mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Merged PR 7751: Fixing broken table on live (plus early push live)
This commit is contained in:
parent
5f4906900a
commit
161abf07c6
@ -16,8 +16,8 @@ ms.date: 04/30/2018
|
|||||||
Windows 10 Pro Education is a new offering in Windows 10, version 1607. This edition builds on the commercial version of Windows 10 Pro and provides important management controls needed in schools by providing education-specific default settings.
|
Windows 10 Pro Education is a new offering in Windows 10, version 1607. This edition builds on the commercial version of Windows 10 Pro and provides important management controls needed in schools by providing education-specific default settings.
|
||||||
|
|
||||||
If you have an education tenant and use devices with Windows 10 Pro, global administrators can opt-in to a free change to Windows 10 Pro Education depending on your scenario.
|
If you have an education tenant and use devices with Windows 10 Pro, global administrators can opt-in to a free change to Windows 10 Pro Education depending on your scenario.
|
||||||
- [change from Windows 10 Pro in S mode to Windows 10 Pro Education in S mode](https://www.microsoft.com/en-us/education/windows/s-mode-change-to-edu)
|
- [Switch from Windows 10 Pro in S mode to Windows 10 Pro Education in S mode](https://www.microsoft.com/en-us/education/windows/s-mode-change-to-edu)
|
||||||
- [change from Windows 10 Pro to Windows 10 Pro Education](#change-from-windows-10-pro-to-windows-10-pro-education)
|
- [Switch from Windows 10 Pro to Windows 10 Pro Education](#switch-from-windows-10-pro-to-windows-10-pro-education)
|
||||||
|
|
||||||
To take advantage of this offering, make sure you meet the [requirements for changing](#requirements-for-changing). For academic customers who are eligible to change to Windows 10 Pro Education, but are unable to use the above methods, contact Microsoft Support for assistance.
|
To take advantage of this offering, make sure you meet the [requirements for changing](#requirements-for-changing). For academic customers who are eligible to change to Windows 10 Pro Education, but are unable to use the above methods, contact Microsoft Support for assistance.
|
||||||
|
|
||||||
@ -37,7 +37,7 @@ You can [compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsFor
|
|||||||
|
|
||||||
For more info about Windows 10 default settings and recommendations for education customers, see [Windows 10 configuration recommendations for education customers](configure-windows-for-education.md).
|
For more info about Windows 10 default settings and recommendations for education customers, see [Windows 10 configuration recommendations for education customers](configure-windows-for-education.md).
|
||||||
|
|
||||||
## change from Windows 10 Pro to Windows 10 Pro Education
|
## Change from Windows 10 Pro to Windows 10 Pro Education
|
||||||
|
|
||||||
For schools that want to standardize all their Windows 10 Pro devices to Windows 10 Pro Education, a global admin for the school can opt-in to a free change through the Microsoft Store for Education.
|
For schools that want to standardize all their Windows 10 Pro devices to Windows 10 Pro Education, a global admin for the school can opt-in to a free change through the Microsoft Store for Education.
|
||||||
|
|
||||||
@ -49,7 +49,7 @@ In this scenario:
|
|||||||
|
|
||||||
See [change using Microsoft Store for Education](#change-using-microsoft-store-for-education) for details on how to do this.
|
See [change using Microsoft Store for Education](#change-using-microsoft-store-for-education) for details on how to do this.
|
||||||
|
|
||||||
### change using Intune for Education
|
### Change using Intune for Education
|
||||||
|
|
||||||
1. In Intune for Education, select **Groups** and then choose the group that you want to apply the MAK license key to.
|
1. In Intune for Education, select **Groups** and then choose the group that you want to apply the MAK license key to.
|
||||||
|
|
||||||
@ -66,7 +66,7 @@ See [change using Microsoft Store for Education](#change-using-microsoft-store-f
|
|||||||
3. The change will automatically be applied to the group you selected.
|
3. The change will automatically be applied to the group you selected.
|
||||||
|
|
||||||
|
|
||||||
### change using Windows Configuration Designer
|
### Change using Windows Configuration Designer
|
||||||
You can use Windows Configuration Designer to create a provisioning package that you can use to change the Windows edition for your device(s). [Install Windows Configuration Designer from the Microsoft Store](https://www.microsoft.com/store/apps/9nblggh4tx22) to create a provisioning package.
|
You can use Windows Configuration Designer to create a provisioning package that you can use to change the Windows edition for your device(s). [Install Windows Configuration Designer from the Microsoft Store](https://www.microsoft.com/store/apps/9nblggh4tx22) to create a provisioning package.
|
||||||
|
|
||||||
1. In Windows Configuration Designer, select **Provision desktop devices** to open the simple editor and create a provisioning package for Windows desktop editions.
|
1. In Windows Configuration Designer, select **Provision desktop devices** to open the simple editor and create a provisioning package for Windows desktop editions.
|
||||||
@ -81,7 +81,7 @@ You can use Windows Configuration Designer to create a provisioning package that
|
|||||||
For more information about using Windows Configuration Designer, see [Set up student PCs to join domain](https://technet.microsoft.com/en-us/edu/windows/set-up-students-pcs-to-join-domain).
|
For more information about using Windows Configuration Designer, see [Set up student PCs to join domain](https://technet.microsoft.com/en-us/edu/windows/set-up-students-pcs-to-join-domain).
|
||||||
|
|
||||||
|
|
||||||
### change using the Activation page
|
### Change using the Activation page
|
||||||
|
|
||||||
1. On the Windows device that you want to change, open the **Settings** app.
|
1. On the Windows device that you want to change, open the **Settings** app.
|
||||||
2. Select **Update & security** > **Activation**, and then click **Change product key**.
|
2. Select **Update & security** > **Activation**, and then click **Change product key**.
|
||||||
@ -103,7 +103,7 @@ When you change to Windows 10 Pro Education, you get the following benefits:
|
|||||||
See [Roll back Windows 10 Pro Education to Windows 10 Pro](#roll-back-windows-10-pro-education-to-windows-10-pro) for more info.
|
See [Roll back Windows 10 Pro Education to Windows 10 Pro](#roll-back-windows-10-pro-education-to-windows-10-pro) for more info.
|
||||||
|
|
||||||
|
|
||||||
### change using Microsoft Store for Education
|
### Change using Microsoft Store for Education
|
||||||
Once you enable the setting to change to Windows 10 Pro Education, the change will begin only after a user signs in to their device. The setting applies to the entire organization or tenant, so you cannot select which users will receive the change. The change will only apply to Windows 10 Pro devices.
|
Once you enable the setting to change to Windows 10 Pro Education, the change will begin only after a user signs in to their device. The setting applies to the entire organization or tenant, so you cannot select which users will receive the change. The change will only apply to Windows 10 Pro devices.
|
||||||
|
|
||||||
**To turn on the automatic change to Windows 10 Pro Education**
|
**To turn on the automatic change to Windows 10 Pro Education**
|
||||||
@ -113,24 +113,24 @@ Once you enable the setting to change to Windows 10 Pro Education, the change wi
|
|||||||
If this is the first time you're signing into the Microsoft Store for Education, you'll be prompted to accept the Microsoft Store for Education Terms of Use.
|
If this is the first time you're signing into the Microsoft Store for Education, you'll be prompted to accept the Microsoft Store for Education Terms of Use.
|
||||||
|
|
||||||
2. Click **Manage** from the top menu and then select the **Benefits tile**.
|
2. Click **Manage** from the top menu and then select the **Benefits tile**.
|
||||||
3. In the **Benefits** tile, look for the **change to Windows 10 Pro Education for free** link and then click it.
|
3. In the **Benefits** tile, look for the **Change to Windows 10 Pro Education for free** link and then click it.
|
||||||
|
|
||||||
4. In the **change all your devices to Windows 10 Pro Education for free** page, check box next to **I understand enabling this setting will change all domain-joined devices running Windows 10 Pro in my organization**.
