Merge branch 'master' into behav-block-contain
@ -1009,7 +1009,27 @@
|
|||||||
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicefilecertificateinfobeta-table.md",
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicefilecertificateinfobeta-table.md",
|
||||||
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicefilecertificateinfo-table",
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicefilecertificateinfo-table",
|
||||||
"redirect_document_id": true
|
"redirect_document_id": true
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-tvm-configassessment-table.md",
|
||||||
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicetvmsecureconfigurationassessment-table",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-tvm-secureconfigkb-table.md",
|
||||||
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicetvmsecureconfigurationassessmentkb-table",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-tvm-softwareinventory-table.md",
|
||||||
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicetvmsoftwareinventoryvulnerabilities-table",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-tvm-softwarevulnerability-table.md",
|
||||||
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicetvmsoftwarevulnerabilitieskb-table",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-alertevents-table.md",
|
"source_path": "windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-alertevents-table.md",
|
||||||
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicealertevents-table",
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-devicealertevents-table",
|
||||||
@ -15513,7 +15533,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"source_path": "windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md",
|
"source_path": "windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md",
|
||||||
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/exploit-protection",
|
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction",
|
||||||
"redirect_document_id": false
|
"redirect_document_id": false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
@ -38,7 +38,7 @@ HoloLens 2 prompts a user to calibrate the device under the following circumstan
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
During this process, you'll look at a set of targets (gems). It's fine if you blink or close your eyes during calibration but try not to stare at other objects in the room. This allows HoloLens to learn about your eye position to render your holographic world.
|
During this process, you'll look at a set of targets (gems). It's fine if you blink during calibration, but try to stay focused on the gems instead of other objects in the room. This allows HoloLens to learn about your eye position to render your holographic world.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -52,7 +52,7 @@ If calibration was successful, you'll see a success screen. If not, read more a
|
|||||||
|
|
||||||
### Calibration when sharing a device or session
|
### Calibration when sharing a device or session
|
||||||
|
|
||||||
Multiple users can share a HoloLens 2 device, without a need for each person to go through device setup. When a new user puts the device on their head for th first time, HoloLens 2 automatically prompts the user to calibrate visuals. When a user that has previously calibrated visuals puts the device on their head, the display seamlessly adjusts for quality and a comfortable viewing experience.
|
Multiple users can share a HoloLens 2 device, without a need for each person to go through device setup. When a new user puts the device on their head for the first time, HoloLens 2 automatically prompts the user to calibrate visuals. When a user that has previously calibrated visuals puts the device on their head, the display seamlessly adjusts for quality and a comfortable viewing experience.
|
||||||
|
|
||||||
### Manually starting the calibration process
|
### Manually starting the calibration process
|
||||||
|
|
||||||
@ -84,7 +84,7 @@ If calibration is unsuccessful try:
|
|||||||
- Moving objects in your visor out of the way (such as hair)
|
- Moving objects in your visor out of the way (such as hair)
|
||||||
- Turning on a light in your room or moving out of direct sunlight
|
- Turning on a light in your room or moving out of direct sunlight
|
||||||
|
|
||||||
If you followed all guidelines and calibration is still failing, please let us know by filing feedback in [Feedback Hub](hololens-feedback.md).
|
If you followed all guidelines and calibration is still failing, you can disable the calibration prompt in Settings. Please also let us know by filing feedback in [Feedback Hub](hololens-feedback.md).
|
||||||
|
|
||||||
Note that setting IPD is not applicable for Hololens 2, since eye positions are computed by the system.
|
Note that setting IPD is not applicable for Hololens 2, since eye positions are computed by the system.
|
||||||
|
|
||||||
@ -92,6 +92,8 @@ Note that setting IPD is not applicable for Hololens 2, since eye positions are
|
|||||||
|
|
||||||
Calibration information is stored locally on the device and is not associated with any account information. There is no record of who has used the device without calibration. This mean new users will get prompted to calibrate visuals when they use the device for the first time, as well as users who opted out of calibration previously or if calibration was unsuccessful.
|
Calibration information is stored locally on the device and is not associated with any account information. There is no record of who has used the device without calibration. This mean new users will get prompted to calibrate visuals when they use the device for the first time, as well as users who opted out of calibration previously or if calibration was unsuccessful.
|
||||||
|
|
||||||
|
The device can locally store up to 50 calibration profiles. After this number is reached, the device automatically deletes the oldest unused profile.
|
||||||
|
|
||||||
Calibration information can always be deleted from the device in **Settings** > **Privacy** > **Eye tracker**.
|
Calibration information can always be deleted from the device in **Settings** > **Privacy** > **Eye tracker**.
|
||||||
|
|
||||||
### Disable calibration
|
### Disable calibration
|
||||||
|
@ -4,7 +4,11 @@ description: Create actionable feedback for HoloLens and Windows Mixed Reality d
|
|||||||
ms.assetid: b9b24c72-ff86-44a9-b30d-dd76c49479a9
|
ms.assetid: b9b24c72-ff86-44a9-b30d-dd76c49479a9
|
||||||
author: mattzmsft
|
author: mattzmsft
|
||||||
ms.author: mazeller
|
ms.author: mazeller
|
||||||
ms.date: 09/13/2019
|
ms.date: 05/14/2020
|
||||||
|
ms.custom:
|
||||||
|
- CI 116157
|
||||||
|
- CSSTroubleshooting
|
||||||
|
audience: ITPro
|
||||||
ms.prod: hololens
|
ms.prod: hololens
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
keywords: feedback, bug, issue, error, troubleshoot, help
|
keywords: feedback, bug, issue, error, troubleshoot, help
|
||||||
@ -15,68 +19,66 @@ appliesto:
|
|||||||
- HoloLens 2
|
- HoloLens 2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Give us feedback
|
# Feedback for HoloLens
|
||||||
|
|
||||||
Use the Feedback Hub to tell us which features you love, which features you could do without, or when something could be better.
|
Use the Feedback Hub to tell us which features you love, which features you could do without, and how something could be better. The engineering team uses the same mechanism internally to track and fix bugs, so please use Feedback Hub to report any bugs that you see. We are listening!
|
||||||
|
|
||||||
## Feedback for Windows Mixed Reality immersive headset on PC
|
Feedback Hub is an excellent way to alert the engineering team to bugs and to make sure that future updates are healthier and more consistently free of bugs. However, Feedback Hub does not provide a response. If you need immediate help, please file feedback, take note of the summary that you provided for your feedback, and then follow up with [HoloLens support](https://support.microsoft.com/supportforbusiness/productselection?sapid=e9391227-fa6d-927b-0fff-f96288631b8f).
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!NOTE]
|
||||||
> Before you report an issue, make sure that your environment meets the following requirements so that you can successfully upload logs and other information:
|
>
|
||||||
>
|
> - Make sure you that you have the current version of Feedback Hub. To do this, select **Start** > **Microsoft Store**, and then select the ellipses (**...**). Then, select **Downloads and updates** > **Get updates**.
|
||||||
> - Have a minimum of 3GB free disk space available on the main drive of the device.
|
>
|
||||||
> - To upload cabs or other large files, connect to a non-metered network.
|
> - To provide the best possible data for fixing issues, we highly recommended that you set your device telemetry to **Full**. You can set this value during the Out-of-Box-Experience (OOBE), or by using the Settings app. To do this by using Settings, select **Start** > **Settings** > **Privacy** > **App Diagnostics** > **On**.
|
||||||
|
|
||||||
1. Make sure that you have the immersive headset connected to your PC, and then on the desktop, select **Feedback Hub**.
|
## Use the Feedback Hub
|
||||||
1. In the left pane, select **Feedback**.
|
|
||||||

|
|
||||||
1. To enter new feedback, select **Add new feedback**.
|
|
||||||

|
|
||||||
1. To make feedback actionable, in **What kind of feedback is this?** select **Problem**.
|
|
||||||
1. In **Summarize your issue**, enter a meaningful title for your feedback.
|
|
||||||
1. In **Give us more detail**, provide details and repro steps.
|
|
||||||

|
|
||||||
|
|
||||||
As the top category, select **Mixed Reality**. Then select an applicable subcategory, as explained in the following table:
|
1. Use the **Start** gesture to open the **Start** menu, and then select **Feedback Hub**. The app opens in your environment.
|
||||||
|
|
||||||
|Subcategory |Description |
|
|
||||||
|----------|----------|
|
|
||||||
| Apps | Issues about a specific application. |
|
|
||||||
| Developer | Issues about authoring or running an app for Mixed Reality. |
|
|
||||||
| Device | Issues about the head-mounted device (HMD) itself. |
|
|
||||||
| Home experience | Issues about your VR environment and your interactions with the your mixed reality home. |
|
|
||||||
| Input | Issues about input methods, such as motion controllers, speech, gamepad, or mouse and keyboard. |
|
|
||||||
| Set up | Anything that is preventing you from setting up the device. |
|
|
||||||
| All other issues | Anything else. |
|
|
||||||
|
|
||||||
1. If possible, add traces or video to your feedback to help us identify and fix the issue more quickly. To do this, follow these steps:
|
|
||||||
1. To start collecting traces, select **Start capture**. The app starts collecting traces and a video capture of your mixed reality scenario.
|
|
||||||
|
|
||||||

|
|
||||||
1. Do not close the Feedback Hub app, but switch to the scenario that produces the issue. Run through the scenario to produce the circumstances that you have described.
|
|
||||||
1. After you finish your scenario, go back to the Feedback Hub app and select **Stop capture**. The app stops collecting information, stores the information in a file, and attaches the file to your feedback.
|
|
||||||
1. Select **Submit**.
|
|
||||||

|
|
||||||
The Thank You page indicates that your feedback has been successfully submitted.
|
|
||||||

|
|
||||||
|
|
||||||
To easily direct other people (such as co-workers, Microsoft staff, [forum](https://forums.hololens.com/) readers et al) to the issue, go to **Feedback** > **My Feedback**, select the issue, select **Share**. This action provides a shortened URL that you can give to others so that they can upvote or escalate your issue.
|

|
||||||
|
> [!NOTE]
|
||||||
|
> If you don't see **Feedback Hub**, select **All Apps** to see the complete list of apps on the device.
|
||||||
|
|
||||||
## Feedback for HoloLens
|
1. To see whether someone else has given similar feedback, enter a few keywords about the topic in the **Feedback** search box.
|
||||||
|
1. If you find similar feedback, select it, add any additional information that you have in the **Write a comment** box, and then select **Upvote**.
|
||||||
|
1. If you don't find any similar feedback, select **Add new feedback**.
|
||||||
|
|
||||||
1. Use the **bloom** gesture to open the **Start** menu, and then select **Feedback Hub**.
|

|
||||||
|
|
||||||

|
1. In **Summarize your feedback**, enter a short summary of your feedback. Then add details in the **Explain in more detail** box. The more details that you provide, such as how to reproduce this problem and the effect that it has, the more useful your feedback is. When you're finished, select **Next**.
|
||||||
1. Place the app in your environment and then select the app to launch it.
|
|
||||||
1. To see if someone else has given similar feedback, in the Feedback search box, enter a few keywords about the topic.
|
|
||||||
|
|
||||||

|
1. Select a topic from **Choose a category**, and then select a subcategory from **Select a subcategory**. The following table describes the categories that are available in the Windows Holographic category.
|
||||||
1. If you find similar feedback, select it, add any details, then select **Upvote**.
|
|
||||||
|
|
||||||

|
> [!NOTE]
|
||||||
1. If you don’t find any similar feedback, select **Add new feedback**, select a topic from **Select a category**, and then select a subcategory from **Select a subcategory**.
|
> **Commercial customers**: To report a bug that is related to MDM, provisioning, or any other device management aspect, select the **Enterprise Management** category, and the **Device** subcategory.
|
||||||
|
|
||||||

|
|Category |Description |
|
||||||
1. Enter your feedback.
|
| --- | --- |
|
||||||
1. If you are reporting a reproducible issue, you can select **Reproduce**. Without closing Feedback Hub, reproduce the issue. After you finish, come back to Feedback Hub and select **I’m done**. The app adds a mixed reality capture of your repro and relevant diagnostic logs to your feedback.
|
|Eye tracking |Feedback about eye tracking, iris sign-in, or calibration. |
|
||||||
1. Select **Post feedback**, and you’re done.
|
|Hologram accuracy, stability, and reliability |Feedback about how holograms appear in space. |
|
||||||
|
|Launching, placing, adjusting, and exiting apps |Feedback about starting or stopping 2D or 3D apps. |
|
||||||
|
|Miracast |Feedback about Miracast. |
|
||||||
|
|Spaces and persistence |Feedback about how HoloLens recognizes spaces and retains holograms in space. |
|
||||||
|
|Start menu and all apps list |Feedback about the **Start** menu and the all apps list. |
|
||||||
|
|Surface mapping |Feedback about surface mapping. |
|
||||||
|
|Taking pictures and videos |Feedback about mixed reality captures. |
|
||||||
|
|Video hologram playback |Feedback about video hologram playback. |
|
||||||
|
|All other issues |All other issues. |
|
||||||
|
|
||||||
|
1. You may be prompted to search for similar feedback. If your problem resembles feedback from other users, select that feedback. Otherwise, select **New feedback** and then select **Next**.
|
||||||
|
|
||||||
|
1. If you are prompted, select the best description of the problem.
|
||||||
|
|
||||||
|
1. Attach any relevant data to your feedback, or reproduce the problem. You can select any of the following options:
|
||||||
|
|
||||||
|
- **Attach a screenshot**. Select this option to attach a screenshot that illustrates the situation that you're describing.
|
||||||
|
- **Attach a file**. Select this option to attach data files. If you have files that are relevant to your problem or that could help us to reproduce your problem, attach them.
|
||||||
|
- **Recreate my problem**. Select this option if you can reproduce the problem yourself. After you select **Recreate my problem**, follow these steps:
|
||||||
|
|
||||||
|
1. Select **Include data about** and make sure that the most relevant types of data are listed. In most cases, the default selections are based on the category and subcategory that you selected for your feedback.
|
||||||
|
1. Select **Start Recording**.
|
||||||
|
|
||||||
|
1. Reproduce your problem. Don’t worry if this means that you have to enter an immersive app. You will return to the feedback page when you're done.
|
||||||
|
1. Select **Stop recording**. After recording stops, you can see the data that is attached to your feedback for the engineering team.
|
||||||
|
|
||||||
|
1. Make sure that you have an active internet connection so that we can receive your feedback. Select **Submit**, and you’re done.
|
||||||
|
BIN
devices/hololens/images/hololens-feedback-1.png
Normal file
After Width: | Height: | Size: 343 KiB |
BIN
devices/hololens/images/hololens-start-feedback.png
Normal file
After Width: | Height: | Size: 60 KiB |
BIN
devices/hololens/images/hololens2-feedbackhub-tile.png
Normal file
After Width: | Height: | Size: 37 KiB |
@ -37,7 +37,7 @@ This update is specific to the Surface Hub 2S and provides the driver and firmwa
|
|||||||
* Improves system stability.
|
* Improves system stability.
|
||||||
* Surface System driver - 1.7.139.0
|
* Surface System driver - 1.7.139.0
|
||||||
* Improves system stability.
|
* Improves system stability.
|
||||||
* Surface SMC Firmware update - 1.173.139.0
|
* Surface SMC Firmware update - 1.176.139.0
|
||||||
* Improves system stability.
|
* Improves system stability.
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
|
BIN
images/screenshot1.png
Normal file
After Width: | Height: | Size: 2.8 MiB |
BIN
images/screenshot10.png
Normal file
After Width: | Height: | Size: 9.5 KiB |
BIN
images/screenshot11.png
Normal file
After Width: | Height: | Size: 69 KiB |
BIN
images/screenshot12.png
Normal file
After Width: | Height: | Size: 113 KiB |
BIN
images/screenshot2.png
Normal file
After Width: | Height: | Size: 24 KiB |
BIN
images/screenshot3.png
Normal file
After Width: | Height: | Size: 71 KiB |
BIN
images/screenshot4.png
Normal file
After Width: | Height: | Size: 17 KiB |
BIN
images/screenshot5.png
Normal file
After Width: | Height: | Size: 19 KiB |
BIN
images/screenshot6.png
Normal file
After Width: | Height: | Size: 14 KiB |
BIN
images/screenshot7.png
Normal file
After Width: | Height: | Size: 75 KiB |
BIN
images/screenshot8.png
Normal file
After Width: | Height: | Size: 53 KiB |
BIN
images/screenshot9.png
Normal file
After Width: | Height: | Size: 59 KiB |
@ -1,21 +1,27 @@
|
|||||||
# [Configure Windows 10](index.md)
|
# [Configure Windows 10](index.md)
|
||||||
## [Accessibility information for IT Pros](windows-10-accessibility-for-ITPros.md)
|
## [Accessibility information for IT Pros](windows-10-accessibility-for-ITPros.md)
|
||||||
## [Configure access to Microsoft Store](stop-employees-from-using-microsoft-store.md)
|
## [Configure access to Microsoft Store](stop-employees-from-using-microsoft-store.md)
|
||||||
## [Cortana integration in your business or enterprise](cortana-at-work/cortana-at-work-overview.md)
|
## [Configure Cortana in Windows 10](cortana-at-work/cortana-at-work-overview.md)
|
||||||
### [Testing scenarios using Cortana in your business or organization](cortana-at-work/cortana-at-work-testing-scenarios.md)
|
## [Set up and test Cortana in Windows 10, version 2004 and later](cortana-at-work/set-up-and-test-cortana-in-windows-10)
|
||||||
#### [Test scenario 1 - Sign-in to Azure AD and use Cortana to manage the notebook](cortana-at-work/cortana-at-work-scenario-1.md)
|
## [Testing scenarios using Cortana in your business or organization](cortana-at-work/cortana-at-work-testing-scenarios.md)
|
||||||
#### [Test scenario 2 - Perform a quick search with Cortana at work](cortana-at-work/cortana-at-work-scenario-2.md)
|
### [Test scenario 1 - Sign into Azure AD, enable the wake word, and try a voice query](cortana-at-work/cortana-at-work-scenario-1.md)
|
||||||
#### [Test scenario 3 - Set a reminder for a specific location using Cortana at work](cortana-at-work/cortana-at-work-scenario-3.md)
|
### [Test scenario 2 - Perform a Bing search with Cortana](cortana-at-work/cortana-at-work-scenario-2.md)
|
||||||
#### [Test scenario 4 - Use Cortana at work to find your upcoming meetings](cortana-at-work/cortana-at-work-scenario-4.md)
|
### [Test scenario 3 - Set a reminder](cortana-at-work/cortana-at-work-scenario-3.md)
|
||||||
#### [Test scenario 5 - Use Cortana to send email to a co-worker](cortana-at-work/cortana-at-work-scenario-5.md)
|
### [Test scenario 4 - Use Cortana to find free time on your calendar](cortana-at-work/cortana-at-work-scenario-4.md)
|
||||||
#### [Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email](cortana-at-work/cortana-at-work-scenario-6.md)
|
### [Test scenario 5 - Find out about a person](cortana-at-work/cortana-at-work-scenario-5.md)
|
||||||
#### [Test scenario 7 - Use Cortana and Windows Information Protection (WIP) to help protect your organization’s data on a device](cortana-at-work/cortana-at-work-scenario-7.md)
|
### [Test scenario 6 - Change your language and perform a quick search with Cortana](cortana-at-work/cortana-at-work-scenario-6.md)
|
||||||
### [Set up and test Cortana with Office 365 in your organization](cortana-at-work/cortana-at-work-o365.md)
|
## [Send feedback about Cortana back to Microsoft](cortana-at-work/cortana-at-work-feedback.md)
|
||||||
### [Set up and test Cortana with Microsoft Dynamics CRM (Preview feature) in your organization](cortana-at-work/cortana-at-work-crm.md)
|
## [Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization](cortana-at-work/cortana-at-work-o365.md)
|
||||||
### [Set up and test Cortana for Power BI in your organization](cortana-at-work/cortana-at-work-powerbi.md)
|
## [Testing scenarios using Cortana in your business or organization](cortana-at-work/cortana-at-work-testing-scenarios.md)
|
||||||
### [Set up and test custom voice commands in Cortana for your organization](cortana-at-work/cortana-at-work-voice-commands.md)
|
### [Test scenario 1 - Sign into Azure AD, enable the wake word, and try a voice query](cortana-at-work/test-scenario-1)
|
||||||
### [Use Group Policy and mobile device management (MDM) settings to configure Cortana in your organization](cortana-at-work/cortana-at-work-policy-settings.md)
|
### [Test scenario 2 - Perform a quick search with Cortana at work](cortana-at-work/test-scenario-2)
|
||||||
### [Send feedback about Cortana at work back to Microsoft](cortana-at-work/cortana-at-work-feedback.md)
|
### [Test scenario 3 - Set a reminder for a specific location using Cortana at work](cortana-at-work/test-scenario-3)
|
||||||
|
### [Test scenario 4 - Use Cortana at work to find your upcoming meetings](cortana-at-work/test-scenario-4)
|
||||||
|
### [Test scenario 5 - Use Cortana to send email to a co-worker](cortana-at-work/test-scenario-5)
|
||||||
|
### [Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email](cortana-at-work/test-scenario-6)
|
||||||
|
### [Test scenario 7 - Use Cortana and Windows Information Protection (WIP) to help protect your organization’s data on a device](cortana-at-work/cortana-at-work-scenario-7)
|
||||||
|
## [Set up and test custom voice commands in Cortana for your organization](cortana-at-work/cortana-at-work-voice-commands.md)
|
||||||
|
## [Use Group Policy and mobile device management (MDM) settings to configure Cortana in your organization](cortana-at-work/cortana-at-work-policy-settings.md)
|
||||||
## [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md)
|
## [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md)
|
||||||
## [Configure kiosks and digital signs on Windows desktop editions](kiosk-methods.md)
|
## [Configure kiosks and digital signs on Windows desktop editions](kiosk-methods.md)
|
||||||
### [Prepare a device for kiosk configuration](kiosk-prepare.md)
|
### [Prepare a device for kiosk configuration](kiosk-prepare.md)
|
||||||
|
@ -13,10 +13,6 @@ manager: dansimp
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Set up and test Cortana with Microsoft Dynamics CRM (Preview feature) in your organization
|
# Set up and test Cortana with Microsoft Dynamics CRM (Preview feature) in your organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
Cortana integration is a Preview feature that's available for your test or dev environment, starting with the CRM Online 2016 Update. If you decide to use this Preview feature, you'll need to turn in on and accept the license terms. After that, your salespeople will get proactive insights from Cortana on important CRM activities, including sales leads, accounts, and opportunities; presenting the most relevant info at any given time. This can even include getting company-specific news that surfaces when the person is meeting with a representative from another company.
|
Cortana integration is a Preview feature that's available for your test or dev environment, starting with the CRM Online 2016 Update. If you decide to use this Preview feature, you'll need to turn in on and accept the license terms. After that, your salespeople will get proactive insights from Cortana on important CRM activities, including sales leads, accounts, and opportunities; presenting the most relevant info at any given time. This can even include getting company-specific news that surfaces when the person is meeting with a representative from another company.
|
||||||
|
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: Send feedback about Cortana at work back to Microsoft (Windows 10)
|
title: Send feedback about Cortana at work back to Microsoft
|
||||||
description: How to send feedback to Microsoft about Cortana at work.
|
description: How to send feedback to Microsoft about Cortana at work.
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
@ -12,15 +12,14 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Send feedback about Cortana at work back to Microsoft
|
# Send feedback about Cortana back to Microsoft
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
To provide feedback on an individual request or response, select the item in the conversation history and then select **Give feedback**. This opens the Feedback Hub application where you can provide more information to help diagnose reported issues.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
We ask that you report bugs and issues. To provide feedback, you can click the **Feedback** icon in the Cortana window. When you send this form to Microsoft it also includes troubleshooting info, in case you run into problems.
|
:::image type="content" source="../../../images/screenshot11.png" alt-text="Screenshot: Send feedback page":::
|
||||||
|
|
||||||

