mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
Merge pull request #4506 from nimishasatapathy/4749599-ASCIIconvesion20-40
Updated-4749599DDFs
This commit is contained in:
commit
14c23f1071
@ -26,9 +26,39 @@ The following are the links to different versions of the DiagnosticLog CSP DDF f
|
|||||||
- [DiagnosticLog CSP version 1.2](diagnosticlog-ddf.md#version-1-2)
|
- [DiagnosticLog CSP version 1.2](diagnosticlog-ddf.md#version-1-2)
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the DiagnosticLog CSP in tree format.
|
The following shows the DiagnosticLog CSP in tree format.
|
||||||

|
```
|
||||||
|
./Vendor/MSFT
|
||||||
|
DiagnosticLog
|
||||||
|
----EtwLog
|
||||||
|
--------Collectors
|
||||||
|
------------CollectorName
|
||||||
|
----------------TraceStatus
|
||||||
|
----------------TraceLogFileMode
|
||||||
|
----------------TraceControl
|
||||||
|
----------------LogFileSizeLimitMB
|
||||||
|
----------------Providers
|
||||||
|
--------------------ProviderGuid
|
||||||
|
------------------------Keywords
|
||||||
|
------------------------TraceLevel
|
||||||
|
------------------------State
|
||||||
|
--------Channels
|
||||||
|
------------ChannelName
|
||||||
|
----------------Export
|
||||||
|
----------------State
|
||||||
|
----------------Filter
|
||||||
|
----DeviceStateData
|
||||||
|
--------MdmConfiguration
|
||||||
|
----FileDownload
|
||||||
|
--------DMChannel
|
||||||
|
------------FileContext
|
||||||
|
----------------BlockSizeKB
|
||||||
|
----------------BlockCount
|
||||||
|
----------------BlockIndexToRead
|
||||||
|
----------------BlockData
|
||||||
|
----------------DataBlocks
|
||||||
|
--------------------BlockNumber
|
||||||
|
```
|
||||||
<a href="" id="--vendor-msft-diagnosticlog"></a>**./Vendor/MSFT/DiagnosticLog**
|
<a href="" id="--vendor-msft-diagnosticlog"></a>**./Vendor/MSFT/DiagnosticLog**
|
||||||
The root node for the DiagnosticLog CSP.
|
The root node for the DiagnosticLog CSP.
|
||||||
|
|
||||||
|
@ -23,10 +23,46 @@ The DMAcc configuration service provider allows an OMA Device Management (DM) ve
|
|||||||
|
|
||||||
For the DMAcc CSP, you cannot use the Replace command unless the node already exists.
|
For the DMAcc CSP, you cannot use the Replace command unless the node already exists.
|
||||||
|
|
||||||
The following diagram shows the DMAcc configuration service provider management object in tree format as used by OMA Device Management version 1.2. The OMA Client Provisioning protocol is not supported by this configuration service provider.
|
The following shows the DMAcc configuration service provider management object in tree format as used by OMA Device Management version 1.2. The OMA Client Provisioning protocol is not supported by this configuration service provider.
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
```
|
||||||
|
./SyncML
|
||||||
|
DMAcc
|
||||||
|
----*
|
||||||
|
--------AppID
|
||||||
|
--------ServerID
|
||||||
|
--------Name
|
||||||
|
--------PrefConRef
|
||||||
|
--------AppAddr
|
||||||
|
------------*
|
||||||
|
----------------Addr
|
||||||
|
----------------AddrType
|
||||||
|
----------------Port
|
||||||
|
--------------------*
|
||||||
|
------------------------PortNbr
|
||||||
|
--------AAuthPref
|
||||||
|
--------AppAuth
|
||||||
|
------------*
|
||||||
|
----------------AAuthLevel
|
||||||
|
----------------AAuthType
|
||||||
|
----------------AAuthName
|
||||||
|
----------------AAuthSecret
|
||||||
|
----------------AAuthData
|
||||||
|
--------Ext
|
||||||
|
------------Microsoft
|
||||||
|
----------------Role
|
||||||
|
----------------ProtoVer
|
||||||
|
----------------DefaultEncoding
|
||||||
|
----------------UseHwDevID
|
||||||
|
----------------ConnRetryFreq
|
||||||
|
----------------InitialBackOffTime
|
||||||
|
----------------MaxBackOffTime
|
||||||
|
----------------BackCompatRetryDisabled
|
||||||
|
----------------UseNonceResync
|
||||||
|
----------------CRLCheck
|
||||||
|
----------------DisableOnRoaming
|
||||||
|
----------------SSLCLIENTCERTSEARCHCRITERIA
|
||||||
|
```
|
||||||
<a href="" id="dmacc"></a>**DMAcc**
|
<a href="" id="dmacc"></a>**DMAcc**
|
||||||
Required. Defines the root node of all OMA DM server accounts that use the OMA DM version 1.2 protocol.
|
Required. Defines the root node of all OMA DM server accounts that use the OMA DM version 1.2 protocol.
|
||||||
|
|
||||||
|
@ -17,11 +17,50 @@ ms.date: 11/01/2017
|
|||||||
|
|
||||||
The DMClient configuration service provider (CSP) is used to specify additional enterprise-specific mobile device management (MDM) configuration settings for identifying the device in the enterprise domain, for security mitigation for certificate renewal, and for server-triggered enterprise unenrollment.
|
The DMClient configuration service provider (CSP) is used to specify additional enterprise-specific mobile device management (MDM) configuration settings for identifying the device in the enterprise domain, for security mitigation for certificate renewal, and for server-triggered enterprise unenrollment.
|
||||||
|
|
||||||
The following diagram shows the DMClient CSP in tree format.
|
The following shows the DMClient CSP in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
DMClient
|
||||||
|
----Provider
|
||||||
|
--------
|
||||||
|
------------EntDeviceName
|
||||||
|
------------ExchangeID
|
||||||
|
------------EntDMID
|
||||||
|
------------SignedEntDMID
|
||||||
|
------------CertRenewTimeStamp
|
||||||
|
------------PublisherDeviceID
|
||||||
|
------------ManagementServiceAddress
|
||||||
|
------------UPN
|
||||||
|
------------HelpPhoneNumber
|
||||||
|
------------HelpWebsite
|
||||||
|
------------HelpEmailAddress
|
||||||
|
------------RequireMessageSigning
|
||||||
|
------------SyncApplicationVersion
|
||||||
|
------------MaxSyncApplicationVersion
|
||||||
|
------------Unenroll
|
||||||
|
------------AADResourceID
|
||||||
|
------------AADDeviceID
|
||||||
|
------------EnrollmentType
|
||||||
|
------------EnableOmaDmKeepAliveMessage
|
||||||
|
------------HWDevID
|
||||||
|
------------ManagementServerAddressList
|
||||||
|
------------CommercialID
|
||||||
|
------------Push
|
||||||
|
----------------PFN
|
||||||
|
----------------ChannelURI
|
||||||
|
----------------Status
|
||||||
|
------------Poll
|
||||||
|
----------------IntervalForFirstSetOfRetries
|
||||||
|
----------------NumberOfFirstRetries
|
||||||
|
----------------IntervalForSecondSetOfRetries
|
||||||
|
----------------NumberOfSecondRetries
|
||||||
|
----------------IntervalForRemainingScheduledRetries
|
||||||
|
----------------NumberOfRemainingScheduledRetries
|
||||||
|
----------------PollOnLogin
|
||||||
|
----------------AllUsersPollOnFirstLogin
|
||||||
|
----Unenroll
|
||||||
|
----UpdateManagementServiceAddress
|
||||||
|
```
|
||||||
<a href="" id="msft"></a>**./Vendor/MSFT**
|
<a href="" id="msft"></a>**./Vendor/MSFT**
|
||||||
All the nodes in this CSP are supported in the device context, except for the **ExchangeID** node, which is supported in the user context. For the device context, use the **./Device/Vendor/MSFT** path and for the user context, use the **./User/Vendor/MSFT** path.
