From dd3c5dcc7242c55f33beb9af12d9b33656385d49 Mon Sep 17 00:00:00 2001 From: Joyce Y <47188252+mypil@users.noreply.github.com> Date: Tue, 5 Nov 2019 21:00:23 +0800 Subject: [PATCH 001/209] Fixed priority localization metadata in line 9 Closes #5300 --- windows/deployment/update/windows-update-error-reference.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/update/windows-update-error-reference.md b/windows/deployment/update/windows-update-error-reference.md index 044398b870..b8d84e3075 100644 --- a/windows/deployment/update/windows-update-error-reference.md +++ b/windows/deployment/update/windows-update-error-reference.md @@ -6,7 +6,7 @@ ms.mktglfcycl: audience: itpro itproauthor: jaimeo author: jaimeo -ms.localizationprioauthor: jaimeo +ms.localizationpriority: medium ms.audience: itpro author: jaimeo ms.date: 09/18/2018 From 9b28cdeb7a980042f0f2f4eea9d7f59856c7af2a Mon Sep 17 00:00:00 2001 From: Jishnu Renugopal Date: Tue, 5 Nov 2019 16:57:57 -0800 Subject: [PATCH 002/209] changing remote cred guard GP picture --- .../images/remote-credential-guard-gp.png | Bin 33227 -> 185481 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/windows/security/identity-protection/images/remote-credential-guard-gp.png b/windows/security/identity-protection/images/remote-credential-guard-gp.png index a65253b04ec73992d7c4a814e41eabe695cd8bed..f7db3ee411c4310743b82bcd52db001daec252dc 100644 GIT binary patch literal 185481 zcmZ^}WmH^Evo?$bcMa}A!l1$3A;H~c7#s$7_krL9cR~md9D=*MyEC|JaC>t<&wb81 z-;eLdUeh&uSFNhv)w}w-x*}DSWHC@lP+?$TFh0vkslmX&>-@b)krDs?qoU4b^Y;hV zMNL)$red7z@UQUBQe06S2Bta=?HP#hS4MG^({+J?!FB!Tf?c4-T7PkK(MPgNAj)Qdp57b`ii-~;PqZ)3Y+m+ueI}HMtrsb z%y~Ws@{JQ@FnPV(f~U*0w!j=7Hxk`B4Bb?9fcq&oKc8%%<_McukZj$#ggH42C36h1 z==!&Es*==+(5C$QB_1*gW@t;Mnp}epKu%FnT22mG!JQ+CLPSD?cI5Kr;7KTLN&Fj;7OAfBYUlCgZncvWKq2r&yKhk*oqQ!X!wei2QGY4ML9$^c` z|2~Vig%c8Dh=uYW&A--As)rS!-g5u7M7^UhN%#I=)oEqMPMZIYFRBIx-N7uG@$|UWVQCtJavBQdh zT~4N6T$E8lq@POJOs#SMM#=haOS}uV0@4QJ(O1#ehioH+@nxikoq(DaYa4Jg>v>GJ zdEo2M>S?zd$>#KUXERq-Z8xKkY!=lDH6?9RdTgrm^4r&wY5$GMfQU}LNXgF}+8tI= zB<#XRR{X1?KjF9QNu09S6;xx^_NdxE8>{{VQ=&Ton`{UL;&IO?g%K49c@xty2Uam5 zb^=HPz2&jZaFH|;5sA<(qz2I4b`}1e)cp<-MQ32Go~o)|^fcbUl!`iR=}^R0B5r8- z``SWG6(Xog`lN# zGG$rgiGe+r54pxy|Gew?D3um>SGJT}mycP-o)1`*A}8MS!tI#GcXr3>fxEvmp)rWj ze;R=O*jUl%_+4eTfqiP|IKQZZD0pfq!ajK8r!J}Vm{x?-=T*Q?a@7pzb=pB)jQF5c z9+W01DPa70TO%IeQc)B~t!Qx6*qtQTw&YGrj=SX)gKtZ&Ny4#LoPpP#VMO^7>uq_V zJ>eTBgH_y>Xs_W&5S9+q+plaK$uO(HPk?elicOSqKY0wx!1GD!uit;Vhw5D?MjlxC z`H8EmtA!DDpSl0XYja*wC?dSXER7UmBQQP=x!su=AD7k)7v79Un5sE)yU59yqf$2^~E_`d^R*$S4z)p_jzbX|&H{He9i|!;$_n-8CpB;(E zP>-lERNBq~LhN7){94G$<^<6joysxKVZzj0h`o`qgdYOXa1uQP~JjtR^IpSD+URvOZ` z_L>Ri9gG{mBTh9&dbdt4nchz1%=ML@^eyR5g%oOvYA%KPqC~B=b6LDU$}^dp6$D>=AT`OW-*aKJfYc5SY$$r?XJwuQvF^|I-{ zcyiLp|CB!ek{Z2s`8RsnI7y$-%eOuWqtz*1|2|~kO9cdovZ62Y#cC4SYtJtb2hax2 zX~N90TnK6OlytaMU2uQ6k{~2xQ+8}yE;G;7TUg?H+!1lh9}qARaJbgl2iuSKE3(|| zjP@Yu#O7mh@s|0tIAkA%@4L7<6@~8bvsR6<32(w`$IXV zgP_Z9j>r{f<{6O!7^PriR{@7-rFKh0%&f7W@Gv2EM&W6z$$ zLnB$Vz7~ZFnXF`w!yRFYt0|jrKkY2K2DCixc&n#q3D0hnjK8k{3;Q~=Fpo^F^6dMG z@Vur4nzISfKYPwDJQGsB6_1l&ByoUw6-j)(qaTg$STeKW;(ub=F$IbYxz zY?14#hnmo5vddJbWOBaM4P=ez$d4r41%2agUD7jL{9PvLKX#tEF7hcKonhwwHsks% zky)8A)U}}WipK%IJpHy+*}x^;IWsrw7p8aJ7;BXuPF;EKe?D#*-L`v9vWPI)Juqz{zblyGUv7+xiyVvYz36*S81CKg8bC z#sYJ_t9HJ4+{-G4_OQSZm?v8mmxuOEhAw>~h#&*VNY)X$gK5cPFc{h9sXmpGlvr!> zB^pKcl$uojU=oZf0~R(D0U}37c1C=LZM4gOfA;2rtS{tr%#91k0{3JMA&zF2^?ay~ zY4mNz;eb9bGpEGWHhePxbTee8Kxg{yKrStLqug9&J>9Y}k?il{s{0c^ox_vuN=EBd zXxm{(h$N-x~QJ`5`S9_+wh6Kk{>6~0#TsZD7qebNqRpkt9OY#`FN4(&5}L3ww=yf=tdsedfWmU$P3e(!zxB`NC)rRdS}lhBS0H0_ zx(|ko;nO>z0b{I|gcl_3%&0~kwZ^0f+N4a+gP?W&ih zh=lmMlWiT)yFhG!o}htq`yACMZhE6lJb0;wmpUFw%JuUMF5oqMcKArN&B{mR!6WCr z2K%}tBis51%B`OI73`~%z0~cLyN2vp;PuNUUVYt>4Jr7pq(FTxh~2e#n}^b>Ls2{v zF`GSI4sIn1^Jyy6?^x%oMN4{taS6w3J5izYtEbu7PS|=>^sj_hSdTV!r!<`l?9DOFlPiz#ZjD*ux@|pV8UWvbO|cujW({G zoS9uGud`G3q%{7nyUp0V+qWkaR^#eI-TPhnDl~mPwB-B4)p1=nz#8nfEVJTwBoXJ< z88UqzyVBbH!lN5Tjax~peX@sxVn;Ybwv*j4$f0yG-yf?h0C>gj=`}ceEtu3igzJ>yDVoT!<5b4 zaH-hb-GkLw$tkV){m%6Haj*9C>PiWHBRdvKuNL{y(Xpy(skC1KiV_5m5JE&xYQm{+ zGCkMR70kjQD2LesFH-=UoJ=q{HWs8+>b5KOirwv4Z|)fs%={15i$~KNK>4OrmsQzC zFfbDEYxC>&@rBz2Pjv|v&U~*NCHhrDr=eZ=*y_8?b|sx?MK^Y9QYuc~Ze{!aw1la@ zpg6oTS2Q?85}SksHBxG8IPBTT(?Rokl6s+LF;a1DRWAL%V9|i>!Eor8~|D_eAKK>7W3dMG&@BK(={C_9u z*s(e&m{uHv-FM|p1fj!5~qG>xKJFQW4G(5t8BW#L~ zkovBUq~pLqzh#V+xap99I+089iM*!`K6IdM&Wd}xZ^v*_m&Ma;&rC=Nlz5z+vuMK2 zlV3rF7KRbHrYY2vNdha`PqT^_ACWOLo`P}3PLISqCEHv z4`uN9;PDv}j!XWV1W9NhJXjNU+?(Jx$TAAE@AFa>Brdcejzna5Put%Eli8$Pay&s| zR^JaQ$c~*K;_Ik|soDUToSPM2uzH6mLlaLf=+r@p?LW$_Vhn~+@>{F zf?gzj7SqBJog740}QfUU(Yx++VL_TwiH(5cHE^u>NNLh13JZjRtCG&x_4Mb!c`?dhyB@1#nr357Ex&W@@0BKg@~OLdM6aQBFoh=P2Qr* z{4SU$lH{!IV`c~o!Q$hzY%vKRtoXue^ay;W@u41~dz&ATwG*bo%7vwZ8Iz?7LR57QxdYfRt1o(8qP@9I@QrFKq{?usrAfHar)zjk#9(wOG`^-!o8&2JEmO|2?qyOo}SO`qVV5D`>hdlOgVh;d_cyR zn_rLh1CxWn=f0RPk`BOiDsH$@;=xrnqTB$wu3Yyu1}-Wuw(-Nk$1|-TpDiW0_JFIL ztI3Oz1Qz89+@4FX&DjE0AD5ok$b?hER~M6utdJY{8sGuzVv28eu$Y)HL?9XEu4q_^ zk7zZ&CH&-e))0y;jX^*%wT=$T+!F0gw$zx;2o)?Xx;|YjzLn!Qn9^&0Gsv0^&bVZ; zGQoY8ZeZUr*USE{Tt*EBZ_EvW_sF=mVQx!kmY-1P7iHyvDqs)eV6)r>#mLsymI#85 zukg`WBj3esU6)B`Jhdca=ihsLCE8<%d|&UoA9b! z4`~`(m=g|4WMf-~{%&-J@~&>fQY+bfd%~$rUD4^$hsE6r$myeOlV>`8P)B80(0Q~a zQgvYRZ$n!w&%J+mV!=2p5_|41AOxSs4Rynf%~P(JIa&^MubsxBRp{}RA)-f<1qX^z zdcK}@%`HtmkR^)IxY$-)Zvc_NzAGo6ra0;DeCHolKkVG~gfQ!|<`h^JAQ_cJsuYHOi>LaUHDTFXPN6WcD9im8UvvovgxW@799lgAfYQme$; zzFP)+5_=!Q%~#B2A|)lq#?ZtrsjVKgeQDiU))#T5+8F{asIP%TnjRzaen1Z`HCNGN zR?YUoKJK`O)!*8xVynQ6QRx&kz~I#vuHp3$s>}2MJ>~HI*iRNa|AZdzEz};Mevj6pgSzvYVfuD zNrb$tX(DWUfuzacGpv&!4{$q(W+&-Lb(u=qB!YMLBmc7BjaDI*{W)gYqxq*TTudq@ zhAyPa6MH>Vk4>sfgs04{Ux&b(&s-9gR32AnG0p0r`*6sKJuiH z=lm-*3F}{wIz9?!t=F%HKDRU#Rk%yZG4VgirIG{Q3E`jUSey@ZjoDuGr10Gu)z31) zhM@)(OI*IbZLVx!QWXxy;%U-z>0~2Qnsh=54%x#!#rqq8GhJE%_@ufo4(n}5J~|Yw zIT)`6I9pvL#9JTn`*&$AEeQce1J#Mi=2*<~Kw7l;)*hVcIbWviBYsSj$j_4xvEia< zKSn<|4K6m2Y=FmPlnRl}F|is;G?33d#nYNvTzX=%c?` zs@>PMtEVx<+XEX1 zwvUI!Ityx?fB2?GexILE#e5=@?p#p~ZM|Qgm&d&NQg%UJA%^nw{Ms+tVV%r4%Y@Cb zsEzzX`gHv1_G!-oaJ02*eonrFK`dB#>-w-{I-tFX6nhTAd;lLcojw%(zPoK*hPWNO z{|;bViBQyz2|r<3)Y`=o#X@*8Dmm-%(nC2EW77aX!5!CUJsTZAdd7oi{s!icXT9|8n8wo`^iRZyRp6D50r97j)aZI)l$rNGX#x_!` z+jli~<@+I5ebEW5!wNf6S>z@tW)Tf~Muk7xq2+i>6u-dX7E@1z&|ZFCY;hBf#eZMG zSPH9Ghb09xikPPCS}^tvlho}SWC57R063ma>ARUN5$gN*sY+*~1wzo>C&bf)mjYkd zz+&^4fE~VLCoaXf!KEBIA7)~`NVuF&JvhB^ty|fdRbKKmiJY<29ZBF0Cgkl3BFus6 z-1w}t==)J`4Vw>ENwTKT#VYTf8Vhc=%__vZ#xZm{X#cV*E}?8orX{F*ph6YQ2&vA& zd?FeqNu`e?mbPSxGqsLoRU{-@N+Z3%h>Pj(Jk?ibfqhrZ!wRxjIq&G`$z)_W(7whV z<&olIiW)Qdl3qDoK<4i6VqKF6-{+5-Nol%qf2^nL@gneF)ecYe&g(iu35&z(m*p~D%e@unWJ46m=Nz;}i*E)B`|Ah5 zq)RiXbjHfo{e-npr=$7qmv1WWv3%sW*kB_X8+KF`-~y*)Mwd5uf{?wyt`O_`p5D~z z#Sfxv1hjCg@*%Ca|J*H}pM$1a$P_lt3D*T|cbui8d7HGblVg-o{06VrK_rEN-gn?W zm4S)za45IY3~$>&A)!UQ(t+#YiG?b;W2MYUT3fxRZ0jg72A8-ckfbeu%`E~G4jPhM zotIu~AvPKQBC-0D<=)Pi-bUB|111VO!40;qj^Ts_Y)UI)pY9r291LFX1F_EALawUF z^w%HoOoJj>q0_(g@Jot7GQR~gI2Sg>id+UmhsOru>#O068e$}oS1P}^*(Suh5+T(n z41w&LOvb ziE9pZn340)R<}B28=K`efi;vL^tKx$o#!`Cfd*+P< zJYr|~x@5_mKQfU*I$J)4f>xDLQ*}E)S5jhYDPR>Fb?Qzb~_Gbb$msHk^t&2 z*buAbXnb|~PI#ck47T(QzCgMUAE2>KH=d7YL6eLQodcrxP+neg`z(G;WyN%wvYFc0 zZw8Adx9LF~sT)CW?M?{YOBTJ!nbkI6jzrYws*@(KGHBm)O~=4Mx-*>({Ds?z>gb{X zDkUI0X2i5rcYE867u=t!y;bE&PllJsMV~g-Sc2daV#VyNTSGufdaH3!`vmHZqZ zlNrVzw-)GSgh=&*xBBdgYBp2Rn|)^-eAqnZx#@;y?|Fb5O-YPC@zd05dfr5QSjg9{ z0k@v=Dzman&qI*D=Gn-*0|&N8c60bxwr6Ab`UzcrrXS?}&ato&yHYqc#Mb|nftB>T zj3bx~({4SmWxb?#yW^Qu-c%=J7QM6&wLAf9t*m=Jz#n!jZ-}UBhtS~H{N@FunvdQ2 zLw{^$q!%=X-Ae5Oc;X*z;Kk4%Vv%7bstC=eg0d1oJb&P%zKk0eyP>8nIwp;yLpX6w*oCvze}bi-bty~XRpFPb9YK>;r?NL%vBg*QH1TbO*Kg#kz?7#Zq-Y}8Ks z)|E&Ozvxr6nf{RA_^s)vqUfB=3EjU@2@=pCT!}bW3oh#)9oxRV^i$`sj3-alm94ro zw$1ZD%Wagxff!~!Cgvh$%$~ECXP$Fk4cImz+RhfM7IC{qX9e7I>mVQ?_%$O&@%}y} zDT{)4FuqQw{bvNhW^1Cji%=FG?%>-S%Z)m=ZzjBZF=u+cUEcOQZ@asE-pCoC4KVt8 z{NCuR^tHuyMavm(%H2i)<+q9lGDtKVb!86s4-3rhk?rqJVI3XJ3+orb!#=PSZx*~f z1C`wYgmJw;XiMZuOufb*yvy6}P~)7g z2GIe~HHV=~if~4pQ;&s77rODnHBSbK$*|%;+=3A#B7vG{eqjPRm!r4_f2r0&k{d)8 zsyLX`nP%(wlw>lxm+fsqTlRrpPUN1IqRo$E@8TuhgPc(45}xZ2VX}&<*zIZ~+mCEqU{IQ~bfc!Nv!|QOY0qKe1&G{H%{wB)TS%97GiU&LnlC4YWUnw94dB&V6)AMoIJTgESu@2T>jPIx0P6>6_f`v&{#E^pt$K1fq4mJ<*iVvA zNVH{+qP?XXT^l^w;E|iPAN7OTi4RM?@`mj{^wERx z&Bsn$$#-?#7#y?(*diaWMQAl0vD`x9;&>4u2%tZCFww*$kyD_4li?pu-JCxCW}|65 z1fT)M{xsDdY+?!+^$^7Vewn|F?;Ph)AKz$`H@fNjk;}_Hz=5LH`U0lqC?LA=4eZEyyfDicO4-OZjfw;YbJa5+s81Afh z8x}A6=hDcbXdVkTaPyvZif!cbIZvBA&87a`%N}RlU_9T=;)+1c68!oP&x0(cSUM^T zBnAZbT}OsZ_Z9X6>!93@9@@pi2Zoa4Y>Tt`k znUOm6^U{`HKBSqlfT!oDE&lLaMs8>>+R3wB$pl60fM2RqqeZJm_lzMb6Qwo-8J0hJ zzG0ej&9TT1&j}!H=#^rka^btkp1W`F)!T;UTOTuTDbCsPiSMW{J#f8kVtekr{QyDT zTX%?j<-m&VOeiIzcj3Z7Ljh)Pfyg{s2Zav6LR{(C{ed^0Na%CtI2LJXgL^Km7Ja(J zyOLF=q*D2!d%MeceJWEVE=P(puWLUcmlv4(4{g!M_N@eO?<>W<)Uh`BJz^nPK7xX^ zD_PnU@xNqDj#^_*+BD_Xb3?yIk0F1}hVl5@G^G{fH>|uj5Ip$dUO%^e;UD_(%Etzr z^QTuaU(D51! zlJ}aEXk62+3$TocO{0)s9WA-c>%8}Rpl+QB76n#U!kYCOT+8VJT1kax*254zIL&9Jz2Z13Ke8iBt7i=PaxB|=3zl$8iA<`R^lxSn7_2)`9_LZ-_h)?;+fbH)_VXxajok;l(Q~xZSrX*s>5Z^`6jw8aQ)B+2 z;)&HWDLz#d>DtY9Ns$9vbwr{XpAg+R`f=XV6}b(0EupzOT;-k)z(pbX802ZU*3;k? z&k|N#yBvnt(5*N|qG%7W_}UXR%4rp?1+58C0wi~TvOxUFZv!1v?AJ1y7jD5$O^jXr zLVon{L4}i7uI;;H6LrfNPey7qCwVlu;GKWD{-(+(wq|!iYV=Kuaz&=r5Agy{^nB{6 zwDOVOGfAYX%no;UVw5FmMkkC9wS&8kc*ObhWU_jz6ukq5R1gH8XC7@9p*Bes4;r*| z+1hwL6^3^<<-#l<1MZ9A**Cn=^|x@VT_`tRF?&D!q-pWz`iXH9mg+-UDSl9cd26x| z%OdwNLMo|46!FQ!zTf=^DkbFa>7PS@{SH+_@#~ICRlSnx-BvsYQNFXJYhS{=?(vpd z98Fyn;mNK#McmQe!A?@M07Nfi>{&qen*wHlEw@5gx?GHWXO5w)Q`saY6t_9n6+kp9 zFT0gMhEEj2Zr=N@cn)_l%kWKrDxpTE{TxPvT)scQ;N-ecTf*(@oWNcK zgoV_paS+Mbi?2V77fI)Id<~cOr0vDdNwH5(&=(tWb*#!v5{eTdE9o%PeMAtRcGm8q zgS|`;X%HEt?hsmYi;PxrQmi^Edjg}yed2>G67rNndER#d^@+(+zUQ};VG)c|$NE6S zk-!F7OpHNoJDn9p%_jUb+WZl}8cbmQnx{`>CGW&_dZD{)+%BoeD4Z4j{UbR^^Xspc zKz^ueRWsL7KJRq`Bl&>zA`rT8u4h*spgsQam9}OKJtQa@Qb%y(4UaD4BAT;Owzg-o z&oQ!M=kk5#4EG92U>6WP5KAtZ{gc9F&j8h<0G*}?S>P6yg}GdMIl+~XuSzC8fbkE& zo>O=9LahZf5Zg02!Q2(u{lzLXgPlq)^aY98g#Ep#iVn6!kEub^T`wxg593Shj<~?7 z8v3o)Um|qGkUk`LHPmB$T>4*llv;?-Oa+(jlN3J8gHW(@`3iBbjGs-TywNzUTd8@aT<;?V@w1P-Xx-^{K)uYApvxaBQonQ^i_66n z&+IiI8<9BT_SrwlA)NR)K&8eyLEfYMy9?RbKiHn6w((uJwDIS%jaaSCtM-}Al$>z1 zNVDB~9TWjRKm`A7w^Ook7!U3WlvHsJYs~NPwAiF`W0%NRGHH^K)ip)r4i}o>#fR@^ z`8j`Q-cWDfWsp1(^^+tp>TsC2b64b+CIj^E{ zc6ra!(Vz>NKz}1^8h>(H%PumULqkJnK02yuVIuQTLJ!VV=r--+nw`_kx1JnJBf<&# zJO#eiA4uW5Uwb67Fy<$nSwi^$#E5a^`OCBL!U-F6(d6#XJPAJE z)L~sf8SL6(4&?^TH^?1WdJitF(2re>n*OePKShlB2GL4Se<4QKyFl|dl3C_9U}h_F zs%#@#2uq8Ivd>`LT+H6)Tl0(2F(`n8AI)1dDlZH{@L}=cQTTqL;rQ}YnY7BO$Npql z8+P~LGZE1b(}3&6!)?8mfZ04w(0hOHE6PEN>UYprdy@dY0Ls>CFgTR;P`~wRYX5#G zV59bBEyVDN8Om>t*zHH4lD&0Dl37h*k&t--k{H24J)QYew&qA=d*(%Wc;pmc+fmdp zfH57~}!8b+O-gZwtdp%q8m3?C>@U)(#qwNEV4Aaig8*4-v^7b9v)Lt~h|CL!hQbi93Hm@S21?P~i9etJ<0~$UyMK7YE zbV$$qbY|JwN9diioL3w2z%;7lz{_THxsN+$m9yZ|rER%#QzBTKj!e`)7ImOvWt*BH zmU4rB!xHL?Gw!7S^jm2k`$=+8B(rs(v8m#oe`tc5)HcWI3uCgKVM)eISBeC+^*2i9 zsB%Nyq_N!e`ll7uk?JHy>Te^VE;_5*e?e!|1o}d%w{;18DSCTF%mpd?%3{-KTtob< zw7)a&t#H@ysyF;e3TVmu>|>}O&U7DnD@oyvET$j}ObF#3uoxzF0>IoXQC z3%1wglMBzwrEOy zX*l-6@=Hj-{-Q2+_iNxUKPpQGjns{7%aHW*6_HkV2NC*KFM|H)zi@T_U2PLG5~j3i z|E$4y_g(#n3dIJe)UUksVLbPjpyZ|TVS70_3Pt;C3H6*cU?nGE$AeR>^3Yh zq#86JCgg~&fWfUoJi;!}|Nb(vk3ACrP!@b{Jt5-n4R_$x+BPO3w>N{GuT?K&bP80C~N87S_6!?RgH+!Ej~N`N+{%A%F%r z48V;mJit(zRUv2w=YT1^vKZ41aUm*88m+A>)cKpJ#pu_-R&lg~NCZQ7_q|L_^qVa6EQ#aeXjC!G*Po``M>=3{e{kF zPCmMWNZN&k=6~DtP}^T$+0%Zo6Mcx6TS77mWSga?neC!fbi0Ws`p8Zd z&%HxBoUe8O&FAV;H@ApFIP}sYGZ9}HgoXF^DgZiLkf<6b1>F;DY%VnNotTfj8VpOJA8W{0^TvZ zM`EI?WbMySPPa;;=-LA>G1|Y|X+KjruB|@JtXmwfj8Oo{h^G^XaG)lEpAaABsrc}7 zx-Ufi6=PXFNO3>zvUkCy|0EmQpa=m;VXy9}$&Jkw^ZOI&cRU~n;^HNArkIu^V@|NY ztM2Fb`E<*mfx3X=gIG+pE%~xs$V64mO_d7v=(+VI&pCcPFkQDreB{v&x&RShho z2_{gv#hb7B?W(O;Fcw*b4X@TQ8p=P2r>2Y+{h?3J;%5JXr8|6VrP^hGeSFvUqr_(m zq4sBg&~+W~hG!N(E3oc2ew{z`!h%CxS=euX99tZTjK^Ow5#dZSTw+;eM9-UNk-$E_ zy0fP%wxhjke4LV7IldMc~2b z*sZ%x$^CD?t|2+eZ^Se*wZ(Fo#WF&^2lTEn1Rw*&3M+F|LbCL3L2$`uW`h88Le@@G z)s(d4a0COy`n8|^^iXgAw)K7`dnO;|jsXxn2?k+WHYXpTEK7!bL_X>#k2Mb@89_tq zfLlPP&zIhiSwR3VT7Wi-<`apIO3}>aajnjn+>S(CdFOC_;Y@x|^5;gLXycAPIQ7hs zml0X4KX*W&Rm5hWG;$T4^9^&r2F(K!PH0b&cUUKOE8{EwJ4tw zhwb6nV(>PAeI^5=%nng!4L%HNZfYxRGZMRPH4W@N7YIZrTus{HlGul0L_rX)KpoJ9 zP}C&ust$X1ZZyJ^3*J5;sXVhs;ZR!}hqnq|y-*g+&S^^?*+0aaTJh8KfmrHv}9+6rvasEl?r$>X<`yYfcDF?GA^wFO-Ib$U0u@J+O$i{ zC2)856tSg*0t0Xnx{C1yi(hJ)gsYk-dyUDoEBYO7m|&~$E`V=qL5>5!wmxFcOO#i~ z7djC(c4&6|Rkz9p)Rjz354=LFbu>(oVhvd|4VON{Ojtut2tx3)_!QcusfHjJcM>lU zBZ1ARV9_<5WRE*2ML3&$kdJ-`32w8Wt)eOu$BL4Gi|WFRTmTV##X5bk8g*F2TxJ47x_b#OuClUc)z!^iC^5c?p@C=Mha9f!*#${%Zf=?nyV$5` z%!{B;f&}3Bn$966=kC18u4Qa2tRyiSw*jafTB7r8#Dp5q@+)qOy3`(Qy z3S6!EIDcQ)X;UGk_lrytt`&Pd3;OwHXz|*XhUdho=R1MuX6c;hCWLamhXtO_>d}J0 zUAqS6TmwTf1TnmuR%h3b&EEUa#kb+n$M^Z}y`vwxfWh03;LHiS)jxecItPBpvTqG! z6RlSs&%SBgs}FVot$>!=YHknqGn1!34(-NlGCk^=vALf#hytEag*=jx?0uf4h2FYn zJkKKqtK$n_$`zMw8)6`oBftCrKY*|@G_RSwBn_gsSkD(5sTUVp(8XGR%3+;?h2e%4 z7BnBVo(ufa5C<>vRX!rgU2i)!XLF~VtBcE^VT+K)pNKMraNp|}(rd(q?QNvIFwh#G zY1v)7@kg^baMVpTtg42gd(b!-4}{haS`kUk2S;4kUSTv;G^kS?P-IfK$D!O*^8 zX3Ja#W;BBv3RNO*Z&Ztzm|ihsAr`MHO4!EHUwMdqTW?-V<+{JQxI^Tv-C(!cl zB20jts2zZ4dJ2*lk7z8ZpT4Q`;c3CBbDO(=NPWxCbEJIguCSoY`(~M2uYl%ozyXY) z*hbVeb#|rwiD4@i5vO%fbEEM&Az2eSyW$ka@NdKEj%h!`D1R`w!#c!Vd%SP8G`HLE zEq*(4U>{`jTNLecBNZdT0<`%7ihOCwBI-w*p+wfbzUHu%Q%bmX)pX+5AQDrwzJe<2 z#qtZH-1)m__hJOl=Om9;=GMfA?auvOQWAUZ(wkKgV;B)qVBaM)ie(0yFv%I)eR0@D zR6Q9Df5=^xW1|F~r%LhiHeG$xzUXO|IvG5^k|ARCg%3*eJ(u;oUYYasSTZBZZNW6A zES9zAV3r@Zc>aAvygGV&sMcR~%57^U1k!zXcatUhb7S3Tdz%=ecG1SR5y4YKVCD}!ggIDS_cKq9M$BGy@A%fz4! zh*8ph#31CFKZaVEBivp?g6k|#&%}{YF~okvA!rW7QMaTdCm@)wqvEVuSz#SAY~e8| zHBz|8d03PFLBy}d^F2=4xVTxM+F}d2P5d7@Sg{5f`0lUi96lYdhWLcY~!uZTn}05Tz2W-UrjAV{Go`e{uV2?mk_p- z#JO|&O4$mL72hqCDdMNoq0QtCFaJ`=+_*)DEl;P?2v4a0^wT!gOhiS-D3amz1?MbM zB(`jB0t($<@5~_UT-@y>;4rhdY4ni+-G}lwx-UuDO|Z#mh7iUU9};=rG2bVh;~9%Q zQMP+NakRQ$>)a!s3mKvknhjCyzE`_kp&v9;(R<+jEaqqU!Bv1TqP`qH5*@b$-LEZX zyGiz4Le>PCEu@8>lv{}j0Jc@_9T%NoR7ewoPaV&U;&<6I8DI5k^u0w!N4^SgQNu)t z8YFvuWYJ`NHkXkrdp1fRa~n|Z+Y8H<1vpk$Z~k(DFvtVNQ`*OSmlJU#gl3Cty=ejw zKA}zoMUZizT(e~_w4QohJ1w156X6iN^9UnT%ORe~trI7AZ;9_q z)NwvJ)AuW9MGk!