Merge remote-tracking branch 'refs/remotes/origin/master' into updating-windows10-change-history

This commit is contained in:
Maggie Evans
2016-08-02 10:56:58 -07:00
19 changed files with 67 additions and 43 deletions

View File

@ -1,8 +1,5 @@
# [Keep Windows 10 secure](index.md)
## [Block untrusted fonts in an enterprise](block-untrusted-fonts-in-enterprise.md)
## [Device Guard certification and compliance](device-guard-certification-and-compliance.md)
### [Get apps to run on Device Guard-protected devices](getting-apps-to-run-on-device-guard-protected-devices.md)
### [Create a Device Guard code integrity policy based on a reference device](creating-a-device-guard-policy-for-signed-apps.md)
## [Manage identity verification using Windows Hello for Business](manage-identity-verification-using-microsoft-passport.md)
### [Implement Windows Hello for Business in your organization](implement-microsoft-passport-in-your-organization.md)
### [Enable phone sign-in to PC or VPN](enable-phone-signin-to-pc-and-vpn.md)
@ -14,6 +11,16 @@
### [Windows Hello biometrics in the enterprise](windows-hello-in-enterprise.md)
## [Configure S/MIME for Windows 10 and Windows 10 Mobile](configure-s-mime.md)
## [Install digital certificates on Windows 10 Mobile](installing-digital-certificates-on-windows-10-mobile.md)
## [Device Guard deployment guide](device-guard-deployment-guide.md)
### [Introduction to Device Guard: virtualization-based security and code integrity policies](introduction-to-device-guard-virtualization-based-security-and-code-integrity-policies.md)
### [Requirements and deployment planning guidelines for Device Guard](requirements-and-deployment-planning-guidelines-for-device-guard.md)
### [Planning and getting started on the Device Guard deployment process](planning-and-getting-started-on-the-device-guard-deployment-process.md)
### [Deploy Device Guard: deploy code integrity policies](deploy-device-guard-deploy-code-integrity-policies.md)
#### [Optional: Create a code signing certificate for code integrity policies](optional-create-a-code-signing-certificate-for-code-integrity-policies.md)
#### [Deploy code integrity policies: policy rules and file rules](deploy-code-integrity-policies-policy-rules-and-file-rules.md)
#### [Deploy code integrity policies: steps](deploy-code-integrity-policies-steps.md)
#### [Deploy catalog files to support code integrity policies](deploy-catalog-files-to-support-code-integrity-policies.md)
### [Deploy Device Guard: enable virtualization-based security](deploy-device-guard-enable-virtualization-based-security.md)
## [Protect derived domain credentials with Credential Guard](credential-guard.md)
## [Protect Remote Desktop credentials with Remote Credential Guard](remote-credential-guard.md)
## [Protect your enterprise data using Windows Information Protection (WIP)](protect-enterprise-data-using-wip.md)
@ -832,7 +839,6 @@
###### [Verify That Network Traffic Is Authenticated](verify-that-network-traffic-is-authenticated.md)
## [Enterprise security guides](windows-10-enterprise-security-guides.md)
### [Control the health of Windows 10-based devices](protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md)
### [Device Guard deployment guide](device-guard-deployment-guide.md)
### [Microsoft Passport guide](microsoft-passport-guide.md)
### [Windows 10 Mobile security guide](windows-10-mobile-security-guide.md)
### [Windows 10 security overview](windows-10-security-guide.md)

