mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 05:47:23 +00:00
Merge branch 'main' into security-book-24
This commit is contained in:
commit
1a1fa67ce2
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: DeclaredConfiguration CSP
|
title: DeclaredConfiguration CSP
|
||||||
description: Learn more about the DeclaredConfiguration CSP.
|
description: Learn more about the DeclaredConfiguration CSP.
|
||||||
ms.date: 09/12/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -45,6 +45,8 @@ The following list shows the DeclaredConfiguration configuration service provide
|
|||||||
- [Results](#hostinventoryresults)
|
- [Results](#hostinventoryresults)
|
||||||
- [{DocID}](#hostinventoryresultsdocid)
|
- [{DocID}](#hostinventoryresultsdocid)
|
||||||
- [Document](#hostinventoryresultsdociddocument)
|
- [Document](#hostinventoryresultsdociddocument)
|
||||||
|
- [ManagementServiceConfiguration](#managementserviceconfiguration)
|
||||||
|
- [ConflictResolution](#managementserviceconfigurationconflictresolution)
|
||||||
<!-- DeclaredConfiguration-Tree-End -->
|
<!-- DeclaredConfiguration-Tree-End -->
|
||||||
|
|
||||||
<!-- Device-Host-Begin -->
|
<!-- Device-Host-Begin -->
|
||||||
@ -728,6 +730,93 @@ The Document node's value is an XML based document containing a collection of se
|
|||||||
|
|
||||||
<!-- Device-Host-Inventory-Results-{DocID}-Document-End -->
|
<!-- Device-Host-Inventory-Results-{DocID}-Document-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Begin -->
|
||||||
|
## ManagementServiceConfiguration
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/DeclaredConfiguration/ManagementServiceConfiguration
|
||||||
|
```
|
||||||
|
<!-- Device-ManagementServiceConfiguration-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
The ManagementServiceConfiguration node that's used to control certain Windows Declared Configuration behavior.
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Description-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Editable-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `node` |
|
||||||
|
| Access Type | Get |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Examples-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Begin -->
|
||||||
|
### ManagementServiceConfiguration/ConflictResolution
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/DeclaredConfiguration/ManagementServiceConfiguration/ConflictResolution
|
||||||
|
```
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This node controls to turn on conflict resolution on and off.
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Description-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Editable-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | The conflict resolution is OFF. |
|
||||||
|
| 1 | The conflict resolution is ON. |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Examples-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-End -->
|
||||||
|
|
||||||
<!-- DeclaredConfiguration-CspMoreInfo-Begin -->
|
<!-- DeclaredConfiguration-CspMoreInfo-Begin -->
|
||||||
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
||||||
## DeclaredConfiguration OMA URI
|
## DeclaredConfiguration OMA URI
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: DeclaredConfiguration DDF file
|
title: DeclaredConfiguration DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the DeclaredConfiguration configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the DeclaredConfiguration configuration service provider.