{0xlLaowU_n4vt#8z7YI9#G=`ZF?2wWAdcer_S5ueHZmfc2+{xe zr#-}pc{MMI5l0mi{x%s&#L^na@~xkiM<6f^H;0Im8&wU9)_GdD^V|Ed%O1GRk|P?~ zWRmp^Z%;FF$&?fXz1IAp^JLA*(60(i;pl&YXIIdS>XNIp=JJ<2m-EY{%UPJE(w7)V z#gI7A3^b^T#)sK0{^%%>ZD9p?;qjOy)nQGJVpOH})0WIe%Rmu3pXcE}7Q=sFEVT_x zHtqo>(=1Yj><^Zt@h#OEZ-<+Xno!o?E>YiILX5wWuQw4ef+oUn7j_Er8gU_|_usC` z(7ylRoGo5K(|b<(tnFm|y;%&p%& zv=E~LkY6n*NR}nHwM+uUUl!>^-7x@?+Zuj~P=x5~FB&?wOaR2Wqp}gM*;+I8+3Is% ze_5`X?8_KLPK!7tL<0*C*@x#bywaP2Kr_y+DTnWDo}QkhlV`u<5)(7CsjI7hQg(N5 z;-a^fm4)vIgSow(nHVs31Rn3nPwsw;ogQGOY*XXjsLSG!C|9Sn6$9W-3&PC=i0#u2 z%syHttd^ng`1$shRmmF5F|*k5+NOGghgD#k4I)z;G7x9Q|kdwm8oypiVL`0%*CEMrdA!d3G8P#+`tI2Y@$wZmxc1>y`v zjI#8PC)8@^A)6YJi_n3uGM-ra#j?|i(K{=18-Qx;VK&!mlpm?0knm+T9VP8m9+PO| zFaIk+GgyvZO(#rZFO-qR zXg0>wkx}u$i&alc^L>)4C~U)aW)qxJDlg2K*yVfYCiB4cl)b3fRKRV!l$o?D+w6z6F8hc>yk|c166t$>_ z`6gf@=E90^rXYj%i{>hWM~7?_EY*?GjBfah0q^MGpj@_`njLr7`M&jaTk7uwwQIXC zrJ0Z(Tmy<6(l=@naTpl3Ueq7>W(UR9->8Cu@cJDoq9iG(MglgD_Y*dYeY_8kpUt+N zdQj7dj>S@wmXh_ex%Cj*qDYS-s<=Rs#r{jjdV;bT0@Tt!k_)FL2f|?;r`$Ww?xGet zQ&c1Ik&ZWBWkdG;>TRhC&n79mDfAUpmJ>N8o-voNj%2iL*=F{r;$zYKl3_fvv4W!f z3LalbJob+@7{(dg>xteU0nu$mCe&+#!74D5pOdyPP6LMoBpiD8%J4>hbz(mInz59~ z(Bdpsv5|(G(7E+0P7v*2234U{>paFc-zU*{!9XbWZsQ61W*}#h)qp~5VONv`FL_!W$rsH0WGo$Bjcgc;_ zOF`-(FUC>P(EM-e7248{JG2qJf;ew(TBT;pLMB!d$37a^+Wjp0{;v2tsaa-2(JNDo z(y-Y=RVH~%tWd4x;E&(-4)a$!@v)cllN-LMXlf=d-O2MVTCvsJNab=JQ-ZIOrfF=y zrWd!QAV8PQcf&<-KX@8DJ$V0J8a;9b+n=O*l7`H$bEoFHV^*j##)?uy9Khi}8(?P| zsFoQr`;AAVu85b*VyJEQv$Z)xr`2?ZFyoxdBhZEF%*Fin0-U19$NSN-!zn+Uzbnv;5@ju z;vpjVH+sIH+; zIHZwaw12gvAN+-ZliPk{Y*o~N^TtarK^pGs1_>#H=DARhK4g%j6&27Fy_^x@q>RZo z-gB{b@#ui>%WV*4F}ebcEkd~=)eX^lU5W%B_X5n8zY^=iEltg3vV>osIeb=4>z%k# z-J-VPMqsssYKM)G{N=?eX2a#-3f;p~@+G&PtxK3z6H!=C`{7#-3KDnP+)B+833TWb zBqz)itCfqsH*5@fu#@%ZDD8xhhP52jf|i)4Q7NOJ;h}+)i+UDp4Qo6O}4=-kxtBQ%wZOqa<#x;ReI; zM2di6!3+iqsKO+qj*%aM@Cuc))$f*u<%tufQ&!tyB+jP_FkI( zlE|6qdRI5NZ|>Xwqtc`mPj)pP@p4PO? zzv0UoB86l$UwUY4CE$l$e(Z9Z*n}2Ox>4;NZTs z-ZP$=#{Ns)>g>O2hoP}eMTwFZhyI#jB?DSyV#zT^y0M$G7{7|aI6MIiCj|sBYjk@c zDX*#K7jeG^U<0}^-&TJTYTXg@X47-O!|E$SmI(J1R`=>8@qNM#>Y`K&_Bg|FcSv2D_G~50DE6!&+6P+hX zGCUHg&$K*P*2#ie?-@aNXG>1(x6~1;ex!gFJ71dRJBe-(>>xdxITd>~($bLwo}AZ}A3uiH)zv{(Hl4q?hH$=Z zBu+?3AQE)mU}mh{IGmrGlV$^;5%#B{Q5Nomu2<#;F+xUFMk10d9xI^cs$HTMC-%nkoo7F5KHm-jWZ0=`o88B zaamZ?0P6Qf_Jyb3&Kc*E8vX&YajyBSDZj@H|Ao?HB~>?nedyW_LkcbQC;JYcCXUzB zMHy*W*iJs4sUp{ONWk&-&V2x#6w!3v?a#|ePtn`($|if|WMpR2u(M-CL_|QvKM{+- z$lP2~X&D)A_aAEJD43X@U17+zJn!ASxR>_TO#-beTrPm>285>F@Z+6z42A?PG_qLy`FHjan(5*^V4y{Db zQ|5&9*&*!QZ8IsZg>gQ$0oX+JxYHagVQRa?5R3EA$0Ju%5^l#OhMFw{s3#2*0uFUH z9t#`7sY8pmvo?kh%%d?7T7VgwIxPt>{-phwg}JuTRKGXF6apX)LB90sWld0}7K{0a zsc96l(!;}pN!!!iq4BFOa2V*r2Zpi_A85qHjFCTzii%GkD>LoD9z02&{XulhzO#ZdFrmuq=$-2p+u(?g#qB z$vmrx#T}JK=vH}`F3T%Nl!rgc5;I8L&{5nRHhNzz?zY~4B!;M(COy*o@@A6*2N`V1 z8MJ(+dec-N2~^i`;4_-h{WOoFyElnNALoZ%6kZE;CftsE+9JNVXvCL8R+xy-h0H5B z^^rG{)O)Hh0M&KPH@j3fzl!W{^9(v#r7snK8j*I@5N;uxqxRl={n}=H0>zV;7vI8A zntOr`>H$3z1pLHd>+k@4y#7!mT^hk_!60wyD&kmBJ2YchIPfSi4KBAV-8dx(PoWJf zPK}k4Q228M~h0hL-QQ+;abaJ^)bwmNHlao_C37-;j zllPZ$H73ZiQx8g)zA={EOlhqd)?BwQspHKwCK=OQGm7Jlm}f)%?rmYcwFe7oE}rV> zyU+c0UwXfQ*?q}$XeSbCVEiGBozELQqMh!{nGL%j!nOYCoVP^x%*dYaKNi1w1_V7{ zbOA}9hZrS}hl*?1Z=O&-d)$KQb=&(`ZK)FTD}#py z;LDkA0L92lacU-DwNAVf5*lq%5E}u>$xponStiK z1fVjK%C&#jd+$J*>x+t~)I|Cp8iOl0j;@wgJH-`d&)&z@R-%)W6KTl6^YLgf44m`D zq<~DtcNB1pcaqNM*DAe9s+PyyK)TG1Z*Md;U2t)qonW3g)x)+NKjeKUUk;yqzE(B5 z$c90i0}d_iSQYC!&i0rLm7PykdS#n?e)3~@{}DB%dpoFJycL$xDUg7Z(=b%IVkKnQ z(*bPh=8to7V2~0l$Cd1ZM17TIrKQWefvy_X=roa$eg43*+4;_Rt~+X)G6x2r@s*9| zj~PHn%#G!H7i#J@$oQE^%(savN6yLH*Vp2FXH?qEb87%a*G|EXX_aAnI%yqI!JHWN z`^DD{-(B}bZ>-Eu9mRnWBPuhcEFvUHPuGA63fxGT?rw;+vbQ_$kZC{32r7bAZS!%3mM-s%ZZvs{nUbL1$5b(7pe1Mg>eO2up?JNv*CryLRaCKjhh5P2KL%?)i?CvG=NmEaa6Vyxr# z;q3A(w9dfAw~wHZm)4qf?e3lf-|m*`FJ{L#)4O}&Pqm7*Jx_PKdy~2QzP@&bEkK+| z*z@4g;o;#7UpxQMxPbv#bDnrxKyQ;xWbFsk2oxbm$L5>LIM4p0CaHab2qIH)Ks9Vt zwGuTdmi&(iWOyNcOT(;$Rf(Fx7HF!Qmg65qv;D$*<*j6p6JPi8`-IYR%yc_4Y}Qq5 z{Dr-}Chb=XIkkg0e()!E-(}%JWtoVe>@u5L#RV${9lV_8N9M(%bMaq&omgmZ1P@o5O zIl8(LbzVweU(H~f5YyC+|LT}CY6#x@?9sL=EP(x;hN6*m)m#PDrnB%C*1WX%!sQwt zyGKUi03DqFqUY=?@H0yfK58k#H)c2P*BFXH(=XKM%%4X$cgv$pG~>=6Uekdt_RNe# zSxsTyH*8kCoHMkTaRP%&r)>NC zmXsb3Kl~;zcQ4XHtE^7$tjL;(^n-kG8(?k>2z;#~vsNrPFg#4%n3_M0%8Bk=ZC^+! zGW}`jY8mo&xqjYi`~Fc|(8M}oVKh|X{Z8obR%QtV_M9B^1v$>cm!0M^7Vib4j#{Ulw^e7b1Lqb^!i z`IW?kAuvZiS=`}mhzLk&$*loco+oygwOd>K=KGPdWRoA|^9RuzTd?n+F2(GzDSNNV z!lIWu@Q}QoV^7mq)R(Lxy1Qlc&z04_sU<|Fk{#U(!pP}}yv`J!v8teY2WEI^dYOoz z0TihLbvtb90B@`b8}!5zKcFA2r3_t_qxzcgGcMeg5k@sj?tED48jcmCh!B4Rm zc6#iH$bP30J@mKZp`?-0h56C6F%OsMJMV(CC5$6n0yVr9#Wuvah~S1J8+wNbME$}o z%$$*jB7Gq?ut{oAX#=`+B@)(77q+-H_Jf{T%?_s$J{vQvCZbQHS(6Wms|kNybPmxD zdszQVR9c(Yy){16U&=sKg$TM2WUr<;24Z~Iw&$oN+}9%e!IUsxv!o1Mv2zxWL_gWU zu>bA-e5<>$R(jB26z}j+S5M(WyIZ6o;kHY^ko5PjI}N+sNmI3eawhd!fH~NP;>3h^cgT5(O87kOGM{^D!` zl-=qNkGTI3iRAcZ;MeEE{v#h+?xjW)L={x=ww;%Xrrv;;oRkqGz5qr4M*Mpl`t2!{ z?r7Wmks|%$MBOt@ePpH3+P+-0T)&q~F7-;B_r%j;>F|rK`q>u?7}@*NGEMIOUKdJQ za&N$26gY>C24Vb(I>-(I5($S+M$r{RB1Nxm0WY69k?Xqr={YPhtnnLqKN{=D>VL!W zZ{)>mOr-?FkDCA=oNzrEm0bpZD?nKjY4%0@>uD$?c5k*h3&oP`&sf(Ul8E6L;|KW! zlH{m3O$Y0|4@xte`XFBh(5#s|_bK(9FGW|d9fDiTUQ&3khLcjX!*A>Bi{{4abJZiF zY3yxQM>I1nx}y8FFP{+p2E1g-=i`-;x>Nq47v-V(wqxl81avu9;X2hp)>xnNrfIot zzfdt{OiF}7ch+ebeSuIw`{BD&2!@O3-64D6B;d4b>m~YmZHs1H-%Pc<#mXnU&SyiC zUmy5a1E7jSjAq5|6Zv>D;!tyGoACcq^@&|J`FF#>ec4E+u5N%v1433YwK8e^=75!N z08{rcIJqGo^?ep7Wa9WdirMxm?~kqsr@GD4yNfe+eJb7r`X!G1~} z+DtJ-@k^`#UL+yWqL@EQz|AY1$?9Kk-1GsjZ9IlqBj>eWVWwhr$0<0O#tVT!(fR+Q zfK12V)awCe{juMY-LOupw#0P(WsSYP1rf0**y0Da`-loRAAs0}c7Wc*8#Rfw<-v|Q z-#8?_hi-in6O(?r7ZnU4bnftxL-5;?M_KhJwwm`<6Xc$H8IH+H^vTUvwIfAlphCDe zddL3WI@1GzA;`?%!9h;^4GR}7U?jscP#znTdqWY#iZcU8zkWleXU8JO>kkQfcYnO#d4Zx9WB*N~MYS|ML z6DC-!JA`@VWo5{kEf;<^m$5uA0?ono-alWIFrylRz4 z;{s(@|D$s9x;75@Qnf44UbO)h&363hLGgOms~Gk?WfKf;JSfjS?TEDq3NjF^d}Dk7(ih`{~dU_tu`Sz--{|D~1utC~k6C^#g zUN9#tc+Ui@4v#IHhgZ5aEOP=wqmIeQaYX*Nl!$<#Z6VB9q=l-A3Rk_R1o57gDrIbQ zSLB8EaH`7>TO8Dn9>*1(I&#!@(#Y~ETqQfb;zu?<$9N2yin9LF!aS-oU?ML3@3I-r zJM@;1Cws>OgAN0mG?XK|n?!_b5-^!8{$%o%E7-;^WgZ{;TW3lY*=yv8PusR(GHnDS znX1j1lmjXd~jGadv#QHs<3bX0vn|$u9W(&$~|pM(R3#Mw_zE^8fg$ z8h}}UlRY>xqPThX8$WP>c`Iiv3WZ;N-I9U*q{E7i7=|6~u+pmTZ94qpj1I)brc$i) znK*WMreEwEIR+039h(X{H`a6)H!8iK#85RB$KbbeEc09C>J9HZ?t!5O zs<=Th3X?t}QFn?|as5P_=QDPl6HeLTdkiF%R&w2yCo&V_l;9vyD0bL*?82A$`G$tr zF^(fD=*MpBDJKXSe{i!@;nx1Te%E0~B|j$HevfJ{SM{7aqNA?E*+b_doihKsEG}`` z36RpjCd}%dIt}d*`PCXI+xJ%THCaY{yu( zB?bq-F#o_ExL#9hL%O}}*#~Id^Ze|w8Rc-qAe1c%<4yIMmCz1CbdUr& z0<-7qyIb+s7S<{C^PhCks^j)dWQYqd2l`;SbSjk0*V|dpzRMYpYOOh260pOd#V?u>k8-2lFB*`VDVFK$tBw_j_gTgyTf1~!M5cV~K z>Hmr7(qCc*(Na#2*lej?mmU_-6-)rjbC?ON#g zN%-)y9bk8Qg=^bMi_>U^%Mk;K2>m3-r#Qv;fRwojjzS}h`vd8JP`}w#>MX60I9pae zBidU4Sw_dkx|UzX*9FOcqFJll>eB=Q*#Mj-@wraj#Gls#MI1ZNCkN{({bHw!cP))|FGu@#_DZ1?ck1C*$8l z#JO~x_J4IGu&6HZ{Re(15iR5YU%W&?2A+j~a|Wy7!2g9Ils)-(`+{gW3n)k7ulJC? z3;SQe7Ds2QG);3vylM~MtqYQ2rl+Tyt#=13w0p4fJFY~t8@5o1i&H@H#a|BG)mSnh zkfOs*8&!Do`+>+Heh$WsK!pL?kPoIJjZ9V09FPq1tIuu!LZhCd>15+Xi{A6T!__nC@8Ra=hMb*+^qEP@$sv5Ku8!Cj{gJ9vUTd_}01d4{ zRbb{;I|QYbtwe*ss+y`OIRbQ5gu(=H^Urr*i;HE$-s7oA)|0S_xKGuh?7o}*l1m=^ znRKUiX01_DR}(`;4#S;=vQ^m|{?Ioj84dsP4?c3o$l2uD?5y9$$_iObx45|2dnZMK z%V|v%9!X%mJ{w6JHwGR`?;gYuSP5Qs?7%>cfbDs_%EbnHtj3iq825?S1URCcwEHn< zayXb!1RXfkj3Z6h80khR-a4WM`UavkEH+Lp>My27uungSvsY^_E>)END;$(b>oNBi z#?tlcfm^V)fdR`ej<${tv_8CNftN4w3Inc)Df}T)E53)HynlUFI2-5eL6(6>LMIA_ zZV&xdin!+`V_n_-u_{{5%1*+KGbc}IM1&_bEe-UPo8+=i)SLe{mGQ5IoQHHrW>#KN zftF?%Pa#GEP1gLFyt`UJy<^uXSXz1;jrAmzs6WdqkCLd z`xS)}$#=*k)RC9LKTHoRQuFCkcozoNNjgd}H9Ov0UFc@SbUE-*p~XkU zbD*4-d-TQnS86rZvgE&6YOQ0qx;Ap!fz0^wXl0sv7TF}p-}v-)U=`;7SumzygK*4G z@_~~XgBCcU4C19`x;NN;r3y)?33c`LT;|zDP+V-+5>8#RFFwU9Sq)J%y{*)gJcD4R zmuLlf^nwk(#3Mm>jVF;Ld2_BWABvCVTPitZeT~3rO4yw`_ zeTb}a886t;?_lZ31jEJru0b9xX5b-}g?eTRwyDsrV?IqNl#@m3jRDCwEDBkg^|dwc zvLof*s}f(^rrFBTH&WjsRc_wdkX;?y)KMzQEya+eyMOlkYfU7hnH0jYm40Ph=yEtef3RDW4rHv&$dz43h%yv&#P(1EI$!)UAmX2*9J3(kIY@*^G#MjK;cf1mNcchg|hgNtvM z3348k6&$V)+tD8dcYavuO*Q0Kcf)7cS^deLoUu(Wj#45BJ}&e{gxc6`tLx8Qy>2=Z zHd?a@{0UAz+L9)i<_GI)7{zCFtaTp(3(I}8ug6JSt6`%f%%Fa&J=XX>2;>kleLp10 zZnQuUmeR;*d48$R#8wxXp8?8PM7IC`^o0h@W=udER<{;=W>-7vtpT!bfWQBjxTJ*> z-!F##m6SbGA1f;rkuy1Z9$YsWz{Z=`;P>JI?bv2#_iv%8PZSv4>!mlYn_xgQv`}&< zSqUEk%()CjvS(vRT_khr(xq0Un-nl5#9N@jQ1yuCpZO*k+Pg@p)~fFAI$eg%-}JgESxY5@x@&x^J+9H zJ8h2h*fE#-P^cd4&%!W@AJFy?o(Hc%v%)=3vCyNR6e%hy$`aZcM_P5R>D_m(ci-qH zvbo`OjXg53({JwY(OxE;QPe;^xhrflkGvfk%$U)tks4mGXDrbd7#ubhtnh_uHTNBC z%t3Nl3k`}lGmv=$-o8p!c^4g)R7|@1htJg9P>gh>?F7*l%)8th)c-&YNDq*_H9eOxlN9g<68$v)t^kb}woi+XvL9k_? z)xXUSZtl4q0L{Y=Chiz%VP%IY(?B&XrGV5glHso@<6lq%KgvyIl2EfBeWOOcP6MA$ zE#Cw_a_Y6UpdSo}q|DDs16&y85s1wva7sa6VnV>48@q(MW|QypZDZeuj$(<1S0f5h z;p9(nTFp6!`$U@0jcE9Ho!k3g>?#$DlC~Vn|CXnd{I^cqvhI@yrc7`L$$a>DQFMNU zE!O)F`9?Rk?>+xAd#B3ZEy;aNvCJE-x{o;g=o?2^AW*~autYb3E9mi4Ytuy6ADQZO zbqmh`l8eE}$cQFDxHoUhuHOJJE-v1W-9L5HlFwyNT6D@aTJ(Asqq%>|q_L4tHo20( zwtHf9iFy(>Odd^~<_oov6MdA%I}73)Y3k-i=?hU{a^=yN4t|=oJqOypWs?*XQLxCVaGGr6!D}E%#d_uua>x_IgFM+I}wU68wb_?A#w*& z`s-X|E>7K}6|N*9z3wdCZ5ZcpE5CY;Twg+iB&4bF{T}~c7Cj}0p0P3e$~M%J@^6uZ zX0yx%sVJq1aB!%9xt?L*N^_9?Rpl4>w!UsY)mC&3ua7|Y;JnsZL3JWp;X)`D z@eUfLI6f}!|6JRljP1|0hk4I8KY{{&_CdQ~CH`fhx^f6s_}1h9tUWdV4;Z`5X~3c? z_h06%l-uh6ui))}*EamCY@_&pZ=-v*Q~Y(>Lwkh1v?v8%M*sbhgX@jWys?sJ$LeKe zPz;|6;2$)1n{)Q$Tc|ngj`{%|5pHaJ+<5vfYv85r7gnz|?}Wds<>KD^t7GuoCqt0S zwmfjL0paZI49b9ycvBIkQ56n7Ee^?{@b_0zQZSKNl$fAwj{V<#ltw6{kkt5dCohla z3QPC3W+PJnE={^6;>*1_r{p1c!8k=N8c~Nu> z3^W`Zm?|nN$jHdO(BLbVc|Uw{-(VOEh5wn^;g@0=uAJAap40#N1A@{N>C~#UDyyqy zTwJ)D3_f8SLFuN@Oji5cPg7h~uUl3uaqphrfy7`I2?@$quU<)Ojlg|;mBwKHbEfJ) z7B^1&8Vd`H8g!+J?n`B9v3Tr$%f!&JgtK$SqNS}Pk^}DhAm9_~HVndQM>FE%au0BU zYd%Sh7W48}N^jIAOZpl}?Y+Urq`L!563L7RbN~zMPxqg*9a}fz=0MU{1Wuo zZ}O`T4Y&gcL;kkWJI#_r&yjy$hUTT6%PI_Meap+FrSb`XlI#Bu6Wyk7ZKBj)GbSx(BrpTV!bBDgnenzBtd^>@DdgEeJNbm!i+)cU&WTDo<8<@!1KmDeT;_rvT_J{qxnxMWvR_zo6 z$VRR8(EPOQ9}^#nQm>sUICE?pO=Cn0S%kLvGO9980a1+;n*2#vs=2cbtwD4<1JRtz zsIXjyy-icmPmcJ!h^d4`q!|D646wq|*?8uZ&a^h#Xw$(INI+DG9-+3U$|e&)e6NFCo+H}~14vZbTaf9LHc>-u;~ z`Q0Qi9ZkY0TLw_TfIsFwGqwHL;MYr2Sjj{0hndQ=!4o-KQo zkzefzT~6$VYr|=Y-bB~O10S~iQ)BtveMVG8g0X@$He#>EhwfSR3r>v_NI9y&>$)E# zO&bUbAM3CIr`2bBA2Al{?}8Sbs|aRE@Gy1T&Y@bz-#^y~0(DH!e0GEa!)n*I=7DEx ztl}prUd@-J&t~BSCsE#)A~(x>EVj2zhwSfTix)320Ta0~3kwLX+k-(HaWia?aP%jH{bY+&Te3i7OrR3#acjwyskigNrMI60i3X2GN@f%3 zwIc>tCg@o}-1L@x&F{``MR@QhYOSD987_k8Esz+N*b0@n3>C$&LIw*^Xt2f!J4R|U zq`=zUE6|B_n0s1({{0$sH>wYr)9&4?2Sf9@a>@x~_-Z2qYFCel27gX34$Z^Ls0# zAFPuZQidnIGm9qlpKBY|B5icXcR}R$ay5lo-KnX#)C)gRdhB@$-^D|1^|t*EtooZ8 z%1b8E)abICy;0_?qtzJGD@N++eVuqpk{I*8*gb8-A7kpNS&0L*LQGtU=3~()YSr{y zF%H!ax3;-+b)7~4nPClhDyRYuSX5F6gY6Zv^kbI_BwWeCq)fAami z>q@}DzW>H``_JiJ_X@Yu3v4NIKQk+-g-SYsFVGzbTA73yns8bj|$#` zRKO8`O#qq$^!D>ZJ8WW%l(h?)EC?wy>84Ct@4#2i;uw^9ejt`W?26$m?1Igby^}&f zq2m!+30S3$?_^z!@-XeBuIczyu&a010;gF@>pY2Z!Og~kdcprlK7M+S=NAAsw|}@9 zm}Afy1fazHapEUbvP!PD6VPkY6UFXC>-6*WfYD1N&{`)?dB5k)Pnub5**ER*SYjl> z38xR`&Hh;87s5JZGvFV5NXnTkn>G3oSw8v{fw;FWyEdQy;pq|E~LoE<)%I zk@c^Qelogo`0ys`M}gmoOZWAfUl+y6@ELVbr>@=i4=T1m-~cpC$!#~oWd66+zO%ba zEhMDh+U6`N`681|pJqj%`Y`m|LBxEHUvk}LphN>>eeSUA#+RRnS7*dK*;)Yn79?%o z#M^^TzcPb5qAyE}Gxxou4er%ciGg^Qn4#*BlLpXwxuH?=3nu6rOqYGBs{o&sD>1$_ zj(+e+3$69-E2xqJFBScZ?XuS^Xy9Fqb--CKfvvJh(#iGm2eY=CFfbW{!Mgg!Bv)<( z!RlgfvOnN>>I&oj&ucy*cj7TKG9vwU7Fo+}I#t}E2`s% ztr8ZNl21Y%%VDTFs(Sxs|IaY{Jb{KEA0GVK44OtVzP&`PA8Ct0(1nIgK6f`EzFH(; z>x)9r{eE^M;I#RX+76!Sy>5qdj=r;Y_+-#M_FgXK;17@tw=}eq8(Cw(y(gP~!{2U! zQ8F|JJy&ZSH_p*9@%O;P8c3G!Xr3+>sH3yu!5c(D@O|(|BgV17`B0SNURD1Xg4X+Z=?&tZqgePOQSgDGrT_ znrS|7tMZ;-7EA?1O}rz8EDXfa_HM0H`gW~lDE*%1^ZQLHjGi|idxDO%tF)xo0x;_7 zxVgX98F|dk*3wBonPtiokz7C~U66(_lB8RcP+8i@aAO!lL(`K>DfnhpDl55VcDFIb zxm2vG4wHu{Dzs(R%R=Tf5}KMUnK(G)LF$MVvWQLsfl_IJ!B^V#uYRiQ=!YI1b?$l8 zu-sJQt0@i!gU7}+!}7qyBNFQ2ct@9G?|t>O`XE}6!xDE}rmsaTb*Kz32s}J?MPKnZ zZoYPnOt8vSy(FRFLFw#Tp~54E7RpMVY?h8}FEjJ^@1#p^9uHl`ykn7H`bxG#h+op$ zfEywFl4Lt|gG>Ugk2(a|@d;*^E*Epi^Om4=Z6{o26T`zTlIgSrGoFW1(F(OS#`r$7 zE-e1IE3BGS4G>nDg0?NL47_eqq8E?7xGOh>m zWDk4-p=Y>CgsWgGWOtz~g-@UT5_yga3TnXZ8KSq$qJJTygj)Qbrvu8)-~#Jq#MBr| zYfHNCLB~jGHcsf>{f;%>aL&?!BWQIbvk)Q`DIpE$?lW1B2skw9e-tqVhXgDt zPKZV386TdFneuR-tdrIYi|2f5#H5sHz}{ngik!SPm_cq#tB?xY9{CjjL)sD$ox$q0 z@mydW>Gi~ea9y_$7x3Io9tV3~A9TSD6cs0~V_>8$U>~h!prtE@Qq%Cu!lZ6KaJPT2`4dwynM+w>qkR*Za} zn<#gINX z$W947kT4@W&r)m7y{73vSmMW;n1I|AUmiSm)zWDXmh zfTI;(bAC}G9f17`YdnSM#3cF(*)z7_ldWQ~~5??GkZ(Hq($8Ak5Nz{+Mp zT=vlnS~rExDR8xLnb* zBOL_IE${6J=e$tCj2+(gl!9uREqL~U50;0)ZVL{;Ah!P3Di7WTi-GyZZz{T)YjkqE zzPIhW*U#Su)(@^75VhBzhD;5AzV*lc+562kuVd)2+DB~Oq7fu~*cs?_fmeTh@%Xco zMB;Rz+g+G^(Tn8y2z2R_4{^w|K&vntN>Ql>F^dyIx0){HnI-rtZaz0-)}C;7Nosz$ zK|<(QM<;V?+4gD0ouYlmYP%GS47J>QTP2R3I69bh4bs-9=zp(3-&^> zCm;LVwZMauJa^PWj3=Sv)oUix!hEz^oA3wq-wGgr2wD*dn)-@u)Z!Fg=f(kL4EIH8 zvW8J417K!kF{`Gg3Wse7ryIz=B>zJt5))(E&i3-Mvey3gVm*9GL*&Spxii-$#EfO} z(3kh;4W(E&NM4ITc#|VdX16#z9f4lly1bH4n93a)Bp)$YBO^z#aaAfDB4&ah5mzG7?Z$tYo0$OYZ|0RNVkNDk{u0-ovhFAh5> zr(DVNq-Ac^{hyv1^<0ld**cGSj65GFZ_Yo*uWvpah~&Ns%a?e>`@GhIJ#XZP;n;aB z_t4H+!AIr1U|)Y6RJX0FT-&cQ&(^QW`GAy@5$TEXvSTnhzH5DJuqP<~d?=H9%yVYv zr2jCegIIUfnZ8!voz%oTh&@&>tmR^}ndW%@+IjXtztw$Hn$5_Y8L$Szr+jK6*WUX+ zT9;FPM`Yr2gz4YO+_-8pS~EJ}1`IOQ_vpRMpM9OyOn|lOMc86x?@VKl@#KCewqUrh z<9q3@=j{DGX@Mx~d6?WU3Zd)K8dV{3)w# zQ*7mCL1N+BE0+>3A3&ye$#BwntzM>+$5!;+yniW3EF5Y55y#*v;9+q+YjZJaZu?i< zet64IqQHmsX{OJfnm9K3m_7B6*?dkM0EpXDtWWF7CS$#w6RJ`ou(!~uEiwR8@2)({ zV(u4lw#c>X=4~n|VVy&BPVku*VBbCE$b}ixQQj7#rg!VCkkqfBw;1-_?ai0Ld@tvVW%d31Wvavy`T| ziw(+5c{RRP$_L&gj2vlK3O`zoP^p>Fu9@)fA;EaNkg$ z3G=kyOM#u~;3MDUdEC!*Q<6lAT7@^EjBgXqL_8oipP-3W(x<06{xbZTP2e+g1Mx?Y z$9K>4JsZo5s{zmX@A|xqkgvI_TODxLwdoS_nkSB;&*$TUdO+v$Ji5#==&>8~>yp&D z^K6IGOXeK||EcoOnpg~zy|7SVa}@(x)YS|X)dCie4^wUT0pVngJ z{>=BP0pnh$C+zdQwfS5?()Ix(MQD{b+SAo^#uo@05xM6~fnY4BgfIDcp)Yan_wl6% z*V?|lx^Bsgc{b6fl{oLMVg#nu2jPNyZ`ujtUy0e5mt5nP&XmvUyNf+rC-2l3Zl)Q} z>P&HsVYJrIw|B$?k)7Yy+m8p@F1b@{m!A&K4ZJ>D3_xC*yIxXD&IsKee(_9&b%T{1 zE%NM-WDz=3J3p=Jfq>%um?5Ap=1q|)@yzD<{v~$d!