From 3ec491639695b90a3f6380054fdad5caab1f2440 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Fri, 28 Jul 2017 11:34:57 -0700 Subject: [PATCH 01/30] date and time format --- ...ngs-windows-defender-advanced-threat-protection.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index 6dd42769f1..d30fbc3c7e 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -54,6 +54,17 @@ To set the time zone: 2. Select the **Timezone UTC** indicator. 3. Select **Timezone Local** or **-8:00**. +### Date-time format in browser +**Internet Explorer(IE) and Microsoft Edge (Edge)** +IE and Edge uses the local configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. + +**Google Chrome** +If you use Google Chrome to access the Windows Defender ATP portal, you might need to configure the language settings for the date and time format to reflect your locale. + +1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. +2. Restart the browser for the settings to take effect. + + ## Suppression rules The suppression rules control what alerts are suppressed. You can suppress alerts so that certain activities are not flagged as suspicious. For more information see, [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md#suppress-alerts). From 2c1e4c4f5c9ea0379f87927f645f21aa52a899da Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 2 Aug 2017 14:04:12 -0700 Subject: [PATCH 02/30] spacing fix --- .../settings-windows-defender-advanced-threat-protection.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index d30fbc3c7e..66224e09dd 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -56,9 +56,11 @@ To set the time zone: ### Date-time format in browser **Internet Explorer(IE) and Microsoft Edge (Edge)** -IE and Edge uses the local configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. + +IE and Edge use the local configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. **Google Chrome** + If you use Google Chrome to access the Windows Defender ATP portal, you might need to configure the language settings for the date and time format to reflect your locale. 1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. From ac93607e8cc2cb69c94bf3624d2e65db00d2af39 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 2 Aug 2017 14:12:03 -0700 Subject: [PATCH 03/30] add date time issue in troubleshooting topic --- ...ndows-defender-advanced-threat-protection.md | 4 +++- ...ndows-defender-advanced-threat-protection.md | 17 +++++++++++++++++ 2 files changed, 20 insertions(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index 66224e09dd..0feb5f25ae 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -57,7 +57,7 @@ To set the time zone: ### Date-time format in browser **Internet Explorer(IE) and Microsoft Edge (Edge)** -IE and Edge use the local configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. +IE and Edge uses the locale settings configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. **Google Chrome** @@ -66,6 +66,8 @@ If you use Google Chrome to access the Windows Defender ATP portal, you might ne 1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. 2. Restart the browser for the settings to take effect. +>[!NOTE] +>There currently is no support for Japanese format (YYYY/MM/DD) in Windows Defender ATP when used in Google Chrome. ## Suppression rules The suppression rules control what alerts are suppressed. You can suppress alerts so that certain activities are not flagged as suspicious. For more information see, [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md#suppress-alerts). diff --git a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md index 5bb2935a52..8b2f4e8ebf 100644 --- a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md @@ -47,6 +47,23 @@ If onboarding endpoints successfully completes but Windows Defender ATP does not For more information, see [Ensure that Windows Defender is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-is-not-disabled-by-a-policy). + +### Windows Defender ATP has some date-time format issues +**Internet Explorer(IE) and Microsoft Edge (Edge)** + +IE and Edge uses the locale settings configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. + +**Google Chrome** + +If you use Google Chrome to access the Windows Defender ATP portal, you might need to configure the language settings for the date and time format to reflect your locale. + +1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. +2. Restart the browser for the settings to take effect. + +>[!NOTE] +>There currently is no support for Japanese format (YYYY/MM/DD) in Windows Defender ATP when used in Google Chrome. + + ### Related topic - [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) - [Review events and errors on endpoints with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) From cdeee01f0c933b5adf956a395e02e9be3408a1aa Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 2 Aug 2017 14:21:05 -0700 Subject: [PATCH 04/30] minor update --- .../troubleshoot-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md index 8b2f4e8ebf..b2e87a83f0 100644 --- a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md @@ -61,7 +61,7 @@ If you use Google Chrome to access the Windows Defender ATP portal, you might ne 2. Restart the browser for the settings to take effect. >[!NOTE] ->There currently is no support for Japanese format (YYYY/MM/DD) in Windows Defender ATP when used in Google Chrome. +>There currently is no support for Japanese date format (YYYY/MM/DD) in Windows Defender ATP when accessed through Google Chrome. ### Related topic From 0d32d11650de59e472c5bbf64d0b3b15e2efb20f Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 2 Aug 2017 14:40:43 -0700 Subject: [PATCH 05/30] include details --- .../settings-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index 0feb5f25ae..91ce5a0bb4 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -67,7 +67,7 @@ If you use Google Chrome to access the Windows Defender ATP portal, you might ne 2. Restart the browser for the settings to take effect. >[!NOTE] ->There currently is no support for Japanese format (YYYY/MM/DD) in Windows Defender ATP when used in Google Chrome. +>There currently is no support for Japanese date format format (YYYY/MM/DD) in Windows Defender ATP when when accessed through Google Chrome. ## Suppression rules The suppression rules control what alerts are suppressed. You can suppress alerts so that certain activities are not flagged as suspicious. For more information see, [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md#suppress-alerts). From cad8702f849ff1431231d7c1e1fdb8baf85763de Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 12 Sep 2017 13:07:52 -0700 Subject: [PATCH 06/30] updates --- .../images/atp-region-control-panel.png | Bin 0 -> 22441 bytes ...ows-defender-advanced-threat-protection.md | 37 ++++++++++++------ 2 files changed, 24 insertions(+), 13 deletions(-) create mode 100644 windows/threat-protection/windows-defender-atp/images/atp-region-control-panel.png diff --git a/windows/threat-protection/windows-defender-atp/images/atp-region-control-panel.png b/windows/threat-protection/windows-defender-atp/images/atp-region-control-panel.png new file mode 100644 index 0000000000000000000000000000000000000000..58d25e0f9d298114ba24ace8d1f807fe609fad9a GIT binary patch literal 22441 zcmcG$bzD{5+BLlCkVd50gb31-lADs0?gjzr?gl|hN~J_Vx*IlK(t@OPcX#LJUFbQ_ zx$oyW=X<~Ri$C}&bI-N*T5GOrT-O-mnuICJOJbsvpo2glOlc``We^B%6$FB(L`4Qh zR3Ri?z&~jAQd&+R5LU;-4_q807AY`@;w&xq3S|im1E1n?@R4-q@1a+k&LS?(=5~&t z{F0wizz~KrFeGm3Wb9~R?`&ab3&KaEq5;OyAI8P(>^&SU%*>rZMc6<2fKja9qmHIV z4^t_fEo@9dTo>4Az$a)ApQzZqb#^myGzIC|-#<)$^!wx%PR70#&FpT;z ztYPG6Yhh~!Y9(C{0me}N9Pi?2YzjKN58V0ZG%-6H8&g|n(D~2!7GMndVVbIiv$ZKG zZ-0ai1fm2&<8IWZV^2)V-hm%`<6~q)%;92f}Ol{PH8>!?k9O{p$8QnH?I7&H@y!!4) zk1Zia-d0&njE83Gv?P0NZ*sJxt}taPj)AqHprKxC%rDQ@_2aEC$f)D`WK?BL@b>(q zFjuYDt@$Jc=Mu4S0fw_t(h|7z7_eBf>Rr!YG(Kj z1F;u6_Z0j{7wX?tTb(0#U+#ZfEVMKDP8xY4HBPrN>by^yU+s5DHQ#hccUe`3H?aV- z;f%Wd!O+|^J$n<$xX>2IBIAuyZ@PF6#~@c(Qxdj*_J>^Vzz1htboo0l_Cl~*M0x3!-F^o99^!s+o_o1x zr}v%I!w>S)LokF51N)Ze>Za0ckOUH96q>8>ZF%cguKVdGE~gy-aw;BX@Nvq4H{ER@ zccG!7t-{Z!sTtsr*>Q1|;MiiqLPOF0173@ZtAfn18diRp z4IU2OFB=%0EOlS*bmP|^L-F=uU`U&tzQ6}N*qwAT_`Xx*{4;P)asHFTrS@hw&*Q6& z+9SWDNyv%VZ3zB7+J4J19_+9IJvPkga)UJbkkw7772>r+df9J~LM)m9e4~6Sq3_;= zZ}CA2Z07y~`^c|_=}3X))>yasun?Ff7;SLnMR@q0)d#n<>HO90>Tuy@DQw3ta?Y;- z62yX!i<=_gvmiEqcWQUEaJS|c*aG{Za=Y~b(t)nu{lValHi)$;;+v2caz5v4Vd}_n}sFUz;=^@UVScR`{X>V`s ze8YjK@@^0ua=C*2Sm5T~mk?clcMn9!vIx&zUW4LKqYJ!Fwdab+_M2?T*Ql!pK7ND? z_e&cuc^t4xzmay|pSIjSy3Jg;b-69Mh970UM;*I|QTbli7++2)K)M-?4O%Pj@4hX& z`E6(%9?J?+EPqE3AZh`93_6;BmNnZ!0a}EgmysCAUt8heAX@PDcc5b9fPuiX^AY#+ z&3^S{6m~ouQT_dShC)I#l$smQs56AJ#fV$e+le+`#N5BN!~Pz4V067)x{S1jbbD(C zK>&F#K{XEB94cPg*?v69!)|k7@Y9wH$s}xunaO&0Z6Ov1<~bD{8Ivl+e2N9#EUdrl4mfnb zfARXPW?A{_8O2Ys3RQVv6+nVW#|F1+7l%-T8-m+INl4d}!7aQ#-wAc9_c?JY?Dl!v zA+f&48o}+#!WF;!efGuS8VX65-xcE}cCXnHHf*lc*@Cw@B*I*D96>i!^1Ih$I|ap4 zBTQg5#QVCJY3vJ;c>*0qA>lY z?JcjK(&lUS=G$!6qs!ujOP8OpaY*ZK%e_k;VRNv7_Z6-88QnsA z>HVR>A{aI@Xur>B@EuqruYDw%AITa!3(aWRGGt+!7F*W?#e21b6NUKJWpbQ?f?BfdfIc=f%HFq$tr zU)=87-8~zKid=eB+Vn2vK&WHkw%=f7=DyP}T*JVJz-%D-`=c)lg8QrRZ{KoLK_)wp zUIf;3U}VMCreK7#Hoo7n(`(fMe)h0!SGboyxx9U95PA_^Ei1F~)0mo?Bxr0*O}EaG z*6DF_(DC**Ly1Alywlh4m6z!_87mUs{9wGW(UYTP#uk6GB@XX1MuRSmuEFI;tW7}= zp#DSQo8bm44Bqcx!msJzvnPw!*BD1^j*z?k-{39v+>24G<@UHQvH6he_BI#N^@W3V zX_v4iD5d3=ksj6IzG0#L?gl$bC<0Dka<*gs^5w=GT-@REiIa<%!BoKy3qz{6R|8lS z)^$Klhr9#p~DUBRm{GBYsF0xa9TCx2u+yCSy z)fLp=gG4>z;^Ihu(i7<4oQE9TQrpnrrF!?09UmV*a~~eK6*#?bA-W`6C($T{`lZqJ zkAO3LsYgDRcEXdq8zpC?5m$B2WrHe|rdX==+Vu2avY$gJ* zIEex>3g(&(=F8?WBHEkkab1HBWe>hX2^?Q5E1krzU%RHKohYC>3;e|g7mbqM{Xni- zyF!?%QT}crOpPv|sIS`g1P(*2YX(`d6J2!h-8PD%9Co@HTs*nW0UF|YQ{GeN#nHW!H9j!m} z(cExdornlEcSiQco(ecT5NUh&Jj3h9wi+B4YDSD2Qb|`|I=Zf$El=)!>Y)vhHhWSv z`#xzxdI4T=&i7i4uJ8?Efr}qm)^is&=#@uge|-+b^VJ`Hb7b2WNY zyIl2K@s!6!98XL5qD;@%hw&^l27jHHe+@knxHD*VT)pox7}?2mH~vR+zLeL;{zNUi%Ky=(38dt^+eVQXac;pLIBH)qXzE2ZPb zb*NRVZq@CPB#*z91M1JY?~>8r?!JvO7bi?7H(SH&R(jS_8<399WKsh@)WM8IhX>oB zWKLVB{dAVh-{NOK6^l*{#mzwE=%ka?qhCBi;R9Q58|Azyn0+=UySZi?c_aDrt=Q&# zF{`WD1l>@g!3*DY2PdqtoSbwbM{dTaNvhY^*+Q6S8>@r2_@hbhv>LkbcyP%T0H_V57Co(57uiZ{!yV#}s810vn zQ{wz|n|g%+TE!Octj8^`?Q0r}{Lakws0$sZ>8Kgmc;jmibf}VhvEB#CHlCUc94pBA zsWZoE&PEJb{o27E-?;&C>$NigRUwXuyF))pSirRF`{oUK*o*@b3F1)Gmw}4|$CE{ictleTq zWHJwjLxcOp&^==w^9HH?woA?I;fqLe>}D+@k|jMCoUAademNLWK)P1C!ArsZ$Y&Gh+tj-ePTl*LZ8p~Z zp;lI{v%1brIU8&|O~KHvo$p#x;?CX#rxeGyGxcARbe*4=mD((IrH~2>h-~#kdA*(K z>cL*Xi42Ri-gc(&*S-)8A?5Lh);dooZgP<$85+YYSFz>peb>?vt7J+hUp4`%?H>#)^~!8C|3E zmhyV<0|Z`Nc78qU3a?$h0pd`_N6)G7}$+tBa?UC2t;s zZ9Jb`9;y+nt(uJm@#bOk=;gEZvoqb~b*+kv5862g?9L3a%eD{q^srUc{v?i$HF5G1 z>!O{BV6Wv=rrnT`p70OCmi>?*jS&7e^8!wF7GRMdqw?>=4=aBl7dQw@Z7qM}F?^PP~s zF?Gf;-#g(bzx?XkwpcdKN2YYo&9qS?oI|frM+t(`5k6KKAut++4&lZGzw;;(zu|*# zHsxs(eQFbo6;x$(124ZR{4{&B#B|=-@7IN(k7jev%eOmqMZ&Hv8Voj?rgWK1^PZ_& zCzj}oH>R;SBorHGf*)NXpJK>~K3(%dDYI#bJ|VCd#TK>9pAfu(ZtijQZ7Iw{Rr}~~ zgdBxfaBv9*J}!v4B7z{oAh_YnHH)^#Lbqvk3OlHZ@1bubXtk**M|R%(3;UKa@%@c36ME&D{!gjnzN{s5Bf9>KC4qZS27K2PdWs*#MJswYIe@J`gRm5>hH9# z;ohBQu><*ybQo2uHLNc&JVSW+Y0!p%fj`Kf&FFjhGuY3Y{Na!OI5zk}j?np&eVC6r z99?s1F+KYFuozBG^S44R(?lO1LYYoAxE`;5U$kzk)S8S|)FLr&+JZZhSEaa2#Wrnf z(Ho4tholoqfoiVHrHxSX+>HsQT!_a6`{7bTUuSBVym)NJ%P4&Pdgtd(Yy0~wGT9@z zZd-{bHs(p#9AvF15%S%MDC&*}f!|z(b~oWM*S!{ia7foLHGcCZV}%>4y%#hm#sad? zDPCwHM;_}4j~PlmSU(A)#l%#fG9khrE_Zx8O8ye&J(+}Ds3h{lzHKR5SM8VB%T;4C zjW#q7o6yZkBT7ikW})DEUV{h#OC+)Y+5K-dB*qy9P4qRfE7SxzHqt^P-)`WGZ3Dev#^&%`nzeDwKqqOLv1#CTz4Vsi2; zs8F7jAinmUSfGr(5f=1XcnZd zGa$GeA9aJlmU9m5pM+V|7!tJ$GOk+m$;Y<2pD-3X?6SOmDl$;92w!AO#zsfOS;2s z{Q1t-ifs)A2b5)QVf@%bhc->WbNAiMm2LwC|J+-3{v*$tKCV7*n~Zbq>lGG5$LetT zz|_FKQ!krB6ob!QImHk&aG{EqxmWQM`$NYXKf@1Eb!BWbvqCkI$rJ1wcOTEL#od(O za+Ih*X4cOf6c3I@dEKUS_u5}5z47w{yB*BGDpuz&D^V|8+MjEfTvz~$3?f^Jf3A1l ztp6a9T?-S^-82UWZTIm{PECCu7+`m<3AfbiJ_i01TUOf~m|{vk%nH@2z4mO}!%B*4 z=Zi0BElx3?@$3un7e`Z3Idd0ojO26HW!V}!v$38SHeJ>4R@RG-ni*;S@P3N+b?03R z5|7L5xC{Tzhe`cV__S>A{rX83E=Dw9ka`; zOgjQg<u-$|ZYItT%3zxidr> zheWvVS_!UmG*}VSow2Qm8asoA7rr>kt55ZKF&&pgv);&kJYSPC5B}j|;h~Tl<+3O^ zzfw&;cv5z7ROGaOJ}sB7+6(iG%@d4O&?Z92yq#82W^gUcdwaKBqVb{u#B{K0Xl6$K zp}kRr5GB2#2~!Xzr&(WwaCQ-W4s*!#-fx>5chG9VAa}9OWkk(JA9r)Le{`^#P~^p@ z&bl{Ro)QPCD~*imUFI$riGggRy_P z?&TXNl%2E%%RBSAs%v0ZeNHl>h+aNDU&toc|2kqyZeN&pek_tRF;Tm5@>MiHmPD>T z|C9NAxu<(EUrSAW#P;!YkJo~$w;zVI!p4_!g_eop8L!Ib$h}oA>fVn*$I_3C4M*?U zLiNADd7e94q)`@{Z4TeVf2K;mJ#==ORf5N`)0e27)Srm>s}PT6hc+#?Ihy<)Phj+? z9eLl8V8f3e(v5-6qv}r z-M2=vf5tU5G|UPs-j5qi z7izq?!Lqk%Izi;#&Wf^h#=R2sAPJ3(jBFFYuKQOKjJ$V#hN&rNCf^!UJC^_JHAA*r}Iz$x!`8TE9MD9WC|5L6LdH(P; zHa7m92Kml|NqSy=aRih~Rc9uxzsNOzNrDXjPMP^XDEJKU2@?1Ca+BS=(pL0K}``i0oVAT-oGR{BGa2Q5*V z_XT+@Vk{e5=ghc|R1DOTb6yAz%~M3wfQ6UQnE0V~>keKPr6D^ZbY*+%P&RJ<6sv)1 zK>U47!>ILPhXWN(oaz|$yxk#j18xzmD5R9e`$E*&@9dnW$4=kBl>+02s&~R{u^$BU zg5v~jr$>+FHwhA*Qv~rM90>ULqYTY^!5{TcOl$kX?=(5M9}EclT%so3ZItE%>tg*=<&T+R8S;=PtFi8lmS4yC{bb1+PsL40U{m5GQHH zr?~yrx(mhPihIpR=(d5C&Tv?rMp1woh11`kq>z7Y(anJTpC3=RlXc=MBcfe)aHDm2G zfu?7$15Q?OHoPp%$Og_F=xcb=L5h9{0*Fbb<|kkKU6k^DX=<7_lpwnyS&XfZ`WrY{%vG>(|b+ zIqHR&Zb3zjg0}~~LEql<{!F)??ZXWnwLd`XSSP#5IqVTclww$%wcN-Z?oB6H7 zB5z#&ru9()`m*DKRPzCYD zc*Sd02)C#4amoFV&{jF&x+~LU!fZc!*XJwtW$q&YlD`Zb0%N^5Dh4LuDaY*T@gLP**Zs~U^IuBKhS1Nd_on{&oZWiX}%A5P3~ zJ|0Auu{h#i&0gNKtH213X9m<~RSV%4j}hZT*i<>9Cbk4BKDNL!{IeGzI&PoFn=~os zyKT`0ZXSiGBobvN+g?7apuU$yD+51jQy_Nf?kNQ&HA#-IV-6~?(5)xBF{;w)B>BTd zNj`(4*f^~rqmMOzuu~0Dq+HqLm%SdIRA`l0L=g5DhL+)#D$C)wRbaaajmvnqXrQ7Z zDwY;Zb?>YRjNF3Y5I^mUaT%dMVwZANp(@F_I4Eazm~?GAHzg?GOq-%;ti~4Z-t$AH z<|B?;F-%LOwYsOsGLX=E#W~FZqQk%qrYMTyNEC0>yY03hEk7F@r+49v&K%h}Q~txb zD}m(XEQN%znsrMO_Zs&>R57K*+D@JuW$%qCu4jg!ZLeImT17!Fs)aL}MVo@v3kT=o z;+ugzm6mOfGk0+?M@AnnHZMGBE_tLe;Xo;|bI_hrkfyv{e&kz2mmzw6 zxe|>H-OnQSp?n0lq?0&E>WIu;RhwL#U32uckKk3nFp-)hjb{6hGOaxj)xs~>gXewg z@6t@;IFt4yZ)AwH_MoS;I4Q}NvEs%Gq z z%BITF#taE>tNlaP-B3Ubx3xhl?@($`x-=^5{5YKTc%=%!IUn($)m`7%r>`6bC>4L$ z9(kPPvHQlz6;0(20cEbWcdB7cR~}xf?`PJXc(1S3bu1jO(JJzC*ghgM@;j$oQE6#S zkRx!d*VlZne|1bwPNI6bJEP|Q(VP1sBA^Y? z@ikZZoBSBZw90y{T+@m#D22uq;pA^AG+Cne2eNzF2i`^50~E_7j$faVVs5_@Lvh-S}pbneM{OFgv6Ls#C4Eav<@XaLy8~ghKtbNBw&hn zR%Oo-2Pgg{*z;dACEpk2%-*hx%G+^m%=R$n=Zu^4q`D#bRx@pO*9R`&|UvgE}b#))h;kvpBu zIG|D(s2{S+mK=DvdrogMs$Xb|qNYA5ap}x-)FeVtf5kB-tzWHwpa)Rko*;Zd&Y01_ z0Wv$sf3^qcT!w{$7=GQ!Ap4t_PaewA5Y=z#4-WQUwXx5Nbqa* z4jQ!?^P*oP?c<}qNj4kNmO9mswAH0EJ#;%`j$U9&U6xguXnBD#d(6$~lOk0hF@TQ1 z&l?6X+Mnt*AuT0=%GvMovl)_Jt?(6$*)XYNNf_Z)+t`i_UX3fIq=?I!&g!+U?!rGo zu4qJ$TC*5BzqoL?*w-7igd*%%LP;K==XvdKw|$R-h`9(JV1+R2c+=X>!o%(3==iYw~fj`9f5l54jB`zkl~U;HQB6A;nbFF zs`H7E{COlbeSskS5-9MtjRxTiYA77Sq8nrBBi4-V`v1# zNOzQj2LFbpP@NR`9Ml<#@TlH51P7`+iJ}BE*TpXnQJ~4@FFz?(+mM3f^@tE&QBXZ- z`Ba~m^6lE=^KqSW@4SJU<4I|XVB21m-eS9kS}a^^3(6Ob_fa?QX|MaedW0>|RnBNt zR|?FUlIq>~B3znW(Bpa^$3KY&-8m-sKX0uL5m@*mvDEvg7KC71@(!0hP4^~gC!&8% zncLeOiKY!7Wkx0SOv3`NZO8N}!{W<~7tgIIsLj4%&7k2wDKf7ZZ;Y;(o|Oy*l$5;a zvZ`t{L&Qx@{qZFhar{s7BA(BVaK_L0wxmi8%d;|-x2Oyyn)j#%YaS2PEHETr+d&G-W-$It5qr}n&0#vd-8 z-p1P6*@wcB>X=TwbmGN}7sC!;wTsnbagPtBW-Q~sZ3Q_l)$^UI;FIVL)abwBvcemG zKyJn4R%tyUYq`L&+5pDIpj_{+ldxQ4j}6XjiTU55(5c)M)OmI`dbb5EY=#kEKtNI3 zsc2&6J~B{MrB^fu_6|KHfRxLJGH2M~PrryizGg*^($wT6kqcpHXcRLtJEnL|DJ2fB zlG%U868Y_n08KqTa^R57$Glf|F=+xCMFy1mC`Z<*`x|5IOF?y zbQ!oAb1yI2<4v7r;)5};?Tdp;j-81O;K*B$JP|d9SWs%XFxD|B){Ke5-mZ-;E~~aUK7i#K?=qTD&=b`% zzBl_G&<1rTf6SJCvw;)-iwwWER{iZPT_28m8^}T!ITmkxe41!ut)L|16B9;B&w%$` zVzNC`#a|d1M39q!XvG(+rpfqBm6Al7MtBk75CIVfM>@FR0jsc+Zo&!!YjJ0NZ&e#m zuJNO*;>@e|Zr~`%g7h2j^HtlHi_v93X*)yZk$Zd~A7cKUqvM}@GDEE0R=;k}nwW9P zQTF~B(cOP+LKMEjozT$rjw&|04nTL)8u|0ND5Y#e_NceQwc?m#t{?~+!Tyw_Ztst8 zIJyiYqgOehaIB8^0$QRzK8;l{1|SL5L@D@NtS15BjRj1cc}c>{>&~k`MhbsMC4e&J z!9*!Oo>gMIbIphLG8IX)AI)HJf&w!hOHV;z+4BBNX!sjz>s{607a;n-%LuV`C4?6T z3*DU`2(gF>;$-@AMFBueL`8$mos_p{{i{Ue-WFf@=r}Ef3+Si;fXsxmfzN3(yDl9SN_kc zBfT)CEKxY}4A_Ckn^YV3+TjhL%l<3&kWg2ZEN&>%k`6_&bNEK&m5i$V(iTxLs7Xpx z$bhG-iumudeWuRuY!6+3$o6Kj9kdvo4<5Zr8WCPG&HCj*#nkV(s;5v;!jJ;R{En;A zzs6O&>_6j*M&Yk<_02{nN=eeiwW7TL-Pan7{1v9(78>9vYMS5FnHp1jV%^-_)Oua8 zSVE@*T%g*RfKk;6gTYWeT~E=;dhmh)juC{~j+1Ui#WwPNyZ!i8)d21xGe3G;^_@B; z6?PT#Kk|Lmy@(JKsb<(r!h^BDN~R#{?f@ZgU60(<{BO}!@%QL5wk42N=^N(e=hqx} zis#zYoYxAD!h13S6bp^B=auumh}3*p|JfyqmUlpy!p0F6eyWw9#P%K=BE_v}^yNr~ ziV}zNaOF<*(GP|(&W{8&bNOZJuk#|$)j|s`&yPNRtj3G1_JM$c0*5|aK%g?3jcOuj zAZK#E>T*4lG*)9XLH*P^J+$jJcN@l2a&Bu)>@dz5ELEkEhcveAKpL8`q103zbJly&>$c%QoUHn z(3`oB3djH`W)gD&-%pIJNQ%1pb>Qd(_9|1tLi0A|4JixRnsEO3=A$9_1`lDzhxLy* zhL;`ZWB|V4p~-T%yi+(QVDp>+5zxIN{5-gDrND(T!)NU#p#l_ zh*=-D@l-yC(ic+(cq{+b4%^M;PxE zceTixu_c|l;jS_iw~|idelUigz5X(f~xzaoDHCEa@{HYH^n|(_A@x{wEUK#T{0Hh^Ep)h;g|rXNKH1(6%|7kN z>n;^s2=)~v?exF-1m3%|izU(SHDymy!bg>|iQ4mkm5${)PFUU)(@d!Q;E0bi@8t2o zH@mdx*nb?*7PPQ4Bd*tZ1=SbL&S-b}s#90;s7YBw)-80i=l@dY!0Rc#h^cfEe_u<2 zqNDYmArgURP}dibG!47<3Ub2Y#h!jH9m$lVqBOyq#bY<$Ul?IQ6tB<))J(9i|3ELp zD5XEPa4)Fsv40~9SZH5bd}9j*bp))6fwq8soIsb$UMhlK>Vf&541T zdIH-Rg+JhEi-n|OB*_w}p7L!+!rA5XW{kURPIkEp&X)pIM(sfq32gY0=b27CT8}m7 zLK?7d%X2}OG5inMGJ>yDC_rPyD1Uc_MYBzD#hn3X8p?KR$n{CKwF-W+8hfD{H?%PD z5f{)1`gH#aj~%C$p+vM*a&aLrsC7&goLqJ#lFhr^ud|P!r~_Y*Ba@Kc-g#q7FqVnl z>Pb-fsP!0lme43qXt>QCyJWXGQViAubhbKRt|nS~9x@S#44GyX z#VegNPe$rgx;i~2`>n!)fR^B#B;`_c;pwu^N>=I(G3Kh(KBU#JBNI>fg9_nePNatl zYZ>6BW>7vYM$c5w6oNeZR$M#7QBd-?zlR=BNy_A@=9E>HA(|i=0$fQd0a}<>4^S)H z%HP_{_OpiUeKorYCDu4LByrQ@QMu)RvL)Xy4zE=oOVfYrVndFyqU4eJiOyMw@k4Gi{; zo>WJznKr%f*dfn)Yr8|h^yYce;h8+S%2seT`b(lpMdO^k6{c_Bz$xq%B_@*c>fA(52hf;Q?)gu8#eM+BC+GhUat;5n z&1ArPg5aYc%F+9#3vY<*2HKb;MAE;x-p?dY|*)2Nou*!1f8T*-2(b6bFqOYlgt z=Zk8hKC08`TpHXT>h#bi6&vuo#`2f_j{U1X8?;T|Sxg`5rdH4UDcl?rL7h$%= z&+lK}HSloB-ktyjDjo8_=>z-QR=2>-|z8Y2@DMdacK?4yfP7l8-%Eo?e7np57CaUp3d^Tz{aU@*2YN&c~GW;J<2 zQZ^>D+WEOnak))qafA)Dkp#LhE1`tZqq-nrpif7g@!2F#!E5_;vvZtIA;T$biCu}qbeX#VwzWDD^(lCkq6Cxujd1ENsFtJb?=1*iuqAE+7XJs zUxT7#_^(LOhr=xenRk5SRHiW|u&j@aqpzYuM1;@NSb>TPKe$4}$oV#E_&H^ifhKxC zAG{-LZ^h8*?`r>We8#cB4TRr9H?#Pn5VGFI7dc&Wb0XNc;TUaxS8g~M5z9n<*XTkm zq<-6t`;e8ziVRa9iU^WKc$A7DBar+iNW%M``)~;;SwH}u37k%R_U`dI8h{B(83Vi|KTi9sg@1gV+o;F5xPmR|K&#E?<`9g$cmyg;#CQ}q0@FTVqXw|$A--5dg-MtI zCj`)N=x_St z?7`1#L_Q15N7)DZAcm!t{wAI>I{ruk7XI|ldoC=pPX(rhqg!q1mj?WfHr)TYvGT8P z+i&-!Uy^~F!ifm->`3a~v{#Aj1W~#v>PvK$wFjG2h0n1k-G|uJnVz|7707hd7hmy> z?-!J~!^40jQX{}d{ouVIU(eVNQS}WCj2`m=rs;{zL{EqfO4;jxE{<$k?fW0f3lfx{ zLOh%;XxwI27liE$Qhi>JohD&pqlvl4qmQw3z@Dp7XDpHUQ09V(;5wqk$V@{v*>1h? z%n`r%TclrsqRkO{Dv0l$vKd~p`g*Es_gNVPPs0?x=FIfWsLM!Ev0s05`uPN}S}pj8 zpGsV)gyCrb6Jn5^k&s;v@#IiNZ?vzI$Br>hCT@|DdH%8S=^;Apj#e08)QoSi<;Z3X zH{(gDdolZj^`(sXXG|>$^DQrYrU$!csnfxEw?sHHkeX7ozP)Nv113QW~37*Cn7laYWzK=ypT$yH<{t-BKLnYGifNDl_?