|
To provide feedback about the application in general, go to the **Settings** menu by selecting the three dots in the top left of the application, and select **Feedback**. This opens the Feedback Hub where more information on the issue can be provided.
|
||||||
|
|
||||||
If you don't want to use the feedback tool in Cortana, you can add feedback through the general Windows Insider Program feedback app. For info about the feedback app, see [How to use Windows Insider Preview – Updates and feedback](https://windows.microsoft.com/en-us/windows/preview-updates-feedback-pc).
|
:::image type="content" source="../../../images/screenshot12.png" alt-text="Screenshot: Select Feedback to go to the Feedback Hub":::
|
||||||
|
|
||||||
|
In order for enterprise users to provide feedback, admins must unblock the Feedback Hub in the [Azure portal](https://portal.azure.com/). Go to the **Enterprise applications section** and enable **Users can allow apps to access their data**.
|
@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: Set up and test Cortana with Office 365 in your organization (Windows 10)
|
title: Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization
|
||||||
description: Learn how to connect Cortana to Office 365 so employees are notified about regular meetings and unusual events. You can even set an alarm for early meetings.
|
description: Learn how to connect Cortana to Office 365 so employees are notified about regular meetings and unusual events. You can even set an alarm for early meetings.
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
@ -12,63 +12,45 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Set up and test Cortana with Office 365 in your organization
|
# Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
Cortana in Windows 10 is already great at letting your employees quickly see what the day is going to look like, do meeting prep work like researching people in LinkedIn or getting documents ready, see where and when their meetings are going to be, get a sense of travel times to and from work, and even get updates from a calendar for upcoming trips.
|
## What can you do with in Windows 10, versions 1909 and earlier?
|
||||||
|
Your employees can use Cortana to help manage their day and be more productive by getting quick answers to common questions, setting reminders, adding tasks to their To-Do lists, and find out where their next meeting is.
|
||||||
|
|
||||||
But Cortana works even harder when she connects to Office 365, helping employees to be notified about unusual events, such as meetings over lunch or during a typical commute time, and about early meetings, even setting an alarm so the employee isn’t late.
|
**See also:**
|
||||||
|
|
||||||

|
[Known issues for Windows Desktop Search and Cortana in Windows 10](https://support.microsoft.com/help/3206883/known-issues-for-windows-desktop-search-and-cortana-in-windows-10).
|
||||||
|
|
||||||
We’re continuing to add more and more capabilities to Cortana so she can become even more helpful with your productivity-related tasks, such as emailing, scheduling, and other tasks that are important to help you be successful.
|
### Before you begin
|
||||||
|
There are a few things to be aware of before you start using Cortana in Windows 10, versions 1909 and earlier.
|
||||||
|
|
||||||
>[!NOTE]
|
- **Azure Active Directory (Azure AD) account.** Before your employees can use Cortana in your org, they must be logged in using their Azure AD account through Cortana's notebook. They must also authorize Cortana to access Microsoft 365 on their behalf.
|
||||||
>For a quick review of the frequently asked questions about Cortana and Office 365 integration, see the blog post, [An early look at Cortana integration with Office 365](https://go.microsoft.com/fwlink/p/?LinkId=717379).
|
|
||||||
|
|
||||||
## Before you begin
|
- **Office 365 Trust Center.** Cortana in Windows 10, version 1909 and earlier, isn't a service governed by the [Online Services Terms](https://www.microsoft.com/en-us/licensing/product-licensing/products). [Learn more about how Cortana in Windows 10, versions 1909 and earlier, treats your data](https://support.microsoft.com/en-us/help/4468233/cortana-and-privacy-microsoft-privacy).
|
||||||
There are a few things to be aware of before you start using Cortana with Office 365 in your organization.
|
|
||||||
|
|
||||||
- **Software requirements.** O365 integration with Cortana is available in all countries/regions where Cortana is supported for consumers today. This includes the United States, United Kingdom, Canada, France, Italy, Germany, Spain, China, Japan, India, and Australia. As Cortana comes to more countries, it will also become available to organizations.
|
- Windows Information Protection (WIP). If you want to secure the calendar, email, and contact info provided to Cortana on a device, you can use WIP. For more info about WIP, see [Protect your enterprise data using Windows Information Protection (WIP)](https://docs.microsoft.com/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip). If you decide to use WIP, you must also have a management solution. This can be Microsoft Intune, Microsoft Endpoint Configuration Manager (version 1606 or later), or your current company-wide 3rd party mobile device management (MDM) solution.
|
||||||
|
|
||||||
- **Azure Active Directory (Azure AD) account.** Before your employees can use Cortana in your org, they must be logged in using their Azure AD account through Cortana’s notebook. They must also authorize Cortana to access Office 365 on their behalf.
|
|
||||||
|
|
||||||
- **Office 365 Trust Center.** Cortana isn't a service covered by the Office 365 Trust Center. [Learn more about how Cortana treats your data](https://go.microsoft.com/fwlink/p/?LinkId=536419).
|
|
||||||
|
|
||||||
- **Troubleshooting tips.** If you run into issues, check out these [troubleshooting tips](https://go.microsoft.com/fwlink/p/?LinkId=620763).
|
- **Troubleshooting tips.** If you run into issues, check out these [troubleshooting tips](https://go.microsoft.com/fwlink/p/?LinkId=620763).
|
||||||
|
|
||||||
## Turn on Cortana with Office 365 on employees’ devices
|
### Turn on Cortana enterprise services on employees devices
|
||||||
You must tell your employees to turn on Cortana before they’ll be able to use it with Office 365.
|
Your employees must connect Cortana to their Microsoft 365 account to be able to use skills like email and calendar.
|
||||||
|
|
||||||
**To turn on local Cortana with Office 365**
|
#### Turn on Cortana enterprise services
|
||||||
|
|
||||||
1. Click on the **Cortana** search box in the taskbar, and then click the **Notebook** icon.
|
1. Select the **Cortana** search box in the taskbar, and then select the **Notebook** icon.
|
||||||
|
|
||||||
2. Click on **Connected Services**, click **Office 365**, and then click **Connect**.
|
2. Select **Manage Skills** , select **Manage accounts** , and under **Microsoft 365** select **Link**. The employee will be directed to sign into their Microsoft 365 account.
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
The employee can also disconnect by clicking **Disconnect** from the **Office 365** screen.
|
|
||||||
|
|
||||||
## Turn off Cortana with Office 365
|
|
||||||
Cortana can only access data in your Office 365 org when it’s turned on. If you don’t want Cortana to access your corporate data, you can turn it off in the Microsoft 365 admin center.
|
|
||||||
|
|
||||||
**To turn off Cortana with Office 365**
|
|
||||||
1. [Sign in to Office 365](https://www.office.com/signin) using your Azure AD account.
|
|
||||||
|
|
||||||
2. Go to the [admin center](https://support.office.com/article/Office-365-admin-center-58537702-d421-4d02-8141-e128e3703547).
|
|
||||||
|
|
||||||
3. Expand **Service Settings**, and select **Cortana**.
|
|
||||||
|
|
||||||
4. Click **Cortana** to toggle Cortana off.
|
|
||||||
|
|
||||||
All Office 365 functionality related to Cortana is turned off in your organization and your employees are unable to use her at work.
|
|
||||||
|
|
||||||
|
3. The employee can also disconnect by selecting **Microsoft 365**, then **Unlink**.
|
||||||
|
|
||||||
|
#### Turn off Cortana enterprise services
|
||||||
|
Cortana in Windows 10, versions 1909 and earlier can only access data in your Microsoft 365 organization when it's turned on. If you don't want Cortana to access your corporate data, you can turn it off in the Microsoft 365 admin center.
|
||||||
|
|
||||||
|
1. Sign into the [Microsoft 365 admin center](https://admin.microsoft.com/) using your admin account.
|
||||||
|
|
||||||
|
2. Select the app launcher icon in the upper-left and choose **Admin**.
|
||||||
|
|
||||||
|
3. Expand **Settings** and select **Settings**.
|
||||||
|
|
||||||
|
4. Select **Cortana** to toggle Cortana's access to Microsoft 365 data off.
|
@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: Cortana integration in your business or enterprise (Windows 10)
|
title: Configure Cortana in Windows 10
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
description: Cortana includes powerful configuration options specifically to optimize for unique small to medium-sized business and enterprise environments.
|
description: Cortana includes powerful configuration options specifically to optimize for unique small to medium-sized business and enterprise environments.
|
||||||
@ -11,53 +11,78 @@ ms.localizationpriority: medium
|
|||||||
ms.author: dansimp
|
ms.author: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Cortana integration in your business or enterprise
|
# Configure Cortana in Windows 10
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
## Who is Cortana?
|
## Who is Cortana?
|
||||||
Cortana is Microsoft’s personal digital assistant, who helps busy people get things done, even while at work.
|
|
||||||
Cortana has powerful configuration options, specifically optimized for your business. By signing in with an Azure Active Directory (Azure AD) account, your employees can give Cortana access to their enterprise/work identity, while getting all the functionality Cortana provides to them outside of work.
|
|
||||||
|
|
||||||
Using Azure AD also means that you can remove an employee’s profile (for example, when an employee leaves your organization) while respecting Windows Information Protection (WIP) policies and ignoring enterprise content, such as emails, calendar items, and people lists that are marked as enterprise data.
|
Cortana is a personal productivity assistant in Microsoft 365, helping your users achieve more with less effort and focus on what matters. The Cortana app in Windows 10 helps users quickly get information across Microsoft 365, using typed or spoken queries to connect with people, check calendars, set reminders, add tasks, and more.
|
||||||
|
|
||||||

|
:::image type="content" source="../../../images/screenshot1.png" alt-text="Screenshot: Cortana home page example":::
|
||||||
|
|
||||||
## Where is Cortana available for use in my organization?
|
## Where is Cortana available for use in my organization?
|
||||||
You can use Cortana at work in all countries/regions where Cortana is supported for consumers. This includes the United States, United Kingdom, Canada, France, Italy, Germany, Spain, China, Japan, India, and Australia. As Cortana comes to more countries, she will also become available to enterprise customers.
|
|
||||||
|
|
||||||
Cortana is available on Windows 10, version 1703 and with limited functionality on Windows 10 Mobile, version 1703.
|
Your employees can use Cortana in the languages listed [here](https://support.microsoft.com/help/4026948/cortanas-regions-and-languages). However, most productivity skills are currently only enabled for English (United States), for users with mailboxes in the United States.
|
||||||
|
|
||||||
|
The Cortana app in Windows 10, version 2004 requires the latest Microsoft Store update to support languages other than English (United States).
|
||||||
|
|
||||||
## Required hardware and software
|
## Required hardware and software
|
||||||
Cortana requires the following hardware and software to successfully run the included scenario in your organization.
|
|
||||||
|
|
||||||
|Hardware |Description |
|
Cortana requires a PC running Windows 10, version 1703 or later, as well as the following software to successfully run the included scenario in your organization.
|
||||||
|---------|------------|
|
|
||||||
|Microphone |For speech interaction with Cortana. If you don't have a microphone, you can still interact with Cortana by typing in the Cortana Search Box in the taskbar. |
|
|
||||||
|Windows Phone |For location-specific reminders. You can also use a desktop device to run through this scenario, but location accuracy is usually better on phones. |
|
|
||||||
|Desktop devices |For non-phone-related scenarios. |
|
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>A microphone is not required to use Cortana.
|
||||||
|
|
||||||
|Software |Minimum version |
|
|**Software** |**Minimum version** |
|
||||||
|---------|------------|
|
|---------|---------|
|
||||||
|Client operating system |<ul><li>**Desktop:** Windows 10, version 1703</li><li>**Mobile:** Windows 10 Mobile, version 1703 (with limited functionality)</li> |
|
|Client operating system | Desktop: <br> - Windows 10, version 2004 (recommended) <br> <br> - Windows 10, version 103 (legacy version of Cortana) <br> <br> Mobile: Windows 10 mobile, version 1703 (legacy version of Cortana) <br> <br> For more information on the differences between Cortana in Windows 10, version 2004 and earlier versions, see **How is my data processed by Cortana** below. |
|
||||||
|Azure Active Directory (Azure AD) |While all employees signing into Cortana need an Azure AD account; an Azure AD premium tenant isn’t required. |
|
|Azure Active Directory (Azure AD) | While all employees signing into Cortana need an Azure AD account, an Azure AD premium tenant isn’t required. |
|
||||||
|Additional policies (Group Policy and Mobile Device Management (MDM)) |There is a rich set of policies that can be used to manage various aspects of Cortana. Most of these policies will limit the abilities of Cortana, but won't turn Cortana off.<p>For example:<p>If you turn **Location** off, Cortana won't be able to provide location-based reminders, such as reminding you to visit the mail room when you get to work.<p>If you turn **Speech** off, your employees won't be able to use “Hello Cortana” for hands free usage or voice commands to easily ask for help. |
|
|Additional policies (Group Policy and Mobile Device Management (MDM)) |There is a rich set of policies that can be used to manage various aspects of Cortana. Most of these policies will limit the abilities of Cortana but won't turn Cortana off. For example, if you turn **Speech** off, your employees won't be able to use the wake word (“Cortana”) for hands-free activation or voice commands to easily ask for help. |
|
||||||
|Windows Information Protection (WIP) (optional) |If you want to secure the calendar, email, and contact info provided to Cortana on a device, you can use WIP. For more info about WIP, see [Protect your enterprise data using Windows Information Protection (WIP)](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip)<p>If you decide to use WIP, you must also have a management solution. This can be Microsoft Intune, Microsoft Endpoint Configuration Manager (version 1606 or later), or your current company-wide 3rd party mobile device management (MDM) solution.|
|
|
||||||
|
|
||||||
## Signing in using Azure AD
|
## Signing in using Azure AD
|
||||||
Your organization must have an Azure AD tenant and your employees’ devices must all be Azure AD-joined for Cortana to work properly. For info about what an Azure AD tenant is, how to get your devices joined, and other Azure AD maintenance info, see [What is an Azure AD directory?](https://msdn.microsoft.com/library/azure/jj573650.aspx)
|
|
||||||
|
|
||||||
## Cortana and privacy
|
Your organization must have an Azure AD tenant and your employees' devices must all be Azure AD-joined for the best Cortana experience. (Users may also sign into Cortana with a Microsoft account, but will not be able to use their enterprise email or calendar.) For info about what an Azure AD tenant is, how to get your devices joined, and other Azure AD maintenance info, see [Azure Active Directory documentation.](https://docs.microsoft.com/azure/active-directory/)
|
||||||
We understand that there are some questions about Cortana and your organization’s privacy, including concerns about what info is collected by Cortana, where the info is saved, how to manage what data is collected, how to turn Cortana off, how to opt completely out of data collection, and what info is shared with other Microsoft apps and services. For more details about these concerns, see the [Cortana, Search, and privacy: FAQ](https://windows.microsoft.com/windows-10/cortana-privacy-faq) topic.
|
|
||||||
|
## How is my data processed by Cortana?
|
||||||
|
|
||||||
|
Cortana's approach to integration with Microsoft 365 has changed with Windows 10, version 2004 and later.
|
||||||
|
|
||||||
|
### Cortana in Windows 10, version 2004 and later
|
||||||
|
|
||||||
|
Cortana enterprise services that can be accessed using Azure AD through Cortana in Windows 10, version 2004 and later, meet the same enterprise-level privacy, security, and compliance promises as reflected in the [Online Services Terms (OST)](https://www.microsoft.com/en-us/licensing/product-licensing/products). For more information, see [Cortana in Microsoft 365](https://docs.microsoft.com/microsoft-365/admin/misc/cortana-integration?view=o365-worldwide#what-data-is-processed-by-cortana-in-office-365).
|
||||||
|
|
||||||
|
#### How does Microsoft store, retain, process, and use Customer Data in Cortana?
|
||||||
|
|
||||||
|
The table below describes the data handling for Cortana enterprise services.
|
||||||
|
|
||||||
|
|
||||||
|
|**Name** |**Description** |
|
||||||
|
|---------|---------|
|
||||||
|
|**Storage** |Customer Data is stored on Microsoft servers inside the Office 365 cloud. Your data is part of your tenant. Speech audio is not retained. |
|
||||||
|
|**Stays in Geo** |Customer Data is stored on Microsoft servers inside the Office 365 cloud in Geo. Your data is part of your tenant. |
|
||||||
|
|**Retention** |Customer Data is deleted when the account is closed by the tenant administrator or when a GDPR Data Subject Rights deletion request is made. Speech audio is not retained. |
|
||||||
|
|**Processing and confidentiality** |Personnel engaged in the processing of Customer Data and personal data (i) will process such data only on instructions from Customer, and (ii) will be obligated to maintain the confidentiality and security of such data even after their engagement ends. |
|
||||||
|
|**Usage** |Microsoft uses Customer Data only to provide the services agreed upon, and for purposes that are compatible with those services. Machine learning to develop and improve models is one of those purposes. Machine learning is done inside the Office 365 cloud consistent with the Online Services Terms. Your data is not used to target advertising. |
|
||||||
|
|
||||||
|
#### How does the wake word (Cortana) work? If I enable it, is Cortana always listening?
|
||||||
|
|
||||||
|
Cortana only begins listening for commands or queries when the wake word is detected, or the microphone button has been selected.
|
||||||
|
|
||||||
|
First, the user must enable the wake word from within Cortana settings. Once it has been enabled, a component of Windows called the [Windows Multiple Voice Assistant platform](https://docs.microsoft.com/windows-hardware/drivers/audio/voice-activation-mva#voice-activation) will start listening for the wake word. No audio is processed by speech recognition unless two local wake word detectors and a server-side one agree with high confidence that the wake word was heard.
|
||||||
|
|
||||||
|
The first decision is made by the Windows Multiple Voice Assistant platform leveraging hardware optionally included in the user's PC for power savings. If the wake word is detected, Windows will show a microphone icon in the system tray indicating an assistant app is listening.
|
||||||
|
|
||||||
|
:::image type="content" source="../../../images/screenshot2.png" alt-text="Microphone icon in the system tray indicating an assistant app is listening":::
|
||||||
|
|
||||||
|
At that point, the Cortana app will receive the audio, run a second, more accurate wake word detector, and optionally send it to a Microsoft cloud service where a third wake word detector will confirm. If the service does not confirm that the activation was valid, the audio will be discarded and deleted from any further processing or server logs. On the user's PC, the Cortana app will be silently dismissed, and no query will be shown in conversation history because the query was discarded.
|
||||||
|
|
||||||
|
If all three wake word detectors agree, the Cortana canvas will show what speech has been recognized.
|
||||||
|
|
||||||
|
### Cortana in Windows 10, versions 1909 and earlier
|
||||||
|
|
||||||
|
Cortana in Windows 10, versions 1909 and earlier, isn't a service covered by the Office 365 Trust Center. [Learn more about how Cortana in Windows 10, version 1909 and earlier, treats your data](https://go.microsoft.com/fwlink/p/?LinkId=536419).
|
||||||
|
|
||||||
Cortana is covered under the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
Cortana is covered under the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
||||||
|
|
||||||
## See also
|
## See also
|
||||||
- [What is Cortana?](https://go.microsoft.com/fwlink/p/?LinkId=746818)
|
|
||||||
|
|
||||||
- [Known issues for Windows Desktop Search and Cortana in Windows 10](https://support.microsoft.com/help/3206883/known-issues-for-windows-desktop-search-and-cortana-in-windows-10)
|
- [What is Cortana?](https://go.microsoft.com/fwlink/p/?LinkId=746818)
|
||||||
|
|
||||||
- [Cortana for developers](https://go.microsoft.com/fwlink/?LinkId=717385)
|
|
@ -13,34 +13,40 @@ manager: dansimp
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Use Group Policy and mobile device management (MDM) settings to configure Cortana in your organization
|
# Use Group Policy and mobile device management (MDM) settings to configure Cortana in your organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 10 Mobile
|
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>For specific info about how to set, manage, and use each of these MDM policies to configure Cortana in your enterprise, see the [Policy CSP](https://go.microsoft.com/fwlink/p/?LinkId=717380) topic, located in the configuration service provider reference topics. For specific info about how to set, manage, and use each of these Group Policies to configure Cortana in your enterprise, see the [Group Policy TechCenter](https://go.microsoft.com/fwlink/p/?LinkId=717381).
|
>For specific info about how to set, manage, and use each of these MDM policies to configure Cortana in your enterprise, see the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider) topic, located in the configuration service provider reference topics.
|
||||||
|
|
||||||
|Group policy |MDM policy |Description |
|
|
||||||
|-------------|-----------|------------|
|
|
||||||
|Computer Configuration\Administrative Templates\Windows Components\Search\AllowCortanaAboveLock|AboveLock/AllowCortanaAboveLock|Specifies whether an employee can interact with Cortana using voice commands when the system is locked.<p>**Note**<br>This setting only applies to Windows 10 for desktop devices. |
|
|
||||||
|Computer Configuration\Administrative Templates\Control Panel\Regional and Language Options\Allow users to enable online speech recognition services|Privacy/AllowInputPersonalization|Specifies whether an employee can use voice commands with Cortana in your organization.<p>**In Windows 10, version 1511**<br>Cortana won’t work if this setting is turned off (disabled).<p>**In Windows 10, version 1607 and later**<br>Cortana still works if this setting is turned off (disabled).|
|
|
||||||
|None|System/AllowLocation|Specifies whether to allow app access to the Location service.<p>**In Windows 10, version 1511**<br>Cortana won’t work if this setting is turned off (disabled).<p>**In Windows 10, version 1607 and later**<br>Cortana still works if this setting is turned off (disabled).|
|
|
||||||
|None|Accounts/AllowMicrosoftAccountConnection|Specifies whether to allow employees to sign in using a Microsoft account (MSA) from Windows apps.<p>Use this setting if you only want to support Azure AD in your organization.|
|
|
||||||
|Computer Configuration\Administrative Templates\Windows Components\Search\Allow search and Cortana to use location|Search/AllowSearchToUseLocation|Specifies whether Cortana can use your current location during searches and for location reminders.|
|
|
||||||
|Computer Configuration\Administrative Templates\Windows Components\Search\Set the SafeSearch setting for Search|Search/SafeSearchPermissions|Specifies what level of safe search (filtering adult content) is required.<p>**Note**<br>This setting only applies to Windows 10 Mobile. Other versions of Windows should use Don't search the web or display web results. |
|
|
||||||
|User Configuration\Administrative Templates\Windows Components\File Explorer\Turn off display of recent search entries in the File Explorer search box|None|Specifies whether the search box can suggest recent queries and prevent entries from being stored in the registry for future reference.|
|
|
||||||
|Computer Configuration\Administrative Templates\Windows Components\Search\Don't search the web or display web results|None|Specifies whether search can perform queries on the web and if the web results are displayed in search.<p>**In Windows 10 Pro edition**<br>This setting can’t be managed.<p>**In Windows 10 Enterprise edition**<br>Cortana won't work if this setting is turned off (disabled).|
|
|
||||||
|Computer Configuration\Administrative Templates\Windows Components\Search\Allow Cortana|Experience/AllowCortana|Specifies whether employees can use Cortana.<p>**Important**<br>Cortana won’t work if this setting is turned off (disabled). However, employees can still perform local searches even with Cortana turned off.|
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|**Group policy** |**MDM policy** |**Description** |
|
||||||
|
|---------|---------|---------|
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\Search\Allow Cortana |Experience/AllowCortana |Specifies whether employees can use Cortana. <br>
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Cortana won’t work if this setting is turned off (disabled). However, on Windows 10, version 1809 and below, employees can still perform local searches even with Cortana turned off. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\Search\AllowCortanaAboveLock |AboveLock/AllowCortanaAboveLock |Specifies whether an employee can interact with Cortana using voice commands when the system is locked. <br>
|
||||||
|
> [!NOTE]
|
||||||
|
> Cortana in Windows 10, versions 2004 and later do not currently support Above Lock. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\App Privacy\LetAppsActivateWithVoice |[Privacy/LetAppsActivateWithVoice](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-privacy#privacy-letappsactivatewithvoice) |Specifies whether apps (such as Cortana or other voice assistants) can activate using a wake word (e.g. “Hey Cortana”). <br>
|
||||||
|
> [!NOTE]
|
||||||
|
> This setting only applies to Windows 10 versions 2004 and later. To disable wake word activation on Windows 10 versions 1909 and earlier, you will need to disable voice commands using Privacy/AllowInputPersonalization. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\App Privacy\LetAppsAccessMicrophone |[Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-privacy#privacy-letappsaccessmicrophone-forcedenytheseapps) | Use this to disable Cortana’s access to the microphone. To do so, specify Cortana’s Package Family Name: Microsoft.549981C3F5F10_8wekyb3d8bbwe <br>
|
||||||
|
Users will still be able to type queries to Cortana. |
|
||||||
|
|Computer Configuration\Administrative Templates\Control Panel\Regional and Language Options\Allow users to enable online speech recognition services |Privacy/AllowInputPersonalization |Specifies whether an employee can use voice commands with Cortana in your organization. <br>
|
||||||
|
**In Windows 10, version 1511** <br> Cortana won’t work if this setting is turned off (disabled). <br> **In Windows 10, version 1607 and later** <br> Non-speech aspects of Cortana will still work if this setting is turned off (disabled). <br> **In Windows 10, version 2004 and later** <br> Cortana will work, but voice input will be disabled. |
|
||||||
|
|None |System/AllowLocation |Specifies whether to allow app access to the Location service. <br>
|
||||||
|
**In Windows 10, version 1511** <br> Cortana won’t work if this setting is turned off (disabled). <br>
|
||||||
|
**In Windows 10, version 1607 and later** <br>
|
||||||
|
Cortana still works if this setting is turned off (disabled). <br>
|
||||||
|
**In Windows 10, version 2004 and later** <br>
|
||||||
|
Cortana still works if this setting is turned off (disabled). Cortana in Windows 10, versions 2004 and later do not currently use the Location service. |
|
||||||
|
|None |Accounts/AllowMicrosoftAccountConnection |Specifies whether to allow employees to sign in using a Microsoft account (MSA) from Windows apps. <br>
|
||||||
|
Disable this setting if you only want to allow users to sign in with their Azure AD account. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\Search\Allow search and Cortana to use location |Search/AllowSearchToUseLocation |Specifies whether Cortana can use your current location during searches and for location reminders. <br>
|
||||||
|
**In Windows 10, version 2004 and later** <br> Cortana still works if this setting is turned off (disabled). Cortana in Windows 10, versions 2004 and later, do not currently use the Location service. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\Search\Don't search the web or display web results |Search/DoNotUseWebResults |Specifies whether search can perform queries on the web and if the web results are displayed in search. <br>
|
||||||
|
**In Windows 10 Pro edition** <br> This setting can’t be managed.
|
||||||
|
**In Windows 10 Enterprise edition** <br> Cortana won't work if this setting is turned off (disabled).
|
||||||
|
**In Windows 10, version 2004 and later** <br> This setting no longer affects Cortana. |
|
||||||
|
|Computer Configuration\Administrative Templates\Windows Components\Search\Set the SafeSearch setting for Search |Search/SafeSearchPermissions |Specifies what level of safe search (filtering adult content) is required. <br>
|
||||||
|
> [!NOTE]
|
||||||
|
> This setting only applies to Windows 10 Mobile. Other versions of Windows should use Don't search the web or display web results. |
|
@ -13,10 +13,6 @@ manager: dansimp
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Set up and test Cortana for Power BI in your organization
|
# Set up and test Cortana for Power BI in your organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
>[!IMPORTANT]
|
||||||
>Cortana for Power BI is deprecated and will not be available in future releases. This topic is provided as a reference for previous versions only.
|
>Cortana for Power BI is deprecated and will not be available in future releases. This topic is provided as a reference for previous versions only.
|
||||||
|
@ -12,49 +12,21 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 1 - Sign-in to Azure AD and use Cortana to manage the notebook
|
# Test scenario 1 – Sign into Azure AD, enable the wake word, and try a voice query
|
||||||
|
|
||||||
- Windows 10, version 1703
|
1. Select the **Cortana** icon in the task bar and sign in using your Azure AD account.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
2. Select the "…" menu and select **Talking to Cortana**.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
||||||
|
|
||||||
This scenario turns on Azure AD and let's your employee use Cortana to manage an entry in the notebook.
|
3. Toggle **Wake word** to **On** and close Cortana.
|
||||||
|
|
||||||
## Turn on Azure AD
|
4. Say **Cortana, what can you do?**.
|
||||||
This process helps you to sign out of a Microsoft Account and to sign into an Azure AD account.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, click the **Notebook**, and then click **About Me**.
|
When you say "Cortana", Cortana will open in listening mode to acknowledge the wake word.
|
||||||
|
|
||||||
2. Click your email address.
|
:::image type="content" source="../../../images/screenshot4.png" alt-text="Screenshot: Cortana listening mode":::
|
||||||
|
|
||||||
A dialog box appears, showing the associated account info.
|
Once you finish saying your query, Cortana will open with the result.
|
||||||
|
|
||||||
3. Click your email address again, and then click **Sign out**.
|
>[!NOTE]
|
||||||
|
>If you've disabled the wake word using MDM or Group Policy, you will need to manually activate the microphone by selecting Cortana, then the mic button.
|
||||||
This signs out the Microsoft account, letting you continue to add and use the Azure AD account.
|
|
||||||
|
|
||||||
4. Click the **Search** box and then the **Notebook** icon in the left rail. This will start the sign-in request.
|
|
||||||
|
|
||||||
5. Click **Sign-In** and follow the instructions.
|
|
||||||
|
|
||||||
6. When you’re asked to sign in, you’ll need to choose an Azure AD account, which will look like kelliecarlson@contoso.com.
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
|
||||||
>If there’s no Azure AD account listed, you’ll need to go to **Windows Settings > Accounts > Email & app accounts**, and then click **Add a work or school account** to add it.
|
|
||||||
|
|
||||||
## Use Cortana to manage the notebook content
|
|
||||||
This process helps you to manage the content Cortana shows in your Notebook.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, click the **Notebook**, scroll down and click **Weather**.
|
|
||||||
|
|
||||||
2. In the **Weather** settings, scroll down to the **Cities your tracking** area, and then click **Add a city**.
|
|
||||||
|
|
||||||
3. Add *Redmond, Washington*, double-click the search result, click **Add**, and then click **Save**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
4. Click on the **Home** icon and scroll to the weather forecast for Redmond, Washington.
|
|
||||||
|
|
||||||