|
||||||
ms.date: 06/28/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -466,6 +466,61 @@ The following XML file contains the device description framework (DDF) for the D
|
|||||||
</Node>
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
|
<Node>
|
||||||
|
<NodeName>ManagementServiceConfiguration</NodeName>
|
||||||
|
<DFProperties>
|
||||||
|
<AccessType>
|
||||||
|
<Get />
|
||||||
|
</AccessType>
|
||||||
|
<Description>The ManagementServiceConfiguration node that is used to control certain Windows Declared Configuration behavior</Description>
|
||||||
|
<DFFormat>
|
||||||
|
<node />
|
||||||
|
</DFFormat>
|
||||||
|
<Occurrence>
|
||||||
|
<One />
|
||||||
|
</Occurrence>
|
||||||
|
<Scope>
|
||||||
|
<Dynamic />
|
||||||
|
</Scope>
|
||||||
|
<DFType>
|
||||||
|
<DDFName />
|
||||||
|
</DFType>
|
||||||
|
</DFProperties>
|
||||||
|
<Node>
|
||||||
|
<NodeName>ConflictResolution</NodeName>
|
||||||
|
<DFProperties>
|
||||||
|
<AccessType>
|
||||||
|
<Add />
|
||||||
|
<Delete />
|
||||||
|
<Get />
|
||||||
|
<Replace />
|
||||||
|
</AccessType>
|
||||||
|
<Description>This node controls to turn on conflict resolution on and off.</Description>
|
||||||
|
<DFFormat>
|
||||||
|
<int />
|
||||||
|
</DFFormat>
|
||||||
|
<Occurrence>
|
||||||
|
<One />
|
||||||
|
</Occurrence>
|
||||||
|
<Scope>
|
||||||
|
<Dynamic />
|
||||||
|
</Scope>
|
||||||
|
<DFType>
|
||||||
|
<MIME />
|
||||||
|
</DFType>
|
||||||
|
<MSFT:AllowedValues ValueType="ENUM">
|
||||||
|
<MSFT:Enum>
|
||||||
|
<MSFT:Value>0</MSFT:Value>
|
||||||
|
<MSFT:ValueDescription>The conflict resolution is OFF.</MSFT:ValueDescription>
|
||||||
|
</MSFT:Enum>
|
||||||
|
<MSFT:Enum>
|
||||||
|
<MSFT:Value>1</MSFT:Value>
|
||||||
|
<MSFT:ValueDescription>The conflict resolution is ON.</MSFT:ValueDescription>
|
||||||
|
</MSFT:Enum>
|
||||||
|
</MSFT:AllowedValues>
|
||||||
|
</DFProperties>
|
||||||
|
</Node>
|
||||||
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
</MgmtTree>
|
</MgmtTree>
|
||||||
```
|
```
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LAPS CSP
|
title: LAPS CSP
|
||||||
description: Learn more about the LAPS CSP.
|
description: Learn more about the LAPS CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -325,7 +325,7 @@ Note if a custom managed local administrator account name is specified in this s
|
|||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
||||||
|
|
||||||
@ -387,7 +387,7 @@ If not specified, this setting defaults to True.
|
|||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LAPS DDF file
|
title: LAPS DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the LAPS configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the LAPS configuration service provider.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -80,7 +80,7 @@ The following XML file contains the device description framework (DDF) for the L
|
|||||||
The allowable settings are:
|
The allowable settings are:
|
||||||
|
|
||||||
0=Disabled (password will not be backed up)
|
0=Disabled (password will not be backed up)
|
||||||
1=Backup the password to Azure AD only
|
1=Backup the password to Microsoft Entra ID only
|
||||||
2=Backup the password to Active Directory only
|
2=Backup the password to Active Directory only
|
||||||
|
|
||||||
If not specified, this setting will default to 0.</Description>
|
If not specified, this setting will default to 0.</Description>
|
||||||
@ -103,7 +103,7 @@ If not specified, this setting will default to 0.</Description>
|
|||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>1</MSFT:Value>
|
<MSFT:Value>1</MSFT:Value>
|
||||||
<MSFT:ValueDescription>Backup the password to Azure AD only</MSFT:ValueDescription>
|
<MSFT:ValueDescription>Backup the password to Microsoft Entra ID only</MSFT:ValueDescription>
|
||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>2</MSFT:Value>
|
<MSFT:Value>2</MSFT:Value>
|
||||||
@ -126,7 +126,7 @@ If not specified, this setting will default to 0.</Description>
|
|||||||
|
|
||||||
If not specified, this setting will default to 30 days
|
If not specified, this setting will default to 30 days
|
||||||
|
|
||||||
This setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Azure AD.
|
This setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID.