{Ov}c^Zbm=Dmepv3qVC`mAMUVWq)<%uoU&yz-Q9kR@IyG6uT}%H zW=82J^Gx!8?~rW&^2XL8VS875JT%y&GF?_t-ET=_H&cPG*4tH#IU|YJ*22g}oAjhZvJRgYpzfWe z_SWxcCgS3fa{n%5eRLb$kA`l3InWuI!~NW-PY?>_4&AJJ{x=09rE7!g*D$VqBXyOC zxT<$1>qDCp?(aUow^)@U;6spvwJENC&K(T-Dft;D?X}K6aMBe0jsVXO^iRle7vHQ(G3oP2 zNO!%_jjL&jjS=k#U@+A7Z`{}b*Srt1i8G?8!FCZ3QQdtof%8Y=hKce!Xt4QnAIDEC zRPNm>$@IC3^cBS86;Z7ilf)bvS^TIt7wXF9vJf7&e(Y)JoHZ>OZUZsXYd1k0gH2zY zCB3pCDt4J1D2>FyX?}lI#Pj+sWX0*@mhaW(&fTZsU@D!y8Wfo(k(;CXi($4Zv3Ng( zOJCx(RHyQ~CNQGnSXVb`-Wog5)n8^89*g>tFGnS-6=*pzf6^=ce6$jWXv<(*h{-^F zhYW6^;%keyGGL3W-@dB(1KO|E+y(ky)+2EkizRGlj$<7jmCyE1HvD`%!zv%TO z5b}KuIQ~U}ET|zmza8J{@7Mu#rO@AybMd_BO03a9+2$qugMJwoap5)(TvstZYOf3_F`ySZ1AR&B|_w%3Tp-g|Luiux=Vjz$dg$xjBSV+lY|12j|2Er;4tkv~F4aFx88wlrPOHst;d2OD zt9>r3BZYPM?gBqqzUfp}q1n~fw*rfFhwr8>uKF4#l zwYqrP`|h4~cuRTqx9*a0)G+kNq5b9CjMU)JH!wi4nyy!ZQ)2)$`Z8Vw zOf%ZJ*T*ob`o68&(;ahhB^A-L$0h?mn=&Aop_1!aKI%({ABswk>63yEJ?rji0R?CA z@gD_;yc+)*ljiVhq6dWQ%PXK)-a@yzE#o+$+{xU*W8^~wt@@0@Bs6d^}9qoPyN^SSMwEvsNV#REwQ>hweBtKS!= zIma3eId?3>jvBm0cflaCA@qO@nEjXu|Ck0rN1pmxft|14t7+J zi}?!;V|9~}@j)^|vVVMl6#N($vn%X3f|8^BwZ!>bLH(ci^LC=H#^-hrMM^@6!-GWx zq)W{Hm?tArG-o8wK1_dGjf3jIxcgnSN+Tn_J&lFRHL`4kNj4X+RY{9Gp8{41Gj=>S zt|!C00HNkOt(3Hq7s9P zQPHX9V@$yNI3Xdb{2a6;*;!drn>vghFPkMs+N>Tgb#9*>(dxpK~e zZV5ellG+dRQ7ao5bDR0k)^MAQBpV`f7U>&qG$su*$^z%^$H}t=ra^qF(w#%37 zP?cs|CeiD-7DVi~S0iZNu1bm{{a5j0^++9bXf)L-LloI~+r_GeCiZum<$hs)uCn^$ zo&(uEF^hF3XWgq^nO7OlpK=8V7pQ)~ICqxqvOOp0DeEZ}PSRLhdUu9CB91>2iHWO| zjZQRct{U-4w39kp+8C-eCz`n-3E9@X@}+$GGx-ZIAN$qT?MBauuOht5HEnZaEpbnF>-W9Q= zUH7xGD6;N^h5IRVNY8``DM*tQ0ccK&<+q|8!q0 zR8bv9BNz|q=5;%6*;_r69N-`O=AJ{&N{!xLzp6S~e8jX4yEElcQ7Ja?O(pqCZ1eQT zbF6(*{-|H16T}+_(LU9&>ZV;ds@=dewXVnK6(e z5EenYB3d^kw&kM%twXDo`TB~TVJx1htFJLGQ_SaZtbw(k6seVM=Nr|{zGnVaAeiB^ zG%KHIZ&uv6Ioe3vPV~=2u=eb?e0Hvj7}^E3=X%LleZ%EnCb}F}F?@wY>q=NRy6hY! zI^Sq#2Yy;@G!<4O;QYU`QN~P|E(Z$dU=d9)E9i1aiZ`e%++55EEQ?A&WsusD7 z6~Dy)`hfw9J3H>nS%8@>sex}(*2M=QT4r9q&3fhhEHxoB)9_ck>802-T3_X5VIg6M zXFgX^nPD2}pqe+Xlp!S*G_;*YXKbl+^(d9HaWvhgdTtWZ|ErSo4r)5v;&`aK6x|gN zr3kAC649VYM^F(F5Rl%BVgN%z?!2`YqubV5jY zzn$6Hoj3D#W_RZPdw=K7o%wuExxaH}#=FL1BcFnyOeksabijd6bm%Lt4wo{=Nc_## zF`ZlsSytAl$g{_2C3{8f5=10p>ArU~oJqG)w@$xh^ZbEX7FKo5uguo6jhdYKNw?M8 z34PX2;FI@h2_oTG!+G>YKlKJ{bC&BhTivW%<=DE<7bFhK)sZt1jF$xdZ?A`Hh)X#a zc`=19n&Tv2A4kcBH!BWTQixqqjmoRZ8NuGx&0Wok{aLt+(6F!5}BF#TDL@ zBDi>F-@o>!f+AY)fLgew3M!bYMmS&}H`}{Okevo~((}ZL0Ez1U`-g?@@nDUjx8WT( z-PMfzB-AUb&V1;B8vb(Cy{ttI^o9I-i!gC9NF!MSO5HjXebw$94PeUo2c{x6;4E(f zTa~Ey z>>np(^EtJ$iHTu@eh&<4=X5@z%o+$xq)Apq>+_if92lK29IL9Ky*Z_pEYZ=?tDZ^Q z_m}W^>LzK`#>yJUPfO1(cCnI(obrQwH~ zWp*wmh%CF;C5Dj$Azofa&tGE2#?lrNFE6)MIO|x6UEXV(WvCe0*7eL8zdCf9XCNf3 zV95vYHO;r^K)nns(?k)xXtb^zAyxgiaLp5Y%OKTD^ZyXxbsi*5{GE3M}Y}u@K43H z_q|oB<{{?(mP-xblOR`&pa7NPlL)TGiGx6n?>^*IbAUnx{ssT5EY+YW<_?_z;Q)1( zgw(~tdoxr(AVtaZUjJA_e*XqXi;I*F(lJC7bdCkQ#n4vYHvdTMXq1C3#IW zh*M^{ldSGH+gWv`m)-J*7skozvg)^`uzJ#5w)x)_QdgevVT22=Y`?2Zy21NKHm#qN zM8Q6yPn-Le)!$9lT1+=MpJA}r{-L{Qb7$KlD|Um_&Z(zC+BW(uq|~1lAd_JrSoOtE z6QVPbBc4Y%!kE88HlnAs&m?*!I%(G3$YAwBmJUB_C#R&S`p*=wJCAZ-joE(DFH9UG zoF`4?)ZFkWS)7`QGhZxw*;i&F;+ZR%u(Lf0RwXw;ms+MQ8{wuaQabvL;njDLO^y;v zG7S;TUQDr&kFOvu`d*`grmZ>bxE89k*N<5iK6^BCfTy8qJ*+qVD_VBn!FlLVFUnC- zTZzeK0m%ATu}v+-W-a?QI?6#~{qwgMVldktaChtj5k9d;J;hNMUD}JD!6#WpLw z{?I$xm6P*y=R1B*p0WDMlA@97x1ANQ zy1gp@Nxne=UFuAVdLLJ2^|~?~UNQKBcYJ5nE4%IOUgEaL7=EcDdf{i_NM{^>_+XfKOd#oO?SvZ9R zRRP7xo)oFDDWNY3T8sW^e0?I?zVOt91b(+O9jEltUR{sCyy*i50pj^vb_I5`@PjBqRid zaCBb!iP(A0qt`|gG;{1-`LoQ4c`dGM>729k({R|Ky}V|`w-E@AV0r)bIlLF z1goC!qzt*;nT#IV@-pnP_}>})bf;Ll&hcu+BVb*I_-q-}q?J4N5BplkKyobmnL%g1 ziiMRdWLRj2#*Aw#uZovNRcvk!>`%4MucPYr4;WS6;d@c%QaK!5Qf)3nL@JGy^Np2F zFY&Y%d|5=K4lK!7SvR|0hwF^XZ20%`j1l*QOAiKT*1KR+HOUyP5UklaX=M6mV84aT zfY-Mc`|Q~Po2uVn>S!TIt~Y%#(?_Dp9wUXx_YzuCNKH27KeymkHB-GT%FyyR)mRQZ zF%{NYa=Qw#qOhw1XzaKUO8$kpq46`L-gFUeu>`7g-Hd_ZBJ5_zy_0$#e2=`MDg0+H zZOaAp9*H;V3kze+>;)Udb1nvy&=(#DQw6c6l&cfBQ5gF;NyNn>IatN4nd1|}$l})k zRAC|QU=uxM{{|mjSyvc@RG%3lXpKW1y!55HTC~aLFqi`@(jl<8U_2Flqid_1F%HeK zLVQ54RMtEbo!d+ji(eV0?D&HzXGog8M#0M7bC4+gjbu){@^e^$WR*QieW?i!-QABV z{S^~(O~E0gR1UJ+gvFMtYDzloWCT%y4dUpM=cj7aN~dAX*ycu7C&ZH%X(1XzOE{}s zx^Cw)a^I~w4ZSd2$(Pig{;HhFe(Fw2xczEFKlaImWK)_Nd)m6lWnnc(s#u9fW9)Iq z7y?j0IwesfUU)HG<8;Bqke!=_4}ai@chJac0j<45e$d*(!TfU^MrgeZFl~==R*wLV zVc32j#&oQ~G}UBJO>5d87+sR$RRZqbjZVgh!S0##h^3vK9+N&%-2(R#4XhTDL_``Z zyVJ?mzcuDTRPSqx62aX{^FW`dcIgCo*JG*=5amif3uuDi;Nz;S&rzc(O`-iOk} zrzn%wxKUu4fuWsSwt%X8HCkRM4NNC{`D!YC&m^k`I_4_tHd?A(&o)73S$)XfK`c>; z;)yB6HyDqiMZ#f{#@1gEqE*KMP*e|iGD1Bx_&5c;q_QH0OOUQDQ!%#*yF}npm z+m^0j^NZ_hlf$yi3B$Xa*j>b$CoZ4@D6qK7;=KXWv__yrcOK$wnYnp(a+Ig)Ma>hF z6y*Ss9a*5VYen}|)Fu_kWtm#Nfr})gr71|^YuPA+r^5}xRM~!|de(*XsJ03$w+0Mb zii#V#2Vc8O$7sYQ*ItfDz-nWIx4uBNrcu}^R|m}>2BCMWErA?Fa@`Y1ho_a z^ykZoT=E3~A6gJS{f=RM`W=}}ejYt#@wH0Z#Sk*re(LyW*mO@*5Tg~1QiW{)$U_5u zDS4XWa!}#`ytbYr4+5Zr|RN?>_f{WPBeV;i`X<1;{x+pBWMH#%mC@j zA4$ny@;5)|Cg8IM2+6Ed=*ZDWpVAyK`y%8k&#+ieo-5Y6B(Z;x(tMYy*v*XV8~P99 zkg)vTB|=QA4(C^U7!_62v12}z0tw%(EgC6|Ufv!K>tX#TC&XijeK%jqWn_BG-ZVOL z5Er7e6}}}_!t@C8qUIhV!^%T+oN0CVOr!vtjRP`jg&V8)U-}ZlAXGY$a!s-kY*paM2c(wcPZcn$Z@v79$1K)o1+F)VIX@?A^cZUKKX+Z{hCbw&Exjy+XU)%60 literal 0 HcmV?d00001 diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index 4f5fd7e713..6088cd305c 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -25,7 +25,7 @@ ms.date: 09/05/2017 [!include[Prerelease information](prerelease.md)] -Use the **Settings** menu ![Settings icon](images/settings.png) to configure the time zone, suppression rules, and view license information. +Use the **Settings** menu ![Settings icon](images/settings.png) to configure the time zone and view license information. ## Time zone settings The aspect of time is important in the assessment and analysis of perceived and actual cyberattacks. @@ -39,7 +39,7 @@ Your current time zone setting is shown in the Windows Defender ATP menu. You ca ### UTC time zone Windows Defender ATP uses UTC time by default. -Setting the Windows Defender ATP time zone to UTC will display all system timestamps (alerts, events, and others) in UTC for all users. Choosing this setting means that all users will see the same timestamps in Windows Defender ATP, regardless of their regional settings. This can help security analysts working in different locations across the globe to use the same time stamps while investigating events. +Setting the Windows Defender ATP time zone to UTC will display all system timestamps (alerts, events, and others) in UTC for all users. This can help security analysts working in different locations across the globe to use the same time stamps while investigating events. ### Local time zone You can choose to have Windows Defender ATP use local time zone settings. All alerts and events will be displayed using your local time zone. @@ -55,25 +55,36 @@ To set the time zone: 1. Click the **Settings** menu ![Settings icon](images/settings.png). 2. Select the **Timezone UTC** indicator. -3. Select **Timezone Local** or **-8:00**. +3. Select **Timezone UTC** or your local time zone, for example -7:00. + +### Regional settings +To apply different date formats for Windows Defender ATP, use regional settings for IE and Edge. If you're using another browser such as Google Chrome, follow the required steps to change the time and date settings for that browser. + -### Date-time format in browser **Internet Explorer(IE) and Microsoft Edge (Edge)** -IE and Edge uses the locale settings configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. +IE and Edge uses the **Region** settings configured in the **Clocks, Language, and Region** option in the Control panel. -**Google Chrome** +Take the following steps to change the date and time format to conform to the format that you need. -If you use Google Chrome to access the Windows Defender ATP portal, you might need to configure the language settings for the date and time format to reflect your locale. +1. Go to **Control Panel** > **Clock, Language, and Region**. +2. Click **Region** > **Change date, time, or number formats**. You can choose to use match the current format to match the Windows display language or you can specify date and time formats to suit your preference. -1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. -2. Restart the browser for the settings to take effect. + ![Image of region settings in control panel](images/atp-region-control-panel.png) ->[!NOTE] ->There currently is no support for Japanese date format format (YYYY/MM/DD) in Windows Defender ATP when when accessed through Google Chrome. +#### Known issues with regional formats +There are some known issues with the time and date formats. + +The following date formats are supported: +- MM/dd/yyyy +- dd/MM/yyyy + +The following date and time formats are currently not supported: +- Date format yyyy/MM/dd +- Date format dd/MM/yy +- Date format with yy. Will only show yyyy. +- Time format HH:mm:ss is not supported (the 12 hour AM/PM format is not supported). Only the 24-hour format is supported. -## Suppression rules -The suppression rules control what alerts are suppressed. You can suppress alerts so that certain activities are not flagged as suspicious. For more information see, [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md#suppress-alerts). ## License Click the license link in the **Settings** menu to view the license agreement information for Windows Defender ATP. From ffb99aedde8eed1f4038e2d491e47621592f8816 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 12 Sep 2017 14:44:33 -0700 Subject: [PATCH 07/30] minor update --- .../settings-windows-defender-advanced-threat-protection.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index 6088cd305c..bf8283a33f 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -86,5 +86,6 @@ The following date and time formats are currently not supported: - Time format HH:mm:ss is not supported (the 12 hour AM/PM format is not supported). Only the 24-hour format is supported. + ## License Click the license link in the **Settings** menu to view the license agreement information for Windows Defender ATP. From 42607bb113d3a8f6a5578968a6c6f90393b8dc40 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 12 Sep 2017 15:15:17 -0700 Subject: [PATCH 08/30] update to include dot in numbers --- .../settings-windows-defender-advanced-threat-protection.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index bf8283a33f..d47d1f13da 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -73,6 +73,8 @@ Take the following steps to change the date and time format to conform to the fo ![Image of region settings in control panel](images/atp-region-control-panel.png) #### Known issues with regional formats + +**Date and time formats**
There are some known issues with the time and date formats. The following date formats are supported: @@ -85,6 +87,8 @@ The following date and time formats are currently not supported: - Date format with yy. Will only show yyyy. - Time format HH:mm:ss is not supported (the 12 hour AM/PM format is not supported). Only the 24-hour format is supported. +**Use of comma to indicate thousand**
+Support of use of comma as a separator in numbers are not supported. Regions where a number is separated with a comma to indicate a thousand, will only see the use of a dot as a separator. For example, 15,5K is displayed as 15.5K. ## License From 0c650fbf09e560f5feeb3abb286125974dd8b155 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 12 Sep 2017 15:17:27 -0700 Subject: [PATCH 09/30] add to troubleshooting topic --- ...ows-defender-advanced-threat-protection.md | 25 ++++++++++--------- 1 file changed, 13 insertions(+), 12 deletions(-) diff --git a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md index 18014303d9..de337b11fd 100644 --- a/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md @@ -50,22 +50,23 @@ If onboarding endpoints successfully completes but Windows Defender ATP does not For more information, see [Ensure that Windows Defender is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-is-not-disabled-by-a-policy). +#### Known issues with regional formats +**Date and time formats**
+There are some known issues with the time and date formats. -### Windows Defender ATP has some date-time format issues -**Internet Explorer(IE) and Microsoft Edge (Edge)** +The following date formats are supported: +- MM/dd/yyyy +- dd/MM/yyyy -IE and Edge uses the locale settings configured in the control panel language settings. To change the date and time format to conform to the locale that you need, you can update the date, time, and number format from your PC's control panel. +The following date and time formats are currently not supported: +- Date format yyyy/MM/dd +- Date format dd/MM/yy +- Date format with yy. Will only show yyyy. +- Time format HH:mm:ss is not supported (the 12 hour AM/PM format is not supported). Only the 24-hour format is supported. -**Google Chrome** - -If you use Google Chrome to access the Windows Defender ATP portal, you might need to configure the language settings for the date and time format to reflect your locale. - -1. Go to **Settings** > **Advanced** > **Languages**, then chose the language that applies to your locale. -2. Restart the browser for the settings to take effect. - ->[!NOTE] ->There currently is no support for Japanese date format (YYYY/MM/DD) in Windows Defender ATP when accessed through Google Chrome. +**Use of comma to indicate thousand**
+Support of use of comma as a separator in numbers are not supported. Regions where a number is separated with a comma to indicate a thousand, will only see the use of a dot as a separator. For example, 15,5K is displayed as 15.5K. ### Related topic From f28c357c48b27c60b5063de6de68495e95e74ba5 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 13 Sep 2017 14:26:30 -0700 Subject: [PATCH 10/30] remove steps, add formats, update decimal --- ...ows-defender-advanced-threat-protection.md | 19 +++++++------------ 1 file changed, 7 insertions(+), 12 deletions(-) diff --git a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md index d47d1f13da..81b976e914 100644 --- a/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md @@ -61,16 +61,10 @@ To set the time zone: To apply different date formats for Windows Defender ATP, use regional settings for IE and Edge. If you're using another browser such as Google Chrome, follow the required steps to change the time and date settings for that browser. -**Internet Explorer(IE) and Microsoft Edge (Edge)** +**Internet Explorer (IE) and Microsoft Edge (Edge)** -IE and Edge uses the **Region** settings configured in the **Clocks, Language, and Region** option in the Control panel. +IE and Edge use the **Region** settings configured in the **Clocks, Language, and Region** option in the Control panel. -Take the following steps to change the date and time format to conform to the format that you need. - -1. Go to **Control Panel** > **Clock, Language, and Region**. -2. Click **Region** > **Change date, time, or number formats**. You can choose to use match the current format to match the Windows display language or you can specify date and time formats to suit your preference. - - ![Image of region settings in control panel](images/atp-region-control-panel.png) #### Known issues with regional formats @@ -82,14 +76,15 @@ The following date formats are supported: - dd/MM/yyyy The following date and time formats are currently not supported: -- Date format yyyy/MM/dd +- Date format yyyy-MM-dd +- Date format dd-MMM-yy - Date format dd/MM/yy +- Date format MM/dd/yy - Date format with yy. Will only show yyyy. - Time format HH:mm:ss is not supported (the 12 hour AM/PM format is not supported). Only the 24-hour format is supported. -**Use of comma to indicate thousand**
-Support of use of comma as a separator in numbers are not supported. Regions where a number is separated with a comma to indicate a thousand, will only see the use of a dot as a separator. For example, 15,5K is displayed as 15.5K. - +**Decimal symbol used in numbers**