|
4. In the **Change all your devices to Windows 10 Pro Education for free** page, check box next to **I understand enabling this setting will change all domain-joined devices running Windows 10 Pro in my organization**.
|
||||||
|
|
||||||
**Figure 4** - Check the box to confirm
|
**Figure 3** - Check the box to confirm
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
5. Click **change all my devices**.
|
5. Click **Change all my devices**.
|
||||||
|
|
||||||
A confirmation window pops up to let you know that an email has been sent to you to enable the change.
|
A confirmation window pops up to let you know that an email has been sent to you to enable the change.
|
||||||
|
|
||||||
6. Close the confirmation window and check the email to proceed to the next step.
|
6. Close the confirmation window and check the email to proceed to the next step.
|
||||||
7. In the email, click the link to **change to Windows 10 Pro Education**. Once you click the link, this will take you back to the Microsoft Store for Education portal.
|
7. In the email, click the link to **Change to Windows 10 Pro Education**. Once you click the link, this will take you back to the Microsoft Store for Education portal.
|
||||||
|
|
||||||
8. Click **change now** in the **changing your device to Windows 10 Pro Education for free** page in the Microsoft Store.
|
8. Click **Change now** in the **changing your device to Windows 10 Pro Education for free** page in the Microsoft Store.
|
||||||
|
|
||||||
You will see a window that confirms you've successfully changeed all the devices in your organization to Windows 10 Pro Education, and each Azure AD joined device running Windows 10 Pro will automatically change the next time someone in your organization signs in to the device.
|
You will see a window that confirms you've successfully changed all the devices in your organization to Windows 10 Pro Education, and each Azure AD joined device running Windows 10 Pro will automatically change the next time someone in your organization signs in to the device.
|
||||||
|
|
||||||
9. Click **Close** in the **Success** window.
|
9. Click **Close** in the **Success** window.
|
||||||
|
|
||||||
@ -142,7 +142,7 @@ Enabling the automatic change also triggers an email message notifying all globa
|
|||||||
So what will users experience? How will they change their devices?
|
So what will users experience? How will they change their devices?
|
||||||
|
|
||||||
### For existing Azure AD joined devices
|
### For existing Azure AD joined devices
|
||||||
Existing Azure AD domain joined devices will be changeed to Windows 10 Pro Education the next time the user logs in. That's it! No additional steps are needed.
|
Existing Azure AD domain joined devices will be changed to Windows 10 Pro Education the next time the user logs in. That's it! No additional steps are needed.
|
||||||
|
|
||||||
### For new devices that are not Azure AD joined
|
### For new devices that are not Azure AD joined
|
||||||
Now that you've turned on the setting to automatically change to Windows 10 Pro Education, the users are ready to change their devices running Windows 10 Pro, version 1607 or higher, version 1703 to Windows 10 Pro Education edition.
|
Now that you've turned on the setting to automatically change to Windows 10 Pro Education, the users are ready to change their devices running Windows 10 Pro, version 1607 or higher, version 1703 to Windows 10 Pro Education edition.
|
||||||
@ -163,13 +163,13 @@ If the Windows device is running Windows 10, version 1703, follow these steps.
|
|||||||
|
|
||||||
1. During initial device setup, on the **How would you like to set up?** page, select **Set up for an organization**, and then click **Next**.
|
1. During initial device setup, on the **How would you like to set up?** page, select **Set up for an organization**, and then click **Next**.
|
||||||
|
|
||||||
**Figure 7** - Select how you'd like to set up the device
|
**Figure 4** - Select how you'd like to set up the device
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
2. On the **Sign in with Microsoft** page, enter the username and password to use with Office 365 or other services from Microsoft, and then click **Next**.
|
2. On the **Sign in with Microsoft** page, enter the username and password to use with Office 365 or other services from Microsoft, and then click **Next**.
|
||||||
|
|
||||||
**Figure 8** - Enter the account details
|
**Figure 5** - Enter the account details
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -182,21 +182,21 @@ If the Windows device is running Windows 10, version 1703, follow these steps.
|
|||||||
|
|
||||||
1. Go to **Settings > Accounts > Access work or school**.
|
1. Go to **Settings > Accounts > Access work or school**.
|
||||||
|
|
||||||
**Figure 9** - Go to **Access work or school** in Settings
|
**Figure 6** - Go to **Access work or school** in Settings
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
2. In **Access work or school**, click **Connect**.
|
2. In **Access work or school**, click **Connect**.
|
||||||
3. In the **Set up a work or school account** window, click the **Join this device to Azure Active Directory** option at the bottom.
|
3. In the **Set up a work or school account** window, click the **Join this device to Azure Active Directory** option at the bottom.
|
||||||
|
|
||||||
**Figure 10** - Select the option to join the device to Azure Active Directory
|
**Figure 7** - Select the option to join the device to Azure Active Directory
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
4. On the **Let's get you signed in** window, enter the Azure AD credentials (username and password) and sign in. This will join the device to the school's Azure AD.
|
4. On the **Let's get you signed in** window, enter the Azure AD credentials (username and password) and sign in. This will join the device to the school's Azure AD.
|
||||||
5. To verify that the device was successfully joined to Azure AD, go back to **Settings > Accounts > Access work or school**. You should now see a connection under the **Connect to work or school** section that indicates the device is connected to Azure AD.
|
5. To verify that the device was successfully joined to Azure AD, go back to **Settings > Accounts > Access work or school**. You should now see a connection under the **Connect to work or school** section that indicates the device is connected to Azure AD.
|
||||||
|
|
||||||
**Figure 11** - Verify the device connected to Azure AD
|
**Figure 8** - Verify the device connected to Azure AD
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -210,7 +210,7 @@ Once the device is joined to your Azure AD subscription, the user will sign in b
|
|||||||
|
|
||||||
You can verify the Windows 10 Pro Education in **Settings > Update & Security > Activation**.
|
You can verify the Windows 10 Pro Education in **Settings > Update & Security > Activation**.
|
||||||
|
|
||||||
**Figure 12** - Windows 10 Pro Education in Settings
|
**Figure 9** - Windows 10 Pro Education in Settings
|
||||||
|
|
||||||
<img src="images/win-10-pro-edu-activated-subscription-active.png" alt="Windows 10 activated and subscription active" />
|
<img src="images/win-10-pro-edu-activated-subscription-active.png" alt="Windows 10 activated and subscription active" />
|
||||||
|
|
||||||
@ -225,12 +225,12 @@ In some instances, users may experience problems with the Windows 10 Pro Educat
|
|||||||
|
|
||||||
Use the following figures to help you troubleshoot when users experience these common problems:
|
Use the following figures to help you troubleshoot when users experience these common problems:
|
||||||
|
|
||||||
**Figure 13** - Illustrates a device in a healthy state, where the existing operating system is activated, and the Windows 10 Pro Education change is active.
|
**Figure 10** - Illustrates a device in a healthy state, where the existing operating system is activated, and the Windows 10 Pro Education change is active.
|
||||||
|
|
||||||
<img src="images/win-10-pro-edu-activated-subscription-active.png" alt="Windows 10 activated and subscription active" /></br></br>
|
<img src="images/win-10-pro-edu-activated-subscription-active.png" alt="Windows 10 activated and subscription active" /></br></br>
|
||||||
|
|
||||||
|
|
||||||
**Figure 14** - Illustrates a device on which the existing operating system is not activated, but the Windows 10 Pro Education change is active.