|
||||||
|
|
||||||
This setting has a maximum allowed value of 365 days.</Description>
|
This setting has a maximum allowed value of 365 days.</Description>
|
||||||
<DFFormat>
|
<DFFormat>
|
||||||
@ -154,7 +154,7 @@ This setting has a maximum allowed value of 365 days.</Description>
|
|||||||
<MSFT:DependencyAllowedValue ValueType="ENUM">
|
<MSFT:DependencyAllowedValue ValueType="ENUM">
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>1</MSFT:Value>
|
<MSFT:Value>1</MSFT:Value>
|
||||||
<MSFT:ValueDescription>BackupDirectory configured to Azure AD</MSFT:ValueDescription>
|
<MSFT:ValueDescription>BackupDirectory configured to Microsoft Entra ID</MSFT:ValueDescription>
|
||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
</MSFT:DependencyAllowedValue>
|
</MSFT:DependencyAllowedValue>
|
||||||
</MSFT:Dependency>
|
</MSFT:Dependency>
|
||||||
@ -442,7 +442,7 @@ If not specified, this setting defaults to True.</Description>
|
|||||||
<DefaultValue>True</DefaultValue>
|
<DefaultValue>True</DefaultValue>
|
||||||
<Description>Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
<Description>Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
||||||
|
|
||||||
@ -499,7 +499,7 @@ If not specified, this setting defaults to True.</Description>
|
|||||||
</AccessType>
|
</AccessType>
|
||||||
<Description>Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
<Description>Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: PassportForWork CSP
|
title: PassportForWork CSP
|
||||||
description: Learn more about the PassportForWork CSP.
|
description: Learn more about the PassportForWork CSP.
|
||||||
ms.date: 08/06/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -265,7 +265,7 @@ If the user forgets their PIN, it can be changed to a new PIN using the Windows
|
|||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-Begin -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 22H2 [10.0.22621] and later |
|
||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-End -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-End -->
|
||||||
|
|
||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-OmaUri-Begin -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-OmaUri-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: PassportForWork DDF file
|
title: PassportForWork DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the PassportForWork configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the PassportForWork configuration service provider.
|
||||||
ms.date: 06/28/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -831,7 +831,7 @@ If you disable or do not configure this policy setting, the PIN recovery secret
|
|||||||
<MIME />
|
<MIME />
|
||||||
</DFType>
|
</DFType>
|
||||||
<MSFT:Applicability>
|
<MSFT:Applicability>
|
||||||
<MSFT:OsBuildVersion>99.9.99999</MSFT:OsBuildVersion>
|
<MSFT:OsBuildVersion>10.0.22621</MSFT:OsBuildVersion>
|
||||||
<MSFT:CspVersion>1.6</MSFT:CspVersion>
|
<MSFT:CspVersion>1.6</MSFT:CspVersion>
|
||||||
</MSFT:Applicability>
|
</MSFT:Applicability>
|
||||||
<MSFT:AllowedValues ValueType="ENUM">
|
<MSFT:AllowedValues ValueType="ENUM">
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Policies supported by Windows 10 Team
|
title: Policies supported by Windows 10 Team
|
||||||
description: Learn about the policies supported by Windows 10 Team.
|
description: Learn about the policies supported by Windows 10 Team.