View File

@ -17,17 +17,17 @@ This topic lists new and updated topics in the [Keep Windows 10 secure](index.md
The topics in this library have been updated for Windows 10, version 1607 (also known as the Anniversary Update). The following new topics have been added:
- [Enable phone sign-in to PC or VPN](enable-phone-signin-to-pc-and-vpn.md)
- [Remote Credential Guard](remote-credential-guard.md)
- [Protect Remote Desktop credentials with Remote Credential Guard](remote-credential-guard.md)
- [Windows Defender Offline in Windows 10](windows-defender-offline.md)
- [Use PowerShell cmdlets for Windows Defender](use-powershell-cmdlets-windows-defender-for-windows-10.md)
- [Use PowerShell cmdlets to configure and run Windows Defender](use-powershell-cmdlets-windows-defender-for-windows-10.md)
- [Enable the Block at First Sight feature in Windows 10](windows-defender-block-at-first-sight.md)
- [Configure enhanced notifications for Windows Defender in Windows 10](windows-defender-enhanced-notifications.md)
- [Run a Windows Defender scan from the command line](run-cmd-scan-windows-defender-for-windows-10.md)
- [Detect and block Potentially Unwanted Applications with Windows Defender](enable-pua-windows-defender-for-windows-10.md)
- [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md)
- [Configure endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md)
- [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md)
- [Configure SIEM tools to consume alerts](configure-siem-windows-defender-advanced-threat-protection.md)
- [Assign user access to the Windows Defender ATP portal](assign-portal-access-windows-defender-advanced-threat-protection.md)
- [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md)
- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md)
- [Configure security information and events management (SIEM) tools to consume alerts](configure-siem-windows-defender-advanced-threat-protection.md)
- [Windows Defender compatibility](defender-compatibility-windows-defender-advanced-threat-protection.md)
@ -37,8 +37,8 @@ The topics in this library have been updated for Windows 10, version 1607 (also
|----------------------|-------------|
|[Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](create-and-verify-an-efs-dra-certificate.md) |New |
|[Mandatory settings for Windows Information Protection (WIP)](mandatory-settings-for-wip.md) |New |
|[Create an enterprise data protection (EDP) policy using Microsoft Intune](create-edp-policy-using-intune.md) |New |
|[Create an enterprise data protection (EDP) policy using System Center Configuration Manager](create-edp-policy-using-sccm.md) |New |
|[Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune.md) |New |
|[Create a Windows Information Protection (WIP) policy using System Center Configuration Manager](create-wip-policy-using-sccm.md) |New |
|[Windows Defender Advanced Threat Protection](windows-defender-advanced-threat-protection.md) (multiple topics) | Updated |
|[Device Guard deployment guide](device-guard-deployment-guide.md) (multiple topics) | Updated |
@ -47,7 +47,7 @@ The topics in this library have been updated for Windows 10, version 1607 (also
|New or changed topic | Description |
|----------------------|-------------|
|[Create an enterprise data protection (EDP) policy using Microsoft Intune](create-edp-policy-using-intune.md) |Added an update about needing to reconfigure your enterprise data protection app rules after delivery of the June service update. |
|[Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune.md) |Added an update about needing to reconfigure your enterprise data protection app rules after delivery of the June service update. |
| [Windows Firewall with Advanced Security](windows-firewall-with-advanced-security.md) (multiple topics) | New |
| [Advanced security audit policy settings](advanced-security-audit-policy-settings.md) (mutiple topics) | New security monitoring reference topics |
| [Windows security baselines](windows-security-baselines.md) | New |

View File

@ -158,6 +158,7 @@ First, you must add the virtualization-based security features. You can do this
``` syntax
dism /image:<WIM file name> /Enable-Feature /FeatureName:Microsoft-Hyper-V-Hypervisor /all
```
> [!NOTE]
> You can also add these features to an online image by using either DISM or Configuration Manager.
@ -183,6 +184,7 @@ If you don't use Group Policy, you can enable Credential Guard by using the regi
- Add a new DWORD value named **LsaCfgFlags**. Set the value of this registry setting to 1 to enable Credential Guard with UEFI lock, set it to 2 to enable Credential Guard without lock, and set it to 0 to disable it.
4. Close Registry Editor.
> [!NOTE]
> You can also turn on Credential Guard by setting the registry entries in the [FirstLogonCommands](http://msdn.microsoft.com/library/windows/hardware/dn922797.aspx) unattend setting.
@ -348,6 +350,7 @@ On devices that are running Credential Guard, enroll the devices using the machi
``` syntax
CertReq -EnrollCredGuardCert MachineAuthentication
```
> [!NOTE]
> You must restart the device after enrolling the machine authentication certificate.
 
@ -364,6 +367,7 @@ By using an authentication policy, you can ensure that users only sign into devi
``` syntax
.\set-IssuancePolicyToGroupLink.ps1 IssuancePolicyName:”<name of issuance policy>” groupOU:”<Name of OU to create>” groupName:”<name of Universal security group to create>”
```
### Deploy the authentication policy
Before setting up the authentication policy, you should log any failed attempt to apply an authentication policy on the KDC. To do this in Event Viewer, navigate to **Applications and Services Logs\\Microsoft\\Windows\\Authentication, right-click AuthenticationPolicyFailures-DomainController**, and then click **Enable Log**.
@ -388,6 +392,7 @@ Now you can set up an authentication policy to use Credential Guard.
14. Click **OK** to create the authentication policy.
15. Close Active Directory Administrative Center.
> [!NOTE]
> When authentication policies in enforcement mode are deployed with Credential Guard, users will not be able to sign in using devices that do not have the machine authentication certificate provisioned. This applies to both local and remote sign in scenarios.
 