|
All the nodes in this CSP are supported in the device context, except for the **ExchangeID** node, which is supported in the user context. For the device context, use the **./Device/Vendor/MSFT** path and for the user context, use the **./User/Vendor/MSFT** path.
|
||||||
|
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: DMSessionActions CSP
|
title: DMSessionActions CSP
|
||||||
description: Learn how the DMSessionActions configuration service provider (CSP) is used to manage the number of sessions the client skips if the device is in a low power state.
|
description: Learn how the DMSessionActions configuration service provider (CSP) is used to manage the number of sessions the client skips if the device is in a low-power state.
|
||||||
ms.author: dansimp
|
ms.author: dansimp
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
@ -16,20 +16,57 @@ manager: dansimp
|
|||||||
|
|
||||||
The DMSessionActions configuration service provider (CSP) is used to manage:
|
The DMSessionActions configuration service provider (CSP) is used to manage:
|
||||||
|
|
||||||
- the number of sessions the client skips if the device is in a low power state
|
- the number of sessions the client skips if the device is in a low-power state
|
||||||
- which CSP nodes should send an alert back to the server if there were any changes.
|
- which CSP nodes should send an alert back to the server if there were any changes.
|
||||||
|
|
||||||
This CSP was added in Windows 10, version 1703.
|
This CSP was added in Windows 10, version 1703.
|
||||||
|
|
||||||
The following diagram shows the DMSessionActions configuration service provider in tree format.
|
The following shows the DMSessionActions configuration service provider in tree format.
|
||||||
|
```
|
||||||
|
./User/Vendor/MSFT
|
||||||
|
DMSessionActions
|
||||||
|
----ProviderID
|
||||||
|
--------CheckinAlertConfiguration
|
||||||
|
------------Nodes
|
||||||
|
----------------NodeID
|
||||||
|
--------------------NodeURI
|
||||||
|
--------AlertData
|
||||||
|
--------PowerSettings
|
||||||
|
------------MaxSkippedSessionsInLowPowerState
|
||||||
|
------------MaxTimeSessionsSkippedInLowPowerState
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
./Device/Vendor/MSFT
|
||||||
|
DMSessionActions
|
||||||
|
----ProviderID
|
||||||
|
--------CheckinAlertConfiguration
|
||||||
|
------------Nodes
|
||||||
|
----------------NodeID
|
||||||
|
--------------------NodeURI
|
||||||
|
--------AlertData
|
||||||
|
--------PowerSettings
|
||||||
|
------------MaxSkippedSessionsInLowPowerState
|
||||||
|
------------MaxTimeSessionsSkippedInLowPowerState
|
||||||
|
|
||||||
|
|
||||||
|
./User/Vendor/MSFT
|
||||||
|
./Device/Vendor/MSFT
|
||||||
|
DMSessionActions
|
||||||
|
----ProviderID
|
||||||
|
--------CheckinAlertConfiguration
|
||||||
|
------------Nodes
|
||||||
|
----------------NodeID
|
||||||
|
--------------------NodeURI
|
||||||
|
--------AlertData
|
||||||
|
--------PowerSettings
|
||||||
|
------------MaxSkippedSessionsInLowPowerState
|
||||||
|
------------MaxTimeSessionsSkippedInLowPowerState
|
||||||
|
```
|
||||||
<a href="" id="vendor-msft-dmsessionactions"></a>**./Device/Vendor/MSFT/DMSessionActions or ./User/Vendor/MSFT/DMSessionActions**
|
<a href="" id="vendor-msft-dmsessionactions"></a>**./Device/Vendor/MSFT/DMSessionActions or ./User/Vendor/MSFT/DMSessionActions**
|
||||||
<p style="margin-left: 20px">Defines the root node for the DMSessionActions configuration service provider.</p>
|
<p style="margin-left: 20px">Defines the root node for the DMSessionActions configuration service provider.</p>
|
||||||
|
|
||||||
<a href="" id="providerid"></a>***ProviderID***
|
<a href="" id="providerid"></a>***ProviderID***
|
||||||
<p style="margin-left: 20px">Group settings per device management (DM) server. Each group of settings is distinguished by the Provider ID of the server. It must be the same DM server Provider ID value that was supplied through the w7 APPLICATION configuration service provider XML during the enrollment process. Only one enterprise management server is supported, which means that there should be only one ProviderID node under NodeCache. </p>
|
<p style="margin-left: 20px">Group settings per device management (DM) server. Each group of settings is distinguished by the Provider ID of the server. It must be the same DM server Provider ID value that was supplied through the w7 APPLICATION configuration service provider XML during the enrollment process. Only one enterprise management server is supported, which means there should be only one ProviderID node under NodeCache. </p>
|
||||||
|
|
||||||
<p style="margin-left: 20px">Scope is dynamic. Supported operations are Get, Add, and Delete.</p>
|
<p style="margin-left: 20px">Scope is dynamic. Supported operations are Get, Add, and Delete.</p>
|
||||||
|
|
||||||
@ -55,12 +92,12 @@ The following diagram shows the DMSessionActions configuration service provider
|
|||||||
<p style="margin-left: 20px">Value type is string. Supported operation is Get.</p>
|
<p style="margin-left: 20px">Value type is string. Supported operation is Get.</p>
|
||||||
|
|
||||||
<a href="" id="powersettings"></a>**PowerSettings**
|
<a href="" id="powersettings"></a>**PowerSettings**
|
||||||
<p style="margin-left: 20px">Node for power related configrations</p>
|
<p style="margin-left: 20px">Node for power-related configrations</p>
|
||||||
|
|
||||||
<a href="" id="maxskippedsessionsinlowpowerstate"></a>**PowerSettings/MaxSkippedSessionsInLowPowerState**
|
<a href="" id="maxskippedsessionsinlowpowerstate"></a>**PowerSettings/MaxSkippedSessionsInLowPowerState**
|
||||||
<p style="margin-left: 20px">Maximum number of continuous skipped sync sessions when the device is in low power state.</p>
|
<p style="margin-left: 20px">Maximum number of continuous skipped sync sessions when the device is in low-power state.</p>
|
||||||
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Replace, and Delete.</p>
|
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Replace, and Delete.</p>
|
||||||
|
|
||||||
<a href="" id="maxtimesessionsskippedinlowpowerstate"></a>**PowerSettings/MaxTimeSessionsSkippedInLowPowerState**
|
<a href="" id="maxtimesessionsskippedinlowpowerstate"></a>**PowerSettings/MaxTimeSessionsSkippedInLowPowerState**
|
||||||
<p style="margin-left: 20px">Maximum time in minutes when the device can skip the check-in with the server if the device is in low power state. </p>
|
<p style="margin-left: 20px">Maximum time in minutes when the device can skip the check-in with the server if the device is in low-power state. </p>
|
||||||
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Replace, and Delete.</p>
|
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Replace, and Delete.</p>
|
||||||
|
@ -17,10 +17,21 @@ Windows 10 allows you to manage devices differently depending on location, netwo
|
|||||||
|
|
||||||
This CSP was added in Windows 10, version 1703.
|
This CSP was added in Windows 10, version 1703.
|
||||||
|
|
||||||
The following diagram shows the DynamicManagement configuration service provider in tree format.