|
||||||
ms.date: 08/06/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -417,6 +417,7 @@ This article lists the policies that are applicable for the Surface Hub operatin
|
|||||||
- [ExcludeJapaneseIMEExceptJIS0208andEUDC](policy-csp-textinput.md#excludejapaneseimeexceptjis0208andeudc)
|
- [ExcludeJapaneseIMEExceptJIS0208andEUDC](policy-csp-textinput.md#excludejapaneseimeexceptjis0208andeudc)
|
||||||
- [ExcludeJapaneseIMEExceptShiftJIS](policy-csp-textinput.md#excludejapaneseimeexceptshiftjis)
|
- [ExcludeJapaneseIMEExceptShiftJIS](policy-csp-textinput.md#excludejapaneseimeexceptshiftjis)
|
||||||
- [ForceTouchKeyboardDockedState](policy-csp-textinput.md#forcetouchkeyboarddockedstate)
|
- [ForceTouchKeyboardDockedState](policy-csp-textinput.md#forcetouchkeyboarddockedstate)
|
||||||
|
- [TouchKeyboardControllerModeAvailability](policy-csp-textinput.md#touchkeyboardcontrollermodeavailability)
|
||||||
- [TouchKeyboardDictationButtonAvailability](policy-csp-textinput.md#touchkeyboarddictationbuttonavailability)
|
- [TouchKeyboardDictationButtonAvailability](policy-csp-textinput.md#touchkeyboarddictationbuttonavailability)
|
||||||
- [TouchKeyboardEmojiButtonAvailability](policy-csp-textinput.md#touchkeyboardemojibuttonavailability)
|
- [TouchKeyboardEmojiButtonAvailability](policy-csp-textinput.md#touchkeyboardemojibuttonavailability)
|
||||||
- [TouchKeyboardFullModeAvailability](policy-csp-textinput.md#touchkeyboardfullmodeavailability)
|
- [TouchKeyboardFullModeAvailability](policy-csp-textinput.md#touchkeyboardfullmodeavailability)
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Configuration service provider preview policies
|
title: Configuration service provider preview policies
|
||||||
description: Learn more about configuration service provider (CSP) policies that are available for Windows Insider Preview.
|
description: Learn more about configuration service provider (CSP) policies that are available for Windows Insider Preview.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -29,10 +29,17 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
- [EnablePhysicalDeviceAccessOnErrorScreens](clouddesktop-csp.md#userenablephysicaldeviceaccessonerrorscreens)
|
- [EnablePhysicalDeviceAccessOnErrorScreens](clouddesktop-csp.md#userenablephysicaldeviceaccessonerrorscreens)
|
||||||
- [EnableBootToCloudSharedPCMode](clouddesktop-csp.md#deviceenableboottocloudsharedpcmode)
|
- [EnableBootToCloudSharedPCMode](clouddesktop-csp.md#deviceenableboottocloudsharedpcmode)
|
||||||
|
|
||||||
|
## Connectivity
|
||||||
|
|
||||||
|
- [UseCellularWhenWiFiPoor](policy-csp-connectivity.md#usecellularwhenwifipoor)
|
||||||
|
- [DisableCellularSettingsPage](policy-csp-connectivity.md#disablecellularsettingspage)
|
||||||
|
- [DisableCellularOperatorSettingsPage](policy-csp-connectivity.md#disablecellularoperatorsettingspage)
|
||||||
|
|
||||||
## DeclaredConfiguration CSP
|
## DeclaredConfiguration CSP
|
||||||
|
|
||||||
- [Document](declaredconfiguration-csp.md#hostcompletedocumentsdociddocument)
|
- [Document](declaredconfiguration-csp.md#hostcompletedocumentsdociddocument)
|
||||||
- [Abandoned](declaredconfiguration-csp.md#hostcompletedocumentsdocidpropertiesabandoned)
|
- [Abandoned](declaredconfiguration-csp.md#hostcompletedocumentsdocidpropertiesabandoned)
|
||||||
|
- [ConflictResolution](declaredconfiguration-csp.md#managementserviceconfigurationconflictresolution)
|
||||||
|
|
||||||
## DeliveryOptimization
|
## DeliveryOptimization
|
||||||
|
|
||||||
@ -52,6 +59,10 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
- [MdmAgentInstalled](devicepreparation-csp.md#mdmprovidermdmagentinstalled)
|
- [MdmAgentInstalled](devicepreparation-csp.md#mdmprovidermdmagentinstalled)
|
||||||
- [RebootRequired](devicepreparation-csp.md#mdmproviderrebootrequired)