+Decimal symbol used is always a dot, even if a comma is selected in the **Numbers** format settings in **Region** settings. For example, 15,5K is displayed as 15.5K. ## License Click the license link in the **Settings** menu to view the license agreement information for Windows Defender ATP. From cd59adc8976a5495296ec9902dc1a51ade24641c Mon Sep 17 00:00:00 2001 From: Elizabeth Ross Date: Thu, 14 Sep 2017 16:51:02 +0000 Subject: [PATCH 11/30] Merged PR 3191: Updated text, formatting, and content organization --- ...change-history-for-configure-windows-10.md | 9 ++-- .../configuration/windows-diagnostic-data.md | 48 +++++++------------ 2 files changed, 22 insertions(+), 35 deletions(-) diff --git a/windows/configuration/change-history-for-configure-windows-10.md b/windows/configuration/change-history-for-configure-windows-10.md index 08c50e3ed2..2a2a60a09d 100644 --- a/windows/configuration/change-history-for-configure-windows-10.md +++ b/windows/configuration/change-history-for-configure-windows-10.md @@ -29,11 +29,12 @@ New or changed topic | Description ## July 2017 | New or changed topic | Description | | --- | --- | -| [Add image for secondary tiles](start-secondary-tiles.md) | Added XML example for Edge secondary tiles and **ImportEdgeAssets** | -| [Customize and export Start layout](customize-and-export-start-layout.md) | Added explanation for tile behavior when the app is not installed | -| [Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added that Microsoft Edge is not supported for assigned access | +|[Windows 10, version 1703 Diagnostic Data](windows-diagnostic-data.md)|Updated categories and included diagnostic data.| +|[Add image for secondary tiles](start-secondary-tiles.md) | Added XML example for Edge secondary tiles and **ImportEdgeAssets** | +|[Customize and export Start layout](customize-and-export-start-layout.md) | Added explanation for tile behavior when the app is not installed | +|[Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added that Microsoft Edge is not supported for assigned access | |[Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md)|Updated several Appraiser events and added Census.Speech. | -| [Manage connections from Windows operating system components to Microsoft-services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) | Updated Date & Time and Windows spotlight sections. | +|[Manage connections from Windows operating system components to Microsoft-services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) | Updated Date & Time and Windows spotlight sections. | ## June 2017 diff --git a/windows/configuration/windows-diagnostic-data.md b/windows/configuration/windows-diagnostic-data.md index 611432abea..9f56ccf841 100644 --- a/windows/configuration/windows-diagnostic-data.md +++ b/windows/configuration/windows-diagnostic-data.md @@ -6,12 +6,14 @@ ms.prod: w10 ms.mktglfcycl: manage ms.sitesec: library ms.localizationpriority: high -author: brianlic-msft +author: eross-msft +ms.author: lizross +ms.date: 09/14/2017 --- # Windows 10, version 1703 Diagnostic Data -Microsoft collects Windows diagnostic data to keep Windows up-to-date, secure, and operating properly. It also helps us improve Windows and, for users who have turned on “tailored experiences”, can be used to provide relevant tips and recommendations to tailor Microsoft products to the user’s needs. This article describes all types diagnostic data collected by Windows at the Full telemetry level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1703 Basic level diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md). +Microsoft collects Windows diagnostic data to keep Windows up-to-date, secure, and operating properly. It also helps us improve Windows and, for users who have turned on “tailored experiences”, can be used to provide more relevant tips and recommendations to tailor Microsoft products to the user’s needs. This article describes all types diagnostic data collected by Windows at the Full telemetry level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1703 Basic level diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md). The data covered in this article is grouped into the following categories: @@ -21,10 +23,8 @@ The data covered in this article is grouped into the following categories: - Product and Service Usage data - Product and Service Performance data - Software Setup and Inventory data -- Content Consumption data -- Browsing, Search and Query data +- Browsing History data - Inking, Typing, and Speech Utterance data -- Licensing and Purchase data > [!NOTE] > The majority of diagnostic data falls into the first four categories. @@ -66,8 +66,15 @@ This type of data includes details about the health of the device, operating sys | Category Name | Description and Examples | | - | - | -| Device health and crash data | Information about the device and software health such as:
  • Error codes and error messages, name and ID of the app, and process reporting the error
  • DLL library predicted to be the source of the error -- xyz.dll
  • System generated files -- app or product logs and trace files to help diagnose a crash or hang
  • System settings such as registry keys
  • User generated files – .doc, .ppt, .csv files where they are indicated as a potential cause for a crash or hang
  • Details and counts of abnormal shutdowns, hangs, and crashes
  • Crash failure data – OS, OS component, driver, device, 1st and 3rd party app data
  • Crash and Hang dumps
    • The recorded state of the working memory at the point of the crash.
    • Memory in use by the kernel at the point of the crash.
    • Memory in use by the application at the point of the crash.
    • All the physical memory used by Windows at the point of the crash.
    • Class and function name within the module that failed.
    | -| Device performance and reliability data | Information about the device and software performance such as:
    • User Interface interaction durations -- Start Menu display times, browser tab switch times, app launch and switch times, and Cortana and search performance and reliability.
    • Device on/off performance -- Device boot, shutdown, power on/off, lock/unlock times, and user authentication times (fingerprint and face recognition durations).
    • In-app responsiveness -- time to set alarm, time to fully render in-app navigation menus, time to sync reading list, time to start GPS navigation, time to attach picture MMS, and time to complete a Microsoft Store transaction.
    • User input responsiveness – onscreen keyboard invocation times for different languages, time to show auto-complete words, pen or touch latencies, latency for handwriting recognition to words, Narrator screen reader responsiveness, and CPU score.
    • UI and media performance and glitches/smoothness -- video playback frame rate, audio glitches, animation glitches (stutter when bringing up Start), graphics score, time to first frame, play/pause/stop/seek responsiveness, time to render PDF, dynamic streaming of video from OneDrive performance
    • Disk footprint -- Free disk space, out of memory conditions, and disk score.
    • Excessive resource utilization – components impacting performance or battery life through high CPU usage during different screen and power states
    • Background task performance -- download times, Windows Update scan duration, Windows Defender Antivirus scan times, disk defrag times, mail fetch times, service startup and state transition times, and time to index on-device files for search results
    • Peripheral and devices -- USB device connection times, time to connect to a wireless display, printing times, network availability and connection times (time to connect to Wi-Fi, time to get an IP address from DHCP etc.), smart card authentication times, automatic brightness environmental response times
    • Device setup -- first setup experience times (time to install updates, install apps, connect to network etc.), time to recognize connected devices (printer and monitor), and time to setup Microsoft Account.
    • Power and Battery life – power draw by component (Process/CPU/GPU/Display), hours of screen off time, sleep state transition details, temperature and thermal throttling, battery drain in a power state (screen off or screen on), processes and components requesting power use during screen off, auto-brightness details, time device is plugged into AC vs. battery, battery state transitions
    • Service responsiveness - Service URI, operation, latency, service success/error codes, and protocol.
    • Diagnostic heartbeat – regular signal to validate the health of the diagnostics system
    +|Device health and crash data | Information about the device and software health such as:
    • Error codes and error messages, name and ID of the app, and process reporting the error
    • DLL library predicted to be the source of the error -- xyz.dll
    • System generated files -- app or product logs and trace files to help diagnose a crash or hang
    • System settings such as registry keys
    • User generated files – .doc, .ppt, .csv files where they are indicated as a potential cause for a crash or hang
    • Details and counts of abnormal shutdowns, hangs, and crashes
    • Crash failure data – OS, OS component, driver, device, 1st and 3rd party app data
    • Crash and Hang dumps
      • The recorded state of the working memory at the point of the crash.
      • Memory in use by the kernel at the point of the crash.
      • Memory in use by the application at the point of the crash.
      • All the physical memory used by Windows at the point of the crash.
      • Class and function name within the module that failed.
      | +|Device performance and reliability data | Information about the device and software performance such as:
      • User Interface interaction durations -- Start Menu display times, browser tab switch times, app launch and switch times, and Cortana and search performance and reliability.
      • Device on/off performance -- Device boot, shutdown, power on/off, lock/unlock times, and user authentication times (fingerprint and face recognition durations).
      • In-app responsiveness -- time to set alarm, time to fully render in-app navigation menus, time to sync reading list, time to start GPS navigation, time to attach picture MMS, and time to complete a Microsoft Store transaction.
      • User input responsiveness – onscreen keyboard invocation times for different languages, time to show auto-complete words, pen or touch latencies, latency for handwriting recognition to words, Narrator screen reader responsiveness, and CPU score.
      • UI and media performance and glitches/smoothness -- video playback frame rate, audio glitches, animation glitches (stutter when bringing up Start), graphics score, time to first frame, play/pause/stop/seek responsiveness, time to render PDF, dynamic streaming of video from OneDrive performance
      • Disk footprint -- Free disk space, out of memory conditions, and disk score.
      • Excessive resource utilization – components impacting performance or battery life through high CPU usage during different screen and power states
      • Background task performance -- download times, Windows Update scan duration, Windows Defender Antivirus scan times, disk defrag times, mail fetch times, service startup and state transition times, and time to index on-device files for search results
      • Peripheral and devices -- USB device connection times, time to connect to a wireless display, printing times, network availability and connection times (time to connect to Wi-Fi, time to get an IP address from DHCP etc.), smart card authentication times, automatic brightness environmental response times
      • Device setup -- first setup experience times (time to install updates, install apps, connect to network etc.), time to recognize connected devices (printer and monitor), and time to setup Microsoft Account.
      • Power and Battery life – power draw by component (Process/CPU/GPU/Display), hours of screen off time, sleep state transition details, temperature and thermal throttling, battery drain in a power state (screen off or screen on), processes and components requesting power use during screen off, auto-brightness details, time device is plugged into AC vs. battery, battery state transitions
      • Service responsiveness - Service URI, operation, latency, service success/error codes, and protocol.
      • Diagnostic heartbeat – regular signal to validate the health of the diagnostics system
      | +|Movies|Information about movie consumption functionality on the device. This isn't intended to capture user viewing, listening or habits.
      • Video Width, height, color pallet, encoding (compression) type, and encryption type
      • Instructions for how to stream content for the user -- the smooth streaming manifest of chunks of content files that must be pieced together to stream the content based on screen resolution and bandwidth
      • URL for a specific two second chunk of content if there is an error
      • Full screen viewing mode details| +|Music & TV|Information about music and TV consumption on the device. This isn't intended to capture user viewing, listening or habits.
        • Service URL for song being downloaded from the music service – collected when an error occurs to facilitate restoration of service
        • Content type (video, audio, surround audio)
        • Local media library collection statistics -- number of purchased tracks, number of playlists
        • Region mismatch -- User OS Region, and Xbox Live region
        | +|Reading|Information about reading consumption functionality on the device. This isn't intended to capture user viewing, listening or habits.
        • App accessing content and status and options used to open a Microsoft Store book
        • Language of the book
        • Time spent reading content
        • Content type and size details
        | +|Photos App|Information about photos usage on the device. This isn't intended to capture user viewing, listening or habits.
        • File source data -- local, SD card, network device, and OneDrive
        • Image & video resolution, video length, file sizes types and encoding
        • Collection view or full screen viewer use and duration of view
      | +|On-device file query | Information about local search activity on the device such as:
      • Kind of query issued and index type (ConstraintIndex, SystemIndex)
      • Number of items requested and retrieved
      • File extension of search result user interacted with
      • Launched item kind, file extension, index of origin, and the App ID of the opening app.
      • Name of process calling the indexer and time to service the query.
      • A hash of the search scope (file, Outlook, OneNote, IE history)
      • The state of the indices (fully optimized, partially optimized, being built)
      | +|Purchasing| Information about purchases made on the device such as:
      • Product ID, edition ID and product URI
      • Offer details -- price
      • Order requested date/time
      • Store client type -- web or native client
      • Purchase quantity and price
      • Payment type -- credit card type and PayPal
      | +|Entitlements | Information about entitlements on the device such as:
      • Service subscription status and errors
      • DRM and license rights details -- Groove subscription or OS volume license
      • Entitlement ID, lease ID, and package ID of the install package
      • Entitlement revocation
      • License type (trial, offline vs online) and duration
      • License usage session
      | ## Software Setup and Inventory data @@ -78,25 +85,13 @@ This type of data includes software installation and update information on the d | Installed Applications and Install History | Information about apps, drivers, update packages, or OS components installed on the device such as:
      • App, driver, update package, or component’s Name, ID, or Package Family Name
      • Product, SKU, availability, catalog, content, and Bundle IDs
      • OS component, app or driver publisher, language, version and type (Win32 or UWP)
      • Install date, method, and install directory, count of install attempts
      • MSI package code and product code
      • Original OS version at install time
      • User or administrator or mandatory installation/update
      • Installation type – clean install, repair, restore, OEM, retail, upgrade, and update
      | | Device update information | Information about Windows Update such as:
      • Update Readiness analysis of device hardware, OS components, apps, and drivers (progress, status, and results)
      • Number of applicable updates, importance, type
      • Update download size and source -- CDN or LAN peers
      • Delay upgrade status and configuration
      • OS uninstall and rollback status and count
      • Windows Update server and service URL
      • Windows Update machine ID
      • Windows Insider build details
      -## Content Consumption data +## Browsing History data -This type of data includes diagnostic details about Microsoft applications that provide media consumption functionality (such as Groove Music), and is not intended to capture user viewing, listening or reading habits. - -| Category Name | Examples | -| - | - | -| Movies | Information about movie consumption functionality on the device such as:
      • Video Width, height, color pallet, encoding (compression) type, and encryption type
      • Instructions for how to stream content for the user -- the smooth streaming manifest of chunks of content files that must be pieced together to stream the content based on screen resolution and bandwidth
      • URL for a specific two second chunk of content if there is an error
      • Full screen viewing mode details
      | -| Music & TV | Information about music and TV consumption on the device such as:
      • Service URL for song being downloaded from the music service – collected when an error occurs to facilitate restoration of service
      • Content type (video, audio, surround audio)
      • Local media library collection statistics -- number of purchased tracks, number of playlists
      • Region mismatch -- User OS Region, and Xbox Live region
      | -| Reading | Information about reading consumption functionality on the device such as:
      • App accessing content and status and options used to open a Microsoft Store book
      • Language of the book
      • Time spent reading content
      • Content type and size details
      | -| Photos App | Information about photos usage on the device such as:
      • File source data -- local, SD card, network device, and OneDrive
      • Image & video resolution, video length, file sizes types and encoding
      • Collection view or full screen viewer use and duration of view
      - -## Browsing, Search and Query data - -This type of data includes details about web browsing, search and query activity in the Microsoft browsers and Cortana, and local file searches on the device. +This type of data includes details about web browsing in the Microsoft browsers. | Category Name | Description and Examples | | - | - | | Microsoft browser data | Information about Address bar and search box performance on the device such as:
      • Text typed in address bar and search box
      • Text selected for Ask Cortana search
      • Service response time
      • Auto-completed text if there was an auto-complete
      • Navigation suggestions provided based on local history and favorites
      • Browser ID
      • URLs (which may include search terms)
      • Page title
      | -| On-device file query | Information about local search activity on the device such as:
      • Kind of query issued and index type (ConstraintIndex, SystemIndex)
      • Number of items requested and retrieved
      • File extension of search result user interacted with
      • Launched item kind, file extension, index of origin, and the App ID of the opening app.
      • Name of process calling the indexer and time to service the query.
      • A hash of the search scope (file, Outlook, OneNote, IE history)
      • The state of the indices (fully optimized, partially optimized, being built)
      | ## Inking Typing and Speech Utterance data @@ -105,13 +100,4 @@ This type of data gathers details about the voice, inking, and typing input feat | Category Name | Description and Examples | | - | - | -| Voice, inking, and typing | Information about voice, inking and typing features such as:
      • Type of pen used (highlighter, ball point, pencil), pen color, stroke height and width, and how long it is used
      • Pen gestures (click, double click, pan, zoom, rotate)
      • Palm Touch x,y coordinates
      • Input latency, missed pen signals, number of frames, strokes, first frame commit time, sample rate
      • Ink strokes written, text before and after the ink insertion point, recognized text entered, Input language - processed to remove identifiers, sequencing information, and other data (such as names, email addresses, and numeric values) which could be used to reconstruct the original content or associate the input to the user.
      • Text of speech recognition results -- result codes and recognized text
      • Language and model of the recognizer, System Speech language
      • App ID using speech features
      • Whether user is known to be a child
      • Confidence and Success/Failure of speech recognition
      | - -## ​​​​​​​Licensing and Purchase data - -This type of data includes diagnostic details about the purchase and entitlement activity on the device. - -| Category Name | Data Examples | -| - | - | -| Purchase history | Information about purchases made on the device such as:
      • Product ID, edition ID and product URI
      • Offer details -- price
      • Order requested date/time
      • Store client type -- web or native client
      • Purchase quantity and price
      • Payment type -- credit card type and PayPal
      | -| Entitlements | Information about entitlements on the device such as:
      • Service subscription status and errors
      • DRM and license rights details -- Groove subscription or OS volume license
      • Entitlement ID, lease ID, and package ID of the install package
      • Entitlement revocation
      • License type (trial, offline vs online) and duration
      • License usage session
      | \ No newline at end of file +| Voice, inking, and typing | Information about voice, inking and typing features such as:
      • Type of pen used (highlighter, ball point, pencil), pen color, stroke height and width, and how long it is used
      • Pen gestures (click, double click, pan, zoom, rotate)
      • Palm Touch x,y coordinates
      • Input latency, missed pen signals, number of frames, strokes, first frame commit time, sample rate
      • Ink strokes written, text before and after the ink insertion point, recognized text entered, Input language - processed to remove identifiers, sequencing information, and other data (such as email addresses and numeric values) which could be used to reconstruct the original content or associate the input to the user.
      • Text input from Windows Mobile on-screen keyboards except from password fields and private sessions - processed to remove identifiers, sequencing information, and other data (such as email addresses, and numeric values) which could be used to reconstruct the original content or associate the input to the user.
      • Text of speech recognition results -- result codes and recognized text
      • Language and model of the recognizer, System Speech language
      • App ID using speech features
      • Whether user is known to be a child
      • Confidence and Success/Failure of speech recognition
      | \ No newline at end of file From ec31357472af9ebee6d163a162a7e44293e46ffc Mon Sep 17 00:00:00 2001 From: John Tobin Date: Thu, 14 Sep 2017 09:59:08 -0700 Subject: [PATCH 12/30] Add dbghost and dbgsvc to block list --- .../device-guard/deploy-code-integrity-policies-steps.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md b/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md index 9f7bef9162..be6f4de127 100644 --- a/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md +++ b/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md @@ -36,6 +36,8 @@ Unless your use scenarios explicitly require them, Microsoft recommends that you - bginfo.exe[1] - cdb.exe - csi.exe +- dbghost.exe +- dbgsvc.exe - dnx.exe - fsi.exe - fsiAnyCpu.exe @@ -110,7 +112,9 @@ Microsoft recommends that you block the following Microsoft-signed applications - + + + @@ -177,6 +181,8 @@ Microsoft recommends that you block the following Microsoft-signed applications + + From baa5a1b402815d3f2f035ffb29b6f1045e6cb351 Mon Sep 17 00:00:00 2001 From: Nicholas Brower Date: Thu, 14 Sep 2017 17:20:24 +0000 Subject: [PATCH 13/30] Merged PR 3193: Merge Olympia enrollment methods into a single topic --- windows/deployment/TOC.md | 2 - .../enrollment-keep-current-edition.md | 44 ---------- .../enrollment-upgrade-to-enterprise.md | 57 ------------ .../olympia/olympia-enrollment-guidelines.md | 87 ++++++++++++++++++- 4 files changed, 84 insertions(+), 106 deletions(-) delete mode 100644 windows/deployment/update/olympia/enrollment-keep-current-edition.md delete mode 100644 windows/deployment/update/olympia/enrollment-upgrade-to-enterprise.md diff --git a/windows/deployment/TOC.md b/windows/deployment/TOC.md index b070057f1d..3d057730dc 100644 --- a/windows/deployment/TOC.md +++ b/windows/deployment/TOC.md @@ -222,8 +222,6 @@ #### [Windows Insider Program for Business using Azure Active Directory](update/waas-windows-insider-for-business-aad.md) #### [Windows Insider Program for Business Frequently Asked Questions](update/waas-windows-insider-for-business-faq.md) #### [Olympia Corp enrollment](update/olympia/olympia-enrollment-guidelines.md) -##### [Keep your current Windows 10 edition](update/olympia/enrollment-keep-current-edition.md) -##### [Upgrade your Windows 10 edition from Pro to Enterprise](update/olympia/enrollment-upgrade-to-enterprise.md) ### [Change history for Update Windows 10](update/change-history-for-update-windows-10.md) ## Windows Analytics diff --git a/windows/deployment/update/olympia/enrollment-keep-current-edition.md b/windows/deployment/update/olympia/enrollment-keep-current-edition.md deleted file mode 100644 index b0016c44ee..0000000000 --- a/windows/deployment/update/olympia/enrollment-keep-current-edition.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: Keep your current Windows 10 edition -description: Olympia Corp enrollment - Keep your current Windows 10 edition -ms.author: nibr -ms.topic: article -ms.prod: w10 -ms.technology: windows -author: nickbrower -ms.date: 09/01/2017 ---- - -# Olympia Corp enrollment - -## Keep your current Windows 10 edition - -1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)). - - ![Settings -> Accounts](images/1-1.png) - -2. If you are already connected to a domain, click the existing account and then click **Disconnect**. Click **Restart Later**. - -3. Click **Connect** and enter your **Olympia corporate account** (e.g., username@olympia.windows.com). Click **Next**. - - ![Set up a work or school account](images/1-3.png) - -4. Enter the temporary password that was sent to you. Click **Sign in**. Follow the instructions to set a new password. - - > [!NOTE] - > Passwords should contain 8-16 characters, including at least one special character or number. - - ![Update your password](images/1-4.png) - -5. Read the **Terms and Conditions**. Click **Accept** to participate in the program. - -6. If this is the first time you are logging in, please fill in the additional information to help you retrieve your account details. - -7. Create a PIN for signing into your Olympia corporate account. - -8. Go to **Start > Settings > Update & Security > Windows Insider Program**. Click on the current Windows Insider account, and click **Change**. Sign in with your **Olympia corporate account**. - - > [!NOTE] - > To complete this step, you will need to register your account with the [Windows Insider Program for Business](https://insider.windows.com/ForBusiness). - -9. Open the **Feedback Hub**, and sign in with your **Olympia corporate account**. diff --git a/windows/deployment/update/olympia/enrollment-upgrade-to-enterprise.md b/windows/deployment/update/olympia/enrollment-upgrade-to-enterprise.md deleted file mode 100644 index 6643971428..0000000000 --- a/windows/deployment/update/olympia/enrollment-upgrade-to-enterprise.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -title: Upgrade your Windows 10 edition from Pro to Enterprise -description: Olympia Corp enrollment - Upgrade your Windows 10 edition from Pro to Enterprise -ms.author: nibr -ms.topic: article -ms.prod: w10 -ms.technology: windows -author: nickbrower -ms.date: 09/01/2017 ---- - -# Olympia Corp enrollment - -## Upgrade your Windows 10 edition from Pro to Enterprise - -1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)). - - ![Settings -> Accounts](images/1-1.png) - -2. If you are already connected to a domain, click the existing account and then click **Disconnect**. Click **Restart Later**. - -3. Click **Connect**, then click **Join this device to Azure Active Directory**. - - ![Update your password](images/2-3.png) - -4. Enter your **Olympia corporate account** (e.g., username@olympia.windows.com). Click **Next**. - - ![Set up a work or school account](images/2-4.png) - -5. Enter the temporary password that was sent to you. Click **Sign in**. Follow the instructions to set a new password. - - > [!NOTE] - > Passwords should contain 8-16 characters, including at least one special character or number. - - ![Update your password](images/2-5.png) - -6. When asked to make sure this is your organization, verify that the information is correct. If so, click **Join**. - -7. If this is the first time you are signing in, please fill in the additional information to help you retrieve your account details. - -8. Create a PIN for signing into your Olympia corporate account. - -9. When asked to make sure this is your organization, verify that the information is correct. If so, click **Join**. - -10. Restart your PC. - -11. In the sign-in screen, choose **Other User** and sign in with your **Olympia corporate account**. Your PC will upgrade to Windows 10 Enterprise*. - -12. Go to **Start > Settings > Update & Security > Windows Insider Program**. Click on the current Windows Insider account, and click **Change**. Sign in with your **Olympia corporate account**. - - > [!NOTE] - > To complete this step, you will need to register your account with the [Windows Insider Program for Business](https://insider.windows.com/ForBusiness). - -13. Open the **Feedback Hub**, and sign in with your **Olympia corporate account**. - -\* Please note that your Windows 10 Enterprise license will not be renewed if your PC is not connected to Olympia. - diff --git a/windows/deployment/update/olympia/olympia-enrollment-guidelines.md b/windows/deployment/update/olympia/olympia-enrollment-guidelines.md index 17b87bd7b0..fddd959017 100644 --- a/windows/deployment/update/olympia/olympia-enrollment-guidelines.md +++ b/windows/deployment/update/olympia/olympia-enrollment-guidelines.md @@ -6,7 +6,7 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: nickbrower -ms.date: 09/01/2017 +ms.date: 09/14/2017 --- # Olympia Corp enrollment guidelines @@ -17,6 +17,87 @@ As part of Windows Insider Lab for Enterprise, you can upgrade to Windows 10 Ent Choose one of the following two enrollment options: -1. [Keep your current Windows 10 edition](./enrollment-keep-current-edition.md) +1. [Keep your current Windows 10 edition](#enrollment-keep-current-edition) + +2. [Upgrade your Windows 10 edition from Pro to Enterprise](#enrollment-upgrade-to-enterprise) + + + +## Keep your current Windows 10 edition + +1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)). + + ![Settings -> Accounts](images/1-1.png) + +2. If you are already connected to a domain, click the existing account and then click **Disconnect**. Click **Restart Later**. + +3. Click **Connect** and enter your **Olympia corporate account** (e.g., username@olympia.windows.com). Click **Next**. + + ![Set up a work or school account](images/1-3.png) + +4. Enter the temporary password that was sent to you. Click **Sign in**. Follow the instructions to set a new password. + + > [!NOTE] + > Passwords should contain 8-16 characters, including at least one special character or number. + + ![Update your password](images/1-4.png) + +5. Read the **Terms and Conditions**. Click **Accept** to participate in the program. + +6. If this is the first time you are logging in, please fill in the additional information to help you retrieve your account details. + +7. Create a PIN for signing into your Olympia corporate account. + +8. Go to **Start > Settings > Update & Security > Windows Insider Program**. Click on the current Windows Insider account, and click **Change**. Sign in with your **Olympia corporate account**. + + > [!NOTE] + > To complete this step, you will need to register your account with the [Windows Insider Program for Business](https://insider.windows.com/ForBusiness). + +9. Open the **Feedback Hub**, and sign in with your **Olympia corporate account**. + + + +## Upgrade your Windows 10 edition from Pro to Enterprise + +1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)). + + ![Settings -> Accounts](images/1-1.png) + +2. If you are already connected to a domain, click the existing account and then click **Disconnect**. Click **Restart Later**. + +3. Click **Connect**, then click **Join this device to Azure Active Directory**. + + ![Update your password](images/2-3.png) + +4. Enter your **Olympia corporate account** (e.g., username@olympia.windows.com). Click **Next**. + + ![Set up a work or school account](images/2-4.png) + +5. Enter the temporary password that was sent to you. Click **Sign in**. Follow the instructions to set a new password. + + > [!NOTE] + > Passwords should contain 8-16 characters, including at least one special character or number. + + ![Update your password](images/2-5.png) + +6. When asked to make sure this is your organization, verify that the information is correct. If so, click **Join**. + +7. If this is the first time you are signing in, please fill in the additional information to help you retrieve your account details. + +8. Create a PIN for signing into your Olympia corporate account. + +9. When asked to make sure this is your organization, verify that the information is correct. If so, click **Join**. + +10. Restart your PC. + +11. In the sign-in screen, choose **Other User** and sign in with your **Olympia corporate account**. Your PC will upgrade to Windows 10 Enterprise*. + +12. Go to **Start > Settings > Update & Security > Windows Insider Program**. Click on the current Windows Insider account, and click **Change**. Sign in with your **Olympia corporate account**. + + > [!NOTE] + > To complete this step, you will need to register your account with the [Windows Insider Program for Business](https://insider.windows.com/ForBusiness). + +13. Open the **Feedback Hub**, and sign in with your **Olympia corporate account**. + +\* Please note that your Windows 10 Enterprise license will not be renewed if your PC is not connected to Olympia. -2. [Upgrade your Windows 10 edition from Pro to Enterprise](./enrollment-upgrade-to-enterprise.md) From abfb498772c4d82ca6dc6a159922c9776424cab0 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 14 Sep 2017 22:30:30 +0000 Subject: [PATCH 14/30] Merged PR 3205: Add link in parent to child Add link to parent topic pointing to important procedure in child topic --- .../deployment/windows-10-enterprise-subscription-activation.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/windows-10-enterprise-subscription-activation.md b/windows/deployment/windows-10-enterprise-subscription-activation.md index c767d18075..9f6b5c02a8 100644 --- a/windows/deployment/windows-10-enterprise-subscription-activation.md +++ b/windows/deployment/windows-10-enterprise-subscription-activation.md @@ -102,7 +102,7 @@ changepk.exe /ProductKey %ProductKey% ### Obtaining an Azure AD licence Enterprise Agreement/Software Assurance (EA/SA): -- Organizations with a traditional EA must order a $0 SKU, process e-mails sent to the license administrator for the company, and assign licenses using Azure AD (ideally to groups using the new Azure AD Premium feature for group assignment). +- Organizations with a traditional EA must order a $0 SKU, process e-mails sent to the license administrator for the company, and assign licenses using Azure AD (ideally to groups using the new Azure AD Premium feature for group assignment). For more information, see [Enabling Subscription Activation with an existing EA](https://docs.microsoft.com/en-us/windows/deployment/deploy-enterprise-licenses#enabling-subscription-activation-with-an-existing-ea). - The license administrator can assign seats to Azure AD users with the same process that is used for O365. - New EA/SA Windows Enterprise customers can acquire both an SA subscription and an associated $0 cloud subscription. From 6376a76a3d5f40e7a5393103e3298f24df9128c6 Mon Sep 17 00:00:00 2001 From: John Tobin Date: Thu, 14 Sep 2017 16:06:58 -0700 Subject: [PATCH 15/30] Correct Cred Guard CI File Rule for KD_KMCI --- .../device-guard/deploy-code-integrity-policies-steps.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md b/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md index be6f4de127..8b11311fb6 100644 --- a/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md +++ b/windows/device-security/device-guard/deploy-code-integrity-policies-steps.md @@ -108,6 +108,7 @@ Microsoft recommends that you block the following Microsoft-signed applications + @@ -167,7 +168,7 @@ Microsoft recommends that you block the following Microsoft-signed applications - + From fe11b1a3d50fad12bd97661a017d706fd1048956 Mon Sep 17 00:00:00 2001 From: Maricia Alforque Date: Fri, 15 Sep 2017 19:53:34 +0000 Subject: [PATCH 16/30] Merged PR 3224: Merge maricia-13755838 to master --- ...ew-in-windows-mdm-enrollment-management.md | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index 4542abf9dd..ecdd2bbd8a 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -929,6 +929,16 @@ For details about Microsoft mobile device management protocols for Windows 10 s +The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/en-us/library/mt221945.aspx) +