|
The following shows the DynamicManagement configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Device/Vendor/MSFT
|
||||||
|
DynamicManagement
|
||||||
|
----NotificationsEnabled
|
||||||
|
----ActiveList
|
||||||
|
----Contexts
|
||||||
|
--------ContextID
|
||||||
|
------------SignalDefinition
|
||||||
|
------------SettingsPack
|
||||||
|
------------SettingsPackResponse
|
||||||
|
------------ContextStatus
|
||||||
|
------------Altitude
|
||||||
|
----AlertsEnabled
|
||||||
|
```
|
||||||
<a href="" id="dynamicmanagement"></a>**DynamicManagement**
|
<a href="" id="dynamicmanagement"></a>**DynamicManagement**
|
||||||
<p style="margin-left: 20px">The root node for the DynamicManagement configuration service provider.</p>
|
<p style="margin-left: 20px">The root node for the DynamicManagement configuration service provider.</p>
|
||||||
|
|
||||||
@ -53,7 +64,7 @@ The following diagram shows the DynamicManagement configuration service provider
|
|||||||
<p style="margin-left: 20px">Supported operation is Get.</p>
|
<p style="margin-left: 20px">Supported operation is Get.</p>
|
||||||
|
|
||||||
<a href="" id="contextid"></a>***ContextID***
|
<a href="" id="contextid"></a>***ContextID***
|
||||||
<p style="margin-left: 20px">Node created by the server to define a context. Maximum amount of characters allowed is 38.</p>
|
<p style="margin-left: 20px">Node created by the server to define a context. Maximum number of characters allowed is 38.</p>
|
||||||
<p style="margin-left: 20px">Supported operations are Add, Get, and Delete.</p>
|
<p style="margin-left: 20px">Supported operations are Add, Get, and Delete.</p>
|
||||||
|
|
||||||
<a href="" id="signaldefinition"></a>**SignalDefinition**
|
<a href="" id="signaldefinition"></a>**SignalDefinition**
|
||||||
@ -65,15 +76,15 @@ The following diagram shows the DynamicManagement configuration service provider
|
|||||||
<p style="margin-left: 20px">Value type is string. Supported operations are Add, Get, Delete, and Replace.</p>
|
<p style="margin-left: 20px">Value type is string. Supported operations are Add, Get, Delete, and Replace.</p>
|
||||||
|
|
||||||
<a href="" id="settingspackresponse"></a>**SettingsPackResponse**
|
<a href="" id="settingspackresponse"></a>**SettingsPackResponse**
|
||||||
<p style="margin-left: 20px">Response from applying a Settings Pack that contains information on each individual action..</p>
|
<p style="margin-left: 20px">Response from applying a Settings Pack that contains information on each individual action.</p>
|
||||||
<p style="margin-left: 20px">Value type is string. Supported operation is Get.</p>
|
<p style="margin-left: 20px">Value type is string. Supported operation is Get.</p>
|
||||||
|
|
||||||
<a href="" id="contextstatus"></a>**ContextStatus**
|
<a href="" id="contextstatus"></a>**ContextStatus**
|
||||||
<p style="margin-left: 20px">Reports status of the context. If there was a failure, SettingsPackResponse should be checked for what exactly failed..</p>
|
<p style="margin-left: 20px">Reports status of the context. If there was a failure, SettingsPackResponse should be checked for what exactly failed.</p>
|
||||||
<p style="margin-left: 20px">Value type is integer. Supported operation is Get.</p>
|
<p style="margin-left: 20px">Value type is integer. Supported operation is Get.</p>
|
||||||
|
|
||||||
<a href="" id="altitude"></a>**Altitude**
|
<a href="" id="altitude"></a>**Altitude**
|
||||||
<p style="margin-left: 20px">A value that determines how to handle conflict resolution of applying multiple contexts on the device. This is required and must be distinct of other priorities..</p>
|
<p style="margin-left: 20px">A value that determines how to handle conflict resolution of applying multiple contexts on the device. This is required and must be distinct of other priorities.</p>
|
||||||
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Delete, and Replace.</p>
|
<p style="margin-left: 20px">Value type is integer. Supported operations are Add, Get, Delete, and Replace.</p>
|
||||||
|
|
||||||
<a href="" id="alertsenabled"></a>**AlertsEnabled**
|
<a href="" id="alertsenabled"></a>**AlertsEnabled**
|
||||||
@ -82,7 +93,7 @@ The following diagram shows the DynamicManagement configuration service provider
|
|||||||
|
|
||||||
## Examples
|
## Examples
|
||||||
|
|
||||||
Disable Cortana based on Geo location and time, From 9am-5pm, when in the 100 meters radius of the specified latitude/longitude
|
Disable Cortana based on Geo location and time, From 9am-5pm, when in the 100-meters radius of the specified latitude/longitude
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
<Replace>
|
<Replace>
|
||||||
|
@ -22,10 +22,44 @@ On the desktop, only per user configuration is supported.
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the EMAIL2 configuration service provider management object in tree format as used by both OMA DM and OMA Client Provisioning.
|
The following shows the EMAIL2 configuration service provider management object in tree format as used by both OMA DM and OMA Client Provisioning.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EMAIL2
|
||||||
|
----Account GUID
|
||||||
|
--------ACCOUNTICON
|
||||||
|
--------ACCOUNTTYPE
|
||||||
|
--------AUTHNAME
|
||||||
|
--------AUTHREQUIRED
|
||||||
|
--------AUTHSECRET
|
||||||
|
--------DOMAIN
|
||||||
|
--------DWNDAY
|
||||||
|
--------INSERVER
|
||||||
|
--------LINGER
|
||||||
|
--------KEEPMAX
|
||||||
|
--------NAME
|
||||||
|
--------OUTSERVER
|
||||||
|
--------REPLYADDR
|
||||||
|
--------SERVICENAME
|
||||||
|
--------SERVICETYPE
|
||||||
|
--------RETRIEVE
|
||||||
|
--------SERVERDELETEACTION
|
||||||
|
--------CELLULARONLY
|
||||||
|
--------SYNCINGCONTENTTYPES
|
||||||
|
--------CONTACTSSERVER
|
||||||
|
--------CALENDARSERVER
|
||||||
|
--------CONTACTSSERVERREQUIRESSL
|
||||||
|
--------CALENDARSERVERREQUIRESSL
|
||||||
|
--------CONTACTSSYNCSCHEDULE
|
||||||
|
--------CALENDARSYNCSCHEDULE
|
||||||
|
--------SMTPALTAUTHNAME
|
||||||
|
--------SMTPALTDOMAIN
|
||||||
|
--------SMTPALTENABLED
|
||||||
|
--------SMTPALTPASSWORD
|
||||||
|
--------TAGPROPS
|
||||||
|
------------8128000B
|
||||||
|
------------812C000B
|
||||||
|
```
|
||||||
In Windows 10 Mobile, after the user’s out of box experience, an OEM or mobile operator can use the EMAIL2 configuration service provider to provision the device with a mobile operator’s proprietary mail over the air. After provisioning, the **Start** screen has a tile for the proprietary mail provider and there is also a link to it in the applications list under **Settings, email & accounts**. After an account has been updated over-the-air by the EMAIL2 CSP, the device must be powered off and then powered back on to see the sync status.
|
In Windows 10 Mobile, after the user’s out of box experience, an OEM or mobile operator can use the EMAIL2 configuration service provider to provision the device with a mobile operator’s proprietary mail over the air. After provisioning, the **Start** screen has a tile for the proprietary mail provider and there is also a link to it in the applications list under **Settings, email & accounts**. After an account has been updated over-the-air by the EMAIL2 CSP, the device must be powered off and then powered back on to see the sync status.
|
||||||
|
|
||||||
Configuration data is not encrypted when sent over the air (OTA). Be aware that this is a potential security risk when sending sensitive configuration data, such as passwords.
|
Configuration data is not encrypted when sent over the air (OTA). Be aware that this is a potential security risk when sending sensitive configuration data, such as passwords.
|
||||||
|
@ -18,10 +18,72 @@ ESP uses the EnrollmentStatusTracking CSP along with the DMClient CSP to track t
|
|||||||
The EnrollmentStatusTracking CSP was added in Windows 10, version 1903.
|
The EnrollmentStatusTracking CSP was added in Windows 10, version 1903.