-dB~roq}KQeN8dIq1!B!}D!8 zhV1MVyCSo&PkD8IKHUA)QQsO|luKE#!+ORER~Aj6A)vGKp(xqUa>@Gh#>d6dBH_=c zvaYCac(v#Iod&G+rlxLt#Gz$WezV(Q`-MYuA0=1rA!+?s@#CjP@Z}?s<0rO(PXpUQ z(!3%P%MAx{XQR2(=G6??*P<6>6s?xxsX;!3&!4HwHK(gUwfM_AkEB@Z&)DLt-q^y* z^M&Nn-m10%V)r7>nK8EyC*gT7MZ>6La$@QW>xR;lEpSLl?Z1d#lYN*biZ!PObGZ-si#~@EiU--^095y_+eok;ZP4&f zyCURdW{{7ByQOV!h@iFgXQOagW>==&;Jx>@6YbW*fN5q2_Lu8*^s1dv&t#dB1Z^*p z#Pk!_*B!>1UpK96|`13bn~`TY&d6*f#M`%0)JT@oMNziGXX zeH>l^9rf8eTO2x#e9uEaI0A^hNl)KS>Lx6#szSWAUiCjvN+%L=0Qm2=jo3c!uE(5j z>sNwbglE5WX?n0ql9aoX!iP^9Sdg+C!I#SR+Qp4W-41!Yt>$;2^d#{=8!#;#x>T+m z3>}Pfxq!p6T>QW2`s%2-mh5XBf)g}Yqk-TW9D+j#7Cg8U+}%C6TX47FZjF0zcXzi& z8u&VI-pst;x7Pf_Vy(J;Z`C<YWm@1F^c%}uG=^CFpIu-qqz;Yw^^3GU-w`b&op;93 zGX+GfH{>MZT%UQ6oC`kVGZ^jn8qco>0av`>OF#DI%*?4&`XTA8^|1PM!7!-X;wA~+ z!<}jJLw~oxR%C2j)Aqhx-5D5!wOa(+(K7S+4?iXq7Q$PK>pR|C%RZw z_p4#f@cTdkJXljq9+#ade!lzvz#Yf4Uak(m+Y}%N=}oD|ET` z_(iMbo-pvwOk&V~8v{w0P}#;eQ$Wel7iVFK>dkSC z0N@Y#Os&u%VN%=V!R)Bi=n;SiK*)0${Ae+f)r~S@(=X~W(4DnA;VCh)`OXQl?mkI4 zkkYGd{vc8(d%HRJ{$7D16#hL(;3>0eY@c4ROB4lBKc*6g?WOr5;?n^*E;>W(|&_$os}CLZ3`$ziU2y1Te~{sV6N1!$gAVgKjGZWr+a1_)Y+YoYU*4?xbX&Qs`FpIn;tx^F zie!GQMR@w?9VMB({$ts?9nHt>NPr5rap$|J#-onsO>aQcQr`Um8jd?3hV+tSI6J-z}Y%;1Y=@$oS3j zzNpdETQ*k9ZYtC(#jgC{{l_v{{Vg1V98*80>d;)lb81zmoz`Gb2GLn-^HtGg&u-+_ zpT*h8!zb+>_NwsKE`rrq78+=WpdtJV_mX}T(BW3LUC=r2CXid~W4K;+2yNf}wCVC< zZV&HH8}o6bvd(0gNusQ+x-x=QrShB7-h3QQRkU?Pe0ez#ZHiBP*xQxgYMj9qvGL1c zz>*id{^)$V8p=ib%>Lpz?%;a$gYRPYj9)E-vrPISb+&I=ig~-;uYLS{avvye<$%Xz zP^=t)$=g}!loFiMxVo_aZLC3EGa_eex5@iKyWUwG^{u zh3oU9IM9XGpvd-z6&Dw~Tk|-d5|Ke%^*CS6w^}NcJ@aCcmeFjf>brdrB$Q=NZr#tc z1A(piCykiBF(&*oSzq}ad0WcGkrS3*_LEGPy`VU1zG5ZD(&(boeCb(@5kvj?fM7XW zYbQi2E0~o}fwK9MO2E+#i(qM3cC1?rrjq3G#CY}H&3f_E)Y-4HKKz;Td%p4fjj?6=>b(Q z;>Nhpqn5<_1KQjVxg5EBrVHk6LudFhOfTMS|P4S8Jv^!=GOak zo-aYSfgZIyJudvf-l68-9!(AokHXA=pAu-12{gz-F_tsfwF4mk`Da90rhO2ZN+>#7 zaG@|_Q|nSq+*nUeV%Da|?o}y>NU~zJ>r!`Ke=|LK@x}bzn46?v^K8mC$W&*cX-gnU zt+rZkh<7D?sKNtYo=(D%%tEqEgU|gLx9#fc>E8O4(J0g?M!J_9=*5$C-ZHdQXONS7 zzkI)Oire%qzN}cySYzS(w>{X7y{*g3RHoSMvT??uns?p*PBA_9bed zbV@6~D6xC66DF-*-nP_Se`X~7@=1Q(pewLr;t?cSyu-6msZ~%|C_?piD8ylWY)nE< zZp;CtCT)2h^9mpPQ+6RD{k-tOv@Q>s*sI{dz5%*7KVnCB>7hnvZb8nnyq>hozMh3=J43wm_Lrb*C)-k%6K@k%<6f;bDDi? z&Q;5L2^)XB>+(gPW5CeT@8i9>@?$=-&~p>uT@)593;~mwggRS0SJkk`y{axKO}}&t zGjS_Y$gPD2YQE-Foz9>!qo0O7sWDR~-(GX7zeJI85}z_UO*(C$qzHJiX)*kKx0pbm zyuNmOIghBf!;8vZB=7GQ4ER|7Kswa@dFQ>L3CX#c;~^Jxtx1HR@R+RSiaiu~+ZDGt z=ia`L4$iFAV0bi{b*UYtw>SKQu26U3fbqrXIk>~R;Q4TVC4Knk-$}uWCJ+IA<8M8 zZPVq6%9&IMF14OUCzFlTe3GWhan)v!ZWmu+$Umq3e!Ucsy*LD0tDEt|nRk)fee0vx zY@@2ZNcyWcn&7GU+}l6JR8 z-^KQ5Vag+H0dUoF37_|@JZqd0n@ICmEFL+U77nU!`Msu#?dGvuJpw;^>wttTUrt$a zr*NTv`J+m|6kQx%ISq2y_KhyGPtJcsTNcvo;`MxB&>0o&d_G=icjCH=m;eK5DT&o`eoMEGed~ z_e&JN{f^b&3DsauNXtm;m*9lJ=X?NVxGKS_Ird+YQ!3 z1w-o)0HVqo)t}S3k&=eTEj()4ULu*Ii>ywA^&5hkPVp%L1UW2x@X{LQ1Q*=|sOF}j z#W7M<=3!Siw*14a!T@}t;!@h9bwk~|RL>7=J2V3uSBnA*E~n(_{Dpc;p*l!H)o*^H zuc)mA_s!P><_%BB$`1HlISS=T!oeH#+{YvXypLgo3Mxsyx~;b>KiNceXe{Fm8PpY-thd4)ZZ zdO6DYwvjU5gpd0!x{2%!hIM+kUqG_nR5QL7@#s;7yeQxq;U<{-Opv1Xp1Ax|lP-&8 z%Z=}TC@YIRl8Ao{e5FbO68ewe!T?0#FZcFIWFNQ*s!M{doC_9gwECh}g~-cSNaNqj zhlDs2&y_Fwh72(j8@=xIx#`b_j9_XQhn29Kc256>N{&kJjBia}?ATe-@vL)2L!Q;( zOM9T}zj5jP<)v$IJ2yhBq7;<#4HrE2kgXudB1tV`quaSyJFr93ejop?Z*i!}gPFjc z&<*X3kBBl6`Km{9oz-GsxB#p(k_WE9+!phuXL4TWgea*iqMtj)T#A^+OLjhxtPX5 zq9^?ow(8joQ^)gMhT+u}z3_`0yl#aKLdGZ}_clacKo0iu@@SmZVTY`#rK!ikmJ6rv zfvg$|vyhssxtv&ZK(?>9M5$`y)P=RCmWN@G;#w|pk%#3FIMLakTHqTdoB|6?X`aVvZU?bJj@2* zCi2kRj3+hC&y)G=z+hbwZjyu6% zrzy#xCY(5A+!+9hM8W4_n3$RtHK;TNrY~L9R#}@3P4t4U#&8_F$wNo+fb66RnK<7Enz^8pRXs{OsR2% zec_UyT$}TG5nQqQVv&UJ^F$C;M6j7RKCk!EmaLBG`5tA7OYd8<(TSit?AzZ_1Sf^$ z7_?L>#5LXR3f7DGQA^FC(k9SBRJb70-CU*QioqXOK_*3+DV$C)g+Nw(8I80Er=vg? zdjows|A1VL)M}`Rb}EU-L78FUuYL#eLWb1qQ8SOr)zv0^!wG6`rB~q-Hek-$5eVxk4>-IenxS<7&fvHW0cwHA3RPH4r*l;#*FI0s+ydr3)4>zJo*`Lp@ENH^CKmZg{jKHvN>1n;4a8?q$d9gD4c;#}X@ zPW|4BNy7At*iq*1sKXyg@(zp^d_>CfY$tlxOtE9MPbtKR3iNrR7E}ids#fX*W#C)q z=9j~wd)5ECm%W2o|&Yv^1q6^#n5Nb25jm5k{f=UpgUihmQ7oB-t+|3np)IJVzpVkak6POC4euJn+Q|(8g`-V5Ng`YH~yOmG}x%BSSy&eZqF|tteJ% zTDbaa2&Qw2Z(~t2WiJTY{t5+)_-CL0YRAFUKD^`f=)mJHz@Vo~=}NOlnW)W43;rmL zLCWJ07Tn-NBbYLWJ@4}^%I0oGAKH|c0w77oyv3yI)$m2Iw`F?%BY_m)E#X1JL z{MRar(~>eO=|t>o53=LoB+03x#qK3Lqr9{>${8$z2+a$fKbs5|?mfZjqJ1O>r{4J* z;O#3^uL%t$3mIv{>8k$sg@sub6@quSpCmnYpbRcJtum4c9&miJ2^{66)zZc5_ZOZ4km^^(TtO5kxm*aik0M;MIeN zlnE7*wP*^36wL4gdr{Pr^Dt;iU4NY|CkD-CV!n!}Y^`n>{av;)JGM6!XKR6cyJO`q zr@bvs7MCN@K)qb;kAmwp0CD5nO4oX^>t)4qRLI89Q?@RkRU#|#YopVES=m=tAykoX zmN-+xbraLGI;4ZnjkTRUn$a<-_(AuMC^rsP2fQYnnoZ7!%IpV04f>LfPO8F?3)>nJIxq4=;2rAbDK*-4q zt=J&(<(Q_D0_kx;Q?7llfH$fP9&wBFb%Jhv>7q*^4rlfGjF?(OWjdP`#fsK%a#i+E zS)>_Rb{FXASo1HPcgNDMHY3iSx3hGXi(r(G?X!rQz~x{C)%`bac>VqTR~w&I+%Q-H zMm)T{A~G_I-b(}!dOD$Cj8u2Mqj3k8+g~pS`6=qr&?ps;hMV<}re zoxl0W4|wd5(yf+qv|F8RZI6P<4M{c~UI^`bXECnpaMrsvck&*2oKM3@1>9+MpD+4D z!dcgPVDNpGBYrNPUR?H*+#7=gEj{;D2%JxRoi-LEM5N!Uu~tNaWmipkt1NjM@)-?!j_RjH;PodL%m&^O>IP z!+v%*hPXz6Xpnk0Mri+_0`&*ea|@peve&RAggRyT2@WT}pWdYYx!725(<7qV-MjmK z@r7ZFV*VuXoB2u~VQYaHA0>KmZL@qyc>HM~V?C%bxuPd8f2r|xmd3Xs7W+N(wiQvropxShS( zrQuu=s_Hbo<+Y?BSlJP@X5YjtpMY*A_KW9!&Vzjgmz&xaWj(X8JL$@{FpN3R$Y|ZV z{;8~!hwg&MF@nd$hEMc1$X%80@v;YDc zR9T^qKWZY{Ts>WAc$tsdm#`~)LG@p1Z_6pibt#l5XM+(?7Jl*G`D;kCK!pyMP{}L5@q)AYKm}20lwa#t;o)5KmpNF=FddZiqEcN*h(-JquDoj zT?vR$aZbNv8zPPW$ix)u&n>R*5>A`(KUMIiV&U{x%s^~EdRt7GJx^vT24Q(!2a)&o zdreNOB7!%l0uY<3^ms8l<}0$R3^5!V&ELmZC%_pOq=U`1PwAaiRCdAg)Wbs{YTR28 zH8PzgAg3S)!LI@B(dnavkreIQ+@2i6*>|hytzBs&pUgao{V9V8K2DIh_gk(v7tVD! zOfJiw@NrJ$46uy48>0(qG-4TYfG?-#lxSTGN91;;!oK)Q7kS$r4+?4jE;i5JP7$se zla~DEt@K1Iax^tFlYpppJCHFkIT;I*$wchRYEO_G6iVjhxUJ7Fs4O`M<&?5Zl*yYc z)5^c)rV?xm98l4|T&z)1X95(a`TXkL2QUO$AE~TFdD@>l6x2~?P(XHNGW3j1U_wYK zSxwLQM}H0g_cnIl7)~xL;<9$6+MZ4WDo7agvMZx*b~q9eKak#(l$JsjS@`En>-1p= zd536ZDBJDkGM6H%C)=?NrY(FZJxtXLHTB7_8JoTM#wE|3SFNU$ z4Q|B;sU%N;!BO2*VHq_b#HI5$d(kCJJu0jRpUC(e?5g9nE#&ArL7ls6Oe(~QZY0OV zAVlNb)7MJK`^~_po)#!PQHWkiQ$?CwEbg1o#*iIDf3<%@Az_`<@5vl5K7zVqzxlmU zm82p5HeN3}2{%WH+lMY*;Q0Fq-{qLeiSeuM>O9E{vUw=Okm`*ezjJ?Cgx!s|v@NOg zNUW_zw@24kJI~S(%+Hg4I;SY$?N?hNYS-BbxtBHxz>^21{)mgR}6xYJH zMQ43VPea$@;~9pP^Ue;^5je4XK2piwPw8s+Fl)QT4l>WKBKUjA54TkcyE5)XsJH0G*@>j&BvZ_>?XC!bmwadCW;q|(rEq<|{1 zmwW=B=C{?cthDtXLmCpC#^T>9=H9dR;h8Tw557@WALEb{&kn1AmFOX3!b}ExZXQg= zTm9T3LT^XNrV}DaW`fVlbHE@ter?8P1+#amI@7s=FQCIdC;m!=SDWnU2vvEp_HU?w zCnlk{+YG~?D|LBaZbb#hFA|pak+}S~di#V(Wh`tgjxAAgg@C`q`r1T;ZC8~J9#WG% zdQM-96_0&OLlQ4dqnns)D=j%E2fwcpc$&GlF{wUD^**9ut$ z@;h>@!HG%#oFrcRsrVSmuSr7Wzl%HURdfxfHDxZi`9D7-VM5f&jLF-qg+yAJU^k6a zo+9{LUGD%1W7*qGP3Xz66 zbKo3k)BniaKwdrpMWV%Nd%nZW?S6oIXZe60!W5J%B1rKQ=ldpCmD7j>F`qMZ(O5>X zyfXTU`loK)>IpX15Nl~tCSt+RaIW*5>?ZHfu41#?Ru4eJ4jd)_IH4EsPr4$Mjg7rG z;r>rZzsy6K>$ZEn-kv}=6#uQT99JB1`2Gw;{jTtK z+r4Alg?o~bfb0Fs<3i2_S2Ds{lXg@TQK#bK?_FLKED4fYVuiujZ!!v#Y z`&-WC^ITr54^B=(lXZP?SrI#WU+1iQa@hCnHaes44R-OHh?9P4iFk#b5*(LCY73nQ z1|Opwtm@cl76ivqn+RNAWo{UK4RqE0g{~TAVMCV|YSXvNQK5O?kbFzWHfHR4EVl zp&Gh8C`w^7u&K!grQz8bYJag~<6xIhfwej)NO+ar9Y%#QBIS`czpJRq{kO^7i_2!w zx$4$&dxz`yC3WRKtv>&Glg(&NMj-EM&8foJ5(BO}PgB<#KcEq&@8V#sW3TnmxqVWT z3kzf@cCfV<=1v*knBrT1UR{g#N#KS<_4R@>DuWlY&1BVCZSjUhRZyhlyJh(N9x!+` ze%)|rKg_uf6!KfW#al=#xVGi2yvf~UXi48xnCwiVRL|FgCJCGH;BXTGs8pmdWlh#n z*E9VzX4Y`-sBpsfv-g|`ajcV%xk>MJUWkG=uK<`v<2#a_deGaqRfbEyOGEB#z3w~y z5sW^sZ@7`47{I)i7AW7au7KJvGAI;LYRI=*57}`o0z-;tzcE257_?g)V}bjU5v8(U z6Z{anuxv@5*$}u>tC%Di&D|&BOvoA3e7iCOCPsAd^+D%kY^_k*kLba_>`vvZaj)XA z$&~B6He$iF%4r7+JtTL8eHX2}L6Z8hgA7xBF(24js>%df?he9gn#fjeQG(NC)kf3U zFpU$<54dc(%bj|ge9no_9s|jEcmSd%qg`#ul3fbg@Pxr153;{Ooj+m3^q`-4J-T*& zIzFr&DMd&dL<ogB)3OCYTTG*~y7)oqhT6jf(MAw`G;>V1qPMs{P_0^w9CeyzJ1`Ok5GAyx9O%Llkd(-(vIblr;#M~I3&;cHN zRdSh7X>=4uILcdnig133}LF}#lcpK>R@K--AYF2`P6Qm8g3sKt56s{nc1E_!X~bj5>^#TOGN|0 zm7WdR=S^R!vrJ)BG}PNX#0jUQ`mcOuH*UUE*58_dHXibmDq$0r*Oa|`4o)^*Y=)(% zSoPf=OucaYSh*aWFf&si6)7bNOuc3)^x)g&haoU4C1cxCK~R%*X0 zR9bxqz5W`jn%i^L2#Bb2+L)Rq;qAj}I^7LdSEPQF&HS-uVm?vj5Fp8=Y4-hH&U%bK z3u8pzDIW+cE)6w+Dd6&Oz^13CbNkpEn;k2GB^I3lsh5*BbCh+NTL(!H+%-B5zX!%Zu za1nor4Qq=n$o85zXlzd2zxL5sBa3i3s>70R)Z9i=t$}1DVY%z7lAG(@JL6yifkCu1 zSurgb5;SF#f}GJhJ`?$OC@2Db&p4$F8^yF=LZn*hb=<7jmS*|I)ctlYsLc342GFUD zO}tNNux`!6bR#iuv7x6cL?>6fP!UdBvQ16d1J{A5>lbj!ye;~Bbyy16YB?aY4o^;v z){|iGs3fV|R&?gMsHp<;l)JqU*X!L)$ahApf4y5{@Tg?88(Zo9tsm1*2ECzOpI+d4 z1pLK`9x`Xb+^S0lNAfA3FsQid8Ab@qE0is+xrNxhkxYV%3l9O@@6HrnUY9X=zcQYU zp#8jbc^#x7-&x;(ygg3gbt?6IRs8lDg9LjjiOS9U{(e=L)p(kjU~}dsky8Ze;WYxo z{ND7}{qoxKTOk4j;K_86yy4Bk5{i;l6#JNJm6=v

6%gRe zdj93{@*fP!!!iNy?STISbN9^ye}F8ciRZr{@+GAIY8Xhsfo&-MDrtuN`7R(V{4M>8 z@n2||z?eBqIPoI-^}o2P{xqZc4fsM2H~x9RpG&@p>SdP|c>as)4ML;JX@>I`C)b}# zDgO&!C;A^x{+D{epJM8dBG7-~Odo>kZohW?i-9mO<~1rT3>iY;E{OZ(N1uU_krC~yxu(C)YI=gr z-$1n;U_n(C=HcOC%#hI)P)0@uLdg^e;gxt;x02N}S=9Lx^!+vL7d~Ybm7KD&a0tXF zKR-Vk!uSk1u!xbOVqsxX7@KW?yYl(>ErldxWznLdqF6XM5_E^Q0vH6F%;zBq6$3+p zLp@^{#ASck@>Rn##@NP&8Kb7Ov{cW^iV>qiSy?&3p^ouC#(4b>xy00z2BR)>KC#UF zKh}M@o|&E1x3mPWRA{MSXV<9zr<+n1NFo4ux_=wzkM~Ar{yPdtbBl|;^1ls)IYkKL zxA7pj^KXm4>Q2!5|Ly5131tWZt^1c|BRcWG2O2C9sSz!pHwlDxE)mGg%$)q1^~W?j zmAx3PV;Egbu~G?2OTkG=N#NHa`KZ<{1;a^4}@$`jYs3Rf8Ms!6Sk&qutl^L0u=H=#!JmCMa+n`T0 zgp{9wkulMS^H1}?jQO3?(^njH`?s&8{@3J#V{^X=`}?A$Kr(KMZ~rtLnVi}`4C7BK z@brJ)g3^|#f4n5wig17XJO6*pSQuNjUCqBcNdAkQ_Dl5txqoM|@;{po*gKW}*&9@+ z`v1(*z&eCTioaOLA-DTKZv|woP(8en;%|Ig+0Kv4+;N|~#cA`#1Q7Abujwn#d{$y; zc8`$Wd|aYlxM&$Z1oD=TOI6Gu)3^FtciUVKX6tied}0_Fw6Qgdvaqe2pFWj9Yy{_F zczzOq#DJM6#skp}MtWej_}E!Gh%D*2L1KBG)HPL)@rXefD10(olt;cq{Su`uXeY&3 zsxY?7ufOFbCd41nT4K5Q)jNzS;)J)WT2hUh5GKw1Y7ycpFeCS1>E~En(kM&)cc04= z;uG(&t=}!CN)0B{7I731WjeBxK~*R0{R+fXrar#;0OVO14BWN(t;@z29_ii&*{ybUJ?5AL`!5ayAo&+@0W zi!Z6N-tK^ryB_e1j`BIT;@4nNNB8?5Bf?a0;2p!ykqblqp>jS;_epii)acCFnI_x^+x&?Geg97$)#c z>U^@`H|~AaXA>T5Ft`=aM0^@R#3yHX?oou*okSNMi`-^+xLn{G@Y->8y9lkzKe{1= zQ@wFS?hUv`u_j#zb2?s2@DViYCGhkrg8D$=o%wc0Ot-&F+>6E0ckAhT{IBqCZ=CAf%MIxUM-L)eQm3 z4Gad*8|n5poR4iR?9$@U0{?uLz&|EZ60i0Br)jcUNV^{0pT`$Uq|kU_36FIq1LWEswALO^@^%xJ_7`i)j zJGwDY1ZP9V3s-IAaydML+d;o$z4sU}Osw?NxNfM_P6(MUOCQt~Y z@9;NZqbE5Lmgs|S!m*tw*@kOi>YlPf$A;E#vS3fpZzW1T@-vNIXcioa9C>d>0>_p3? zx6;4cT_9OHQg(qADz>QTf%&D7`lt@w-NC{lNdSVo!9;c}0jn!izauUsl_Y9POZVCs zx;F8R{<;+uLi4vSF-?-vus&#FzT$m}ZcPLK(x@{6UM<$_{%qmxiREfc+{6;s^sfT> zi9Ey^Ejc#84gwBOq{pZO43u^CP;p~gaa`rkSH1_dp*QK9Q?)|wjy0luq5{RKP5N6# zT-<5LmnD!Td5X+yfg2FT!DIZ$s{v%C)!~7{b+$h6`~LcUK3q6fKo(}Qr5LoeOHM|+rw@fu;ZE1vc|AvB<@(m`{8b5;I6ai$NG@;`ChxF`$ z>pNTL6lXmg4MZGoBqkb41?27ivSI)q2v7V4%~8L&a_D6)q`?F*N_+$*WB3APiR5L7 z*o0myDs1B^{8i5 z8FjFh32;{+B22nFh}VJ>)}S7C`mJYa8Kh6hgA|U`Ctw4B8=#`h)52K7vrZ9QMLT7@ z=`4a^m!-VG-t$;qG~)wp)M0*+rMls|M~KmK{eMl0-Nn$)NTQekJptFir=ilS>8~M? znQ2=M=e(AB`ZFj>2uq)21xsV$%lUY+y=+i+!iT#KU3#h%tq)Gk#s7p-F+SA7`qIr; zRedAq9MEsvIM2j67FG#;Hoxb+*vMXDe}b6iem;8 zXt#v`P-#vn@+~Cx0nwG=_XrU%?&S$X&&+(QB3_L;V7ZYkUj@+%aH;I>y}1J& zs!tT;1GFH+THXXLl2#hbEv?%m24L->b+e-M~X);TWo&;b2D^MI!c#ltm3%~MSn96#yw>0Q}*pj&1 z>er+Osh)97z@8#;dwN8KmiHK{5l#Qb)kkQ4Ee3r9bpZr@$^}0{)rNy3Ck*Pf=uJwW z?o^@Icm8~c;pB1?0UoB<-Ui`F9Jl&B-jvSPt{Bg&qjr>?KM^3v@0f`8-D}@5Qo1+m&)J0P3!z+;jz1nfHb4Oy3aY9(n>&o%4BfruaQFM zGvW4rZQYYpxc#I4aogsBu?12eJe@-ErnI{Z~2e*-h|juvUIk= zt5w=lU>bx{J~K@>iDo`BYE`XVPEaB>`Mu>*PQ(_8{U=wKAo(V!MFkN z5myviYFK{cbdoJTOoKf_sB&=*XbqKZ{3LYlFhlTm?eqykf1OxR`TOF0@*mlNbZeWPxvP90G7Im9cupfL{-!PQw*NDakI z6c)yc-to`?-cTD24-=B5ltdcFMuvSNO44rWoKnYkuXjm+a5-_=iSdm%n~mSi>OEO* z^FCR=5a>tCt*%TC^`qiFwoH8F49P2^j8Jxnbr%9Oe@L@+uV?32VC`G0plrb)2+Vw5 zotX5EXVw)Tc^f5{WM-P9cD)?_C;kNbA^Q+())>8Mv|i=4g{X5$eHPw&9$0vl;6`}z zL2|(+A)xz=f{+GS&(l;7m!rT>A~gVkuQ zvC1vWx`yksOKgxsyzj0|EAO*P{;+aoP6Sj3{3-D4`o!~x{`a90EARo4_8$p?aAI}) zKLT4!M;GV+lOU-0h5e&B+wbLHAvgK|jC=o+ru@%1{2v4UA4wpRQTi3hzcW%*tU$58 ze|FigoLl9evGR)h?LR|n7!@b&e}vY;c}RaJv;VV0a2p39|H(iZk;2%v691hc2G#|W zkx_{M<8j5K+7}-iZfk3dppYJah1_lNJ5fS~X`3i&#RY6_782pE- z_~G2v&dx6{&rr7Qn!lvD_>=Ka9Q6u>3*B6m004;A^?AmXlao_WQi_-V)yYpzNp8maTT7LSU02usa1z~g>8yoZa?knC?_cve3 z|Fq2i@2Z%6U(seMq@3dPcFLV|@?Uh4!rpK4hanXJsJSBKbcsH(uaz&~Z$E{_fnh?a ztu&XjvR<9}AS!&2Wg?Hxe%tnC$~Yh8m=s|IS;_WtK~T)(N1_r=@AqiCy(1Ewuy8xW zW#rM+SIU}%tmj7QSUeZNKC?%Tj%t0*Tx9@rBZ}mm-Z*KW#rfs-MY!}c3LlRF|D9k6 zQO9Jl>sf%C-5_dvD11B~xi7qiY%C50-*V`65oX!Zkc6^bW#4ak0{UU9-7Bdi_&DILaDD1JNI9b8cen2f zrjfodS$6#>WdL*ApeNb1cA2Xy(Z#+41jf_I(_Zb~d|z=ReoaO+@ezM{hG=rVqot=; zdb!Tw8!<0C*PXWVbH0A8z9Y}$bqHlX8a|4xn!|T3KAqwKXr; zZj#e|dw@-U*qp!keJ&X@X>_B8T3IG(yXB5K{PS?U-qP)NY)(^EaVk`t=t|G_y=7O( z{Z+CIt@%eH?$DrL&0iHFo)||1_DgcParxAkyO!2pJ0}e#t6k=~?p-&J)gOi&t6c?JeP5GtFdB2#2<+Hp)?0CSb1U}-adRHFn4hGqc*PE=XX)cz|kYV z&`aR+fO>}|3y@c!v&=y3S=xDB-V{gdDXM^cS&t_Uo1X)X zmdkrO&B(lYZ6lm0n6~dy%kBr25It0%qjqxVGU_8+d|;lK9&$>DbkeBTv}^H&ydK}8 z&L+kaPS)(!XO@2sU8Wi9G9T14g4dF;%`J}P-H5F2<@;mFacF>7HHqn1W=}l|sOl*m z-|jkO-Hx4mn`d8m8+og(+Ur#sC#)<%DHBaCEkJwSGuTFcXJc0$*ux04XtLiWJX^c$ z&a7M)reS9+rrm$0iT(W9?z9(O%kXL9$brN?_-w)X9%juahe%m7)l5*=`zdTU+y;Hm zY6W`TV%~0-VI-MeX90NXbD(c{6Fr&?{0z|+MF$8*K!~pSJ?}9?&`Hc^6B+*6aN_u^ z@*A~>=Ee`G3l%m(ef51Rj&=ntX{(RbD~4b%sE%J;vY3hnO)(Yzf?yB&`J1GqRzS&JPlw()lLxYtUv17e4w9j)43@rZcpMLTu`IL?47P@s3U)#ZYP z1Kl_><1!%(QqF}W?IvQ>A6T^upI2N?pa>1F`?~vu|4kgsGgfL!Q5&6_KT8%=K1$!< zXVkuD4;R}I_=M(e`-h^oz3J{8GEO{w{n^H40S!rgIX2JsMYeXY*c9sWL;fLY>cP)Q zh9j*g%vlOX_{n6vESQIAf~|8kPE<3x14_!-6%|ZA-wBuX4rYd`7>6aSe*rei<3ce{ z&qsI*Tx_EYXynUjJu<}-dag!fUKV>Mq>>Onxql%8Q?M(Y ziV2M+B#vmR>!wi?TjaCThw=0}uW@VJz$cDgka{gjrm5tLoX6*peq$i=yqhI}6e?zi zG8Uy~1h@IE97hS?6AmNMOzS49m}qA91Er9vg#491O(l`HB4#2UdG~n8?g%VZKK_Uh z_AXWTKzQN^tSZpFgQg@I@%KD1cyNT)KM|`e+~pjeOi(E_t+1~#sOYLAr%l1Hv^1Bg z*n%kcxaor}ege6s^0%@V=@>k0WagwI7t$)L5jD%7Z7=W-luV+b-J=AMy>_h5VbN~3 z%2HHTa*Ul_Ow43-?W#gtTT$^pcyLh&t7d0r+gb zq#1u~R!BaE=f z9T^>FZrvB;H^=nFbBhhZQX1MNVs2Pv9~nqWBll!9ON^Ga0zcz&4#JfxJjn<4&l(Rk z$Y>+NG|2kzdp`zN7A2NvCW(|*yr~DCI!2-0Vj zC+tyqH4n+D@7eCoJ9B)B`?ZI#B$~}5|`qCKF zMCGouEw!HCdB0q8fGOK91}3)$)$DpdaY^RipY{AyY9LdhL@#>b4%VEPGu-bo98`4r z^qQHGt>`1E`8HgB{RPtnyVmym6aM{!Ekp2^!@w+|M>uKK0G7JiX8V2yPtdStld@4j zbq}v-+$&Nz0+Wa@H@q4;pu4_I&FsoobR79maV?{na?J36r8-o_2Gh8^ghlgc=S8QJhK;7h7d4>4>!?