|
**Figure 11** - Illustrates a device on which the existing operating system is not activated, but the Windows 10 Pro Education change is active.
|
||||||
|
|
||||||
<img src="images/win-10-pro-edu-not-activated-subscription-active.png" alt="Windows 10 not activated and subscription active" /></br></br>
|
<img src="images/win-10-pro-edu-not-activated-subscription-active.png" alt="Windows 10 not activated and subscription active" /></br></br>
|
||||||
|
|
||||||
@ -260,7 +260,7 @@ Devices must be running Windows 10 Pro, version 1607 or higher, or domain joined
|
|||||||
A popup window will display the Windows 10 version number and detailed OS build information.
|
A popup window will display the Windows 10 version number and detailed OS build information.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If a device is running a previous version of Windows 10 Pro (for example, version 1511), it will not be changeed to Windows 10 Pro Education when a user signs in, even if the user has been assigned a license.
|
> If a device is running a previous version of Windows 10 Pro (for example, version 1511), it will not be changed to Windows 10 Pro Education when a user signs in, even if the user has been assigned a license.
|
||||||
|
|
||||||
### Roll back Windows 10 Pro Education to Windows 10 Pro
|
### Roll back Windows 10 Pro Education to Windows 10 Pro
|
||||||
|
|
||||||
@ -269,10 +269,10 @@ If your organization has the Windows 10 Pro to Windows 10 Pro Education change e
|
|||||||
- Logging into Microsoft Store for Education page and turning off the automatic change.
|
- Logging into Microsoft Store for Education page and turning off the automatic change.
|
||||||
- Selecting the link to turn off the automatic change from the notification email sent to all global administrators.
|
- Selecting the link to turn off the automatic change from the notification email sent to all global administrators.
|
||||||
|
|
||||||
Once the automatic change to Windows 10 Pro Education is turned off, the change is effective immediately. Devices that were changeed will revert to Windows 10 Pro only after the license has been refreshed (every 30 days) and the next time the user signs in. This means that a user whose device was changeed may not immediately see Windows 10 Pro Education rolled back to Windows 10 Pro for up to 30 days. However, users who haven't signed in during the time that a change was enabled and then turned off will never see their device change from Windows 10 Pro.
|
Once the automatic change to Windows 10 Pro Education is turned off, the change is effective immediately. Devices that were changed will revert to Windows 10 Pro only after the license has been refreshed (every 30 days) and the next time the user signs in. This means that a user whose device was changed may not immediately see Windows 10 Pro Education rolled back to Windows 10 Pro for up to 30 days. However, users who haven't signed in during the time that a change was enabled and then turned off will never see their device change from Windows 10 Pro.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Devices that were changeed from mode to Windows 10 Pro Education cannot roll back to Windows 10 Pro Education S mode.
|
> Devices that were changed from mode to Windows 10 Pro Education cannot roll back to Windows 10 Pro Education S mode.
|
||||||
|
|
||||||
**To roll back Windows 10 Pro Education to Windows 10 Pro**
|
**To roll back Windows 10 Pro Education to Windows 10 Pro**
|
||||||
|
|
||||||
@ -280,7 +280,7 @@ Once the automatic change to Windows 10 Pro Education is turned off, the change
|
|||||||
2. Select **Manage > Benefits** and locate the section **Windows 10 Pro Education** and follow the link.
|
2. Select **Manage > Benefits** and locate the section **Windows 10 Pro Education** and follow the link.
|
||||||
3. In the **Revert to Windows 10 Pro** page, click **Revert to Windows 10 Pro**.
|
3. In the **Revert to Windows 10 Pro** page, click **Revert to Windows 10 Pro**.
|
||||||
|
|
||||||
**Figure 15** - Revert to Windows 10 Pro
|
**Figure 12** - Revert to Windows 10 Pro
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -296,9 +296,9 @@ If you have on-premises Active Directory Domain Services (AD DS) domains, users
|
|||||||
|
|
||||||
You need to synchronize these identities so that users will have a *single identity* that they can use to access their on-premises apps and cloud services that use Azure AD (such as Windows 10 Pro Education). This means that users can use their existing credentials to sign in to Azure AD and access the cloud services that you provide and manage for them.
|
You need to synchronize these identities so that users will have a *single identity* that they can use to access their on-premises apps and cloud services that use Azure AD (such as Windows 10 Pro Education). This means that users can use their existing credentials to sign in to Azure AD and access the cloud services that you provide and manage for them.
|
||||||
|
|
||||||
Figure 11 illustrates the integration between the on-premises AD DS domain with Azure AD. [Microsoft Azure Active Directory Connect](https://www.microsoft.com/en-us/download/details.aspx?id=47594) (Azure AD Connect) is responsible for synchronization of identities between the on-premises AD DS domain and Azure AD. Azure AD Connect is a service that you can install on-premises or in a virtual machine in Azure.
|
(Azure AD Connect) is responsible for synchronization of identities between the on-premises AD DS domain and Azure AD. Azure AD Connect is a service that you can install on-premises or in a virtual machine in Azure.
|
||||||
|
|
||||||
**Figure 16** - On-premises AD DS integrated with Azure AD
|
**Figure 13** - On-premises AD DS integrated with Azure AD
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -308,6 +308,6 @@ For more information about integrating on-premises AD DS domains with Azure AD,
|
|||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)
|
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)<BR>
|
||||||
[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md)
|
[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md)<BR>
|
||||||
[Compare Windows 10 editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare)
|
[Compare Windows 10 editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare)
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 03/23/2018
|
|||||||
|
|
||||||
# AccountManagement CSP
|
# AccountManagement CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
AccountManagement CSP is used to configure setting in the Account Manager service in Windows Holographic for Business edition. Added in Windows 10, version 1803.
|
AccountManagement CSP is used to configure setting in the Account Manager service in Windows Holographic for Business edition. Added in Windows 10, version 1803.
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/23/2018
|
|||||||
|
|
||||||
# AccountManagement DDF file
|
# AccountManagement DDF file
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **AccountManagement** configuration service provider.
|
This topic shows the OMA DM device description framework (DDF) for the **AccountManagement** configuration service provider.
|
||||||
|
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 04/17/2018
|
|||||||
|
|
||||||
# Accounts CSP
|
# Accounts CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The Accounts configuration service provider (CSP) is used by the enterprise (1) to rename a device, (2) to create a new local Windows account and joint it to a local user group. This CSP was added in Windows 10, version 1803.
|
The Accounts configuration service provider (CSP) is used by the enterprise (1) to rename a device, (2) to create a new local Windows account and joint it to a local user group. This CSP was added in Windows 10, version 1803.
|
||||||
|
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 04/17/2018
|
|||||||
|
|
||||||
# Accounts CSP
|
# Accounts CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **Accounts** configuration service provider.
|
This topic shows the OMA DM device description framework (DDF) for the **Accounts** configuration service provider.
|
||||||
|
|
||||||
|
@ -35,8 +35,11 @@ A JSON string that contains the user account name and Application User Model ID
|
|||||||
For a step-by-step guide for setting up devices to run in kiosk mode, see [Set up a kiosk on Windows 10 Pro, Enterprise, or Education.](http://go.microsoft.com/fwlink/p/?LinkID=722211)
|
For a step-by-step guide for setting up devices to run in kiosk mode, see [Set up a kiosk on Windows 10 Pro, Enterprise, or Education.](http://go.microsoft.com/fwlink/p/?LinkID=722211)
|
||||||
|
|
||||||
> [!Note]
|
> [!Note]
|
||||||
> You cannot set both KioskModeApp and Configuration at the same time in the device in Windows 10, version 1709.