|
- [RebootRequired](devicepreparation-csp.md#mdmproviderrebootrequired)
|
||||||
|
|
||||||
|
## Display
|
||||||
|
|
||||||
|
- [ConfigureMultipleDisplayMode](policy-csp-display.md#configuremultipledisplaymode)
|
||||||
|
|
||||||
## DMClient CSP
|
## DMClient CSP
|
||||||
|
|
||||||
- [DiscoveryEndpoint](dmclient-csp.md#deviceproviderprovideridlinkedenrollmentdiscoveryendpoint)
|
- [DiscoveryEndpoint](dmclient-csp.md#deviceproviderprovideridlinkedenrollmentdiscoveryendpoint)
|
||||||
@ -97,7 +108,6 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
|
|
||||||
## PassportForWork CSP
|
## PassportForWork CSP
|
||||||
|
|
||||||
- [EnableWindowsHelloProvisioningForSecurityKeys](passportforwork-csp.md#devicetenantidpoliciesenablewindowshelloprovisioningforsecuritykeys)
|
|
||||||
- [DisablePostLogonProvisioning](passportforwork-csp.md#devicetenantidpoliciesdisablepostlogonprovisioning)
|
- [DisablePostLogonProvisioning](passportforwork-csp.md#devicetenantidpoliciesdisablepostlogonprovisioning)
|
||||||
|
|
||||||
## Reboot CSP
|
## Reboot CSP
|
||||||
@ -112,6 +122,10 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
|
|
||||||
- [ExchangeModernAuthEnabled](surfacehub-csp.md#deviceaccountexchangemodernauthenabled)
|
- [ExchangeModernAuthEnabled](surfacehub-csp.md#deviceaccountexchangemodernauthenabled)
|
||||||
|
|
||||||
|
## TextInput
|
||||||
|
|
||||||
|
- [TouchKeyboardControllerModeAvailability](policy-csp-textinput.md#touchkeyboardcontrollermodeavailability)
|
||||||
|
|
||||||
## Update
|
## Update
|
||||||
|
|
||||||
- [AllowTemporaryEnterpriseFeatureControl](policy-csp-update.md#allowtemporaryenterprisefeaturecontrol)
|
- [AllowTemporaryEnterpriseFeatureControl](policy-csp-update.md#allowtemporaryenterprisefeaturecontrol)
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Connectivity Policy CSP
|
title: Connectivity Policy CSP
|
||||||
description: Learn more about the Connectivity Area in Policy CSP.
|
description: Learn more about the Connectivity Area in Policy CSP.
|
||||||
ms.date: 04/10/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -11,6 +11,8 @@ ms.date: 04/10/2024
|
|||||||
|
|
||||||
[!INCLUDE [ADMX-backed CSP tip](includes/mdm-admx-csp-note.md)]
|
[!INCLUDE [ADMX-backed CSP tip](includes/mdm-admx-csp-note.md)]
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- Connectivity-Editable-Begin -->
|
<!-- Connectivity-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Connectivity-Editable-End -->
|
<!-- Connectivity-Editable-End -->
|
||||||
@ -584,6 +586,104 @@ Also, see the "Web-based printing" policy setting in Computer Configuration/Admi
|
|||||||
|
|
||||||
<!-- DiablePrintingOverHTTP-End -->
|
<!-- DiablePrintingOverHTTP-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Begin -->
|
||||||
|
## DisableCellularOperatorSettingsPage
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/DisableCellularOperatorSettingsPage
|
||||||
|
```
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy makes all configurable settings in the 'Cellular' > 'Mobile operator settings' page read-only.
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Description-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Editable-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Disabled. |
|
||||||
|
| 1 | Enabled. |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Examples-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Begin -->
|
||||||
|
## DisableCellularSettingsPage
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- DisableCellularSettingsPage-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/DisableCellularSettingsPage
|
||||||
|
```
|
||||||
|
<!-- DisableCellularSettingsPage-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy makes all configurable settings in the 'Cellular' Settings page read-only.