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the EnrollmentStatusTracking CSP in tree format.
|
The following shows the EnrollmentStatusTracking CSP in tree format.
|
||||||
|
```
|
||||||
|
./User/Vendor/MSFT
|
||||||
|
EnrollmentStatusTracking
|
||||||
|
----Setup
|
||||||
|
--------Apps
|
||||||
|
------------PolicyProviders
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------TrackingPoliciesCreated
|
||||||
|
------------Tracking
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------AppName
|
||||||
|
------------------------TrackingUri
|
||||||
|
------------------------InstallationState
|
||||||
|
------------------------RebootRequired
|
||||||
|
--------HasProvisioningCompleted
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
./Device/Vendor/MSFT
|
||||||
|
EnrollmentStatusTracking
|
||||||
|
----DevicePreparation
|
||||||
|
--------PolicyProviders
|
||||||
|
------------ProviderName
|
||||||
|
----------------InstallationState
|
||||||
|
----------------LastError
|
||||||
|
----------------Timeout
|
||||||
|
----------------TrackedResourceTypes
|
||||||
|
--------------------Apps
|
||||||
|
----Setup
|
||||||
|
--------Apps
|
||||||
|
------------PolicyProviders
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------TrackingPoliciesCreated
|
||||||
|
------------Tracking
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------AppName
|
||||||
|
------------------------TrackingUri
|
||||||
|
------------------------InstallationState
|
||||||
|
------------------------RebootRequired
|
||||||
|
--------HasProvisioningCompleted
|
||||||
|
|
||||||
|
|
||||||
|
./User/Vendor/MSFT
|
||||||
|
./Device/Vendor/MSFT
|
||||||
|
EnrollmentStatusTracking
|
||||||
|
----DevicePreparation
|
||||||
|
--------PolicyProviders
|
||||||
|
------------ProviderName
|
||||||
|
----------------InstallationState
|
||||||
|
----------------LastError
|
||||||
|
----------------Timeout
|
||||||
|
----------------TrackedResourceTypes
|
||||||
|
--------------------Apps
|
||||||
|
----Setup
|
||||||
|
--------Apps
|
||||||
|
------------PolicyProviders
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------TrackingPoliciesCreated
|
||||||
|
------------Tracking
|
||||||
|
----------------ProviderName
|
||||||
|
--------------------AppName
|
||||||
|
------------------------TrackingUri
|
||||||
|
------------------------InstallationState
|
||||||
|
------------------------RebootRequired
|
||||||
|
--------HasProvisioningCompleted
|
||||||
|
```
|
||||||
<a href="" id="vendor-msft"></a>**./Vendor/MSFT**
|
<a href="" id="vendor-msft"></a>**./Vendor/MSFT**
|
||||||
For device context, use **./Device/Vendor/MSFT** path and for user context, use **./User/Vendor/MSFT** path.
|
For device context, use **./Device/Vendor/MSFT** path and for user context, use **./User/Vendor/MSFT** path.
|
||||||
|
|
||||||
|
@ -19,10 +19,25 @@ The EnterpriseAPN configuration service provider (CSP) is used by the enterprise
|
|||||||
> [!Note]
|
> [!Note]
|
||||||
> Starting in Windows 10, version 1703 the EnterpriseAPN CSP is supported in Windows 10 Home, Pro, Enterprise, and Education editions.
|
> Starting in Windows 10, version 1703 the EnterpriseAPN CSP is supported in Windows 10 Home, Pro, Enterprise, and Education editions.
|
||||||
|
|
||||||
The following image shows the EnterpriseAPN configuration service provider in tree format.
|
The following shows the EnterpriseAPN configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseAPN
|
||||||
|
----ConnectionName
|
||||||
|
--------APNName
|
||||||
|
--------IPType
|
||||||
|
--------IsAttachAPN
|
||||||
|
--------ClassId
|
||||||
|
--------AuthType
|
||||||
|
--------UserName
|
||||||
|
--------Password
|
||||||
|
--------IccId
|
||||||
|
--------AlwaysOn
|
||||||
|
--------Enabled
|
||||||
|
----Settings
|
||||||
|
--------AllowUserControl
|
||||||
|
--------HideView
|
||||||
|
```
|
||||||
<a href="" id="enterpriseapn"></a>**EnterpriseAPN**
|
<a href="" id="enterpriseapn"></a>**EnterpriseAPN**
|
||||||
<p style="margin-left: 20px">The root node for the EnterpriseAPN configuration service provider.</p>
|
<p style="margin-left: 20px">The root node for the EnterpriseAPN configuration service provider.</p>
|
||||||
|
|
||||||
|
@ -15,10 +15,35 @@ manager: dansimp
|
|||||||
|
|
||||||
The EnterpriseAppVManagement configuration service provider (CSP) is used to manage virtual applications in Windows 10 PCs (Enterprise and Education editions). This CSP was added in Windows 10, version 1703.
|
The EnterpriseAppVManagement configuration service provider (CSP) is used to manage virtual applications in Windows 10 PCs (Enterprise and Education editions). This CSP was added in Windows 10, version 1703.
|
||||||
|
|
||||||
The following diagram shows the EnterpriseAppVManagement configuration service provider in tree format.
|
The following shows the EnterpriseAppVManagement configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseAppVManagement
|
||||||
|
----AppVPackageManagement
|
||||||
|
--------EnterpriseID
|
||||||
|
------------PackageFamilyName
|
||||||
|
----------------PackageFullName
|
||||||
|
--------------------Name
|
||||||
|
--------------------Version
|
||||||
|
--------------------Publisher
|
||||||
|
--------------------InstallLocation
|
||||||
|
--------------------InstallDate
|
||||||
|
--------------------Users
|
||||||
|
--------------------AppVPackageId
|
||||||
|
--------------------AppVVersionId
|
||||||
|
--------------------AppVPackageUri
|
||||||
|
----AppVPublishing
|
||||||
|
--------LastSync
|
||||||
|
------------LastError
|
||||||
|
------------LastErrorDescription
|
||||||
|
------------SyncStatusDescription
|
||||||
|
------------SyncProgress
|
||||||
|
--------Sync
|
||||||
|
------------PublishXML
|
||||||
|
----AppVDynamicPolicy
|
||||||
|
--------ConfigurationId
|
||||||
|
------------Policy
|
||||||
|
```
|
||||||
**./Vendor/MSFT/EnterpriseAppVManagement**
|
**./Vendor/MSFT/EnterpriseAppVManagement**
|
||||||
<p style="margin-left: 20px">Root node for the EnterpriseAppVManagement configuration service provider.</p>
|
<p style="margin-left: 20px">Root node for the EnterpriseAppVManagement configuration service provider.</p>
|
||||||
|
|
||||||
|
@ -22,10 +22,23 @@ The EnterpriseAssignedAccess configuration service provider allows IT administra
|
|||||||
|
|
||||||
To use an app to create a lockdown XML see [Use the Lockdown Designer app to create a Lockdown XML file](https://docs.microsoft.com/windows/configuration/mobile-devices/mobile-lockdown-designer). For more information about how to interact with the lockdown XML at runtime, see [**DeviceLockdownProfile class**](https://msdn.microsoft.com/library/windows/hardware/mt186983).
|
To use an app to create a lockdown XML see [Use the Lockdown Designer app to create a Lockdown XML file](https://docs.microsoft.com/windows/configuration/mobile-devices/mobile-lockdown-designer). For more information about how to interact with the lockdown XML at runtime, see [**DeviceLockdownProfile class**](https://msdn.microsoft.com/library/windows/hardware/mt186983).
|
||||||
|
|
||||||
The following diagram shows the EnterpriseAssignedAccess configuration service provider in tree format as used by both the Open Mobile Alliance (OMA) Device Management (DM) and OMA Client Provisioning.
|
The following shows the EnterpriseAssignedAccess configuration service provider in tree format as used by both the Open Mobile Alliance (OMA) Device Management (DM) and OMA Client Provisioning.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseAssignedAccess
|
||||||
|
----AssignedAccess
|
||||||
|
--------AssignedAccessXml
|
||||||
|
----LockScreenWallpaper
|
||||||
|
--------BGFileName
|
||||||
|
----Theme
|
||||||
|
--------ThemeBackground
|
||||||
|
--------ThemeAccentColorID
|
||||||
|
--------ThemeAccentColorValue
|
||||||
|
----Clock
|
||||||
|
--------TimeZone
|
||||||
|
----Locale
|
||||||
|
--------Language
|
||||||
|
```
|
||||||
The following list shows the characteristics and parameters.
|
The following list shows the characteristics and parameters.