      The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

      +
        +
      • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
      • +
      • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
      • +
      • DomainName - fully qualified domain name if the device is domain-joined.
      • +
      +

      For examples, see section 4.3.1 RequestSecurityToken of the the MS-MDE2 protocol documentation.

      + + [Firewall CSP](firewall-csp.md)

      Added new CSP in Windows 10, version 1709.

      @@ -1361,6 +1371,16 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware
    • System/LimitEnhancedDiagnosticDataWindowsAnalytics
    + +The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/en-us/library/mt221945.aspx) +

    The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

    +
      +
    • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
    • +
    • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
    • +
    • DomainName - fully qualified domain name if the device is domain-joined.
    • +
    +

    For examples, see section 4.3.1 RequestSecurityToken of the the MS-MDE2 protocol documentation.

    + From 3d21ef1009a8fbdacb4ceb8f6cf526f426362e24 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Fri, 15 Sep 2017 13:09:36 -0700 Subject: [PATCH 17/30] add api parameters --- ...ows-defender-advanced-threat-protection.md | 267 +++--------------- 1 file changed, 33 insertions(+), 234 deletions(-) diff --git a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md index 2d146c99a0..4890e798ee 100644 --- a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md @@ -36,240 +36,39 @@ The ArcSight field column contains the default mapping between the Windows Defen Field numbers match the numbers in the images below. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Portal labelSIEM field nameArcSight fieldExample valueDescription
    1AlertTitlenameA dll was unexpectedly loaded into a high integrity process without a UAC promptValue available for every alert.
    2SeveritydeviceSeverityMediumValue available for every alert.
    3CategorydeviceEventCategoryPrivilege EscalationValue available for every alert.
    4SourcesourceServiceNameWindowsDefenderATPWindows Defender Antivirus or Windows Defender ATP. Value available for every alert.
    5MachineNamesourceHostNameliz-beanValue available for every alert.
    6FileNamefileNameRobocopy.exeAvailable for alerts associated with a file or process.
    7FilePathfilePathC:\Windows\System32\Robocopy.exeAvailable for alerts associated with a file or process. \
    8UserDomainsourceNtDomaincontosoThe domain of the user context running the activity, available for Windows Defender ATP behavioral based alerts.
    9UserNamesourceUserNameliz-beanThe user context running the activity, available for Windows Defender ATP behavioral based alerts.
    10Sha1fileHash5b4b3985339529be3151d331395f667e1d5b7f35Available for alerts associated with a file or process.
    11Md5deviceCustomString555394b85cb5edddff551f6f3faa9d8ebAvailable for Windows Defender AV alerts.
    12Sha256deviceCustomString69987474deb9f457ece2a9533a08ec173a0986fa3aa6ac355eeba5b622e4a43f5Available for Windows Defender AV alerts.
    13ThreatNameeviceCustomString1Trojan:Win32/Skeeyah.A!bitAvailable for Windows Defender AV alerts.
    14IpAddresssourceAddress218.90.204.141Available for alerts associated to network events. For example, 'Communication to a malicious network destination'.
    15UrlrequestUrldown.esales360.cnAvailabe for alerts associated to network events. For example, 'Communication to a malicious network destination'.
    16RemediationIsSuccessdeviceCustomNumber2TRUEAvailable for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE.
    17WasExecutingWhileDetecteddeviceCustomNumber1FALSEAvailable for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE.
    18AlertIdexternalId636210704265059241_673569822Value available for every alert.
    19LinkToWDATPflexString1`https://securitycenter.windows.com/alert/636210704265059241_673569822`Value available for every alert.
    20AlertTimedeviceReceiptTime2017-05-07T01:56:59.3191352ZThe time the activity relevant to the alert occurred. Value available for every alert.
    21MachineDomainsourceDnsDomaincontoso.comDomain name not relevant for AAD joined machines. Value available for every alert.
    22ActordeviceCustomString4Available for alerts related to a known actor group.
    21+5ComputerDnsNameNo mappingliz-bean.contoso.comThe machine fully qualified domain name. Value available for every alert.
    LogOnUserssourceUserIdcontoso\liz-bean; contoso\jay-hardeeThe domain and user of the interactive logon user/s at the time of the event. Note: For machines on Windows 10 version 1607, the domain information will not be available.
    Internal fieldLastProcessedTimeUtcNo mapping2017-05-07T01:56:58.9936648ZTime when event arrived at the backend. This field can be used when setting the request parameter for the range of time that alerts are retrieved.
    Not part of the schemadeviceVendorStatic value in the ArcSight mapping - 'Microsoft'.
    Not part of the schemadeviceProductStatic value in the ArcSight mapping - 'Windows Defender ATP'.
    Not part of the schemadeviceVersionStatic value in the ArcSight mapping - '2.0', used to identify the mapping versions.
    +> [!div class="mx-tdBreakAll"] +| Portal label | SIEM field name | ArcSight field | Example value | Description | +|------------------|---------------------------|---------------------|------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| +| 1 | AlertTitle | name | A dll was unexpectedly loaded into a high integrity process without a UAC prompt | Value available for every alert. | +| 2 | Severity | deviceSeverity | Medium | Value available for every alert. | +| 3 | Category | deviceEventCategory | Privilege Escalation | Value available for every alert. | +| 4 | Source | sourceServiceName | WindowsDefenderATP | Windows Defender Antivirus or Windows Defender ATP. Value available for every alert. | +| 5 | MachineName | sourceHostName | liz-bean | Value available for every alert. | +| 6 | FileName | fileName | Robocopy.exe | Available for alerts associated with a file or process. | +| 7 | FilePath | filePath | C:\Windows\System32\Robocopy.exe | Available for alerts associated with a file or process. \ | +| 8 | UserDomain | sourceNtDomain | contoso | The domain of the user context running the activity, available for Windows Defender ATP behavioral based alerts. | +| 9 | UserName | sourceUserName | liz-bean | The user context running the activity, available for Windows Defender ATP behavioral based alerts. | +| 10 | Sha1 | fileHash | 5b4b3985339529be3151d331395f667e1d5b7f35 | Available for alerts associated with a file or process. | +| 11 | Md5 | deviceCustomString5 | 55394b85cb5edddff551f6f3faa9d8eb | Available for Windows Defender AV alerts. | +| 12 | Sha256 | deviceCustomString6 | 9987474deb9f457ece2a9533a08ec173a0986fa3aa6ac355eeba5b622e4a43f5 | Available for Windows Defender AV alerts. | +| 13 | ThreatName | eviceCustomString1 | Trojan:Win32/Skeeyah.A!bit | Available for Windows Defender AV alerts. | +| 14 | IpAddress | sourceAddress | 218.90.204.141 | Available for alerts associated to network events. For example, 'Communication to a malicious network destination'. | +| 15 | Url | requestUrl | down.esales360.cn | Availabe for alerts associated to network events. For example, 'Communication to a malicious network destination'. | +| 16 | RemediationIsSuccess | deviceCustomNumber2 | TRUE | Available for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE. | +| 17 | WasExecutingWhileDetected | deviceCustomNumber1 | FALSE | Available for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE. | +| 18 | AlertId | externalId | 636210704265059241_673569822 | Value available for every alert. | +| 19 | LinkToWDATP | flexString1 | `https://securitycenter.windows.com/alert/636210704265059241_673569822` | Value available for every alert. | +| 20 | AlertTime | deviceReceiptTime | 2017-05-07T01:56:59.3191352Z | The time the activity relevant to the alert occurred. Value available for every alert. | +| 21 | MachineDomain | sourceDnsDomain | contoso.com | Domain name not relevant for AAD joined machines. Value available for every alert. | +| 22 | Actor | deviceCustomString4 | | Available for alerts related to a known actor group. | +| 21+5 | ComputerDnsName | No mapping | liz-bean.contoso.com | The machine fully qualified domain name. Value available for every alert. | +| | LogOnUsers | sourceUserId | contoso\liz-bean; contoso\jay-hardee | The domain and user of the interactive logon user/s at the time of the event. Note: For machines on Windows 10 version 1607, the domain information will not be available. | +| | InternalIPv4List | No mapping | 192.168.1.7, 10.1.14.1 | | +| | InternalIPv4List | No mapping | fd30:0000:0000:0001:ff4e:003e:0009:000e, FE80:CD00:0000:0CDE:1257:0000:211E:729C | | +| Internal field | LastProcessedTimeUtc | No mapping | 2017-05-07T01:56:58.9936648Z | Time when event arrived at the backend. This field can be used when setting the request parameter for the range of time that alerts are retrieved. | +| | Not part of the schema | deviceVendor | | Static value in the ArcSight mapping - 'Microsoft'. | +| | Not part of the schema | deviceProduct | | Static value in the ArcSight mapping - 'Windows Defender ATP'. | +| | Not part of the schema | deviceVersion | | Static value in the ArcSight mapping - '2.0', used to identify the mapping versions. |1234567891011121314151617181920212223242526272829303132 ![Image of alert with numbers](images/atp-alert-page.png) From e54ffd815cbc6a1654d26eb7bce05c5447524d1d Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Fri, 15 Sep 2017 13:30:48 -0700 Subject: [PATCH 18/30] table fix --- ...ortal-mapping-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md index 4890e798ee..a65efde847 100644 --- a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md @@ -36,7 +36,7 @@ The ArcSight field column contains the default mapping between the Windows Defen Field numbers match the numbers in the images below. -> [!div class="mx-tdBreakAll"] +> [!div class="mx-tableFixed"] | Portal label | SIEM field name | ArcSight field | Example value | Description | |------------------|---------------------------|---------------------|------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | 1 | AlertTitle | name | A dll was unexpectedly loaded into a high integrity process without a UAC prompt | Value available for every alert. | From 21e94fe377909313bf6c80a0c4f54ee36deef596 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Fri, 15 Sep 2017 13:31:36 -0700 Subject: [PATCH 19/30] typo --- ...ortal-mapping-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md index a65efde847..1732c065bd 100644 --- a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md @@ -45,7 +45,7 @@ Field numbers match the numbers in the images below. | 4 | Source | sourceServiceName | WindowsDefenderATP | Windows Defender Antivirus or Windows Defender ATP. Value available for every alert. | | 5 | MachineName | sourceHostName | liz-bean | Value available for every alert. | | 6 | FileName | fileName | Robocopy.exe | Available for alerts associated with a file or process. | -| 7 | FilePath | filePath | C:\Windows\System32\Robocopy.exe | Available for alerts associated with a file or process. \ | +| 7 | FilePath | filePath | C:\Windows\System32\Robocopy.exe | Available for alerts associated with a file or process. | | 8 | UserDomain | sourceNtDomain | contoso | The domain of the user context running the activity, available for Windows Defender ATP behavioral based alerts. | | 9 | UserName | sourceUserName | liz-bean | The user context running the activity, available for Windows Defender ATP behavioral based alerts. | | 10 | Sha1 | fileHash | 5b4b3985339529be3151d331395f667e1d5b7f35 | Available for alerts associated with a file or process. | From 670c70f9959c482300da7390c3d260f9bd1b9a04 Mon Sep 17 00:00:00 2001 From: Liza Poggemeyer Date: Fri, 15 Sep 2017 22:31:20 +0000 Subject: [PATCH 20/30] Merged PR 3231: Add new article described default apps in W10 Enterprise SKU --- windows/application-management/TOC.md | 1 + .../apps-in-windows-10.md | 153 ++++++++++++++++++ ...ange-history-for-application-management.md | 4 +- windows/application-management/index.md | 3 + 4 files changed, 160 insertions(+), 1 deletion(-) create mode 100644 windows/application-management/apps-in-windows-10.md diff --git a/windows/application-management/TOC.md b/windows/application-management/TOC.md index 6b96cc2abc..3f1e9a5aaa 100644 --- a/windows/application-management/TOC.md +++ b/windows/application-management/TOC.md @@ -101,5 +101,6 @@ #### [Running a Locally Installed Application Inside a Virtual Environment with Virtualized Applications](app-v/appv-running-locally-installed-applications-inside-a-virtual-environment.md) ## [Service Host process refactoring](svchost-service-refactoring.md) ## [Per-user services in Windows](per-user-services-in-windows.md) +## [Understand apps in Windows 10](apps-in-windows-10.md) ## [Deploy app upgrades on Windows 10 Mobile](deploy-app-upgrades-windows-10-mobile.md) ## [Change history for Application management](change-history-for-application-management.md) diff --git a/windows/application-management/apps-in-windows-10.md b/windows/application-management/apps-in-windows-10.md new file mode 100644 index 0000000000..215e71f9f0 --- /dev/null +++ b/windows/application-management/apps-in-windows-10.md @@ -0,0 +1,153 @@ +--- +title: Windows 10 - Apps +description: What are Windows, UWP, and Win32 apps +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: mobile +ms.author: elizapo +author: lizap +ms.localizationpriority: low +ms.date: 09/15/2017 +--- +# Understand the different apps included in Windows 10 + +The following types of apps run on Windows 10: +- Windows apps - introduced in Windows 8, primarily installed from the Store app. +- Universal Windows Platform (UWP) apps - designed to work across platforms, can be installed on multiple platforms including Windows client, Windows Phone, and Xbox. All UWP apps are also Windows apps, but not all Windows apps are UWP apps. +- "Win32" apps - traditional Windows applications, built for 32-bit systems. + +Digging into the Windows apps, there are two categories: +- System apps - Apps that are installed in the c:\Windows\* directory. These apps are integral to the OS. +- Apps - All other apps, installed in c:\Program Files\WindowsApps. There are two classes of apps: + - Provisioned: Installed the first time you sign into Windows. You'll see a tile or Start menu item for these apps, but they aren't installed until the first sign-in. + - Installed: Installed as part of the OS. + +The following tables list the system apps, installed Windows apps, and provisioned Windows apps in a standard Windows 10 Enterprise installation. (If you have a custom image, your specific apps might differ.) The tables list the app, the full name, show the app's status in Windows 10 version 1511, 1607, and 1703, and indicate whether an app can be uninstalled through the UI. + +Some of the apps show up in multiple tables - that's because their status changed between versions. Make sure to check the version column for the version you are currently running. + +> [!TIP] +> Want to see a list of the apps installed on your specific image? You can run the following PowerShell cmdlet: +> ```powershell +> Get-AppxPackage |Select Name,PackageFamilyName +> Get-AppsProvisionedPackage -Online | select DisplayName,PackageName +> ``` + + +## System apps +System apps are integral to the operating system. Here are the typical system apps in Windows 10 versions 1511, 1607, and 1703. + +| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? | +|------------------|-------------------------------------------|------|------|------|--------------------------------------------------------| +| Cortana UI | CortanaListenUIApp | | | x | No | +| | Desktop Learning | | | x | No | +| | DesktopView | | | x | No | +| | EnvironmentsApp | | | x | No | +| Mixed Reality + | HoloCamera | | | x | No | +| Mixed Reality + | HoloItemPlayerApp | | | x | No | +| Mixed Reality + | HoloShell | | | x | No | +| | Microsoft.AAD.Broker.Plugin | x | x | x | No | +| | Microsoft.AccountsControl | x | x | x | No | +| Hello setup UI | Microsoft.BioEnrollment | x | x | x | No | +| | Microsoft.CredDialogHost | | | x | No | +| | Microsoft.LockApp | x | x | x | No | +| Microsoft Edge | Microsoft.Microsoft.Edge | x | x | x | No | +| | Microsoft.PPIProjection | | x | x | No | +| | Microsoft.Windows. Apprep.ChxApp | | x | x | No | +| | Microsoft.Windows. AssignedAccessLockApp | x | x | x | No | +| | Microsoft.Windows. CloudExperienceHost | x | x | x | No | +| | Microsoft.Windows. ContentDeliveryManager | x | x | x | No | +| Cortana | Microsoft.Windows.Cortana | x | x | x | No | +| | Microsoft.Windows. Holographic.FirstRun | | | x | No | +| | Microsoft.Windows. ModalSharePickerHost | | | x | No | +| | Microsoft.Windows. OOBENetworkCaptivePort | | | x | No | +| | Microsoft.Windows. OOBENetworkConnection | | | x | No | +| | Microsoft.Windows. ParentalControls | x | x | x | No | +| | Microsoft.Windows. SecHealthUI | | | x | No | +| | Microsoft.Windows. SecondaryTileExperience | x | x | x | No | +| | Microsoft.Windows. SecureAssessmentBrowser | | x | x | No | +| Start | Microsoft.Windows. ShellExperienceHost | x | x | x | No | +| Windows Feedback | Microsoft.WindowsFeedback | x | * | * | No | +| | Microsoft.XboxGameCallableUI | x | x | x | No | +| Xbox logon UI | Microsoft.XboxIdentityProvider | x | | | No | +| Contact Support | Windows.ContactSupport | x | x* | x* | In 1511, no.* | +| | Windows.Devicesflow | x | | | No | +| Settings | Windows.ImmersiveControlPanel | x | x | x | No | +| Connect | Windows.MiracastView | x | x | x | No | +| Print UI | Windows.PrintDialog | x | x | x | No | +| Purchase UI | Windows.PurchaseDialog | x | | | No | + +> [!NOTE] +> - The Windows Feedback app changed to the Windows Feedback Hub in version 1607. It's listed in the installed apps table below. +> - As of Windows 10 version 1607, you can use the Optional Features app to uninstall the Contact Support app. + +## Installed Windows apps +Here are the typical installed Windows apps in Windows 10 versions 1511, 1607, and 1703. + +| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? | +|--------------------|-----------------------------------------|------|------|------|---------------------------| +| Remote Desktop | Microsoft.RemoteDesktop | | x | x | Yes | +| PowerBI | Microsoft.Microsoft PowerBIforWindows | | x | x | Yes | +| Candy Crush | king.com.CandyCrushSodaSaga | x | | | Yes | +| Code Writer | ActiproSoftwareLLC.562882FEEB491 | | x | x | Yes | +| Eclipse Manager | 46928bounde.EclipseManager | | x | x | Yes | +| Pandora | PandoraMediaInc.29680B314EFC2 | | x | x | Yes | +| Photoshop Express | AdobeSystemIncorporated. AdobePhotoshop | | x | x | Yes | +| Duolingo | D5EA27B7.Duolingo- LearnLanguagesforFree | | | x | Yes | +| Network Speed Test | Microsoft.NetworkSpeedTest | | x | x | Yes | +| Paid Wi-FI | | x | | | Yes | +| Skype Video | | x | | | Yes | +| Twitter | | x | | | Yes | +| PicArts | | x | | | Yes | +| Minecraft | | x | | | Yes | +| Flipboard | | x | | | Yes | + +## Provisioned Windows apps +Here are the typical provisioned Windows apps in Windows 10 versions 1511, 1607, and 1703. + +| Name | Full name | 1511 | 1607 | 1703 | Uninstall through UI? | +|---------------------------------|----------------------------------------|------|------|------|---------------------------| +| 3D Builder | Microsoft.3DBuilder | x | | x | Yes | +| App Connector | Microsoft.Appconnector | x | | | Yes, through Settings app | +| Money | Microsoft.BingFinance | x | | | Yes | +| News | Microsoft.BingNews | x | * | * | Yes | +| Sports | Microsoft.BingSports | x | | | Yes | +| Weather | Microsoft.BingWeather | x | x | x | No | +| Phone Companion | Microsoft.CommsPhone | x | | | Yes | +| | Microsoft.ConnectivityStore | x | | | No | +| | Microsoft.DesktopAppInstaller | | x | x | Yes, through Settings app | +| Get Started/Tips | Microsoft.Getstarted | x | x | x | Yes | +| Messaging | Microsoft.Messaging | x | x | x | No | +| Microsoft 3D Viewer | Microsoft.Microsoft3DViewer | | | x | No | +| Get Office | Microsoft.MicrosoftOfficeHub | x | x | x | Yes | +| Solitaire | Microsoft.Microsoft SolitaireCollection | x | x | x | Yes | +| Sticky Notes | Microsoft.MicrosoftStickyNotes | | x | x | No | +| OneNote | Microsoft.Office.OneNote | x | x | x | No | +| Sway | Microsoft.Office.Sway | x | * | * | Yes | +| | Microsoft.OneConnect | | x | x | No | +| Paint 3D | Microsoft.MSPaint | | | x | No | +| People | Microsoft.People | x | x | x | No | +| Get Skype/Skype (preview)/Skype | Microsoft.SkypeApp | x | x | x | Yes | +| | Microsoft.StorePurchaseApp | | x | x | No | +| | Microsoft.Wallet | | | x | No | +| Photos | Microsoft.Windows.Photos | x | x | x | No | +| Alarms & Clock | Microsoft.WindowsAlarms | x | x | x | No | +| Calculator | Microsoft.WindowsCalculator | x | x | x | No | +| Camera | Microsoft.WindowsCamera | x | x | x | No | +| Mail and Calendar | Microsoft.windows communicationsapps | x | x | x | No | +| Feedback Hub | Microsoft.WindowsFeedbackHub | * | x | x | Yes | +| Maps | Microsoft.WindowsMaps | x | x | x | No | +| Phone | Microsoft.WindowsPhone | x | | | No | +| Voice Recorder | Microsoft.SoundRecorder | x | x | x | No | +| Store | Microsoft.WindowsStore | x | x | x | No | +| Xbox | Microsoft.XboxApp | x | x | x | No | +| | Microsoft.XboxGameOverlay | | | x | No | +| | Microsoft.XboxIdentityProvider | * | x | x | No | +| Groove | Microsoft.ZuneMusic | x | x | x | No | +| Movies & TV | Microsoft.ZuneVideo | x | x | x | No | +| | Microsoft.XboxSpeech ToTextOverlay | | | x | No | + +> [!NOTE] +> - As of Windows 10, version 1607, News and Sway are installed apps. +> - Both Feedback Hub and Microsoft.XboxIdentityProvider were installed apps in version 1511 and provisioned apps in versions 1607 and later. \ No newline at end of file diff --git a/windows/application-management/change-history-for-application-management.md b/windows/application-management/change-history-for-application-management.md index 7641745172..5178cf9050 100644 --- a/windows/application-management/change-history-for-application-management.md +++ b/windows/application-management/change-history-for-application-management.md @@ -8,6 +8,7 @@ ms.sitesec: library ms.pagetype: security ms.localizationpriority: high author: jdeckerms +ms.date: 09/15/2017 --- # Change history for Configure Windows 10 @@ -17,7 +18,8 @@ This topic lists new and updated topics in the [Configure Windows 10](index.md) ## September 2017 | New or changed topic | Description | | --- | --- | -| [Per-user services in Windows](per-user-services-in-windows.md) | New | +| [Per-user services in Windows 10](per-user-services-in-windows.md) | New | +| [Understand the different apps included in Windows 10](apps-in-windows-10.md) | New | ## July 2017 | New or changed topic | Description | diff --git a/windows/application-management/index.md b/windows/application-management/index.md index d6c32fbe93..17767877fd 100644 --- a/windows/application-management/index.md +++ b/windows/application-management/index.md @@ -6,6 +6,7 @@ ms.mktglfcycl: manage ms.sitesec: library author: jdeckerms ms.localizationpriority: medium +ms.date: 09/15/2017 --- # Windows 10 application management @@ -20,5 +21,7 @@ Learn about managing applications in Windows 10 and Windows 10 Mobile clients. |---|---| |[App-V](app-v/appv-getting-started.md)| Microsoft Application Virtualization (App-V) for Windows 10 enables organizations to deliver Win32 applications to users as virtual applications| |[Sideload apps in Windows 10](sideload-apps-in-windows-10.md)| Requirements and instructions for side-loading LOB applications on Windows 10 and Windows 10 Mobile clients| +|[Per User services in Windows 10](sideload-apps-in-windows-10.md)| Overview of per user services and instructions for viewing and disabling them in Windows 10 and Windows 2016| +|[Understand apps in Windows 10](apps-in-windows-10.md)| Overview of the different apps included by default in Windows 10 Enterprise| | [Service Host process refactoring](svchost-service-refactoring.md) | Changes to Service Host grouping in Windows 10 | | [Deploy app updgrades on Windows 10 Mobile](deploy-app-upgrades-windows-10-mobile.md) | How to upgrade apps on Windows 10 Mobile | From 84c952fb070b4ac5251f9b38ee7c0741ab406ddc Mon Sep 17 00:00:00 2001 From: Celeste de Guzman Date: Fri, 15 Sep 2017 18:23:48 -0700 Subject: [PATCH 21/30] updated to address PM feedback --- education/windows/change-history-edu.md | 6 ++++++ education/windows/use-set-up-school-pcs-app.md | 7 +++++-- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/education/windows/change-history-edu.md b/education/windows/change-history-edu.md index 699111447d..f5cf7d1f00 100644 --- a/education/windows/change-history-edu.md +++ b/education/windows/change-history-edu.md @@ -15,6 +15,12 @@ ms.date: 08/01/2017 This topic lists new and updated topics in the [Windows 10 for Education](index.md) documentation. +## September 2017 + +| New or changed topic | Description | +| --- | ---- | +| [Use the Set up School PCs app ](use-set-up-school-pcs-app.md) | Updated the prerequisites to provide more clarification. | + ## August 2017 | New or changed topic | Description | diff --git a/education/windows/use-set-up-school-pcs-app.md b/education/windows/use-set-up-school-pcs-app.md index ca1953e1e0..860f0fa609 100644 --- a/education/windows/use-set-up-school-pcs-app.md +++ b/education/windows/use-set-up-school-pcs-app.md @@ -9,7 +9,7 @@ ms.pagetype: edu ms.localizationpriority: high author: CelesteDG ms.author: celested -ms.date: 08/01/2017 +ms.date: 09/18/2017 --- # Use the Set up School PCs app @@ -103,7 +103,10 @@ You can watch the descriptive audio version here: [Microsoft Education: Use the - [Download the latest Set up School PCs app from the Microsoft Store](https://www.microsoft.com/store/apps/9nblggh4ls40). - Install the app on your work PC and make sure you're connected to your school's network. -- You must be an administrator on Office 365 and Azure Active Directory, and have Microsoft Store for Education configured. It's best if you sign up for and configure Intune for Education before using the Set up School PCs app. +- You must have Office 365 and Azure Active Directory. +- You must have the Microsoft Store for Education configured. +- You must be a global admin, store admin, or purchaser in the Microsoft Store for Education. +- It's best if you sign up for and [configure Intune for Education](get-started/use-intune-for-education.md) before using the Set up School PCs app. - Have a USB drive, 1 GB or larger, to save the provisioning package. We recommend an 8 GB or larger USB drive if you're installing Office. ## Set up School PCs step-by-step From 67cd6ba7d6051ff5feb201b5b5ed7d37b860ef3d Mon Sep 17 00:00:00 2001 From: Celeste de Guzman Date: Fri, 15 Sep 2017 18:49:47 -0700 Subject: [PATCH 22/30] fixed link --- education/windows/use-set-up-school-pcs-app.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/education/windows/use-set-up-school-pcs-app.md b/education/windows/use-set-up-school-pcs-app.md index 860f0fa609..72ee15e1ab 100644 --- a/education/windows/use-set-up-school-pcs-app.md +++ b/education/windows/use-set-up-school-pcs-app.md @@ -106,7 +106,7 @@ You can watch the descriptive audio version here: [Microsoft Education: Use the - You must have Office 365 and Azure Active Directory. - You must have the Microsoft Store for Education configured. - You must be a global admin, store admin, or purchaser in the Microsoft Store for Education. -- It's best if you sign up for and [configure Intune for Education](get-started/use-intune-for-education.md) before using the Set up School PCs app. +- It's best if you sign up for and [configure Intune for Education](../get-started/use-intune-for-education.md) before using the Set up School PCs app. - Have a USB drive, 1 GB or larger, to save the provisioning package. We recommend an 8 GB or larger USB drive if you're installing Office. ## Set up School PCs step-by-step From 290f190a50bdb6b67928b3522f7f8fc6eb3de673 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 18 Sep 2017 18:04:31 +0000 Subject: [PATCH 23/30] Merged PR 3242: Fix Store terms and links --- ...ace-app-with-windows-store-for-business.md | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/devices/surface/deploy-surface-app-with-windows-store-for-business.md b/devices/surface/deploy-surface-app-with-windows-store-for-business.md index 1e6ca989c9..aceac9a792 100644 --- a/devices/surface/deploy-surface-app-with-windows-store-for-business.md +++ b/devices/surface/deploy-surface-app-with-windows-store-for-business.md @@ -1,6 +1,6 @@ --- title: Deploy Surface app with Microsoft Store for Business or Microsoft Store for Education (Surface) -description: Find out how to add and download Surface app with Windows Store for Business or Microsoft Store for Education, as well as install Surface app with PowerShell and MDT. +description: Find out how to add and download Surface app with Microsoft Store for Business or Microsoft Store for Education, as well as install Surface app with PowerShell and MDT. keywords: surface app, app, deployment, customize ms.prod: w10 ms.mktglfcycl: deploy @@ -31,11 +31,11 @@ The Surface app is a lightweight Windows Store app that provides control of many * Quick access to support documentation and information for your device -If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Windows Store or your Windows Store for Business. +If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Microsoft Store or your Microsoft Store for Business. ##Surface app overview -The Surface app is available as a free download from the [Windows Store](https://www.microsoft.com/store/apps/Surface/9WZDNCRFJB8P). Users can download and install it from the Windows Store, but if your organization uses Microsoft Store for Business instead, you will need to add it to your store’s inventory and possibly include the app as part of your Windows deployment process. These processes are discussed throughout this article. For more information about Microsoft Store for Business, see [Microsoft Store for Business](https://technet.microsoft.com/windows/store-for-business) in the Windows TechCenter. +The Surface app is available as a free download from the [Microsoft Store](https://www.microsoft.com/store/apps/Surface/9WZDNCRFJB8P). Users can download and install it from the Microsoft Store, but if your organization uses Microsoft Store for Business instead, you will need to add it to your store’s inventory and possibly include the app as part of your Windows deployment process. These processes are discussed throughout this article. For more information about Microsoft Store for Business, see [Microsoft Store for Business](https://technet.microsoft.com/windows/store-for-business) in the Windows TechCenter. ##Add Surface app to a Microsoft Store for Business account @@ -45,7 +45,7 @@ Before users can install or deploy an app from a company’s Microsoft Store for 2. Log on to the portal. -3. Enable offline licensing: click **Manage->Store settings**, and then select the **Show offline licensed apps to people shopping in the store** checkbox, as shown in Figure 1. For more information about Microsoft Store for Business app licensing models, see [Apps in Windows Store for Business](https://technet.microsoft.com/itpro/windows/manage/apps-in-windows-store-for-business#licensing_model).

    +3. Enable offline licensing: click **Manage->Store settings**, and then select the **Show offline licensed apps to people shopping in the store** checkbox, as shown in Figure 1. For more information about Microsoft Store for Business app licensing models, see [Apps in Microsoft Store for Business](https://technet.microsoft.com/itpro/windows/manage/apps-in-windows-store-for-business#licensing_model).