|
||||||
|
<!-- DisableCellularSettingsPage-Description-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularSettingsPage-Editable-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- DisableCellularSettingsPage-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Disabled. |
|
||||||
|
| 1 | Enabled. |
|
||||||
|
<!-- DisableCellularSettingsPage-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularSettingsPage-Examples-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-End -->
|
||||||
|
|
||||||
<!-- DisableDownloadingOfPrintDriversOverHTTP-Begin -->
|
<!-- DisableDownloadingOfPrintDriversOverHTTP-Begin -->
|
||||||
## DisableDownloadingOfPrintDriversOverHTTP
|
## DisableDownloadingOfPrintDriversOverHTTP
|
||||||
|
|
||||||
@ -899,6 +999,55 @@ If you disable this setting or don't configure it, the user will be able to crea
|
|||||||
|
|
||||||
<!-- ProhibitInstallationAndConfigurationOfNetworkBridge-End -->
|
<!-- ProhibitInstallationAndConfigurationOfNetworkBridge-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Begin -->
|
||||||
|
## UseCellularWhenWiFiPoor
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/UseCellularWhenWiFiPoor
|
||||||
|
```
|
||||||
|
<!-- UseCellularWhenWiFiPoor-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows the use of a cellular connection when Wi-Fi connectivity is limited.
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Description-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Editable-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 1 |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | Disabled. |
|
||||||
|
| 1 (Default) | Enabled. |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Examples-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-End -->
|
||||||
|
|
||||||
<!-- Connectivity-CspMoreInfo-Begin -->
|
<!-- Connectivity-CspMoreInfo-Begin -->
|
||||||
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Connectivity-CspMoreInfo-End -->
|
<!-- Connectivity-CspMoreInfo-End -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Display Policy CSP
|
title: Display Policy CSP
|
||||||
description: Learn more about the Display Area in Policy CSP.
|
description: Learn more about the Display Area in Policy CSP.
|
||||||
ms.date: 01/18/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -9,10 +9,72 @@ ms.date: 01/18/2024
|
|||||||
<!-- Display-Begin -->
|
<!-- Display-Begin -->
|
||||||
# Policy CSP - Display
|
# Policy CSP - Display
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- Display-Editable-Begin -->
|
<!-- Display-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Display-Editable-End -->
|
<!-- Display-Editable-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Begin -->
|
||||||
|
## ConfigureMultipleDisplayMode
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Display/ConfigureMultipleDisplayMode
|
||||||
|
```
|
||||||
|
<!-- ConfigureMultipleDisplayMode-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy set the default display to set the arrangement between cloning or extending.
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Description-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Editable-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 1 |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | Default. |
|
||||||
|
| 1 (Default) | Clone. |
|
||||||
|
| 2 | Extend. |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | ConfigureMultipleDisplayMode |
|
||||||
|
| Path | Display > AT > System > DisplayCat |
|
||||||
|
| Element Name | ConfigureMultipleDisplayModePrompt |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Examples-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-End -->
|
||||||
|
|
||||||
<!-- DisablePerProcessDpiForApps-Begin -->
|
<!-- DisablePerProcessDpiForApps-Begin -->
|
||||||
## DisablePerProcessDpiForApps
|
## DisablePerProcessDpiForApps
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LocalPoliciesSecurityOptions Policy CSP
|
title: LocalPoliciesSecurityOptions Policy CSP
|
||||||
description: Learn more about the LocalPoliciesSecurityOptions Area in Policy CSP.
|
description: Learn more about the LocalPoliciesSecurityOptions Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -388,10 +388,27 @@ Audit: Audit the use of Backup and Restore privilege This security setting deter
|
|||||||
|:--|:--|
|
|:--|:--|
|
||||||
| Format | `b64` |
|
| Format | `b64` |
|
||||||
| Access Type | Add, Delete, Get, Replace |
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
| Allowed Values | List (Delimiter: ``) |
|
| Default Value | AA== |
|
||||||
| Default Value | 00 |
|
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-DFProperties-End -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| AQ== | Enable. |
|
||||||
|
| AA== (Default) | Disable. |
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | Audit: Audit the use of Backup and Restore privilege |
|
||||||
|
| Path | Windows Settings > Security Settings > Local Policies > Security Options |
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-GpMapping-End -->
|
||||||
|
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-Begin -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-Begin -->
|
||||||
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-End -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-End -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: RemoteDesktopServices Policy CSP
|
title: RemoteDesktopServices Policy CSP
|
||||||
description: Learn more about the RemoteDesktopServices Area in Policy CSP.