|
> In Windows 10, version 1803 the Configuration node introduces single app kiosk profile to replace KioskModeApp CSP node. KioskModeApp node will be deprecated soon, so you should use the single app kiosk profile in config xml for Configuration node to configure public-facing single app Kiosk.
|
||||||
>
|
>
|
||||||
|
> Starting in Windows 10, version 1803 the KioskModeApp node becomes No-Op if Configuration node is configured on the device. That Add/Replace/Delete command on KioskModeApp node always returns SUCCESS to the MDM server if Configuration node is set, but the data of KioskModeApp will not take any effect on the device. Get command on KioskModeApp will return the configured JSON string even it’s not effective.
|
||||||
|
|
||||||
|
> [!Note]
|
||||||
> You cannot set both KioskModeApp and ShellLauncher at the same time on the device.
|
> You cannot set both KioskModeApp and ShellLauncher at the same time on the device.
|
||||||
|
|
||||||
Starting in Windows 10, version 1607, you can use a provisioned app to configure the kiosk mode. For more information about how to remotely provision an app, see [Enterprise app management](enterprise-app-management.md).
|
Starting in Windows 10, version 1607, you can use a provisioned app to configure the kiosk mode. For more information about how to remotely provision an app, see [Enterprise app management](enterprise-app-management.md).
|
||||||
@ -66,7 +69,9 @@ The supported operations are Add, Delete, Get and Replace. When there's no confi
|
|||||||
Added in Windows 10, version 1709. Specifies the settings that you can configure in the kiosk or device. This node accepts an AssignedAccessConfiguration xml as input to configure the device experience. For details about the configuration settings in the XML, see [Create a Windows 10 kiosk that runs multiple apps](https://docs.microsoft.com/en-us/windows/configuration/lock-down-windows-10-to-specific-apps). Here is the schema for the [AssignedAccessConfiguration](#assignedaccessconfiguration-xsd).
|
Added in Windows 10, version 1709. Specifies the settings that you can configure in the kiosk or device. This node accepts an AssignedAccessConfiguration xml as input to configure the device experience. For details about the configuration settings in the XML, see [Create a Windows 10 kiosk that runs multiple apps](https://docs.microsoft.com/en-us/windows/configuration/lock-down-windows-10-to-specific-apps). Here is the schema for the [AssignedAccessConfiguration](#assignedaccessconfiguration-xsd).
|
||||||
|
|
||||||
> [!Note]
|
> [!Note]
|
||||||
> You cannot set both KioskModeApp and Configuration at the same time on the device in Windows 10, version 1709.
|
> In Windows 10, version 1803 the Configuration node introduces single app kiosk profile to replace KioskModeApp CSP node. KioskModeApp node will be deprecated soon, so you should use the single app kiosk profile in config xml for Configuration node to configure public-facing single app Kiosk.
|
||||||
|
>
|
||||||
|
> Starting in Windows 10, version 1803 the KioskModeApp node becomes No-Op if Configuration node is configured on the device. That Add/Replace/Delete command on KioskModeApp node always returns SUCCESS to the MDM server if Configuration node is set, but the data of KioskModeApp will not take any effect on the device. Get command on KioskModeApp will return the configured JSON string even it’s not effective.
|
||||||
|
|
||||||
Enterprises can use this to easily configure and manage the curated lockdown experience.
|
Enterprises can use this to easily configure and manage the curated lockdown experience.
|
||||||
|
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 02/22/2018
|
|||||||
# AssignedAccess DDF
|
# AssignedAccess DDF
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **AssignedAccess** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
This topic shows the OMA DM device description framework (DDF) for the **AssignedAccess** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
||||||
|
|
||||||
You can download the DDF files from the links below:
|
You can download the DDF files from the links below:
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 01/04/2018
|
|||||||
|
|
||||||
# BitLocker CSP
|
# BitLocker CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The BitLocker configuration service provider (CSP) is used by the enterprise to manage encryption of PCs and devices. This CSP was added in Windows 10, version 1703.
|
The BitLocker configuration service provider (CSP) is used by the enterprise to manage encryption of PCs and devices. This CSP was added in Windows 10, version 1703.
|
||||||
|
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 01/29/2018
|
|||||||
# Defender CSP
|
# Defender CSP
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The Windows Defender configuration service provider is used to configure various Windows Defender actions across the enterprise.
|
The Windows Defender configuration service provider is used to configure various Windows Defender actions across the enterprise.
|
||||||
|
|
||||||
The following image shows the Windows Defender configuration service provider in tree format.
|
The following image shows the Windows Defender configuration service provider in tree format.
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 01/29/20178
|
|||||||
# Defender DDF file
|
# Defender DDF file
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **Defender** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
This topic shows the OMA DM device description framework (DDF) for the **Defender** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
||||||
|
|
||||||
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 11/01/2017
|
|||||||
# DMClient CSP
|
# DMClient CSP
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The DMClient configuration service provider is used to specify additional enterprise-specific mobile device management configuration settings for identifying the device in the enterprise domain, security mitigation for certificate renewal, and server-triggered enterprise unenrollment.
|
The DMClient configuration service provider is used to specify additional enterprise-specific mobile device management configuration settings for identifying the device in the enterprise domain, security mitigation for certificate renewal, and server-triggered enterprise unenrollment.
|
||||||
|
|
||||||
The following diagram shows the DMClient configuration service provider in tree format.
|
The following diagram shows the DMClient configuration service provider in tree format.
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 12/05/2017
|
|||||||
# DMClient DDF file
|
# DMClient DDF file
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **DMClient** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
This topic shows the OMA DM device description framework (DDF) for the **DMClient** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
||||||
|
|
||||||
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 03/01/2018
|
|||||||
# EnterpriseModernAppManagement CSP
|
# EnterpriseModernAppManagement CSP
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The EnterpriseModernAppManagement configuration service provider (CSP) is used for the provisioning and reporting of modern enterprise apps. For details about how to use this CSP to for reporting apps inventory, installation and removal of apps for users, provisioning apps to devices, and managing app licenses, see [Enterprise app management](enterprise-app-management.md).
|
The EnterpriseModernAppManagement configuration service provider (CSP) is used for the provisioning and reporting of modern enterprise apps. For details about how to use this CSP to for reporting apps inventory, installation and removal of apps for users, provisioning apps to devices, and managing app licenses, see [Enterprise app management](enterprise-app-management.md).
|
||||||
|
|
||||||
> [!Note]
|
> [!Note]
|
||||||
|
@ -13,9 +13,6 @@ ms.date: 03/01/2018
|
|||||||
# EnterpriseModernAppManagement DDF
|
# EnterpriseModernAppManagement DDF
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **EnterpriseModernAppManagement** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
This topic shows the OMA DM device description framework (DDF) for the **EnterpriseModernAppManagement** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
||||||
|
|
||||||
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 03/22/2018
|
|||||||
|
|
||||||
# MultiSIM CSP
|
# MultiSIM CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The MultiSIM configuration service provider (CSP) is used by the enterprise to manage devices with dual SIM single active configuration. An enterprise can set policies on whether that user can switch between SIM slots, specify which slot is the default, and whether the slot is embedded. This CSP was added in Windows 10, version 1803.
|
The MultiSIM configuration service provider (CSP) is used by the enterprise to manage devices with dual SIM single active configuration. An enterprise can set policies on whether that user can switch between SIM slots, specify which slot is the default, and whether the slot is embedded. This CSP was added in Windows 10, version 1803.
|
||||||
|
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 02/27/2018
|
|||||||
|
|
||||||
# MultiSIM CSP
|
# MultiSIM CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **MultiSIM** configuration service provider.
|
This topic shows the OMA DM device description framework (DDF) for the **MultiSIM** configuration service provider.