|
||||||
|
|
||||||
<a href="" id="-vendor-msft-enterpriseassignedaccess-"></a>**./Vendor/MSFT/EnterpriseAssignedAccess/**
|
<a href="" id="-vendor-msft-enterpriseassignedaccess-"></a>**./Vendor/MSFT/EnterpriseAssignedAccess/**
|
||||||
|
@ -29,10 +29,22 @@ To learn more about WIP, see the following articles:
|
|||||||
- [Create a Windows Information Protection (WIP) policy](https://technet.microsoft.com/itpro/windows/keep-secure/overview-create-wip-policy)
|
- [Create a Windows Information Protection (WIP) policy](https://technet.microsoft.com/itpro/windows/keep-secure/overview-create-wip-policy)
|
||||||
- [General guidance and best practices for Windows Information Protection (WIP)](https://technet.microsoft.com/itpro/windows/keep-secure/guidance-and-best-practices-wip)
|
- [General guidance and best practices for Windows Information Protection (WIP)](https://technet.microsoft.com/itpro/windows/keep-secure/guidance-and-best-practices-wip)
|
||||||
|
|
||||||
The following diagram shows the EnterpriseDataProtection CSP in tree format.
|
The following shows the EnterpriseDataProtection CSP in tree format.
|
||||||
|
```
|
||||||

|
./Device/Vendor/MSFT
|
||||||
|
EnterpriseDataProtection
|
||||||
|
----Settings
|
||||||
|
--------EDPEnforcementLevel
|
||||||
|
--------EnterpriseProtectedDomainNames
|
||||||
|
--------AllowUserDecryption
|
||||||
|
--------RequireProtectionUnderLockConfig
|
||||||
|
--------DataRecoveryCertificate
|
||||||
|
--------RevokeOnUnenroll
|
||||||
|
--------RMSTemplateIDForEDP
|
||||||
|
--------AllowAzureRMSForEDP
|
||||||
|
--------EDPShowIcons
|
||||||
|
----Status
|
||||||
|
```
|
||||||
<a href="" id="--device-vendor-msft-enterprisedataprotection"></a>**./Device/Vendor/MSFT/EnterpriseDataProtection**
|
<a href="" id="--device-vendor-msft-enterprisedataprotection"></a>**./Device/Vendor/MSFT/EnterpriseDataProtection**
|
||||||
The root node for the CSP.
|
The root node for the CSP.
|
||||||
|
|
||||||
|
@ -19,10 +19,24 @@ The EnterpriseDesktopAppManagement configuration service provider is used to han
|
|||||||
|
|
||||||
Application installations can take some time to complete, hence they are done asynchronously. When the Exec command is completed, the client can send a generic alert to the management server with a status, whether it's a failure or success. For a SyncML example, see [Alert example](#alert-example).
|
Application installations can take some time to complete, hence they are done asynchronously. When the Exec command is completed, the client can send a generic alert to the management server with a status, whether it's a failure or success. For a SyncML example, see [Alert example](#alert-example).
|
||||||
|
|
||||||
The following diagram shows the EnterpriseDesktopAppManagement CSP in tree format.
|
The following shows the EnterpriseDesktopAppManagement CSP in tree format.
|
||||||
|
```
|
||||||

|
./Device/Vendor/MSFT
|
||||||
|
EnterpriseDesktopAppManagement
|
||||||
|
----MSI
|
||||||
|
--------ProductID
|
||||||
|
------------Version
|
||||||
|
------------Name
|
||||||
|
------------Publisher
|
||||||
|
------------InstallPath
|
||||||
|
------------InstallDate
|
||||||
|
------------DownloadInstall
|
||||||
|
------------Status
|
||||||
|
------------LastError
|
||||||
|
------------LastErrorDesc
|
||||||
|
--------UpgradeCode
|
||||||
|
------------Guid
|
||||||
|
```
|
||||||
<a href="" id="--vendor-msft-enterprisedesktopappmanagement"></a>**./Device/Vendor/MSFT/EnterpriseDesktopAppManagement**
|
<a href="" id="--vendor-msft-enterprisedesktopappmanagement"></a>**./Device/Vendor/MSFT/EnterpriseDesktopAppManagement**
|
||||||
The root node for the EnterpriseDesktopAppManagement configuration service provider.
|
The root node for the EnterpriseDesktopAppManagement configuration service provider.
|
||||||
|
|
||||||
|
@ -21,10 +21,23 @@ The EnterpriseExt configuration service provider allows OEMs to set their own un
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the EnterpriseExt configuration service provider in tree format as used by both the Open Mobile Alliance (OMA) Device Management (DM) and OMA Client Provisioning.
|
The following shows the EnterpriseExt configuration service provider in tree format as used by both the Open Mobile Alliance (OMA) Device Management (DM) and OMA Client Provisioning.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseExt
|
||||||
|
----DeviceCustomData
|
||||||
|
--------CustomID
|
||||||
|
--------CustomString
|
||||||
|
----Brightness
|
||||||
|
--------Default
|
||||||
|
--------MaxAuto
|
||||||
|
----LedAlertNotification
|
||||||
|
--------State
|
||||||
|
--------Intensity
|
||||||
|
--------Period
|
||||||
|
--------DutyCycle
|
||||||
|
--------Cyclecount
|
||||||
|
```
|
||||||
The following list shows the characteristics and parameters.
|
The following list shows the characteristics and parameters.
|
||||||
|
|
||||||
<a href="" id="--vendor-msft-enterpriseext"></a>**./Vendor/MSFT/EnterpriseExt**
|
<a href="" id="--vendor-msft-enterpriseext"></a>**./Vendor/MSFT/EnterpriseExt**
|
||||||
|
@ -23,10 +23,20 @@ The EnterpriseExtFileSystem configuration service provider (CSP) allows IT admin
|
|||||||
|
|
||||||
File contents are embedded directly into the syncML message, so there is a limit to the size of the file that can be retrieved from the device. The default limit is 0x100000 (1 MB). You can configure this limit by using the following registry key: **Software\\Microsoft\\Provisioning\\CSPs\\.\\Vendor\\MSFT\\EnterpriseExtFileSystem\\MaxFileReadSize**.
|
File contents are embedded directly into the syncML message, so there is a limit to the size of the file that can be retrieved from the device. The default limit is 0x100000 (1 MB). You can configure this limit by using the following registry key: **Software\\Microsoft\\Provisioning\\CSPs\\.\\Vendor\\MSFT\\EnterpriseExtFileSystem\\MaxFileReadSize**.
|
||||||
|
|
||||||
The following diagram shows the EnterpriseExtFileSystem configuration service provider in tree format as used by the Open Mobile Alliance (OMA) Device Management (DM).
|
The following shows the EnterpriseExtFileSystem configuration service provider in tree format as used by the Open Mobile Alliance (OMA) Device Management (DM).
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseExtFileSystem
|
||||||
|
----Persistent
|
||||||
|
--------Files_abc1
|
||||||
|
--------Directory_abc2
|
||||||
|
----NonPersistent
|
||||||
|
--------Files_abc3
|
||||||
|
--------Directory_abc4
|
||||||
|
----OemProfile
|
||||||
|
--------Directory_abc5
|
||||||
|
--------Files_abc6
|
||||||
|
```
|
||||||
The following list describes the characteristics and parameters.
|
The following list describes the characteristics and parameters.
|
||||||
|
|
||||||
<a href="" id="--vendor-msft-enterpriseextfilesystem"></a>**./Vendor/MSFT/EnterpriseExtFileSystem**
|
<a href="" id="--vendor-msft-enterpriseextfilesystem"></a>**./Vendor/MSFT/EnterpriseExtFileSystem**
|
||||||
|
@ -19,10 +19,51 @@ The EnterpriseModernAppManagement configuration service provider (CSP) is used f
|
|||||||
> [!Note]
|
> [!Note]
|
||||||
> Windows Holographic only supports per-user configuration of the EnterpriseModernAppManagement CSP.
|
> Windows Holographic only supports per-user configuration of the EnterpriseModernAppManagement CSP.
|
||||||
|
|
||||||
The following image shows the EnterpriseModernAppManagement configuration service provider in tree format.