-_rBW~zeP z9>oBP^ckY^6U!cxtiSZ~9$^`aZ=96qq5c$tz2iM080Qt};)>dKjT6M{xPgQ^B14{g3dHvF3hj!SU$yh>dg64e?259=!9dshJ&e2HeZl}f6X;%~ zoR3i?i1gsHp4HaL8l(MkZJyuZ==)g%FUkjqkY%|x43i+)Jm_v5gV0L7(HGp%R`z!`_}q9IwwJ9A~lp;^a;+ z3EnDVR@*)XfHre<$(R6wk=XM9;eiVLmPRgrWDArm#>Xnvwc3V@N7sef;Q+|qtk#kX z!kl3t-4P*;sP%=cWh+jIbmf>BKE0Pz8M5u|J(v0e5MZ0(ls~@C8&uZu<6z1I$rA1Q zaup1+Wh;adZj{?tcwk?+T*m56ED@$Y;r|GB#{^Ym_S#5Vi#93=-54Bi^rmuOUL%w* zHlcByRejn6;}Y{Y;HK8xUD(!&w#_SgJ}pBB(ioBP(PK+5Qruh~V326o=Q&L&97~6U z8s0uEjj15jWQICjONy4|1X!qGMOkY3qp7`(wcADn+w{OMpp*Jl6pAm*F7R^DrM5&ye#;bU#_gy^`+JeEZa-CtlN zV0wF?FCUkkB}h8|9giW^vTkWMK_e(LaKaAi{owK(c6uEQzPCoeNv6Z);i%t)Svkg# zG?w$F$LRAIMy1?4WReFt)#_JG7DGgLAZJiLrAqIbkbk1Z+}8cC)(ewe?<=sjnF|RL zmnJ3BcEwf!7toJo8nEv9z-b+1t_Lm`47Gg!nrX^4I52=%SXgMb-XVZumW6)Iq}#y& z6tG=svLoO$$4Sq~h>edAfCvpao~<;C4@@jUPOixQ9KF3PepS3!b4CS@3x$#0&BycM zgvXNDp-T#0^d_}FNNvHM?~4rb?trR)UwdfXN{gh~o0nB>AZzSv>}L70GS#v^msnXy z5yp8|Yw&uHKO+b)`){oI-<{U9%Uw$ta&-#6WsEqa~S(~QK zg$5za*@bL);|JFrlITUq6~qrC-FoCasD) zcDi3znAKf4h(~<*gGY+SHcxVNCpF`5C2>?rgr~NM)44rJRYl+D<@urW56Jm4?4ni# z;S37-v_!~ps7vJDf5Op38vukvZ#||8P5e3_UiL6cHbbomij3|^yD|J`a?XI&T1XeK2uiD@9Clo|IbKsVEebZ z$PLuH@JL7_-7+#<+dI|q3k^nOW7ZnMr*`k}z40w*XvVi!1#uT%rde^M=yr|koTG)- z7Q2&N&Tz(7dBbndK?BWMYTG83A6ud|Lw}X6iz6mmt2Z0dcrRbD63aHdKQ^*r)4(#I z6hD})XP=qv+?q*w%zTI$>r=3pgXy1zO%txWK?;U1fHkkVe6_cgq~D*e$w$NoJ! zTGc09qbFn1=h0&U=p%#|aagJjA$2A&Bha7nm*w`^VT;OY_5~!Nb+wB=VJa4<7hthz zFd2x_Z|vw{sOKw zJ#F!s(k_3nPYaqiq`pc;zVVS|9aj@Fx(*5yT~I6S9I9{aH- z&;8?9>37}Cp3&)R*pQNmqJ<`d|3}t4MOPLz>b6y}ZL2D_ZQCn0Dz;IvRk2ygif!Ar zZL{K>_3yp!-KX9AJ|D(xW6stFdjCF(XXh6AZM;c)5`R#lWDc@!;maJ>!pb%X!c%1FmnmYZj_>Qt!gbVX_hlbGdV9Y2%Ir+??Aglws(X_AU0P^D(_g7knzB_zK5y-Z9d1*sp$8XZXdC`CcifoL zpfyrfYDmlr65O{PB#NnhCg(n?G`u>qvvi}K1I-<~dpcwQdn3{z-D48Qpz%M>%o?vn z3qZ#yNn3X_!L|GqdH0{GI2Mn~SJ4N8C$Nb{u{+epG4+R;!l)laTW})DUDW5zl)FZT zFn6nPHkCYmB8vD{cxy9DbHR~9m^^J>GqX!-Rh6Z8J1A~%Y$}c3MpNa9Miy3N)84~X z{IgpkU!{kO3#rPA%c*aEyEpCL*m@;hpq>#u!yX_(2+8HvLc(Rl?;QgU zt~0_uatL=2#WkABgOlf7REJyx&l`5ixTm=7#?RpbOq?@ewepJ5cnhc;SA{owLf9!- z{0-;a-#XQbq~s^oYv~5W@coR%?Nt0PeN<_ z#0TT{xJ#m60irXTqj0ZKM>hl<1PX-fMhhNTHQKm+Jrii)d|smLEU2sMW-t|c5_HuM zTD*9IkBD+Er9C0#`9QV#-&L_q?_;egO-L@TuB6m5wsi_igm9wCi@33n7!_{pPJzP0 zkWZVT#$yWsHEf&#GLBGH+m?oedM~aJdycHOjXc!|8KdRJYh^#z_32&Nfo0YrakkA( zP}~2?BLH5j@oV&BFb z8OSRB<~IPHdJe^tiUMw44w_&@MMXQF)~st98`Tv&Il$nTsJ=!`=VUMjw}qW@U_$(_ zI7ZAzO;s@dN{Vi`QtCo`=2f>NW~>l@AwJhLN!VCyVkAQrg{JDzaN)KqN50F3yZPJS;dDs>0%9K%0gth@M zVRNh{A+BN#jSqP$iCBmy`0B(x;|Ymc5UeJYIJg3*Qm}v=Jhs+}*9>jRegruv6Uy_n z%@!Z9aeb!YO3?Q5BV1ctOMpe?kAwGDD5crmlOz{DLtsqhcY?5~-hbEf3CO*IpXyJa zH|j8%ZRmNUcT^VVV`0ASTQzLu+vye6r?1B56v7f^YJQp1jKZWH!ow=ds*Q0^x< zxN;gNMjhmim<~!QNQq2*_sl>g$pGsT8Q9xiIIY2P^9YKGyM9bKF@m*Jc5 zzDC8{y6ehEvXZXBl7o4=p5xIOrT7}xT)$N*k&LH`yqZHfg|(H#$+!K2IR)MkZ$+?x zPeh@lbe3x6{BU6b)EAR0O=Dk{<-VKuCgvK=^y>SH`j)>M^PJbdY3wyxd1n5}qo5>; zxab)dJQ(RFV-=&?;a#tjN!d;hzv+s5yPF2v#ZE)&l3qs2c_}CHq2y;%4;-iw3Wf^n z6J&_POh$|9N-PYrN+Hgq^mH1!QmiPX;>LrOmWHXg>eMtPpZX&8NgnsNBAiS(Af*&Q z2x#mw$cA1#m#0%=s4j!p>u?F)h>+~M8`A|f5J%SUqfDdG9|lVy%SlKWe~&!O#UdT0 zMD@hI4Y#91F0!H2!9dP^(~q167rkZTz)UA49igifIaGZk8st$CDU44W5yZd`Y%u09 z@cg(87Y_vnCWF7pWeumeOWrCmywNeyC=;pi>)EZ^_=#uCqxYj?VFiYLDv!`HiUe}5 zBfZ?E{T!>L8ih`vCL0)_Am?}{y$UuhNV^m=Q#^EbeN8L5BRP|P;gCw7R=%Z+kE&?w zFg{qUn(qBIg05LdV3;FwPx$-{Ni#0rrS#-UD#ku;Qa$2Afw_dAU0i#)b1tF$Q)J~S zp+fn<&amyVFM5{3&k^2LpnA4iQuP?)JJ5=pfr|^gp1^Pbwhpi4@U@x}czhAf{X;QC-vNvBw z;x6QsGm2se&d66Hg;x~eNEeXdXr~wESJ^nb);+PK1eDQuA>zeUM1?uh(sbVL|B#K# z2p}q}uD7zxV5^OVWwI+KS~yrdFuyCqG*w@1X?cT!>S#jH>3RW+!eaPc!n(eF=NoSh zqvpzN`3^AE;|kV+V z-Ncas{T~{z8?w6NDbn~Ow`#Cm=imNH8DdKk9aPky)h;b}cdXvZ*9(@-mkIw7!#gVW zK72y_PMA)6S6|7Utp_3NPy4~Cw+N~75lOcR#EVx`7X8e>D?^xqL_?=xh{@~xMRjan zy>mVX%l0*=<&3qahi`-kgry6?s*mY59D+8gfGb++K7LnkC1vcf;ipA~u1U@>UL`U;T2yzrU33KM*N zLq_(Ch*)$rnisyf8#nAt^cl2K>_3w=StpH_*eH~JHtv_FsDITdS%GVfYMApn5Y9X%lxuQ-Uz>+X9_dwuA3wFi>XKuxe*s`#wGLa*AN%h-*T3ZV? z)HZk=P(NKI_<8{T)#fab;oLbPs7PO3`l>RLp7(X555wO`yp=#*L9QA2en6!w-~ccs|v$1Uw~R|I2gBXm3VwLnFjkcd2t{NF1npTd+`Zw5m{BRdJT z;YVIkmIaZ3L7r9cuBs&2(~3q`7djHDY%`FAn3FNPr;&>g;oc>s*)t%6hr*b7uKrGm zjKR8CL1W=^qzqVap4OViszF$uNL`BADW=1dc`G_k`1)7o5dY=?;4wOoQ@`W)b*Jd$`#;^z4 zXy<5>QvcTTVdjfW1n&1_wm1k@McBSuT%3PeO*8gHwgu=MDunw*5H1uH9#&W0^E1zo zfT8;Rt9eCMrE5EiX@9ri+#aq=75DJhK@ocg*Odv4&B1x9MQ&nb8>}OCH(9ct`0%;s}}?pbvj)kIc+0**$B;hmoF^aCD?ysx?D*Q)D*pU6-cI_JVAyZ`y(O z7x?hI>8gV*wqDxZ(rbDzW(ZV6&ZvDxBV$4$e!kg8HmUBvd1wm__dVXB

O^g#J?x zN5Ww7UEPY{j^#>Zj`zC&=sQP0B4w|_iOByg%G)(dovIhqEif-fw9y&3SRU+Q|BrtI z9+bXtN29@GYCJEB1>jhd?GEI^5$?aIh48TN)17bUYDuN9UN^QmzGt4mpAD1W#UzTE zA7&tD_yOPTO)$icrFLuP<1zo{VQn*i_ykkPY-ud(4KZ!Z_!`IxYpn2(# zn>oGU@Ez}#dhu|4e80id8oQefqCmsz&K2WV{67WzsAz+CFK55#EPh?-B_3t2blQ;7 zZ0SYb&ytyzZ1=zT>T|jGf7iJZBj*a7tOxSzs>9W0`U^C-b+I)OZk^t9M?E%@w+o;;!o=S4KKrVp5FcaVqYLX^kt-(NTa zZZuuI*nu=v@_n?Puf+@in9Jb8G-eZm;>nDdNm6Qu##+x<=$@3?>kqV)$;+sqa|@G$ z0oXJScMiMqb>kvYRicP`atBkRIpqfu+$1xF@&9J@0*{eI9U4pl0$?d>55BDWDpRNz4^M5w3zn4TPHlrCIvgCHH`b0b>Ygy?p`DP? z{hK*S;=&?l!IpFyO^wV3g1D>A;K*@+$I7xVl9=8!fyq#`gvO3p(u(5C`Z!P^pcvMi zUN7cUBjnj8qab=nF(<+~p$$-P#NF1gH{5v9uGsfy*=v7giT-9Bt>5I#m@fS)lHPu@ z_XN9mcM#j4r{NzbDOveNx@5PyQMQktXSo4!csB8rI-PxA)Jn}dGQ39R;DB8ubZrdJ z;~<3&ZkM+=6qZjLQiMo0=zz@^@09~kV-9LhXYLPpglDo65{xD|jX*8rueG~ozX=jt z{=&*FL9E^n_92{XQa^0+U5V^aS)3V&M@1)Tc?Z|e5J2Q*xEC$vCsnE+c=k+;_jrJx z$YKL`#`1}QW2H<>Z@9qXK=hULd0w3MsCS0+^RUN~csh?t$Ps0BTk#Qd>}M*A0+%iM zcIh3{U(ULDJO8J&f>7T4(vsfEh9^JBi96I>kLg7nnE-Id^D{O#Hf|{=L|)SZSjy2Q zX-oBW^*(ud;;E|j-!xiVh7tV!{{CTMYK1|!zTfrkJkkD|wjjh-veC_@_{n%NRfZEP zizv~~9`<&j%?qsDe0zZG8{^K2C@z%mD`HArq+QRyqWP+@ZRMXpc#kmaLtckLJ&nVV(;#O>A>Y^{n3t7`T8cT@PPrM^@~NJO zM_PfT8=KoCOz+Hz;_NaTl;7fu(+A=M;wLOC5^h1*@HZc>NknrzpHDc{*K@CpQYQ(= zlJ5XZ7tHHx*S>aQmmmc-6qTz@@q~7ya+j#v)f|7 zNqZAxmd+n&zb=n`74NJ!a~j>~g?t8S@q%1zHy=kVLjQL{Mi-{vuJY{%K?;I4#C~9d zop1SX7V}I~Ksdv7=9hih@CmH`4HaZO7HSe1k>8J?$l(I^q4Xi6OKoD0s`Y>na-O`x zbTZ9M8qV?U6r&x0X3J^vNcDj4r4u&4!i41YRQkxxzhNDVwOuLKjPu6j;q|b7MJ9~8 zF6&xgX3ObA49ft@FpJMK^0FeQlYT3*9pqh_@6fxM4FY_A6)!hZ4 zuG~8$yM9xuDQOW8T_l3`$AIMCMDNqVR#*>=bokUQn>M@0RTAnuG?REWU<}b!Ec@H~ zTnB|%QBwb6CF?<4g@X!A{T~$U%uwScV$Ed^$r1)aBcr@nCuOLnUNOgGZEt>k`P3 zCSs6IP~u@-+0}3;U7(n%!2anY5?*Xd_0gIv`TO}K6OV$UQ6GEusczS2V(O^jaB2AC zOAF2~{_ntvVG*X9Q2zn}Vf0;%p`G zF_-aOfIh!&eqlaX1QUL(^6dzHxhWy9=!&aTU}4Dj@i3QQiD8imx9+tyD2J;p$f5T< z2)+~x+}Zr_N$Sv2QA(G3&R=#e9|3 zLY<5l3JUv`0Svzb^t@e|mqp}E-8wJT7b2opgfJ|5^Lb?@ebJ1dzzSGrTXht1fYN74 z%F9npBXDuSMiyONmSg77cV6ckI)g^+!kGeaSqIxI!z0{Jwi0w~P4mE5Vy287)pFl2hIN{n=C03RY9Zt;` zhx3@l(ILCeq&mI{nP>?aZGq>KITx+mr8ZHE2G%7J4IhfSMVp!N+NYa!-NbX?w#NAq zxcDb~x+eXv@;}C60!ZQto|pt}kD=N6X4!3|WaVTpfv`Tzp1r?c=- zc!<@70)D)I3Qgj(4My(7lOG=^cV}9`Y3x<{u8Yt~4 zPNbDHTa}_)3doEC=W=8K>z|ult;9!Y$RVKA{^LJAou`9}L_9sSms;B&Q%7~}<5J|#ez%W6Wd zky=lz4eEr0SX4&gMWWpNfHc9%9sC#e&qRdN4`>5IXDe^rApn66UqXku^k#6PjoEA+z{=j;mf#WBYoQ1$ka1!k3rSQ$}69xLXayx+^sTdi{}JPP+MAI=P*f2a%tbEK8gk#b#4XAjoId(@nKR|UvMtga8-w6B$o5{Zw9?Y-}&reLLUrs z>pfo;Js@SLE%-6Nm6lrmnXj<3RG|E0Am6Z*c=~ z@iid}O{-m9U^iN{;Bq3)5D|nvnN8o;XK(5xj5p@PVEKr3_^793)*^B_S%!|n66h;2 zc`al#Kq4j{2*t3byPghAf1PGvE9$*e>M-|lMLMoB2$-%ywk~d!Gym@1gec&f{ssBi zMAN*QCh$e|EXn^uQeMCAaRA|I@|XpC@^$MPd>TFE9rKrQvFg!tCJSnw5AD8-A9)f~ z^&y504p>9ztr<yVxj-1yA7Ix7C}mrB2Jo0zo!F^V~vxzxTS^-ri&; zm-{Y{9e+!(t@Ux=VpdKa1;|>c7i1oRjQjd1Br_cjC9P88h7FxzuK6wd825lxLe9*O zKdSZ4uk@bY;^yGi90Cj9)lh^Pk5Sx1c`Y%^kx57c|MmsYxhd~J1e|$WNr~!R#otSHjTd^9cI^>Tu zieRpZPbZVeuRX;-IFkfYO3X9wJ>2n z$w!c88-etMdO-M3HbQ|1R5{4EKUt|QeCOzG>JhX6{a4VR?w}B$Uq&Fx-9HF`3)#D1RCixWz%#G=&Y-^g%K1_QIevP>jzDQ0;Lm2_&%a2LqVDV4lJYQ*9sULeBwyXsbM9+@^5Dg- z(rSP5L?^ZzNH9K~&SSH|k{(>EGeq}~;nvq~Q+^uUIztSGFmw4{ApC*L>^dy^d*3)@ zP#f#dfs~$)U28Z;22q1V^wJ)FyYfb0_bgG^dOMI)QvC0SO3~ov@XNS9%4c_Mk7@Y7 z)wuMWMcd-W7ZKYUj{m&Ov%!=~SZpb^oVEVY#b420OwjNng8+bUwFkNGpNZ(l`*WZ6 zjvJin+~T3{6OvpF?t;c}nXk9Ol=p)i+y>(xFAeX@qkufEhh~FD;6y~<6rte0@E-v8 z;a8&ZMz`|(0^rJ z%thY?Vi2snL4&9h-bpYnx9k|v5@Zw8x1avah2~wT@>9!BkqsB`=)Xw)LjnQzHrxJa zA$v{FwS)fnvK{s2#7(|WXb4}m7S66rK4)G8YpqDxmPOUtR0eB*tiC=!mXU}BbYCbz z;!${fJW4bUGZ-G;LlP25`oWi`K-=i@#kaGwV`64jRYfR4{oxQP_m5n9O>8`M@x~+7U+S+#1$2B5T~V~0S8NGbgFFRjVl&IfDD(!B zEMh8%X?SPCdAiVCvB?H#U_@bL0;KrrXKPf`;X+;!P|-0icwFGLqSC@VB7MZEA14VY*Y z!>)2GEwcs$Xt>&ERg$w3kqYOBOP49s3&_^r?XOY%2#eIe z#WX1U0oigBVvfmp(OP&fG)ftmA-v61`+QVz%G4g8^{QHKw&dz1-#V z8)r{LDd`U|C9#7>8^&Fez~ymlee%bKw(pI3h@a@s&(9;*2YYcLD!KWbnj{R*J5Rl#;>L&6 zf~_HL#8~h0L2lw_i4sk`MfYdKjPITTCu7&mZumd(mu%PL zTu%C;UBlVvc?vG_1&hD@5U!D&p)}QhTT}Y?EL~UU>#E}qT8T3`5QJ7Q*$WAJ6PmrA z(GIRMVwpr$e;;a1-8m}6fDs#%iZ3%djl90yIuNJ`QVq>)=P=yAJ+FAn1J_DHaUhJC zG^h*+i{S`VsOYb_O!p{JL~SC36OYT^&!<5O{6}bS$%7cuUJt(YX+utMAGg1Vt9c{( zfQrDjDC+4*@MOCk>}zo)Ty_qV>;k)SOh2@dqvc_t@#sUteu_Um=f00SzpQ@}rKnLk zy!dmzZ>jdlw?a@WG(q(da@wXa%Cb&Oo4hOKZ z@hOP`Rr_1RN9?kO<85N^UW%Wegr8ieA#m!xKnzVGU~wGmy~duuy%*W;+4S@Kxor!6 zLX-mkYhhF-^it(BaTXmQySkT@@`a(vW+Tws-PveC82wfpZ6d3ih}OK#`26kOVcQfA z$;JzR2#oZp!XFv>u6-vCll(UJ_tsw` z2m$}*19D*k+dFef}m(h2bPFE`FyeB=l`qk(PnMoEa2W z6z@;&M?7^s{^INP_}N*yTr8j20@b*MKh)Lvkb|gW;t&&dm9KT9aa-_+2ghaKuZ?hWiDsXy+UC#;k)Zdo6Sp^3 zm8^OFxd{^?!IF-o zoK};|V-M10Wf_XHk31FGt@aGB4xToIA-{Gvj_dhbNvr+(&1AV0R4`tPqMe>uXbwcG zK86ro8;-XC&KdOi0=VlrR8zyezyG#|Pv%ZuC}-jJR_5|Y-|ODcrz+F!M&4gJqfa2T?$&cU8%22DHIxKz>=Zv-j7_e3#n7gz zIY4W~?uB+WhR9B!Iu7>vF!1mP&{kI%EU8@W=1;dW@P|5<5Y@Gjsw~7@Zxc^zWzyaW zX=n|6e9oFqne2fvfE2y1s`qFvyYooRRzF6+0db64IiO^YfGW7%4sSWv7lrt%i2Zv{ z>&m}fzwXo?X){n4%UKZ+_`AL48oo-hIbq}UhE73St9Q`gEx{R|DT((qcQiRE$w6Hu z-3d|VFZD)AHPX>fpN8ZpS@olj5aL$SpdsfHQRkKgXy}%NO=yR1&mT_G`n;{uh33wh z#sII3(QY^m&J0-t?(q_2O4q%umzU6j=t!2Y(uxtN}8VvvZOw@WriaqZ@ecaNkU5dN_4NJ$4*x4-#Ild1AbiN-cFLUz*rG zN!EtHxXxhMVJBH+GE50al)oZPvVoVD2nTvFNovqY*7V z@>hpr^lM(pw7yo~Czrt$RC+$TOvxQUC%oxmS)2UDbiHR1e8%7$tA}ph*9i2< zbh=k*dG^WQYbTc99jfFh%}QK$$k3VJqFL#>I{lESbX8lP|BJXde__79BRG0Anc2!} zG38)nWOQd@tkVGo4&J)4u>loV;-mW`o|-`yB-4||%(1!+-k|y#+T|geWai+o1IcYR zBzFe`7?@_3McZ@0XJo}A7ZwOi#i7XRRxq58rUQZ+Bi`*`%40ujJZ2#V^t+>jbxDnV zu7vjZkXR|B155M2XAUEPQ+9*7;}5!`D`+F-Mp@)tv%v9JswX5TM`UfVxSTG7|N7UF zV6e4dvH<4dfFJ3Y=-sy=h3xf{!^3fkmI-~RpOFkv#j&pvUqb z5|ith{fh2&%w!J)&qHVLNtd9qY6v;E}QhAb{>CiqPnbO z7tr9kG(08{eZY`1OH*N<^t9@ETb3kJRN5^6a@P?*+X_KqSt}&eT!7+W^Z}Nv5KMq~l9fW0_9T!gMQXraVnrp(K z))J4WSziC^)mcG*f{$nNzQD;e`xgwmDzrdF9-N0~&BskxR!34_W3ky+V;t^ZUw?~C zH2xv%{~-M?C;x-=_t#Ck(0ML{WBa|}S^Kp>EVo`8sY$91re=bGP-(6D(?lQ)C_ynM ze7GxIYCKGC9AOG8<#)wi`dVga7xma(;tdlM#0#d%ineQTi2esHKY=kZ+vZgH>Dl8@ zG&W`LY}RD|9G~fiOAGJ^xjdD6Q)So*_XT8Hc?7`EEKgS)nZHeYcehfA&(6i*j!skQ z|1kps1LRNECp**@-fnoe2TzIEo9En~BPQoeFCz zMTB)B$LlJAiIVHMFfl9nt)W%g+sl`hmXPOGmHhkY+x@48?*g2M`szjx79alaJVr#- z|E7qM0*h0S8XjG&{S+0&`yra#-Yd~mVBnorzbtS z^E)&IlVEW{SzSHkE{mx`|NW=H=MfFu!o$p_Go2TAI`y%dQlm?7r7-$Au%v?yxix+1 zWIOS1CAV#SSBjDJAk6L~|PfvyaWDN_AT2g|^C5y`9?=FQ+om(ph6^NWSB36B^ zSp42rCYRILUGUdFx$dR+3Izc7nn8Vm4Ah3pIz3q?4y7h@Nd=)CV*qb~mHX@VUH`?2^RIf#&WYVkkSSW>g2uU@; z9&BCG_A+!_pDl!G7PIwpAW&nI60)!_kk8j-@a^o;t)gCEBdcQH%47lzNf|bSI9>OD z(e*ft#|;0@H%K(IS0>Kc1Me*yj!SjRSHj^+Ch!ivzsOcZyDYVq6kilT8ya7UpLY+X zxa&Kc$%4keWw^G|_#y8#{19_bbft1@J6#EQptrj@Avv2Wd!98{-}*I4eQ0DsDEq1l zZ}m?UoSwX&M8;;N`N;Bze3)i0BT~|Rmml~!2g~ckyEbVk98Gw1I5w+1gPs(9-@bi4 zNQ()pWfVi%V%<>X=SF4`9i~d=&bom#M&1wK!$X>Od6en(H512JOv! zdx-n&a8DdQ?HQUtsk5+!SI(FWH2&_epHWp}E`essw+N-huw)hVwGB&AK=EH`FGZ*q zFnZ@)TX|+prwdxI|_4z=NPrTHHYu5d`WfV0)R=9# zOS`{K_6{{s7py8kN2loj$G`S`v%m+ASpAK1JsTS^1AaVqtT36S(?ZJtD})@iDyy>P zLX!?WfNNU4zs3D|ju_JZokC>^`a;0B|1x|WHs}-VRN{7KX9rp*k#N&TK^85_?vYH$ z2rC5aF@j)V*BN-!Y^7#CntIlRsX$0)6VXG__h}KtwpSLhp%NjLm!hpP8Gr*BO<;a9 zcSF)VUI`pIx+=i^B;s)Ux>CJ5ZvP-*6Tmfxd8U4NBjAm8sK-A$OM_d&0L52In|!Ev zYyg+*zr=(B4q}?r9`VR%zou7BuFU`s!zSl-4W_r<;+m}M7 zG66n4F%`i=@6W@S4cGkNF6E+UTxXP$BsY3a&p)YX7(%HyF`JQegZ*>%maqcKc=#lc zB(EMtJ+iXk>Gkw1t*wPr;$xqS2-J>-49`=l9T}UX1pEmr&{40wiQX8W3-W*vkm;i< z_0EiUkG%bz<+$)96ev-Nq;!As#FFBMIj8pBq&^gU^k~4oLsW<+CZvb_Q9*?#v3|6| z@x4dFVQpiL_50$t3p3A8vvn3W$0Hj4k=OERxk)c=@Jpuf)S7{QQZ>X@6PXM5X!oWI zUWytezlaJuZd$*0b0;{oy3c_nDfx(8kQ3Zk8P+LL)M0ne_h9Lhe>ReAgTEQM8GO%r z>^*Fov4-V(dQ8`oTR3fm$MOv|T{qk~0VW}i!DRRp27&Ml36Y)I*jOY%Pa9U0Rp)`2 zA14;Fb%e3{ZCxKsUGxEe3qHT(sh^ic9JKuXAMkWcD3~#>Rxw$U<>^u&Z^8n8FnU@@ zeG;a>Bvx#rwvx-0l0c+MPFYyMPM;^Bymk%e=#)+nmejDfTnxm-Y7of)pj!m~Z#Fj? zQoO>>+EOY36)QB5=KCMejpe#QACuYP^t0P7iSAkhq`R>*hJhW`mjd;jqRxEL?1Ns^ zd_sw$Nb)C)jQ3@$}7-1DVQnm-V8Q%jb4@(VF z%ECPT%~_kK?B?MA54J0tnUVq*468hX0=BtkNH|?k>ZO!DJ(-)i8=s3F7Ji^6rQSG` z(3p^~XOn=R8sVfa&&8!pzW@14H_p^H%U1P{oLINz=9{ZuS99{EylUsE8i%?fJU9A- zeKF#ve@Sui>^py%z^vAa0}n)#`NJDtaD2Cdwm$Px=K_2VL&_NS!M4z34QooJb}XZ& zT`&H=g6Ogavau0$8&XanW6ES`KnC1{cXzOvv*^v{>*`APBGgbDOABIlbOOVe1&W&5 zF0(6h$^eG(xQ=tp=m3H?l|*_Q{g!?coSXV?%USYoVQ0J+b1lzgr`04&)gbbx}Y&ND=F*`=LDp8lQBAbx-Tz4B56ke*!{60WwlCbTF^ud z^n%ZI^u##mtq6i1Kb{5%d_}yaCAm7e%5nRBI50G&r;C)=;ee6z(g7N= z(A(3;Em*G>uoG?k``qoPdnO%CYK<20xU~3MoBmF%4TphB(ATCpcMp{%^X#j`3VcZ0 zkkew46`oc;`;nP)L5-?sw(!|g_Qrjs%e99k{42MsLMi^)=LZHHsXrxtg<$D_U08Gd`XyW#@pPnI&6wlz_3g9y67NClMpak02P}9Nz!nNQ zI-)+6Z@8_?YyZ8A&fwFMeJ_<^xSg@%+a}Ty72`yRe)}ijMIPD3KFF0XF=ZjBtXOg7 z=DUV;AGpu!YAThoBiQhv=z0aZ0Dv1+0*nwLhXtC5Q=spyUZQ7kjmQd#aCc)B^ViE* z^}Y7O*4a|(+GS-cZHxTkyt;2F$2w?DX+6ty>E6fc5XRmX;hRZ(mI^9g8H4QhKyc+4 zVp?_^qb~aU%o=ISD#sfJ!pF$=WM(HfwQeUc|Ce>D@Hh(ZKKp|~0I~8P)@iBMXc)s$ zgQmb3ozyrC+twKrB6tD;9z!`TE%n1pDjG>bTNsi}ZgRG(2(hzYjYq?k+5q=KOEH z5<3Ue)3UCZS}xA-M!VF&xtT!L^{cT8s&K8azEy4Fy$*_Ci|<66XHa_T;-@e^1n?2X zSZxm%h?`>s!C{zvgZ21jis~A$@Tl0B0Tp#JK-~1aL|JT{nin#wBWv4NjO?M}c`|W* zW6+IR<81$C?GbmYN|PQc^`V37Il`wSkHQ#_nKWv+Jnc7^$JxdEA!(aDAw*(qD!c1CaE9dF!vFmA#aJVl!qiBd{;g@VhQu-o?h36uwc^MfWjKXh|RJ$7HqvhdLGd5%A@m))u(2&BVy7%=ZhfiwuWPw;) zMJp95wE4(Y12Dj<%Wu^%H##oWqUzlz^9Zkf);zhi*qIYR_+Uj^BjV0RCw%lvFF%Q} zh#?L|F_MF$()*{{huc;!6>=1mf8ee6lgaLkLVV4~xauWPH+UqRYsJMmEW)@1{C`M6 zGc#%>R#V%d(&EVmQ-eFPkEdIg49`~BxP(Ei-o_yHpzh2iQ~sT@cvRvD8+QB$C!1$? zn7<&Bt@ir(NH(vmEZ~VD+sHaUD|M07$PKMvFHsrFwc&gL_vc^k#<`8TrzJIC<%{*q z4SO~f#q#CZKcI`p8+U~H|Gu`30;>?Lz67iAC#sT(?mtf@nRO*i={``dzE>se@z{AL zzTV-^?zao^mwDv^g|1f=z8-|-4vy-lJ&s8__}cSwbj*dhcISo^^lP&C(s$`Ig}cK3 zC)jIgGNQiHOzCWck`>@JyH0ls_-RovqIY&{1BZ$)HU+;aIl?=dtdJS z+|!eNIpg&3HmV{2`X{Kb1?DBQ6li6%=Usk#6=jE*qxF+MA!MA_efPlCUQA4U=l0_q zP=Cu?boMwL71XYD{JSB-$r0n}s|7oi=$V{{2jTz4g=Rpw(DMbk3EG`~?