View File

@ -40,34 +40,43 @@ Learn about managing and updating Windows 10.
<td align="left"><p>[Windows Spotlight on the lock screen](windows-spotlight.md)</p></td>
<td align="left"><p>Windows Spotlight is an option for the lock screen background that displays different background images and occasionally offers suggestions on the lock screen.</p></td>
</tr>
<tr class="odd">
<tr class="even">
<td align="left"><p>[Manage Windows 10 Start layout options](windows-10-start-layout-options-and-policies.md)</p></td>
<td align="left"><p>Organizations might want to deploy a customized Start screen and menu to devices running Windows 10 Enterprise or Windows 10 Education. A standard Start layout can be useful on devices that are common to multiple users and devices that are locked down for specialized purposes.</p></td>
</tr>
<tr class="even">
<tr class="odd">
<td align="left"><p>[Lock down Windows 10](lock-down-windows-10.md)</p></td>
<td align="left"><p>Enterprises often need to manage how people use corporate devices. Windows 10 provides a number of features and methods to help you lock down specific parts of a Windows 10 device.</p></td>
</tr>
<tr class="odd">
<tr class="even">
<td align="left"><p>[Join Windows 10 Mobile to Azure Active Directory](join-windows-10-mobile-to-azure-active-directory.md)</p></td>
<td align="left"><p>Devices running Windows 10 Mobile can join Azure Active Directory (Azure AD) when the device is configured during the out-of-box experience (OOBE).</p></td>
</tr>
<tr class="even">
<tr class="odd">
<td align="left"><p>[Configure devices without MDM](configure-devices-without-mdm.md)</p></td>
<td align="left"><p>Create a runtime provisioning package to apply settings, profiles, and file assets to a device running Windows 10 Pro, Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile, or Windows 10 Mobile Enterprise.</p></td>
</tr>
<tr class="odd">
<tr class="even">
<td align="left"><p>[Windows 10 servicing options](introduction-to-windows-10-servicing.md)</p></td>
<td align="left"><p>This article describes the new servicing options available in Windows 10, Windows 10 Mobile, and Windows 10 IoT Core (IoT Core) and how they enable enterprises to keep their devices current with the latest feature upgrades. It also covers related topics, such as how enterprises can make better use of Windows Update, and what the new servicing options mean for support lifecycles.</p></td>
</tr>
<tr class="even">
<tr class="odd">
<td align="left"><p>[Application development for Windows as a service](application-development-for-windows-as-a-service.md)</p></td>
<td align="left"><p>In todays environment, where user expectations frequently are set by device-centric experiences, complete product cycles need to be measured in months, not years. Additionally, new releases must be made available on a continual basis, and must be deployable with minimal impact on users. Microsoft designed Windows 10 to meet these requirements by implementing a new approach to innovation, development, and delivery called [Windows as a service (WaaS)](introduction-to-windows-10-servicing.md). The key to enabling significantly shorter product cycles while maintaining high quality levels is an innovative community-centric approach to testing that Microsoft has implemented for Windows 10. The community, known as Windows Insiders, is comprised of millions of users around the world. When Windows Insiders opt in to the community, they test many builds over the course of a product cycle and provide feedback to Microsoft through an iterative methodology called flighting.</p></td>
</tr>
<tr class="even">
<td align="left"><p>[Application Virtualization for Windows (App-V)](appv-for-windows.md)</p></td>
<td align="left"><p>When you deploy Application Virtualization (App-V) in your orgnazation, you can deliver Win32 applications to users as virtual applications. Virtual applications are installed on centrally managed servers and delivered to users as a service in real time and on as as-needed basis. Users launch virtual applications from familiar access points, including the Windows Store, and interact with them as if they were installed locally.</p></td>
</tr>
<tr class="odd">
<td align="left"><p>[User Experience Virtualization for Windows (UE-V)](uev-for-windows.md)</p></td>
<td align="left"><p>When you deploy User Experience Virtualization (UE-V) in your organization, you can synchronize users' personalized application and operating system settings across all the devices they work from. UE-V allows you to capture user-customized application and Windows settings and store them on a centrally managed network file share. When users log on, their personalized settings are applied to their work session, regardless of which device or virtual desktop infrastructure (VDI) sessions they log on to.</p></td>
</tr>
<tr class="even">
<td align="left"><p>[Windows Store for Business](windows-store-for-business.md)</p></td>
<td align="left"><p>Welcome to the Windows Store for Business! You can use the Store for Business, to find, acquire, distribute, and manage apps for your organization.</p></td>
</tr><tr class="odd">
</tr>
<tr class="odd">
<td align="left"><p>[Change history for Manage and update Windows 10](change-history-for-manage-and-update-windows-10.md)</p></td>
<td align="left"><p>This topic lists new and updated topics in the Manage and update Windows 10 documentation for [Windows 10 and Windows 10 Mobile](../index.md).</p></td>
</tr>
@ -76,5 +85,6 @@ Learn about managing and updating Windows 10.
 