|
||||||
|
|
||||||
|
@ -16,10 +16,6 @@ ms.date: 04/26/2018
|
|||||||
# What's new in MDM enrollment and management
|
# What's new in MDM enrollment and management
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices.
|
This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices.
|
||||||
|
|
||||||
For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](http://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347).
|
For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](http://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347).
|
||||||
@ -1203,6 +1199,7 @@ For details about Microsoft mobile device management protocols for Windows 10 s
|
|||||||
<li>LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems</li>
|
<li>LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems</li>
|
||||||
<li>LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation</li>
|
<li>LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation</li>
|
||||||
<li>LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode</li>
|
<li>LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode</li>
|
||||||
|
<li>Notifications/DisallowCloudNotification</li>
|
||||||
<li>RestrictedGroups/ConfigureGroupMembership</li>
|
<li>RestrictedGroups/ConfigureGroupMembership</li>
|
||||||
<li>Search/AllowCortanaInAAD</li>
|
<li>Search/AllowCortanaInAAD</li>
|
||||||
<li>Search/DoNotUseWebResults</li>
|
<li>Search/DoNotUseWebResults</li>
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - AccountPoliciesAccountLockoutPolicy
|
# Policy CSP - AccountPoliciesAccountLockoutPolicy
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - ApplicationDefaults
|
# Policy CSP - ApplicationDefaults
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - ApplicationManagement
|
# Policy CSP - ApplicationManagement
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - AppRuntime
|
# Policy CSP - AppRuntime
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/06/2018
|
|||||||
|
|
||||||
# Policy CSP - Bluetooth
|
# Policy CSP - Bluetooth
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - Browser
|
# Policy CSP - Browser
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/14/2018
|
|||||||
|
|
||||||
# Policy CSP - Connectivity
|
# Policy CSP - Connectivity
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - ControlPolicyConflict
|
# Policy CSP - ControlPolicyConflict
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - CredentialsDelegation
|
# Policy CSP - CredentialsDelegation
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - DeliveryOptimization
|
# Policy CSP - DeliveryOptimization
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - DeviceLock
|
# Policy CSP - DeviceLock
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - Display
|
# Policy CSP - Display
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - Experience
|
# Policy CSP - Experience
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - FileExplorer
|
# Policy CSP - FileExplorer
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,8 +11,6 @@ ms.date: 04/11/2018
|
|||||||
|
|
||||||
# Policy CSP - KioskBrowser
|
# Policy CSP - KioskBrowser
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
These policies currently only apply to Kiosk Browser app. Kiosk Browser is a Microsoft Store app, added in Windows 10 version 1803, that provides IT a way to customize the end user’s browsing experience to fulfill kiosk, signage, and shared device scenarios. Application developers can also create their own kiosk browser and read these policies using [NamedPolicy.GetPolicyFromPath(String, String) Method](https://docs.microsoft.com/en-us/uwp/api/windows.management.policies.namedpolicy.getpolicyfrompath#Windows_Management_Policies_NamedPolicy_GetPolicyFromPath_System_String_System_String_).
|
These policies currently only apply to Kiosk Browser app. Kiosk Browser is a Microsoft Store app, added in Windows 10 version 1803, that provides IT a way to customize the end user’s browsing experience to fulfill kiosk, signage, and shared device scenarios. Application developers can also create their own kiosk browser and read these policies using [NamedPolicy.GetPolicyFromPath(String, String) Method](https://docs.microsoft.com/en-us/uwp/api/windows.management.policies.namedpolicy.getpolicyfrompath#Windows_Management_Policies_NamedPolicy_GetPolicyFromPath_System_String_System_String_).
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - LanmanWorkstation
|
# Policy CSP - LanmanWorkstation
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/06/2018
|
|||||||
|
|
||||||
# Policy CSP - LocalPoliciesSecurityOptions
|
# Policy CSP - LocalPoliciesSecurityOptions
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - MSSecurityGuide
|
# Policy CSP - MSSecurityGuide
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - MSSLegacy
|
# Policy CSP - MSSLegacy
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - Notifications
|
# Policy CSP - Notifications
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/15/2018
|
|||||||
|
|
||||||
# Policy CSP - RestrictedGroups
|
# Policy CSP - RestrictedGroups
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - Search
|
# Policy CSP - Search
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - Security
|
# Policy CSP - Security
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - Settings
|
# Policy CSP - Settings
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - System
|
# Policy CSP - System
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - SystemServices
|
# Policy CSP - SystemServices
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - TaskScheduler
|
# Policy CSP - TaskScheduler
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - TextInput
|
# Policy CSP - TextInput
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - Update
|
# Policy CSP - Update
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - UserRights
|
# Policy CSP - UserRights
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - WindowsConnectionManager
|
# Policy CSP - WindowsConnectionManager
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 03/12/2018
|
|||||||
|
|
||||||
# Policy CSP - WindowsDefenderSecurityCenter
|
# Policy CSP - WindowsDefenderSecurityCenter
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -11,9 +11,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
# Policy CSP - WindowsPowerShell
|
# Policy CSP - WindowsPowerShell
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
<hr/>
|
<hr/>
|
||||||
|
|
||||||
|
@ -12,8 +12,6 @@ ms.date: 03/06/2018
|
|||||||
|
|
||||||
# RootCATrustedCertificates CSP
|
# RootCATrustedCertificates CSP
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The RootCATrustedCertificates configuration service provider enables the enterprise to set the Root Certificate Authority (CA) certificates.
|
The RootCATrustedCertificates configuration service provider enables the enterprise to set the Root Certificate Authority (CA) certificates.
|
||||||
|
|
||||||
|
@ -12,8 +12,6 @@ ms.date: 03/07/2018
|
|||||||
|
|
||||||
# RootCATrustedCertificates DDF file
|
# RootCATrustedCertificates DDF file
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **RootCACertificates** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
This topic shows the OMA DM device description framework (DDF) for the **RootCACertificates** configuration service provider. DDF files are used only with OMA DM provisioning XML.
|
||||||
|
|
||||||
|
@ -12,9 +12,6 @@ ms.date: 02/01/2018
|
|||||||
# UEFI CSP
|
# UEFI CSP
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
The UEFI configuration service provider (CSP) interfaces to UEFI's Device Firmware Configuration Interface (DFCI) to make BIOS configuration changes. This CSP was added in Windows 10, version 1803.
|
The UEFI configuration service provider (CSP) interfaces to UEFI's Device Firmware Configuration Interface (DFCI) to make BIOS configuration changes. This CSP was added in Windows 10, version 1803.
|
||||||
|
|
||||||
The following diagram shows the UEFI CSP in tree format.
|
The following diagram shows the UEFI CSP in tree format.
|
||||||
|
@ -12,10 +12,6 @@ ms.date: 02/01/2018
|
|||||||
# UEFI DDF file
|
# UEFI DDF file
|
||||||
|
|
||||||
|
|
||||||
> [!WARNING]
|
|
||||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
|
||||||
|
|
||||||
|
|
||||||
This topic shows the OMA DM device description framework (DDF) for the **Uefi** configuration service provider.
|
This topic shows the OMA DM device description framework (DDF) for the **Uefi** configuration service provider.
|
||||||
|
|
||||||
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download).
|
||||||
|
@ -15,6 +15,12 @@ ms.date: 04/30/2018
|
|||||||
|
|
||||||
This topic lists new and updated topics in the [Configure Windows 10](index.md) documentation for Windows 10 and Windows 10 Mobile.
|
This topic lists new and updated topics in the [Configure Windows 10](index.md) documentation for Windows 10 and Windows 10 Mobile.