    ![Show offline licenses apps checkbox](images/deploysurfapp-figure1-enablingapps.png "Show offline licenses apps checkbox")
    *Figure 1. Enable apps for offline use* @@ -70,7 +70,7 @@ Before users can install or deploy an app from a company’s Microsoft Store for ##Download Surface app from a Microsoft Store for Business account After you add an app to the Windows Store for Business account in Offline mode, you can download and add the app as an AppxBundle to a deployment share. 1. Log on to the Microsoft Store for Business account at https://businessstore.microsoft.com. -2. Click **Manage->Apps & software**. A list of all of your company’s apps is displayed, including the Surface app you added in the [Add Surface app to a Windows Store for Business account](#add-surface-app-to-a-windows-store-for-business-account) section of this article. +2. Click **Manage->Apps & software**. A list of all of your company’s apps is displayed, including the Surface app you added in the [Add Surface app to a Microsoft Store for Business account](#add-surface-app-to-a-microsoft-store-for-business-account) section of this article. 3. Under **Actions**, click the ellipsis (**…**), and then click **Download for offline use** for the Surface app. 4. Select the desired **Platform** and **Architecture** options from the available selections for the selected app, as shown in Figure 4. @@ -78,7 +78,7 @@ After you add an app to the Windows Store for Business account in Offline mode, *Figure 4. Download the AppxBundle package for an app* 5. Click **Download**. The AppxBundle package will be downloaded. Make sure you note the path of the downloaded file because you’ll need that later in this article. -6. Click either the **Encoded license** or **Unencoded license** option. Use the Encoded license option with management tools like System Center Configuration Manager or when you use Windows Imaging and Configuration Designer (Windows ICD). Select the Unencoded license option when you use Deployment Image Servicing and Management (DISM) or deployment solutions based on imaging, including the Microsoft Deployment Toolkit (MDT). +6. Click either the **Encoded license** or **Unencoded license** option. Use the Encoded license option with management tools like System Center Configuration Manager or when you use Windows Configuration Designer to create a provisioning package. Select the Unencoded license option when you use Deployment Image Servicing and Management (DISM) or deployment solutions based on imaging, including the Microsoft Deployment Toolkit (MDT). 7. Click **Generate** to generate and download the license for the app. Make sure you note the path of the license file because you’ll need that later in this article. >[!NOTE] @@ -104,7 +104,10 @@ To download the required frameworks for the Surface app, follow these steps: The following procedure provisions the Surface app onto your computer and makes it available for any user accounts created on the computer afterwards. 1. Using the procedure described in the [How to download Surface app from a Windows Store for Business account](#download-surface-app-from-a-windows-store-for-business-account) section of this article, download the Surface app AppxBundle and license file. 2. Begin an elevated PowerShell session. ->**Note:**  If you don’t run PowerShell as an Administrator, the session won’t have the required permissions to install the app. + + >[!NOTE] + >If you don’t run PowerShell as an Administrator, the session won’t have the required permissions to install the app. + 3. In the elevated PowerShell session, copy and paste the following command: ``` Add-AppxProvisionedPackage –Online –PackagePath \ Microsoft.SurfaceHub_10.0.342.0_neutral_~_8wekyb3d8bbwe.AppxBundle –LicensePath \ Microsoft.SurfaceHub_8wekyb3d8bbwe_a53ef8ab-9dbd-dec1-46c5-7b664d4dd003.xml @@ -130,7 +133,7 @@ Before the Surface app is functional on the computer where it has been provision ##Install Surface app with MDT The following procedure uses MDT to automate installation of the Surface app at the time of deployment. The application is provisioned automatically by MDT during deployment and thus you can use this process with existing images. This is the recommended process to deploy the Surface app as part of a Windows deployment to Surface devices because it does not reduce the cross platform compatibility of the Windows image. -1. Using the procedure described [earlier in this article](#download-surface-app-from-a-windows-store-for-business-account), download the Surface app AppxBundle and license file. +1. Using the procedure described [earlier in this article](#download-surface-app-from-a-microsoft-store-for-business-account), download the Surface app AppxBundle and license file. 2. Using the New Application Wizard in the MDT Deployment Workbench, import the downloaded files as a new **Application with source files**. 3. On the **Command Details** page of the New Application Wizard, specify the default **Working Directory** and for the **Command** specify the file name of the AppxBundle, as follows: From d5d7bad675db3d28adf1e5a171890b6688ebd0c5 Mon Sep 17 00:00:00 2001 From: Maricia Alforque Date: Mon, 18 Sep 2017 18:42:47 +0000 Subject: [PATCH 24/30] Merged PR 3247: Renamed Windows Store for Business --- windows/client-management/mdm/TOC.md | 6 +++--- windows/client-management/mdm/applocker-csp.md | 4 ++-- windows/client-management/mdm/assign-seats.md | 4 ++-- .../mdm/bulk-assign-and-reclaim-seats-from-user.md | 4 ++-- .../mdm/data-structures-windows-store-for-business.md | 6 +++--- .../client-management/mdm/enterprise-app-management.md | 2 +- .../mdm/enterprisemodernappmanagement-csp.md | 2 +- windows/client-management/mdm/get-inventory.md | 4 ++-- .../mdm/get-localized-product-details.md | 4 ++-- windows/client-management/mdm/get-offline-license.md | 4 ++-- windows/client-management/mdm/get-product-details.md | 4 ++-- windows/client-management/mdm/get-product-package.md | 4 ++-- windows/client-management/mdm/get-product-packages.md | 4 ++-- windows/client-management/mdm/get-seat.md | 4 ++-- .../mdm/get-seats-assigned-to-a-user.md | 4 ++-- windows/client-management/mdm/get-seats.md | 4 ++-- .../management-tool-for-windows-store-for-business.md | 10 +++++----- .../mdm/new-in-windows-mdm-enrollment-management.md | 10 +++++++++- .../client-management/mdm/reclaim-seat-from-user.md | 4 ++-- .../rest-api-reference-windows-store-for-business.md | 6 +++--- 20 files changed, 51 insertions(+), 43 deletions(-) diff --git a/windows/client-management/mdm/TOC.md b/windows/client-management/mdm/TOC.md index 2d6046fef1..8b53725783 100644 --- a/windows/client-management/mdm/TOC.md +++ b/windows/client-management/mdm/TOC.md @@ -17,9 +17,9 @@ ## [Enterprise app management](enterprise-app-management.md) ## [Device update management](device-update-management.md) ## [Bulk enrollment](bulk-enrollment-using-windows-provisioning-tool.md) -## [Management tool for the Windows Store for Business](management-tool-for-windows-store-for-business.md) -### [REST API reference for Windows Store for Business](rest-api-reference-windows-store-for-business.md) -#### [Data structures for Windows Store for Business](data-structures-windows-store-for-business.md) +## [Management tool for the Micosoft Store for Business](management-tool-for-windows-store-for-business.md) +### [REST API reference for Micosoft Store for Business](rest-api-reference-windows-store-for-business.md) +#### [Data structures for Micosoft Store for Business](data-structures-windows-store-for-business.md) #### [Get Inventory](get-inventory.md) #### [Get product details](get-product-details.md) #### [Get localized product details](get-localized-product-details.md) diff --git a/windows/client-management/mdm/applocker-csp.md b/windows/client-management/mdm/applocker-csp.md index 7564c89e41..2737a54616 100644 --- a/windows/client-management/mdm/applocker-csp.md +++ b/windows/client-management/mdm/applocker-csp.md @@ -266,9 +266,9 @@ FilePublisherCondition PublisherName="CN=Microsoft Corporation, O=Microsoft Corp You can get the publisher name and product name of apps using a web API. -**To find publisher and product name for Microsoft apps in Windows Store for Business** +**To find publisher and product name for Microsoft apps in Microsoft Store for Business** -1. Go to the Windows Store for Business website, and find your app. For example, Microsoft OneNote. +1. Go to the Microsoft Store for Business website, and find your app. For example, Microsoft OneNote. 2. Copy the ID value from the app URL. For example, Microsoft OneNote's ID URL is https:<\span>//www.microsoft.com/store/apps/onenote/9wzdncrfhvjl, and you'd copy the ID value, **9wzdncrfhvjl**. 3. In your browser, run the Store for Business portal web API, to return a JavaScript Object Notation (JSON) file that includes the publisher and product name values. diff --git a/windows/client-management/mdm/assign-seats.md b/windows/client-management/mdm/assign-seats.md index 510be6e748..f8ba2b865f 100644 --- a/windows/client-management/mdm/assign-seats.md +++ b/windows/client-management/mdm/assign-seats.md @@ -1,6 +1,6 @@ --- title: Assign seat -description: The Assign seat operation assigns seat for a specified user in the Windows Store for Business. +description: The Assign seat operation assigns seat for a specified user in the Microsoft Store for Business. ms.assetid: B42BF490-35C9-405C-B5D6-0D9F0E377552 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Assign seat -The **Assign seat** operation assigns seat for a specified user in the Windows Store for Business. +The **Assign seat** operation assigns seat for a specified user in the Microsoft Store for Business. ## Request diff --git a/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md b/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md index 33f5904925..7b7845d806 100644 --- a/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md +++ b/windows/client-management/mdm/bulk-assign-and-reclaim-seats-from-user.md @@ -1,6 +1,6 @@ --- title: Bulk assign and reclaim seats from users -description: The Bulk assign and reclaim seats from users operation returns reclaimed or assigned seats in the Windows Store for Business. +description: The Bulk assign and reclaim seats from users operation returns reclaimed or assigned seats in the Microsoft Store for Business. ms.assetid: 99E2F37D-1FF3-4511-8969-19571656780A ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Bulk assign and reclaim seats from users -The **Bulk assign and reclaim seats from users** operation returns reclaimed or assigned seats in the Windows Store for Business. +The **Bulk assign and reclaim seats from users** operation returns reclaimed or assigned seats in the Microsoft Store for Business. ## Request diff --git a/windows/client-management/mdm/data-structures-windows-store-for-business.md b/windows/client-management/mdm/data-structures-windows-store-for-business.md index 7a1bbaa552..d272b736e4 100644 --- a/windows/client-management/mdm/data-structures-windows-store-for-business.md +++ b/windows/client-management/mdm/data-structures-windows-store-for-business.md @@ -1,5 +1,5 @@ --- -title: Data structures for Windows Store for Business +title: Data structures for Microsoft Store for Business MS-HAID: - 'p\_phdevicemgmt.business\_store\_data\_structures' - 'p\_phDeviceMgmt.data\_structures\_windows\_store\_for\_business' @@ -13,10 +13,10 @@ author: nickbrower ms.date: 06/19/2017 --- -# Data structures for Windows Store for Business +# Data structures for Microsoft Store for Business -Here's the list of data structures used in the Windows Store for Business REST APIs: +Here's the list of data structures used in the Microsoft Store for Business REST APIs: - [AlternateIdentifier](#alternateidentifier) - [BulkSeatOperationResultSet](#bulkseatoperationresultset) diff --git a/windows/client-management/mdm/enterprise-app-management.md b/windows/client-management/mdm/enterprise-app-management.md index c203cabb0a..fd6c08650e 100644 --- a/windows/client-management/mdm/enterprise-app-management.md +++ b/windows/client-management/mdm/enterprise-app-management.md @@ -18,7 +18,7 @@ This topic covers one of the key mobile device management (MDM) features in Wind Windows 10 offers the ability for management servers to: -- Install apps directly from the Windows Store for Business +- Install apps directly from the Microsoft Store for Business - Deploy offline Store apps and licenses - Deploy line-of-business (LOB) apps (non-Store apps) - Inventory all apps for a user (Store and non-Store apps) diff --git a/windows/client-management/mdm/enterprisemodernappmanagement-csp.md b/windows/client-management/mdm/enterprisemodernappmanagement-csp.md index ebe9611293..f8a14b5289 100644 --- a/windows/client-management/mdm/enterprisemodernappmanagement-csp.md +++ b/windows/client-management/mdm/enterprisemodernappmanagement-csp.md @@ -68,7 +68,7 @@ The following image shows the EnterpriseModernAppManagement configuration servic - PackageDetails - returns all inventory attributes of the package. This includes all information from PackageNames parameter, but does not validate RequiresReinstall. - RequiredReinstall - Validates the app status of the apps in the inventory query to determine if they require a reinstallation. This attribute may impact system performance depending on the number of apps installed. Requiring reinstall occurs when resource package updates or when the app is in a tampered state. - Source - specifies the app classification that aligns to the existing inventory nodes. You can use a specific filter or if no filter is specified then all sources will be returned. If no value is specified, all classifications are returned. Valid values are: - - AppStore - This classification is for apps that were acquired from Windows Store. These were apps directly installed from Windows Store or enterprise apps from Windows Store for Business. + - AppStore - This classification is for apps that were acquired from Windows Store. These were apps directly installed from Windows Store or enterprise apps from Microsoft Store for Business. - nonStore - This classification is for apps that were not acquired from the Windows Store. - System - Apps that are part of the OS. You cannot uninstall these apps. This classification is read-only and can only be inventoried. - PackageTypeFilter - Specifies one or multiple types of packages you can use to query the user or device. Multiple values must be separated by |. Valid values are: diff --git a/windows/client-management/mdm/get-inventory.md b/windows/client-management/mdm/get-inventory.md index 3c83d22f62..c5268976eb 100644 --- a/windows/client-management/mdm/get-inventory.md +++ b/windows/client-management/mdm/get-inventory.md @@ -1,6 +1,6 @@ --- title: Get Inventory -description: The Get Inventory operation retrieves information from the Windows Store for Business to determine if new or updated applications are available. +description: The Get Inventory operation retrieves information from the Microsoft Store for Business to determine if new or updated applications are available. MS-HAID: - 'p\_phdevicemgmt.get\_seatblock' - 'p\_phDeviceMgmt.get\_inventory' @@ -15,7 +15,7 @@ ms.date: 06/19/2017 # Get Inventory -The **Get Inventory** operation retrieves information from the Windows Store for Business to determine if new or updated applications are available. +The **Get Inventory** operation retrieves information from the Microsoft Store for Business to determine if new or updated applications are available. ## Request diff --git a/windows/client-management/mdm/get-localized-product-details.md b/windows/client-management/mdm/get-localized-product-details.md index eaa61805b9..d735043656 100644 --- a/windows/client-management/mdm/get-localized-product-details.md +++ b/windows/client-management/mdm/get-localized-product-details.md @@ -1,6 +1,6 @@ --- title: Get localized product details -description: The Get localized product details operation retrieves the localization information of a product from the Windows Store for Business. +description: The Get localized product details operation retrieves the localization information of a product from the Micosoft Store for Business. ms.assetid: EF6AFCA9-8699-46C9-A3BB-CD2750C07901 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get localized product details -The **Get localized product details** operation retrieves the localization information of a product from the Windows Store for Business. +The **Get localized product details** operation retrieves the localization information of a product from the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-offline-license.md b/windows/client-management/mdm/get-offline-license.md index 3bf57d69fb..292398084a 100644 --- a/windows/client-management/mdm/get-offline-license.md +++ b/windows/client-management/mdm/get-offline-license.md @@ -1,6 +1,6 @@ --- title: Get offline license -description: The Get offline license operation retrieves the offline license information of a product from the Windows Store for Business. +description: The Get offline license operation retrieves the offline license information of a product from the Micosoft Store for Business. ms.assetid: 08DAD813-CF4D-42D6-A783-994A03AEE051 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get offline license -The **Get offline license** operation retrieves the offline license information of a product from the Windows Store for Business. +The **Get offline license** operation retrieves the offline license information of a product from the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-product-details.md b/windows/client-management/mdm/get-product-details.md index f11532b8c5..c35071dc7b 100644 --- a/windows/client-management/mdm/get-product-details.md +++ b/windows/client-management/mdm/get-product-details.md @@ -1,6 +1,6 @@ --- title: Get product details -description: The Get product details operation retrieves the product information from the Windows Store for Business for a specific application. +description: The Get product details operation retrieves the product information from the Micosoft Store for Business for a specific application. ms.assetid: BC432EBA-CE5E-43BD-BD54-942774767286 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get product details -The **Get product details** operation retrieves the product information from the Windows Store for Business for a specific application. +The **Get product details** operation retrieves the product information from the Micosoft Store for Business for a specific application. ## Request diff --git a/windows/client-management/mdm/get-product-package.md b/windows/client-management/mdm/get-product-package.md index 30f41c7a77..69792850cb 100644 --- a/windows/client-management/mdm/get-product-package.md +++ b/windows/client-management/mdm/get-product-package.md @@ -1,6 +1,6 @@ --- title: Get product package -description: The Get product package operation retrieves the information about a specific application in the Windows Store for Business. +description: The Get product package operation retrieves the information about a specific application in the Micosoft Store for Business. ms.assetid: 4314C65E-6DDC-405C-A591-D66F799A341F ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get product package -The **Get product package** operation retrieves the information about a specific application in the Windows Store for Business. +The **Get product package** operation retrieves the information about a specific application in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-product-packages.md b/windows/client-management/mdm/get-product-packages.md index f65a5ec30c..932a85e68d 100644 --- a/windows/client-management/mdm/get-product-packages.md +++ b/windows/client-management/mdm/get-product-packages.md @@ -1,6 +1,6 @@ --- title: Get product packages -description: The Get product packages operation retrieves the information about applications in the Windows Store for Business. +description: The Get product packages operation retrieves the information about applications in the Micosoft Store for Business. ms.assetid: 039468BF-B9EE-4E1C-810C-9ACDD55C0835 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get product packages -The **Get product packages** operation retrieves the information about applications in the Windows Store for Business. +The **Get product packages** operation retrieves the information about applications in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-seat.md b/windows/client-management/mdm/get-seat.md index 5c1e6fbba9..c6b07c1a2a 100644 --- a/windows/client-management/mdm/get-seat.md +++ b/windows/client-management/mdm/get-seat.md @@ -1,6 +1,6 @@ --- title: Get seat -description: The Get seat operation retrieves the information about an active seat for a specified user in the Windows Store for Business. +description: The Get seat operation retrieves the information about an active seat for a specified user in the Micosoft Store for Business. ms.assetid: 715BAEB2-79FD-4945-A57F-482F9E7D07C6 ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get seat -The **Get seat** operation retrieves the information about an active seat for a specified user in the Windows Store for Business. +The **Get seat** operation retrieves the information about an active seat for a specified user in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-seats-assigned-to-a-user.md b/windows/client-management/mdm/get-seats-assigned-to-a-user.md index d7c55310d3..d0227888e5 100644 --- a/windows/client-management/mdm/get-seats-assigned-to-a-user.md +++ b/windows/client-management/mdm/get-seats-assigned-to-a-user.md @@ -1,6 +1,6 @@ --- title: Get seats assigned to a user -description: The Get seats assigned to a user operation retrieves information about assigned seats in the Windows Store for Business. +description: The Get seats assigned to a user operation retrieves information about assigned seats in the Micosoft Store for Business. ms.assetid: CB963E44-8C7C-46F9-A979-89BBB376172B ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get seats assigned to a user -The **Get seats assigned to a user** operation retrieves information about assigned seats in the Windows Store for Business. +The **Get seats assigned to a user** operation retrieves information about assigned seats in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/get-seats.md b/windows/client-management/mdm/get-seats.md index 88d7e51517..4b995cc98c 100644 --- a/windows/client-management/mdm/get-seats.md +++ b/windows/client-management/mdm/get-seats.md @@ -1,6 +1,6 @@ --- title: Get seats -description: The Get seats operation retrieves the information about active seats in the Windows Store for Business. +description: The Get seats operation retrieves the information about active seats in the Micosoft Store for Business. ms.assetid: 32945788-47AC-4259-B616-F359D48F4F2F ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Get seats -The **Get seats** operation retrieves the information about active seats in the Windows Store for Business. +The **Get seats** operation retrieves the information about active seats in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/management-tool-for-windows-store-for-business.md b/windows/client-management/mdm/management-tool-for-windows-store-for-business.md index 0cef4c42b9..02d281e49f 100644 --- a/windows/client-management/mdm/management-tool-for-windows-store-for-business.md +++ b/windows/client-management/mdm/management-tool-for-windows-store-for-business.md @@ -1,6 +1,6 @@ --- -title: Management tool for the Windows Store for Business -description: The Windows Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. +title: Management tool for the Micosoft Store for Business +description: The Micosoft Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. MS-HAID: - 'p\_phdevicemgmt.business\_store\_portal\_management\_tool' - 'p\_phDeviceMgmt.management\_tool\_for\_windows\_store\_for\_business' @@ -13,9 +13,9 @@ author: nickbrower ms.date: 06/19/2017 --- -# Management tool for the Windows Store for Business +# Management tool for the Micosoft Store for Business -The Windows Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. The Store for Business enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates. +The Micosoft Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. The Store for Business enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates. Here's the list of the available capabilities: @@ -26,7 +26,7 @@ Here's the list of the available capabilities: - Custom Line of Business app support –Enables management and distribution of enterprise applications through the Store for Business. - Support for Windows desktop and mobile devices - The Store for Business supports both desktop and mobile devices. -For additional information about Store for Business, see the TechNet topics in [Windows Store for Business](https://technet.microsoft.com/library/mt606951.aspx). +For additional information about Store for Business, see the TechNet topics in [Micosoft Store for Business](https://technet.microsoft.com/library/mt606951.aspx). ## Management services diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index ecdd2bbd8a..8df80081ce 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -102,7 +102,7 @@ For details about Microsoft mobile device management protocols for Windows 10 s
-

Management tool for the Windows Store for Business

+

Management tool for the Micosoft Store for Business

New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

@@ -999,6 +999,10 @@ For details about Microsoft mobile device management protocols for Windows 10 s

Added new policies.

+Microsoft Store for Business +

Windows Store for Business name changed to Microsoft Store for Business.

+ + [Policy CSP](policy-configuration-service-provider.md)

Added the following new policies for Windows 10, version 1709:

    @@ -1371,6 +1375,10 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware
  • System/LimitEnhancedDiagnosticDataWindowsAnalytics
+ +Microsoft Store for Business +

Windows Store for Business name changed to Microsoft Store for Business.

+ The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/en-us/library/mt221945.aspx)

The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

diff --git a/windows/client-management/mdm/reclaim-seat-from-user.md b/windows/client-management/mdm/reclaim-seat-from-user.md index ee30992445..1319338ddc 100644 --- a/windows/client-management/mdm/reclaim-seat-from-user.md +++ b/windows/client-management/mdm/reclaim-seat-from-user.md @@ -1,6 +1,6 @@ --- title: Reclaim seat from user -description: The Reclaim seat from user operation returns reclaimed seats for a user in the Windows Store for Business. +description: The Reclaim seat from user operation returns reclaimed seats for a user in the Micosoft Store for Business. ms.assetid: E2C3C899-D0AD-469A-A319-31A420472A4C ms.author: maricia ms.topic: article @@ -12,7 +12,7 @@ ms.date: 06/19/2017 # Reclaim seat from user -The **Reclaim seat from user** operation returns reclaimed seats for a user in the Windows Store for Business. +The **Reclaim seat from user** operation returns reclaimed seats for a user in the Micosoft Store for Business. ## Request diff --git a/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md b/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md index 5016c86ac9..d64e4e1b4d 100644 --- a/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md +++ b/windows/client-management/mdm/rest-api-reference-windows-store-for-business.md @@ -1,6 +1,6 @@ --- -title: REST API reference for Windows Store for Business -description: REST API reference for Windows Store for Business +title: REST API reference for Micosoft Store for Business +description: REST API reference for Micosoft Store for Business MS-HAID: - 'p\_phdevicemgmt.business\_store\_portal\_management\_rest\_api\_reference' - 'p\_phDeviceMgmt.rest\_api\_reference\_windows\_store\_for\_Business' @@ -13,7 +13,7 @@ author: nickbrower ms.date: 06/19/2017 --- -# REST API reference for Windows Store for Business +# REST API reference for Micosoft Store for Business Here's the list of available operations: From 5341e95d5022585935a358d7be6d72be9bb835fd Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 18 Sep 2017 13:53:57 -0700 Subject: [PATCH 25/30] add description for ipv4 and ipv6 --- ...mapping-windows-defender-advanced-threat-protection.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md index 1732c065bd..f775017c4c 100644 --- a/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md @@ -53,7 +53,7 @@ Field numbers match the numbers in the images below. | 12 | Sha256 | deviceCustomString6 | 9987474deb9f457ece2a9533a08ec173a0986fa3aa6ac355eeba5b622e4a43f5 | Available for Windows Defender AV alerts. | | 13 | ThreatName | eviceCustomString1 | Trojan:Win32/Skeeyah.A!bit | Available for Windows Defender AV alerts. | | 14 | IpAddress | sourceAddress | 218.90.204.141 | Available for alerts associated to network events. For example, 'Communication to a malicious network destination'. | -| 15 | Url | requestUrl | down.esales360.cn | Availabe for alerts associated to network events. For example, 'Communication to a malicious network destination'. | +| 15 | Url | requestUrl | down.esales360.cn | Available for alerts associated to network events. For example, 'Communication to a malicious network destination'. | | 16 | RemediationIsSuccess | deviceCustomNumber2 | TRUE | Available for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE. | | 17 | WasExecutingWhileDetected | deviceCustomNumber1 | FALSE | Available for Windows Defender AV alerts. ArcSight value is 1 when TRUE and 0 when FALSE. | | 18 | AlertId | externalId | 636210704265059241_673569822 | Value available for every alert. | @@ -63,12 +63,12 @@ Field numbers match the numbers in the images below. | 22 | Actor | deviceCustomString4 | | Available for alerts related to a known actor group. | | 21+5 | ComputerDnsName | No mapping | liz-bean.contoso.com | The machine fully qualified domain name. Value available for every alert. | | | LogOnUsers | sourceUserId | contoso\liz-bean; contoso\jay-hardee | The domain and user of the interactive logon user/s at the time of the event. Note: For machines on Windows 10 version 1607, the domain information will not be available. | -| | InternalIPv4List | No mapping | 192.168.1.7, 10.1.14.1 | | -| | InternalIPv4List | No mapping | fd30:0000:0000:0001:ff4e:003e:0009:000e, FE80:CD00:0000:0CDE:1257:0000:211E:729C | | +| | InternalIPv4List | No mapping | 192.168.1.7, 10.1.14.1 | List of IPV4 internal IPs for active network interfaces. | +| | InternalIPv6List | No mapping | fd30:0000:0000:0001:ff4e:003e:0009:000e, FE80:CD00:0000:0CDE:1257:0000:211E:729C | List of IPV6 internal IPs for active network interfaces. | | Internal field | LastProcessedTimeUtc | No mapping | 2017-05-07T01:56:58.9936648Z | Time when event arrived at the backend. This field can be used when setting the request parameter for the range of time that alerts are retrieved. | | | Not part of the schema | deviceVendor | | Static value in the ArcSight mapping - 'Microsoft'. | | | Not part of the schema | deviceProduct | | Static value in the ArcSight mapping - 'Windows Defender ATP'. | -| | Not part of the schema | deviceVersion | | Static value in the ArcSight mapping - '2.0', used to identify the mapping versions. |1234567891011121314151617181920212223242526272829303132 +| | Not part of the schema | deviceVersion | | Static value in the ArcSight mapping - '2.0', used to identify the mapping versions. ![Image of alert with numbers](images/atp-alert-page.png) From 4c3c8d03d60314172f3c73b11a9ced0e1489fdeb Mon Sep 17 00:00:00 2001 From: Maricia Alforque Date: Mon, 18 Sep 2017 20:57:38 +0000 Subject: [PATCH 26/30] Merged PR 3250: Update/BranchReadinessLevel in Policy CSP --- .../new-in-windows-mdm-enrollment-management.md | 1 + windows/client-management/mdm/policy-csp-update.md | 14 +++++++++----- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index 8df80081ce..38b240b6b4 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -1374,6 +1374,7 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware
  • Search/AllowCloudSearch
  • System/LimitEnhancedDiagnosticDataWindowsAnalytics
  • +

    Added new settings to Update/BranchReadinessLevel policy in Windows 10 version 1709.

    Microsoft Store for Business diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md index e3a796b41d..1bf1c34365 100644 --- a/windows/client-management/mdm/policy-csp-update.md +++ b/windows/client-management/mdm/policy-csp-update.md @@ -471,8 +471,12 @@ This policy is accessible through the Update setting in the user interface or Gr

    The following list shows the supported values: -- 16 (default) – User gets all applicable upgrades from Current Branch (CB). -- 32 – User gets upgrades from Current Branch for Business (CBB). +- 2 {0x2} - Windows Insider build - Fast (added in Windows 10, version 1709) +- 4 {0x4} - Windows Insider build - Slow (added in Windows 10, version 1709) +- 8 {0x8} - Release Windows Insider build (added in Windows 10, version 1709) +- 16 {0x10} - (default) Semi-annual Channel (Targeted). Device gets all applicable feature updates from Semi-annual Channel (Targeted). +- 32 {0x20} - Semi-annual Channel. Device gets feature updates from Semi-annual Channel. + @@ -1253,12 +1257,12 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego > Don't use this policy in Windows 10, version 1607 devices, instead use the new policies listed in [Changes in Windows 10, version 1607 for update management](device-update-management.md#windows10version1607forupdatemanagement). You can continue to use RequireDeferUpgrade for Windows 10, version 1511 devices. -

    Allows the IT admin to set a device to CBB train. +

    Allows the IT admin to set a device to Semi-Annual Channel train.