## Related topics
[Windows 10 and Windows 10 Mobile](../index.md)
 
 [Learn how Microsoft does IT at the IT Showcase](https://www.microsoft.com/itshowcase)
[Learn how Microsoft does IT at the IT Showcase](https://www.microsoft.com/itshowcase)

View File

@ -30,7 +30,8 @@ Since its inception, Windows 10 has included a number of user experience feature
* **Microsoft account notifications**. For users who have a connected Microsoft account, toast notifications about their account like parental control notifications or subscription expiration.
Windows 10 tips, tricks, and suggestions and Windows Store suggestions can be turned on or off by users. For example, users are able to select personal photos for the lock screen as opposed to the images provided by Microsoft, or turn off tips, tricks, or suggestions as they use Windows.
>[!TIP]
> On all Windows desktop editions, users can directly enable and disable Windows 10 tips, tricks, and suggestions and Windows Store suggestions. For example, users are able to select personal photos for the lock screen as opposed to the images provided by Microsoft, or turn off tips, tricks, or suggestions as they use Windows.
Windows 10, version 1607 (also known as the Anniversary Update), provides organizations the ability to centrally manage the type of content provided by these features through Group Policy or mobile device management (MDM). The following table describes how administrators can manage suggestions and tips in Windows 10 commercial and education editions.

View File

@ -20,7 +20,7 @@ If youre already using UE-V 2.x and youre planning to upgrade user devices
3. Enable the UE-V service on user devices.
4. Install the UE-V template generator.
4. Install the UE-V template generator if you want to synchronize application settings for custom applications.
> **Important**&nbsp;&nbsp;You can upgrade your existing UE-V installation to Windows 10, version 1607 from UE-V versions 2.1 or 2.0 only. If you are using a previous version of UE-V, youll need to upgrade from that version to UE-V 2.x before you upgrade to Windows 10, version 1607..
@ -30,17 +30,17 @@ Performing an in-place upgrade on user devices automatically installs the UE-V s
## Verify that UE-V settings were migrated correctly
After upgrading a user device to Windows 10, its important to verify that UE-V settings and template registrations were migrated correctly during the upgrade. You can verify UE-V settings using Windows Powershell or the devices registry.
After upgrading a user device to Windows 10, version 1607, its important to verify that UE-V settings and template registrations were migrated correctly during the upgrade. You can verify UE-V settings using Windows Powershell or the devices registry.
**To verify UE-V settings using Windows PowerShell**
1. Run PowerShell as Administrator and type **Get-UEVConfiguration** to view current configurations.
1. Run PowerShell as Administrator, type **Get-UEVConfiguration**, and press ENTER to view current configurations.
2. Check that the settings were successfully updated.
3. Type **Get-UEVTemplate** to check that your templates are still registered.
3. Type **Get-UEVTemplate** and press ENTER to check that your templates are still registered.
> **Note** Youll need to register the Notepad template again after you upgrade the device to Windows 10.
> **Note** Youll need to register the NotePad template again after you upgrade the device to Windows 10.
**To verify UE-V settings using the devices registry**
@ -54,7 +54,7 @@ After upgrading a user device to Windows 10, its important to verify that UE-
The UE-V service is the client-side component that captures user-personalized application and Windows settings and saves them in settings packages. Settings packages are built, locally stored, and copied to the settings storage location.
With Windows 10, version 1607 and later, the UE-V service is installed on user devices and no longer requires a separate download and installation. Enable the service to start using UE-V. You can enable the service with the Group Policy editor or with Windows PowerShell.
With Windows 10, version 1607 and later, the UE-V service replaces the UE-V Agent and no longer requires a separate download and installation. Enable the service on user devices to start using UE-V. You can enable the service with the Group Policy editor or with Windows PowerShell.
> **Important**&nbsp;&nbsp;The UE-V Agent used in prior releases of UE-V is replaced with the UE service. The UE-V service included with Windows 10, version 1607 and later releases, does not include the agent user interface and is configurable through cmdlets or registry settings only.
@ -70,11 +70,11 @@ With Windows 10, version 1607 and later, the UE-V service is installed on user d
**To enable the UE-V service with Windows PowerShell**
1. Run PowerShell as Administrator and enter **Enable-UEV**.
1. Run PowerShell as Administrator, type **Enable-UEV**, and press ENTER.
2. Restart the device.
3. Type **Get-UEVStatus** to verify that the service was successfully enabled.
3. Type **Get-UEVStatus** and press ENTER to verify that the service was successfully enabled.
## Install the UE-V template generator
@ -88,7 +88,7 @@ The UE-V template generator is included in the Windows Assessment and Deployment
![Selecting UE-V features in ADK](images/uev-adk-select-uev-feature.png)
3. To open the generator, select **Microsoft User Experience Virtualization Generator** from the **Start** menu.
3. To open the generator, open the **Start** menu and navigate to **Windows Kits** > **Microsoft User Experience Virtualization (UE-V) Template Generator**.
## Other resources for this feature