|
|
@ -12,32 +12,15 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 2 - Perform a quick search with Cortana at work
|
# Test scenario 2 – Perform a Bing search with Cortana
|
||||||
|
|
||||||
- Windows 10, version 1703
|
1. Select the **Cortana** icon in the taskbar.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
2. Type **What time is it in Hyderabad?**.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
||||||
|
|
||||||
This scenario helps you perform a quick search using Cortana, both by typing and through voice commands.
|
Cortana will respond with the information from Bing.
|
||||||
|
|
||||||
## Search using Cortana
|
:::image type="content" source="../../../images/screenshot5.png" alt-text="Screenshot: Cortana showing current time in Hyderbad":::
|
||||||
This process helps you use Cortana at work to perform a quick search.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
>[!NOTE]
|
||||||
|
>This scenario requires Bing Answers to be enabled. For more information, see [Set up and configure the Bing Answers feature](https://docs.microsoft.com/windows/configuration/cortana-at-work/set-up-and-test-cortana-in-windows-10#set-up-and-configure-the-bing-answers-feature).
|
||||||
2. Type *Weather in New York*.
|
|
||||||
|
|
||||||
You should see the weather in New York, New York at the top of the search results.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Search with Cortana, by using voice commands
|
|
||||||
This process helps you to use Cortana at work and voice commands to perform a quick search.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the **Search** box).
|
|
||||||
|
|
||||||
2. Say *What's the weather in Chicago?* Cortana tells you and shows you the current weather in Chicago.
|
|
||||||
|
|
||||||

|
|
@ -12,77 +12,15 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 3 - Set a reminder for a specific location using Cortana at work
|
# Test scenario 3 - Set a reminder
|
||||||
|
|
||||||
- Windows 10, version 1703
|
This scenario helps you set up, review, and edit a reminder. For example, you can remind yourself to send someone a link to a document after a meeting.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
1. Select the **Cortana** icon in the taskbar and type _Remind me to send a link to the deck at 3:05pm_ and press **Enter**.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
||||||
|
|
||||||
This scenario helps you set up, review, and edit a reminder based on a location. For example, reminding yourself to grab your expense report receipts before you leave the house.
|
Cortana will create a reminder in Microsoft To Do and will remind you at the appropriate time.
|
||||||
|
|
||||||
>[!NOTE]
|
:::image type="content" source="../../../images/screenshot6.png" alt-text="Screenshot: Cortana set a reminder":::
|
||||||
>You can set each reminder location individually as you create the reminders, or you can go into the **About me** screen and add both **Work** and **Home** addresses as favorites. Make sure that you use real addresses since you’ll need to go to these locations to complete your testing scenario.<p>Additionally, if you’ve turned on the **Meeting & reminder cards & notifications** option (in the **Meetings & reminders** option of your Notebook), you’ll also see your pending reminders on the Cortana **Home** page.
|
|
||||||
|
|
||||||
## Create a reminder for a specific location
|
:::image type="content" source="../../../images/screenshot7.png" alt-text="Screenshot: Cortana showing reminder on page":::
|
||||||
This process helps you to create a reminder based on a specific location.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, click on the **Notebook** icon, and then click **Reminders**.
|
|
||||||
|
|
||||||
2. Click the **+** sign, add a subject for your reminder, such as _Remember to file expense report receipts_, and then click **Place**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
3. Choose **Arrive** from the drop-down box, and then type a location to associate with your reminder. For example, you can use the physical address of where you work. Just make sure you can physically get to your location, so you can test the reminder.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
4. Click **Done**.
|
|
||||||
|
|
||||||
>[!NOTE]
|
|
||||||
>If you’ve never used this location before, you’ll be asked to add a name for it so it can be added to the **Favorites list** in Windows Maps.
|
|
||||||
|
|
||||||
5. Choose to be reminded the **Next time you arrive at the location** or on a specific day of the week from the drop-down box.
|
|
||||||
|
|
||||||
6. Take a picture of your receipts and store them locally on your device.
|
|
||||||
|
|
||||||
7. Click **Add Photo**, click **Library**, browse to your picture, and then click **OK**.
|
|
||||||
|
|
||||||
The photo is stored with the reminder.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
8. Review the reminder info, and then click **Remind**.
|
|
||||||
|
|
||||||
The reminder is saved and ready to be triggered.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Create a reminder for a specific location by using voice commands
|
|
||||||
This process helps you to use Cortana at work and voice commands to create a reminder for a specific location.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the **Search** box).
|
|
||||||
|
|
||||||
2. Say _Remind me to grab my expense report receipts before I leave home_.
|
|
||||||
|
|
||||||
Cortana opens a new reminder task and asks if it sounds good.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
3. Say _Yes_ so Cortana can save the reminder.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Edit or archive an existing reminder
|
|
||||||
This process helps you to edit or archive and existing or completed reminder.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, click on the **Notebook** icon, and then click **Reminders**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
2. Click the pending reminder you want to edit.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
3. Change any text that you want to change, click **Add photo** if you want to add or replace an image, click **Delete** if you want to delete the entire reminder, click **Save** to save your changes, and click **Complete and move to History** if you want to save a completed reminder in your **Reminder History**.
|
|
||||||
|
@ -12,42 +12,16 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 4 - Use Cortana at work to find your upcoming meetings
|
# Test scenario 4 - Use Cortana to find free time on your calendar
|
||||||
|
|
||||||
- Windows 10, version 1703
|
This process helps you find out if a time slot is free on your calendar.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
1. Select the **Cortana** icon in the taskbar.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
||||||
|
|
||||||
This scenario helps you search for both general upcoming meetings, and specific meetings, both manually and verbally.
|
|
||||||
|
|
||||||
>[!NOTE]
|
|
||||||
>If you’ve turned on the **Meeting & reminder cards & notifications** option (in the **Meetings & reminders** option of your Notebook), you’ll also see your pending reminders on the Cortana **Home** page.
|
|
||||||
|
|
||||||
## Find out about upcoming meetings
|
|
||||||
This process helps you find your upcoming meetings.
|
|
||||||
|
|
||||||
1. Check to make sure your work calendar is connected and synchronized with your Azure AD account.
|
|
||||||
|
|
||||||
2. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
2. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
||||||
|
|
||||||
3. Type _Show me my meetings for tomorrow_.
|
3. Type **Am I free at 3 PM tomorrow?**
|
||||||
|
|
||||||
You’ll see all your meetings scheduled for the next day.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Find out about upcoming meetings by using voice commands
|
|
||||||
This process helps you to use Cortana at work and voice commands to find your upcoming meetings.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the **Search** box.
|
|
||||||
|
|
||||||
2. Say _Show me what meeting I have at 3pm tomorrow_.
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
|
||||||
>Make sure that you have a meeting scheduled for the time you specify here.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
Cortana will respond with your availability for that time, as well as nearby meetings.
|
||||||
|
|
||||||
|
:::image type="content" source="../../../images/screenshot8.png" alt-text="Screenshot: Cortana showing free time on a calendar":::
|
@ -12,48 +12,14 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 5 - Use Cortana to send email to a co-worker
|
# Test scenario 5 - Test scenario 5 – Find out about a person
|
||||||
|
|
||||||
- Windows 10, version 1703
|
Cortana can help you quickly look up information about someone or the org chart.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
1. Select the **Cortana** icon in the taskbar.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
||||||
|
|
||||||
This scenario helps you to send an email to a co-worker listed in your work address book, both manually and verbally.
|
2. Type or select the mic and say, **Who is name of person in your organization's?**
|
||||||
|
|
||||||
## Send an email to a co-worker
|
:::image type="content" source="../../../images/screenshot8.png" alt-text="Screenshot: Cortana showing name of person in your organization":::
|
||||||
This process helps you to send a quick message to a co-worker from the work address book.
|
|
||||||
|
|
||||||
1. Check to make sure your Microsoft Outlook or mail app is connected and synchronized with your Azure AD account.
|
Cortana will respond with information about the person. You can select the person to open information about them in Microsoft Search.
|
||||||
|
|
||||||
2. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
|
||||||
|
|
||||||
3. Type _Send an email to <contact_name>_.
|
|
||||||
|
|
||||||
Where _<contact_name>_ is the name of someone in your work address book.
|
|
||||||
|
|
||||||
4. Type your email message subject into the **Quick message** (255 characters or less) box and your message into the **Message** (unlimited characters) box, and then click **Send**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Send an email to a co-worker by using voice commands
|
|
||||||
This process helps you to use Cortana at work and voice commands to send a quick message to a co-worker from the work address book.
|
|
||||||
|
|
||||||
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the **Search** box.
|
|
||||||
|
|
||||||
2. Say _Send an email to <contact_name>_.
|
|
||||||
|
|
||||||
Where _<contact_name>_ is the name of someone in your work address book.
|
|
||||||
|
|
||||||
3. Add your email message by saying, _Hello this is a test email using Cortana at work._
|
|
||||||
|
|
||||||
The message is added and you’re asked if you want to **Send it**, **Add more**, or **Make changes**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
4. Say _Send it_.
|
|
||||||
|
|
||||||
The email is sent.
|
|
||||||
|
|
||||||