    The following list shows the supported values: -- 0 (default) – User gets upgrades from Current Branch. -- 1 – User gets upgrades from Current Branch for Business. +- 0 (default) – User gets upgrades from Semi-Annual Channel (Targeted). +- 1 – User gets upgrades from Semi-Annual Channel. From dd7bacf4d7169aa9c0dfab20847df41b9b110d09 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 18 Sep 2017 21:11:56 +0000 Subject: [PATCH 27/30] Merged PR 3254: Fixed Store reference --- ...oy-surface-app-with-windows-store-for-business.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/devices/surface/deploy-surface-app-with-windows-store-for-business.md b/devices/surface/deploy-surface-app-with-windows-store-for-business.md index aceac9a792..52626b026e 100644 --- a/devices/surface/deploy-surface-app-with-windows-store-for-business.md +++ b/devices/surface/deploy-surface-app-with-windows-store-for-business.md @@ -31,11 +31,11 @@ The Surface app is a lightweight Windows Store app that provides control of many * Quick access to support documentation and information for your device -If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Microsoft Store or your Microsoft Store for Business. +If your organization is preparing images that will be deployed to your Surface devices, you may want to include the Surface app (formerly called the Surface Hub) in your imaging and deployment process instead of requiring users of each individual device to download and install the app from the Windows Store or your Microsoft Store for Business. ##Surface app overview -The Surface app is available as a free download from the [Microsoft Store](https://www.microsoft.com/store/apps/Surface/9WZDNCRFJB8P). Users can download and install it from the Microsoft Store, but if your organization uses Microsoft Store for Business instead, you will need to add it to your store’s inventory and possibly include the app as part of your Windows deployment process. These processes are discussed throughout this article. For more information about Microsoft Store for Business, see [Microsoft Store for Business](https://technet.microsoft.com/windows/store-for-business) in the Windows TechCenter. +The Surface app is available as a free download from the [Windows Store](https://www.microsoft.com/store/apps/Surface/9WZDNCRFJB8P). Users can download and install it from the Windows Store, but if your organization uses Microsoft Store for Business instead, you will need to add it to your store’s inventory and possibly include the app as part of your Windows deployment process. These processes are discussed throughout this article. For more information about Microsoft Store for Business, see [Microsoft Store for Business](https://technet.microsoft.com/windows/store-for-business) in the Windows TechCenter. ##Add Surface app to a Microsoft Store for Business account @@ -49,7 +49,7 @@ Before users can install or deploy an app from a company’s Microsoft Store for ![Show offline licenses apps checkbox](images/deploysurfapp-figure1-enablingapps.png "Show offline licenses apps checkbox")
    *Figure 1. Enable apps for offline use* -4. Add Surface app to your Micrososft Store for Business account by following this procedure: +4. Add Surface app to your Microsoft Store for Business account by following this procedure: * Click the **Shop** menu. * In the search box, type **Surface app**, and then click the search icon. * After the Surface app is presented in the search results, click the app’s icon. @@ -68,7 +68,7 @@ Before users can install or deploy an app from a company’s Microsoft Store for * Click **OK**. ##Download Surface app from a Microsoft Store for Business account -After you add an app to the Windows Store for Business account in Offline mode, you can download and add the app as an AppxBundle to a deployment share. +After you add an app to the Microsoft Store for Business account in Offline mode, you can download and add the app as an AppxBundle to a deployment share. 1. Log on to the Microsoft Store for Business account at https://businessstore.microsoft.com. 2. Click **Manage->Apps & software**. A list of all of your company’s apps is displayed, including the Surface app you added in the [Add Surface app to a Microsoft Store for Business account](#add-surface-app-to-a-microsoft-store-for-business-account) section of this article. 3. Under **Actions**, click the ellipsis (**…**), and then click **Download for offline use** for the Surface app. @@ -102,7 +102,7 @@ To download the required frameworks for the Surface app, follow these steps: ##Install Surface app on your computer with PowerShell The following procedure provisions the Surface app onto your computer and makes it available for any user accounts created on the computer afterwards. -1. Using the procedure described in the [How to download Surface app from a Windows Store for Business account](#download-surface-app-from-a-windows-store-for-business-account) section of this article, download the Surface app AppxBundle and license file. +1. Using the procedure described in the [How to download Surface app from a Microsoft Store for Business account](#download-surface-app-from-a-microsoft-store-for-business-account) section of this article, download the Surface app AppxBundle and license file. 2. Begin an elevated PowerShell session. >[!NOTE] @@ -121,7 +121,9 @@ The following procedure provisions the Surface app onto your computer and makes ``` 4. The Surface app will now be available on your current Windows computer. + Before the Surface app is functional on the computer where it has been provisioned, you must also provision the frameworks described earlier in this article. To provision these frameworks, use the following procedure in the elevated PowerShell session you used to provision the Surface app. + 5. In the elevated PowerShell session, copy and paste the following command: ``` Add-AppxProvisionedPackage –Online –SkipLicense –PackagePath \Microsoft.VCLibs.140.00_14.0.23816.0_x64__8wekyb3d8bbwe.Appx From 3619cc57ba0e570f72ba67827d9f56eb7a39e2f7 Mon Sep 17 00:00:00 2001 From: Trudy Hakala Date: Mon, 18 Sep 2017 21:43:01 +0000 Subject: [PATCH 28/30] Merged PR 3259: Merge msfb-12118094 to master add autopilot video, update device file information and sample graphics --- store-for-business/add-profile-to-devices.md | 20 +++++++++++------- .../images/autopilot-process.png | Bin 9361 -> 8131 bytes .../images/msfb-autopilot-csv.png | Bin 0 -> 8466 bytes 3 files changed, 12 insertions(+), 8 deletions(-) create mode 100644 store-for-business/images/msfb-autopilot-csv.png diff --git a/store-for-business/add-profile-to-devices.md b/store-for-business/add-profile-to-devices.md index 0f6cc91a16..2be986c161 100644 --- a/store-for-business/add-profile-to-devices.md +++ b/store-for-business/add-profile-to-devices.md @@ -7,20 +7,20 @@ ms.sitesec: library ms.pagetype: store author: TrudyHa ms.author: TrudyHa -ms.date: 07/05/2107 +ms.date: 09/12/2017 ms.localizationpriority: high --- # Manage Windows device deployment with Windows AutoPilot Deployment **Applies to** - - Windows 10 -> [!IMPORTANT] -> This topic has been updated to reflect the latest functionality, which we are releasing to customers in stages. You may not see all of the options described here until you receive the update. +Windows AutoPilot Deployment Program simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows AutoPilot](https://docs.microsoft.com/windows/deployment/windows-10-auto-pilot). -Windows AutoPilot Deployment Program simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows AutoPilot](https://docs.microsoft.com/windows/deployment/windows-10-auto-pilot). +Watch this video to learn more about Windows AutoPilot in Micrsoft Store for Business. + + ## What is Windows AutoPilot Deployment Program? In Microsoft Store for Business, you can manage devices for your organization and apply an *AutoPilot deployment profile* to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows based on the AutoPilot deployment profile you applied to the device. @@ -54,9 +54,13 @@ To manage devices through Microsoft Store for Business and Education, you'll nee ### Device information file format Columns in the device information file need to use this naming and be in this order: -- Column 1: Device Serial Number -- Column 2: Windows Product ID -- Column 3: Hardware Hash +- Column A: Device Serial Number +- Column B: Windows Product ID +- Column C: Hardware Hash + +Here's a sample device information file: + +![Notepad file showing example entries for Column A (Device Serial Number), Column B (Windows Product ID), and Column C (Hardware Hash).](images/msfb-autopilot-csv.png) When you add devices, you need to add them to an *AutoPilot deployment group*. Use these groups to apply AutoPilot deployment profiles to a group of devices. The first time you add devices to a group, you'll need to create an AutoPilot deployment group. diff --git a/store-for-business/images/autopilot-process.png b/store-for-business/images/autopilot-process.png index 491b8c0ef0e40126a8cd01c10805e4f8aa998f67..56c379fd5f176f51e56382b36d70142135b7b9b5 100644 GIT binary patch literal 8131 zcmcI}XH=8hm$#xQMFj!rhysEXsnVMwMY@7?L+@1~A#?;qq;~>HkrKE-=sf}HAf3=# zKtLgsgbs?7dBFL5@16JkG9M;urJStu?6c2r_q{`&X((MMp(nX;;lg$0r}A1CE)d87 zze9-#fX{pJ<7L3tMK>)axeLYpj4Qz6vdv@l#}_V?MUftv5dv%CS5FPxE?l4hpS>^6 zS~GiGxWKHhEdTh0hcPbgryF%=TF0FK7pigD=qZzG`-=P|Q@0Igk&gwI4ry(slom}y zV@jzY$|t3ckL2X8ib_O3x^r2M=1ve8-lg%=@9AxC z87iWsDQcXgp7cMJsuCa+NUYUd%yrXT*ovt8P}b&4FPdgSG2pEBPQ)&p7x@d1VpV|9 zG)~NI|7sjNa(5fmoPCg#e=?ducIvzqQ=b(Vq{LV0KI{2&`}@eqNTFVdaibp-eb1Y2 zCgVvWZYWm&O70IyIYq;)wb{kjEH$RSlO-~;@g`_3zlE0M$d68XDCUUp-WSl98*m$h zgj-NLbhJ7pqj>W8`Fu!N&6NyUe+{uTo(S>KIM)b0_vY^AQMPMpThMpmR7&GN+P;}^ z_w!EG!oKX?@ZpxW!Fz1t`R9-NXc7t=i*dJUPfmVqnACeb-eA2fsJlXF{B5FzfGID4 z^W;WcOg9!eBUJA({COdJ8NS?Q#q5N8xz!aAYq5M=)=x@CM&r(kIvaaQ=+}GVx}}de z($1a=h$+Vw*yFrxRQH+&p{!)gEgEEVsMEai;g2M1?}LLoJ383e*|FLZ+q(oM@sY$l zgUPc^RQ_w$IqXQRcQRfJ37J^grlgsj^r_7&@wc>m_c=Sn{GBZL&G>F4H8s}bA%FYa zAuZ>J;!6=}ChL-{7=cvBtXe;Bbr+Y7w^zy1Wqc*X#p#s20$?;sgrs0WL12FhEn!6Q zj_5}5lrAfVJGFmz;F!+}g27-8Hs&}&?HfNe5Y^X9`sjaJY(3+}lW)j8H&(D%?AjUw9bIx#lE>bvju^A?*M$7mcZ3q3ud8j^OT7`= zV{Q~rF)?-nbfmetxvZ>=hR^uj<|S#5pKf9Rw4VTIb$h<}gMD@VtWUebhWeU~XFM|3 zU>WhEqM}d;1cQP`$zP0*AvLA0KCDXCr0no47wfS_zo$0g7mJmo)l0<9G`!cY zU6bzv|mq%fWfB&8&G@OMOL2obaZqcJa|y!GIyJf&hzA`E_d!) zGxw(|Kpl1d!`I$)pAMMvj4cdCc6Wf8ib=|&G&3`^qC$Jk<^9)NgN9}SkzALwkBXvW zGO$@2Cr>(86l9Bz>?&r?(#!OxI#sKK+t(im9fJnJZ+A13c=}&q1VD#DL zT#6rxzo@zC8yXsdK$x+yvGH+H5s~-U(4xI&lH?nO=85Lo{VzN_Ov^$20fel#YOq=@ zMCe<|ge?UH1;F<7^mH^D-PNUhuSbo-gRn+M|Lzc{$vki13-pqUlmqV2-G^&2yy=@@ zA1?H}qu&7=(>9(~QSX%^ozgg&>=F5`b~@{n*4WtC?(Xiy#6&zE-xP9j6%^bYi)0B{N}UN*JG8v zYymI|hrnAbO#594xku>CpC7yPRbrQ1BvcbEZ*bH|8X*po@L*iOpBit5O;>yF z$kf-|m3wMO3@OTYKIUQ~c~|y=t`{ylS<@Gqzr%+1QnxHESS&w6N2#;hZpbtvh9 z&&pKV8^%So15LSX9RWG8g0=b?*qmkT0NAgW<9hH<5LsPb0793HUtmx>a z7r#?;mEFM??x0Dp-hSFUS@SnpZ2ilP#a=|Q!j50wV2Y`ka6ZJ@l;Y++;n?9Sj>#<} z^B;hr_=7QxP_i550F+u^>VNqAptc;fysM2Uc@XSX{nyo;)~!m_?Ah`hV104i-&+3k04FX+NzuzYfQob1n?{ zsRG)&NS2CRD|XHo#yr*tY`IJnB7@wM1pbB1Yz+$-yhlDbDtGe#yT1b(Ux?mnmB>=1 z){Qef^Dh6mNP9)kF^wq*-M-)Q%MHe^udi-@=H9sg_r5l}$RI)@O!jGC zkAslW)b>&`3eFRx(wFW7+i&Mpy}!eguA7y1klAED?ZmKLmML0YCgZ4|Eq%=)FlaPq z42Vd-P3Vl$eUFgvGOLaRDv)B>U8O1UDHyDbr!w2YGavHhOX({F@mQ~sdgOQ{(KWT( zOn2FJ!pT7~2E&4J58rx(U}Nc@l(Xy8uh7mFa`jLaLaPyaS5I;mj=U7Xo>07*R{NP( z5`G}0{DBv+D^+Hu0`;DsrxqT3jrm?Ymi^90SB;)i3l)bPuCnvTSVSuSk;7eNygnrl z2pn!=(9oY0m6Ei&Y_de;z(SYwMW8e14_fECKO`UA;INZr;q(fn%2r~RC@KDC|-Zj9B}i?}~kP*>CGNyY8E zFD+gcrw6Cr42Z{!ujI`ZG+fgV%>FCOk6poaAAe7vtpqmgFkfY?i<4yN&BAB8nq$uO+aH5dh5MzxiD9g4P(C5x#R-_UovC1TpL<>!Zu{O)ME1ov zE=7SbUV&^aR&fx@G77U`c4mYk@-#-3V+$d9!p&M5O61Y>KV7r~!|n&w>y{aan!P5- zO3pBcxZNs=e;b#E!^`A%DkD<`FHwpwCA|Hp|WD1Q2{E44O^I_IN~$kk?(jKGI*)aJxZ8O}cxs35`u$YDhXHT6LsD31g!h#x z3&%dL1)t0}u&iX2$`%@GQ)J7oui4cL7dYJfo}?qN%?yGDzpqDmKGE7ruE|Wkaf?r# zEfHVsWr$jtx|g>$7Vp#0R&G8Pj3I8Uta==Qn)Gbvyh5cRJB7(KM}bAeHMUFv^i$DR z$F~)>J9`Qzd&O?g2%p-qw~39&zqahpv^ddD7wfZ4oP_%$G%s)m-1CKmFhe>s8b=g3 z4iEtH;rA<3kQrEzytuVacuNSc?p%>XyW=g^d@gvQFDGTt`W84Z;t3jdCS`fB_!HHq zI|UY&%TBiD(~gNx2`E1rTd2gTRY<$640+!8w10%s%yI9xMWU~Hn^85Xm>QrHj$lt$ zT+eT>Ya0SG)w0zI2f!cv`bm#wtNWY1;}pNBz(#g%=41D8muokKedP(e*OQAuu1IIc zqqZRys7-6UU>4Z$()Jh1G!Tc@uOXH?fvU;TWoKIzdrcRBEya$!oI#51R&G{?;eMNR zC!>mPj=sc8%x{-cG&_&t+Rb=T0;9H(k!%_&u!N>8tjfWhzY45p!jX$nC^ZBVmw^F{ z2{A~a^_Doi_FO1$FI~C~s$`4N*J2YE@s)?$D&KU3Exq-rb(kE%R5DlJFd^74#mYU zm)~$37o}%9WXQidZS~{{^GqG|z^2-YT>(-3NX`+jr0f`7;K%RbqY5$Fz48mr5kGbD$qdSa5-&c?$9x^A)5`B735Liz4I+ud1*1=~NXQQR zZw(Eq_uzMgRx;)#n6KiP+!s@YJ8QH}c&8G*=-<{VsftoTV&13ZHu?ltsxIrJ9wUf# zKNKpf<&I!6>tLO@{DD6dCr1gdmH`>CGE)gsxPsD6<}Wuq`|P3Oy0d>6%eNw&uDAJq zio}@T(WSAFnjINy|AXSZO#NT$WRV|nF8;0b5$?-%`FuA={*faCf-hze{d(uDBFbOf z6YhzWy)EQEIcqdm8})fl*oiT_a)CkXSA@%t#7X?bo>=@$-zyBW&9KwxmeUGF|C5VF z#Q#r9ZEX!^%6{fbgeG)5PqhJKLcTth_zec6K63kxnEm?FPJC(9_OVYk!`xR94fAO! zukF5*NKn)h1B`wJre7uV=3dGo3T+ z&||imuHwFPghw3a^~N%Re|k^WiN;$>Y+;?(roX0J-!Jnm zih~#=4b*sg5ce53cx6IVwv+Z(ngMtCKg*04+Y8TGT38z}o|Ku=m?AxgzywHPNCV>s z(JN~aZT2-L^ejNe?Dp;qEB8IF-&n!x?R5uKcxKpzRrZHCu8r3Z-~pX=0#waWc(h(t zQosQcF=6$oh;GTGw%dBTCV&%43kbAOulTov(CT%V=A)>XEs3EA$+WOOvA;Gq{X-&w z{@92T!DFN@FS`}y)WLg6-FqQg%p4rn-xM!-76%i0VDsk+ah|j%Sb?jD!g{=waul77 zscTds<{6S)gU|T%S)urc3vPjH@693%HgujlQD!-z`wKB+I=g|+B3hcWL3Yi$eura( z9Wuj#MT(?z(bd}Nw<9Z!M*gKiH(HvK@c4O!d}ie;&BhV}I(By|xvF3a zn^??))UeTeotia08ATjk54b`Q(&Og2P5Y2K=*I(D{w4RLW z&#wI0(XFx*Eq2F6uh=rvK24}|lY99!sCI4z=%q!`&APf>5mEvWg2H#M{UN#AG zd{)n2wmXtd{$bbFCHPJ5Fl)Qs|>NJ}{p6FxAdU*8ldt(|PqZN^4;i!9T`!(iiMW7Rb^WWQUUCTBPM*Lh*Q`xzg(Rk$@Ot1Fw5kxTN6 z12PjjFJ4r-%za+$j50xjSMV5=W`;~!O3LAUFmt$pF2^Q`IR8Yvp6Qhj_iw%A1>ZQ<R#gD;VS z3FraDz5|HS1bqX>9zTBkI87Awsa|_JoGesIvmv2hW8PZaBDcT#{P}bA#DvFU$Mr+| zvuT9Rae0i^*YB;F%>-$8&N{zWSx?alCY}QsvUz-;WgYV;$~Ka~C9lfK#>e=KP2w9H zKGoKGoSq!-uA*mWXXoZ*B_vc#`gT_{U!95X??%0_0MH9(L$djH8{=KmnTr+b=i29Nd{>8n*ng_ zos~KZOz+I&T6Q{$(&vsmPnS^z44N75<3Ju?X&a#AjUbeJLP7$XV<%rbulQx1pqQAL zh=_=|xUx|G<{m%1sVAE?fKVd&45lK$anghk#F_5^k|Sf5S;ymz4Dk>@hLzT*tgdWb#lvy;;GLHg) zlf0}LkQK(OcBh@@q3?xRB&2Zj*>MX5H8<@_#6vuri@PQJ%XGXz7RLj;czJpG`0@^J zER4_2YMf%3r92*G^gi@{7~JvBp4tQM#%LPQ9|iEbF-S`o%1aTD6D4!F%NpI<+Io5W z=;w|JmCmub)7C=$HdzhRR8^z9KLnHi{{72WduYnt`j6Gj##?jVCw7qe4O#Aq=g*$< zF~Q;RU;DVi;^N#5E3b_^e!wUukB;)l_D00y2;XKo;}iW)agG4etY%aXkxwRsg<3xpxrhx&Sw3f1R7e1NWOTtU>P?6pBD%ovBK>>@$u1ktcqRULJ z06#y!pdiajGcYk7<53%4US7o@lw!tE zJd#5*J%>Zw^&62i#baryCkj!z1_sIl0N>hrdgFtGgEKQe^DRMZ<0S`sd)LXxq9P*H z)zk)gf{rB3%A2_ROCNPo@VA@9@M}>6+RcHi$j{FQrbmOp^Vv#KAFTZSPy0TKmKZlo zq0x^^*oumZc3-qXatq+_p!AsZ_;lFG%{e3_%(#@c=Rp`tO%0~y2W!#za4>XiM>&5v1BTMftyV9pz>A;ibny9DS z)ct*w?XubyK&Db27H!J;YDj1>E}DodB+DaLMe2?;=P{{!?C?d+BG+h`2NLln;Vqaa zr1SFG(H2SJ4;5kewk`zPYA8$93Xo2+zMk$7`WD`%&7e(g5%TMyv%~@0?YX2dTGg4n z*TdrMTk9S2w!oB_@G<%2$0R{mU@RS2uJ(Z!7+2r#dH26q7VaK2p33f#UoJ*dy=DLg P?-!I6G~|orOauQ5#L_S$ literal 9361 zcmcI~Wl&sO(=M*TU4mYzxX77D znhIr5((fWd6X)b2kF*6HFHA=XgHlT>O@S=k+0?pmm?