|
||||||
|
|
||||||
|
## May 2018
|
||||||
|
|
||||||
|
New or changed topic | Description
|
||||||
|
--- | ---
|
||||||
|
[Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Added note that Wi-Fi Sense is no longer available.
|
||||||
|
|
||||||
## RELEASE: Windows 10, version 1803
|
## RELEASE: Windows 10, version 1803
|
||||||
|
|
||||||
The topics in this library have been updated for Windows 10, version 1803. The following new topics have been added:
|
The topics in this library have been updated for Windows 10, version 1803. The following new topics have been added:
|
||||||
|
@ -9,7 +9,7 @@ ms.sitesec: library
|
|||||||
ms.pagetype: mobile
|
ms.pagetype: mobile
|
||||||
author: eross-msft
|
author: eross-msft
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.date: 07/27/2017
|
ms.date: 05/02/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Manage Wi-Fi Sense in your company
|
# Manage Wi-Fi Sense in your company
|
||||||
@ -18,7 +18,8 @@ ms.date: 07/27/2017
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
- Windows 10 Mobile
|
- Windows 10 Mobile
|
||||||
|
|
||||||
>Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare).
|
>[!IMPORTANT]
|
||||||
|
>Beginning with Windows 10, version 1803, Wifi-Sense is no longer available. The following information only applies to Windows 10, version 1709 and prior. Please see [Connecting to open Wi-Fi hotspots in Windows 10](https://privacy.microsoft.com/windows-10-open-wi-fi-hotspots) for more details.
|
||||||
|
|
||||||
Wi-Fi Sense learns about open Wi-Fi hotspots your Windows PC or Windows phone connects to by collecting information about the network, like whether the open Wi-Fi network has a high-quality connection to the Internet. By using that information from your device and from other Wi-Fi Sense customers' devices too, Wi-Fi Sense builds a database of these high-quality networks. When you’re in range of one of these Wi-Fi hotspots, you automatically get connected to it.
|
Wi-Fi Sense learns about open Wi-Fi hotspots your Windows PC or Windows phone connects to by collecting information about the network, like whether the open Wi-Fi network has a high-quality connection to the Internet. By using that information from your device and from other Wi-Fi Sense customers' devices too, Wi-Fi Sense builds a database of these high-quality networks. When you’re in range of one of these Wi-Fi hotspots, you automatically get connected to it.
|
||||||
|
|
||||||
|
@ -46,11 +46,6 @@ X = unsupported <BR>
|
|||||||
| **Home > Pro for Workstations** |  |  |  |  |  |  |
|
| **Home > Pro for Workstations** |  |  |  |  |  |  |
|
||||||
| **Home > Pro Education** |  |  |  |  |  |  |
|
| **Home > Pro Education** |  |  |  |  |  |  |
|
||||||
| **Home > Education** |  |  |  |  |  |  |
|
| **Home > Education** |  |  |  |  |  |  |
|
||||||
<!-- | **S > Pro** |  <br>(1709) |  <br>(1709) |  |  |  <br>(1709) |  <br>(1709) |
|
|
||||||
| **S > Pro for Workstations** |  <br>(1709) |  <br>(1709) |  |  |  <br>(1709) |  <br>(1709) |
|
|
||||||
| **S > Pro Education** |  <br>(1709) |  <br>(1709) |  |  <br>(1709 - MSfB) |  <br>(1709) |  |
|
|
||||||
| **S > Education** |  |  |  |  <br>(MSfB) |  |  |
|
|
||||||
| **S > Enterprise** |  <br>(1709) |  <br>(1709) |  |  <br>(1703 - PC)<br>(1709 - MSfB) |  <br>(1709) |  | -->
|
|
||||||
| **Pro > Pro for Workstations** |  |  |  |  <br>(MSfB) |  |  |
|
| **Pro > Pro for Workstations** |  |  |  |  <br>(MSfB) |  |  |
|
||||||
| **Pro > Pro Education** |  |  |  |  <br>(MSfB) |  |  |
|
| **Pro > Pro Education** |  |  |  |  <br>(MSfB) |  |  |
|
||||||
| **Pro > Education** |  |  |  |  <br>(MSfB) |  |  |
|
| **Pro > Education** |  |  |  |  <br>(MSfB) |  |  |
|
||||||
|
@ -63,4 +63,4 @@ You'll be prompted to save your files before the switch starts. Follow the promp
|
|||||||
|
|
||||||
[Compare Windows 10 editions](https://www.microsoft.com/WindowsForBusiness/Compare)<BR>
|
[Compare Windows 10 editions](https://www.microsoft.com/WindowsForBusiness/Compare)<BR>
|
||||||
[Windows 10 Pro Education](https://docs.microsoft.com/education/windows/test-windows10s-for-edu)<BR>
|
[Windows 10 Pro Education](https://docs.microsoft.com/education/windows/test-windows10s-for-edu)<BR>
|
||||||
[Introdiction to Microsoft Intune in the Azure portal](https://docs.microsoft.com/en-us/intune/what-is-intune)
|
[Introduction to Microsoft Intune in the Azure portal](https://docs.microsoft.com/en-us/intune/what-is-intune)
|
||||||
|
@ -24,7 +24,7 @@ The recovery process included in this topic only works for desktop devices. WIP
|
|||||||
>[!IMPORTANT]
|
>[!IMPORTANT]
|
||||||
>If you already have an EFS DRA certificate for your organization, you can skip creating a new one. Just use your current EFS DRA certificate in your policy. For more info about when to use a PKI and the general strategy you should use to deploy DRA certificates, see the [Security Watch Deploying EFS: Part 1](https://technet.microsoft.com/magazine/2007.02.securitywatch.aspx) article on TechNet. For more general info about EFS protection, see [Protecting Data by Using EFS to Encrypt Hard Drives](https://msdn.microsoft.com/library/cc875821.aspx).<br><br>If your DRA certificate has expired, you won’t be able to encrypt your files with it. To fix this, you'll need to create a new certificate, using the steps in this topic, and then deploy it through policy.
|
>If you already have an EFS DRA certificate for your organization, you can skip creating a new one. Just use your current EFS DRA certificate in your policy. For more info about when to use a PKI and the general strategy you should use to deploy DRA certificates, see the [Security Watch Deploying EFS: Part 1](https://technet.microsoft.com/magazine/2007.02.securitywatch.aspx) article on TechNet. For more general info about EFS protection, see [Protecting Data by Using EFS to Encrypt Hard Drives](https://msdn.microsoft.com/library/cc875821.aspx).<br><br>If your DRA certificate has expired, you won’t be able to encrypt your files with it. To fix this, you'll need to create a new certificate, using the steps in this topic, and then deploy it through policy.
|
||||||
|
|
||||||
**To manually create an EFS DRA certificate**
|
## Manually create an EFS DRA certificate
|
||||||
|
|
||||||
1. On a computer without an EFS DRA certificate installed, open a command prompt with elevated rights, and then navigate to where you want to store the certificate.
|
1. On a computer without an EFS DRA certificate installed, open a command prompt with elevated rights, and then navigate to where you want to store the certificate.
|
||||||
|
|
||||||
@ -46,7 +46,7 @@ The recovery process included in this topic only works for desktop devices. WIP
|
|||||||
>[!Note]
|
>[!Note]
|
||||||
>To add your EFS DRA certificate to your policy by using Microsoft Intune, see the [Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune.md) topic. To add your EFS DRA certificate to your policy by using System Center Configuration Manager, see the [Create a Windows Information Protection (WIP) policy using System Center Configuration Manager](create-wip-policy-using-sccm.md) topic.