|
|
@ -12,38 +12,14 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
---
|
---
|
||||||
|
|
||||||
# Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email
|
# Test scenario 6 – Change your language and perform a quick search with Cortana
|
||||||
|
|
||||||
- Windows 10, version 1703
|
Cortana can help employees in regions outside the US search for quick answers like currency conversions, time zone conversions, or weather in their location or another.
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
1. Select the **Cortana** icon in the taskbar.
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering. For more info, see the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and the [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
|
||||||
|
|
||||||
Cortana automatically finds patterns in your email, suggesting reminders based things that you said you would do so you don’t forget about them. For example, Cortana recognizes that if you include the text, _I’ll get this to you by the end of the week_ in an email, you're making a commitment to provide something by a specific date. Cortana can now suggest that you be reminded about this event, letting you decide whether to keep it or to cancel it.
|
2. Select the **…** menu, then select **Settings**, **Language**, then select **Español (España)**. You will be prompted to restart the app.
|
||||||
|
|
||||||
>[!NOTE]
|
3. Once the app has restarted, type or say **Convierte 100 Euros a Dólares**.
|
||||||
>The Suggested reminders feature is currently only available in English (en-us).
|
|
||||||
|
|
||||||
**To use Cortana to create Suggested reminders for you**
|
|
||||||
|
|
||||||
1. Make sure that you've connected Cortana to Office 365. For the steps to connect, see [Set up and test Cortana with Office 365 in your organization](cortana-at-work-o365.md).
|
|
||||||
|
|
||||||
2. Click on the **Cortana** search box in the taskbar, click the **Notebook** icon, and then click **Permissions**.
|
|
||||||
|
|
||||||
3. Make sure the **Contacts, email, calendar, and communication history** option is turned on.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
4. Click the **Notebook** icon again, click the **Suggested reminders** option, click to turn on the **All reminder suggestions cards** option, click the **Notify me when something I mentioned doing is coming up** box, and then click **Save**.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
5. Create and send an email to yourself (so you can see the Suggested reminder), including the text, _I’ll finish this project by end of day today_.
|
|
||||||
|
|
||||||
6. After you get the email, click on the Cortana **Home** icon, and scroll to today’s events.
|
|
||||||
|
|
||||||
If the reminder has a specific date or time associated with it, like end of day, Cortana notifies you at the appropriate time and puts the reminder into the Action Center. Also from the Home screen, you can view the email where you made the promise, set aside time on your calendar, officially set the reminder, or mark the reminder as completed.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
:::image type="content" source="../../../images/screenshot10.png" alt-text="Screenshot: Cortana showing a change your language and showing search results in Spanish":::
|
@ -14,9 +14,6 @@ manager: dansimp
|
|||||||
|
|
||||||
# Test scenario 7 - Use Cortana and Windows Information Protection (WIP) to help protect your organization’s data on a device
|
# Test scenario 7 - Use Cortana and Windows Information Protection (WIP) to help protect your organization’s data on a device
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
>[!IMPORTANT]
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
||||||
|
|
||||||
|
@ -13,26 +13,19 @@ manager: dansimp
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Testing scenarios using Cortana in your business or organization
|
# Testing scenarios using Cortana in your business or organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
We've come up with a list of suggested testing scenarios that you can use to test Cortana in your organization. After you complete all the scenarios, you should be able to:
|
We've come up with a list of suggested testing scenarios that you can use to test Cortana in your organization. After you complete all the scenarios, you should be able to:
|
||||||
|
|
||||||
- [Sign-in to Cortana using Azure AD, manage entries in the notebook, and search for content across your device, Bing, and the cloud, using Cortana](cortana-at-work-scenario-1.md)
|
- [Sign into Azure AD, enable the Cortana wake word, and try a voice query](cortana-at-work-scenario-1.md)
|
||||||
|
|
||||||
- [Perform a quick search with Cortana at work](cortana-at-work-scenario-2.md)
|
- [Perform a Bing search with Cortana](cortana-at-work-scenario-2.md)
|
||||||
|
|
||||||
- [Set a reminder and have it remind you when you’ve reached a specific location](cortana-at-work-scenario-3.md)
|
- [Set a reminder](cortana-at-work-scenario-3.md)
|
||||||
|
|
||||||
- [Search for your upcoming meetings on your work calendar](cortana-at-work-scenario-4.md)
|
- [Use Cortana to find free time on your calendar](cortana-at-work-scenario-4.md)
|
||||||
|
|
||||||
- [Send an email to a co-worker from your work email app](cortana-at-work-scenario-5.md)
|
- [Find out about a person](cortana-at-work-scenario-5.md)
|
||||||
|
|
||||||
- [Review a reminder suggested by Cortana based on what you’ve promised in email](cortana-at-work-scenario-6.md)
|
- [Change your language and perform a quick search with Cortana](cortana-at-work-scenario-6.md)
|
||||||
|
|
||||||
- [Use Windows Information Protection (WIP) to secure content on a device and then try to manage your organization’s entries in the notebook](cortana-at-work-scenario-7.md)
|
- [Use Windows Information Protection (WIP) to secure content on a device and then try to manage your organization’s entries in the notebook](cortana-at-work-scenario-7.md)
|
||||||
|
|
||||||
>[!IMPORTANT]
|
|
||||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
|
@ -13,15 +13,11 @@ manager: dansimp
|
|||||||
---
|
---
|
||||||
|
|
||||||
# Set up and test custom voice commands in Cortana for your organization
|
# Set up and test custom voice commands in Cortana for your organization
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
|
||||||
- Windows 10 Mobile, version 1703
|
|
||||||
|
|
||||||
Working with a developer, you can create voice commands that use Cortana to perform voice-enabled actions in your line-of-business (LOB) Universal Windows Platform (UWP) apps. These voice-enabled actions can reduce the time necessary to access your apps and to complete simple actions.
|
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>For more info about how your developer can extend your current apps to work directly with Cortana, see [The Cortana Skills Kit](https://docs.microsoft.com/cortana/getstarted).
|
>This content applies to Cortana in versions 1909 and earlier, but will not be available in future releases.
|
||||||
|
|
||||||
|
Working with a developer, you can create voice commands that use Cortana to perform voice-enabled actions in your line-of-business (LOB) Universal Windows Platform (UWP) apps. These voice-enabled actions can reduce the time necessary to access your apps and to complete simple actions.
|
||||||
|
|
||||||
## High-level process
|
## High-level process
|
||||||
Cortana uses a Voice Command Definition (VCD) file, aimed at an installed app, to define the actions that are to happen during certain vocal commands. A VCD file can be very simple to very complex, supporting anything from a single sound to a collection of more flexible, natural language sounds, all with the same intent.
|
Cortana uses a Voice Command Definition (VCD) file, aimed at an installed app, to define the actions that are to happen during certain vocal commands. A VCD file can be very simple to very complex, supporting anything from a single sound to a collection of more flexible, natural language sounds, all with the same intent.
|
||||||
|
@ -0,0 +1,49 @@
|
|||||||
|
---
|
||||||
|
title: Set up and test Cortana in Windows 10, version 2004 and later
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
description: Cortana includes powerful configuration options specifically to optimize for unique small to medium-sized business and enterprise environments.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: kwekua
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Set up and test Cortana in Windows 10, version 2004 and later
|
||||||
|
|
||||||
|
## Before you begin
|
||||||
|
|
||||||
|
- If your enterprise had previously disabled Cortana for your employees using the **Computer Configuration\Administrative Templates\Windows Components\Search\Allow Cortana** Group Policy or the **Experience\AllowCortana** MDM setting but want to enable it now that Cortana is part of Microsoft 365, you will need to re-enable it at least for Windows 10, version 2004 and later.
|
||||||
|
- **Cortana is regularly updated through the Microsoft Store.** Beginning with Windows 10, version 2004, Cortana is an appx preinstalled with Windows and is regularly updated through the Microsoft Store. To receive the latest updates to Cortana, you will need to [enable updates through the Microsoft Store](https://docs.microsoft.com/windows/configuration/stop-employees-from-using-microsoft-store).
|
||||||
|
|
||||||
|
## Set up and configure the Bing Answers feature
|
||||||
|
Bing Answers provides fast, authoritative results to search queries based on search terms. When the Bing Answers feature is enabled, users will be able to ask Cortana web-related questions in the Cortana in Windows app, such as "What's the current weather?" or "Who is the president of the U.S.?," and get a response, based on public results from Bing.com.
|
||||||
|
|
||||||
|
The above experience is powered by Microsoft Bing, and Cortana sends the user queries to Bing. The use of Microsoft Bing is governed by the [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement) and [Privacy Statement](https://privacy.microsoft.com/en-US/privacystatement).
|
||||||
|
|
||||||
|
## Configure the Bing Answers feature
|
||||||
|
|
||||||
|
Admins can configure the Cortana in Windows Bing Answers feature for their organizations. As the admin, use the following steps to change the setting for Bing Answers at the tenant/security group level. This setting is enabled by default, so that all users who have Cortana enabled will be able to receive Bing Answers. By default, the Bing Answer feature will be available to your users.
|
||||||
|
|
||||||
|
Users cannot enable or disable the Bing Answer feature individually. So, if you disable this feature at the tenant/security group level, no users in your organization or specific security group will be able to use Bing Answers in Cortana in Windows.
|
||||||
|
|
||||||
|
Sign in to the [Office Configuration Admin tool](https://config.office.com/).
|
||||||
|
|
||||||
|
Follow the steps [here](https://docs.microsoft.com/deployoffice/overview-office-cloud-policy-service#steps-for-creating-a-policy-configuration) to create this policy configuration. Once completed, the policy will look as shown below:
|
||||||
|
|
||||||
|
:::image type="content" source="../../../images/screenshot3.png" alt-text="Screenshot: Bing policy example":::
|
||||||
|
|
||||||
|
## How does Microsoft handle customer data for Bing Answers?
|
||||||
|
|
||||||
|
When a user enters a search query (by speech or text), Cortana evaluates if the request is for any of our first-party compliant skills if enabled in a specific market, and does the following:
|
||||||
|
|
||||||
|
1. If it is for any of the first-party compliant skills, the query is sent to that skill, and results/action are returned.
|
||||||
|
|
||||||
|
2. If it is not for any of the first-party compliant skills, the query is sent to Bing for a search of public results from Bing.com. Because enterprise searches might be sensitive, similar to [Microsoft Search in Bing](https://docs.microsoft.com/MicrosoftSearch/security-for-search#microsoft-search-in-bing-protects-workplace-searches), Bing Answers in Cortana has implemented a set of trust measures, described below, that govern how the separate search of public results from Bing.com is handled. The Bing Answers in Cortana trust measures are consistent with the enhanced privacy and security measures described in [Microsoft Search in Bing](https://docs.microsoft.com/MicrosoftSearch/security-for-search). All Bing.com search logs that pertain to Cortana traffic are disassociated from users' workplace identity. All Cortana queries issued via a work or school account are stored separately from public, non-Cortana traffic.
|
||||||
|
|
||||||
|
Bing Answers is enabled by default for all users. However, admins can configure and change this for specific users/user groups in their organization.
|
||||||
|
|
||||||
|
## How the Bing Answer policy configuration is applied
|
||||||
|
Before a query is sent to Bing for a search of public results from Bing.com, the Bing Answers service checks with the Office Cloud Policy Service to see if there are any policy configurations that pertain to the user for allowing Bing Answers to respond to questions users ask Cortana. If the user is a member of an AAD group that is assigned that policy configuration, then the appropriate policy settings are applied and a check is made again in 10 minutes.
|
46
windows/configuration/cortana-at-work/test-scenario-1.md
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
---
|
||||||
|
title: Test scenario 1 – Sign in with your work or school account and use Cortana to manage the notebook
|
||||||
|
description: A test scenario about how to sign in with your work or school account and use Cortana to manage the notebook.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 1 – Sign in with your work or school account and use Cortana to manage the notebook
|
||||||
|
|
||||||
|
This scenario turns on Azure AD and lets your employee use Cortana to manage an entry in the notebook.
|
||||||
|
|
||||||
|
## Sign in with your work or school account
|
||||||
|
|
||||||
|
This process helps you to sign out of a Microsoft Account and to sign into an Azure AD account.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, then click the profile picture in the navigation to open Cortana settings.
|
||||||
|
|
||||||
|
2. Click your email address.
|
||||||
|
|
||||||
|
A dialog box appears, showing the associated account info.
|
||||||
|
|
||||||
|
3. Click **Sign out** under your email address.
|
||||||
|
|
||||||
|
This signs out the Microsoft account, letting you continue to add your work or school account.
|
||||||
|
|
||||||
|
4. Open Cortana again and select the **Sign in** glyph in the left rail and follow the instructions to sign in with your work or school account.
|
||||||
|
|
||||||
|
## Use Cortana to manage the notebook content
|
||||||
|
|
||||||
|
This process helps you to manage the content Cortana shows in your Notebook.
|
||||||
|
|
||||||
|
1. Select the **Cortana** icon in the taskbar, click **Notebook**, select **Manage Skills.** Scroll down and click **Weather**.
|
||||||
|
|
||||||
|
2. In the **Weather** settings, scroll down to the **Cities you're tracking** area, and then click **Add a city**.
|
||||||
|
|
||||||
|
3. Add **Redmond, Washington**.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> The data created as part of these scenarios will be uploaded to Microsoft's Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
38
windows/configuration/cortana-at-work/test-scenario-2.md
Normal file
@ -0,0 +1,38 @@
|
|||||||
|
---
|
||||||
|
title: Test scenario 2 - Perform a quick search with Cortana at work
|
||||||
|
description: A test scenario about how to perform a quick search with Cortana at work.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 2 – Perform a quick search with Cortana at work
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
||||||
|
|
||||||
|
This scenario helps you perform a quick search using Cortana, both by typing and through voice commands.
|
||||||
|
|
||||||
|
## Search using Cortana
|
||||||
|
|
||||||
|
1. Click on the Cortana icon in the taskbar, and then click in the Search bar.
|
||||||
|
|
||||||
|
2. Type **Type Weather in New York**.
|
||||||
|
|
||||||
|
You should see the weather in New York, New York at the top of the search results.
|
||||||
|
Insert screenshot
|
||||||
|
|
||||||
|
## Search with Cortana, by using voice commands
|
||||||
|
|
||||||
|
This process helps you to use Cortana at work and voice commands to perform a quick search.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the Search box).
|
||||||
|
|
||||||
|
2. Say **What's the weather in Chicago?** Cortana tells you and shows you the current weather in Chicago.
|
||||||
|
Insert screenshot
|
79
windows/configuration/cortana-at-work/test-scenario-3.md
Normal file
@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
title: Test scenario 3 - Set a reminder for a specific location using Cortana at work
|
||||||
|
description: A test scenario about how to set up, review, and edit a reminder based on a location.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 3 - Set a reminder for a specific location using Cortana at work
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
||||||
|
|
||||||
|
This scenario helps you set up, review, and edit a reminder based on a location. For example, reminding yourself to grab your expense report receipts before you leave the house.
|
||||||
|
|
||||||
|
>[!Note]
|
||||||
|
>You can set each reminder location individually as you create the reminders, or you can go into the About me screen and add both Work and Home addresses as favorites. Make sure that you use real addresses since you’ll need to go to these locations to complete your testing scenario.
|
||||||
|
|
||||||
|
Additionally, if you’ve turned on the Meeting & reminder cards & notifications option (in the Meetings & reminders option of your Notebook), you’ll also see your pending reminders on the Cortana Home page.
|
||||||
|
|
||||||
|
## Create a reminder for a specific location
|
||||||
|
|
||||||
|
This process helps you to create a reminder based on a specific location.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, click on the **Notebook** icon, and then click **Reminders**.
|
||||||
|
|
||||||
|
2. Click the **+** sign, add a subject for your reminder, such as **Remember to file expense report receipts**, and then click **Place**.
|
||||||
|
|
||||||
|
3. Choose **Arrive** from the drop-down box, and then type a location to associate with your reminder. For example, you can use the physical address of where you work. Just make sure you can physically get to your location, so you can test the reminder.
|
||||||
|
|
||||||
|
4. Click **Done**.
|
||||||
|
|
||||||
|
>[!Note]
|
||||||
|
>If you’ve never used this location before, you’ll be asked to add a name for it so it can be added to the Favorites list in Windows Maps.
|
||||||
|
|
||||||
|
5. Choose to be reminded the Next time you arrive at the location or on a specific day of the week from the drop-down box.
|
||||||
|
|
||||||
|
6. Take a picture of your receipts and store them locally on your device.
|
||||||
|
|
||||||
|
7. Click **Add Photo**, click **Library**, browse to your picture, and then click **OK**.
|
||||||
|
|
||||||
|
The photo is stored with the reminder.
|
||||||
|
|
||||||
|
Insert screenshot 6
|
||||||
|
|
||||||
|
8. Review the reminder info, and then click **Remind**.
|
||||||
|
|
||||||
|
The reminder is saved and ready to be triggered.
|
||||||
|
Insert screenshot
|
||||||
|
|
||||||
|
## Create a reminder for a specific location by using voice commands
|
||||||
|
|
||||||
|
This process helps you to use Cortana at work and voice commands to create a reminder for a specific location.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone* icon (to the right of the Search box).
|
||||||
|
|
||||||
|
2. Say **Remind me to grab my expense report receipts before I leave home**.
|
||||||
|
|
||||||
|
Cortana opens a new reminder task and asks if it sounds good.
|
||||||
|
insert screenshot
|
||||||
|
|
||||||
|
3. Say **Yes** so Cortana can save the reminder.
|
||||||
|
insert screenshot
|
||||||
|
|
||||||
|
## Edit or archive an existing reminder
|
||||||
|
|
||||||
|
This process helps you to edit or archive and existing or completed reminder.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, click on the **Notebook** icon, and then click **Reminders**.
|
||||||
|
|
||||||
|
2. Click the pending reminder you want to edit.
|
||||||
|
|
||||||
|
3. Change any text that you want to change, click **Add photo** if you want to add or replace an image, click **Delete** if you want to delete the entire reminder, click Save to save your changes, and click **Complete and move to History** if you want to save a completed reminder in your **Reminder History**.
|
52
windows/configuration/cortana-at-work/test-scenario-4.md
Normal file
@ -0,0 +1,52 @@
|
|||||||
|
---
|
||||||
|
title: Use Cortana at work to find your upcoming meetings (Windows 10)
|
||||||
|
description: A test scenario about how to use Cortana at work to find your upcoming meetings.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 4 - Use Cortana at work to find your upcoming meetings
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
||||||
|
|
||||||
|
This scenario helps you search for both general upcoming meetings, and specific meetings, both manually and verbally.
|
||||||
|
|
||||||
|
>[!Note]
|
||||||
|
>If you’ve turned on the Meeting & reminder cards & notifications option (in the Meetings & reminders option of your Notebook), you’ll also see your pending reminders on the Cortana Home page.
|
||||||
|
|
||||||
|
## Find out about upcoming meetings
|
||||||
|
|
||||||
|
This process helps you find your upcoming meetings.
|
||||||
|
|
||||||
|
1. Check to make sure your work calendar is connected and synchronized with your Azure AD account.
|
||||||
|
|
||||||
|
2. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
||||||
|
|
||||||
|
3. Type **Show me my meetings for tomorrow**.
|
||||||
|
|
||||||
|
You’ll see all your meetings scheduled for the next day.
|
||||||
|
|
||||||
|
Cortana at work, showing all upcoming meetings
|
||||||
|
screenshot
|
||||||
|
|
||||||
|
## Find out about upcoming meetings by using voice commands
|
||||||
|
|
||||||
|
This process helps you to use Cortana at work and voice commands to find your upcoming meetings.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the Search box.
|
||||||
|
|
||||||
|
2. Say **Show me what meeting I have at 3pm tomorrow**.
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>Make sure that you have a meeting scheduled for the time you specify here.
|
||||||
|
|
||||||
|
Cortana at work, showing the meeting scheduled for 3pm
|
||||||
|
screenshot
|
61
windows/configuration/cortana-at-work/test-scenario-5.md
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
---
|
||||||
|
title: Use Cortana to send email to a co-worker (Windows 10)
|
||||||
|
description: A test scenario about how to use Cortana at work to send email to a co-worker.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 5 - Use Cortana to send email to a co-worker
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering.
|
||||||
|
|
||||||
|
This scenario helps you to send an email to a co-worker listed in your work address book, both manually and verbally.
|
||||||
|
|
||||||
|
## Send email to a co-worker
|
||||||
|
|
||||||
|
This process helps you to send a quick message to a co-worker from the work address book.
|
||||||
|
|
||||||
|
1. Check to make sure your Microsoft Outlook or mail app is connected and synchronized with your Azure AD account.
|
||||||
|
|
||||||
|
2. Click on the **Cortana** icon in the taskbar, and then click in the **Search** bar.
|
||||||
|
|
||||||
|
3. Type **Send an email to <contact_name>**.
|
||||||
|
|
||||||
|
Where <contact_name> is the name of someone in your work address book.
|
||||||
|
|
||||||
|
4. Type your email message subject into the **Quick message** (255 characters or less) box and your message into the **Message** (unlimited characters) box, and then click **Send**.
|
||||||
|
|
||||||
|
Cortana at work, showing the email text
|
||||||
|
screenshot
|
||||||
|
|
||||||
|
## Send an email to a co-worker by using voice commands
|
||||||
|
|
||||||
|
This process helps you to use Cortana at work and voice commands to send a quick message to a co-worker from the work address book.
|
||||||
|
|
||||||
|
1. Click on the **Cortana** icon in the taskbar, and then click the **Microphone** icon (to the right of the Search box.
|
||||||
|
|
||||||
|
2. Say **Send an email** to <contact_name>.
|
||||||
|
|
||||||
|
Where <contact_name> is the name of someone in your work address book.
|
||||||
|
|
||||||
|
3. Add your email message by saying, **Hello this is a test email using Cortana at work**.
|
||||||
|
|
||||||
|
The message is added and you’re asked if you want to **Send it**, **Add more**, or **Make changes**.
|
||||||
|
|
||||||
|
Cortana at work, showing the email text created from verbal commands
|
||||||
|
screenshot
|
||||||
|
|
||||||
|
4. Say **Send it**.
|
||||||
|
|
||||||
|
The email is sent.
|
||||||
|
|
||||||
|
Cortana at work, showing the sent email text
|
||||||
|
screenshot
|
48
windows/configuration/cortana-at-work/test-scenario-6.md
Normal file
@ -0,0 +1,48 @@
|
|||||||
|
---
|
||||||
|
title: Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email
|
||||||
|
description: A test scenario about how to use Cortana with the Suggested reminders feature.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering. For more info, see the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and the [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
||||||
|
|
||||||
|
Cortana automatically finds patterns in your email, suggesting reminders based things that you said you would do so you don’t forget about them. For example, Cortana recognizes that if you include the text, I’ll get this to you by the end of the week in an email, you're making a commitment to provide something by a specific date. Cortana can now suggest that you be reminded about this event, letting you decide whether to keep it or to cancel it.
|
||||||
|
|
||||||
|
>[!Important]
|
||||||
|
>The Suggested reminders feature is currently only available in English (en-us).
|
||||||
|
|
||||||
|
## Use Cortana to create suggested reminders for you
|
||||||
|
|
||||||
|
1. Make sure that you've connected Cortana to Office 365. For the steps to connect, see [Set up and test Cortana with Office 365 in your organization](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-o365).
|
||||||
|
|
||||||
|
2. Click on the **Cortana** search box in the taskbar, click the **Notebook** icon, and then click **Permissions**.
|
||||||
|
|
||||||
|
3. Make sure the **Contacts**, **email**, **calendar**, and **communication history** option is turned on.
|
||||||
|
|
||||||
|
Permissions options for Cortana at work
|
||||||
|
screenshot
|
||||||
|
|
||||||
|
4. Click the **Notebook** icon again, click the **Suggested reminders** option, click to turn on the **All reminder suggestions cards** option, click the **Notify me when something I mentioned doing is coming up** box, and then click **Save**.
|
||||||
|
|
||||||
|
Suggested reminders options for Cortana at work
|
||||||
|
screenshot
|
||||||
|
|
||||||
|
5. Create and send an email to yourself (so you can see the Suggested reminder), including the text, **I’ll finish this project by end of day today**.
|
||||||
|
|
||||||
|
6. After you get the email, click on the Cortana **Home** icon, and scroll to today’s events.
|
||||||
|
|
||||||
|
If the reminder has a specific date or time associated with it, like end of day, Cortana notifies you at the appropriate time and puts the reminder into the Action Center. Also from the Home screen, you can view the email where you made the promise, set aside time on your calendar, officially set the reminder, or mark the reminder as completed.
|
||||||
|
|
||||||
|
Cortana Home screen with your suggested reminder showing
|
||||||
|
screenshot
|
@ -0,0 +1,25 @@
|
|||||||
|
---
|
||||||
|
title: Testing scenarios using Cortana in your business or organization
|
||||||
|
description: A list of suggested testing scenarios that you can use to test Cortana in your organization.
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: manage
|
||||||
|
ms.sitesec: library
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.author: dansimp
|
||||||
|
ms.date: 10/05/2017
|
||||||
|
ms.reviewer:
|
||||||
|
manager: dansimp
|
||||||
|
---
|
||||||
|
|
||||||
|
# Testing scenarios using Cortana in your business or organization
|
||||||
|
|
||||||
|
We've come up with a list of suggested testing scenarios that you can use to test Cortana in your organization. After you complete all the scenarios, you should be able to:
|
||||||
|
|
||||||
|
- [Sign in with your work or school account and use Cortana to manage the notebook](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-1)
|
||||||
|
- [Perform a quick search with Cortana at work](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-2)
|
||||||
|
- [Set a reminder for a specific location using Cortana at work](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-3)
|
||||||
|
- [Use Cortana at work to find your upcoming meetings](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-4)
|
||||||
|
- [Use Cortana to send email to a co-worker](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-5)
|
||||||
|
- [Review a reminder suggested by Cortana based on what you've promised in email](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-6)
|
||||||
|
- [Use Cortana and Windows Information Protection (WIP) to help protect your organization's data on a device](https://docs.microsoft.com/windows/configuration/cortana-at-work/cortana-at-work-scenario-7)
|
@ -39,7 +39,7 @@ An example of Microsoft Intune Windows Encryption settings is shown below.
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
Note that a device which is encrypted automatically will need to be decrypted prior to changing the encyption algorithm.
|
Note that a device which is encrypted automatically will need to be decrypted prior to changing the encryption algorithm.
|
||||||
|
|
||||||
The settings are available under Device Configuration -> Profiles -> Create profile -> Platform = Windows 10 and later, Profile type = Endpoint protection -> Configure -> Windows Encryption -> BitLocker base settings, Configure encryption methods = Enable.
|
The settings are available under Device Configuration -> Profiles -> Create profile -> Platform = Windows 10 and later, Profile type = Endpoint protection -> Configure -> Windows Encryption -> BitLocker base settings, Configure encryption methods = Enable.
|
||||||
|
|
||||||
|
@ -80,6 +80,10 @@ Each OEM has a unique link to provide to their respective customers, which the O
|
|||||||