~%9dzqRw^5AuktUs@Q<+|Zl zwo!JJMVZstX+VJ#NP(m}gYrWAdT}A590B>~Jpi}x?^5*t+cIzQ1u&3q6Y%1pE-dVS zIU8n~>UkHT#nQ;-P@;H;pLSg6kPx_lGB)w&q4IKVV60FmyQ;EOz!Au7aKY#4cDg3W zeb!p-y4`iOB-DOv^W+uyenOb&dA7cuw8LBZC;ogo_gt|zs_EqnvrOhaXlC#&;*GEF z3=ao4>)w6z?;uYD0%F3YR>PPHt=`k>C+A$C%=leI*^m9vm`whczL@(M= z=Q5Y$g$kVpAg@Dpw3Vfm=UtK(OZET496Tr#NoZBmZm?Z_7T8RXYtNtj{nYCAg*=!* zhcIU$U`NPqyvYR#IYU6OQF0O8W~F{x#i5~E&q>S^x(F|F&LQ+Z!7lfQ!IykBk?j!z zuHR(j1TLF49c<+T7uos6T)+9*={`PgteUPg+K>i_J(7MszFIY%t&b+Ei(4rC@RQ#~ew*5*Vqk z22iL(Fo!PkY040|UVj67P`InwVfa??eBOrPJ}uQ6^m0H7-n~XbYXT{b^!*y7;t;bHYOKoQEn$dwHw?by$ed zF+kGo%k36;Z1NnvJ<-hyBipw}dl6D&9f5kulEL6y5I$fxFONVsl zd`#$gF2jNZ3-(udAG3wBZB{|qF_+T>@eAE+dcm5|6+kC_Z2i0xj?$|fA`)8%43UO^B|3iG3Zhy#upMIVo{$m zE61!8-@YF_Des{jui~)^k>s~fq`^k4#xjp$%pav(n#j$GE9!f*AJis(JQt_wbuh?q z!cx5H#)EmE{GL{iIvWp_O6^9R^7yh;^>K-UW<6Uuia_0{@sLMz=;dB*qU+}fex%V; za<)8cvz);ZNIjv|oGJLmUY+K>rmFLoM)+RN_-;KH%lT-oUH;SrqU>joEOH8daB#AM zPdxT_WWRuN>VTHCJk`3z9PXVejWGehxGveLrg6j=O+ZUl-1#+J7FH+Jp_zG<3L+g) z6#R(mwz&`cH5ZwPhv=rxrW+XuEaNr}tY4;qsXe95r5(QRU_j})|xZG&5 zul+|FGjB-Y+oW?aqdlk8pvFjEQ;WC!E}s$87BbOCIpoGDsSP3lhUd@4b zth~(qL+*OqAQsto-WfKq=EdTDP+Xsvq1Ff=*`K7S&<&Wo>^ps$rcC5NLo@Kwl1#w& zP$gNQaw^WF4V>Pqom(t>j9?bPQGWRq?0&qNk*BaxOX(N6Jk-I$OhP4($`7JOzR?P9 zKbbsHMq7!=eqYqmnK0!A@jjL~DlN}gC!SWjkF3EX*drxECN(?Cln7O7#@F~X#eG{U zF8yq$hBp^xPrWhTL_8*yFuTdDt*>}Q`+buU{jXJpn2J~J7fG_ezm>_8?!c~gK^|1S zis66wl!louKk9UIWSrvm#3eAQGw-zpo-|W)D*kee3_A)|S#r%bk{3@#*G@t#&-q=Z zSz>(=+tl|8Z-F37StWrA$uGp_j9XyRGVK-wRETpv%WQuLD?tC%n*o^JsrgB=rcR&m z<3i_)LGAj*$x<@<_P{vG{A_1sn72b=`n^tcbLPQwYT;oHg9N6pY;XIe``7pjrk#@j zkDX+aezZa}KRe#68V4Ljo|!+{n)Ap!yN^t&)pj=y#J2ZlblYQC!1%AihF%=tgwtSd zH|f9u?Y?XIHxi7ZBumF)&3w>d={J$z%qe(5KU5!*$gvCuaboyT_9IXEnlUru*K-Iv ziwQEpeuw9&(){~&Y=`&;#75@;z!mzi1-yV7eM0ZXgfkiy&|LrB1blqm9zlfePqzY; zu^S%TtAx`xsH*;xaEuWu!3fpKhBz?=euqn$Dbw){@PFSges1d=Abnj-W^2x*ja0UI1B^(*b} zt!SsVr_Hw;{Ra$k#Bc7E(d(0_)TnF~_&+X=BXCpikC5SfaNNk4%9nKGHeU4~Ai~+s zAV)npW=T5K@&++i8wPrpz<)mjx5Ecg;Hv%#N(e*$`U#SPM+}0l1*I|3Fdn5zy?6AA zS-dSFKAz6NsX6EcRb~(NF%x-5xOa-Xh3NWtb;*gF$*cwF9p)Z^XLfn2jTz2O`A3YK z@EXjkvp;7NloF`sl=TiSfywm;htod5^qJZr6CbPxg^A-*k0fTVciR%>T$}k;HKOjO z^wUn{7k#JeG)Q^UuP}@hO$uY|>Dp;n63{oxN*!QVLM`Y9omFI z-vro-LZo@|@pbUdhBKv&I0CU*vwQY|HGC=BXb?{W) zX@jl)v!Did0vA)ksZWoEAZXfTSbM2%NYqp3K=wB2Go(1>jpB}WW1{=cLxXoR`W&lM z1jNIo?f^8^gBkg8&Q@c3*|!@tdsG&bs26F`g4W!1ih`b(8Mk!4^zpyP!*NsV{b?>> zB2?hE>36N`be3KOJIB*=r3S56;zum-yk>*va%W2DF?8%<D}!UgZduHuTIIqWreE zFS(C3d2Q8I=2_bkkP4o-^) z{%8!*x+mHcvO2lzP!vDRZx?0`l1NSAl>#Bx{L{8;(Yj7>(t9kgyADRRPgdsSC;k+{ zx)&dB^&jc{%-6che#n47s5N(-Q8Hqxh`^6=^Ck_=Bv+33bh_|kw?%YlwyRdw(NI$C zc5wuSXZoU|jDKq)m})A#HNc!B*Zm>svB2T+!G~IMlRUZ0tnC&oxMeNlkDFDCI0YNjw2|H%XPf7&9}V$T7t@#YlTt9z>A0rK%XD z%YIivL*_LD1lKiv{kVsfCKf-^4X6Ch&3Mw_580&0s9VpNNw7lfOM2#7g$AY7nv@*d z(uKPq=f2@l9Mj$&tK0;(;t45FXg+ZG96x0dushHnMs&g_;x2o-2UoJLF2!cP%H3~Oqza{S)Q2%<8P*_O%XEh3I9GX)L* zn;$pzxl3GR+Hmd{+^C~-^Yh<594oHE&r?90 zJg8naIPpKVMT?5xsvwz;{HgT(YeQu>0}r!}@LmjnA;p(r2%KDjG0=#Hih4X#ICiyY zh#@2+=K?0j0)lO8h$Yl*h;GI1)@Y<0eYX!HMv-C+l>rc3apxkilhKt59Iq4=}vs0$%n@A{A5*u;4=rU?mwp zKxw_(OjGQ}Z&PkK5+VB_)@M_MfcGJU2>9{m!@?4jz>d_4ZPG||j5*iCVm2{Z`S8mI z3?&K--oQJ<+@eO`#p#QSO-8+|yYRehfGO+r+OQXE;@vIxFE9e3QYe9-E6~G1$|OkP zI(VJDucQ~eeM#*tg{ZniBua;SkpL(nb=TG()+cU)>Ky->J+cC9TT?cFGt;Bm zQaTbwNx}$G%6?A(vU05hmp%bG9>RV>ng+v^tU-c~kRP+TN5Jpjh@r(G(?Fc$#)m#_ z~SL2$82V-x*%`x<(h3MR8YiZ$dYck&7B6Z-ePAVEAfF)cTk zG>5OlPG6N=l>6lz;IWb$kHxg}K~Y^kMd~rY3un1+9At=Qhai^Dlb5gHyPBiPtBlg_ zSS~mBo2`$~o~5&3%e7+G`NoQNVkjeI`U$-<9^F5_Vi@3DMb3>s$J2}lBMw;lVyg#B z#X8t1gTfv`)NlL@eq6-VKNd957SdjuT71#-y^aRn-tJX_ zrUJgKj7CJvKDFcqAdS^LX5{%%sX%KRRIy@yakC?S|L5=QkHCN?Vs&en%lrl5 z&pM8VG^F-{+EkY6y57q#i=Wj_yAw^t?i|1mele({*)vxMrw=c+*5c`!WX;bNyMo6S zXw?%f)9HN@s9JjpWNT;|tutR!E#s9$476QhNKV%@@NS-$eeE8n%jZ-5EZV`SUnjL#B+WUWLk^g{H_a>_Qbs;8 z{mS!^@|~wYMHbZiabNo&cOn$`VYePrmj&MylIY?S^gMHc_>}CYL6YS=G`sNGYLh>z zaf&@wI2F?3LsH~smaO~(^lvF&#)5~6)n^}i6`Qh2DR6NXKUAN82BwB@N1lG)dg=xF zYr~XmT@!LvJ1r_navVLByDB}`OmD~O2eL(4(p~Dvg1j3=q)2DaBzA`5ZqOza{iutd z|LnW6;>?^ze2a=|E=s?2efOsXzt(^{tqccxPe%-|^ zPEeM2cpGev+o!jER?X~~6%nPRHSe6m)!;A5sKp~OhhQQiTnB zampzY48UAXH_I!%GGr-$yb_~E*6*3`0-|dO^fq&MCJu9Ay=lOG;wptI=|4crk}qC= zY~>!{b^WAwUvkI0u#D}zb!hntim0;bem`?#3$Pzg?iP+?L3zyGiY0A-H zjfBNHXu`mJ{CyKqLEvc~T99W*E1L2|jyf$vRaJWtI$>3ElBzqTa|)co*O4Xq+aSHm zMRLxw%^}iWT6ipSJGFF`^JrUY!CGBabr&R+J;Bi*&Hy*ExYei)gc9^`qA9K~jO)+v zd5#j7HrtHjvW=waWH50eg%q|beD`W6+HY;=AM>`%r?Ac#U@xq7H0p{7$WaGSb`baY z;-xAju;X6lE9a<-VjYOD3x8m*uDIL8dnoR5`B`$HHBBC=(QRownVnXhM?MJ{^|%ky zR(0sc4t`?7HaKnz+DB!=E^vS^1COE|b#nUb{1p88OFzFD_2DHo2sV{vKl=f3)5|UR zApUz@Q;d1Y=Kb3!bsy}lPyG=OnvVdkmHu&I{dOX+yKjh_Axv$z4vk|+!1^rQ$8!RSjm>1>3n5Ft2J!Bqxl8D&$54F6QOdhPKV2%8B#u1CL-oLL6 z)>0>>ja-skY;Ply^w>{V4%S-do+{&tHTZ*BJ{FWEixnJW#MfweK>jwoG!&Qr18ziOb3wswiA&h0zB zT}Lp~dC_A2JCbz{i-S67d#s5CKZ|6w%J0S3G-iCYksF^RJf+5A6`1d&ElB1HK<%xM z3X2@9{lzwk9NAR3a|Wsw^1h3UvN|aohtKoBT?aLu+nGAA9# zJT+PXE(Pun3QJ4)k^H2D6)86m@oWj;q`~pn6gc-BRr*DRdu~5yK;7jf3fm#G_+qsHQUvVl%t8?4t#st_*_jRl)_7% zZ`m;;7W@2^j`LX+Uh^s^i)}C#Ld>pvZ|y_pcdKl_DRoZcZ3*V8?tL9VJDc0rY}3#CW!=rbo$YEpfrL#5 z=?b1{sB2^2klF7z?>=#dQiy*U#SG54OiR#(5MbF=OqYhe@g(r^YH%(vF>)c2Ei6&! z+AAp>l(~bOWxo_z?_P%fcV~NR4B0k@m;%%%YlBTkf97yO%shfQ1d&Ckga-OTrspzJ z-D&9JPp%yu;O;p;qxMqrr2Bid?T$&dMkH0kCNMg-?OlhHZ%|uo{01i{vvHaIRtlk0 zFUx}6?}1}#&&_wZE1Gg>@*K?t=nK_ZIYf}T{nglDm8lrVoPCwx7^Sq-%VWb$8nT;q zd#DeP5!KC-#f;(aATw&rgi~y;x9VJw2}oE%3DI>(pDO$mgkr!!YnJ?(Zv8>@*Jjt< zHHoWt>(pW6i3E4!4q|YMl)S5eR-b2}Ig-m?bFgJZghm7Ybu2x9Z50Hg&x`faaA~g> zM)B!hss7=`Mw?4d5RjF0$Ni=ud>ILnObbC2ny5m~&Ed53% z*saR=E2A&^((31Gq|&{h^NDZxF8?+E{#$6!x^j5Z#^whzK~?e|ejDRK2t907mOb>x z@dZX4poW&AKNfd49SqFF2BYMZXz49m3$TCvHw-i`}7uy*>8YM4zsA|3zE-a=O1YkwFiaJAvy* zO54^*mg3m-k%>`9)%(O`*+jb?SAKh`C?-0kF0OxR&y&m zcYa|m-j22-TwXLlewD}YpZxpJAbnZLaomGgCv(I9!QGyjZ!2S8Y$8b8tJa*CJ(mUm zJM_W(hvm(OAXD-?VeU(?_^`J*#@;u2;kWL?Y+P=t>x5J3kbdMU@X`^sLqG)cc|13n zz9RaW!Oze4c}Ninpy;{q4D~cM7K1xE686X$zD@s;pW_hJStUxuZIIc17sst(y%hiW zRHcBAAaKsM3$OyVb(5&Q+=k~#lC9Xo0I(b>JM?n@2?KV7@axO3X%dl?$I(^qp~l5i zb4C1*em(mO%zkWw{i}7)Ah92Y`cb-KVgy}42D;XOZ0HHDKiq)zr{!D`MH*8VbI{ba z{-S$)DG|_y5K(6yW2PMIp9fl^5*)8G*Hl!eKaquMyxF06fd~xdEPwuX2m)=Plljh+ zA=$T>$o--G^boND+`2hS1Y!{scJEwCVcr8{<*k{V_;_+sf7+){Xi8 z%RDT(Ad1ej`}(jPC+s% z^oCjxyNip9stVVmmE39d*2fgtVT)h^9r{3<9`0C^Tngml%32k#&(5#B4sXXfdl9)Q?EQi;l^X%NB|7dzPk zKALL$l{#UM@fFoB=~5-g*W}zaN~L(wZgZ(=3tjG(+;_1U(gO}7eTAiJ&1@IulNx2b z1IaA9T1#N`)?=Tm(3r(SC>LF36-k^|+G_L?LZF1M;rd?A6{fB1y>yC_gU&|42F6zu za$ort6C~08iz|ZgR@JdNWcs4AlNxyQ9Lw>x^;T4_Sm%rq35TIq;)@R1!2f|L;wru-DX=m0 znK!Stweyl7O=fs!Cb1mRdjH-HK0qhnqs?j~8VX7v&XXsuuqR_5A%r7L{L2v@%=5Ca zped#YbHNQ#wT9@p;h{w%?c4=(ojh)Ly@h$#8rFbdywYU1nJX4nU0od;iy4a|4zpaH z;TmfY!6poGiNLGZIXyi{3b}KXhOR|~p1n6*i}>4}F!!+K9Z!CNV238x7O0`<(0{Kq zz}oP-o*)TrlR64#eN~{v74sY!kb;02cm<<&L~Az)J>Fn7YreOn>)Yyl6*ilgBI~|q z?Qvxhrm(r3kG_Zc{wtKa(LI!qu_$yFoSzAg4@Jjk<7x=E)X!r;cZr0%#L5LvrZN zD_uwDIkI{VD@+fiVHrfl>vO3tE#YD_sbF(Xyxo6ZrzyzDjRtl`vK_F%)FZoH?(})s z+A``SVR~9WhC2kIjnm?nQlq}=(eU)R$~>5Wyjz1%v>KY4nrdnpLVkiD_8%@1IjQeM zUC?MVW5H!BRo0+Fq0Fv)FB>T(k`#bH|9iIs=3YFQapByrqxobrfM=fPi{cq#IF9i9zkWo7N{kHCRQ0#>~x zuiMMcybGf?x5b>!^}tocravo!m`t~vIimm&r`divieDwK+o9v;#1)qdDw6d$Sxq39 z5ds!5F-ot!FqzhVFYRH~8k7_O87D&Gh~qDV-((<@hr7j$&FlqOX5{la5Brg9{nDYM zt^cw))}Xagg^c{>fRJ>GwplPw%qJN$g|u2xBM3o6M1%r?+1ePp2fBd*hgF2AuN5ck z5}2Y2aSZ&cvo|~$qg4E9R3MZ#Xe?O-LdJJbj*gBpX;%6>+9Uh3E5!$KKB3!lb@yX! zs)QWEGCPW3q;UF+l1hov8SZ)lVnY32qygO-CIL;-Z!LZ?{y@!vDIJ_v2Y{4O{97r6 zZES4h<Icmw#)aQtZ)5byM8DseO}0L}bR*@E^SMhMXHQfG&--LfX~eUu%|FVL?h zOW9AtLJ96kqzccmrtk2&KvV3ARE!SYG_SNPPpLpctV2Y4q@*KJO&s zTIS>Eq58|tI$na2Ynu0=S;fbcC41>VI|eYp*azq&d_j0Ue*yf4{oZI4%KzPrV*6H% zKm_bYvN((|9_yRQeIw;r|M+_Tj%HFlMu;17p;&6U9GWrpsJk=RTl{;c2um6a(j*w8 z3*dyHJ#JerX93$V_Ouystf~0Qg-M0U1(B#Tv=W2e2*~8eg(#>(XqAzzLq`5qHGm}2!s>CJYqXQm3Tc%BMSZhaHfVS c@a)AOTa|KIfTa?0j0j3vLP5Mz)F|+O08haIxc~qF diff --git a/store-for-business/images/msfb-autopilot-csv.png b/store-for-business/images/msfb-autopilot-csv.png new file mode 100644 index 0000000000000000000000000000000000000000..d150ae4f42a82258b9254d15076781837665a2f6 GIT binary patch literal 8466 zcma)idpy(c`~S!>l}bgCIYq_WAvuLj5%YEmrW+MjqE&QOE0Lg5erKGQH$~4mr757^=smvZU5K{Rq{mJi2u<7$x8uRQF zH|>6jC*IsGxc9f{1_a1owZVAQ{bINNEh*+D@_K)L@PGA2vzD(iWD1MjazdVc4Tdxy zwtltue{_By{f#r48JA{SN&xpID_LLYJ+1)e-b3!&l=wZsF6nYfEsu94wNNYxge(3U z5yaO3mUmZIz_y^uV6-ThLk%eUC5+JocRf4;^Wko0_J~fCL%mu8xtk+{fpfZQTCZ%> z$RQU6xAY~p17_PB8uV^04C^tJDdnZyGcdGTBUZv(J| zzh;&FL66xs*z1Zrr zXu_RcgFVNzM*gFy;5zWQ=xE*Szs`@7hX1LW>iMOYoZ-NPOP<)IYcWNgdZ+6y?v2oq zS9b=J949oDB8w$udyJOsR_+>N&UP6A0P9~dxnzLuU!YJ_MR?qX1yL0PiB`kGbY{9iO&M0(i=)C$#!Pf zAD&%-Id2WCgAmP7#qCch&UonrF2u1C!gbXju~Ftfugg*T3~^=q4m@+6d3o=Q{;=Ot6)_Cz-{-n z^lnEde{fh^nAgN389TF(R<>CJ6_=na509s0u(=H*b1iuW15KKv=b*+`h=ljAKvB!t zY#IXL3P*+io3OHhA50}8)j`|34Aw83Gf6hc_MOEUjGprwQH7?#9CkuWX~Ei~W0yBD+Cc~=pWdTBI>RBZtRfd9-Qg&)7lz@`S%zo+rJIpS?3w28)OpUuv)GjQ_>7KTAS8H^XgZnr5` z!Lw!GG+(%aT_``F-)#4)+q=<<8b^I7)$etk zL4Kq;T&g%e?`BHwd)M6P>HM)`4N`9*$Hc4Sk9X{g3x#&0smubD^I_%bQ}EVj()fWv z)CC__*0PuRP}2*w@6Q?4A!*^76c&Yo%ew{uq&~bv4Uha<^3+N2(Pvy*+&%#`my^!^ zG(BL0}8^K1>J-h;KarUL__9{eHM$X7&fik1PCXW48Yf zL;^~-|IInh3I9!7Dh2=M8RrH54{DUfI```p*$yQA=v#j2RM>qzpssx8MGeI((+H$JCt_xw%yZ=fbJk*h4;ysw>6016va|d-zCb5*9N20^`fXJq#}P zt@bWAeCBo~tMYLN%S(6CL;f*i%M3X$1qG|rzw$4hxT@7@1uSP1cH)1um_Dk&qL*as zQCoCeI_H?ZTc{er55J1??54O$Ia1i`GL2nzwX!3Ar#$=c$0XA;b89gPKDJYD?hn<#Lq4ugtKf4)J#pu}Vwaiibb|Q@FLk#x7v_|lQ6d+M14ldf) zqCVhOVe6;R2WC=|ZY%C}s7}yJF%M1`)hsf1`oz7acw48WQej>_ZBBcSTx(9C}R8GxH zt%Jzvep?UjKqwy&#dnm`8rvL+w4yxs2k9skO_KhKxz3s2&SbReWmZ7+g?-l;gsX|H zPVb2X?Sc*^1s^B%k6EdGN^@}43ew%N#;EWu9&AO}C&RAX-cna< zQB*ne+e7_GDYx;Q>Q8Ec|`G%f%i>O z-D!juRRwkUHcDE>N2!Voh1wz3j**8LKgBPpWh$CpcuXVIr|uRGa*%KAo0&Ae(;HTQ zN;=Aa12~zP-BI50+t;-vc4z$*+xFYbzX<-v{hve3_!ke6-xn1AE}rZJTJ!=K98`c?aR%;I#To!e;vQz}$r~76slE`WCDU846n@h}B;T#cy1_Kx_;EPDfy{$70_s7kV$Uevp~MiDyr5jb~=I zEPUsHXzT7w*xAgckHl{)#%uepC(-k9tY{1MN&&iAfYLH^nlH)fh578Bn)S`Aa{p&4Sf_NW!k~oX^^89DW?q7Rf$( zGm^6&MmKDt3zfSoaI8+R)>`=n(REY3U$)jzhLdl}+RB9kEvk7Y`cFIxAH$`9(;KQ{o%tGeEn%|B1PTRq6zl3>s#@0x9#`o{P1n&!6%4mr_|6NA~e#~|R z2W*X8sKnN>rY1tCZ=<-=R0J@XB*Q^PB@9ve+@eP+g-c50zGIaf_ohyLYlvA?)a% zcONZc0T{G+(Ils-u*BGpBcAGUC4QhdN;Vz*1hG%!Np65tjx^K~a1vb+v4ERB5D~|1 zxi`jo!)!LR>PA?|21;2`?y_fs-}`VqIG%9tcyEp>squXP@QJ}@Qt;uI_7S6NuBi)% zD91eVO^!v^daL3x%lu?S=W8i#4bcNSM8E1~qop26@qVw31$P7J(MVFTC%2!qA78F> ztAOIW25fXV;R1WUsmE~MxCweSu?--j;@H{YYj4qOZMMn_)%7S@_pwTna7lglQEg6k zc~iPS=w>|XI6YMQntYQ&K}zR(Y?ADovbUzm_&ubQcHOB`f+h^K#xi+HwEr+f7d1ML!;ynWhdqLJc5(bB znx<0d2Ac-$b-y_IO=ItT*FpZ~^Hy>|1oq%_mi05_We$sjX9Ri~_&)4G$m?y|`0nv} zc;X_=hsj__0J7BfC6!*=K~Cmx&RdBr_Ybx)^AUra)>wi9pNgCgx#MUQ1*E& z)EB`X_PoA6%sy%LJwb<|=FM>!JdvL2aqfNp6wEg1DfY|yz4aE8YZi#rXNM4W@hZa= z!zue42mCeE^oy6{#pt3cj7$6AJ{%{W3EVEmzM2K{FLN_1(5awaNgW_f;u{E1Y!`>R zOk)#ypBerf?rRxEFld}Z=+Oe0iI*y*iFdHJLm0(cV&lTV+nTYSR_}EuOHQ?RJZK(} zxP0@G`aD*!eouqMc@jMQ_VfdagtXg+mxqEf%X)9f?iH_4&=~4+d=D#l!#^QXwlLV& zw-L$uwV57Y&C!by$1hC;XST$)#qVJdGsy#i4B#^$#e75Za}0;eDGlHIZg>XJfUxh; z0cY$2!;O;GxAn39NdfC|e{$|K@N)lpVt3*~U)qc4gsRFvp{ZgPV)ag+V0eP+K}E1)AA9_sl@a8vC}8Cg9~5@(&SKy3`wk5(IQxJ| z^ZeP<_U%$oQX`Jj^C{#^^(X_{2N&{=-)s!vos~El8dxoh0P81sgdQm3)p0CzC=6PG zZ~>4JUP6$Bmh{~BBjl&_%Qflzusi(#nU|`_ins~lyc)khIftf;C&)6oO%dZF9Sn1P zob1!Wk!pMAzE!e3Ewp4cUYjvY-8~`MNj2DyRW;xaZ~}f&qbU`~BGzM$J|p+6o06~e zVxQBu|J?;#Jad#||ncvu7al>kSD`#0+UqZcM0)Rfq z^EWs@sVsop?s?0BU|T?%__Q?Ovg4NNr_Jt|+eWL2B`FZNTVVJ{u!YEp%J=yQv*SHqXUO@JZ0M~UV6!Uan4gm;$tP4`KBOt5=^t<|=kd>8$N4A`o9>!h@E`5j1ZZV*O6dnESvr8(J1r6jZG%b6$NtMEc*?vS&8$SGt+mjIb?f~ zpqD=fXzkjtbSOE(psqD*&g*QDR`Jv{&!F}4dckT#RRUbT9~$@Z9;+*FW5}&#;zsBoNK_|!e8;T+x(QN71ttS&^|JftE~zX~WbKn((t>rPmV2{43gy_pao^pR;|0-X zjjVO|YlxQD0x-$T?%9>L4hs4nv zmu7v$9Nt8K%R8MzHfGgmjUfvMis9pedQ)7%3-O!L!4fm+|&A{6lIU z*Yx<-DHRd#)TST4T@pmYOW!-%cg0)E=jvy*Tt?^yg_xZGYe6Vfb!2-(nC}BTPHRYM z=J^e#oyR_j)MKus4_Z!P-q*w#rrLkE#&izL;fTp#L%c4Li!-mp_;LLx$U@#R+g)ur zPFdLOoz-P2dHB3ehxynkRKcl*Az2E&e3_h9MJ&cYz3wm{h)y8j0~zCUf!PZZ(+QmH%2)zL#SVq9|*t#~d@TrNqMyR&$wa;zu%a?7KnOpG#wP(>xBxhv2=t_c5 zj}Ha$)8rUAU90)&HKkv^cE$!VY4oloA76Z%IO()>vX)%kN$K^6^jZ8B&gAE~laxIY zV{Uhck|*KUI1Eh!in=*+g2m~4%EHYhOWdq8F@Q(VU3+*Z$1Q!2b|Mxsr&a5}W}fbi zI}TP=)z=rz)C&S;FC)n_oO|eHgKt;j)?nDrWpq)h+7A)|b<7{+ywG7(7LeJ`vHsE# zv~gJ@Nhb4W`=f_YEUm}7Kk8C34SsoJnmt?|%TJ3UNslB+xW2WsD)`XeP=h>iI7e=r ztx*K^I_y&1!rySyptP~*4Wn^ZNyAK~LQ2~q+0$m%hsBFZnvM?TbQj?a_7*JtCSG0{(I8rWx&@90_ zsp+beoB6=*4rSI8)sh-wdi`!G=ud4{ zo8{0%#)pU9^^Z^@788T3WZ<>D>039)dKxQ^pC-fJocbg{g$_e)3qyKeYygKy14XZ{ z4zJB~c76iA6uP>~VjV12Ci{Qn_ynh;WJHU2 zZ$j%{ag!TEdp!w2vQ+TlFu4K`*iGSjL=!$>zIxPnt%kV~+WjsxeHI+KNfq*`ecxl{ z@9kPe@2CBNaZ3Slxk#mD3DLxk@i&B}NlW1aQsW}#_UF<+f90+jbI+>fK*c)4ZMJv5 zc14~sQw`ucsI6nw0SE31KP6AsJ{r-uW-?wR@#aP}_5H^O_nXy(b#>qJHZ$Pgx+b@9 z^^5=-h4L1jthv;rpy2$}y3)YatV)(VYH_LxILw3Lu`~Qgh|Jtx zs$c@+L@&9`8P2x%S2(<8PzkcFV!tVmMCC3=>8w(>#~DU<|L}x{K1p}JrkquiXNDTOuYNpyRh~dT-R1bd3Ck%f3-4>viC%XpB;N2<2;6ru(FdkjV)g! zwFY7w|ByR?|LE&;SbxVan5N^q_(kg6jej72$j`)%Gkns-lAQ(OK^$JsGBVc|$DDJ< z#ypw7#?8xAs|5d)t7UfJdN#Sr{9>(aW=@3z;&^PDUFeMYqm`h-5XZiV5O%ZvSY0`l zv@&kZ7TJ}MUI;qIK>p5m%*Xy7tmIXEJTk zKKoHbtm>}6q?YkB%h=ukI?jzEC2x3XYDO&&s@Iq{{V87@ofMA literal 0 HcmV?d00001 From 91dd1e1413ea095a9730001f2ebd9e8dcae66635 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 18 Sep 2017 23:58:04 +0000 Subject: [PATCH 29/30] Updated windows-firewall-with-advanced-security-design-guide.md --- .../windows-firewall-with-advanced-security-design-guide.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security-design-guide.md b/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security-design-guide.md index 47ca379543..2d55ec35a7 100644 --- a/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security-design-guide.md +++ b/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security-design-guide.md @@ -1,7 +1,6 @@ --- title: Windows Defender Firewall with Advanced Security Design Guide (Windows 10) -description: Windows Defender Firewall with Advanced Security -Design Guide +description: Windows Defender Firewall with Advanced Security Design Guide ms.assetid: 5c631389-f232-4b95-9e48-ec02b8677d51 ms.prod: w10 ms.mktglfcycl: deploy From b73a5d1e1ecfef69d702e82827d640ef0fc26ad2 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 19 Sep 2017 15:05:53 +0000 Subject: [PATCH 30/30] Merged PR 3268: Removed duplicate note --- windows/configuration/start-layout-xml-desktop.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/configuration/start-layout-xml-desktop.md b/windows/configuration/start-layout-xml-desktop.md index e203016bfa..6454a3fe7c 100644 --- a/windows/configuration/start-layout-xml-desktop.md +++ b/windows/configuration/start-layout-xml-desktop.md @@ -32,8 +32,7 @@ On Windows 10 for desktop editions, the customized Start works by: >[!NOTE] >Using the layout modification XML to configure Start is not supported with roaming user profiles. For more information, see [Deploy Roaming User Profiles](https://technet.microsoft.com/en-US/library/jj649079.aspx). ->[!NOTE] ->Using the layout modification XML to configure Start is not supported with roaming user profiles. For more information, see [Deploy Roaming User Profiles](https://technet.microsoft.com/library/jj649079.aspx). + ## LayoutModification XML