|
>To add your EFS DRA certificate to your policy by using Microsoft Intune, see the [Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune.md) topic. To add your EFS DRA certificate to your policy by using System Center Configuration Manager, see the [Create a Windows Information Protection (WIP) policy using System Center Configuration Manager](create-wip-policy-using-sccm.md) topic.
|
||||||
|
|
||||||
**To verify your data recovery certificate is correctly set up on a WIP client computer**
|
## Verify your data recovery certificate is correctly set up on a WIP client computer
|
||||||
|
|
||||||
1. Find or create a file that's encrypted using Windows Information Protection. For example, you could open an app on your allowed app list, and then create and save a file so it’s encrypted by WIP.
|
1. Find or create a file that's encrypted using Windows Information Protection. For example, you could open an app on your allowed app list, and then create and save a file so it’s encrypted by WIP.
|
||||||
|
|
||||||
@ -60,7 +60,7 @@ The recovery process included in this topic only works for desktop devices. WIP
|
|||||||
|
|
||||||
4. Make sure that your data recovery certificate is listed in the **Recovery Certificates** list.
|
4. Make sure that your data recovery certificate is listed in the **Recovery Certificates** list.
|
||||||
|
|
||||||
**To recover your data using the EFS DRA certificate in a test environment**
|
## Recover your data using the EFS DRA certificate in a test environment
|
||||||
|
|
||||||
1. Copy your WIP-encrypted file to a location where you have admin access.
|
1. Copy your WIP-encrypted file to a location where you have admin access.
|
||||||
|
|
||||||
@ -72,18 +72,26 @@ The recovery process included in this topic only works for desktop devices. WIP
|
|||||||
|
|
||||||
Where *encryptedfile.extension* is the name of your encrypted file. For example, corporatedata.docx.
|
Where *encryptedfile.extension* is the name of your encrypted file. For example, corporatedata.docx.
|
||||||
|
|
||||||
**To quickly recover WIP-protected desktop data after unenrollment**
|
## Recover WIP-protected after unenrollment
|
||||||
|
|
||||||
It's possible that you might revoke data from an unenrolled device only to later want to restore it all. This can happen in the case of a missing device being returned or if an unenrolled employee enrolls again. If the employee enrolls again using the original user profile, and the revoked key store is still on the device, all of the revoked data can be restored at once, by following these steps.
|
It's possible that you might revoke data from an unenrolled device only to later want to restore it all. This can happen in the case of a missing device being returned or if an unenrolled employee enrolls again. If the employee enrolls again using the original user profile, and the revoked key store is still on the device, all of the revoked data can be restored at once.
|
||||||
|
|
||||||
>[!IMPORTANT]
|
>[!IMPORTANT]
|
||||||
>To maintain control over your enterprise data, and to be able to revoke again in the future, you must only perform this process after the employee has re-enrolled the device.
|
>To maintain control over your enterprise data, and to be able to revoke again in the future, you must only perform this process after the employee has re-enrolled the device.
|
||||||
|
|
||||||
1. Have your employee sign in to the unenrolled device, open a command prompt, and type:
|
1. Have the employee sign in to the unenrolled device, open an elevated command prompt, and type:
|
||||||
|
|
||||||
<code>Robocopy “%localappdata%\Microsoft\EDP\Recovery” “<i>new_location</i>” /EFSRAW</code>
|
<code>Robocopy "%localappdata%\Microsoft\EDP\Recovery" "<i>new_location</i>" * /EFSRAW</code>
|
||||||
|
|
||||||
Where ”*new_location*" is in a different directory. This can be on the employee’s device or on a Windows 8 or Windows Server 2012 or newer server file share that can be accessed while you're logged in as a data recovery agent.
|
Where "*new_location*" is in a different directory. This can be on the employee’s device or on a shared folder on a computer that runs Windows 8 or Windows Server 2012 or newer and can be accessed while you're logged in as a data recovery agent.
|
||||||
|
|
||||||
|
To start Robocopy in S mode, open Task Manager. Click **File** > **Run new task**, type the command, and click **Create this task with administrative privileges**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
If the employee performed a clean installation and there is no user profile, you need to recover the keys from the System Volume folder in each drive. Type:
|
||||||
|
|
||||||
|
<code>Robocopy "<i>drive_letter</i>:\System Volume Information\EDP\Recovery\" "<i>new_location</i>" * /EFSRAW</code>
|
||||||
|
|
||||||
2. Sign in to a different device with administrator credentials that have access to your organization's DRA certificate, and perform the file decryption and recovery by typing:
|
2. Sign in to a different device with administrator credentials that have access to your organization's DRA certificate, and perform the file decryption and recovery by typing:
|
||||||
|
|
||||||
@ -91,41 +99,11 @@ It's possible that you might revoke data from an unenrolled device only to later
|
|||||||
|
|
||||||
3. Have your employee sign in to the unenrolled device, and type:
|
3. Have your employee sign in to the unenrolled device, and type:
|
||||||
|
|
||||||
<code>Robocopy "<i>new_location</i>" “%localappdata%\Microsoft\EDP\Recovery\Input”</code>
|
<code>Robocopy "<i>new_location</i>" "%localappdata%\Microsoft\EDP\Recovery\Input"</code>
|
||||||
|
|
||||||
4. Ask the employee to lock and unlock the device.
|
4. Ask the employee to lock and unlock the device.
|
||||||
|
|
||||||
The Windows Credential service automatically recovers the employee’s previously revoked keys from the <code>Recovery\Input</code> location.
|
The Windows Credential service automatically recovers the employee’s previously revoked keys from the `Recovery\Input` location.
|
||||||
|
|
||||||
**To quickly recover WIP-protected desktop data in a cloud-based environment**
|
|
||||||
|
|
||||||
If you use a cloud environment in your organization, you may still want to restore an employee's data after revocation. While much of the process is the same as when you're not in a cloud environment, there are a couple of differences.
|
|
||||||
|
|
||||||
>[!IMPORTANT]
|
|
||||||
>To maintain control over your enterprise data, and to be able to revoke again in the future, you must only perform this process after the employee has re-enrolled the device.
|
|
||||||
|
|
||||||
1. Have your employee sign in to the device that has revoked data for you to restore, open the **Run** command (Windows logo key + R), and type one of the following commands:
|
|
||||||
|
|
||||||
- If the keys are still stored within the employee's profile, type: <code>Robocopy “%localappdata%\Microsoft\EDP\Recovery” “<i>new_location</i>” * /EFSRAW</code>
|
|
||||||
|
|
||||||
-or-
|
|
||||||
|
|
||||||
- If the employee performed a clean installation over the operating system and you need to recover the keys from the System Volume folder, type: <code>Robocopy “<i>drive_letter:</i>\System Volume Information\EDP\Recovery\” "<i>new_location</i>” * /EFSRAW></code>
|
|
||||||
|
|
||||||
>[!Important]
|
|
||||||
>The “*new_location*” must be in a different directory, either on the employee’s device or on a Windows 8 or Windows Server 2012 or newer server file share, which can be accessed while you're logged in as a data recovery agent.
|
|
||||||
|
|
||||||
2. Sign in to a different device with administrator credentials that have access to your organization's DRA certificate private key, and perform the file decryption and recovery by typing:
|
|
||||||
|
|
||||||
<code>cipher.exe /D “<i>new_location</i>”</code>
|
|
||||||
|
|
||||||
3. Have your employee sign in to the device again, open the **Run** command, and type:
|
|
||||||
|
|
||||||
<code>Robocopy “<i>new_location</i>” “%localappdata%\Microsoft\EDP\Recovery\Input”</code>
|
|
||||||
|
|
||||||
4. Ask the employee to lock and unlock the device.
|
|
||||||
|
|
||||||
The Windows Credential service automatically recovers the employee’s previously revoked keys from the <code>Recovery\Input</code> location. All your company’s previously revoked files should be accessible to the employee again.
|
|
||||||
|
|
||||||
## Auto-recovery of encryption keys
|
## Auto-recovery of encryption keys
|
||||||
Starting with Windows 10, version 1709, WIP includes a data recovery feature that lets your employees auto-recover access to work files if the encryption key is lost and the files are no longer accessible. This typically happens if an employee reimages the operating system partition, removing the WIP key info, or if a device is reported as lost and you mistakenly target the wrong device for unenrollment.
|
Starting with Windows 10, version 1709, WIP includes a data recovery feature that lets your employees auto-recover access to work files if the encryption key is lost and the files are no longer accessible. This typically happens if an employee reimages the operating system partition, removing the WIP key info, or if a device is reported as lost and you mistakenly target the wrong device for unenrollment.
|
||||||
|
Binary file not shown.