|

|
||||||
3. Customer selects the **Yes** checkbox, followed by the **Accept** button, and they’re done. Authorization happens instantaneously.
|
3. Customer selects the **Yes** checkbox, followed by the **Accept** button, and they’re done. Authorization happens instantaneously.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Once this process has completed, it is not currently possible for an administrator to remove an OEM. To remove an OEM or revoke
|
||||||
|
their permissions, send a request to msoemops@microsoft.com
|
||||||
|
|
||||||
4. The OEM can use the Validate Device Submission Data API to verify the consent has completed. This API is discussed in the latest version of the API Whitepaper, p. 14ff [https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx](https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx). **Note**: this link is only accessible by Microsoft Device Partners. As discussed in this whitepaper, it’s a best practice recommendation for OEM partners to run the API check to confirm they’ve received customer consent before attempting to register devices, thus avoiding errors in the registration process.
|
4. The OEM can use the Validate Device Submission Data API to verify the consent has completed. This API is discussed in the latest version of the API Whitepaper, p. 14ff [https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx](https://devicepartner.microsoft.com/assets/detail/windows-autopilot-integration-with-oem-api-design-whitepaper-docx). **Note**: this link is only accessible by Microsoft Device Partners. As discussed in this whitepaper, it’s a best practice recommendation for OEM partners to run the API check to confirm they’ve received customer consent before attempting to register devices, thus avoiding errors in the registration process.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
|
@ -94,7 +94,7 @@ If the Microsoft Store is not accessible, the AutoPilot process will still conti
|
|||||||
Windows Autopilot depends on specific capabilities available in Windows 10 and Azure Active Directory. It also requires an MDM service such as Microsoft Intune. These capabilities can be obtained through various editions and subscription programs:
|
Windows Autopilot depends on specific capabilities available in Windows 10 and Azure Active Directory. It also requires an MDM service such as Microsoft Intune. These capabilities can be obtained through various editions and subscription programs:
|
||||||
|
|
||||||
To provide needed Azure Active Directory (automatic MDM enrollment and company branding features) and MDM functionality, one of the following is required:
|
To provide needed Azure Active Directory (automatic MDM enrollment and company branding features) and MDM functionality, one of the following is required:
|
||||||
- [Microsoft 365 Business subscriptions](https://www.microsoft.com/microsoft-365/business)
|
- [Microsoft 365 Business Premium subscriptions](https://www.microsoft.com/microsoft-365/business)
|
||||||
- [Microsoft 365 F1 subscriptions](https://www.microsoft.com/microsoft-365/enterprise/firstline)
|
- [Microsoft 365 F1 subscriptions](https://www.microsoft.com/microsoft-365/enterprise/firstline)
|
||||||
- [Microsoft 365 Academic A1, A3, or A5 subscriptions](https://www.microsoft.com/education/buy-license/microsoft365/default.aspx)
|
- [Microsoft 365 Academic A1, A3, or A5 subscriptions](https://www.microsoft.com/education/buy-license/microsoft365/default.aspx)
|
||||||
- [Microsoft 365 Enterprise E3 or E5 subscriptions](https://www.microsoft.com/microsoft-365/enterprise), which include all Windows 10, Office 365, and EM+S features (Azure AD and Intune).
|
- [Microsoft 365 Enterprise E3 or E5 subscriptions](https://www.microsoft.com/microsoft-365/enterprise), which include all Windows 10, Office 365, and EM+S features (Azure AD and Intune).
|
||||||
|
@ -21,14 +21,14 @@ ms.reviewer:
|
|||||||
**Applies to**
|
**Applies to**
|
||||||
- Windows 10, version 1703 or later
|
- Windows 10, version 1703 or later
|
||||||
- Hybrid deployment
|
- Hybrid deployment
|
||||||
- Certificate trust
|
- Key trust
|
||||||
|
|
||||||
|
|
||||||
## Directory Synchronization
|
## Directory Synchronization
|
||||||
|
|
||||||
In hybrid deployments, users register the public portion of their Windows Hello for Business credential with Azure. Azure AD Connect synchronizes the Windows Hello for Business public key to Active Directory.
|
In hybrid deployments, users register the public portion of their Windows Hello for Business credential with Azure. Azure AD Connect synchronizes the Windows Hello for Business public key to Active Directory.
|
||||||
|
|
||||||
The key-trust model needs Windows Server 2016 domain controllers, which configures the key registration permissions automatically; however, the certificate-trust model does not and requires you to add the permissions manually.
|
The key-trust model needs Windows Server 2016 domain controllers, which configure the key registration permissions automatically; however, the certificate-trust model does not and requires you to add the permissions manually.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> If you already have a Windows Server 2016 domain controller in your domain, you can skip **Configure Permissions for Key Synchronization**. In this case, you should use the pre-created group KeyAdmins in step 3 of the "Group Memberships for the Azure AD Connect Service Account" section of this article.
|
> If you already have a Windows Server 2016 domain controller in your domain, you can skip **Configure Permissions for Key Synchronization**. In this case, you should use the pre-created group KeyAdmins in step 3 of the "Group Memberships for the Azure AD Connect Service Account" section of this article.
|
||||||
@ -61,6 +61,9 @@ Sign-in a domain controller or management workstation with _Domain Admin_ equiva
|
|||||||
5. In the **Enter the object names to select** text box, type the name of the Azure AD Connect service account. Click **OK**.
|
5. In the **Enter the object names to select** text box, type the name of the Azure AD Connect service account. Click **OK**.
|
||||||
6. Click **OK** to return to **Active Directory Users and Computers**.
|
6. Click **OK** to return to **Active Directory Users and Computers**.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> If your AD forest has multiple domains. Please make sure you add the ADConnect sync service account (that is, MSOL_12121212) into "Enterprise Key Admins" group to gain permission across the domains in the forest.
|
||||||
|
|
||||||
### Section Review
|
### Section Review
|
||||||
|
|
||||||
> [!div class="checklist"]
|
> [!div class="checklist"]
|
||||||
|
@ -238,6 +238,7 @@
|
|||||||
##### [Configure and validate exclusions](microsoft-defender-atp/linux-exclusions.md)
|
##### [Configure and validate exclusions](microsoft-defender-atp/linux-exclusions.md)
|
||||||
##### [Static proxy configuration](microsoft-defender-atp/linux-static-proxy-configuration.md)
|
##### [Static proxy configuration](microsoft-defender-atp/linux-static-proxy-configuration.md)
|
||||||
##### [Set preferences](microsoft-defender-atp/linux-preferences.md)
|
##### [Set preferences](microsoft-defender-atp/linux-preferences.md)
|
||||||
|
##### [Detect and block Potentially Unwanted Applications](microsoft-defender-atp/linux-pua.md)
|
||||||
|
|
||||||
#### [Troubleshoot]()
|
#### [Troubleshoot]()
|
||||||
##### [Troubleshoot installation issues](microsoft-defender-atp/linux-support-install.md)
|
##### [Troubleshoot installation issues](microsoft-defender-atp/linux-support-install.md)
|
||||||
@ -245,6 +246,7 @@
|
|||||||
##### [Troubleshoot performance issues](microsoft-defender-atp/linux-support-perf.md)
|
##### [Troubleshoot performance issues](microsoft-defender-atp/linux-support-perf.md)
|
||||||
|
|
||||||
|
|
||||||
|
#### [Privacy](microsoft-defender-atp/linux-privacy.md)
|
||||||
#### [Resources](microsoft-defender-atp/linux-resources.md)
|
#### [Resources](microsoft-defender-atp/linux-resources.md)
|
||||||
|
|
||||||
### [Configure and manage Microsoft Threat Experts capabilities](microsoft-defender-atp/configure-microsoft-threat-experts.md)
|
### [Configure and manage Microsoft Threat Experts capabilities](microsoft-defender-atp/configure-microsoft-threat-experts.md)
|
||||||
@ -349,10 +351,10 @@
|
|||||||
##### [DeviceNetworkEvents](microsoft-defender-atp/advanced-hunting-devicenetworkevents-table.md)
|
##### [DeviceNetworkEvents](microsoft-defender-atp/advanced-hunting-devicenetworkevents-table.md)
|
||||||
##### [DeviceProcessEvents](microsoft-defender-atp/advanced-hunting-deviceprocessevents-table.md)
|
##### [DeviceProcessEvents](microsoft-defender-atp/advanced-hunting-deviceprocessevents-table.md)
|
||||||
##### [DeviceRegistryEvents](microsoft-defender-atp/advanced-hunting-deviceregistryevents-table.md)
|
##### [DeviceRegistryEvents](microsoft-defender-atp/advanced-hunting-deviceregistryevents-table.md)
|
||||||
##### [DeviceTvmSoftwareInventoryVulnerabilities](microsoft-defender-atp/advanced-hunting-tvm-softwareinventory-table.md)
|
##### [DeviceTvmSoftwareInventoryVulnerabilities](microsoft-defender-atp/advanced-hunting-devicetvmsoftwareinventoryvulnerabilities-table.md)
|
||||||
##### [DeviceTvmSoftwareVulnerabilitiesKB](microsoft-defender-atp/advanced-hunting-tvm-softwarevulnerability-table.md)
|
##### [DeviceTvmSoftwareVulnerabilitiesKB](microsoft-defender-atp/advanced-hunting-devicetvmsoftwarevulnerabilitieskb-table.md)
|
||||||
##### [DeviceTvmSecureConfigurationAssessment](microsoft-defender-atp/advanced-hunting-tvm-configassessment-table.md)
|
##### [DeviceTvmSecureConfigurationAssessment](microsoft-defender-atp/advanced-hunting-devicetvmsecureconfigurationassessment-table.md)
|
||||||
##### [DeviceTvmSecureConfigurationAssessmentKB](microsoft-defender-atp/advanced-hunting-tvm-secureconfigkb-table.md)
|
##### [DeviceTvmSecureConfigurationAssessmentKB](microsoft-defender-atp/advanced-hunting-devicetvmsecureconfigurationassessmentkb-table.md)
|
||||||
#### [Apply query best practices](microsoft-defender-atp/advanced-hunting-best-practices.md)
|
#### [Apply query best practices](microsoft-defender-atp/advanced-hunting-best-practices.md)
|
||||||
|
|
||||||
### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md)
|
### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md)
|
||||||
|
BIN
windows/security/threat-protection/images/lab-creation-page.png
Normal file
After Width: | Height: | Size: 135 KiB |
@ -22,30 +22,34 @@ ms.topic: article
|
|||||||
|
|
||||||
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
- Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-exposedapis-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
## API description
|
## API description
|
||||||
|
|
||||||
Adds or remove tag to a specific [Machine](machine.md).
|
Adds or remove tag to a specific [Machine](machine.md).
|
||||||
|
|
||||||
|
|
||||||
## Limitations
|
## Limitations
|
||||||
|
|
||||||
1. You can post on machines last seen in the past 30 days.
|
1. You can post on machines last seen in the past 30 days.
|
||||||
|
|
||||||
2. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
2. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
|
||||||
|
|
||||||
|
|
||||||
## Permissions
|
## Permissions
|
||||||
|
|
||||||
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md)
|
||||||
|
|
||||||
Permission type | Permission | Permission display name
|
Permission type | Permission | Permission display name
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
Application | Machine.ReadWrite.All | 'Read and write all machine information'
|
Application | Machine.ReadWrite.All | 'Read and write all machine information'
|
||||||
Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine information'
|
Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine information'
|
||||||
|
|
||||||
>[!Note]
|
>[!Note]
|
||||||
> When obtaining a token using user credentials:
|
> When obtaining a token using user credentials:
|
||||||
>- The user needs to have at least the following role permission: 'Manage security setting' (See [Create and manage roles](user-roles.md) for more information)
|
>
|
||||||
|
>- The user needs to have at least the following role permission: 'Manage security setting'. For more (See [Create and manage roles](user-roles.md) for more information)
|
||||||
>- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information)
|
>- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information)
|
||||||
|
|
||||||
## HTTP request
|
## HTTP request
|
||||||
|
|
||||||
```
|
```
|
||||||
POST https://api.securitycenter.windows.com/api/machines/{id}/tags
|
POST https://api.securitycenter.windows.com/api/machines/{id}/tags
|
||||||
```
|
```
|
||||||
@ -58,17 +62,18 @@ Authorization | String | Bearer {token}. **Required**.
|
|||||||
Content-Type | string | application/json. **Required**.
|
Content-Type | string | application/json. **Required**.
|
||||||
|
|
||||||
## Request body
|
## Request body
|
||||||
|
|
||||||
In the request body, supply a JSON object with the following parameters:
|
In the request body, supply a JSON object with the following parameters:
|
||||||
|
|
||||||
Parameter | Type | Description
|
Parameter | Type | Description
|
||||||
:---|:---|:---
|
:---|:---|:---
|
||||||
Value | String | The tag name. **Required**.
|
Value | String | The tag name. **Required**.
|
||||||
Action | Enum | Add or Remove. Allowed values are: 'Add' or 'Remove'. **Required**.
|
Action | Enum | Add or Remove. Allowed values are: 'Add' or 'Remove'. **Required**.
|
||||||
|
|
||||||
|
|
||||||
## Response
|
## Response
|
||||||
If successful, this method returns 200 - Ok response code and the updated Machine in the response body.
|
|
||||||
|
|
||||||
|
If successful, this method returns 200 - Ok response code and the updated Machine in the response body.
|
||||||
|
|
||||||
## Example
|
## Example
|
||||||
|
|
||||||
|
@ -1,53 +1,53 @@
|
|||||||
---
|
---
|
||||||
title: DeviceTvmSecureConfigurationAssessment table in the advanced hunting schema
|
title: DeviceTvmSecureConfigurationAssessment table in the advanced hunting schema
|
||||||
description: Learn about Threat & Vulnerability Management security assessment events in the DeviceTvmSecureConfigurationAssessment table of the Advanced hunting schema. These events provide machine information as well as security configuration details, impact, and compliance information.
|
description: Learn about Threat & Vulnerability Management security assessment events in the DeviceTvmSecureConfigurationAssessment table of the Advanced hunting schema. These events provide machine information as well as security configuration details, impact, and compliance information.
|
||||||
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, security configuration, DeviceTvmSecureConfigurationAssessment
|
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, security configuration, DeviceTvmSecureConfigurationAssessment
|
||||||
search.product: eADQiWindows 10XVcnh
|
search.product: eADQiWindows 10XVcnh
|
||||||
search.appverid: met150
|
search.appverid: met150
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.author: dolmont
|
ms.author: dolmont
|
||||||
author: DulceMontemayor
|
author: DulceMontemayor
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 11/12/2019
|
ms.date: 11/12/2019
|
||||||
---
|
---
|
||||||
|
|
||||||
# DeviceTvmSecureConfigurationAssessment
|
# DeviceTvmSecureConfigurationAssessment
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
||||||
|
|
||||||
[!include[Prerelease information](../../includes/prerelease.md)]
|
[!include[Prerelease information](../../includes/prerelease.md)]
|
||||||
|
|
||||||
Each row in the `DeviceTvmSecureConfigurationAssessment` table contains an assessment event for a specific security configuration from [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md). Use this reference to check the latest assessment results and determine whether devices are compliant.
|
Each row in the `DeviceTvmSecureConfigurationAssessment` table contains an assessment event for a specific security configuration from [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md). Use this reference to check the latest assessment results and determine whether devices are compliant.
|
||||||
|
|
||||||
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
||||||
|
|
||||||
| Column name | Data type | Description |
|
| Column name | Data type | Description |
|
||||||
|-------------|-----------|-------------|
|
|-------------|-----------|-------------|
|
||||||
| `DeviceId` | string | Unique identifier for the machine in the service |
|
| `DeviceId` | string | Unique identifier for the machine in the service |
|
||||||
| `DeviceName` | string | Fully qualified domain name (FQDN) of the machine |
|
| `DeviceName` | string | Fully qualified domain name (FQDN) of the machine |
|
||||||
| `OSPlatform` | string | Platform of the operating system running on the machine. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7.|
|
| `OSPlatform` | string | Platform of the operating system running on the machine. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7.|
|
||||||
| `Timestamp` | datetime |Date and time when the record was generated |
|
| `Timestamp` | datetime |Date and time when the record was generated |
|
||||||
| `ConfigurationId` | string | Unique identifier for a specific configuration |
|
| `ConfigurationId` | string | Unique identifier for a specific configuration |
|
||||||
| `ConfigurationCategory` | string | Category or grouping to which the configuration belongs: Application, OS, Network, Accounts, Security controls |
|
| `ConfigurationCategory` | string | Category or grouping to which the configuration belongs: Application, OS, Network, Accounts, Security controls |
|
||||||
| `ConfigurationSubcategory` | string |Subcategory or subgrouping to which the configuration belongs. In many cases, this describes specific capabilities or features. |
|
| `ConfigurationSubcategory` | string |Subcategory or subgrouping to which the configuration belongs. In many cases, this describes specific capabilities or features. |
|
||||||
| `ConfigurationImpact` | string | Rated impact of the configuration to the overall configuration score (1-10) |
|
| `ConfigurationImpact` | string | Rated impact of the configuration to the overall configuration score (1-10) |
|
||||||
| `IsCompliant` | boolean | Indicates whether the configuration or policy is properly configured |
|
| `IsCompliant` | boolean | Indicates whether the configuration or policy is properly configured |
|
||||||
|
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
- [Advanced hunting overview](advanced-hunting-overview.md)
|
- [Advanced hunting overview](advanced-hunting-overview.md)
|
||||||
- [Learn the query language](advanced-hunting-query-language.md)
|
- [Learn the query language](advanced-hunting-query-language.md)
|
||||||
- [Understand the schema](advanced-hunting-schema-reference.md)
|
- [Understand the schema](advanced-hunting-schema-reference.md)
|
||||||
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
@ -1,53 +1,53 @@
|
|||||||
---
|
---
|
||||||
title: DeviceTvmSecureConfigurationAssessmentKB table in the advanced hunting schema
|
title: DeviceTvmSecureConfigurationAssessmentKB table in the advanced hunting schema
|
||||||
description: Learn about the various secure configurations assessed by Threat & Vulnerability Management in the DeviceTvmSecureConfigurationAssessmentKB table of the Advanced hunting schema.
|
description: Learn about the various secure configurations assessed by Threat & Vulnerability Management in the DeviceTvmSecureConfigurationAssessmentKB table of the Advanced hunting schema.
|
||||||
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, security configuration, MITRE ATT&CK framework, knowledge base, KB, DeviceTvmSecureConfigurationAssessmentKB
|
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, security configuration, MITRE ATT&CK framework, knowledge base, KB, DeviceTvmSecureConfigurationAssessmentKB
|
||||||
search.product: eADQiWindows 10XVcnh
|
search.product: eADQiWindows 10XVcnh
|
||||||
search.appverid: met150
|
search.appverid: met150
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.author: dolmont
|
ms.author: dolmont
|
||||||
author: DulceMontemayor
|
author: DulceMontemayor
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 11/12/2019
|
ms.date: 11/12/2019
|
||||||
---
|
---
|
||||||
|
|
||||||
# DeviceTvmSecureConfigurationAssessmentKB
|
# DeviceTvmSecureConfigurationAssessmentKB
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
||||||
|
|
||||||
[!include[Prerelease information](../../includes/prerelease.md)]
|
[!include[Prerelease information](../../includes/prerelease.md)]
|
||||||
|
|
||||||
The `DeviceTvmSecureConfigurationAssessmentKB` table in the advanced hunting schema contains information about the various secure configurations — such as whether a device has automatic updates on — checked by [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md). It also includes risk information, related industry benchmarks, and applicable MITRE ATT&CK techniques and tactics. Use this reference to construct queries that return information from the table.
|
The `DeviceTvmSecureConfigurationAssessmentKB` table in the advanced hunting schema contains information about the various secure configurations — such as whether a device has automatic updates on — checked by [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md). It also includes risk information, related industry benchmarks, and applicable MITRE ATT&CK techniques and tactics. Use this reference to construct queries that return information from the table.
|
||||||
|
|
||||||
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
||||||
|
|
||||||
| Column name | Data type | Description |
|
| Column name | Data type | Description |
|
||||||
|-------------|-----------|-------------|
|
|-------------|-----------|-------------|
|
||||||
| `ConfigurationId` | string | Unique identifier for a specific configuration |
|
| `ConfigurationId` | string | Unique identifier for a specific configuration |
|
||||||
| `ConfigurationImpact` | string | Rated impact of the configuration to the overall configuration score (1-10) |
|
| `ConfigurationImpact` | string | Rated impact of the configuration to the overall configuration score (1-10) |
|
||||||
| `ConfigurationName` | string | Display name of the configuration |
|
| `ConfigurationName` | string | Display name of the configuration |
|
||||||
| `ConfigurationDescription` | string | Description of the configuration |
|
| `ConfigurationDescription` | string | Description of the configuration |
|
||||||
| `RiskDescription` | string | Description of the associated risk |
|
| `RiskDescription` | string | Description of the associated risk |
|
||||||
| `ConfigurationCategory` | string | Category or grouping to which the configuration belongs: Application, OS, Network, Accounts, Security controls|
|
| `ConfigurationCategory` | string | Category or grouping to which the configuration belongs: Application, OS, Network, Accounts, Security controls|
|
||||||
| `ConfigurationSubcategory` | string |Subcategory or subgrouping to which the configuration belongs. In many cases, this describes specific capabilities or features. |
|
| `ConfigurationSubcategory` | string |Subcategory or subgrouping to which the configuration belongs. In many cases, this describes specific capabilities or features. |
|
||||||
| `ConfigurationBenchmarks` | string | List of industry benchmarks recommending the same or similar configuration |
|
| `ConfigurationBenchmarks` | string | List of industry benchmarks recommending the same or similar configuration |
|
||||||
| `RelatedMitreTechniques` | string | List of Mitre ATT&CK framework techniques related to the configuration |
|
| `RelatedMitreTechniques` | string | List of Mitre ATT&CK framework techniques related to the configuration |
|
||||||
| `RelatedMitreTactics ` | string | List of Mitre ATT&CK framework tactics related to the configuration |
|
| `RelatedMitreTactics ` | string | List of Mitre ATT&CK framework tactics related to the configuration |
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
- [Advanced hunting overview](advanced-hunting-overview.md)
|
- [Advanced hunting overview](advanced-hunting-overview.md)
|
||||||
- [Learn the query language](advanced-hunting-query-language.md)
|
- [Learn the query language](advanced-hunting-query-language.md)
|
||||||
- [Understand the schema](advanced-hunting-schema-reference.md)
|
- [Understand the schema](advanced-hunting-schema-reference.md)
|
||||||
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
@ -1,56 +1,56 @@
|
|||||||
---
|
---
|
||||||
title: DeviceTvmSoftwareInventoryVulnerabilities table in the advanced hunting schema
|
title: DeviceTvmSoftwareInventoryVulnerabilities table in the advanced hunting schema
|
||||||
description: Learn about the inventory of software in your devices and their vulnerabilities in the DeviceTvmSoftwareInventoryVulnerabilities table of the advanced hunting schema.
|
description: Learn about the inventory of software in your devices and their vulnerabilities in the DeviceTvmSoftwareInventoryVulnerabilities table of the advanced hunting schema.
|
||||||
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, software, inventory, vulnerabilities, CVE ID, OS DeviceTvmSoftwareInventoryVulnerabilities
|
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, software, inventory, vulnerabilities, CVE ID, OS DeviceTvmSoftwareInventoryVulnerabilities
|
||||||
search.product: eADQiWindows 10XVcnh
|
search.product: eADQiWindows 10XVcnh
|
||||||
search.appverid: met150
|
search.appverid: met150
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.author: dolmont
|
ms.author: dolmont
|
||||||
author: DulceMontemayor
|
author: DulceMontemayor
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 11/12/2019
|
ms.date: 11/12/2019
|
||||||
---
|
---
|
||||||
|
|
||||||
# DeviceTvmSoftwareInventoryVulnerabilities
|
# DeviceTvmSoftwareInventoryVulnerabilities
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
[!include[Prerelease information](../../includes/prerelease.md)]
|
[!include[Prerelease information](../../includes/prerelease.md)]
|
||||||
|
|
||||||
The `DeviceTvmSoftwareInventoryVulnerabilities` table in the advanced hunting schema contains the [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md) inventory of software on your devices as well as any known vulnerabilities in these software products. This table also includes operating system information, CVE IDs, and vulnerability severity information. Use this reference to construct queries that return information from the table.
|
The `DeviceTvmSoftwareInventoryVulnerabilities` table in the advanced hunting schema contains the [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md) inventory of software on your devices as well as any known vulnerabilities in these software products. This table also includes operating system information, CVE IDs, and vulnerability severity information. Use this reference to construct queries that return information from the table.
|
||||||
|
|
||||||
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
||||||
|
|
||||||
| Column name | Data type | Description |
|
| Column name | Data type | Description |
|
||||||
|-------------|-----------|-------------|
|
|-------------|-----------|-------------|
|
||||||
| `DeviceId` | string | Unique identifier for the machine in the service |
|
| `DeviceId` | string | Unique identifier for the machine in the service |
|
||||||
| `DeviceName` | string | Fully qualified domain name (FQDN) of the machine |
|
| `DeviceName` | string | Fully qualified domain name (FQDN) of the machine |
|
||||||
| `OSPlatform` | string | Platform of the operating system running on the machine. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7. |
|
| `OSPlatform` | string | Platform of the operating system running on the machine. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7. |
|
||||||
| `OSVersion` | string | Version of the operating system running on the machine |
|
| `OSVersion` | string | Version of the operating system running on the machine |
|
||||||
| `OSArchitecture` | string | Architecture of the operating system running on the machine |
|
| `OSArchitecture` | string | Architecture of the operating system running on the machine |
|
||||||
| `SoftwareVendor` | string | Name of the software vendor |
|
| `SoftwareVendor` | string | Name of the software vendor |
|
||||||
| `SoftwareName` | string | Name of the software product |
|
| `SoftwareName` | string | Name of the software product |
|
||||||
| `SoftwareVersion` | string | Version number of the software product |
|
| `SoftwareVersion` | string | Version number of the software product |
|
||||||
| `CveId` | string | Unique identifier assigned to the security vulnerability under the Common Vulnerabilities and Exposures (CVE) system |
|
| `CveId` | string | Unique identifier assigned to the security vulnerability under the Common Vulnerabilities and Exposures (CVE) system |
|
||||||
| `VulnerabilitySeverityLevel` | string | Severity level assigned to the security vulnerability based on the CVSS score and dynamic factors influenced by the threat landscape |
|
| `VulnerabilitySeverityLevel` | string | Severity level assigned to the security vulnerability based on the CVSS score and dynamic factors influenced by the threat landscape |
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
- [Advanced hunting overview](advanced-hunting-overview.md)
|
- [Advanced hunting overview](advanced-hunting-overview.md)
|
||||||
- [Learn the query language](advanced-hunting-query-language.md)
|
- [Learn the query language](advanced-hunting-query-language.md)
|
||||||
- [Understand the schema](advanced-hunting-schema-reference.md)
|
- [Understand the schema](advanced-hunting-schema-reference.md)
|
||||||
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
@ -1,51 +1,51 @@
|
|||||||
---
|
---
|
||||||
title: DeviceTvmSoftwareVulnerabilitiesKB table in the advanced hunting schema
|
title: DeviceTvmSoftwareVulnerabilitiesKB table in the advanced hunting schema
|
||||||
description: Learn about the software vulnerabilities tracked by Threat & Vulnerability Management in the DeviceTvmSoftwareVulnerabilitiesKB table of the advanced hunting schema.
|
description: Learn about the software vulnerabilities tracked by Threat & Vulnerability Management in the DeviceTvmSoftwareVulnerabilitiesKB table of the advanced hunting schema.
|
||||||
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, software, inventory, vulnerabilities, CVE ID, CVSS, DeviceTvmSoftwareVulnerabilitiesKB
|
keywords: advanced hunting, threat hunting, cyber threat hunting, mdatp, windows defender atp, wdatp search, query, telemetry, schema reference, kusto, table, column, data type, description, threat & vulnerability management, TVM, device management, software, inventory, vulnerabilities, CVE ID, CVSS, DeviceTvmSoftwareVulnerabilitiesKB
|
||||||
search.product: eADQiWindows 10XVcnh
|
search.product: eADQiWindows 10XVcnh
|
||||||
search.appverid: met150
|
search.appverid: met150
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.author: dolmont
|
ms.author: dolmont
|
||||||
author: DulceMontemayor
|
author: DulceMontemayor
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.date: 11/12/2019
|
ms.date: 11/12/2019
|
||||||
---
|
---
|
||||||
|
|
||||||
# DeviceTvmSoftwareVulnerabilitiesKB
|
# DeviceTvmSoftwareVulnerabilitiesKB
|
||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||||
|
|
||||||
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
||||||
|
|
||||||
[!include[Prerelease information](../../includes/prerelease.md)]
|
[!include[Prerelease information](../../includes/prerelease.md)]
|
||||||
|
|
||||||
The `DeviceTvmSoftwareVulnerabilitiesKB` table in the advanced hunting schema contains the list of vulnerabilities [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md) assesses devices for. Use this reference to construct queries that return information from the table.
|
The `DeviceTvmSoftwareVulnerabilitiesKB` table in the advanced hunting schema contains the list of vulnerabilities [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md) assesses devices for. Use this reference to construct queries that return information from the table.
|
||||||
|
|
||||||
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
For information on other tables in the advanced hunting schema, see [the advanced hunting reference](advanced-hunting-reference.md).
|
||||||
|
|
||||||
| Column name | Data type | Description |
|
| Column name | Data type | Description |
|
||||||
|-------------|-----------|-------------|
|
|-------------|-----------|-------------|
|
||||||
| `CveId` | string | Unique identifier assigned to the security vulnerability under the Common Vulnerabilities and Exposures (CVE) system |