^FKts{`GC zLK8VvP=&Vpu!az0DS%+~zM?oMR_~(IE1#-!7BIq|G);_O-=dBtdpBNk$>c5~?Ys2i z0^A<$k!)bUKgh}Fsb6!JpQ(f;)P9Gw_s7fifBh=rY-nuyp~+D4wC4+I?u6SRrnOusR1ldTYxiXj-` z8rlHw;}GgTsZSHtrIobFLdC|A-+ugVOW}BMY4|))7yk4_LZz@;W3qIC@uilz3sGWa zvne)_!h5=&=%$gz9r$4eO!~*Vc+j0&Qn-5K>{|2}*vTK&eTdcj+u@b)Kk@iqgk^X< zOfO+jnjN5-g|K>$E5+*tmCAKS8|A%O1kvWeH6S2lo?P6j={PK9vt4bc`-7hO%t)g; zPbY=cv<+Na7tGFc_gDPC5;aMg=InPk#XzhNX!1yd`B=T4{ts900G!zmzkP4Fwr$(i zUE8*8cWc|WZQixD)z-$=#@5!;--CDN|IVB_b0(9_Ig?~^l5ehju2>+qmKwNdDEWim z+{cw_WRfs(Rf_+|!pGfhe8RB|35F0A&DSVg$FKmYT7tpP&vCL_jh%dS>Htk)?$4Ed zB8*nwt*;NePLx3(;x|TO|9Ew9O*~5Rv8jD7f7`x2w^t|v2nj*mhn0V1BZHco0DlDR z!B$VlTHOqo`sN8c<9b+3d15}|OM?X=2Mmp{oK+%Si$k~1RS;dkFVGuo;jwj7g)w5r zGnVBUy_g8$m#YW?%o*h)v(Ug*t`~OQdj(4#OQV-0tj8beFFxGUw};E{-;^+sbq?$W zVSl+#RY-)u;A+b)ns z=ZWodl*X;&Mu#hci?tzr@29;*e20Sw@`;)JzP&-L9DqB7RH)rTxs^6FLcJF*t-n3s zYJt#T@H6^Jk<7jhxusXGjRR5o_M>skh2rsTcryO2R*!&ka`aNB963YxIi4F?^m9!c z-B3z;-qC$>bk)fcu`X925H`GT1o107{OXY~{Dkp5WkN9pKY(@=kyLCIgI5rtNLAoM z_lX%HhcD>-7;%5G?qT(M?&n44E@Y%LaHKDo=@sG;pC@i}PrzSZJmV~$zZ!El`f#%0 zc!j^+%boJ^qX|KW!$Cq_s>8W%IjKl>)mZmPNk^}x_Wvm?l-)LJ z1!b?vFZg}1*XYj-ZY=tu^Ik5V7S2EXh1EkFs{IYmPs1xxK08cIJsXk4ikglWJblaV zQ+I#Y#Xdh*Uo~8VVCLjB39CCg|GzfO=unWzByB0^l@)x-`*0U|DWIkHXG3U z9~*P`KqEUUD!X@`tXgs;u7&ny`W^jRno3dDR``7VKAA7ViURQ)PvtbFHn+@J59ETD z`1KLgMO=BCJZG2u^o8){@MKfF2+;<`vy&R%w!5K6d41Q5t9du=@%+&X>xYc(uav?l z$a|c*dOfOt-?E?~Z^N$#s^D|GAmr0_PS<+X8=&!eva@-lH-^%phID&@@*%(bJ|&Ux zIj%3MCeP*W)A;jKOFrZ2kl>=*kwD<0BTlcJ!SE)Vaj;>0&hiuR-4ePyy|~caOR-&c zlie)5cpDsbf&rbZTVFS1kNBo9P1%Q&1F+AQr`1el$7s+m8q^UFzaKv+m8j|fa)rUW zDl7Z5({3jv&ku>md#4YdUqq=Xd+U+-?HDOheK&Zf#d-X`5FWdSEnIGobPPE?vDF*u z0e67#zoVdYSqtrl;M80VPlzEF97{^*{f+0gcs#yXr0bl%J~nH&>p#O?zjWHuYhsD* z)wq0LnDee$S|~l4nlkw;GnW|^W@hm>5DbR*Fgu0R4(tEC^=*Hxd}!OWjI(N1Raq;l zXoP2_5%a)hhfD{tprJ+EfNP>0kcE(*4Df@2J(Kh_XmaNod3Vikl8L_kmH6?-$4*Pw z;Upv}J*ATKQb8xEYRM%{YmI3Oz4sBEP~E*pLOm{&;?E}iqJzqfeVaUpoSOvdaSZAg-jP(j|>P!qJ!>X2g3>Ab^}!goiekC(0Si7+=cB1tzxV zY&yzszHu3w(T?|0Yu?l(EDGLe_uw5+(!Iyib~v7nIh6L4K!0U~H190Ro_|cn_btt* zn1Go_ejS6|bvms`@*gV#kr6$EO7#zI1jXo9wEm%;G=q#4hX;znk3ZBUfwF82p z(xkMML|Rz`_Uq9elz(S<7C?xa~*uH)+Gf35_q8hO0t)6IJ zeSIkTTJP%GkV}~l-<~z+e?(L)J%PNSTq%)FH>=0JJ_OqpT;B)Q*Tue7O})Q@5)G7N zLK?!`y`K;W!hRRZzQ9TS2e1q(`VV0FCyw?TV0qiT3SQX=1uIj#ppI$+>U2fW$L}XO zj=l_BDp&hfxqxla(f{i1NlX}tb9hMFy#BWB_zx9|ze}rd{?{8MVg{|K5|$dp31m>% z=iu&*4^9lQVZg!Fr5aNaAaS8dV){0U)QUeqmGmt(emTYjSF%DTd0*wx)S@V%jTg;*3I>I=!!HK6OES6=8!Yur;#>~)zBsOkDCvZi=qF3>(&H7M4 zT$E$_>_vOa%~IW<4`@C#Yd+*Ro$T5N@7wW!nyiio;lq|@+25I&cMPv(B?EvaHI>b; zaG?iQy=xZKRR+6*{xk(y6jj?>@Y5n_^5n=Pr;X)It2~H)gS}VbXf|uo5}tiCPQXdsplh0u@@Upp$~$ zk<*DqiFxJkUiNVN&&aj`RTD_4w}PKNKbGs2IIz_fY>q*~zXM0D^+qqM%KZ}y(WzJb z>b;p2*1PBnVQEhprOh>Ds33HV|2)4nSTh1z=qy@&mjsg*^#zhpi+ z^pjy{215#e8eaaRiO!@C=z)a{ubfR@bEVO*L3zHH^q{BFPPF>*OB&f3Bo6+beE(YI zg>7g}s*mlHB5D^2+#4ws&ZTiH|M$;c=hu_H??$cN--@m-Tsx;G1wK~RTfT4vp3J}&p{Jr@ z#FMfBJm=%v1oX&;-TrF357onEmbO^wjER(Yw^y>yik*qJdi!V1?yPD8h&UvB2 zR#I1$ZK3A1pMSE~;P;*_G@Gxn%x$-$z1ZQ*+IEkhO^(O7Et{^GUOm=G$#+mV;<|zj z^6*6PFG=|Ln@}{I_2vTj23{b=GJsEru65(XEu`5_`?^2a{;(x7Pz9J27iIuF;bh%< zi6I&jINBW@>1>TegHfml->GyfiTL%9r?wZ(98Wd~#y_trl5+#_;*cR^u^>`UEZUC= zW%hqdqG5TOe6F)s*wsP`X(RbO*^Tb6d>gkg{}f22sj4J}kktu#e27K5-XSC4_YSYI z_04%R!PM1;4+)l2a7;GXIhnR&ic3H6A34PF}h42P+~3v^)XFKR7;_5umxZJvk&HKfJS!cBlz6u{gJi88aJ@C2%-6m z?JJ6`)JH{~)Iad1f0-%@L7ah;@HCUUV$PbRY$oTYyE9W=9&hN$swmkOPgoF?&3%?J z;@t&`n|(ptGp9wP|Cdk+REFZzRPcAy$rr;xD7|wzN;gHJ5UAq)gbXi{ACPQBu25B> zlzg@XS{t~^+!ek@gh=S?KXQ|vrs?8NT_qIos~7irwB>Da$4XcjpM$GqFeWs5N8F6y z?Hx%SPev?X+w-~yEg)=Y*<}5s)8l3o0unCIDx{m=Rj{LjPtQDoKR?=~P>+j5 zY@WJUv|pr>@!m00Hk>Myl%TKdi%6-oqJ2u$4W_0x!zvqW9pQ}Ye;gv(%LCaI#|l2e z!Fnj`M)sI$C+5{b}9IsS|WY7oy_SP}8^ARh7mHs0Q2 zt|-$x3QYrVT6@CY7G z0b`oVGWi!#_U!Qlu{B&u%u9~5eCan(x0GyDNi9^gO<%JO#JwtFF|xD_Sv-+dt=>kK zSz!>=yJXW9@W-10MM182g4A&V6z;dDI<`2935I$pZbjEy^*{m!o5;(Nuty8ytbaVG z(chf^#<#q(msPmCd7USI@0`Je?m#)2-JxXF`7uMF(rEknL(>M8%%?j}t(kK$zZ}Hw zKt#717vayTiqNMu^}jc}5LJTDOkvH9EFnGjl8U`1_LgDVDn{JNlgV2S8ZMuEt{@Ur zB+pYOt^p1#ff*1ABS_}6Cp6ib{AfK&&{^|6aal{0cxqpJBb`+%Hum|j0NlvpzWSj# z83m%{CU8}56p=YUrX^RZTq7dF9&vf27U6ePdxsCy=Id6=%wG~5`FV8rN81FGC*N_ z<^ksJn>x1ojc|xbcZPx{xqnQd*BNxuZAPS zZ1J{rv=PtZa^lpIdv4C8U);7Dya4jGdXYUETY;s;u=2!&`|5f9&m3j`m3nWCx2SoB zPRRFp;;T;%yEmD^t6g_6n_h4tmpDr&+(FOB<<}d8jB`!{09$UqJoj0P*%;)A9tnm( zk=UW#*mI&P)*t8bx&yEL<;-3F^am7X^Hi^pgN7u+QQNGlHa!p)1bX7fo#q}+uA~fo z7KX3AE~`G*B<}W_h|3$r?ayqIH^uWvB=}41;m1$*JJY-PT)u#xfMUqvPFI}Vka&x2 zX+}!C#uti=P9sA14=0q5Gfd-^DssuzvlusTdBe#(Uq`gwkwaVuVzlGkiHcp zvEDN#3-=(;uI`lj;%RxL^i+}};zA<>GzCns0}e%VM!TMPUEQemXB}LPg+<<` zLzA_cOJ#|{VIQ6AvtD4O78>pyrtc|F!L`|p$6u6cvtBH#z;t?Ti5 zpnrO*h7)=rVz2*gIDZw9#XXJ1s(fdF^e68-Fn;+!G&(=|iOLGg*Wm`uygTrGeFn|f zqb)4+b}Ve$excr{bXp8#Y)z?VFa`K%! z6h(cKRyyq{!`eqKrz?u-7yW@yvEWJ(AbOi{lWF?F-4>}zIm0sHW9ZdkmnLTohtDs3 zK}&UjwL4z)r3__ZSTiJs9U!2`#(Zd5^B+d~@M6x^7>B&_LX}oy+K+ ziuy#I-ggB5L<9X4!gljo$LmGx&8~Y$KIeMF&7vMhyap)DX@kMiZA{|FM`&F?Y2hITzd4znFaZxPNqCX(52l!uwmvP8X|AF;-U)`s7|n zd3x_9rDS+uA)-b5CoQUs)4M#Epf*Q7!;NS(r1DDl}^#9tPl5wQY9cmVpuH;g_`*%nb4Ef)oL z+Jt}4kaOBSKy?E%I(0m^?H826v^)qiq5yrigPz-WtL(+p3=Vmr+r@B=4~Xk=GX^7M zXOthk3z%z%b?IqD)aRfvxbeR~7cd?FZF1kcAQ^rI%1C}~jU*|P84p8%4|e`_J=@kB z>DWFdefy0=$8{KgbB?$(xa7Uc-$U;6i%?Wj`jj$Hyl%^2$xMc_$N6DKv)Z;o2p&#{ z@bB-Mk);Jrr^k7A+w7&E3i5bj4Zv-U)jmWqdZ&XwCc3FDZFZLD6|vdg%RZ%$`@CJG zpGG5Y1W&uv2!H*eh_mH)CzfE_eILNqmzKUJFW3DO^N|eA_Ag66R=>`jZFQUTI5q(p zT)l{Jiq3c)EYSi$(dH2*F9 zB%p-R_~kHsm5pJt?_jaRWX$l|Qcs!f{jIwTNLQedS2&7mrc><8#QX#I@NEhe4Kal? z&|k-)&F1jaSI_Q5yQ?To&J8DggqV^N{S#!)lEVW=w`QsW4_NR$sUi>w7oq*Y-+H4A zD6B$oW9PtsX&6EAw;Z& zXd8=I*mkxGIdN7hLHI%W9ZQ}f=)VXE0U<=!ODd~wIKgEtdIhDW@c6zq9>1u4OLUWsW zgWmOv%|CuO1<2fz22)FaZW9}W=<5o=CYysYx10E8oSX?uC=lAW@Eei&o=gG-%XdK) zXIgP$Vt`2R*D%JJ_Llk^I9i#NlJe7GfnAg#16MbnDn$C-@#5)?tcokkaO>;q4enME zy?=WO>nZvStY=laqv*c(yX7hzGNt_U5!i7xG@I{E9g0m=fI#4Rp@IhCYSxLc&dd*b zp2x6eX*?8eVk>pldYk>^2H&pgj-Zf&!(LqaT#p?Zm0q zmbz7ff=2ULZu|kkaN8)dQL#8Vvn=+)XY^nhmXwqfv5p`VZWqS_SaaF_fj2W_aSzTB4Gpz~-Xw|{KN(ZJ^1UUemS!!E{XUBHR@#E5p``(g3R(GSn zyaT-J`pSnher~|8}{p36OD;| zSM@J~HBF84?NjYIFCQ5H&B*Ja471BJWBYXT?<)9a#YxfEl3Z2o)`Sw<6J`E{bD3oe zUn3SRmfVC#gDN0n@=-p0uAlrI+oNcFVvmu7IT*j*gL3D{jC_A?m%^;^D%%;>N4J(Gl$A~o82)i$9VsDr}^JKGDGtZOD8l9&xPLbxQGJa#Ez04m!)DEvP3LeBJ#50g{#f1Sfm28swo-*f>GSnEE$nMnkhh_?BIz zL3usAFRaD=$^1`ASTXaZQ9+shkXjK?HoFU|BDZ|{9 z5K%uXMkO9!V0UMY+d%m^raUU#|nd@5xPN}GnY}bV-baI7Zv4R7b9Z1CG6tH}}(a4Fw8F%wXAVM?7UB`-Q- z;$UFD3@n9_dmzm17z^mk1a(DgjtgO98vEYz?1DW%^i1$Oni<-kVJ-e()% z?AomQzN3W!S$=PHtt3`k4maH=eGj1KIQI``;ssc0)~jlk0VQQcRJbaj;)@lt?olL0 z9JfubMh+Hq0_B3KICv^vfr6S_mibtoYyo3&i2Wm%E`0|kbJ}E56*qIV{D)C;xbcaZ zP~(fw8c|U^aB@?HBsOOA-X&^2h$K^a@Kdv=nP6zGNUr6`3JsAY;_!TBF|+r+o#{fWcC!?u$9j5e z-$(;I9h2uAf(LUDldYjbj4lv_age3zUOQS?h@*-1UOGK}u+AKU)_UV5)Ih*k;mZTM z7&3OKSBBUyL#N0{#eqw;+7za?ibu9uC*TABR)v`}xbg^dR6$M;6=ywb5j}ax5O;81 zT6+z}v5D2PNxh+&hTlzjWgZ9OCkV`>TNt=xohahs(j-r=vT8x0{KHA}nt5QYx-Bl4 zq{4V;V<7+KMlY5GL<^yL8i%1XEKyl&=}^0y=Ik`eWI3Ez{>{Sf8`n4RdSYQgEFJmW z>FLxY2LObrQfhO269XDk2p^g)l*(TnjEua_7fZhmva|%2+P}Cf_RollM{(n; zWrYARG~Rh~IxSIg%g58gp>{ufRbYYn4V9t<@`m4Y_zaG2(uu3|(p(O9K8ooR0UPd^ zA&0$!D^RFm6i=_E-rTJ=f@(>U1hjiIoz?5^5i}XFWLZkf&TgB?& zPuBsR)*#9%%EYgH^{2<)7SX~oMugEYgpf}grbgzH(;%-=vioCD<8j=ul)po}t z$^dSLIGwvKSJj}n_#X|i1wNk=V)=FD;Ksohays{tEsbg3E=-=AmDTty2!XOx+D;ZR*d_Y4tyk^CI zNu_2s4L%)ntv$qB7=Pp4EOrjRxB3ltcyu`D&_*whs@gnKenxqFo^Xg{gj}#sLI#gk zm^f3t5+rOZ0rkyWGnfA>((hI$2~Xy45|GehwzmhNRn&twhv9Be2i9f}Xv`#ViLt@( zYzw8j?P?^}q-!VV5y}PQO2oQjAwzn|v`R>i6w+v})XrN;8zxCLlZkou?c&e)?(Rz{ zEz+9nz%srKlkY3rGh4NUoj5rHY|Gl&q7;4WnpzT}omXlbV4atmK~ZHTKr<(xy<}eD z_HNIlpP3_sxb~~QQWsHs-th5FTL5*vGfQ$Z29&Zsgi$cKYcYkaq2^BkE&QUDKfm)9 zj&6?!j0yj$CXYA!7WqfV%Q9RU4E!}vvHTK=?nDo_oYQvDW=*xxA$1DPy!8I?hVvn` zvNW>ZJc*iWx$rt;o=24cE{tI+n;Yl(&v2tkZ|SYO?E>5Csdb?wTJ+*QN^t8SUC8KR zaLTckiooR8DY|I&ui+P)Hm5iDn`0b|H;=smZUeF#)qYi}+7h|+0Gg$?`+vOX`=ih1 zg!lX}g&;cU_X>2sp?+`FWvB1klFgG3Xo}UU=?bkH&X%ql@$JsqUA3(5z3Cy?pVNMv;#u;v`pV1iJ07 z7${*ho7pX*)5)w*3KL*DGSM^rWEAE@tAzkMHx{S!P56={jDY;~!0T_q1SX!y zUs+ERi&M=(U9>nz#Qeaa!y+PDYzM|o(bZqw*^+YgIA_cCkpZ~J3A%y>;&%h;CIPsF zVQ}`loW-(k&95iCHPr72^}}zoaGqZ9pFUn@b8Jn)8nBd`{0*pA!V8N1v_B~M309_a zMC)2vb@Aj(SELA+j*iVqI4Q$%7?9yA-g9CCDcc+ZD3wZcYcSv~MI{m8e@du|_ozM0 zy3UfVMi3f(%rAMoQRBUA^1Y4=sXMdjZ~2GdeXiuT_x9Wq#5i9Kq+<0KTiJw2KXHZ)0@4Tz5gc@-(}cM{=uTc6^v;w>Bvu-CQ(p7?DJP6Xj^JQM>t- zK?BU+y-7&PiuBQ6lbzV0iI>QI&?UaTYr4MKQscX4?5oAVFjwqCf;puyI&x>QTQ?b0 zMvRH+*^xbg^5DYCl?2!1+vk3jh34T5iqKtQxe^XUr0KBs`UJw;+rI;=6D`-87*=Wc zLc(Q!dC~^uHIn1B*&u9Oz?o9J8_?zoFeh#4_7}x=A*=oKYG7ni1jPN!-kmOASxv{%G@EEF9gHF{PK)()j_dDtRAl*dwbfORtt4e4MICj24%4}DE!xDS zF{F(}$buX*w%B~hWnAg=E4{zCFu7bt3H6-K8yeyMT=+)tu_1$YeH&P9&SkKb2$UgS z1$IPp5c7!qpuY>lVlrn_{#Q4!xa-SoVeEhhKQ64N;N5^m3X2mqeFA9W9Gs!=M|-`> z!B)9}&~{vA_;?1gWY~%T3A>P5mWmqvEPwsM;>1dZco^>di?{t8>jAR?kT>uS!q4oY>o1G7NJ#k)Owr`U4d7ba!{m8L;c-%CJo6_HYvnI4 z>MO^{ffA_GWIT@Msm};Y#R-qUTl~$)lVOum{hO_8)l7fcsUEXk3gQu?PQcGM2uI}$ z?3?1I^dfW1NcGtB0f!Z~KiND44nxxMS(do%{aqUTo0=RjtlzA!l zx2z)dN~hIi^%_e%hm=~#&Fr_{P?4Ly#?%2=dHgy9dZ2uCz|#usj$i}&WJUw zKgk8Ohlf)rzc-ipWk;;N#r7xa2mr0hiy@=e5kYl3NARmvZ?46G5qLI>s#EtYB3fn6 z3WtX~II0{(zyD_VryD&&nvpxD?&q7=Ok2{$PGdM9qscze~-K7Febg_A%9_0x*lGUv|Nu4e7LKmGP;f7_Riz(}jr z`k~R&WMx_C*XB1X(-)VR%UkT9f8&8&4MTbSt&jf1zNL+Xk#ks10&hU*iZa5t^6K## zu-H*O&~h7|;07(M9{dqq8-`Ka72xTD`}+7V)R$90wF=T7!paL5GfwzDQSD?ktn7F{ z7`g8q;>oYiFiF9eNmQ)8%>jX@%|80`qswG<(XN8k3@uArgO<|Y0crmiCM1G^psZIU zB_n!)l`^D?d92XtsUFuCMbmtf)PtFWmTxBI3Z|P0?Y-^V4~1np;XdMGM}dX|8-a=N zO7rIyga^E!g&C7VBW0c*$bq${R-WQEUXFNN28U`r-r|)MHz@hixJEM**<5CXMve4h zlNI+9_5xgv7mLBJM9_(IhL;-$C*GI>x#%z|-s*)v#h_WIl>0)43=ncUx>nhr1|_z7 zTW=|P6qDdf^D0K|+5&GI6B9%B=hKSvw3J?TFAspA9t4 zd(E0KO?OKQ4(T7Rcq-B$24$pYaCYO{F@BtsGcuIh7~MbH&pw~J*BX%jH&-w*?2|uu z`Y2cGwlPpu{WcEb4O6RDAIGSZ@~HSG>3OIPHQMcMn7vsKq~~B*=6PJWw+}h(%d#1Bj=^mKi4iMNiD#NbP5t8$R9P0RvOzg z$T5OxvGJ$H0cz~Xx9G^`hFC&>t@p9;dfB5o$% zr$>hryY{%>gtZAzM;?S!R^~W^Dr-USSB-~5!i0J{S^vOG%Wl2>=7;IPjwpUPg2|k% zvWMj*bsH8dNl!2sX-XeI)8m3ObE94%Ccz-#zTnR|YOw+wP)FP*A!DFLlC<(%Z1NWp zPdqCh-}@jlqACRz?kGVH4lkp7k>QWOWH}bSicWM$c%nHsCy3sSAxj<>A?OWRGqp7b zap=r7&vGQ?V~4MYNHJqK{Df#Q3w(~ z0Hm!RX?xc?F@O&Y;t}3ZUw6lN*e3)mM0jBWoTCX}0?kLnZy*u;y5hVfp#?0nF(1i5 z72YlP;GDNa;n`Tg_XnM>k%pXxe%&Hii1;v3d?ySJg}I|!L%99;NRcpuFks$Kn ziRg-i;2p&L{?=MZ%;u=cvXLrX1JMqt>o+Wr!Ym%$^Tl9sAriNcKnQ{n5Wqv>#KKJy zPl*GRgaxPSf?{C1s@H=N89&7i5eFUI_On+qoW}|)yXROAx$`Fzq=-y@>x|Qh zf5b<}JE(TeOZfaoWwf=VKmFucgo|N!lxL7*lv$8SSt+_z-%^zmu%mZ8KsIf<3S=KG z9}Y;a#jvWDO8r9Ww6Qbi?~O^36h7+L8O&L}q9b6Cv2T%$Q4u{qluO(QgnhYTv%&~= z(QE*p5 zoAh_VKyYem>V>bTSz?~apA6>M8qLP2iK{oznlHk3E>3U7${#Y3DCA#qDIm-F#}<&9 z(kWC*MWW+X{VYbbz~qtOvc$X#y&&n76!DmMIt11G`+~aLefs#B z{eV$S5fKT*tdXnscgSmpX2vg$&$K5)xm=Fi8vT~0`5!V-A7xZ*%^&rBkE-7l;m=}_`@`d;d<;#-_v?f0iY&ZVVWd6Ba^KI`JTZ#OvKsHG?UpJi2)v3wbO$U<(-Unq; z{sW3hHl0M5NEdTaWY6sgv-CtlNXtjL(5f#01K#>tM5vwWf%J$WGx`mLdX47I)DN5CH8i|`Zwed>|236?sI@nO(nc{{LocFPzyoU{ zk6;&b`wYD;EN^VtS3W|5Xh?sTgk%13oD?9oVB(cE%OK zg>yg|pbHN?0cRv3YQB-gFTEzxuhQ3BR6}Ys=eM_Fw{NCv z^IBAKf9a0Ty`x6mfbw^DH;7(*1U5os$d+A@;$th{+Jy)c699Z7)>~|bW@i0G?Lv~fOx>FD8{$ZJfhw8Nv{BN?*Q;H)63EL0*EL5uVGsvU~-q3}*Y{8@hJ=h6XLC2R{tqC+Zr7L~#URC8IKw-MLiR>~(^^5i6@O>K7#5_(9P*zmgV_n2ZDa^#rtqhTdUXGAb$-yCUz)Oh~%| zP1W%*Wovq&yWTU{wTi&;La+kYTSGT1JT0BO|JgSttz*zREvD}%qz|*z7ZVoNh@m_r z&@b@KiPS}ofve!tLXVw7>BtGL%o#d3G&?_8@UjSm@;pqFQy|AbcK;hBvYpo;9wnPz zv@rj@T!GSiNFp6VKUuf%or4fy#`~_rLW93xXJ)rlsS0D>0wJO!v(DF6+_IM3B^GF& z3=*6ZXTCH``|Ss&mbe+hA`ddJp47V@*i%AoRW|b*>g@cUyvmSQ*{>RKsY2fuQL2zE zOgjlW)~t=07&%IbI3x)R<}60Z-c-0`16)i&ahWnn!t;EbY81B{ckd@ z1DG6#kaUUw04#(A5RT|eYEl($P{Jsdk{+coL%6@(6CO~=dXMdCc%ChsaYot9XgBH> zNX8(zyp_}eK3ncqp)QrCCdZLadS;2}+_0)HYteEaQ3 ziK)`x(nsk~C?tYs1Q24SF_cPW-{p~XV>P zSS)Pp@mJwS%^I#(6G>lWe*X0%ErVknFL`W3YNhX>bnN0IR}z<{rKO;poE(NJ^$Ujp zeLsmYnErNDp^beIwlDHs`lUo?CvA6+>~;SyQjDp;VO{Zg`)9$h?H@c4br0J8!nBa( z%M8Dhru=utCpp`lKX}-3H;Vn>_0USd43E!BR~z=J^m}fGrc^MU{{7Rj)b=bY%LQC+ zk}^5G!wqM$i^yQ2icu&xn$2=;j#O{=I5B*-ky(S8Xl?TNo{ded@ zrvpUld(;1&P3hotx#!aU>+DDD=89&QE5L8V3Hd50f3N?vdCYjd$jXklc|wp-Y3)wo$hiW{`}(E@+oI=n2K& z(Y?b-r^f*kzCJJL<9a|?n2t)j<>CI=mRsGU*fhiKIhp6{Pf(vPu25dWBqM`1<|^Xa%_dK6XsZA>cyMjJ=REF6-ZqE* zi%NbEBx)g(dU2-t0;6Us+_o8Iy=)1$%R<$aY5!$*8Fjj)^ivPK2KoBjK=wA{1Rn?7qq+`=$s;?( zmDYn~94lU&=pjbZ-LG4cI)jdQSc}KK`2|G}w#y$fzE*-ds)cpT#aDYPJ)_8IxiP>+ zwBgc2q5P}(N*jkl-!^xqWo0qHKPoXeY!HOQbtki%&@_WSIhy=9lzUU(2qmb#+REw?H~{zYk3Gxq}<+x1ph#*d$g33<`at5}*Vw&I6aF?W<7M9WblfdW1^ zL9K1RlyM|Y{cuy~T|#=HARwG5kiQrPs?Znne0<`PHD-nw<%7f@&V}nsdR5oV(=8>u zv{qTHS*F7+_J@L9u1npmwzn1{4iF0hu~lc$}@d_cq&Qb$&6bNi9_O9X(Q;?N<4i#WTunB_lRZKIwtGo;H%vutu| z-K76F?R+9^k0 zcq7qIN{E}|MNaG?NhvX`2{iLoZrj0m5~h;yrl;abwbJ9s;{3{$3Uaafa1I))c%&bX zk`ao6lawNp>CR5xon%Pzd8OyPC#keh$$gH|l-v4UlK4lKVfQy5(cf5<{PejP_oh<$r+h%yNAIAC``0Fk~+6!Dh_%n{%)sxbaf@SP)056qkJ7>N=~lF zjt#0fNG6Kv>szSFu~@G_)8Kl^*<;-NWy@LZc%X1lk$!_z4(SLq74GURnR&k?x zFi6`0ckA3d-cn2}MIX;`V5~?}8(`byFV1PaJD+pG{Si}AW|0^)*mNqnp(JN~x)hr8 z6iw#oshdRL6YKiqN{QOKO#yC9gHmM!Fmt_(lU>0`NMK`#>}(ERe6*ID?vo*Yd3hmY zzaTi(EGFi@lR6`f8rx8rluYK4FInq9B;!_)h3P;xRjy7mo%v`py^_s$X#JQ2GW?ZU zBA;>@DV9o^Yv5b$QDlL%JXup-d{+WRyzw>S(^2N-fz`oxK1v0*@ z*P$n*Zzr*~2&SjOlVY^mjgMRGl7*L{-#?RCSyoDYOM&GG!pkNm9{wj2^j5^lvDPS(7+-7%8Ho;j}0cB8JwW%UxB z^4r3LD$Z6q(UjSgKoU2v8j91OyPR&yx~k8qy%ABp#drdVa@ib-GU*J7{r!Sk`OmBX zKR-V*QqtnhPgNX^55Wp5adm5yq$ITb15?xE8zQBgk8`4(qcUPr+W60hJ0x@rqK?&5 zRk6JECtlX?yc6ao&Wov-f@<*Yc0cIOX*;EjoX|y8YfhGL9hv5TIAT+2k_&; zwt8Sp5_SNQkwj<+bqMlTcxqxHot;h_kD{DUWO}05$?7t!u|9>}=&53}dnh|E;mo## zu$l;@l##JyG0g*ilPuVrr)J zWCFa%F9oRJ?fs8(!ETTGvFKVp#$^Whx%w{7`@?4TNkOE~J>rmQ{JDA=9jrO8#LwTw zMv$`ScF~aO1SD;e`moyT53}Xfh_-Sk>|PL-YmJ;aYQ~9UFP&-gBJW6p?1R@zLq;YH z>3x|Zq_Www;K;umNO*#EVD7k2|AxSXGY(;g~ELJ#&54UbcfZ(>eVgYsOqu;@TQNI}RQr)0iuA3@Bt>Z4 z?)rV~*5*(SLe;;+l;-jn?Ads7rp(EL#Xx$y~;=@ON zpznRL(COE09ZU`MJWZtU=Kg;Ov#O5qSn)eV47`XM6EQ}!56nm`A%25lgZ)#N8rw>E zEq0p<)dtKw46&I?9|GxZN5nr3%=9!9g0jK*8+cJhr>Ol^q5<${t~a3Ddh`DV15>_8 zf7yGYSClUYl-kwK(}_glo{<)b`1JX)G9SMF^(LO+u))xH3>UZ2+o;) zIlb}16~>bpoTlDcKinbVCIO?