|
The following shows the EnterpriseModernAppManagement configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
EnterpriseModernAppManagement
|
||||||
|
----AppManagement
|
||||||
|
--------EnterpriseID
|
||||||
|
------------PackageFamilyName
|
||||||
|
----------------PackageFullName
|
||||||
|
--------------------Name
|
||||||
|
--------------------Version
|
||||||
|
--------------------Publisher
|
||||||
|
--------------------Architecture
|
||||||
|
--------------------InstallLocation
|
||||||
|
--------------------IsFramework
|
||||||
|
--------------------IsBundle
|
||||||
|
--------------------InstallDate
|
||||||
|
--------------------ResourceID
|
||||||
|
--------------------PackageStatus
|
||||||
|
--------------------RequiresReinstall
|
||||||
|
--------------------Users
|
||||||
|
--------------------IsProvisioned
|
||||||
|
----------------DoNotUpdate
|
||||||
|
----------------AppSettingPolicy
|
||||||
|
--------------------SettingValue
|
||||||
|
--------UpdateScan
|
||||||
|
--------LastScanError
|
||||||
|
--------AppInventoryResults
|
||||||
|
--------AppInventoryQuery
|
||||||
|
----AppInstallation
|
||||||
|
--------PackageFamilyName
|
||||||
|
------------StoreInstall
|
||||||
|
------------HostedInstall
|
||||||
|
------------LastError
|
||||||
|
------------LastErrorDesc
|
||||||
|
------------Status
|
||||||
|
------------ProgressStatus
|
||||||
|
----AppLicenses
|
||||||
|
--------StoreLicenses
|
||||||
|
------------LicenseID
|
||||||
|
----------------LicenseCategory
|
||||||
|
----------------LicenseUsage
|
||||||
|
----------------RequesterID
|
||||||
|
----------------AddLicense
|
||||||
|
----------------GetLicenseFromStore
|
||||||
|
```
|
||||||
<a href="" id="device-or-user-context"></a>**Device or User context**
|
<a href="" id="device-or-user-context"></a>**Device or User context**
|
||||||
For user context, use **./User/Vendor/MSFT** path and for device context, use **./Device/Vendor/MSFT** path.
|
For user context, use **./User/Vendor/MSFT** path and for device context, use **./Device/Vendor/MSFT** path.
|
||||||
|
|
||||||
|
@ -16,10 +16,30 @@ manager: dansimp
|
|||||||
|
|
||||||
The eUICCs configuration service provider is used to support eUICC enterprise use cases and enables the IT admin to manage (assign, re-assign, remove) subscriptions to employees. This CSP was added in windows 10, version 1709.
|
The eUICCs configuration service provider is used to support eUICC enterprise use cases and enables the IT admin to manage (assign, re-assign, remove) subscriptions to employees. This CSP was added in windows 10, version 1709.
|
||||||
|
|
||||||
The following diagram shows the eUICCs configuration service provider in tree format.
|
The following shows the eUICCs configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Device/Vendor/MSFT
|
||||||
|
eUICCs
|
||||||
|
----eUICC
|
||||||
|
--------Identifier
|
||||||
|
--------IsActive
|
||||||
|
--------PPR1Allowed
|
||||||
|
--------PPR1AlreadySet
|
||||||
|
--------Profiles
|
||||||
|
------------ICCID
|
||||||
|
----------------ServerName
|
||||||
|
----------------MatchingID
|
||||||
|
----------------State
|
||||||
|
----------------IsEnabled
|
||||||
|
----------------PPR1Set
|
||||||
|
----------------PPR2Set
|
||||||
|
----------------ErrorDetail
|
||||||
|
--------Policies
|
||||||
|
------------LocalUIEnabled
|
||||||
|
--------Actions
|
||||||
|
------------ResetToFactoryState
|
||||||
|
------------Status
|
||||||
|
```
|
||||||
<a href="" id="--vendor-msft-euiccs"></a>**./Vendor/MSFT/eUICCs**
|
<a href="" id="--vendor-msft-euiccs"></a>**./Vendor/MSFT/eUICCs**
|
||||||
Root node.
|
Root node.
|
||||||
|
|
||||||
|
@ -20,10 +20,88 @@ Firewall rules in the FirewallRules section must be wrapped in an Atomic block i
|
|||||||
|
|
||||||
For detailed information on some of the fields below see [[MS-FASP]: Firewall and Advanced Security Protocol documentation](https://msdn.microsoft.com/library/mt620101.aspx).
|
For detailed information on some of the fields below see [[MS-FASP]: Firewall and Advanced Security Protocol documentation](https://msdn.microsoft.com/library/mt620101.aspx).
|
||||||
|
|
||||||
The following diagram shows the Firewall configuration service provider in tree format.
|
The following shows the Firewall configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
Firewall
|
||||||
|
----
|
||||||
|
--------Global
|
||||||
|
------------PolicyVersionSupported
|
||||||
|
------------CurrentProfiles
|
||||||
|
------------DisableStatefulFtp
|
||||||
|
------------SaIdleTime
|
||||||
|
------------PresharedKeyEncoding
|
||||||
|
------------IPsecExempt
|
||||||
|
------------CRLcheck
|
||||||
|
------------PolicyVersion
|
||||||
|
------------BinaryVersionSupported
|
||||||
|
------------OpportunisticallyMatchAuthSetPerKM
|
||||||
|
------------EnablePacketQueue
|
||||||
|
--------DomainProfile
|
||||||
|
------------EnableFirewall
|
||||||
|
------------DisableStealthMode
|
||||||
|
------------Shielded
|
||||||
|
------------DisableUnicastResponsesToMulticastBroadcast
|
||||||
|
------------DisableInboundNotifications
|
||||||
|
------------AuthAppsAllowUserPrefMerge
|
||||||
|
------------GlobalPortsAllowUserPrefMerge
|
||||||
|
------------AllowLocalPolicyMerge
|
||||||
|
------------AllowLocalIpsecPolicyMerge
|
||||||
|
------------DefaultOutboundAction
|
||||||
|
------------DefaultInboundAction
|
||||||
|
------------DisableStealthModeIpsecSecuredPacketExemption
|
||||||
|
--------PrivateProfile
|
||||||
|
------------EnableFirewall
|
||||||
|
------------DisableStealthMode
|
||||||
|
------------Shielded
|
||||||
|
------------DisableUnicastResponsesToMulticastBroadcast
|
||||||
|
------------DisableInboundNotifications
|
||||||
|
------------AuthAppsAllowUserPrefMerge
|
||||||
|
------------GlobalPortsAllowUserPrefMerge
|
||||||
|
------------AllowLocalPolicyMerge
|
||||||
|
------------AllowLocalIpsecPolicyMerge
|
||||||
|
------------DefaultOutboundAction
|
||||||
|
------------DefaultInboundAction
|
||||||
|
------------DisableStealthModeIpsecSecuredPacketExemption
|
||||||
|
--------PublicProfile
|
||||||
|
------------EnableFirewall
|
||||||
|
------------DisableStealthMode
|
||||||
|
------------Shielded
|
||||||
|
------------DisableUnicastResponsesToMulticastBroadcast
|
||||||
|
------------DisableInboundNotifications
|
||||||
|
------------AuthAppsAllowUserPrefMerge
|
||||||
|
------------GlobalPortsAllowUserPrefMerge
|
||||||
|
------------AllowLocalPolicyMerge
|
||||||
|
------------AllowLocalIpsecPolicyMerge
|
||||||
|
------------DefaultOutboundAction
|
||||||
|
------------DefaultInboundAction
|
||||||
|
------------DisableStealthModeIpsecSecuredPacketExemption
|
||||||
|
--------FirewallRules
|
||||||
|
------------FirewallRuleName
|
||||||
|
----------------App
|
||||||
|
--------------------PackageFamilyName
|
||||||
|
--------------------FilePath
|
||||||
|
--------------------Fqbn
|
||||||
|
--------------------ServiceName
|
||||||
|
----------------Protocol
|
||||||
|
----------------LocalPortRanges
|
||||||
|
----------------RemotePortRanges
|
||||||
|
----------------LocalAddressRanges
|
||||||
|
----------------RemoteAddressRanges
|
||||||
|
----------------Description
|
||||||
|
----------------Enabled
|
||||||
|
----------------Profiles
|
||||||
|
----------------Action
|
||||||
|
--------------------Type
|
||||||
|
----------------Direction
|
||||||
|
----------------InterfaceTypes
|
||||||
|
----------------EdgeTraversal
|
||||||
|
----------------LocalUserAuthorizationList
|
||||||
|
----------------FriendlyName
|
||||||
|
----------------IcmpTypesAndCodes
|
||||||
|
----------------Status
|
||||||
|
----------------Name
|
||||||
|
```
|
||||||
<a href="" id="--vendor-msft-applocker"></a>**./Vendor/MSFT/Firewall**
|
<a href="" id="--vendor-msft-applocker"></a>**./Vendor/MSFT/Firewall**
|
||||||