|
description: Learn more about the RemoteDesktopServices Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -156,7 +156,7 @@ FIPS compliance can be configured through the System cryptography. Use FIPS comp
|
|||||||
<!-- DisconnectOnLockLegacyAuthn-Applicability-Begin -->
|
<!-- DisconnectOnLockLegacyAuthn-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ [10.0.20348.2461] and later <br> ✅ [10.0.25398.887] and later <br> ✅ Windows 10, version 2004 [10.0.19041.4474] and later <br> ✅ Windows 11, version 21H2 with [KB5037770](https://support.microsoft.com/help/5037770) [10.0.22000.2960] and later <br> ✅ Windows 11, version 22H2 with [KB5037771](https://support.microsoft.com/help/5037771) [10.0.22621.3593] and later <br> ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
||||||
<!-- DisconnectOnLockLegacyAuthn-Applicability-End -->
|
<!-- DisconnectOnLockLegacyAuthn-Applicability-End -->
|
||||||
|
|
||||||
<!-- DisconnectOnLockLegacyAuthn-OmaUri-Begin -->
|
<!-- DisconnectOnLockLegacyAuthn-OmaUri-Begin -->
|
||||||
@ -217,7 +217,7 @@ This policy applies only when using legacy authentication to authenticate to the
|
|||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-Begin -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ [10.0.20348.2461] and later <br> ✅ [10.0.25398.887] and later <br> ✅ Windows 10, version 2004 [10.0.19041.4474] and later <br> ✅ Windows 11, version 21H2 with [KB5037770](https://support.microsoft.com/help/5037770) [10.0.22000.2960] and later <br> ✅ Windows 11, version 22H2 with [KB5037771](https://support.microsoft.com/help/5037771) [10.0.22621.3593] and later <br> ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-End -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-End -->
|
||||||
|
|
||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-OmaUri-Begin -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-OmaUri-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: TextInput Policy CSP
|
title: TextInput Policy CSP
|
||||||
description: Learn more about the TextInput Area in Policy CSP.
|
description: Learn more about the TextInput Area in Policy CSP.
|
||||||
ms.date: 01/18/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -9,6 +9,8 @@ ms.date: 01/18/2024
|
|||||||
<!-- TextInput-Begin -->
|
<!-- TextInput-Begin -->
|
||||||
# Policy CSP - TextInput
|
# Policy CSP - TextInput
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- TextInput-Editable-Begin -->
|
<!-- TextInput-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- TextInput-Editable-End -->
|
<!-- TextInput-Editable-End -->
|
||||||
@ -1172,6 +1174,56 @@ Specifies the touch keyboard is always docked. When this policy is set to enable
|
|||||||
|
|
||||||
<!-- ForceTouchKeyboardDockedState-End -->
|
<!-- ForceTouchKeyboardDockedState-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Begin -->
|
||||||
|
## TouchKeyboardControllerModeAvailability
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/TextInput/TouchKeyboardControllerModeAvailability
|
||||||
|
```
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
Specifies whether the controller keyboard mode is enabled or disabled for the touch keyboard. When this policy is set to disabled, the controller keyboard mode for touch keyboard is disabled.