_19CArTmAb>GbMnzdum|j)B|ZW7v7H7rXgplN;0S& z3_3PG*0*8iU6s$G@0jVM?hcZrqCB8?M8vts`m}>VbpeU4wWx>`*s#D}*HRb3tCPM? zzoevRVh&u|ny>Nm?rG>B`0zg17`CLw$uzd$MID;)u8#SH{~!3TQz4})2oBb?6J3%D z2R$#kXes%p*8&W<1`@6$sb*?bkV=k4ELU;a8AGKtkTV#uqbVn@2E}vFrWVYs9mD7Q zf|ac)nMx7PKa?Y?YEe`6qc)WaMYZ)!UCeOhvION`!Oq-cvF){NrmDK7nmgmR?MMTO1XEQ@iuYq=#{!A1UEsPlEU&O=Zl3zlZP3hBh`a)ve z9E7=-CCFL|D&JhX2B(-kTHfI>~GmvHIw9$SmNP?;jj5IQ@Yv$Z_@f8{ zGQ+5g($wbjhYD?-v)43irbtGRFD$w-F@yaE7F{PxFR3lKDG)GHoA#e`W$TtOR4(qB zZP<}C(m7=#Y!QW$<01j1v~aDNg@-H*`9KBH3+!cOvPq)K(Jj~1!`+F<`mfrMfu1Ch z8f`GibUH(i3MLGzLjH>m%R3SSI;XDY`7+yRD^2FaWyuyV-!!1o&b*d9?%>JvI=zkC zE>K0wIrBZ8+iWT%f)tp_lJ62b2CAy*;^*ewgo6Av4AUPyNkc{Q(3&_FB$!{GV{8H zg#l}L;QG_EC>+hs*!HFxo1OzYk9%?VZ9lRb7Q46v+EwKq; z3LJ^gga{A5U{GO;C~#(**4w2gcfsRWB#bq+ySF=e(^L(wl*lqbarCpQI98B!peT1@ zr`2CyZO|`4MNpaLhop=I@c0;R+d|x%_R1MHVgw3evSLxk?d%RFPG9WOa`tY0)vIET z#ayE@6-|i(MGbL?s7O6FS9Df@!ts>ub13@FrxR^7Z&;vnVcRa9hkIYaDf)RQYLvO` z$(|Mh0$pbRIzXzA)r%0Y;w=Fwn`y-U*FwoF3@}c7kONcaLJkxi6jFT{v`Rdf-(jZ5 za5pAbl%izOLOaX-=9G{s)m&Cz!x_iBlsC;OQV~Ke>>k>uM(AZN3B!(FGL;|3&(`Ma zxA^98WwQbz0fbXk3NMpYlFP77x$My27Etsz&zvBo_o!qQmAugu+W5*SO@1E6X#e%i z`d%X22GW=WY}O`WGI(f&xpPK198c-*7syibMv@%2TQ=!C5Sz79O*`AQb_pqyy)YlX zG~a;$C84s>SY7Py?EyD)(a!h`;Vz8H3X5yHhy92E*9YcXDMk&D zKzYpgPD1Eu=GBrxA_`$BFih0>*cZ%}!1jwHec#p*LTPU`PEp|fh$n%8CVj&8!b%l- zP*7*R%OO2iSv}Ww$LIl*Y7G161NVMIl}tdR9mBX%(oo^c6&O+O1&oi1xU*sKWGNc! zh*vTj=TmKX$&U+-}pDy+jcjJr`ul`feOZ_1)Cm&uSdsA44;v-S~ zo6$-nyusR`jyY~}H;+(9J$ueU8WUSW>~|FZwJpgwgpM6TskYLq1SG(`R=VJD#o(j% z8BEg&&hxHR2jns|mSOh2v7*`NikP@b=%@;~)VWsTLl3y#1}_lRkL9r>@B0FND+(4v zElQd3&NUG(YMHej4wu4XoCC$^T$#oK&V3-};ugWJ)QR?|Bmifgu`=DWGrB@4nSqpN zE5(Jv#2j=$`bk{4XRM-9DpH2RMZX3Mz_}V6dQ&SkZW##CHa;$x$ z%@=f-0iWjTdCAllUl*619uSjkvn%n-lFaHC94ohDkmL&M1&=!jR;#A%{T(98UW{eE zdWk}mUwLwsAN8L^83n!ie}Q@Ejm5jWK;qPt|AN>QxJ{)l!#&%i2TwffagFOJ6ta#q zEx(-z1ozB1PgqN5^=_o3i!V8maAonK-82W@HisKc;tGq5q%dTP3(1LN#{GVY>n<12 zvgGOPEy3{DnC=vnmI4Kn63pr`>YlCkl>7ax`m)0YD#bmR-yZ1n^0QdZ%3pz_m3gg$ z_VU4js1nUH8gKhejo(+rQ~^D9E@pK?yRvvM=p^(CX?j}cwO+=kR%Wl&u8~z$sG`T! zjtDjT6*@Trq_K|3y51lF!iqGP;GlajS0lJNf?hl3!h&^HvR%n7exqf%eFqVl<}4@! z^U6j%w4I7i^m=%rGol_H)k!3 z(TMVbhW%D#I@^G*t<4doO6NzuNbBST&M})SeuU~hpIW_PtWt=V7_26umbi%F#%cb2 zYX6b`Qfj1!ei%UU$FEBLb{_<3Pte+6w&d$%p$;z1*(ye@J(~FP9+E_0thim3r;UQE z$vkMPGerNj3Iuc0jG+pY{13fSs7kSN{_+OM$TzNG7^0^M!dp{Tlx~%yYjnhUy0O8< z1Ai$LEX5V_2C(u~b^(9QHF(RaGaS-m?N&F{aew>f%h zri%0he!{s)_zisg2(&%t?eC0v3MLIU`%y=q;5*GY)ji1~_aZmk-_*g;oBrv^Px`Lc zRiY|yu0so(M#$;+M8PudU&R->vQ(c z1cAKl+mvH6NN78Qr&=ecLigKEXznp-QQTh(tMS=NJ-z)f>kK(g5Dhll&|5-cy9`zZ zf~mQ?`@2^nm~5tavKgzvwV!P{TIa?m>{eu3qQ}4FQ(_#}jrE_JU_#yOut?rr1`C|T zdUlI-w*&vAG+(ma89gKJOg3&}^5l`Mx!i~rJA>5jZYUg#``3=ep+ea{?+KVT;`!BD z74#Z|AtHUySqna!wa1QA!*`HD`q)E$YDfa=kT(o*P>+I6r}V ziYK-6XOy&`a2t|OWv)i$;-%+5pJ<5}4%d@t>#i06-IyOn(RIEV9OjCRpiyO~{d|S! z(ajZ@E=}25$4eiE6KkL9oN2T$c}VMk7bxX{)YsPEx^cd_Jr(2kvg1^O$scwJh)W{^ z|ENRloU~`CRxxor6?zZ8`m|*gh8bU?@h#7y%29{o9g57A-NJe}T}SE!haDjQc5Ts6 zRb10cZEF}F0wY0kF+}5PdW-{Lmk;qEBgXBzZ+)DNJsPUZ1vwQTH5n{MJyk<=25V#=y8eOuR&a&U z6~$tD;cPvJemkBoKrkok1P7&~D57dG)~}eG&X&QXus7%0Tx+km+y_)xQk%f_lxs=N zmoxyE|D68ZBWZAZQ0_jFU6`w1G^O&#DmpxWn0a z|MZvOdpwjw?m}^M!}v>g?OVE|`aggnWwYgWfxOm!0QtL&es*S0PnFedxr&YBIUjmP z8|`ehmzL=qk4ga!vAkVhFq_Qm5F4Hg2=r{H3It^m$f)5B@2LcYSNBr)AD#1TLGXVV z&fZg!1E!NXGz<97-W0O&*~xs@=1BsvB8z&6q;d=S{|miL43)(2Ez}EIaw;R@5Ja0y z;~akwTkb-KW!fStR>xzhn<~+Q6^;YyDwg|3HlJRS7vV# zoJN1VHQXe9z+r-Z4q!qxp#tDaU(CsXcr^>TQ_^^~)_YY-%`GkyO!*9?w;(qaRDO8f z9DN}@HDdp4!J+Ei@%SyhKhdU<`CvF2%S@~o_Mbn0IGisql`GZBG(1%%LhFBWY%FWu zMzvMB?WU|56IL8u_Z=+J{fG$|erGet&xVG_+k#XfVPhh`G8p=cMaVj=Yd;+fXc5>N zzsr_5sRl8Ux$^0pBg%VKzDU> zWouY0m{bP+E>CCB|DeEy^{rg!G9llzRR(Jq8cwMV{xQASKMh6L^^HP&j~LA-KR7zRzFU?Qg5dJi^LG+s#%4o(c&!DoJgRK1~5HZq{Jo4^fM+o+w)m9Sy6 znFSwR;*jjWdVkdI;;KJq$5?9@h2Hpt2fW+pZ9L_ltoHy637`G~PKa6kBh81K1~GGe zN?Gge$mY{1yTxmlmQwWHudqZ_&mA;(giMfYt~N+lZxpdTx1uV-=jRI~03A!yJ4tnqbEirz?y4-dPh*OBIJ;cj23 z#OOo-dmkxmwITPkXLbeDju<&}m3BB0!v2K(IQ zq;6T?X$iq!s-UhsX%ui;9E*-YevY@Df5RPxR2l_4i?M`7EeVO|Qg2Fh62N1^_vO1N zc&Vz(PP1{td}B!0s`Lw)elPnbW};Y17he11BO=A;3&s}d1Iew2YmXBOH|XpfJ1bTc zW6cu8Nlxr&_e_45f@WWmCD!YI)~LsM?Sgzr-g|8T z8fboITd9DcE^?}5Y6B`Li%l$;A1iP;tT-Exn9plj{-@QGjY}TDgw(4U9nf?pWe3PT zeEkDjk}KE)I7?)~d^g+DV^A|VB|2(Jw>QE3*0RL?<65_SV-7B^zTRG-prGyArDo&; zjam&gwZ!v;ktVZic29px?%ushutE(4WutUwK8nc5QX6r{%L|E0^~O+zN9=;}zl{fK zj%-L$Ct%1(t##fEW-Ru!5`V3`e~J*3SIbUNz|)e)t>E&x)p>xLZMfh=$sCVPE5!3_ z5k^VlBp7(x1%|?m?t3YO4f{R@maiZu#uDG1j;ZgNZDn^%@6TW3+M7T9*xNMXjkC^? zu>Tn8X`?IHjwh+3wJEd(p^H_fU5^cz-VbH5kSE2m5x+*K9Z4JS6|UfT0)q zWzK$%FAq@&3iMzrT0+qnMqE>`R(LFzA>f0pmbY}?jR{ITu~_~uij?t_x$w|ss}yM7 zo_%q=&Tu2eCi*L~wg9{uZw1h4?FHy41{EpwQCvGWMI6^vzC>(JC}cc;ydEA-LQwH` zEOBbx?>mFhyss_8g{Jq0V3?7{MG}ciF0YXYR5Ls&q}X9@iUiR~QN(Y}SDP*T3~^j; zIZ`C7K{9DF3vRarKL=Tb%2;9|e_(hC2`Cbq>n)-#h@^xge00Nm-cmZ4kxdjCdvr}vVHSK3hL?i*^iN33O@3Fbr!;@si}drnb--=yWk}?BsVWlI=jo-zXzzO z%c&`#+nbVSsV}h@t8+4ir$}+JwlH%NBkdRmTZIaSN4}y3r=g3aQCU-Poxjdf*W(W< zvQYd44d<+aHr3&Yr}OF#At*T+5yZLI-3_T16RVw`d@xEcIRXEE!XhITt>?e+#I0WB zR*SU$L)c>6H(SnIlj6j`)T`m<)+KI(D2$4(1am^75uQ6&=4C6Eb)0@nomrIh2!A_5a z#QmHHVl;mk zKq=9gn)0&5Og#~z9QzTYBkND5SJu}e>b0VrknEREP5+!;uQ5|BX4fjVyKxSRI%n?? zq!x;hoMTkqrnBWZZJ6&Kg*}s?#4MmJimNZ=Z~MFh{cuqwZqOsV0WU2E#Ex*cIuC1V z!I{%$c6-3XnzCHu8?63^(_(3?n1LI&U1e%8)ULk9>>Xay>lVnZ1Gp?b9EQrTcOl5` zk(iX!L<+*)s7A)z;I;~c!^x1pZIS)Wd{apTQG)2B>T+;IZ=b3*M zyC$la$AWz$kOq03AgO3^&r}g#h9#U~abXFLdf(K+c^t!k`RZ@n6!SsZn`}Y2r^d5f zk@0BNIy+vTc^kdsFcs(!Z8S@OvT@clP&2#FV4d;7Y;=Tdslg3|-e!r47WRh{)!SLO zFqRk|`fkj%r*3B-h6PjULkY;dY=(6vLGC=Sr0&!O1?B~o;GUCUe@Ldc?Gk6Ey7e>*~`XY!UX#S(@oWsY@6Oh3?l_lqyTr)66?CMak@Pi8c~dpm0<y{*+%H8^|C&(n1hRF&o|mR9 zTAt8y7D#{MTQ9Z?5KNQ9KL? zQ|3m!V{JUWYXTx3iQ3Kz)zF>u<{P^DlluCyqEfipZx~QRs;qvYI>+)^W03=?Wp zbhEy8Arp}_t=T3Cke20|5?6&lNnM7A-{qwwS(_YDIW6?-kws#j176>TEgoFn@O-3m zct^r_6qJ^%UM($Z0zC$~YVES&9gafnM^Q!=31b?^6~{B!0crKM4v$o6&amN8a2$K%mjWaNY9XNmz4Ftp9$#nP?k^Y$ts!Qp(C7ZEoPOC$&ARPvM~eF+|NailOc zm@}+R!3mi^NvX(9mrEmvqv%YPs?jwo%Dq&4$qM{JTQ1OpnO;I;BmR_Kt)lr;eAJ0_l?Ah53RK_z)QWS~MJ&Catwuo55^y!d=~ zO?r8}7ys|Y1+2?#m+JRFn9{D!_%XY5U@IN^?0ca4EZ6K{lea+gdn=$dfJ6-3Yil{a^*ZK!ZksVB?hXC)F zHTtvmn%?n{uSF$FLc^tCCY9owP5`%dRcVoGwk)4L3Lb?>V1H! zKV;HqgibK20$nb`5OsD;YTZd&tk4x`;pnuYeZuFCQtUzxmP-Y@o%h1zJj1Bi>cTl+ znj9{;?cNz{*Jtl$p-KzJY&U0rYdPLe4%=tY`)~#5B)EXF3Iijx3ODP8&Eci)g?c!O z!=X?Kah~3^qET4^PVG;+k7unZ9A-e)U?%>RMxjLeCcfW$gn&R|Q04lP!EIivD;CkO zTj}4A=Fynk&XikUdv!TSaQF>A#M(igVVY=7+@e(KDOq4}Jut zFxp{TgF^m^0@srUhmn0;&x@8pKAO&qh*A_&q16trm)rZz(<-O24PVuGUu$zJX}S7= zlO&^o(EUKHzKs_21l!Vt9p+q=s>)_TgKo1HN?UHC_ZbvZV*Fqt=bRx>RcFaW3wlZn!3A%S{j{GPpGn?+ccumFqWp9O*9Tn#;)yjf zHZ=_r27#VKb@A7}F7g;Kv((@O4m`b#~t@Xdnt^9BBgz z7PCE2Ckdi>W|&>YYNQP52pzSdV3JSm`HU#jZ^VHDL%-5X|1FZ>ytvHXV;Azo0`VRJ z?_934X6u3#pkN?Y5SSG62*k`kpx8P_@k#vS=$2 zWOS$iS7*_qZ&(U@D?3dgy<$PhiF$5QDKxQQfA8{)aA$Coo>IWk;5-mmEfHj~+vxsj zt^{Bx-|Pfj+FcN@k*;s0nZGFQdVWRW_arL~> z?=VG850nVz@U-A2%zLsDVZKX*P1Vyhvh<1YK zr69*YuF@<1V5u)|_8A}-M&U6fXF zq>Q<|zS0vm^0E#v)@`~!JUkd)&;I$py_uRkt--FFt4;2dl$4&;RW-Z+xMHu*_y33M zw;OH5;P-Vb?g{rqK5gailzIQg*l^^Je8>vNr;ybPEpFT^0f4w)<&@24-wq!gR%`#3 z#NvJEeTLaC`OV;x{;j3yh;SJYahLDmseFIO@hwgT|9W^n+}VZ$ib;UeM$@kQS|;?G zMu*7Y5h$JX`&##u!~5huq&PVIdHzAalTCiy-TnRIkpq-uufp`NMJ$hmEZoTv>@7pS z!+S~kjW1toFsEAa{3sN+7aD&}L{OX*Ih?nBm3Y4voehSNou$*;xvWRIwOyj`+R|)6 z6dbcAV4)nAab244lm8KZv*p4&B>SeE1;s?N-S_;0gv&|%joa;vhjiNd&Ae5nni92> z9Ao#f!l>S5z~S-8iCpJ1rI1)Q{wjt@!g$A7wdDyt#SVAJp9}bwx<$uct8kauKQ!vO zM5nTYMcG8dN&e;99b6YeW>jo^H}4ct@}fdKeFi7jqO~W@A-(f#P1_58Ss+5f+{KQ6 zy5+B_`MK2CeVdW`Jk_+gy1%nbZGQd`KnpI55NrI#2yrdXo7NFJ4^?^OdXqY&Kq9(% z60q!kffiBnLNekM7xt$*Pz$UPqhRppMgH(Uf(7L3eXT5x^>0R?S}-$mT8?aXOh$Y| zk#3)mjp1;j!yM2J)}IVGoGrPPD^-12-)+7cdSl8)ThBZzr-LBB9r46uH-*&`rSHCN zzHjA%MytcgK4AXLvk4{ZeeRm7b_fLh=PHwP?{RwbJL7Y9ly!D!jBd-F)H`sv@56O< z?DnIgB;)l?xp^6-BYq~o>dc$`S0sB`vJm%ym*#MT?JpfqwtKw;+2DSHNFxDlZ`#Pw z``GS}8TTc;+!T?{s6huq=Uch-K$_Ok9G*<4zj?XBg0_MW$s~@UtuUoH++YMk?v5?T%fk^?RyV>AIn~=03vG8?ZT{kJ zpD$dZQcj}`JVtx@{M)x%10MG`)NJHA$xaG6;xQq^mE?~>6Z?{N5&>^#Vt}RQFBXHp z-|2%29lq>7`w{%sDPn2t_t6eZr2n}^L`r^tp9ZX_%>}H(Giab*r2<5>X zmLjE_8Kdj1w0e(uNhUl+OClUtM*vBF;kB@+d<{2fp- zqTa^D+Ppr}-?9bA&~Z1XD8wiZT_ZusQNMi7en~zaD*dP{(UnwEff}2Sx+6s9(k0z{gIK~F-ES1*d1s6t zvI6*x+|{?iO#*K4K8jP@v5Wa~BV)(jO_$Zc#HDZv=OV9fG@{Oepuiv~eEf-J6x4UK9|5-mDX#eLaTH25Ij(#lnCQyMD01`5_H<%f*;<86c3^Os)(S@_1WGa?{ z?3-DhtluA<@A^1|z%HjX(AsX3Yjzlx=KQwcBQ;#w7*T6@PvClY2Un%p4KH*2G!xk! zr1Oj~_S=zZPF?{qIVt1~4trdC>=TR*KdU9w6$!=W3V*niI>z>X zfkyJgz|}bW&DX5g3qDtjuop!`sTGWM9}-uWh|C`q3a(a(8neTB6VZE zVGNeGL7Cr(kLcH99Gz5LJyLi4u0?6mn&Dgs_=XoDj_ux^U^UMheGBnX!mg|IdM8#_ z+)l~;`8)dthkM1NA_CQ;&`&nzz%C?>3WM9%(eBVmTC_O2ciIBcKbVKdYF z`ZKcl8}Wvx05d{}LyBnRd zA=E7y`|vk=#yNN&ux6pT&`v}@v5mGhMur1~EEtZLFI^ul!0@y9V_>|)N>*#2XdG1` zJG#(>mj9BJ*Q1S=J>)liR5Yi|I0A3o@7bL%NNluv;dB+l?`biiM5VI?(>a9=0OmF| zd%z`CZw9r;m@;@iqRZ;EMWKe_VJ|cZ0^}N{856r8r-34;g~N2G0xe1JwuY#r#YT|g z(kjNowxONky^AHIl=`r-sHRDXn5@0SbO?^tbFMSkQy>c&bmFYcApjck|0AqPWFCbs z0F#P=`*;1LK&QfaxpLDNS@iKVR(z9s@3r3QjRc|YG! z21aFtpF`54sL0}pHRu^cUdUsV9sYfmTCWrNIM2uA{`vuJ)@^rl^D~3n2lyC2SV)Hz z!{qsTFpQer?sS2VC&naS?H+taDUtB@6OKls1@t{yyD#LKVCQ}K=f-O+?0Z|(A2>53 zLqu_--_JNqlvWP)z*hh`Rs)m40xoTl^1Bv+;*RYtdJ9r^jN4MP69@r#<%Fe%anD

4=Cr|ApXGZ!48EwRFptIU7&B>Ml+lY&Uk=SAk4Bxvid1sX0q|D!b7 z{UQ2)928;FB+4r-X=1fKtprsMSkh*l;rI<6y4@nsghY@|i3G;(c*Ck#)PaBNOMRd0 z667+;ZxNtLMsITu2JfFqc`1^=$Rl{T z8A4c2IpRT$=hy$MP2E|J#2yuLVs%{*j}~wLSK(oTVyBN8AQuA|GcmFLu1r4S4s%9F z&d8~;BJ)#3U(3$1=#yM=5kOdX1>s1yW79gikZx}FP^H%TB1aWmvcw8Z5_BPAg4R|P zPH9c#VpkCJU)(VVhJ&$D{Td1I_tEha4RZfgk+kf#*SizYo0beyh^G%n&tz*W>gq-d zjrv1VTTxbBKfy*PcH=V!2yGX3#RujS3bZ=g4g`G_YhEAlNyHtl$sSY!&xV5Ro%StU5BBFn0G^hR zvz9v#twnj7;n!_*fjAAZch}+gSUoTx&q^%PX5W%JEsjB=HRrg8d`FkGMA0eM(`hxZ z+Qzr~O_~-;rhj*KpueX+p04RiCPz=tp03H=7Qb+3Dntifs4S5k)as|RJez5=9H*I$ zL3wr(@nP7;)7hlI}<}%~aT>jTH9wlJNp2v965&=>^Tnk@LB98|xBlWJ2pnvd0NcX~sH9wZPKs)6S1UXv& z$t>|XweyagDfe%-13!U?d+R>et4h19EMN;;O4BU-*E}BZwU1 z%R?7`P0<54(MYsM3~zcgG2Qn%HAZ2CrJH|z%nEfrqRkY+KQ_&7mL9W;Ji)%uOo=bfgFVpN{l_lHDMu#xUeZg{r!@k0DyPp3#x7`5Lx3 zoO^gO(*GDqlX6@O6OBC6 zJLh}@-DyHiTt-H~9h{&F&VuN6)FIH*H3+c^DL4ij9tTB89pkNJwTPXI-TsFHxr%&M z1uSYEwCqTM3WKi6HhibqR@6gduFY;FzLxqAv)qvb5GqSJ)3W+r!hY7I<&xg5QFtsnIXla9(TeRF z_-X^dq3U_JtFoe7-CWf#Wi|i14{&Ng%MBrmO_Yh(*>VQPiUtNTI}N6`1<^Z(puh3h z)zN$hT1yM>waEHvK0<10u!YJ1Y}$~v zGHBH@^O>T1Z7#oXs?;L>R73%|+@eARXq;qI%gnQwKaF~AJC5{ebs^?m==`Pwg0 z7IG^snC!Hoy86WCN=mi$IkuZ$Jzfir^< ze(|oGGce5w-XM&%Qq|4P6*YANL@%SJ%^$SfPyept?@_HC->n%rmO8)c9Q?=Yx!Oj( zg2U-6mq1}LUxf53rXQ&M4m%q` zatYIKNX zs;W|)>B+_zJl1@xr0 zyDN3#Q6Wu7n!YT&!Ghax$KmMVq4{gwU2|}Fb{IsB-YH21=T2C46|S^FqcTn9v$MNX zIx4E*-|sx>A>i^XriPv&!?9nt$f5|?AzsOXJq*pi`ir(~OO(GJa`ZPT-PKyHA?HA9 z9nVZBwp?*msn$wX3qW`-rOq|Y)a;Dvpy^eV6_?5m(ZmC|W_0dGb)HN=gYJJL${7K9oe{2LEq;=IUbbh$N=0 zi+X?~QzWm|He4Y&N^ixdlYGXdo`(T7kdy{zFyy?g1%vd#N+Az z$$h^VNkRWh1oG2y?v91l^RFz5KC`xB@R>3U#N7biUPgLo$?MoQ*HGk1v|vok*#l;S z>k{4r9Ux0wYUy~v4D$MUU8|vVb^;^%lvR?i6S)7+W3eV)&)A(_#<|w%JNu>rJ_b=b>336#7pOxjUP#;U`pb5!3`>;-N1u9H?IVKjYep$kv=L!Nu}z5Xd0! znUNCy7QQ@v!wCrPIJ{uA=^ecsxq2P(?0x%-Nx}xhW4pVE2rZv&Gi3Y|+@hXkEcJW3 z)U-7|SLT5g2V>_aSp8|oVSmC==cxI6c@k9ZG!8Oa$~UDDKEyq0c5Vg}1OsD~UAbb1x*knMs zn;Iy_W@Dgu;O-4dzSP=NfEefH;C8QP6p5Ih9){prYf$JLcks1ZuTJr>u1zDWVou7E zQHNEP>dkbq9*)?ndB2YYdt=^xY<#Nk6X)2LTM%SRCd1H6;qYz3zi@rJl4M`fkv0S~ z&yHFSRFfn4nCP~yiDZ-P?&uaLR6#Msakkqx8xo!ZA&7@g|MO~pt$sxQE{^U%PD(}? zKN-X?RxyqL|3tEjkz&UL_&#Me)-hU~FJF(XmhShr4f@Z>S_sNQ@2CR(uw^_M%F5}S ztG9!5Xynb@0Go~PA0XtGXKwxT84;J=S3=@ER>#oqb@w~8L0)n1x=dIz&T8u5^ks@- zuy`JkS**aRF6?@{MFEhZf5*~=_yMfTd#Fdu*1pBKN-Msi$P~Yja^m^@bMyE&G(V

4@~3?{@N}pbs{s^4T{bu!HC$*F!LU#a(dKv^EfR7?!aRl`bu2qr zn0(vfVhiT}gcoWcmluoXj@MsYHQ3K>!r)+QBdz0xetTNY*m-Zb0Z;8s&kxuX{*_Bi_HEAIV^aTk~x)nDz(15Ty}iHu%6^BJ3y_3x z+514<;OqeMdUF<==Ig9I+rc|XQtc<-0oR*7X>Iv9L3*mp^2^d{GuX@U3YDA?9_hbN z;VNTKR703p^8mpDe!UJQMOq)0?R|nFFg$O$L%rkldZvS~{094UcNAQXW47CuF)aOK z{msb3_t&!PXMmr=&kY6Dm-9bY-IlYe<>J3UGoRc4{G%rTw{UH z*%c&(?DjVD$t`4!u6CZDlZ+h%Zlw^$<19Y%o zYv8-X^)gNW)xqxhPY2un{Z0+Md2B@Y>HlNvtb!tm+AZ6-6z=Zs?(Q@+&@}Gu?q0Zi zH}3B4jZ?VOxVyVM4EMixCT1e$rJnMkG9xlhp7ZU!Ru5eZ`Qk!Bo$sm96-2dxN?5VQ zY&oV@K>*`k(Tm}A zBP;AL%b2{ZlRSUypwp7-g5LhD)YTRynQURKdtxXcx+22S3VeAVhd`?blw!71?al=y zLX~YOHH^9O4FsS=KmdQm>K`f?>RXLnU-)&71IZc7$qB5Z*QCc8Vp-7a;z2LRBLuW- zjz2{+?pY?m*7jZqDLVfSXd6nyhanX&PSnBOWNT!fJ>100aPy+5_8$|zIa+_WU<@iq z(P*Gx*TNWJW?0++8xJoM*z)j-pohL5`Q($yG%Zw$%dE)Ju%bi4X`jXAuX=s+J<0fTeDhHu=O8Aj zbz>xJadSRPidcuoQj=o?BDpaEh?+zfc``vS- z2G~IK>YEJ=;a&uW*>|u{W-d|Aic)_16*iaHZu@$8diJiYXg%m*P;N@`!MFeadJ;cj z7Ns2vam3Dj|4;3pGf*ZzEPhKy!(%Qa&!{*l{CCjsv_aubROxI!vb49k%Iti6Ok!k+ zPH-p`3Ar3BRum$?Iktw{FB?<&S7JRU8X<{7QOQl%Cc(A5YUO`S0MvI@ShQc(7Jwa8 z%pow2#_c1msA7Gi^c0QoKdCJJRAzZ73>NsBeFMu#EBpJ3n<%l9b}VX`q*PbvXwJ_p zm3A=Rzf>Xr`Lr(F{IMPT(f==?%0Pm`Y_?StCYEV(D=bXh!UVz`pB$D)78W+@Tby)5 zVIH6)y_#iOWl4bynwk?U0X1Ulduc;~q1f%265kZ%6Cbd8nn^~&fo{5|pbF?T_+^=M%b@l3%r_?PYaXbn($KTA8TX-P6a;9w+6vcb(hf&UI&^%yXwoIo zUJ(Q4$e*&4WdX?Xr9GC?NLHAy8gxo~rMzrN`gWar7B~ajD+qT$;syqr-wsxaE_=)6 zxkq~@!lew91SD)+d4Bpben*6g<4aID;MFBoD?Scz~SMQTu97|D+_z042gT0?6tN(X_1iHRRqcK)Y2%1Fqe?Zs&KAP$uq)dBc zqa-a<2%eNAU8T8GBkNHTiUYN>8z-N6pCrzuU8NOMkCQX~B!DRd_s@Tg-hT^GM!era z^J=-3o|^oW^;9)|pyR3kM&z1>QJ+A<{(!y{RXzfIqTam#@dJUCk`euwvUcrVPIe|us)uv7QU0M zN9w-3q~7=>60a0zO~H{HpJbqnh5nEkQpgH-&+;lf&pqycROLX8JcdGJZF^mnP_B4n zKuhiW{VAg?adDX@M!+{t2G{0u^D>O_FL&1ChKotvFIz_Du0dGlM}gE{sXhVej@XUI zrpgYhf#9~^hC)-g&)@oFkMu|C%iE_r{;+lS@}s_)kE3eKM-1YLJX zXv#E+_EWUuKgb%qcz)-t5|4Jt$@+EX@Zf4ECWU3Abmf<7Ixflr&IkAUhak0Vgm~NP zk;{aQ5F>stEA6EfYsSk(9-TLAW|72n;Qju6>1<*i?k~>u!$z8KYE{n3;|7xQO}^gL zNBf`I0xB8G&G3w5mTZtAy{u2QOO$S8s^Z0E_V-LiuY^V3NWNEi)@%N{_&NKTjE?V# zDTliul>NoMC^xi{Oc|NE6@{)KXp{A#$3hSHm3#sqTUXoRA*01@L-udG!Pvc&pg5U4 zc>$vvlPM1)odPi4I}JT*w68m7pU!Z>arT$te!z_C8!1eW8NS;jLa~f3y0NUbl{X`9 zQ^b&@u*_?b0m!M>pNa;*`6mJeM{QR=36$|aoSQAb5-TI!xNztCau*oPsF;b`{6i?K z3$wB|dL!rkNi@%!d-}~k+A+vEY*$bPy&9!CA>bsS7c4HUXjfCiWNxmnpMPN#g&IDd z@TRhv!WYYD1&||)`;Q~+MS6zAhX+(;V4pEYKEj*!EY)#kmit~3tgw}4*)o%dpHTYHYXO9*^lZ^ z9dw7w~j zJgFC5Vwko?RqRhbD&9Y&(s(+JWabqKl_}4;v}o&pQgmqgClI#&>S~6*Uz*zRvD`A1 z$C0c#(-X?Dhg<+5Nx_t2SSB(ccso3{$~w=3TM^S&d(MsH`As)87T4;pmbj`{bZ@Yx zs~nD&R`2?Pj+#*DU#3he4S!0Sx}FXM1fHIT=Gns^%q|sey#sp6MtJ`NV879q3@n_6 zS?a#U$Ob+I*G|W^`kG;@5!