<p style="margin-left: 20px">Root node for the Firewall configuration service provider.</p>
|
<p style="margin-left: 20px">Root node for the Firewall configuration service provider.</p>
|
||||||
|
|
||||||
|
@ -37,7 +37,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
**DHA-Session (Device HealthAttestation session)**
|
**DHA-Session (Device HealthAttestation session)**
|
||||||
<p style="margin-left: 20px">The Device HealthAttestation session (DHA-Session) describes the end-to-end communication flow that is performed in one device health attestation session.</p>
|
<p style="margin-left: 20px">The Device HealthAttestation session (DHA-Session) describes the end-to-end communication flow that is performed in one device health attestation session.</p>
|
||||||
|
|
||||||
<p style="margin-left: 20px">The following list of transactions are performed in one DHA-Session:</p>
|
<p style="margin-left: 20px">The following list of transactions is performed in one DHA-Session:</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>DHA-CSP and DHA-Service communication:
|
<li>DHA-CSP and DHA-Service communication:
|
||||||
<ul><li>DHA-CSP forwards device boot data (DHA-BootData) to DHA-Service</li>
|
<ul><li>DHA-CSP forwards device boot data (DHA-BootData) to DHA-Service</li>
|
||||||
@ -75,7 +75,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
<strong>DHA-Enabled MDM (Device HealthAttestation enabled device management solution)</strong>
|
<strong>DHA-Enabled MDM (Device HealthAttestation enabled device management solution)</strong>
|
||||||
<p style="margin-left: 20px">Device HealthAttestation enabled (DHA-Enabled) device management solution is a device management tool that is integrated with the DHA feature.</p>
|
<p style="margin-left: 20px">Device HealthAttestation enabled (DHA-Enabled) device management solution is a device management tool that is integrated with the DHA feature.</p>
|
||||||
<p style="margin-left: 20px">DHA-Enabled device management solutions enable enterprise IT managers to raise the security protection bar for their managed devices based on hardware (TPM) protected data that can be trusted even if a device is compromised by advanced security threats or running a malicious (jailbroken) operating system.</p>
|
<p style="margin-left: 20px">DHA-Enabled device management solutions enable enterprise IT managers to raise the security protection bar for their managed devices based on hardware (TPM) protected data that can be trusted even if a device is compromised by advanced security threats or running a malicious (jailbroken) operating system.</p>
|
||||||
<p style="margin-left: 20px">The following list of operations are performed by DHA-Enabled-MDM:</p>
|
<p style="margin-left: 20px">The following list of operations is performed by DHA-Enabled-MDM</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>Enables the DHA feature on a DHA-Enabled device</li>
|
<li>Enables the DHA feature on a DHA-Enabled device</li>
|
||||||
<li>Issues device health attestation requests to enrolled/managed devices</li>
|
<li>Issues device health attestation requests to enrolled/managed devices</li>
|
||||||
@ -85,7 +85,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
|
|
||||||
<strong>DHA-CSP (Device HealthAttestation Configuration Service Provider)</strong>
|
<strong>DHA-CSP (Device HealthAttestation Configuration Service Provider)</strong>
|
||||||
<p style="margin-left: 20px">The Device HealthAttestation Configuration Service Provider (DHA-CSP) uses a device’s TPM and firmware to measure critical security properties of the device’s BIOS and Windows boot, such that even on a system infected with kernel level malware or a rootkit, these properties cannot be spoofed.</p>
|
<p style="margin-left: 20px">The Device HealthAttestation Configuration Service Provider (DHA-CSP) uses a device’s TPM and firmware to measure critical security properties of the device’s BIOS and Windows boot, such that even on a system infected with kernel level malware or a rootkit, these properties cannot be spoofed.</p>
|
||||||
<p style="margin-left: 20px">The following list of operations are performed by DHA-CSP:</p>
|
<p style="margin-left: 20px">The following list of operations is performed by DHA-CSP:</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>Collects device boot data (DHA-BootData) from a managed device</li>
|
<li>Collects device boot data (DHA-BootData) from a managed device</li>
|
||||||
<li>Forwards DHA-BootData to Device Health Attestation Service (DHA-Service)</li>
|
<li>Forwards DHA-BootData to Device Health Attestation Service (DHA-Service)</li>
|
||||||
@ -97,7 +97,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
<p style="margin-left: 20px">Device HealthAttestation Service (DHA-Service) validates the data it receives from DHA-CSP and issues a highly trusted hardware (TPM) protected report (DHA-Report) to DHA-Enabled device management solutions through a tamper resistant and tamper evident communication channel.</p>
|
<p style="margin-left: 20px">Device HealthAttestation Service (DHA-Service) validates the data it receives from DHA-CSP and issues a highly trusted hardware (TPM) protected report (DHA-Report) to DHA-Enabled device management solutions through a tamper resistant and tamper evident communication channel.</p>
|
||||||
|
|
||||||
<p style="margin-left: 20px">DHA-Service is available in 2 flavors: “DHA-Cloud” and “DHA-Server2016”. DHA-Service supports a variety of implementation scenarios including cloud, on premises, air-gapped, and hybrid scenarios.</p>
|
<p style="margin-left: 20px">DHA-Service is available in 2 flavors: “DHA-Cloud” and “DHA-Server2016”. DHA-Service supports a variety of implementation scenarios including cloud, on premises, air-gapped, and hybrid scenarios.</p>
|
||||||
<p style="margin-left: 20px">The following list of operations are performed by DHA-Service:</p>
|
<p style="margin-left: 20px">The following list of operations is performed by DHA-Service:</p>
|
||||||
|
|
||||||
- Receives device boot data (DHA-BootData) from a DHA-Enabled device</li>
|
- Receives device boot data (DHA-BootData) from a DHA-Enabled device</li>
|
||||||
- Forwards DHA-BootData to Device Health Attestation Service (DHA-Service) </li>
|
- Forwards DHA-BootData to Device Health Attestation Service (DHA-Service) </li>
|
||||||
@ -126,7 +126,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
<li>Available in Windows for free</li>
|
<li>Available in Windows for free</li>
|
||||||
<li>Running on a high-availability and geo-balanced cloud infrastructure </li>
|
<li>Running on a high-availability and geo-balanced cloud infrastructure </li>
|
||||||
<li>Supported by most DHA-Enabled device management solutions as the default device attestation service provider</li>
|
<li>Supported by most DHA-Enabled device management solutions as the default device attestation service provider</li>
|
||||||
<li>Accessible to all enterprise managed devices via following:
|
<li>Accessible to all enterprise-managed devices via following:
|
||||||
<ul>
|
<ul>
|
||||||
<li>FQDN = has.spserv.microsoft.com) port</li>
|
<li>FQDN = has.spserv.microsoft.com) port</li>
|
||||||
<li>Port = 443</li>
|
<li>Port = 443</li>
|
||||||
@ -144,7 +144,7 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
<li>Offered to Windows Server 2016 customer (no added licensing cost for enabling/running DHA-Service) </li>
|
<li>Offered to Windows Server 2016 customer (no added licensing cost for enabling/running DHA-Service) </li>
|
||||||
<li>Hosted on an enterprise owned and managed server device/hardware</li>
|
<li>Hosted on an enterprise owned and managed server device/hardware</li>
|
||||||
<li>Supported by 1st and 3rd party DHA-Enabled device management solution providers that support on-premises and hybrid (Cloud + OnPrem) hardware attestation scenarios</li>
|
