From 6186a92adaf5d90667a5a0c4d99808e9816d2a34 Mon Sep 17 00:00:00 2001 From: Ryan Hecht <78107732+RyanHechtMSFT@users.noreply.github.com> Date: Mon, 14 Feb 2022 12:02:26 -0500 Subject: [PATCH 1/5] Add additional Microsoft Edge endpoint --- ...erating-system-components-to-microsoft-services-using-MDM.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services-using-MDM.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services-using-MDM.md index be4a1f0663..f12658e2d0 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services-using-MDM.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services-using-MDM.md @@ -179,4 +179,4 @@ For Windows 10 and Windows 11, the following MDM policies are available in the [ |settings-win.data.microsoft.com| |msedge.api.cdp.microsoft.com| |\*.dl.delivery.mp.microsoft.com| - +|edge.microsoft.com| From 832a449ad83ca2e6fde4a4368b9ced6c7b4f2e1b Mon Sep 17 00:00:00 2001 From: Jordan Geurten Date: Tue, 15 Feb 2022 16:30:35 -0800 Subject: [PATCH 2/5] Updated the recommended driver blocklist with the latest vulnerable driver additions --- ...icrosoft-recommended-driver-block-rules.md | 399 +++++++++++++++--- 1 file changed, 331 insertions(+), 68 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md index cf94595896..e4cc6d0f33 100644 --- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md @@ -46,7 +46,7 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- ```xml - 10.0.22493.0 + 10.0.22530.0 {D2BDA982-CCF6-4344-AC5B-0B44427B6816} {2E07F7E4-194C-4D20-B7C9-6F44A6C5A234} @@ -64,6 +64,8 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + @@ -112,6 +114,14 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + + + + + @@ -145,7 +155,7 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - + @@ -157,10 +167,60 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -169,6 +229,10 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + @@ -328,66 +392,114 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + - - + + + + + + + + + + + + + + - + + + + + - + + + + + - + + + + - + - + + + + + + + + + + + + + + + @@ -407,33 +519,44 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + - - + + + - - + + + + + + + + + + + @@ -443,18 +566,27 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - + + - - - - - - + + + + + + + + + + + + + + @@ -466,6 +598,13 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + + + + @@ -479,8 +618,14 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + + + @@ -499,6 +644,42 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -526,42 +707,59 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - - - - - - - - + + + + - - + + + + + + + + + + + + + + + + + + + - + + + + + + + + + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - + @@ -610,6 +808,14 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + + + + + @@ -643,7 +849,7 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - + @@ -655,10 +861,60 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -667,6 +923,10 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + + @@ -831,6 +1091,9 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- + + + @@ -845,7 +1108,7 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - 10.0.22493.0 + 10.0.22530.0 From 4a2b22a6811ec7671d3a669d928aad27491a93cf Mon Sep 17 00:00:00 2001 From: Jordan Geurten Date: Tue, 15 Feb 2022 16:32:13 -0800 Subject: [PATCH 3/5] Removed the ALLOW ALL rules --- .../microsoft-recommended-driver-block-rules.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md index e4cc6d0f33..f486f73efc 100644 --- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules.md @@ -64,8 +64,6 @@ Microsoft recommends enabling [HVCI](/windows/security/threat-protection/device- - - From 57fa8b44c6489650a758f9b5726bf584255da9fb Mon Sep 17 00:00:00 2001 From: Ying Hua Date: Wed, 16 Feb 2022 13:40:34 +0800 Subject: [PATCH 4/5] update with existing .openpublishing.publish.config.json --- .openpublishing.publish.config.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.openpublishing.publish.config.json b/.openpublishing.publish.config.json index f9ebdac192..389a789ca5 100644 --- a/.openpublishing.publish.config.json +++ b/.openpublishing.publish.config.json @@ -405,13 +405,13 @@ { "path_to_root": "_themes.pdf", "url": "https://github.com/Microsoft/templates.docs.msft.pdf", - "branch": "master", + "branch": "main", "branch_mapping": {} }, { "path_to_root": "_themes", "url": "https://github.com/Microsoft/templates.docs.msft", - "branch": "master", + "branch": "main", "branch_mapping": {} } ], @@ -420,7 +420,7 @@ "Publish", "Pdf" ], - "master": [ + "main": [ "Publish", "Pdf" ] From 418df1ff4dd6626605b8e0f9bc9ab68a823fc22a Mon Sep 17 00:00:00 2001 From: Thomas Raya Date: Wed, 16 Feb 2022 14:18:54 -0800 Subject: [PATCH 5/5] Update .acrolinx-config.edn --- .acrolinx-config.edn | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.acrolinx-config.edn b/.acrolinx-config.edn index 64354d7a64..9f8eac523b 100644 --- a/.acrolinx-config.edn +++ b/.acrolinx-config.edn @@ -1,4 +1,4 @@ -{:allowed-branchname-matches ["master" "main"] +{:allowed-branchname-matches ["main"] :allowed-filename-matches ["windows/"] :targets