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Description-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Editable-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | The OS determines when it's most appropriate to be available. |
|
||||||
|
| 1 | Controller keyboard is always available. |
|
||||||
|
| 2 | Controller keyboard is always disabled. |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Examples-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-End -->
|
||||||
|
|
||||||
<!-- TouchKeyboardDictationButtonAvailability-Begin -->
|
<!-- TouchKeyboardDictationButtonAvailability-Begin -->
|
||||||
## TouchKeyboardDictationButtonAvailability
|
## TouchKeyboardDictationButtonAvailability
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Wifi Policy CSP
|
title: Wifi Policy CSP
|
||||||
description: Learn more about the Wifi Area in Policy CSP.
|
description: Learn more about the Wifi Area in Policy CSP.
|
||||||
ms.date: 01/31/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -188,10 +188,7 @@ By default, ICS is disabled when you create a remote access connection, but admi
|
|||||||
|
|
||||||
<!-- AllowManualWiFiConfiguration-Description-Begin -->
|
<!-- AllowManualWiFiConfiguration-Description-Begin -->
|
||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Allow or disallow connecting to Wi-Fi outside of MDM server-installed networks. Most restricted value is 0.
|
Allow or block connections to Wi-Fi outside of MDM server-installed networks. If you change this setting to Block, you must deploy enterprise Wi-Fi profiles to the device using the Wi-Fi CSP before you apply this setting. Otherwise, the device will go offline since it won't be able to connect to Wi-Fi. Note that choosing to block Wi-Fi connections will delete any previously installed user-configured Wi-Fi profiles from the device, though not all non-MDM profiles will be deleted.
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> Setting this policy deletes any previously installed user-configured and Wi-Fi sense Wi-Fi profiles from the device. Certain Wi-Fi profiles that aren't user configured nor Wi-Fi sense might not be deleted. In addition, not all non-MDM profiles are completely deleted.
|
|
||||||
<!-- AllowManualWiFiConfiguration-Description-End -->
|
<!-- AllowManualWiFiConfiguration-Description-End -->
|
||||||
|
|
||||||
<!-- AllowManualWiFiConfiguration-Editable-Begin -->
|
<!-- AllowManualWiFiConfiguration-Editable-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: WindowsAI Policy CSP
|
title: WindowsAI Policy CSP
|
||||||
description: Learn more about the WindowsAI Area in Policy CSP.
|
description: Learn more about the WindowsAI Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -286,10 +286,9 @@ This policy setting allows you to turn off Windows Copilot.
|
|||||||
<!-- TurnOffWindowsCopilot-Description-End -->
|
<!-- TurnOffWindowsCopilot-Description-End -->
|
||||||
|
|
||||||
<!-- TurnOffWindowsCopilot-Editable-Begin -->
|
<!-- TurnOffWindowsCopilot-Editable-Begin -->
|
||||||
|
|
||||||
> [!Note]
|
|
||||||
> - The TurnOffWindowsCopilot policy isn't for the [new Copilot experience](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/evolving-copilot-in-windows-for-your-workforce/ba-p/4141999) that's in some [Windows Insider builds](https://blogs.windows.com/windows-insider/2024/05/22/releasing-windows-11-version-24h2-to-the-release-preview-channel/) and that will be gradually rolling out to Windows 11 and Windows 10 devices. <!--9048085-->
|
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
> [!NOTE]
|
||||||
|
> - The TurnOffWindowsCopilot policy isn't for the [new Copilot experience](https://techcommunity.microsoft.com/blog/windows-itpro-blog/evolving-copilot-in-windows-for-your-workforce/4141999) that's in some [Windows Insider builds](https://blogs.windows.com/windows-insider/2024/05/22/releasing-windows-11-version-24h2-to-the-release-preview-channel/) and that will be gradually rolling out to Windows 11 and Windows 10 devices. <!--9048085-->
|
||||||
<!-- TurnOffWindowsCopilot-Editable-End -->
|
<!-- TurnOffWindowsCopilot-Editable-End -->
|
||||||
|
|
||||||
<!-- TurnOffWindowsCopilot-DFProperties-Begin -->
|
<!-- TurnOffWindowsCopilot-DFProperties-Begin -->
|
||||||
|
Loading…
x
Reference in New Issue
Block a user