<li>Supported by 1st and 3rd party DHA-Enabled device management solution providers that support on-premises and hybrid (Cloud + OnPrem) hardware attestation scenarios</li>
|
||||||
<li><p>Accessible to all enterprise managed devices via following:</p>
|
<li><p>Accessible to all enterprise-managed devices via following:</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>FQDN = (enterprise assigned)</li>
|
<li>FQDN = (enterprise assigned)</li>
|
||||||
<li>Port = (enterprise assigned)</li>
|
<li>Port = (enterprise assigned)</li>
|
||||||
@ -155,12 +155,12 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
<td style="vertical-align:top">The operation cost of running one or more instances of Server 2016 on-premises.</td>
|
<td style="vertical-align:top">The operation cost of running one or more instances of Server 2016 on-premises.</td>
|
||||||
</tr>
|
</tr>
|
||||||
<tr class="even">
|
<tr class="even">
|
||||||
<td style="vertical-align:top">Device Health Attestation - Enterprise Managed Cloud<p>(DHA-EMC)</p></td>
|
<td style="vertical-align:top">Device Health Attestation - Enterprise-Managed Cloud<p>(DHA-EMC)</p></td>
|
||||||
<td style="vertical-align:top"><p>DHA-EMC refers to an enterprise managed DHA-Service that is running as a virtual host/service on a Windows Server 2016 compatible - enterprise managed cloud service, such as Microsoft Azure.</p>
|
<td style="vertical-align:top"><p>DHA-EMC refers to an enterprise-managed DHA-Service that is running as a virtual host/service on a Windows Server 2016 compatible - enterprise-managed cloud service, such as Microsoft Azure.</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>Offered to Windows Server 2016 customers with no additional licensing cost (no added licensing cost for enabling/running DHA-Service)</li>
|
<li>Offered to Windows Server 2016 customers with no additional licensing cost (no added licensing cost for enabling/running DHA-Service)</li>
|
||||||
<li>Supported by 1st and 3rd party DHA-Enabled device management solution providers that support on-premises and hybrid (Cloud + OnPrem) hardware attestation scenarios </li>
|
<li>Supported by 1st and 3rd party DHA-Enabled device management solution providers that support on-premises and hybrid (Cloud + OnPrem) hardware attestation scenarios </li>
|
||||||
<li><p>Accessible to all enterprise managed devices via following:</p>
|
<li><p>Accessible to all enterprise-managed devices via following:</p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>FQDN = (enterprise assigned)</li>
|
<li>FQDN = (enterprise assigned)</li>
|
||||||
<li>Port = (enterprise assigned)</li>
|
<li>Port = (enterprise assigned)</li>
|
||||||
@ -176,10 +176,22 @@ The following is a list of functions performed by the Device HealthAttestation C
|
|||||||
## CSP diagram and node descriptions
|
## CSP diagram and node descriptions
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the Device HealthAttestation configuration service provider in tree format.
|
The following shows the Device HealthAttestation configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
HealthAttestation
|
||||||
|
----VerifyHealth
|
||||||
|
----Status
|
||||||
|
----ForceRetrieve
|
||||||
|
----Certificate
|
||||||
|
----Nonce
|
||||||
|
----CorrelationID
|
||||||
|
----HASEndpoint
|
||||||
|
----TpmReadyStatus
|
||||||
|
----CurrentProtocolVersion
|
||||||
|
----PreferredMaxProtocolVersion
|
||||||
|
----MaxSupportedProtocolVersion
|
||||||
|
```
|
||||||
<a href="" id="healthattestation"></a>**./Vendor/MSFT/HealthAttestation**
|
<a href="" id="healthattestation"></a>**./Vendor/MSFT/HealthAttestation**
|
||||||
<p style="margin-left: 20px">The root node for the device HealthAttestation configuration service provider.</p>
|
<p style="margin-left: 20px">The root node for the device HealthAttestation configuration service provider.</p>
|
||||||
|
|
||||||
@ -306,13 +318,13 @@ SSL-Session:
|
|||||||
There are three types of DHA-Service:
|
There are three types of DHA-Service:
|
||||||
- Device Health Attestation – Cloud (owned and operated by Microsoft)
|
- Device Health Attestation – Cloud (owned and operated by Microsoft)
|
||||||
- Device Health Attestation – On Premise (owned and operated by an enterprise, runs on Windows Server 2016 on premises)
|
- Device Health Attestation – On Premise (owned and operated by an enterprise, runs on Windows Server 2016 on premises)
|
||||||
- Device Health Attestation - Enterprise Managed Cloud (owned and operated by an enterprise, runs on Windows Server 2016 compatible enterprise managed cloud)
|
- Device Health Attestation - Enterprise-Managed Cloud (owned and operated by an enterprise, runs on Windows Server 2016 compatible enterprise-managed cloud)
|
||||||
|
|
||||||
DHA-Cloud is the default setting. No further action is required if an enterprise is planning to use Microsoft DHA-Cloud as the trusted DHA-Service provider.
|
DHA-Cloud is the default setting. No further action is required if an enterprise is planning to use Microsoft DHA-Cloud as the trusted DHA-Service provider.
|
||||||
|
|
||||||
For DHA-OnPrem & DHA-EMC scenarios, send a SyncML command to the HASEndpoint node to instruct a managed device to communicate with the enterprise trusted DHA-Service.
|
For DHA-OnPrem & DHA-EMC scenarios, send a SyncML command to the HASEndpoint node to instruct a managed device to communicate with the enterprise trusted DHA-Service.
|
||||||
|
|
||||||
The following example shows a sample call that instructs a managed device to communicate with an enterprise managed DHA-Service.
|
The following example shows a sample call that instructs a managed device to communicate with an enterprise-managed DHA-Service.
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
<Replace>
|
<Replace>
|
||||||
|
@ -21,10 +21,14 @@ The Maps configuration service provider (CSP) is used to configure the maps to d
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the Maps configuration service provider in tree format.
|
The following shows the Maps configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Vendor/MSFT
|
||||||
|
Maps
|
||||||
|
----Packages
|
||||||
|
--------Package
|
||||||
|
------------Status
|
||||||
|
```
|
||||||
<a href="" id="maps"></a>**Maps**
|
<a href="" id="maps"></a>**Maps**
|
||||||
Root node.
|
Root node.
|
||||||
|
|
||||||
|
@ -17,10 +17,22 @@ manager: dansimp
|
|||||||
The MultiSIM configuration service provider (CSP) is used by the enterprise to manage devices with dual SIM single active configuration. An enterprise can set policies on whether that user can switch between SIM slots, specify which slot is the default, and whether the slot is embedded. This CSP was added in Windows 10, version 1803.
|
The MultiSIM configuration service provider (CSP) is used by the enterprise to manage devices with dual SIM single active configuration. An enterprise can set policies on whether that user can switch between SIM slots, specify which slot is the default, and whether the slot is embedded. This CSP was added in Windows 10, version 1803.
|
||||||
|
|
||||||
|
|
||||||
The following diagram shows the MultiSIM configuration service provider in tree format.
|
The following shows the MultiSIM configuration service provider in tree format.
|
||||||
|
```
|
||||||

|
./Device/Vendor/MSFT
|
||||||
|
MultiSIM
|
||||||
|
----ModemID
|
||||||
|
--------Identifier
|
||||||
|
--------IsEmbedded
|
||||||
|
--------Slots
|
||||||
|
------------SlotID
|
||||||
|
----------------Identifier
|
||||||
|
----------------IsEmbedded
|
||||||
|
----------------IsSelected
|
||||||
|
----------------State
|
||||||
|
--------Policies
|
||||||
|
------------SlotSelectionEnabled
|
||||||
|
```
|
||||||
<a href="" id="multisim"></a>**./Device/Vendor/MSFT/MultiSIM**
|
<a href="" id="multisim"></a>**./Device/Vendor/MSFT/MultiSIM**
|
||||||
Root node.
|
Root node.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user