|
| `CveId` | string | Unique identifier assigned to the security vulnerability under the Common Vulnerabilities and Exposures (CVE) system |
|
||||||
| `CvssScore` | string | Severity score assigned to the security vulnerability under th Common Vulnerability Scoring System (CVSS) |
|
| `CvssScore` | string | Severity score assigned to the security vulnerability under th Common Vulnerability Scoring System (CVSS) |
|
||||||
| `IsExploitAvailable` | boolean | Indicates whether exploit code for the vulnerability is publicly available |
|
| `IsExploitAvailable` | boolean | Indicates whether exploit code for the vulnerability is publicly available |
|
||||||
| `VulnerabilitySeverityLevel` | string | Severity level assigned to the security vulnerability based on the CVSS score and dynamic factors influenced by the threat landscape |
|
| `VulnerabilitySeverityLevel` | string | Severity level assigned to the security vulnerability based on the CVSS score and dynamic factors influenced by the threat landscape |
|
||||||
| `LastModifiedTime` | datetime | Date and time the item or related metadata was last modified |
|
| `LastModifiedTime` | datetime | Date and time the item or related metadata was last modified |
|
||||||
| `PublishedDate` | datetime | Date vulnerability was disclosed to public |
|
| `PublishedDate` | datetime | Date vulnerability was disclosed to public |
|
||||||
| `VulnerabilityDescription` | string | Description of vulnerability and associated risks |
|
| `VulnerabilityDescription` | string | Description of vulnerability and associated risks |
|
||||||
| `AffectedSoftware` | string | List of all software products affected by the vulnerability |
|
| `AffectedSoftware` | string | List of all software products affected by the vulnerability |
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
- [Advanced hunting overview](advanced-hunting-overview.md)
|
- [Advanced hunting overview](advanced-hunting-overview.md)
|
||||||
- [Learn the query language](advanced-hunting-query-language.md)
|
- [Learn the query language](advanced-hunting-query-language.md)
|
||||||
- [Understand the schema](advanced-hunting-schema-reference.md)
|
- [Understand the schema](advanced-hunting-schema-reference.md)
|
||||||
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
- [Overview of Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
|
@ -48,10 +48,10 @@ Table and column names are also listed within the Microsoft Defender Security Ce
|
|||||||
| **[DeviceImageLoadEvents](advanced-hunting-deviceimageloadevents-table.md)** | DLL loading events |
|
| **[DeviceImageLoadEvents](advanced-hunting-deviceimageloadevents-table.md)** | DLL loading events |
|
||||||
| **[DeviceEvents](advanced-hunting-deviceevents-table.md)** | Multiple event types, including events triggered by security controls such as Windows Defender Antivirus and exploit protection |
|
| **[DeviceEvents](advanced-hunting-deviceevents-table.md)** | Multiple event types, including events triggered by security controls such as Windows Defender Antivirus and exploit protection |
|
||||||
| **[DeviceFileCertificateInfo](advanced-hunting-devicefilecertificateinfo-table.md)** | Certificate information of signed files obtained from certificate verification events on endpoints |
|
| **[DeviceFileCertificateInfo](advanced-hunting-devicefilecertificateinfo-table.md)** | Certificate information of signed files obtained from certificate verification events on endpoints |
|
||||||
| **[DeviceTvmSoftwareInventoryVulnerabilities](advanced-hunting-tvm-softwareinventory-table.md)** | Inventory of software on devices as well as any known vulnerabilities in these software products |
|
| **[DeviceTvmSoftwareInventoryVulnerabilities](advanced-hunting-devicetvmsoftwareinventoryvulnerabilities-table.md)** | Inventory of software on devices as well as any known vulnerabilities in these software products |
|
||||||
| **[DeviceTvmSoftwareVulnerabilitiesKB ](advanced-hunting-tvm-softwarevulnerability-table.md)** | Knowledge base of publicly disclosed vulnerabilities, including whether exploit code is publicly available |
|
| **[DeviceTvmSoftwareVulnerabilitiesKB ](advanced-hunting-devicetvmsoftwarevulnerabilitieskb-table.md)** | Knowledge base of publicly disclosed vulnerabilities, including whether exploit code is publicly available |
|
||||||
| **[DeviceTvmSecureConfigurationAssessment](advanced-hunting-tvm-configassessment-table.md)** | Threat & Vulnerability Management assessment events, indicating the status of various security configurations on devices |
|
| **[DeviceTvmSecureConfigurationAssessment](advanced-hunting-devicetvmsecureconfigurationassessment-table.md)** | Threat & Vulnerability Management assessment events, indicating the status of various security configurations on devices |
|
||||||
| **[DeviceTvmSecureConfigurationAssessmentKB](advanced-hunting-tvm-secureconfigkb-table.md)** | Knowledge base of various security configurations used by Threat & Vulnerability Management to assess devices; includes mappings to various standards and benchmarks |
|
| **[DeviceTvmSecureConfigurationAssessmentKB](advanced-hunting-devicetvmsecureconfigurationassessmentkb-table.md)** | Knowledge base of various security configurations used by Threat & Vulnerability Management to assess devices; includes mappings to various standards and benchmarks |
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
- [Advanced hunting overview](advanced-hunting-overview.md)
|
- [Advanced hunting overview](advanced-hunting-overview.md)
|
||||||
|
@ -13,7 +13,7 @@ ms.author: macapara
|
|||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -35,7 +35,7 @@ ms.topic: article
|
|||||||
Microsoft Defender ATP extends support to also include the Windows Server operating system. This support provides advanced attack detection and investigation capabilities seamlessly through the Microsoft Defender Security Center console.
|
Microsoft Defender ATP extends support to also include the Windows Server operating system. This support provides advanced attack detection and investigation capabilities seamlessly through the Microsoft Defender Security Center console.
|
||||||
|
|
||||||
The service supports the onboarding of the following servers:
|
The service supports the onboarding of the following servers:
|
||||||
- Windows Server 2008 R2 SP1
|
- Windows Server 2008 R2 SP1
|
||||||
- Windows Server 2012 R2
|
- Windows Server 2012 R2
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
- Windows Server (SAC) version 1803 and later
|
- Windows Server (SAC) version 1803 and later
|
||||||
@ -57,11 +57,11 @@ There are two options to onboard Windows Server 2008 R2 SP1, Windows Server 2012
|
|||||||
|
|
||||||
|
|
||||||
### Option 1: Onboard servers through Microsoft Defender Security Center
|
### Option 1: Onboard servers through Microsoft Defender Security Center
|
||||||
You'll need to take the following steps if you choose to onboard servers through Microsoft Defender Security Center.
|
You'll need to take the following steps if you choose to onboard servers through Microsoft Defender Security Center.
|
||||||
|
|
||||||
- For Windows Server 2008 R2 SP1 or Windows Server 2012 R2, ensure that you install the following hotfix:
|
- For Windows Server 2008 R2 SP1 or Windows Server 2012 R2, ensure that you install the following hotfix:
|
||||||
- [Update for customer experience and diagnostic telemetry](https://support.microsoft.com/en-us/help/3080149/update-for-customer-experience-and-diagnostic-telemetry)
|
- [Update for customer experience and diagnostic telemetry](https://support.microsoft.com/en-us/help/3080149/update-for-customer-experience-and-diagnostic-telemetry)
|
||||||
|
|
||||||
- In addition, for Windows Server 2008 R2 SP1, ensure that you fulfill the following requirements:
|
- In addition, for Windows Server 2008 R2 SP1, ensure that you fulfill the following requirements:
|
||||||
- Install the [February monthly update rollup](https://support.microsoft.com/en-us/help/4074598/windows-7-update-kb4074598)
|
- Install the [February monthly update rollup](https://support.microsoft.com/en-us/help/4074598/windows-7-update-kb4074598)
|
||||||
- Install either [.NET framework 4.5](https://www.microsoft.com/download/details.aspx?id=30653) (or later) or [KB3154518](https://support.microsoft.com/help/3154518/support-for-tls-system-default-versions-included-in-the-net-framework)
|
- Install either [.NET framework 4.5](https://www.microsoft.com/download/details.aspx?id=30653) (or later) or [KB3154518](https://support.microsoft.com/help/3154518/support-for-tls-system-default-versions-included-in-the-net-framework)
|
||||||
@ -73,7 +73,7 @@ You'll need to take the following steps if you choose to onboard servers through
|
|||||||
|
|
||||||
- Turn on server monitoring from Microsoft Defender Security Center.
|
- Turn on server monitoring from Microsoft Defender Security Center.
|
||||||
|
|
||||||
- If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), attach the Microsoft Monitoring Agent (MMA) to report to your Microsoft Defender ATP workspace through Multihoming support.
|
- If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), attach the Microsoft Monitoring Agent (MMA) to report to your Microsoft Defender ATP workspace through Multihoming support.
|
||||||
|
|
||||||
Otherwise, install and configure MMA to report sensor data to Microsoft Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent).
|
Otherwise, install and configure MMA to report sensor data to Microsoft Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent).
|
||||||
|
|
||||||
@ -82,10 +82,10 @@ You'll need to take the following steps if you choose to onboard servers through
|
|||||||
|
|
||||||
### Configure and update System Center Endpoint Protection clients
|
### Configure and update System Center Endpoint Protection clients
|
||||||
|
|
||||||
Microsoft Defender ATP integrates with System Center Endpoint Protection. The integration provides visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware.
|
Microsoft Defender ATP integrates with System Center Endpoint Protection. The integration provides visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware.
|
||||||
|
|
||||||
The following steps are required to enable this integration:
|
The following steps are required to enable this integration:
|
||||||
- Install the [January 2017 anti-malware platform update for Endpoint Protection clients](https://support.microsoft.com/help/3209361/january-2017-anti-malware-platform-update-for-endpoint-protection-clie)
|
- Install the [January 2017 anti-malware platform update for Endpoint Protection clients](https://support.microsoft.com/help/3209361/january-2017-anti-malware-platform-update-for-endpoint-protection-clie)
|
||||||
|
|
||||||
- Configure the SCEP client Cloud Protection Service membership to the **Advanced** setting
|
- Configure the SCEP client Cloud Protection Service membership to the **Advanced** setting
|
||||||
|
|
||||||
@ -95,19 +95,19 @@ The following steps are required to enable this integration:
|
|||||||
1. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
|
1. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**.
|
||||||
|
|
||||||
2. Select Windows Server 2012 R2 and 2016 as the operating system.
|
2. Select Windows Server 2012 R2 and 2016 as the operating system.
|
||||||
|
|
||||||
3. Click **Turn on server monitoring** and confirm that you'd like to proceed with the environment setup. When the setup completes, the **Workspace ID** and **Workspace key** fields are populated with unique values. You'll need to use these values to configure the MMA agent.
|
3. Click **Turn on server monitoring** and confirm that you'd like to proceed with the environment setup. When the setup completes, the **Workspace ID** and **Workspace key** fields are populated with unique values. You'll need to use these values to configure the MMA agent.
|
||||||
|
|
||||||
<span id="server-mma"/>
|
<span id="server-mma"/>
|
||||||
|
|
||||||
### Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP
|
### Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP
|
||||||
|
|
||||||
1. Download the agent setup file: [Windows 64-bit agent](https://go.microsoft.com/fwlink/?LinkId=828603).
|
1. Download the agent setup file: [Windows 64-bit agent](https://go.microsoft.com/fwlink/?LinkId=828603).
|
||||||
|
|
||||||
2. Using the Workspace ID and Workspace key provided in the previous procedure, choose any of the following installation methods to install the agent on the server:
|
2. Using the Workspace ID and Workspace key provided in the previous procedure, choose any of the following installation methods to install the agent on the server:
|
||||||
- [Manually install the agent using setup](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#install-the-agent-using-setup) <br>
|
- [Manually install the agent using setup](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#install-the-agent-using-setup) <br>
|
||||||
On the **Agent Setup Options** page, choose **Connect the agent to Azure Log Analytics (OMS)**.
|
On the **Agent Setup Options** page, choose **Connect the agent to Azure Log Analytics (OMS)**.
|
||||||
- [Install the agent using the command line](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#install-the-agent-using-the-command-line) and [configure the agent using a script](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#add-a-workspace-using-a-script).
|
- [Install the agent using the command line](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#install-the-agent-using-the-command-line) and [configure the agent using a script](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#add-a-workspace-using-a-script).
|
||||||
|
|
||||||
3. You'll need to configure proxy settings for the Microsoft Monitoring Agent. For more information, see [Configure proxy settings](configure-proxy-internet.md).
|
3. You'll need to configure proxy settings for the Microsoft Monitoring Agent. For more information, see [Configure proxy settings](configure-proxy-internet.md).
|
||||||
|
|
||||||
@ -116,7 +116,7 @@ Once completed, you should see onboarded servers in the portal within an hour.
|
|||||||
<span id="server-proxy"/>
|
<span id="server-proxy"/>
|
||||||
|
|
||||||
### Configure server proxy and Internet connectivity settings
|
### Configure server proxy and Internet connectivity settings
|
||||||
|
|
||||||
- Each Windows server must be able to connect to the Internet using HTTPS. This connection can be direct, using a proxy, or through the <a href="https://docs.microsoft.com/azure/log-analytics/log-analytics-oms-gateway" data-raw-source="[OMS Gateway](https://docs.microsoft.com/azure/log-analytics/log-analytics-oms-gateway)">OMS Gateway</a>.
|
- Each Windows server must be able to connect to the Internet using HTTPS. This connection can be direct, using a proxy, or through the <a href="https://docs.microsoft.com/azure/log-analytics/log-analytics-oms-gateway" data-raw-source="[OMS Gateway](https://docs.microsoft.com/azure/log-analytics/log-analytics-oms-gateway)">OMS Gateway</a>.
|
||||||
- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that you [enable access to Microsoft Defender ATP service URLs](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
|
- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that you [enable access to Microsoft Defender ATP service URLs](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
|
||||||
|
|
||||||
@ -127,7 +127,7 @@ Once completed, you should see onboarded servers in the portal within an hour.
|
|||||||
|
|
||||||
2. Select Windows Server 2008 R2 SP1, 2012 R2 and 2016 as the operating system.
|
2. Select Windows Server 2008 R2 SP1, 2012 R2 and 2016 as the operating system.
|
||||||
|
|
||||||
3. Click **Onboard Servers in Azure Security Center**.
|
3. Click **Onboard Servers in Azure Security Center**.
|
||||||
|
|
||||||
4. Follow the onboarding instructions in [Microsoft Defender Advanced Threat Protection with Azure Security Center](https://docs.microsoft.com/azure/security-center/security-center-wdatp).
|
4. Follow the onboarding instructions in [Microsoft Defender Advanced Threat Protection with Azure Security Center](https://docs.microsoft.com/azure/security-center/security-center-wdatp).
|
||||||
|
|
||||||
@ -140,16 +140,16 @@ To onboard Windows Server (SAC) version 1803, Windows Server 2019, or Windows Se
|
|||||||
|
|
||||||
Supported tools include:
|
Supported tools include:
|
||||||
- Local script
|
- Local script
|
||||||
- Group Policy
|
- Group Policy
|
||||||
- Microsoft Endpoint Configuration Manager
|
- Microsoft Endpoint Configuration Manager
|
||||||
- System Center Configuration Manager 2012 / 2012 R2 1511 / 1602
|
- System Center Configuration Manager 2012 / 2012 R2 1511 / 1602
|
||||||
- VDI onboarding scripts for non-persistent machines
|
- VDI onboarding scripts for non-persistent machines
|
||||||
|
|
||||||
For more information, see [Onboard Windows 10 machines](configure-endpoints.md).
|
For more information, see [Onboard Windows 10 machines](configure-endpoints.md).
|
||||||
|
|
||||||
Support for Windows Server, provide deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well.
|
Support for Windows Server, provide deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well.
|
||||||
|
|
||||||
1. Configure Microsoft Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints.md).
|
1. Configure Microsoft Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints.md).
|
||||||
|
|
||||||
2. If you're running a third-party antimalware solution, you'll need to apply the following Windows Defender AV passive mode settings. Verify that it was configured correctly:
|
2. If you're running a third-party antimalware solution, you'll need to apply the following Windows Defender AV passive mode settings. Verify that it was configured correctly:
|
||||||
|
|
||||||
@ -165,12 +165,12 @@ Support for Windows Server, provide deeper insight into activities happening on
|
|||||||
```
|
```
|
||||||
|
|
||||||
1. Confirm that a recent event containing the passive mode event is found:
|
1. Confirm that a recent event containing the passive mode event is found:
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
3. Run the following command to check if Windows Defender AV is installed:
|
3. Run the following command to check if Windows Defender AV is installed:
|
||||||
|
|
||||||
```sc query Windefend```
|
```sc.exe query Windefend```
|
||||||
|
|
||||||
If the result is 'The specified service does not exist as an installed service', then you'll need to install Windows Defender AV. For more information, see [Windows Defender Antivirus in Windows 10](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
|
If the result is 'The specified service does not exist as an installed service', then you'll need to install Windows Defender AV. For more information, see [Windows Defender Antivirus in Windows 10](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
|
||||||
|
|
||||||
@ -188,12 +188,12 @@ The following capabilities are included in this integration:
|
|||||||
- Server investigation - Azure Security Center customers can access Microsoft Defender Security Center to perform detailed investigation to uncover the scope of a potential breach
|
- Server investigation - Azure Security Center customers can access Microsoft Defender Security Center to perform detailed investigation to uncover the scope of a potential breach
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> - When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created. The Microsoft Defender ATP data is stored in Europe by default.
|
> - When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created. The Microsoft Defender ATP data is stored in Europe by default.
|
||||||
> - If you use Microsoft Defender ATP before using Azure Security Center, your data will be stored in the location you specified when you created your tenant even if you integrate with Azure Security Center at a later time.
|
> - If you use Microsoft Defender ATP before using Azure Security Center, your data will be stored in the location you specified when you created your tenant even if you integrate with Azure Security Center at a later time.
|
||||||
|
> - When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created and the Microsoft Defender ATP data is stored in Europe by default. If you need to move your data to another location, you need to contact Microsoft Support to reset the tenant. Server endpoint monitoring utilizing this integration has been disabled for Office 365 GCC customers.
|
||||||
|
|
||||||
|
|
||||||
|
## Offboard servers
|
||||||
## Offboard servers
|
|
||||||
You can offboard Windows Server (SAC), Windows Server 2019, and Windows Server 2019 Core edition in the same method available for Windows 10 client machines.
|
You can offboard Windows Server (SAC), Windows Server 2019, and Windows Server 2019 Core edition in the same method available for Windows 10 client machines.
|
||||||
|
|
||||||
For other server versions, you have two options to offboard servers from the service:
|
For other server versions, you have two options to offboard servers from the service:
|
||||||
@ -210,10 +210,10 @@ For more information, see [To disable an agent](https://docs.microsoft.com/azure
|
|||||||
### Remove the Microsoft Defender ATP workspace configuration
|
### Remove the Microsoft Defender ATP workspace configuration
|
||||||
To offboard the server, you can use either of the following methods:
|
To offboard the server, you can use either of the following methods:
|
||||||
|
|
||||||
- Remove the Microsoft Defender ATP workspace configuration from the MMA agent
|
- Remove the Microsoft Defender ATP workspace configuration from the MMA agent
|
||||||
- Run a PowerShell command to remove the configuration
|
- Run a PowerShell command to remove the configuration
|
||||||
|
|
||||||
#### Remove the Microsoft Defender ATP workspace configuration from the MMA agent
|
#### Remove the Microsoft Defender ATP workspace configuration from the MMA agent
|
||||||
|
|
||||||
1. In the **Microsoft Monitoring Agent Properties**, select the **Azure Log Analytics (OMS)** tab.
|
1. In the **Microsoft Monitoring Agent Properties**, select the **Azure Log Analytics (OMS)** tab.
|
||||||
|
|
||||||
@ -228,7 +228,7 @@ To offboard the server, you can use either of the following methods:
|
|||||||
1. In the navigation pane, select **Settings** > **Onboarding**.
|
1. In the navigation pane, select **Settings** > **Onboarding**.
|
||||||
|
|
||||||
1. Select **Windows Server 2012 R2 and 2016** as the operating system and get your Workspace ID:
|
1. Select **Windows Server 2012 R2 and 2016** as the operating system and get your Workspace ID:
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
2. Open an elevated PowerShell and run the following command. Use the Workspace ID you obtained and replacing `WorkspaceID`:
|
2. Open an elevated PowerShell and run the following command. Use the Workspace ID you obtained and replacing `WorkspaceID`:
|
||||||
|
@ -23,36 +23,45 @@ ms.topic: article
|
|||||||
|
|
||||||
Conducting a comprehensive security product evaluation can be a complex process requiring cumbersome environment and machine configuration before an end-to-end attack simulation can actually be done. Adding to the complexity is the challenge of tracking where the simulation activities, alerts, and results are reflected during the evaluation.
|
Conducting a comprehensive security product evaluation can be a complex process requiring cumbersome environment and machine configuration before an end-to-end attack simulation can actually be done. Adding to the complexity is the challenge of tracking where the simulation activities, alerts, and results are reflected during the evaluation.
|
||||||
|
|
||||||
The Microsoft Defender ATP evaluation lab is designed to eliminate the complexities of machine and environment configuration so that you can focus on evaluating the capabilities of the platform, running simulations, and seeing the prevention, detection, and remediation features in action.
|
The Microsoft Defender ATP evaluation lab is designed to eliminate the complexities of machine and environment configuration so that you can focus on evaluating the capabilities of the platform, running simulations, and seeing the prevention, detection, and remediation features in action.
|
||||||
|
|
||||||
When you get started with the lab, you'll be guided through a simple set-up process where you can specify the type of configuration that best suits your needs.
|
|
||||||
|
|
||||||
After the lab setup process is complete, you can add Windows 10 or Windows Server 2019 machines. These test machines come pre-configured to have the latest and greatest OS versions with the right security components in place and Office 2019 Standard installed.
|
|
||||||
|
|
||||||
With the simplified set-up experience, you can focus on running your own test scenarios and the pre-made simulations to see how Microsoft Defender ATP performs.
|
With the simplified set-up experience, you can focus on running your own test scenarios and the pre-made simulations to see how Microsoft Defender ATP performs.
|
||||||
|
|
||||||
You'll have full access to all the powerful capabilities of the platform such as automated investigations, advanced hunting, and threat analytics, allowing you to test the comprehensive protection stack that Microsoft Defender ATP offers.
|
You'll have full access to the powerful capabilities of the platform such as automated investigations, advanced hunting, and threat analytics, allowing you to test the comprehensive protection stack that Microsoft Defender ATP offers.
|
||||||
|
|
||||||
|
You can add Windows 10 or Windows Server 2019 machines that come pre-configured to have the latest OS versions and the right security components in place as well as Office 2019 Standard installed.
|
||||||
|
|
||||||
|
You can also install threat simulators. Microsoft Defender ATP has partnered with industry leading threat simulation platforms to help you test out the Microsoft Defender ATP capabilities without having to leave the portal.
|
||||||
|
|
||||||
|
Install your preferred simulator, run scenarios within the evaluation lab, and instantly see how the platform performs - all conveniently available at no extra cost to you. You'll also have convenient access to wide array of simulations which you can access and run from the simulations catalog.
|
||||||
|
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
You'll need to fulfill the [licensing requirements](minimum-requirements.md#licensing-requirements) or have trial access to Microsoft Defender ATP to access the evaluation lab.
|
You'll need to fulfill the [licensing requirements](minimum-requirements.md#licensing-requirements) or have trial access to Microsoft Defender ATP to access the evaluation lab.
|
||||||
|
|
||||||
|
You must have **Manage security settings** permissions to:
|
||||||
|
- Create the lab
|
||||||
|
- Create machines
|
||||||
|
- Reset password
|
||||||
|
- Create simulations
|
||||||
|
|
||||||
|
For more information, see [Create and manage roles](user-roles.md).
|
||||||
|
|
||||||
Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-main-abovefoldlink)
|
Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-main-abovefoldlink)
|
||||||
|
|
||||||
|
|
||||||
## Get started with the lab
|
## Get started with the lab
|
||||||
You can access the lab from the menu. In the navigation menu, select **Evaluation and tutorials > Evaluation lab**.
|
You can access the lab from the menu. In the navigation menu, select **Evaluation and tutorials > Evaluation lab**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
When you access the evaluation lab for the first time, you'll find an introduction page with a link to the evaluation guide. The guide contains tips and recommendations to keep in mind when evaluating an advanced threat protection product.
|
|
||||||
|
|
||||||
It's a good idea to read the guide before starting the evaluation process so that you can conduct a thorough assessment of the platform.
|
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>- Each environment is provisioned with a limited set of test machines.
|
>- Each environment is provisioned with a limited set of test machines.
|
||||||
>- Depending the type of environment structure you select, machines will be available for the specified number of hours from the day of activation.
|
>- Depending the type of environment structure you select, machines will be available for the specified number of hours from the day of activation.
|
||||||
>- When you've used up the provisioned machines, no new machines are provided. A deleted machine does not refresh the available test machine count.
|
>- When you've used up the provisioned machines, no new machines are provided. A deleted machine does not refresh the available test machine count.
|
||||||
>- Given the limited resources, it’s advisable to use the machines carefully.
|
>- Given the limited resources, it’s advisable to use the machines carefully.
|
||||||
|
|
||||||
|
Already have a lab? Make sure to enable the new threat simulators and have active machines.
|
||||||
|
|
||||||
## Setup the evaluation lab
|
## Setup the evaluation lab
|
||||||
|
|
||||||
@ -60,17 +69,37 @@ It's a good idea to read the guide before starting the evaluation process so tha
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
2. Depending on your evaluation needs, you can choose to setup an environment with fewer machines for a longer period or more machines for a shorter period. Select your preferred lab configuration then select **Create lab**.
|
2. Depending on your evaluation needs, you can choose to setup an environment with fewer machines for a longer period or more machines for a shorter period. Select your preferred lab configuration then select **Next**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
|
3. (Optional) You can choose to install threat simulators in the lab.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
>[!IMPORTANT]
|
||||||
|
>You'll first need to accept and provide consent to the terms and information sharing statements.
|
||||||
|
|
||||||
|
4. Select the threat simulation agent you'd like to use and enter your details. You can also choose to install threat simulators at a later time. If you choose to install threat simulation agents during the lab setup, you'll enjoy the benefit of having them conveniently installed on the machines you add.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
5. Review the summary and select **Setup lab**.
|
||||||
|
|
||||||
|
After the lab setup process is complete, you can add machines and run simulations.
|
||||||
|
|
||||||
When the environment completes the setup process, you're ready to add machines.
|
|
||||||
|
|
||||||
## Add machines
|
## Add machines
|
||||||
When you add a machine to your environment, Microsoft Defender ATP sets up a well-configured machine with connection details. You can add Windows 10 or Windows Server 2019 machines.
|
When you add a machine to your environment, Microsoft Defender ATP sets up a well-configured machine with connection details. You can add Windows 10 or Windows Server 2019 machines.
|
||||||
|
|
||||||
The machine will be configured with the most up-to-date version of the OS and Office 2019 Standard as well as other apps such as Java, Python, and SysIntenals.
|
The machine will be configured with the most up-to-date version of the OS and Office 2019 Standard as well as other apps such as Java, Python, and SysIntenals.
|
||||||
|
|
||||||
|
>[!TIP]
|
||||||
|
> Need more machines in your lab? Submit a support ticket to have your request reviewed by the Microsoft Defender ATP team.
|
||||||
|
|
||||||
|
If you chose to add a threat simulator during the lab setup, all machines will have the threat simulator agent installed in the machines that you add.
|
||||||
|
|
||||||
The machine will automatically be onboarded to your tenant with the recommended Windows security components turned on and in audit mode - with no effort on your side.
|
The machine will automatically be onboarded to your tenant with the recommended Windows security components turned on and in audit mode - with no effort on your side.
|
||||||
|
|
||||||
The following security components are pre-configured in the test machines:
|
The following security components are pre-configured in the test machines:
|
||||||
@ -94,9 +123,6 @@ Automated investigation settings will be dependent on tenant settings. It will b
|
|||||||
|
|
||||||
1. From the dashboard, select **Add machine**.
|
1. From the dashboard, select **Add machine**.
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
|
||||||
2. Choose the type of machine to add. You can choose to add Windows 10 or Windows Server 2019.
|
2. Choose the type of machine to add. You can choose to add Windows 10 or Windows Server 2019.
|
||||||
|
|
||||||