View File

@ -101,3 +101,5 @@ Add or vote on suggestions [here](http://uev.uservoice.com/forums/280428-microso
- [Prepare a UE-V Deployment](uev-prepare-for-deployment.md)
- [User Experience Virtualization (UE-V) Release Notes](uev-release-notes-1607.md) for Windows 10, version 1607
- [Upgrade to UE-V for Windows 10](uev-upgrade-uev-from-previous-releases.md)

View File

@ -16,7 +16,7 @@ This topic lists new and updated topics in the [Plan for Windows 10 deployment](
## RELEASE: Windows 10, version 1607
The topics in this library have been updated for Windows 10, version 1607 (also known as the Anniversary Update). The following new topics have been added:
The topics in this library have been updated for Windows 10, version 1607 (also known as the Anniversary Update).
## July 2016

View File

@ -7,7 +7,7 @@ ms.prod: w10
ms.mktglfcycl: explore
ms.sitesec: library
author: brianlic-msft
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in AppLocker?

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
ms.pagetype: security, mobile
author: brianlic-msft
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in BitLocker?

View File

@ -7,7 +7,7 @@ ms.prod: w10
ms.mktglfcycl: explore
ms.sitesec: library
author: brianlic-msft
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in Credential Guard?

View File

@ -7,7 +7,7 @@ ms.pagetype: devices, mobile
ms.mktglfcycl: explore
ms.sitesec: library
author: jdeckerMS
redirect_url: /whats-new/whats-new-windows-10-version-1507-and-1511
redirect_url: https://technet.microsoft.com/en-us/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# Enterprise management for Windows 10 devices

View File

@ -8,7 +8,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: security
author: jdeckerMS
redirect_url: /manage/lockdown-features-windows-10
redirect_url: https://technet.microsoft.com/en-us/itpro/windows/manage/lockdown-features-windows-10
---
# Lockdown features from Windows Embedded 8.1 Industry

View File

@ -8,7 +8,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
ms.pagetype: mobile, security
author: jdeckerMS
redirect_url: /whats-new/whats-new-windows-10-version-1607
redirect_url: https://technet.microsoft.com/en-us/itpro/windows/whats-new/whats-new-windows-10-version-1607
---
# Windows Hello overview

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
ms.pagetype: mobile
author: jdeckerMS
redirect_url: /deploy/provisioning-packages
redirect_url: https://technet.microsoft.com/en-us/itpro/windows/deploy/provisioning-packages
---
# Provisioning packages

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
author: brianlic-msft
ms.pagetype: security, mobile
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in security auditing?

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
ms.pagetype: security, mobile
author: brianlic-msft
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in Trusted Platform Module?

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: explore
ms.sitesec: library
ms.pagetype: security
author: brianlic-msft
redirect_url: whats-new-windows-10-version-1507-and-1511.md
redirect_url: https://technet.microsoft.com/itpro/windows/whats-new/whats-new-windows-10-version-1507-and-1511
---
# What's new in User Account Control?

View File

@ -7,7 +7,7 @@ ms.prod: w10
ms.mktglfcycl: explore
ms.sitesec: library
author: jdeckerMS
redirect_url: /manage/windows-spotlight
redirect_url: https://technet.microsoft.com/en-us/itpro/windows/manage/windows-spotlight
---
# Windows Spotlight on the lock screen