required values.
|
||||||
|
|
||||||
- **Files** - Hash value
|
|
||||||
- **Certificate** - PEM certificate file
|
|
||||||
|
|
||||||
5. Click **Update rule**.
|
5. Click **Add rule**.
|
||||||
|
|
||||||
## Edit a list
|
## Edit a list
|
||||||
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
||||||
|
|
||||||
2. Select the type of entity you'd like to edit the list from.
|
2. Select the tab of the entity type you'd like to edit the list from.
|
||||||
|
|
||||||
3. Update the details of the rule and click **Update rule**.
|
3. Update the details of the rule and click **Update rule**.
|
||||||
|
|
||||||
## Delete a list
|
## Delete a list
|
||||||
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
1. In the navigation pane, select **Settings** > **Automation allowed/blocked list**.
|
||||||
|
|
||||||
2. Select the type of entity you'd like to delete the list from.
|
2. Select the tab of the entity type you'd like to delete the list from.
|
||||||
|
|
||||||
3. Select the list type by clicking the check-box beside the list type.
|
3. Select the list type by clicking the check-box beside the list type.
|
||||||
|
|
||||||
|
@ -10,7 +10,7 @@ ms.pagetype: security
|
|||||||
ms.author: macapara
|
ms.author: macapara
|
||||||
author: mjcaparas
|
author: mjcaparas
|
||||||
ms.localizationpriority: high
|
ms.localizationpriority: high
|
||||||
ms.date: 06/04/2018
|
ms.date: 06/15/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Minimum requirements for Windows Defender ATP
|
# Minimum requirements for Windows Defender ATP
|
||||||
@ -42,6 +42,9 @@ Windows Defender Advanced Threat Protection requires one of the following Micros
|
|||||||
|
|
||||||
For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2).
|
For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2).
|
||||||
|
|
||||||
|
### Browser requirements
|
||||||
|
Internet Explorer and Microsoft Edge are supported. Any HTML5 compliant browsers are also supported.
|
||||||
|
|
||||||
### Network and data storage and configuration requirements
|
### Network and data storage and configuration requirements
|
||||||
When you run the onboarding wizard for the first time, you must choose where your Windows Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter.
|
When you run the onboarding wizard for the first time, you must choose where your Windows Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter.
|
||||||
|
|
||||||
|
@ -11,7 +11,7 @@ ms.pagetype: security
|
|||||||
localizationpriority: medium
|
localizationpriority: medium
|
||||||
author: andreabichsel
|
author: andreabichsel
|
||||||
ms.author: v-anbic
|
ms.author: v-anbic
|
||||||
ms.date: 05/30/2018
|
ms.date: 06/15/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Customize Attack surface reduction
|
# Customize Attack surface reduction
|
||||||
@ -54,7 +54,7 @@ This could potentially allow unsafe files to run and infect your devices.
|
|||||||
|
|
||||||
You can specify individual files or folders (using folder paths or fully qualified resource names) but you cannot specify if the exclusions should only be applied to individual rules: the exclusions will apply to all rules that are enabled (or placed in audit mode) and that allow exclusions.
|
You can specify individual files or folders (using folder paths or fully qualified resource names) but you cannot specify if the exclusions should only be applied to individual rules: the exclusions will apply to all rules that are enabled (or placed in audit mode) and that allow exclusions.
|
||||||
|
|
||||||
Windows 10, version 1803 supports environment variables and wildcards. For information about using wildcards in Windows Defender Exploit Guard, see [Use wildcards in the file name and folder path or extension exclusion lists](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
|
Windows 10, version 1803 supports environment variables and wildcards. For information about using wildcards in Windows Defender Exploit Guard, see [Use wildcards in the file name and folder path or extension exclusion lists](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus#use-wildcards-in-the-file-name-and-folder-path-or-extension-exclusion-lists).
|
||||||
|
|
||||||
Exclusions will only be applied to certain rules. Some rules will not honor the exclusion list. This means that even if you have added a file to the exclusion list, some rules will still evaluate and potentially block that file if the rule determines the file to be unsafe.
|
Exclusions will only be applied to certain rules. Some rules will not honor the exclusion list. This means that even if you have added a file to the exclusion list, some rules will still evaluate and potentially block that file if the rule determines the file to be unsafe.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user