^}F_^li084XGN*DgUI)iaQIc|jZd$KQv6CCAxX(_1v0 z=l1|{b#Rh(aIu$I=;O)cmHFtOpb^~3$s5IYvvpSU3z5_lmR{y~|DSG~>V4v*moV7V zr4?d}{?J7A%pBAb;8@yF3knK3x7%N4QIOdW=@Kb5OeTq6v-OfwGX<=+lgc*wYuL!{ zpOFhETUITVn{0z`*RXMgeJ$Pf!HNdQ8nI4!kBWEfU$ZjhJ zdMH`u!t%79nIlLFQJ|h}O6A-e$^tzo&_Wr2(8*YoH;18Wol=G;!wUwpT08r4vqgF1 zhj*|Nk|DXD>N0k3(rdR-(&Raz94ND4LhmXq&f@Q(>8+02q&yt8s8}~e4dSDfgf!rB z^u>?Ae3HaYWjptFA8V8X{wANqL9PBLH779w#DeDFY()LIf;Ef74cQhCHQpF}wP5#x zIzYCCctA#Kp#Pa)=#%<3O7KAk3YN^8Ol7G=M7q?7dClXUYg-5{XeU?UV3-CzdB|t+ zsXn9$I5I%LG=@Z!BaNTCpyEA&N2EnUIisPX=?M&l-Q`aSb;D=GtTY$3hwHHP2U#~6(dK# z&gq7vu={S{RDb(23sD4{P*q$*{=bmFluqxoi2$nD`# zsSOs4A3WYrhfD;$fA;}(uXEy8{R|veY2Qxwq&1qoAY%1f17^J!4ab(hSy<5If7$tT zPMSnGJNoNgR~@!@B+u4c!G@4WYECE*W}{~OF$?XO51Jgt;l()+mlv74-lj#N%u1~c(o-+sm7B&HA$;* zB2ar(&p~}+V7G;|RILQvi<4!@Ue4TbEWwyVvAxdg*3jVwo*seZe=8Y2g-b21#HWT~ zrS6O^av>hv?ej_{A`&mRVTh0_`W7Y-=Q+CNEoY}|0^n|`dn>QV-*#JB96y8~E+D!h zZek#wm@ppPxqx*!~ zW`hW!LGAszqlR946-_Ol<7~AFPx#}BzTUO#$!s3sNi$8vRO}S5OA@N zC1!CDjs=EjsCF@O^X8lbzQP$0^x=3)*4jcCljElsOI3fm)citSDU1&5Sn%c0Q+wQ4 zXSqCQrD<&@=8q)+11e9qTw?gNI6%u6Oc~8G3mbxxNsivU^1Od3Hruk|-Frcdb!Wxy z#0P1-uS%_5kJVIiDsaoj%8^uc@1w; zHjTfVI}>a+6Ln{{f@JYoo!IwNmppSlMRuKBN&Ia)2e0lO zS+h+!B;Tb_-^q`@d+u%y7klI-I5IOSB#Kv}_JH|mnAcHIzNDDf#%lWvi>$=`OOyy}iYt0BCruxx;D4cC}`SvO} zLm4OzUK!8yX{_i;d%IhEe)w+jyh73F+``R78T^Lbwi@opqAZ#MD-`m#OF}6vAzZLR z&EPb|pzsvZp%FtY?~iyDe9w3ifVJ4yclSLBD3EkUv~etmT9sng*GSaWB-4VCvgjAd z{HS5LTleh1&GbGrZHeM$MLtQBVYE_vXh2pjAR2%)a|j%iGmbTW?mRyt!`wN`uDQAe zGnko*+IqdJ=ty>v311406J8GE25Q80Ay)lN#|(*ioyxWBmOa{gXHNCIsB`^pRRRlh zpg1%Yab9P=zFN!5^#1r%@c@NH+u~;YPY$2;(Mb1fmh%bp0JXq<&=qwFE?9R?09^Yq zkeQ7hKld*F#^Dah5M%w0`w=MznM2d_oq=ZHx%E?QO&0c<|7d0!{Qg{?rpF8371zK~ zQd5KV)Ym2)&F~;a-@qdy6a@}y+DZ-;9Sh=T=gU=%xpijdQQV_Gptg|?S55vhjNOjd za5Ixtb^Mz;Z%;jV$!xw#K~Th=We#Pjc$pSNUIgTu2mS30AHs(X{Xxw}oam2_XVB5m zB5hd~(A$5YqLCT0&UbrO*h{~Zz+iqrNViGYPXEasMkD`WN|3uneJXoUQpC?s=whQY zO0UyPl+2R{^YH@~%7hMU5F>%|D4-qqKYrsrUnxO2DIV;Y| zEdH=$M(wXMd~a)`*VnIulhZ%pKOJO*7ex9YMPHusW8_U^6>s7PD29J6K^ivThh9t$ z^<1;SZF*;P$9F#>oh%K0+?p5+mVlZPRPSVsAc-8AnUp@sWQ6sw>l+5I*Czi#-=4iyul`ul4&bXPHH8`eN>)FU+ z#bNP9=wOhKPr-3(8lTsz43a!hEfqCGU1|{%b_hA56yaMzpir zK+@P4*i@8fk5j6-DqYJJYjRmqAVVEGmz{&D1~Byl7h75)r=r5uWJ4s-AZ9bXFQ`e$ zsMIssjW09uY&P~>Sj<3*ywh0g#Ed)&uIDpdHPVf?e;v*s4UdkImNI0O3!17Rg%Qxz z%px*%)zWHH(9AHe=R)>Q#ir-iPE}=XV4`PX+v!93^-ZIU&EZ`QLE=GKBO@|Tb+6Rfpq**OO$XzDzpg3%7%#;Pk8K@$7_evt zVu@>{2N=U#=NBd@&wWr-*Ha~c(AGUm>TQJ9 z>i=*V#D+JKvUdDkLbbO= z^L=*ugI1s={+AOp=*fsw{&r94yTH}MPLfBHvG4H3x%8#F-@ujMy`#sJV=7m6pe>9U ziRq%%_^TtkvLT!_mQETUx7hW(LG*{KIi`6n4@Oal(f(W8k_$W11w*)!oX*cpvK-$q z!LZGH^V&ukINnhEB)c<-(!;p0f3CK5Y(EeB3PNtF)3wNmWl?Gtm9i#|AqZ z(LOvoQJ%s^I@riMtL^ZcOzWWxzoaeTXJ>YjB%d6;fHHKDgrWKl*k`m-m#Av3Kyo-I zP58vd>eNmTPQBxq)T&?3dMg^{TkRnYwZ7c=-_lz8Z$GMWt_}p`iU0M*2kY&7VF|p9 zUH7P??rvh+QEtP=$o0R!4jc(TGa@wo=qWE)%=>Aw<5!0-^!xxLe>?&`8i3ql?rKWj z_4FVODP>aN7!_;ruU_!L?*q;!^Vy5;S2TM!V}HIbwI)DAEQJ(ev5-62@0D`JTSK&B z1XR{JR%f+NRQPA9_pcJdX|dq-?ulmn=0@cHnA)zC6KWxqf>Ielt;b`{)vlfKaeh%N zN-AP|XmR+6y7Ag6fW=$c-Xx5uH!u!sxB4G}8pH5(Gfp7mrXP426WW;23mOdQ#=x9O zB)N${nei2K9Zzt)f{wcDgpY6yXYt`P^m5@$%qakA;Y{QA?-H?7)XSZ*DXN}|8&l1q zXN}imlgcUUNWC@BN+GRCsCKUHq-HXkw`Y8tWf$z^dxm)BN|7Ol?9Cji7Q1`GFV+dO$&4>WZ6}D!P z7;LIr+hrIk9ls=B<7H%fQio-84R21g2Qufq`koQneteDF0SulDx;xkIp%YAk4B-<) zz0vzuuXF|*Z4TlJWN2{{TL?{A){V?=%wMk_qN+GS_w$VjCFh`_A(f35x=R3|9y^aqMxhroxh({vP;(kUTwhz3C~I^7UocFne6@AlwKkbl<7;AWo>B7{l)E zZU72Jd|4bAW;jCVo)Lr|g62cK-VU7LsozCG$`p#^Ua_b%9&+4E@;x+NmvSiQ_v3TJ zd|l{GAZGrI8V=OOO%3DOE4pfWlw&ey3_RsI_~l(f_(WjQvo>0LKv&w|Hq(F}^lOFm zcDv|}BX;QxDEb63vm$9ctbRq7ondEJlD1NkD&LAQf!nr1TZomZ?1+f(>4ppcnx0Iz zrLWw4?jr7DyL@Y{CVmpExx%(1*@^tV+g-xPfkHebc$~87Jse{)xZ=lmeA{9r;Pd{r z`C-o!Jm}?i_J$fuAQboI)iYQP)x6>w8G39uAnB_oZq618UFSzO+Qeqw{x@jKLzEl= zXa|ZkPQls;*TTHU5f7g5qHkHyirke|EhW+PCQf+Qo}#>tr?(kg|AI1$MJ%tJwdtyv z&LxZsc8weAWU*++c3cd=-CuK1Bt$tZaQSEw1+6M>&n_p~k~W9lmWyXN&cZs8r< zb!Ny_t6v8YEFR@v7j%F99_GHAk>{t;?n7B!Oao>*N^aZco?ORB?tJGfp40u^7orwXj3ZrP zRX`$+KVNv$Rr@#H7i^%d)sYtqy-P40U$i?n%Tx6JotF*27X~=kalW1U3_>DU^+thd zt`^gt)uGtKYf(>vx2&vYi=jJh(-D5!K1IITPuYJAVSMq;EB8B5w-ny7beUR^`ZN;* z%-$sMJ+o`3N3nJkVdBY@zbJoL^DL!)vEk%A-ryDs+WAtqLz0sn%63KpU+W>%=PNt@ z??3p?)|h3jJ#x(CF@dy9cA+P2Y7q+x|p3E-}kW{ z$~=B(1%kNdjmh}$jHurG0&`suSAAPT@hdAmqob(0q21wJ7pj~4x|u1V6{LcxFt1cqd9ke#;eULVv{K1;9ylM|kzCATuUy?|-D!0^#W=2xqh>n! zMXk)C_}zu0an=Zjqs0^)ZEuuee>nqE)51yFSVNMED90%kZ#!*6Vs-!KwZ+j_+Gb9- zNh>~aI7#OOfM$m0vAANHj^?@;B@(WO7gPzx0Rw0nwKq3V9LAn?CY~N1$LhGho}Rcw z+;${w^qO%teO@`MDf>zJ^?L_5zgFF4sFFkKt)hVQEfZr1Yi)iG%Vqdu^+(d>4o<2r z4uWiD@#oHr#z5IoOr03o0e_*aT-Afxm#M%q^=};%@H$<%5a`aIFQtJnfv^RbOD%J9FD#74K2B4RKTWV zm?qQhB|LJfn9#Ti46fuJOtr_!sqXL;XqD>MAeqtvp^aKocLbabc!kP1ZQfSn;ePCG zny7*MaE!tb{mL%JnlSQO1|a5(lyz&v$Mo|&AOIGJ7ZYL?re|;k&kacrhc&w?ugcL`wcHmE^Q28o*doRYDUL|rs+~AZ zQ$QR4Jwxz*df^Xe&)Uxm9`0py>gCfp2}PT;L;pitNyY9Nr+z9i4=wngrro|G(Q&VT zcV1(YYpW#l7qEcGI`i;S%rAotovJmGr-`pzda>VPvV{K@115ZaaI!v z+1oa0K!ECb-A9RGV1|eR zM2!>`Y+Q8c=o9^4jTJQK1)JWDb!}EhjeYOt@)CO5p4dyXt@%fFa>0cMFT@D8~CK=o#PeLKT_IF5BZU zig;QUC03m}y1!6!lk7;(t;zhl-w5U*%km9IqSgQcGnulO%d@N?ATo`%@IrxwRjo} z+zE54Pz4ux8!zFns;iDeH%Gwnw0LfVd=#?+Ahw-ay_b608Gyn`Q~K)<5D9X=9!oe~ zF~oDezl-DMe6#Ky9|-MKH?jXY86!kA(02?_O;2Sy@#jYf`MxlR zWrs+htLlS~Gm8=_t$M7O6Yt|oQVtXm8@mZ`;$7j28%WDJl_^!vT4L3sl0oh<&jqd* zZtoKh(S9#cXJ&SXWxC98vy_+&)eI=fW#^oE`zO;-!jfn+c@n=np4e3b}s8#g$+ zL#sTW@tP7UGb4H9-ldM@!5o$fLo(Fur0U5f!Cp99N&=>#x_U`^RCSu3o6RdXTdd=N z1~vMe(dN5cYAyNvonQ4+{WB=5yHzDj#C8F~1G3@S1PIM#4sv{?<=(YZxGo+XH0(=7lNbGG~#eobT` zhy|-r8_*qqg61|nIiVOTcI`ksk3~UBT6F@K0tpT$v4cQSG#n#`qY$$fERTWDjQS@v zO}yfVl#$iIX8FGCbv!R$Pw#jrqK?k?tRaP3^=5!>yBn^4d!0Q<+2zqOzSNN2>@8+-P`F}nqslYH>IlXAox^Uhbt^-4bLTcK zXRB!YeVc~Xnw*uP$~8PvF7$8XTb&v#Jr=F`0fnfV#z&$e))}wN_ChVD8Plpp^@qFR z)Wf|;fjj#W-?QPr5`d${CRfLdd>}8eZ^+i1PdH;H>(+hT_3H)U({YpC((^i*O&7{U zV8IaWm>ikOKCv_iJR|x}C0t$No%Ii^hFt6s6o!?kS4E*Ti|m=I;0~Pipq-omiDj^)!PGB^VEFfqCvb;>kbv z0pGB>Jm|Se##KveZeBAk|lo>XCL^HfJJXsYW{PJLhEbD}2qUh6H#^uSHS-xvtJ~}QFkeMW1 z+kOdz%`3-H&~GJ@W_g*?EwMx)jzBMpuu zDoQN95~WP_KoL4l>kcBJ3g*Q6!f@(ZWUtP4q+!;)6!VImHdZ%E`H~t(kh8g6%1gKWDA)U?CnOg^6tVfR}$POBt zWAM8XN$#M(ncceF6U3^h1xLOHmhbq@Rm64Wm=&vU#PPVv*W|@~>}Ip}l+y@zW2D)j z=zrjt*qQ~ho)ccJvtYjo4CB_krY5zYDSqpIQA_2W#-(3=1@JBR1VO19XFK;>`ah&1X>T1EV;Y)%Czrtq7noD~ORE_>RfmN4 zrn)ObL{rPE)qY@WXX96HiqZ_`r@K z`Oy8-C?qup)8mfWS=>#xrht+*6y5Zd?cKvllKC1ap5@e?iCBghQl=-vQgkYhjQmJ# z4(piDd)};boiXOUg6SFf0^+%_mI&R!-N{AqshJK;K7KENOkevf`)hA|5}nPerGCO%Lea z>YMCEAg=$I?G+84oH*Acb`S${qh_9sv$~gJOeI0xG9aq+s|jZz+~1O~4&EIcIQTmJ zlMC-9B)Iakmbuh8)|(joX-V6}g;T zpQ#x#S=;r>RTS|JhZ5tk5d6m6IgLjzj1wUW3Nt>7ZX0&8j}9F?U;6&e`c{Orbkj?Z z!{@+ZHZJ(>kt&9CL2*-$v!>bjx_gn&;4~2KNYI5vs*?-sP+nkqwdMpaUA}Vd>cqQY zo0LEFXAqz9_>!oH`MMCt@dmEKAVgL~mGB3*H&sVI^7cHKIE%>~4MGMBq0gP4& zQaF^u^<~&Iam>&>v3Y@hjUf(~70yen7X(butWsi1=zLC0Z#)<|i`ATxPu(`%pzi~l zk9^MCo3HH+Sz>Cw_Eawlk#=ldfwbX7o%W#Or{@{Idk+gTVOI_x^e>^TxFv?&V-Z1C zpOpvk7A~!E0^V;0Vco&{NEChDwh*9I1{r%{C%%J@e^93zKtx}dn7;U4aaQ0v@6zi% zXlII=+;JBi;b`K-bBU!x$eZzo;=|+fHqOw=mwxcx@Se>L!|Q=K;u3j7(y|P?WYH&D z)Mks@Zq1>C&zD!LlOImEBQwFl67WTv1+AEJgdzbU>bcgh#k#rT%+9DB-=L& zbhqX|qx=j89peZkzhe53t9VfDV-jG3XBTG!lKs)wwu!k-0jO_#elYO_PjxsxMf zh%>K31BD691|pAsOP)i}`b?Q2-?Y(viEFAEo4_40pYi){+zA=Oy1unnlBf2cIKHKp zwI&*X>kIG7NLd6_lT+n)N@HyhZbqFS8ZZ0#q1b)=Fl@Dr2qL?H7s^^nY1##xabm%+ zFX&LwxEcgrpbLTIvO+w7M#64q1U<1?#G>1u z1X{_6YgXIGC(i^fs%HSqmt$CQVZz0h8$Xi>H_oOR;My-?i={sKzzO@d-HSX9A53j< z#?@ZFM%Vt>Scc)HK@^2Vbp(!nbe#B-` zOZ{a1974AW^r4?LXU1$(Wj zx~!vi7v^y>@3vRxu@q;+l?TzG@lgKjy4Skwq;^>Fq;#sg(@8!A!&p1*s7w|X%7K6p zJRZ&T+@OYUQL!dQ>gCW_3kMpklbDQ4FNeS8Ygw>CIWa5v-+9NMSfO4q`C9ojjOJmf zHLO)y6U#$NvLLI@U7wyruoTQrr`yUfvpwa)hw`-H8YE8Y9UH@A zZfO7&hEnmM&`E2A!sCM?SL$fCEnMDG0DGs`|VO85LJlRr= zv5$f75fE)``i~AQV~@OfJzgb9oiwwieCvqxT(HQ5GzVV3eMV!jBbbUloD|S%;N?{h z6wwqmTckgf41L0DsUzbt6{up9U+ZzOIp6;5i=|XkQz*UMR1&82{)*Ein(l6NI_y;h z*IwIv6NVwp@4MYzY{SKezezzjAQ7MdcT)KFIQWBf-ju9s8l3U{B z;MY=%<@5LY@q&c11`@3dJ)Pr9M9PE0=3Tq5s_!;8dg(EZfgS8;T?9=i+zF>0IQ9>w z3-idC{H7Me_@0HIW)$Qnegb0vgNwaLe<`6_TH%0TwV1mnZyA{p&OhoWV8CwZT8!%y zf>1J{5MgSn;0kZ?Cyq*(YY;w7bmMSDoRnA>uT~>#@fgNF1qqpKNHOEPVQ<`u^>1uf zQZoB6GPxqrcQf1N>&Ca-^q}wAp;xu_Ue%e^c#bWg-nN(Ayb8o8(!ypQVs|nljrGP* zdj84lRhmgfaTOg@Ks27XlA-t8Dnp#*&sJAqbR&LREiUVq;f6f;hFz4eZe>hALRTfT zC0o8yKeTU`U8sRZiP7fRqnKvbpXsy=&}<9u$*Q(U;XE0)5c~}7G7V}3iR~7QFtWJ} z52Fb#TzFd!_yguQbZ2S~BnwD$H=C)cXfX*JDnRoS@$}l(Vn57*5o@Gr8EmIJ@pmp2 zR_>Mn``d3zx4+R;ipu$_GO>{t!Zd*u1i8nKc!dK}WWUa07dH0oNw#v6O?UiM80w?s zNHJFX8tRZcvTQZ@=i|Gz?t(^N#r#_UiGjvjYoVLi@_8n{^a2nTo8vfZc&hr3uG2&4 z7v!?05cXwgtlP9o5tNl36LlN6T)reGExJ07g~O80PFB44oLr(~(`fQmV1CA>rIm#J!t zuj)tu4;Q4RMeKK9;pewaykC=A{EiF3zzm6ju}cL&>Q5$XjpEI0OO6`Yro(8MaJ9XR zjogtE9p~jEjO=q> zEEaa&Hq2y*-@q|6LwmpVhj9r1wZTz42azim*g`ZO1D0%T43kM@5+XUocEu0adZKIO z!mcBciBfik^CP;16ZN3eLo9z;44q^w)L33em{l(!JL;9}Ou~Vv%;A@*wE)toZP3rd zq%hYz`JR;bS|qpNK*7|(0Uo4Ujcv*ZI+4d%avSiwtihvKvjeOdYPU~~G_bKNk12cS zE`K?QQ1*BSof>9JL?po6#*d6Lu(J1d)LmF4Cqx;RU>x;>R}vcA)VWE+W3AI0LU@9` z)br`BiwCx7WGfD9DE*U&Ea+ssdU;UEG;~FB>&fIR_3@`P&?hs(z_iT61Q?73=06vl z=G~dm6|X7f-8VpLprQM4Hxt>QHC!Luqxo?36N=~cq>?`m?~EDS1xhlvg7{fsm@}Eh z;+()1TpyOd{M)1?HQ$)C5(By+H`Z1V=!e?#_SB%w)>L=LX0nfdYK3pZ+{FJHZ64}! z5yHKQP0?H)d>e<+@Gt3v`~Ii0^I88@e&ET%Ly#kUs;?CwiK3adlLALX)0P#vScCiG zuPE3K1Gd0K88#*DWt3V9EB<&uCO&aY47oD7Nz{GU+!rZWwvMNJ_T=FcJ9c23UO6xexyg(KNr6ClH z_Qwos`|t?O*MSlPcBY~(#7`|}^2gbgBR7oC+&od1O)yK+_pM&&YSt0S_*E?f1x4wO zg=qw`0MgcStf)Uh`IzA>{T@lM(*+4%JF_I76a(05j}QhRR1?8fIS0XNWIW<{48SUW zEdP_dj-k~Ecsr~8U}rKp%Gh7Z_3%%^pbb?3t=#t@slj@ z9)0c3jG1!?+gG=CR~7jTZ$D5^!6>!fe=jWpvesaA`x3dDR=En&+Fbs{wlKq4)7w+($o;-_wKH(9gwqDgG%2`4=7IO1voGiDiP~k&si~6 zQ(~P4u|j|`oR431XHPDDM8Z5oyMnH~&}6JMxw;6oTO%9-ixNfx>9ZAvw!P$0FRURg z#+pr!@Cc09A{|qp)CGQ&L396;yHDX&y{`p+r3SwOft%OSAW=dE=tJX!YX*7#L>Omc z?~XHL@b?iLtWHhY;98TQ1uBMIt3Gg+4@yi6ha)aPV7zsh$VwT`O9A7w`Q9=dgIHA@@$=xI%W9pc_v^Azfy)2hpOrRk*wn&+&EKd zG}N!8*H7V%E%(nr7MG(Dz%hrW8+)=F2f&PVUrXd=$M2`9{wDe)fRbxQTtF&%})WYI|E=ekCIh_+uj_0(laXBr-9;>A_TdHL_8 zqW)z9LMq`)f462#MY!vf$h71P-`F^mQSeUXEF{Ngyfwu?#wUK_yw8iLuk6>FN~Fq5 zug?P_B7$&${AgmMX9q{Fppt8wwC@FyVgb-C7yGBoWelr>e<0FQoeN-jL+7oEUeMsD z`zH{P7!K(t#~dkDLnxqNyraxdq2I=vlHdAqbqPsik_`0|u?C8KJR4hy65&x&DtLK-Q+PDdU={ z;T+^>?r|n6zG}e|9}@yitqmQ@=Kbsaw}C;pe7M3JMUUW7F}Mvc$2>lc=Ip&vU=QK! za>F+C2g&WomVT=N1`2R;ve+OZt?0~ATTNDKAUaud=!8nkHI$Az=~2BUiNz%2I; ziF?bht^Q2F(4-Xx;SRq&BOe*Js#(xpg8SD))9Bx=a>qWoVbb`?fgNcj{>pae!NSp* zVQBV*&9$92`v*mCwsP6Pg%Z?ClY76kZRK=K)ofE2W$}YUf5n??V3UeYe$cdh^r6P{ zYP+n#_0@)k;76hY`>$UJHkJVj_l#G5#4xo79%A4eE}V;tKkSJC(WiU<6U^;-VNxMe zlVd$o(`8B)wNXhWr_QlYxlNdV>u+3coBLM<3q9)eisV_JJ+00n=?0hV6jE3E&~(=( zraJ>LH%@5>Sfoke{}e3|R`=i960$J*-{UTX?((k~tB|ADp3MJFvCwq=K3xN4ZM^Vc zfA7+B>xRr9t2T7}`b`+!P#W3UL;VC|)CiFa3cIf+3F5$oqfwL@XkB?kAHvfDYmR<$ zAW!_CIP>!(+J+*#K*^5f9;W3_zrW!fVt(azxCEUx)2o`{M-;q5JjnoeVg5IsQABHL ze&fI0a2KZKKZl{)!R6S;@wOuMm%Rbrt6MYxyXL~u`;<7{Xqq0gG@MN&*8%Sz3_YPU z!?gcY_<{yVyOk<(XhTwTm7y;<Jf@rM?_^XrqJ&kI=xS3h>tv%xB7a(wz4wj6H_w=v%7om z4wIV$H)d`;l>PI|n^P-3{ZRTeTF2ZJrZA#YuwX@l@1qc4;5Gcy+k=m6>m@VuTR2%Mc;$p9$||+1Y=$= zGHP->utc-l%9MZ;dX8;%RKTvDQF&NK?a9IW7pMa&vG<0$r^hE*h(9*D<)$OoDeIbP zI2YnOzYnRUX@IX$aIYx9kd)Xeonay4-haCs44w6?0>(_JV*NtnIcYQ?;AEz+LJko? z9XIuya1C*Y&<*RzlMSH>t^77}?fv+lZ62>7O<+p}3g4sDWjId7O#XRuG} zjg*?apTTUc$tL#D)#jM-rkNtvEGVZ&*beXAHsTi}KRPokW|8*_~3`cjSd+8=`Dp*L44);H&QCYDK1EDb`ZCS+lp9wjmOElW;5Zv9J;1VRbHSX@*Ci!RXKl9Bz+=u(pU-#*vPF0eca6#VrV=%I^>X2C#{^kOM{piWa<@Wa%Zfr#dgfO3n zi3v9ch1P9`ln2hhKDVr*#j2FdYNsb2r|8{-Y4pXX&70-fs)K;I;&&wNh=9B@!m(P6 zGZ$L%dXp<4?;PTBeSLQtDQSg42r`@ogo~Djl^(=hvg^Drp(qw|<;xA7}@=~T&8@V2B3S4JPD2g=iQqqF4S+8jN=*~;BR z5%y6lD1id58w$@W3@sDesU5n#1Wxef&-I-a$E=_~zUWf;m>>w;E42iwH7ri($kA!2wI|x^7 zfBP*MYUY@}55V}2q*3BM(1SzR!B#;!A{MHEUQ*QR&DSZg)fa2uppTEMYet$!sUDn= z+>A9H{-Np_9C@APlZwc0Suiw%e5v@&lIFOE`#1G3&1+DPl7$n1x!ZG+k_L0%-mEsn zW63A8spQh`zSG__hQ;vKXy_C;nl1U0Q(F{#&7V|IX_A?~L#F5(#S-DGyqrTv{_>~+~NzQ@#B?Qb$!;4SE?lIHm4XWZS{%%F8 z7(Fd!Y@w>_LUk;rq=iI`Z#%$L+R@cI1LUj3EX(VlN&B#~bnH5G>-ab#Lu zkbsb7Vl2M^5kTF*(MA>B+@(v=>KIk`v8`iDG$ku!e8&g}A6Z{t7kwnnty}9&2^%Uq z>r%eRK-L;FVugiAsGeJXe*PUr_%rmZ#q*7(F(Tku`@wf`co@am*_p){#wsTUj=EOK z6bi4Pw{+>8%Qn&bNF+jS2ruxXe3;)Ii5zv4_CT|O>2 z&I3p^ME3EUm;h`YV`}s?yg#6-&bK6wz;<*cEUHNCW_^Jilb{o>pYc6qwz0?X{e#!0 z*5Vi2Bpb2BLY&ktlp0rKOz-sNXOVFuJ%oxxo$AgnTuAASv9EJlFzhr~1s^;KmkF1n zVA*fsK* zTc7godsUnQBY&(JsIX1mpQkR%;v`BR9|$*(1$$MR>Q6pv-8oI-0jWnrU=82mSH4Ub zx;P$pW3v11b^lgJr$|^t0|`$p@fT+N5ph#nhYdUw`>wIojo-+i^#|kRJ4Y$v_PgY} zT}s#Oqpko1{>)%UKcx^;9C&cyoZZrRs{?=pCc-=cbqaL%AF2QI`5DoO=YNqraoph}dA;)*ZZ z_VCIi^mD=?@rC7)(J*ebn34va>S$K*M{dKlBQyBg9@J$#H)%RowDx@%h8K1`u*vK# z(`%FNvYfXD$iH0IE@52@yZ}0xRXB$2kEEYG-1q%W%W4pag~+2Wi}ZQUmgpFco+-aJ z`GjO`MSY?Efaz{bpUA8kNelsgQh7x3?K{?&+Pk8gAI*s3@b#|p1X+s1r`!T!h#qmF z@NQno(!|-p!ouFoj-+w(daLW}1Hv1NzEAD)L`rrSPFuK7gzH?~b?ZKyN)}HOMGNO~ z-5B!tFlgf7Ba=NT`Ky4HZO_(>tWK=i0%V#e3BiDggcX_pZ<$g+#=yulb zO@=Qx()f7=4>Ue3y4sxf=x9AFaNF^wxHOnQF4$vlm#t$}*{kcEH8#_#IV`odHmJ2P z_P?DoLC(Fhv(6$O&1g=tln#D7+}MMfSht~?+1zi=ON#$<(rjdM4k$r%I_u)#^}c>} zCOvX0i4#)eGkhe$ZhjJr>1q>QYe;^nQJ`~|1et@^*qQ%&xuS1zK`3JjX){nuU*x?D zGrNDjVv66wGq^atxCZz7d{h%6ilE8O9k@`r>Qp8Xt=5>mNm&>5wb|>G#D)2-W|ocW zB-Qwzp+93Y=y}1lcuM@bW-Zo7z?5)<#AqEp5C4n&;y`G&X6M5m8bhgb{ z_o#rhzHwbyY!IA~NY{wH(ms5PnlUOtvu!8w0k?n&0ld7o5JY_b8;J=JSw1Do^!W7I z<}O)hF+_nI)L0aDA1q(IR`rd^{#z60y5NepY`eFN`CFIc#SfzjdYvDiEa>s$s12QB zhYq!$@U}OWl91(M9nvL#9^RT@&Dz`$FXo>(K5k=mk2#b(+V+nulNv0#r`Ur96eZlq zYw}gIZ1{Hdj+D`eHO;~rmN@hDci_3SlIl$zIuUvAuEi9}S07sD?b>xhHaI>fmMY)M zA~)!oqHNEjXLKz^aDT_d9Qe3P*ipO7nkKuZ_U^;FpjRP1_f0phmRwb37TJ^U{?&u9 zjlzJyQQB!ngCM!}s?obh@3gS{{)VTF%x%?-C=+UhHIwU|!H*nQ+qpN@ixp(0jS7i} zTVL%_4zbC-!(~5&v*)pHOmJKUn(WuhBHS7>s#gUpwEGC*|XuPvj=c(%pk@>c^@h&iu8U!Bjp1Zje zk>$o@W1Eak(2n@Btw8}6#h|p+mWW@(ESK}dz04rdGd2$1f(SvZIz(QK6&0h(7mH%Z zcBke~?8S00iNPT<1m;5o7?H5faVl!h#l_%>5g^QKU~)C{yN=;S=)}atl4k^cOY^9Z zg;|W)uP_-YRGt~yMUChmLV_5Z4LeR$K~>d$3I2RRa-Nt`RY0w1XRr=PJlBU*Jp}zI;lldljbBcO%0Vysa zxZ%*k)kICEMXDYJG(baUM+|_*WMC-O)3*sLffNkG{ct+J8T#Y6Z?+Iui&!9d*A}(! z@l!uWlD64Hjju4>WYSVV!cxyKt#-j@6rs#~ZOsTbHv-ReD?Q`=FJ+ICl)|aO{DEk_ zw=z6#d;bu#NzBd76%k9ub3^INGFtuZ05qb%pou zl)aXT>&Zix$t0u)>0b5k1u~~KgjFTH9hL1)h~Yu;-hin&b)GKY0IxtXqZ~u=ed>Ns zxQ1`X`5gzw-6cphrTZ)vcIpo53_j#tZH{<;{E7uiRu9h2b|8zK);>7{H;WJn@+KUU+f;NZwL zda;5yDpn?