|

|
||||||
@ -114,20 +140,31 @@ Automated investigation settings will be dependent on tenant settings. It will b
|
|||||||
|
|
||||||
4. Machine set up begins. This can take up to approximately 30 minutes.
|
4. Machine set up begins. This can take up to approximately 30 minutes.
|
||||||
|
|
||||||
The environment will reflect your test machine status through the evaluation - including risk score, exposure score, and alerts created through the simulation.
|
5. See the status of test machines, the risk and exposure levels, and the status of simulator installations by selecting the **Machines** tab.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
>[!TIP]
|
||||||
|
>In the **Simulator status** column, you can hover over the information icon to know the installation status of an agent.
|
||||||
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
## Simulate attack scenarios
|
## Simulate attack scenarios
|
||||||
Use the test machines to run attack simulations by connecting to them.
|
Use the test machines to run your own attack simulations by connecting to them.
|
||||||
|
|
||||||
If you are looking for a pre-made simulation, you can use our ["Do It Yourself" attack scenarios](https://securitycenter.windows.com/tutorials). These scripts are safe, documented, and easy to use. These scenarios will reflect Microsoft Defender ATP capabilities and walk you through investigation experience.
|
You can simulate attack scenarios using:
|
||||||
|
- The ["Do It Yourself" attack scenarios](https://securitycenter.windows.com/tutorials)
|
||||||
|
- Threat simulators
|
||||||
|
|
||||||
You can also use [Advanced hunting](advanced-hunting-query-language.md) to query data and [Threat analytics](threat-analytics.md) to view reports about emerging threats.
|
You can also use [Advanced hunting](advanced-hunting-query-language.md) to query data and [Threat analytics](threat-analytics.md) to view reports about emerging threats.
|
||||||
|
|
||||||
> [!NOTE]
|
### Do-it-yourself attack scenarios
|
||||||
> The connection to the test machines is done using RDP. Make sure that your firewall settings allow RDP connections.
|
If you are looking for a pre-made simulation, you can use our ["Do It Yourself" attack scenarios](https://securitycenter.windows.com/tutorials). These scripts are safe, documented, and easy to use. These scenarios will reflect Microsoft Defender ATP capabilities and walk you through investigation experience.
|
||||||
|
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>The connection to the test machines is done using RDP. Make sure that your firewall settings allow RDP connections.
|
||||||
|
|
||||||
1. Connect to your machine and run an attack simulation by selecting **Connect**.
|
1. Connect to your machine and run an attack simulation by selecting **Connect**.
|
||||||
|
|
||||||
@ -146,20 +183,70 @@ You can also use [Advanced hunting](advanced-hunting-query-language.md) to query
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
4. Run simulations on the machine.
|
4. Run Do-it-yourself attack simulations on the machine.
|
||||||
|
|
||||||
|
|
||||||
|
### Threat simulator scenarios
|
||||||
|
If you chose to install any of the supported threat simulators during the lab setup, you can run the built-in simulations on the evaluation lab machines.
|
||||||
|
|
||||||
|
|
||||||
|
Running threat simulations using third-party platforms is a good way to evaluate Microsoft Defender ATP capabilities within the confines of a lab environment.
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>Before you can run simulations, ensure the following requirements are met:
|
||||||
|
>- Machines must be added to the evaluation lab
|
||||||
|
>- Threat simulators must be installed in the evaluation lab
|
||||||
|
|
||||||
|
1. From the portal select **Create simulation**.
|
||||||
|
|
||||||
|
2. Select a threat simulator.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
3. Choose a simulation or look through the simulation gallery to browse through the available simulations.
|
||||||
|
|
||||||
|
You can get to the simulation gallery from:
|
||||||
|
- The main evaluation dashboard in the **Simulations overview** tile or
|
||||||
|
- By navigating from the navigation pane **Evaluation and tutorials** > **Simulation & tutorials**, then select **Simulations catalog**.
|
||||||
|
|
||||||
|
4. Select the devices where you'd like to run the simulation on.
|
||||||
|
|
||||||
|
5. Select **Create simulation**.
|
||||||
|
|
||||||
|
6. View the progress of a simulation by selecting the **Simulations** tab. View the simulation state, active alerts, and other details.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
After running your simulations, we encourage you to walk through the lab progress bar and explore Microsoft Defender ATP features. See if the attack simulations you ran triggered an automated investigation and remediation, check out the evidence collected and analyzed by the feature.
|
||||||
|
|
||||||
After running your simulations, we encourage you to walk through the lab progress bar and explore Microsoft Defender ATP features. See if your attacks triggered an automated investigation and remediation, check out the evidence collected and analyzed by the feature.
|
|
||||||
|
|
||||||
|
|
||||||
Hunt for attack evidence through advanced hunting by using the rich query language and raw telemetry and check out some world-wide threats documented in Threat analytics.
|
Hunt for attack evidence through advanced hunting by using the rich query language and raw telemetry and check out some world-wide threats documented in Threat analytics.
|
||||||
|
|
||||||
|
|
||||||
## Simulation results
|
## Simulation gallery
|
||||||
Get a full overview of the simulation results, all in one place, allowing you to drill down to the relevant pages with every detail you need.
|
Microsoft Defender ATP has partnered with various threat simulation platforms to give you convenient access to test the capabilities of the platform right from the within the portal.
|
||||||
|
|
||||||
View the machine details page by selecting the machine from the table. You'll be able to drill down on relevant alerts and investigations by exploring the rich context provided on the attack simulation.
|
View all the available simulations by going to **Simulations and tutorials** > **Simulations catalog** from the menu.
|
||||||
|
|
||||||
### Evaluation report
|
|
||||||
|
A list of supported third-party threat simulation agents are listed, and specific types of simulations along with detailed descriptions are provided on the catalog.
|
||||||
|
|
||||||
|
You can conveniently run any available simulation right from the catalog.
|
||||||
|
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Each simulation comes with an in-depth description of the attack scenario and references such as the MITRE attack techniques used and sample Advanced hunting queries you run.
|
||||||
|
|
||||||
|
**Examples:**
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
|
## Evaluation report
|
||||||
The lab reports summarize the results of the simulations conducted on the machines.
|
The lab reports summarize the results of the simulations conducted on the machines.
|
||||||
|
|
||||||