Before Width: | Height: | Size: 9.9 KiB After Width: | Height: | Size: 9.5 KiB |
@ -11,13 +11,9 @@ ms.pagetype: security
|
|||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
author: andreabichsel
|
author: andreabichsel
|
||||||
ms.author: v-anbic
|
ms.author: v-anbic
|
||||||
ms.date: 04/30/2018
|
ms.date: 05/02/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Enable the Block at First Sight feature
|
# Enable the Block at First Sight feature
|
||||||
|
|
||||||
**Applies to**
|
**Applies to**
|
||||||
@ -30,6 +26,7 @@ ms.date: 04/30/2018
|
|||||||
|
|
||||||
**Manageability available with**
|
**Manageability available with**
|
||||||
|
|
||||||
|
- Intune
|
||||||
- Group Policy
|
- Group Policy
|
||||||
- Windows Defender Security Center app
|
- Windows Defender Security Center app
|
||||||
|
|
||||||
@ -58,8 +55,6 @@ In Windows 10, version 1803, the Block at First Sight feature can now block non-
|
|||||||
|
|
||||||
The Block at First Sight feature only uses the cloud protection backend for executable files and non-portable executable files that are downloaded from the Internet, or originating from the Internet zone. A hash value of the .exe file is checked via the cloud backend to determine if this is a previously undetected file.
|
The Block at First Sight feature only uses the cloud protection backend for executable files and non-portable executable files that are downloaded from the Internet, or originating from the Internet zone. A hash value of the .exe file is checked via the cloud backend to determine if this is a previously undetected file.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
If the cloud backend is unable to make a determination, the file will be locked by Windows Defender AV while a copy is uploaded to the cloud. The cloud will perform additional analysis to reach a determination before it allows the file to run or blocks it in all future encounters, depending on whether the file is determined to be malicious or safe.
|
If the cloud backend is unable to make a determination, the file will be locked by Windows Defender AV while a copy is uploaded to the cloud. The cloud will perform additional analysis to reach a determination before it allows the file to run or blocks it in all future encounters, depending on whether the file is determined to be malicious or safe.
|
||||||
|
|
||||||
In many cases this process can reduce the response time for new malware from hours to seconds.
|
In many cases this process can reduce the response time for new malware from hours to seconds.
|
||||||
@ -69,6 +64,23 @@ In many cases this process can reduce the response time for new malware from hou
|
|||||||
|
|
||||||
Block at First Sight requires a number of Group Policy settings to be configured correctly or it will not work. Usually, these settings are already enabled in most default Windows Defender AV deployments in enterprise networks.
|
Block at First Sight requires a number of Group Policy settings to be configured correctly or it will not work. Usually, these settings are already enabled in most default Windows Defender AV deployments in enterprise networks.
|
||||||
|
|
||||||
|
### Confirm Block at First Sight is enabled with Intune
|
||||||
|
|
||||||
|
1. In Intune, navigate to **Device configuration - Profiles > *Profile name* > Device restrictions > Windows Defender Antivirus**.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> The profile you select must be a Device Restriction profile type, not an Endpoint Protection profile type.
|
||||||
|
|
||||||
|
2. Verify these settings are configured as follows:
|
||||||
|
|
||||||
|
- **Cloud-delivered protection**: **Enable**
|
||||||
|
- **File Blocking Level**: **High**
|
||||||
|
- **Time extension for file scanning by the cloud**: **50**
|
||||||
|
- **Prompt users before sample submission**: **Send all data without prompting**
|
||||||
|
|
||||||
|
For more information about configuring Windows Defender AV device restrictions in Intune, see [Configure device restriction settings in Microsoft Intune](https://docs.microsoft.com/en-us/intune/device-restrictions-configure).
|
||||||
|
|
||||||
|
For a list of Windows Defender AV device restrictions in Intune, see [Device restriction for Windows 10 (and newer) settings in Intune](https://docs.microsoft.com/en-us/intune/device-restrictions-windows-10#windows-defender-antivirus).
|
||||||
|
|
||||||
|
|
||||||
### Confirm Block at First Sight is enabled with Group Policy
|
### Confirm Block at First Sight is enabled with Group Policy
|
||||||
@ -113,7 +125,7 @@ The feature is automatically enabled as long as **Cloud-based protection** and *
|
|||||||
|
|
||||||
2. Click the **Virus & threat protection** tile (or the shield icon on the left menu bar) and then the **Virus & threat protection settings** label:
|
2. Click the **Virus & threat protection** tile (or the shield icon on the left menu bar) and then the **Virus & threat protection settings** label:
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
3. Confirm that **Cloud-based Protection** and **Automatic sample submission** are switched to **On**.
|
3. Confirm that **Cloud-based Protection** and **Automatic sample submission** are switched to **On**.
|
||||||
|
|
||||||
|
@ -36,8 +36,10 @@ The Automated investigations list shows all the investigations that have been in
|
|||||||
|
|
||||||
## Understand the Automated investigation flow
|
## Understand the Automated investigation flow
|
||||||
### How the Automated investigation starts
|
### How the Automated investigation starts
|
||||||
Entities are the starting point for Automated investigations. When an alert contains a supported entity for Automated investigation (for example, a file) that resides on a machine that has a *supported operating system for Automated investigation then an Automated investigation can start.
|
Entities are the starting point for Automated investigations. When an alert contains a supported entity for Automated investigation (for example, a file) that resides on a machine that has a supported operating system for Automated investigation then an Automated investigation can start.
|
||||||
*Currently only Windows 10 version 1803 (spring creators update) and above are supported operating systems for Autoamted Investigation
|
|
||||||
|
>[!NOTE]
|
||||||
|
>Currently, Automated investigation only supports Windows 10, version 1803 or later.
|
||||||
|
|
||||||
The alerts start by analyzing the supported entities from the alert and also runs a generic machine playbook to see if there is anything else suspicious on that machine. The outcome and details from the investigation is seen in the Automated investigation view.
|
The alerts start by analyzing the supported entities from the alert and also runs a generic machine playbook to see if there is anything else suspicious on that machine. The outcome and details from the investigation is seen in the Automated investigation view.
|
||||||
|
|
||||||
|
@ -34,7 +34,7 @@ The Windows Defender Security Center interface is a little different in Windows
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
For more information about Windows 10 in S mode, including how to switch out of S mode, see Windows 10 Pro in S mode.
|
For more information about Windows 10 in S mode, including how to switch out of S mode, see [Windows 10 Pro/Enterprise in S mode](https://docs.microsoft.com/en-us/windows/deployment/windows-10-pro-in-s-mode).
|
||||||
|
|
||||||
##Managing Windows Defender Security Center settings with Intune
|
##Managing Windows Defender Security Center settings with Intune
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user