|

|
||||||
@ -172,6 +259,7 @@ At a glance, you'll quickly be able to see:
|
|||||||
- Detection sources
|
- Detection sources
|
||||||
- Automated investigations
|
- Automated investigations
|
||||||
|
|
||||||
|
|
||||||
## Provide feedback
|
## Provide feedback
|
||||||
Your feedback helps us get better in protecting your environment from advanced attacks. Share your experience and impressions from product capabilities and evaluation results.
|
Your feedback helps us get better in protecting your environment from advanced attacks. Share your experience and impressions from product capabilities and evaluation results.
|
||||||
|
|
||||||
|
Before Width: | Height: | Size: 138 KiB After Width: | Height: | Size: 100 KiB |
After Width: | Height: | Size: 173 KiB |
Before Width: | Height: | Size: 44 KiB After Width: | Height: | Size: 135 KiB |
After Width: | Height: | Size: 70 KiB |
After Width: | Height: | Size: 291 KiB |
After Width: | Height: | Size: 55 KiB |
Before Width: | Height: | Size: 47 KiB After Width: | Height: | Size: 113 KiB |
After Width: | Height: | Size: 204 KiB |
After Width: | Height: | Size: 169 KiB |
After Width: | Height: | Size: 105 KiB |
After Width: | Height: | Size: 279 KiB |
@ -276,6 +276,10 @@ Download the onboarding package from Microsoft Defender Security Center:
|
|||||||
|
|
||||||
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
||||||
|
|
||||||
|
## Operating system upgrades
|
||||||
|
|
||||||
|
When upgrading your operating system to a new major version, you must first uninstall Microsoft Defender ATP for Linux, install the upgrade, and finally reconfigure Microsoft Defender ATP for Linux on your device.
|
||||||
|
|
||||||
## Uninstallation
|
## Uninstallation
|
||||||
|
|
||||||
See [Uninstall](linux-resources.md#uninstall) for details on how to remove Microsoft Defender ATP for Linux from client devices.
|
See [Uninstall](linux-resources.md#uninstall) for details on how to remove Microsoft Defender ATP for Linux from client devices.
|
@ -255,6 +255,10 @@ Now run the tasks files under `/etc/ansible/playbooks/`.
|
|||||||
|
|
||||||
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
||||||
|
|
||||||
|
## Operating system upgrades
|
||||||
|
|
||||||
|
When upgrading your operating system to a new major version, you must first uninstall Microsoft Defender ATP for Linux, install the upgrade, and finally reconfigure Microsoft Defender ATP for Linux on your device.
|
||||||
|
|
||||||
## References
|
## References
|
||||||
|
|
||||||
- [Add or remove YUM repositories](https://docs.ansible.com/ansible/2.3/yum_repository_module.html)
|
- [Add or remove YUM repositories](https://docs.ansible.com/ansible/2.3/yum_repository_module.html)
|
||||||
|
@ -207,6 +207,10 @@ If the product is not healthy, the exit code (which can be checked through `echo
|
|||||||
|
|
||||||
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
See [Log installation issues](linux-resources.md#log-installation-issues) for more information on how to find the automatically generated log that is created by the installer when an error occurs.
|
||||||
|
|
||||||
|
## Operating system upgrades
|
||||||
|
|
||||||
|
When upgrading your operating system to a new major version, you must first uninstall Microsoft Defender ATP for Linux, install the upgrade, and finally reconfigure Microsoft Defender ATP for Linux on your device.
|
||||||
|
|
||||||
## Uninstallation
|
## Uninstallation
|
||||||
|
|
||||||
Create a module *remove_mdatp* similar to *install_mdatp* with the following contents in *init.pp* file:
|
Create a module *remove_mdatp* similar to *install_mdatp* with the following contents in *init.pp* file:
|
||||||
|
@ -0,0 +1,300 @@
|
|||||||
|
---
|
||||||
|
title: Privacy for Microsoft Defender ATP for Linux
|
||||||
|
description: Privacy controls, how to configure policy settings that impact privacy and information about the diagnostic data collected in Microsoft Defender ATP for Linux.
|
||||||
|
keywords: microsoft, defender, atp, linux, privacy, diagnostic
|
||||||
|
search.product: eADQiWindows 10XVcnh
|
||||||
|
search.appverid: met150
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: deploy
|
||||||
|
ms.sitesec: library
|
||||||
|
ms.pagetype: security
|
||||||
|
ms.author: dansimp
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
manager: dansimp
|
||||||
|
audience: ITPro
|
||||||
|
ms.collection: M365-security-compliance
|
||||||
|
ms.topic: conceptual
|
||||||
|
---
|
||||||
|
|
||||||
|
# Privacy for Microsoft Defender ATP for Linux
|
||||||
|
|
||||||
|
**Applies to:**
|
||||||
|
|
||||||
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Linux](microsoft-defender-atp-linux.md)
|
||||||
|
|
||||||
|
Microsoft is committed to providing you with the information and controls you need to make choices about how your data is collected and used when you’re using Microsoft Defender ATP for Linux.
|
||||||
|
|
||||||
|
This topic describes the privacy controls available within the product, how to manage these controls with policy settings and more details on the data events that are collected.
|
||||||
|
|
||||||
|
## Overview of privacy controls in Microsoft Defender ATP for Linux
|
||||||
|
|
||||||
|
This section describes the privacy controls for the different types of data collected by Microsoft Defender ATP for Linux.
|
||||||
|
|
||||||
|
### Diagnostic data
|
||||||
|
|
||||||
|
Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, detect, diagnose and fix problems, and also make product improvements.
|
||||||
|
|
||||||
|
Some diagnostic data is required, while some diagnostic data is optional. We give you the ability to choose whether to send us required or optional diagnostic data through the use of privacy controls, such as policy settings for organizations.
|
||||||
|
|
||||||
|
There are two levels of diagnostic data for Microsoft Defender ATP client software that you can choose from:
|
||||||
|
|
||||||
|
* **Required**: The minimum data necessary to help keep Microsoft Defender ATP secure, up-to-date, and performing as expected on the device it’s installed on.
|
||||||
|
|
||||||
|
* **Optional**: Additional data that helps Microsoft make product improvements and provides enhanced information to help detect, diagnose, and remediate issues.
|
||||||
|
|
||||||
|
By default, only required diagnostic data is sent to Microsoft.
|
||||||
|
|
||||||
|
### Cloud delivered protection data
|
||||||
|
|
||||||
|
Cloud delivered protection is used to provide increased and faster protection with access to the latest protection data in the cloud.
|
||||||
|
|
||||||
|
Enabling the cloud-delivered protection service is optional, however it is highly recommended because it provides important protection against malware on your endpoints and across your network.
|
||||||
|
|
||||||
|
### Sample data
|
||||||
|
|
||||||
|
Sample data is used to improve the protection capabilities of the product, by sending Microsoft suspicious samples so they can be analyzed. Enabling automatic sample submission is optional.
|
||||||
|
|
||||||
|
There are three levels for controlling sample submission:
|
||||||
|
|
||||||
|
- **None**: no suspicious samples are submitted to Microsoft.
|
||||||
|
- **Safe**: only suspicious samples that do not contain personally identifiable information (PII) are submitted automatically. This is the default value for this setting.
|
||||||
|
- **All**: all suspicious samples are submitted to Microsoft.
|
||||||
|
|
||||||
|
## Manage privacy controls with policy settings
|
||||||
|
|
||||||
|
If you're an IT administrator, you might want to configure these controls at the enterprise level.
|
||||||
|
|
||||||
|
The privacy controls for the various types of data described in the preceding section are described in detail in [Set preferences for Microsoft Defender ATP for Linux](linux-preferences.md).
|
||||||
|
|
||||||
|
As with any new policy settings, you should carefully test them out in a limited, controlled environment to ensure the settings that you configure have the desired effect before you implement the policy settings more widely in your organization.
|
||||||
|
|
||||||
|
## Diagnostic data events
|
||||||
|
|
||||||
|
This section describes what is considered required diagnostic data and what is considered optional diagnostic data, along with a description of the events and fields that are collected.
|
||||||
|
|
||||||
|
### Data fields that are common for all events
|
||||||
|
There is some information about events that is common to all events, regardless of category or data subtype.
|
||||||
|
|
||||||
|
The following fields are considered common for all events:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ----------------------- | ----------- |
|
||||||
|
| platform | The broad classification of the platform on which the app is running. Allows Microsoft to identify on which platforms an issue may be occurring so that it can correctly be prioritized. |
|
||||||
|
| machine_guid | Unique identifier associated with the device. Allows Microsoft to identify whether issues are impacting a select set of installs and how many users are impacted. |
|
||||||
|
| sense_guid | Unique identifier associated with the device. Allows Microsoft to identify whether issues are impacting a select set of installs and how many users are impacted. |
|
||||||
|
| org_id | Unique identifier associated with the enterprise that the device belongs to. Allows Microsoft to identify whether issues are impacting a select set of enterprises and how many enterprises are impacted. |
|
||||||
|
| hostname | Local machine name (without DNS suffix). Allows Microsoft to identify whether issues are impacting a select set of installs and how many users are impacted. |
|
||||||
|
| product_guid | Unique identifier of the product. Allows Microsoft to differentiate issues impacting different flavors of the product. |
|
||||||
|
| app_version | Version of the Microsoft Defender ATP for Linux application. Allows Microsoft to identify which versions of the product are showing an issue so that it can correctly be prioritized.|
|
||||||
|
| sig_version | Version of security intelligence database. Allows Microsoft to identify which versions of the security intelligence are showing an issue so that it can correctly be prioritized. |
|
||||||
|
| supported_compressions | List of compression algorithms supported by the application, for example `['gzip']`. Allows Microsoft to understand what types of compressions can be used when it communicates with the application. |
|
||||||
|
| release_ring | Ring that the device is associated with (for example Insider Fast, Insider Slow, Production). Allows Microsoft to identify on which release ring an issue may be occurring so that it can correctly be prioritized. |
|
||||||
|
|
||||||
|
### Required diagnostic data
|
||||||
|
|
||||||
|
**Required diagnostic data** is the minimum data necessary to help keep Microsoft Defender ATP secure, up-to-date, and perform as expected on the device it’s installed on.
|
||||||
|
|
||||||
|
Required diagnostic data helps to identify problems with Microsoft Defender ATP that may be related to a device or software configuration. For example, it can help determine if a Microsoft Defender ATP feature crashes more frequently on a particular operating system version, with newly introduced features, or when certain Microsoft Defender ATP features are disabled. Required diagnostic data helps Microsoft detect, diagnose, and fix these problems more quickly so the impact to users or organizations is reduced.
|
||||||
|
|
||||||
|
#### Software setup and inventory data events
|
||||||
|
|
||||||
|
**Microsoft Defender ATP installation / uninstallation**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| correlation_id | Unique identifier associated with the installation. |
|
||||||
|
| version | Version of the package. |
|
||||||
|
| severity | Severity of the message (for example Informational). |
|
||||||
|
| code | Code that describes the operation. |
|
||||||
|
| text | Additional information associated with the product installation. |
|
||||||
|
|
||||||
|
**Microsoft Defender ATP configuration**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| --------------------------------------------------- | ----------- |
|
||||||
|
| antivirus_engine.enable_real_time_protection | Whether real-time protection is enabled on the device or not. |
|
||||||
|
| antivirus_engine.passive_mode | Whether passive mode is enabled on the device or not. |
|
||||||
|
| cloud_service.enabled | Whether cloud delivered protection is enabled on the device or not. |
|
||||||
|
| cloud_service.timeout | Time out when the application communicates with the Microsoft Defender ATP cloud. |
|
||||||
|
| cloud_service.heartbeat_interval | Interval between consecutive heartbeats sent by the product to the cloud. |
|
||||||
|
| cloud_service.service_uri | URI used to communicate with the cloud. |
|
||||||
|
| cloud_service.diagnostic_level | Diagnostic level of the device (required, optional). |
|
||||||
|
| cloud_service.automatic_sample_submission | Automatic sample submission level of the device (none, safe, all). |
|
||||||
|
| edr.early_preview | Whether the machine should run EDR early preview features. |
|
||||||
|
| edr.group_id | Group identifier used by the detection and response component. |
|
||||||
|
| edr.tags | User-defined tags. |
|
||||||
|
| features.\[optional feature name\] | List of preview features, along with whether they are enabled or not. |
|
||||||
|
|
||||||
|
#### Product and service usage data events
|
||||||
|
|
||||||
|
**Security intelligence update report**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| from_version | Original security intelligence version. |
|
||||||
|
| to_version | New security intelligence version. |
|
||||||
|
| status | Status of the update indicating success or failure. |
|
||||||
|
| using_proxy | Whether the update was done over a proxy. |
|
||||||
|
| error | Error code if the update failed. |
|
||||||
|
| reason | Error message if the update failed. |
|
||||||
|
|
||||||
|
#### Product and service performance data events
|
||||||
|
|
||||||
|
**Kernel extension statistics**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| version | Version of Microsoft Defender ATP for Linux. |
|
||||||
|
| instance_id | Unique identifier generated on kernel extension startup. |
|
||||||
|
| trace_level | Trace level of the kernel extension. |
|
||||||
|
| subsystem | The underlying subsystem used for real-time protection. |
|
||||||
|
| ipc.connects | Number of connection requests received by the kernel extension. |
|
||||||
|
| ipc.rejects | Number of connection requests rejected by the kernel extension. |
|
||||||
|
| ipc.connected | Whether there is any active connection to the kernel extension. |
|
||||||
|
|
||||||
|
#### Support data
|
||||||
|
|
||||||
|
**Diagnostic logs**
|
||||||
|
|
||||||
|
Diagnostic logs are collected only with the consent of the user as part of the feedback submission feature. The following files are collected as part of the support logs:
|
||||||
|
|
||||||
|
- All files under */var/log/microsoft/mdatp*
|
||||||
|
- Subset of files under */etc/opt/microsoft/mdatp* that are created and used by Microsoft Defender ATP for Linux
|
||||||
|
- Product installation and uninstallation logs under */var/log/microsoft_mdatp_\*.log*
|
||||||
|
|
||||||
|
### Optional diagnostic data
|
||||||
|
|
||||||
|
**Optional diagnostic data** is additional data that helps Microsoft make product improvements and provides enhanced information to help detect, diagnose, and fix issues.
|
||||||
|
|
||||||
|
If you choose to send us optional diagnostic data, required diagnostic data is also included.
|
||||||
|
|
||||||
|
Examples of optional diagnostic data include data Microsoft collects about product configuration (for example number of exclusions set on the device) and product performance (aggregate measures about the performance of components of the product).
|
||||||
|
|
||||||
|
#### Software setup and inventory data events
|
||||||
|
|
||||||
|
**Microsoft Defender ATP configuration**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| -------------------------------------------------- | ----------- |
|
||||||
|
| connection_retry_timeout | Connection retry time-out when communication with the cloud. |
|
||||||
|
| file_hash_cache_maximum | Size of the product cache. |
|
||||||
|
| crash_upload_daily_limit | Limit of crash logs uploaded daily. |
|
||||||
|
| antivirus_engine.exclusions[].is_directory | Whether the exclusion from scanning is a directory or not. |
|
||||||
|
| antivirus_engine.exclusions[].path | Path that was excluded from scanning. |
|
||||||
|
| antivirus_engine.exclusions[].extension | Extension excluded from scanning. |
|
||||||
|
| antivirus_engine.exclusions[].name | Name of the file excluded from scanning. |
|
||||||
|
| antivirus_engine.scan_cache_maximum | Size of the product cache. |
|
||||||
|
| antivirus_engine.maximum_scan_threads | Maximum number of threads used for scanning. |
|
||||||
|
| antivirus_engine.threat_restoration_exclusion_time | Time out before a file restored from the quarantine can be detected again. |
|
||||||
|
| filesystem_scanner.full_scan_directory | Full scan directory. |
|
||||||
|
| filesystem_scanner.quick_scan_directories | List of directories used in quick scan. |
|
||||||
|
| edr.latency_mode | Latency mode used by the detection and response component. |
|
||||||
|
| edr.proxy_address | Proxy address used by the detection and response component. |
|
||||||
|
|
||||||
|
**Microsoft Auto-Update configuration**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| --------------------------- | ----------- |
|
||||||
|
| how_to_check | Determines how product updates are checked (for example automatic or manual). |
|
||||||
|
| channel_name | Update channel associated with the device. |
|
||||||
|
| manifest_server | Server used for downloading updates. |
|
||||||
|
| update_cache | Location of the cache used to store updates. |
|
||||||
|
|
||||||
|
### Product and service usage
|
||||||
|
|
||||||
|
#### Diagnostic log upload started report
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| sha256 | SHA256 identifier of the support log. |
|
||||||
|
| size | Size of the support log. |
|
||||||
|
| original_path | Path to the support log (always under */var/opt/microsoft/mdatp/wdavdiag/*). |
|
||||||
|
| format | Format of the support log. |
|
||||||
|
|
||||||
|
#### Diagnostic log upload completed report
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| request_id | Correlation ID for the support log upload request. |
|
||||||
|
| sha256 | SHA256 identifier of the support log. |
|
||||||
|
| blob_sas_uri | URI used by the application to upload the support log. |
|
||||||
|
|
||||||
|
#### Product and service performance data events
|
||||||
|
|
||||||
|
**Unexpected application exit (crash)**
|
||||||
|
|
||||||
|
Unexpected application exits and the state of the application when that happens.
|
||||||
|
|
||||||
|
**Kernel extension statistics**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ------------------------------ | ----------- |
|
||||||
|
| pkt_ack_timeout | The following properties are aggregated numerical values, representing count of events that happened since kernel extension startup. |
|
||||||
|
| pkt_ack_conn_timeout | |
|
||||||
|
| ipc.ack_pkts | |
|
||||||
|
| ipc.nack_pkts | |
|
||||||
|
| ipc.send.ack_no_conn | |
|
||||||
|
| ipc.send.nack_no_conn | |
|
||||||
|
| ipc.send.ack_no_qsq | |
|
||||||
|
| ipc.send.nack_no_qsq | |
|
||||||
|
| ipc.ack.no_space | |
|
||||||
|
| ipc.ack.timeout | |
|
||||||
|
| ipc.ack.ackd_fast | |
|
||||||
|
| ipc.ack.ackd | |
|
||||||
|
| ipc.recv.bad_pkt_len | |
|
||||||
|
| ipc.recv.bad_reply_len | |
|
||||||
|
| ipc.recv.no_waiter | |
|
||||||
|
| ipc.recv.copy_failed | |
|
||||||
|
| ipc.kauth.vnode.mask | |
|
||||||
|
| ipc.kauth.vnode.read | |
|
||||||
|
| ipc.kauth.vnode.write | |
|
||||||
|
| ipc.kauth.vnode.exec | |
|
||||||
|
| ipc.kauth.vnode.del | |
|
||||||
|
| ipc.kauth.vnode.read_attr | |
|
||||||
|
| ipc.kauth.vnode.write_attr | |
|
||||||
|
| ipc.kauth.vnode.read_ex_attr | |
|
||||||
|
| ipc.kauth.vnode.write_ex_attr | |
|
||||||
|
| ipc.kauth.vnode.read_sec | |
|
||||||
|
| ipc.kauth.vnode.write_sec | |
|
||||||
|
| ipc.kauth.vnode.take_own | |
|
||||||
|
| ipc.kauth.vnode.link | |
|
||||||
|
| ipc.kauth.vnode.create | |
|
||||||
|
| ipc.kauth.vnode.move | |
|
||||||
|
| ipc.kauth.vnode.mount | |
|
||||||
|
| ipc.kauth.vnode.denied | |
|
||||||
|
| ipc.kauth.vnode.ackd_before_deadline | |
|
||||||
|
| ipc.kauth.vnode.missed_deadline | |
|
||||||
|
| ipc.kauth.file_op.mask | |
|
||||||
|
| ipc.kauth_file_op.open | |
|
||||||
|
| ipc.kauth.file_op.close | |
|
||||||
|
| ipc.kauth.file_op.close_modified | |
|
||||||
|
| ipc.kauth.file_op.move | |
|
||||||
|
| ipc.kauth.file_op.link | |
|
||||||
|
| ipc.kauth.file_op.exec | |
|
||||||
|
| ipc.kauth.file_op.remove | |
|
||||||
|
| ipc.kauth.file_op.unmount | |
|
||||||
|
| ipc.kauth.file_op.fork | |
|
||||||
|
| ipc.kauth.file_op.create | |
|
||||||
|
|
||||||
|
## Resources
|
||||||
|
|
||||||
|
- [Privacy at Microsoft](https://privacy.microsoft.com/)
|
@ -0,0 +1,65 @@
|
|||||||
|
---
|
||||||
|
title: Detect and block potentially unwanted applications with Microsoft Defender ATP for Linux
|
||||||
|
description: Detect and block Potentially Unwanted Applications (PUA) using Microsoft Defender ATP for Linux.
|
||||||
|
keywords: microsoft, defender, atp, linux, pua, pus
|
||||||
|
search.product: eADQiWindows 10XVcnh
|
||||||
|
search.appverid: met150
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: deploy
|
||||||
|
ms.sitesec: library
|
||||||
|
ms.pagetype: security
|
||||||
|
ms.author: dansimp
|
||||||
|
author: dansimp
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
manager: dansimp
|
||||||
|
audience: ITPro
|
||||||
|
ms.collection: M365-security-compliance
|
||||||
|
ms.topic: conceptual
|
||||||
|
---
|
||||||
|
|
||||||
|
# Detect and block potentially unwanted applications with Microsoft Defender ATP for Linux
|
||||||
|
|
||||||
|
**Applies to:**
|
||||||
|
|
||||||
|
- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Linux](microsoft-defender-atp-linux.md)
|
||||||
|
|
||||||
|
The potentially unwanted application (PUA) protection feature in Microsoft Defender ATP for Linux can detect and block PUA files on endpoints in your network.
|
||||||
|
|
||||||
|
These applications are not considered viruses, malware, or other types of threats, but might perform actions on endpoints that adversely affect their performance or use. PUA can also refer to applications that are considered to have poor reputation.
|
||||||
|
|
||||||
|
These applications can increase the risk of your network being infected with malware, cause malware infections to be harder to identify, and can waste IT resources in cleaning up the applications.
|
||||||
|
|
||||||
|
## How it works
|
||||||
|
|
||||||
|
Microsoft Defender ATP for Linux can detect and report PUA files. When configured in blocking mode, PUA files are moved to the quarantine.
|
||||||
|
|
||||||
|
When a PUA is detected on an endpoint, Microsoft Defender ATP for Linux keeps a record of the infection in the threat history. The history can be visualized from the Microsoft Defender Security Center portal or through the `mdatp` command-line tool. The threat name will contain the word "Application".
|
||||||
|
|
||||||
|
## Configure PUA protection
|
||||||
|
|
||||||
|
PUA protection in Microsoft Defender ATP for Linux can be configured in one of the following ways:
|
||||||
|
|
||||||
|
- **Off**: PUA protection is disabled.
|
||||||
|
- **Audit**: PUA files are reported in the product logs, but not in Microsoft Defender Security Center. No record of the infection is stored in the threat history and no action is taken by the product.
|
||||||
|
- **Block**: PUA files are reported in the product logs and in Microsoft Defender Security Center. A record of the infection is stored in the threat history and action is taken by the product.
|
||||||
|
|
||||||
|
>[!WARNING]
|
||||||
|
>By default, PUA protection is configured in **Audit** mode.
|
||||||
|
|
||||||
|
You can configure how PUA files are handled from the command line or from the management console.
|
||||||
|
|
||||||
|
### Use the command-line tool to configure PUA protection:
|
||||||
|
|
||||||
|
In Terminal, execute the following command to configure PUA protection:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ mdatp --threat --type-handling potentially_unwanted_application [off|audit|block]
|
||||||
|
```
|
||||||
|
|
||||||
|
### Use the management console to configure PUA protection:
|
||||||
|
|
||||||
|
In your enterprise, you can configure PUA protection from a management console, such as Puppet or Ansible, similarly to how other product settings are configured. For more information, see the [Threat type settings](linux-preferences.md#threat-type-settings) section of the [Set preferences for Microsoft Defender ATP for Linux](linux-preferences.md) topic.
|
||||||
|
|
||||||
|
## Related topics
|
||||||
|
|
||||||
|
- [Set preferences for Microsoft Defender ATP for Linux](linux-preferences.md)
|
@ -43,7 +43,7 @@ There are two levels of diagnostic data for Microsoft Defender ATP client softwa
|
|||||||
|
|
||||||
* **Optional**: Additional data that helps Microsoft make product improvements and provides enhanced information to help detect, diagnose, and remediate issues.
|
* **Optional**: Additional data that helps Microsoft make product improvements and provides enhanced information to help detect, diagnose, and remediate issues.
|
||||||
|
|
||||||
By default, both optional and required diagnostic data are sent to Microsoft.
|
By default, only required diagnostic data is sent to Microsoft.
|
||||||
|
|
||||||
### Cloud delivered protection data
|
### Cloud delivered protection data
|
||||||
|
|
||||||
@ -127,6 +127,21 @@ The following fields are collected:
|
|||||||
| edr.tags | User-defined tags. |
|
| edr.tags | User-defined tags. |
|
||||||
| features.\[optional feature name\] | List of preview features, along with whether they are enabled or not. |
|
| features.\[optional feature name\] | List of preview features, along with whether they are enabled or not. |
|
||||||
|
|
||||||
|
#### Product and service usage data events
|
||||||
|
|
||||||
|
**Security intelligence update report**
|
||||||
|
|
||||||
|
The following fields are collected:
|
||||||
|
|
||||||
|
| Field | Description |
|
||||||
|
| ---------------- | ----------- |
|
||||||
|
| from_version | Original security intelligence version. |
|
||||||
|
| to_version | New security intelligence version. |
|
||||||
|
| status | Status of the update indicating success or failure. |
|
||||||
|
| using_proxy | Whether the update was done over a proxy. |
|
||||||
|
| error | Error code if the update failed. |
|
||||||
|
| reason | Error message if the updated filed. |
|
||||||
|
|
||||||
#### Product and service performance data events
|
#### Product and service performance data events
|
||||||
|
|
||||||
**Kernel extension statistics**
|
**Kernel extension statistics**
|
||||||
@ -138,6 +153,7 @@ The following fields are collected:
|
|||||||
| version | Version of Microsoft Defender ATP for Mac. |
|
| version | Version of Microsoft Defender ATP for Mac. |
|
||||||
| instance_id | Unique identifier generated on kernel extension startup. |
|
| instance_id | Unique identifier generated on kernel extension startup. |
|
||||||
| trace_level | Trace level of the kernel extension. |
|
| trace_level | Trace level of the kernel extension. |
|
||||||
|
| subsystem | The underlying subsystem used for real-time protection. |
|
||||||
| ipc.connects | Number of connection requests received by the kernel extension. |
|
| ipc.connects | Number of connection requests received by the kernel extension. |
|
||||||
| ipc.rejects | Number of connection requests rejected by the kernel extension. |
|
| ipc.rejects | Number of connection requests rejected by the kernel extension. |
|
||||||
| ipc.connected | Whether there is any active connection to the kernel extension. |
|
| ipc.connected | Whether there is any active connection to the kernel extension. |
|
||||||
@ -259,7 +275,13 @@ The following fields are collected:
|
|||||||
| ipc.kauth.vnode.read_sec | |
|
| ipc.kauth.vnode.read_sec | |
|
||||||
| ipc.kauth.vnode.write_sec | |
|
| ipc.kauth.vnode.write_sec | |
|
||||||
| ipc.kauth.vnode.take_own | |
|
| ipc.kauth.vnode.take_own | |
|
||||||
|
| ipc.kauth.vnode.link | |
|
||||||
|
| ipc.kauth.vnode.create | |
|
||||||
|
| ipc.kauth.vnode.move | |
|
||||||
|
| ipc.kauth.vnode.mount | |
|
||||||
| ipc.kauth.vnode.denied | |
|
| ipc.kauth.vnode.denied | |
|
||||||
|
| ipc.kauth.vnode.ackd_before_deadline | |
|
||||||
|
| ipc.kauth.vnode.missed_deadline | |
|
||||||
| ipc.kauth.file_op.mask | |
|
| ipc.kauth.file_op.mask | |
|
||||||
| ipc.kauth_file_op.open | |
|
| ipc.kauth_file_op.open | |
|
||||||
| ipc.kauth.file_op.close | |
|
| ipc.kauth.file_op.close | |
|
||||||
@ -268,6 +290,7 @@ The following fields are collected:
|
|||||||
| ipc.kauth.file_op.link | |
|
| ipc.kauth.file_op.link | |
|
||||||
| ipc.kauth.file_op.exec | |
|
| ipc.kauth.file_op.exec | |
|
||||||
| ipc.kauth.file_op.remove | |
|
| ipc.kauth.file_op.remove | |
|
||||||
|
| ipc.kauth.file_op.unmount | |
|
||||||
| ipc.kauth.file_op.fork | |
|
| ipc.kauth.file_op.fork | |
|
||||||
| ipc.kauth.file_op.create | |
|
| ipc.kauth.file_op.create | |
|
||||||
|
|
||||||
|
@ -47,6 +47,8 @@ Turn on the preview experience setting to be among the first to try upcoming fea
|
|||||||
## Preview features
|
## Preview features
|
||||||
|
|
||||||
The following features are included in the preview release:
|
The following features are included in the preview release:
|
||||||
|
- [Attack simulators in the evaluation lab](evaluation-lab.md#threat-simulator-scenarios) <br> Microsoft Defender ATP has partnered with various threat simulation platforms to give you convenient access to test the capabilities of the platform right from the within the portal.
|
||||||
|
|
||||||
- [Create indicators for certificates](manage-indicators.md) <br> Create indicators to allow or block certificates.
|
- [Create indicators for certificates](manage-indicators.md) <br> Create indicators to allow or block certificates.
|
||||||
|
|
||||||
- [Microsoft Defender ATP for Linux](microsoft-defender-atp-linux.md) <br> Microsoft Defender ATP now adds support for Linux. Learn how to install, configure, update, and use Microsoft Defender ATP for Linux.
|
- [Microsoft Defender ATP for Linux](microsoft-defender-atp-linux.md) <br> Microsoft Defender ATP now adds support for Linux. Learn how to install, configure, update, and use Microsoft Defender ATP for Linux.
|
||||||
|
@ -88,5 +88,4 @@ crl.microsoft.com`
|
|||||||
- `https://static2.sharepointonline.com`
|
- `https://static2.sharepointonline.com`
|
||||||
|
|
||||||
|
|
||||||
## Related topics
|
|
||||||
- [Validate licensing provisioning and complete setup for Microsoft Defender ATP](licensing.md)
|
|
||||||
|
@ -27,9 +27,13 @@ The following features are generally available (GA) in the latest release of Mic
|
|||||||
|
|
||||||
For more information preview features, see [Preview features](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection).
|
For more information preview features, see [Preview features](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection).
|
||||||
|
|
||||||
|
|
||||||
> [!TIP]
|
> [!TIP]
|
||||||
> RSS feed: Get notified when this page is updated by copying and pasting the following URL into your feed reader:
|
> RSS feed: Get notified when this page is updated by copying and pasting the following URL into your feed reader:
|
||||||
`https://docs.microsoft.com/api/search/rss?search=%22Microsoft+Defender+ATP+as+well+as+security+features+in+Windows+10+and+Windows+Server.%22&locale=en-us`
|
>
|
||||||
|
> ```https
|
||||||
|
> https://docs.microsoft.com/api/search/rss?search=%22Microsoft+Defender+ATP+as+well+as+security+features+in+Windows+10+and+Windows+Server.%22&locale=en-us
|
||||||
|
> ```
|
||||||
|
|
||||||
## April 2020
|
## April 2020
|
||||||
|
|
||||||
@ -59,7 +63,7 @@ For more information preview features, see [Preview features](https://docs.micro
|
|||||||
|
|
||||||
## September 2019
|
## September 2019
|
||||||
|
|
||||||
- [Tamper Protection settings using Intune](../windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md#turn-tamper-protection-on-or-off-for-your-organization-using-intune)<br/>You can now turn Tamper Protection on (or off) for your organization in the Microsoft 365 Device Management portal (Intune).
|
- [Tamper Protection settings using Intune](../windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md#turn-tamper-protection-on-or-off-for-your-organization-using-intune)<br/>You can now turn Tamper Protection on (or off) for your organization in the Microsoft 365 Device Management Portal (Intune).
|
||||||
|
|
||||||
- [Live response](live-response.md)<BR> Get instantaneous access to a machine using a remote shell connection. Do in-depth investigative work and take immediate response actions to promptly contain identified threats - real-time.
|
- [Live response](live-response.md)<BR> Get instantaneous access to a machine using a remote shell connection. Do in-depth investigative work and take immediate response actions to promptly contain identified threats - real-time.
|
||||||
|
|
||||||
|