_YbNWin!-;k#z-EmthnLzu-yV3uvJ}JW}HVLCq|du0BLB;@c9*?f+^gY zm>@o@)QgT5<~HHoe=}gg!O!S22TP};CI5|QT=&H58@)=ds`J9Ntv{De*Ir}f@|FDN z`;H#P;d^^jG+vf)<{Z)p-?fw_xzwZkoqOnXj&a;~mO=}iu&llV7nwHs_*Z z8RzAN>>vs`I2ZIZq_Ht~E4SjDcP74)>l>4LzH#7gNel!=J!{(sDaQC8XE9mU;ol=s zt-sM?bS-wFJWTU>W^8R6QLsOu%`l~&vXD=0QR$eX(&7Q`oQc9l1!Z`=8FBNg91n!- zp+=CbKMk~juDZ(1-c;Q-fAhQufvI1Z!ARZIFNMufVU&-n$P z3{crV6t@KfzcB~`>MRzM~zY-X)j6> zcBznt**PkLR3B8z;_$l<>2|K#OJI3t35RR6jbQN`>gdr*Bync}X6j)iqF3r?yRAt}kx6uk4i0jG_XBYt%2myOD5q$c-c^zjC2;TD9(3*4)PhvsXX+O@DG1Fp@ zxu362Dn~l&J_g6e7ktU3Ag)Izky_2*c@#5sqtrzIHM`ioyx}_#hbx+y5#*p5wdyPq z`{b1~&=b>FSTs2xuIi3Li4~WFo06ln5Vdo3?0b;xcw%UpGxypeAFGg%SCKAUN%?E! z3yBigvOUv5?&VP%{Dv2~s%Z4C!kBdyP49foa)4fuf>{8Qc*aJ&tX62A!_EjQm*|5r zr4g(J9{Se$)vg$i3%BmGQtTX>fYeprV+MW2u_uoa66~g%TSy3slm=^i5Jo2By}^^3 zLu{oXqKW4SY2FFDee-ou3=C&nMP*oB=P%E(ShIxazlfFqvyc=_Fs zW-YDExA)QXY5A@2@0~!MIV;W-9Aa=1IVhprexREZ<9Kbk-JKPv(sWp!nr9XyCz`t< zG-@oy$*!)L0)5Qd4wS>7s8{%QVbk}vG0ub`TSuQiF58A}J;IB59 zheWr8d(Prbe~%sVo6Oc8VzHct8c?Z4S40H(_~7VaLY!wdXw3QO^r&ko?%qjm+T7!8 zB?2~xZhGrICnZ~${^11Xl#nYnV(^xJM+_zbr#D^V;)qD}Hj#+Y!%XGZyNyd1-HyYL zx5G`*y{FKxH}EPkNlEOqH>emQW-@fbTDtxKMclyW)(CJvE=cA$ zgGJd{Cg(c_ZVUxhW9V6;Wz{{7mqy~TOQCe^tTC@8!GxaJE_9rz8)j}p2xgWmJ|i*P zf7oS>_Sf?vYfHvFTV9uVUtPTYd5f=D`CIH7+-y_KbnZ17pVX^Bz*j~xG zF7XAZ!J~A>D1BqG>T(@0Y#ZHCUa%IJM7ts9T6dbUhxn0{ z#iozMku|)xM#P`Rb(rVkko&bQBNzq zLDcd#A!4$sZv>n_*!v<#16*bf#o~@K){IQF`e(?GeV$n5%4~ZZ1WV-mqeRD^s7@a{ zo5u+@ID_xB#~1jJ3q)mEJXL&vY7XiJ;XXnPPo8X8+)N!`mb)*i?b;yxIeY5q0ws+i z@qtt8n@11^PHGX1HRRuX>eI(5c?7`bap_T}f3HYNT!$Y~wiml0g?`@WpE00gvdOcA zal~PYORHBacTB6~4n5|a1JWTKkMaB+lSGk^t(DLI_;yQ{MBeG_T0Vrys@f4Z9xgFo z)u2OvAwn%PNh3x1I;16ns#zoaie<&}7{!0JDjIDU0kCAoJI2V#MuT>jZ%sjOr*c92 z-ZVYV$~6dP5eM<0o`REYrT~zWEkah%C55-qIu4^f)_Qujq@CO*{ObQwP!lLs^Qh19In=C_~J9%3;RMEDwd3>yQhZ>WIb? zy?sK6|J<7&Szk=eVy-~HJkU*1cT=KLX7yu9E0dqTdn`7dJ?eVOu~d;GH|FYjNd z8UN#u{@=TfA;LA0Fgy-IozwF?oOeQ)`03W?vM;Ic&2e?O7#;9{wehuR+PT&A)HF{7 zvQ{gy1BA~MkO7h9i@Ep645yz#wJlWP^3_{)jvd9$&+L z(7~d<+yzrtRk<4Ah*c!#N(kP%#_$MTEjfyxk$bN)gLj0I@j*X2qV&XB-%eS;CLKY(58qQ=Nrcqs(|3EUV zc85YakQEq>pCN3oLvdv#81PBTyT80yUUY93 zma!$jgbN}kA{ddvF4#Bt*pFeijdukLx3O5Ki=nj>>Am!*bi2U8eEPmE;}YQg9`u@f zEUR<$(j&&;IDDD0MLm=K?*X&S*pw3+PL0#ZeKHdh zjiDRw8%aF7(Gx0su=L0`DuJJ?9UKMGs-nET!W?$L$1V|ahE*FQ>7JM~xHw)$TjMh^ zyeVk^rky2Xwqx{jk_xizm1k#DNarg*y5y*8UMlD)e4xPSn3=(&j2&p$1Uw0(Zu&ts znL|4gqwC}K`r78zxdM11U~1PyJ-TWsub+Q2n*MAjDuOg$RI9JjIKfyQou~rEi2G~# z#fFF#?>nU8wkM>FRF93`=tP4JX8LieFX+mH6YuOUwk2*ZOYn5d_N0Q(F z;FY77f_cwqPzKwT)7v~(>BW3Sz8q;AbhkDOrnlql1^w1_x~;xE_N9&<3eQ9?4Y*(;|bb;9xSiR)cQyG=>7{QQC?SW=t3PK6nXI}i>a&L%0~{JrK;@_J8&y991YI3)N_tKHN2p}I z6KsVSRmy6BMLgd8LEqF8QC3zqL_#z)>f#VDNzH^ipAEx65^s4J>; zV|6QV>myP3MJzdTpxIm%9~_D;EG-{BkoP~+#v?;;%=9&^pC~YP&kdBtbWj4!R;Td4 z-8=fl=j(4D1!MX*!=xw;yoIZx6vI%b>+Si8t+evf*Sa5V#3QmV8)9kGmAnhU>`>i< zqAkSRMziWtaM)fi@TZMQO?jpMyHu}2GAT!FqS4E1PNUks5l-)6GiRWQEFk`Yvin`` z9l^z!@M~AuOSfx;od7jS&i+z|S&G>m2(%OV%Yz%l{T@m}6d6)-`qigOgiF4tzV)%? zpy+QY`g|`ZT|A3a4(pQ)Wb0QEdn2(R=+EN5$kWnn#_RlC^=iyxK{x?7h<8f2Un*RI zLcuC>&Y0uy*&-%*+a#)eFu&&6RBkRO}fDG^H;d-{A-y38@{L4zyzb6>ucY?v_tR3krx#$p+MlLG2IFgSYWx_YRD-8=ZJZb6L8itCU)xh6 zSGC}*p=7;lzvVQ!y6jkV(d|qwJT^4dgMmYexE za&Cv5DEpIeWq4Rz6|;b=JM+Z|r%vwTw%%=ap-$QE`)(zJmVgmyGjpgR+6KIjbR2<& zZi2ZR4iT~z-<9x0wV6PQH2qX5UbVcxHK}~Zbmc~FJya?2=FB)=a0%|x=J)s$p-7<5 z!-nP4M(YE2Q#%)D&lQfRo-LPsIF46N!NO`xx(p%jRPof3;e@umd5ogaKrHN>40Mbl z`jtWLtK-52V#>-4;+ZxT`V(1!apW{!O&Gyf*4@M-Z<5a^)DYzJQ~VJDo6$7!A-hOc zka;SI^+ShX(S?7d7*Z1hjP)K)1%r-kM*Ll0d{|_P$tm`1y02oI-duux^M!!B>&yNq z;~@|e2TULmg!lOg#7Bb`n84hmCn9lBD>mnOLv)68bBR@{za;rLQBNvSh%3_O|C)9RGAIzQ zaiTU7j$I0^XGfoT{U5LK#(R30M1ZwOlkc^+04j6K!~4+yQ{oj?jMVpf55W#B^PJ>a zQA7cqhJE_0AxRaF_WZ9Ce6Wq6zItp(O26kqkCTk*|8n$Lc^-w@rp1E{Rky|9^WvS> z%|D#F5vq&nSaf%Nqx$Z1LW6}i(%S*>VzqcsWN1taKN{oo`w?cVo-+Uoqe~ogLwbJN zRl%Cf11A1K>b1I~c$7)U?s3Ci(^FTz(wpo{#hU#*G~h%Wdi$LADy@oKGT-}$Enf8R z^635_-Y}Z1C{OvY^HWGG+Cia$OcGiufZ(=?{ggcqn zt2cuVUrgjre&~WXU(&d3$#^z6mnthO=UUv@@fd*F?dFLPlUWGeXT}gBH0cUXP+Q&D zfUpBvKNqX!$i&eQa9JhW$q=Hwb0g~NK6^>HD7sUn8;%kKx?*u)vENi#n?dpljP}uW zxh?4&urM;AYHU?mcP9V4D@7(FMl~cQr}CODOcqe*AZ*zFYOdmvlB`560Oq`4W4osg zcs-(+7uYXCo!C)r$L`9vz>m;ZG?o?l^q6{{D?x%pO??`!@ zxLwK`=uh5l73*sHE4#NTN+BU5;^uGlwpZcWX#`pD!l}BLIcydQB8fOfWq!s9k+i>iP&vrV%)B!dQ|)V)dT}Qnkf*i3T)L>@>DBg^IoWn& zFg@b(m~p;G=*@-4mZ!sJHh2hUAHT@ZtvKm*R&Z?$0dy!wWQN-o@JCCvw~@mEvFmL* zl4r;`mfl15@QreWik$*_$VRZ4VzfFpzf!UN%UE1oV)ZKj(~bSawRGKH2tXTVCmiy~ zpA2^zAb!^-`G;5RmYQ?GGj^h<1S^0F^+r<4@mi@2HY6mVfLUf0*1N(ej6XJr4?h!x zp{fj@9BP>go_+0n#dSdq!54hQ9Ia>|4k5a+ui!C5&mJsxQ49CMn4vG!vA3^R!I<94 z+6IpU7^Uv{4Az~ymb>jaPwRAftbM&2e_qwijbiM>JYGAAR(R*g($1MMgx#L@#}OM4 zN|ZK$g4Yah=O4fbqpql{_E&jl%~hJjs{fMT-{|mkmdo^I_lRj!`_( z%CqTu47LLdUp+qq{xixzbrLhxM^*eWnV%i#Q_CIPd}2>DmpwV+nPEe;QG`Ryq*BZQ zxx)DpR^uiu1nqR>T1x_MP!C1U|mW?rc5RJY6ebue7*FQ!OK%Ycb$$ zyD@sN<97JDgwGB2!%}s^N9rVzvXb|}jrc~Mrdz&)rbH{Pv;K($I*{`$k{r?fyC-f- z%$br~Qp;IyfA#A2j=s1YhF1)M4D}rZ2#FMTqnK8U&L}BP=lt^VCKCFGsaYUu5pylb z%0AotMG_f^o0))(#J4kcNS^jOGYk(Lj)xlD(B-yvdp6NLEutWbO0 zWM4Qn(JSmpJ7TkCd0O`IQ7lcvj)mNjiOYHjW{W+FTHaXwZa`bx^#P6N(D&8~44tke z1y6YX>YwvC;(@4(MpT=YudOB?k1y$Jm{aKaW>Vp=Ue}(FH$-ir5E`AKwwd7o@2WAZCSdLkB`OYKGo@Ao(?UKb3AhSzzJERY zZ8Cd6rgM78_uv@E?84TbF41(I3psJL+EXh$%(tiyLGD%MoFWr;C@;yLQ^&EWal>4smog#=Mun2uMngx5+)`RikH_oSk zh&v-DlNP~OmnDpV*b^{kV1X%B&6$%_Z|E}bCiRLG5O^yqTwMMsfuD4CbVZ~r7sF0p z?b6zblOt%_7ceD3sDywN>L*9jow1(;x;3GT-z$g;fmj*jBEK5UiyQs#t~vksr~MFh zw-^7^8KZ2MkOX2)K9&71vao(xSy^^J#m*uSNaj4?1!$su@t>_|N{L+LkGslVTeh6; zQSeBME8_O)Ee-w#ve?3uEw@FipdX4z=c0|(TEZwzd~D&|r0Pl9)SFE_obzynpRpB$ z%1J;xI?#+ZUO-#BSazCoKNHjtT*1}3`cC%&y?3yDYjuH~Yi;imgJhu&y;))DOQ5MG zM=5Pz;URs6+Zd~O{yRRJ8NcfGJdOE^pRa0r?exXPt7!W+hN7hr6l93c)TA z{?l#@i9J%mQKH^lz#52+lgZ?@sH}8vA<&M3!0QgxuUh6qtuZ?zTL1O)J%TJZxdaRH zg|l{3BwhwwZkrhEsPz)MQykgO!XRlSH@e|n8hdQ+sYLjleTmi+Rarm)fVcRS4C3jD z#WL=)s{O%}8(@p+4zpksQnhg0&T7R6dbbJAY-JMrJ0-RJ;|Z)uxoM~RBIZL27=wvS zAdIv5y1OSI_WjLl@dZB%8m5%0{-pqG+szHB>zwN4FvAnpIPqLFI~>gS^TXoKLU8p7 zIMo%!vy|3q?*2u4anErHO|<~JO};hO(Hfg38W`p%gK|~25L!)pt$#R^F@QBK)vp?f z>0t-orr8R+W@kPyEG;Gao#b%dCBWagq5; z$pp&Ijv{_-o;87 z`I7UYZktGjh_{Y0#Xn<$2G|&BZF|f_BG^jEEKty?Fr-SMVH}2O%iOaaci-LY427)poPqQ2Rhn&wER6$)w;mx zM8>;css|t9^?q&%%sGX$wwo|LXhjlFY{ZZ|A(6M=bMB$1hPq{;1}ns60?#hhc781q zGke$I5c{b6l0jV|2;Q)7m7(`(%Fb@AcDC}kUcJI=S-^z%N%d#HW=Bn%GRJga#6V+Q z?u|P1sC+)L@nrvnZkbfxGaWyeL|hbu5eLmYYXWk19VC}acnjnzHpn>2_*^L;9?uY>^9XA;Okq=`t} zF!vAC_nodG`ZBz|Fa39x{vEgG#KTgGtEnp=B=yKnhfO}SEo?>ru2Y6VN<)K41)9DF z0rW>}jr=N{f4tZQ-<5a1Yp@N<{rU)DyRVd`N z*z(OQYoewuh_8)iBbaTad;Rpur6bfX_Treprd$xXe;$qh#m zuf^ayVd{=*K^0_{8_x81ubMIX3Df!I=Tpmxzc~E+L#C8;64H7U(30}K9am5lm6buY zr2;5fhRv^D{j!!37g2$W^28N;`~bQUr$cd&N0|5z$v9`#3VTq0Oek}g5?=T|=G%nt z8u-FJMAH3;>hhUUZSsai#Zy493=NIi-ef@c>Y)(~ed6{JjAXY$dI(Mmo@nLkM7$C~ zpb#s2{dkh5%9xv}{?M)$(7VG0h^_U^cz*AXtjBMVBt?b$A8vZeRLM2nY3x#Z%EavAY z3TF3IM4AXEA~o%d4;Q{^ie@lr@Yn_j6p29p-bl!jWJ$zny?8J$hdXtJ!)1T71AZ6h zIzrn#2%I!Dc$E=!LZO}=sk{2(9P^S9*;VHZpX|d z^?b~hpRy~>iP`lt6V{;57(G;Pn<7xNTQ#}S^HZSb!BQKP?S)O){PN{DIh3xix?|tG zR+LU0T*@k~obg5pPVV~W>OA1R-An16z3UM)nZ(7&N0WisLkrK{$#oW<=hNH>vW&lM z+bs-$8v7VO6@W^2AS{H8TnxlB=((o%m7t%(-xwIUPhovch5a?Vy@TIXHOmv!Xrra zlp$DAKmbW_%>@cw*yif%x*gssZUg7Cj^*>Um`b*xb9=k39h>xsO5w55wxE+w1!6Ba z#4z;t7HF|nD`0buXluObLN>dgcReFoX>zD7H<_e?Mq*pZ?QLU7gB@m)Z9kD;rv-nR zyrlzX#J`l699Osjo8_Gf(n@N~`nR&EMHDK9e=Ttj=p2G2of`~84QSa!Tj8b|y#Gxj zq;LeIg)+7frq725{+sss=`LOO6&#umR4^suDYz>Ip@K7=`_zUTgY=9^e?CCzWHYdKLGXSZbzt7HzoE_g7F7GF1JBe}znfriV)4FO@T;4MKg7nfhCW{v>4Jj6fK6=CPG&cu?RBR_i#$y;?afR^dH?yR26!rdh zDB`D>g)tgsH~Z>T8zGrD{Z0%idDMm#wk*TW;$s|)Bo;)&m*5YqKOp1>d)HEpQH(D~=fVuJRASnR|2XzBJ_xZr z&}emdj&P7P_@};qg?RrzMrJ90?K%ECAiY-DasKbm`csmqe`A|3b92KJRZy_~cfk6i zJtS89XWCBUKc+4I-L#9{bd=ySEfiY=d~0}bLKeR_Z`Ek8X_52e z(i9Q!`43Jb9f?$(Tj?_;V?;OIM=iW}2$Rg?P2ql>7P7=`ki*XO>@xY121OH*5=f9T z*igboE&qJOOC$gElI=A1oonIK`W4up$Lo;n!_x)akM#C-HfDwW^3m!X-PXSlimEmQ z?CdMK?$4cFWd*jZq0oajRBVP&9$3sNO`cqv@Upzv{_CdxU&D9<0ShQS^0mbItz=sV5S3{s?GVw~047lz4yUj5(+}YFL zGJm7-A2mTj&uh_~K5EfdIqhoXv_7_f5f{pNKOU_J#hg!BWM)&t_)&N!eJ%r2ga1N5 zl!=*K?}s9Rx4Xc(R08}*<0pAHsQ-Xs-r{EnHXV$ORKH_J)Z{7?b9L9w!ha`~5S&)O zzWTe2wy6&JOLH*}^oFL70H7sJuH)FlN9s=)-$&QS$p`Rk^=BA`oYqQkWw1-4&iVj@ zqh;ao5kFaiR?;ZkNph;3#(sHofJ}VWgW!Gg0ao4)043&XLgz5dZQjliJsGmZzp&H zebo0|?3-7zjJ#UJ%{`z2chsJq#Kcu#7eKRYUVivCu9;sJnA%6f67&Vy16dX64A2B z@iw<`L@1NW7m1DYD^7y>z4BH%q$zYi7B|VfhC1PFc#nFArWl@@jqDe4alv3xU=eNz z8mfsgQcpr!pM9{ zPh+l>;fvY;3Kqdl=w_P;tz^S{l^DD~V;fWek+kMRMHOE3akb#-VC%Q+nSEzo&-IJ69bWB2hm|CE#HDr{>46wjehXem^E{J#$?tISaDMTv3dK zm``QppH)A(q3$l5+|rkstP~ZY3(V`fYT&4RV&?x(bm>IoUI#T&|K9jEUF~4w6!*^6 z&8jutqro$UdCFM4$5>dqF86)(v>~05guQs6R`(@*|IfXsP)JZ~Z?1AU=oxWy zdwb((sd;C*82=4cD5L}zB;t-$s}bq2J(^=Yln4TWSeQz6Ag}4^>8sn@rdrBDsFMGe z4uOX#a`V(Y-GDI)Cy_!Z%|s{Jd_}sZXMQ82rb*eKV{B{qfa~UU+MLXnCE~x-j+`*=L9>~wgXcVQPDjl0CSPG zeeAxtK-)P?yykxG!~b{}czZ`h_^sB6pef=sJP; zW*gREY)g#CY18GQY5z^0xAu6K=AfW%MD;%Y|H#;2otW*+^pA}JDFG{;`TXQFJDW(` zH@tI5Gi?`ewrGeJ`FwEHu&h}nvxNSn4{>a>KU{PRzLwH5+CLU88zu8G*I?bi<4Dxvg2muLnA= zncG6Y!5;0bbdxtdD0)7(M^`wWD{-x&_ms)jPvlMs|8n_p_ig=YTA|0S|q}#2VA>!qjTn0Y&L8TORGQlyfNJhvTdsuEggmW48*i zXlFFw?cgtXH`VjYNigH03e8$i-HP2=58}aM9a^WksN=yRCYP0T&+JecSa*G+mmYY6 z>sP(av^p5+aN`BWtZ{dH-NH~r#trV(>i)xM`OBQaA%`$$#=6URpgp|NeP`I9EPWP! z-c1XZ{BA;Im9V*ES2QtzQVC=Q*4uO84KI8tu4mr37W2UP`lH+7aK2;aVC{G_wT0lJ z$%yw#2T{bv9&eI;N}Wi1&H6I=@i4ZIp{Fs@gW~)spwm;+zPF+7SzMrZA%bXyRJEjdWmy29yrenu zyK`ak>14UtJ&mqfYVf@=(*moF2-3x8JLpE4G;MF`3`s?IffwL$eL-Xw{W=vlDHV_~k_9XG7_L>1#WsM#I;- z=-15F{UwbKmHSo{Oyu*?0>RMw%X!Ee?sFn|4$y|Wx+v=IEO5^~>oL*u2qWTh;zB&%aTY_rOC$bMU8ug1wi9^LpDd z_V7;}B>8XCgtL%V@!^(@+k98xs~{6%yxk8CFyXq}?(KJ|No5S+vZp6l{PA4)`fH2V z_fN47XMX%gC*NBEGE zP!A_k?;mCjwdBhp5`@zD8a;_-^$$!JTNnASeyj1SaqHTg#!@iRw#N)9Aa1uMkB9DG zO&TzL8nG4mxzy$w)tnSxTHaie$G4~{kY<-<-PoD1hvKwKTetSz$0)w`E^U3Tns#;1mOh02{5%kkHF7-j24TPxmg zO=({p36GBaZ17PLE0_lTR>E&oS|YN`vTe^_ah5SJ%+W<;X!xmX4K}#({v7jPv+}-& zEIf|9DO)<>ZjfEuy&Izr%G%c1ory|o$<({u#vD`XH(@sF^1GGhIlClfIsd` z=c2Tt6yBg)fCgR$wq!Mbegfty%r@wfmAbd9;0M^*URrlY-de#X#TYL}%a?66xp~-? z6P>Fm<#QF)wJ>O#(;sbT)Hg6B+UVOL)f;y1YlV}Q+l%~^xO-A=L>Dk`<>#?UuDE)% zqsO|Jgf4h*2JxZGqYb+lQ6_iqp(f9L{NmEejW zZp_b=_oI3o(jQ5B(j;~7)mO|LuFE;gF|gWPx9k7>N_}_C&0E}D)b_l0*W3U34?#I* z9y?6mMjr|rLC?ShO;&d3LwgO<+Hwx_d%kyeJL8{m?1W`R7@{&7g4?L>yJeKaVmgF5 z2>&U&(ML2>cSXQ+_8H}pzH<#b$Mx*CmnQ&X6^iR)J6i7sE~ca8<%2uh)GdEd*-%pQ z2A2YaVY1o?mI|=*ARw^Ab$3YTlJ79x=1zG8dtkIJj1jF)&z5oc=}5iqhK49f)j2LY z(`==qRWN}0+OHrEwWP#)qU;#q!rUOLLl!f7lb7m&vaB!O03s(m{>}mDU8ScX^hyT{ z*3YI-CHa>yU1G;%7sa)cuyq+ZbUsZ*u^hgaO{bItAcp=!&J@>Pfl{G%EVkA zZYVXeBg%SlWb|1{P+gHp7>tq^in}=lbW46kRh6HVFl`H45wA@~a}cysWm_b4W>X|j zK-NO=n{(CVn@N!C2ht03S8j8Ec`ta?1@80_dNi3EU0-X)5lp*#B1&cZY<7o$@@izE zAtb-3gWyPA@)}2M02LLf`tM!@*D_dTrq?;bw0?mpub~0=?fJM2!yf^O$=!>?HCbg>-- zowK_4|J{4vd(Nr4U+%Ze%&OE}vsQi@&ln>}JJ$U0EU*9W((M;Zk3Dw-RQYoKFM}TV z`N5~R8rQiOV^t$464-)dPIr=Ho~yT^KO|qzACeES)nu6c8*BOS3g{izA3eunY(q~6 zw5TGSV=-TeagG?+lahdg%fAso>%$L_tO6IFBsS*G%k)R8E&3D;#}{J2wpl?E{uf?d;*y1%U^!#OS8 zZ+Tz#Q^4yf47`a{6aHy4v3oB1ACVzWg~P+eE+i@KEKnA@&!EX;HZ(yaTFDTX&EuF| ziI|NVQ|E5EyFY%fk$0X$T=@|9h440d1QaE_oo7Ae4wM_Z=ju2pKAH7I6KriXL{%-U zuL*3mwGR4sA25EMtDmbIe$7@!S z(|?a%rMH1YJ1}2b5v$fAE2a587Jp;BtMsCBz&quWjzkL0p!tfpANA&B z$SH<_xqr6O&QM^d%xTD;a?4}ywO9BRv6Nl#2m$(<8rh&ZelJE z>`yQigtL)Q}6SyMwWNTU#bdpA}@0r;?Ot2hlkW5&3nd#0H8 zR=Tkq9vuBFQG=!A4R!;53jzZdtuC8I3oZHwu8~zw!cKF}swKku_De`{(?@YX(O~0? zaIJzUp4lVH#Bfz)|80bPG&}yh_cGw0?cklqjI5RFGN?wQx^uWsxRvBiK18?3*A%K>D#eFm81_h% zjU9NutFLYu*^YXw@61-{5LCAC>o7UdkHPhKXhXYscB>@=4XHZ5?jSfzwcmesW(|#@ zVSKOQt~g3=>T{DJ^CkOxt~$%b^I(EC^BXx0)3z^|3O^+J7ypz5c*S;3#VooS0W+Dj8iIeziY(!Un<5c~O<8%&s z(?r8bfCdtu0!~XiMm$B0&MGOO(`WQx$Ym`NEu)5NkoQGO##ZDsqk*#;vGb!$BHL6IK z7#%9T%UN});}u>#bQe6bg>y7UFsV=&@4*Wn2o53MAw6!dSq6}191LO0I?BYygps>;7SPl?nQC#6~@su>f?4+li;Rq~dr zf~wfV7%_860rZlQ93Vm&`jy?_gv8kJQBf`IWymHY{yMpwC;KqgAnye|E(wfY?!+bJ zci5QzWnJZ}bn0Gy&=uJb%40OTM55L5#s6k9**|3>cbYZ~qAejK>KRMh#?yfbv{y#D z&f^EA`F>M&EsX@)CC5I@cq`sHao;@P4Fm7>4|$H^@!;fGDil%w)E7uJvg3^5G5vRa z!OjZ=iK#8x#w)mOEM5#TpNIbZNF?p#2G+G!IIwkL{o~azS!*N0-aABZXi@QS$(O7{ zzzq{o&gZA$LKA3+`{Cu=EK~CJ5pSP~N-9np1`54xe-N=Zuxr5#4*wm($hu`G*vFb6 z#aLGUIQH4(Dw)rnSNsk)%>GBG_z!zsV86Kw5-efEbj$JbA=BeM;PuIf%v#IubGy1H z9B#;hX{DG66HQx(trN#B{0DFp`~JNRm{4a07XpXXJ;I8nYt^=k{oT>z5*{A+9sXM?t|9xXpDc2_^;Bfdq z8Jc>51%Ei24a>U?{(|`itj-j(ON`||7#^EOC2egS4F0!0_Gu7FS#~I3&7NgHJ5rst z5dJSjonzZc>}Gjov-^|R=aX*f+ZofyGIO<-X2<=OyxDV4=<|CnVM*=g&C^7AJW9NO zA^u9wcea4OZg|-OF{lX^kwy&oOp7k_t$#a|4Z7kw{>P#G09v;Q4o`eKC-%J{#v za&#c6sY64|5u$#Jwu}?_?w4h3vEJss8C8UBXlPjNeq%xls1o$;CHQmrNbtUJw^VDo zlc1*K9~&EMZ+@p*t`STjn|cTdjc%_n{EyH!-sMYkILo}+?2b6`KE7$AJ6E6$A!a|w zWO2)T`|beGk2BrY^GUksi}-Q70@*H24hu`DDX8wOYqc*YmHx)pnlUiZeu`WyieC$h zga~5lR^EQ`st{eD4G(N)C!W4Mya5ex16YfUkdY=6!Z+#kiouB$aZ^rF{Wa zL9qXo08cN)lACSh|GhG;z5@XmqJ0TpCGwhKwwrKBbaxwQ>#Zhvn^HjnF9)kG4q|X# zl&vth4f9XtyHCf(2*5qzzw+g8LP@yxncP)L>B-_ z>K4bi#+>t+!_YZl@>^N9 zTdQr4FqT8VF8hW_L>qQ@!cMnkV%QWXGsyn~$pw@ocK#Ow+pTi~E$+j4FsUwiP;?Oo z?RKo*_U;dWy(27+Nk(5jw#4Px0J_=!^&z-dYJhUkY6oI{F*b-swO~GLX-`LiuEc*_ z!8xQtbfbN5zW_#)E}uT&a+_FxYv~?q^y%>(diI-2r)F zivz^!?MQtU9SU_v_eeXvcc<6%MU0aU?1;Kc&R=~fszu{p=8p`YM|V#4rVS}8y^%fe~|$jaCr2wGKrv>ewax6hQJh z7SQ5E?d9#=Es!Xsc67Q)=%3XldU@XZyD1p9v+$2s_Fe3lzRN?Spy_gy^3h9z-)E_j zVEpt;EZDGa0c}@mlQZ8y-8~~5+K2MTYDc#{H@g+awIdnU`#3}urCNJnwCXK z`V+y1cH;Jnm~Gd2Y|}JwI~JÜ!~C?udlq0{$>X_|e+)2X)=c~$~9VfjCxyxNrv z-?i-xP+9J|99kLptCCLA3y@blzjv>Trg9 z$hFz&iy>sPUDJ-j;X$)WL}5KBuyl{lfAwDED3UmHt6A?oiX20cb= zt*`#>^XZx+CzwPHqPm=JtS_Wh>7Di?q(d=RSx`kQH|t%8=x5hRs;?O%{M-i>cQlR| z4Ed~v&v)pY_s<8a7$%7HzrAoY>QQP8y4L3d0?I!8I(JdJaVY-!!ZVYnW?__ye+HCx z(!HCwh6?aCZNK3@hZF~+Td89|I&dy(ezUuSMEy(d|6XWRwm`%kHHEEkBMAq`qiQ1Y zC4#B^M;8A-7^w3hEDG?Ln_*OV36uYb>OoVpkC16U zIn2l({^u_|_5MW{cA1-p%16q32DG~awWmY?!p${gr z2KOwthT@6|*D;O9BFiLWe#Kcfd9cB81Tv6vvk`)a>o;{>6Qq1$sVEZ@6345kcAC&_ z3*#A1nK~vYEJ!pZeq1&N2AcsoX7_Sg%9#l{Ds_c$q|^SqhlpQ>gE5XzkhTfKlav2L zX8(V64u|fpNHCt9$ydEEqHFOv!buoLPIr1z+I^T_@NcHJtn>SQND`gGM+Cs+5}j*H ztmU0+*VoT0TAw|aYR_xTwv;wZ%+Fht=BjiDd+w|g)jX^t5ka%Wr9T*D`_a;5T-=;d zvaPPJdY(IGdOFCROU{tD@w=if!{b3nSc=@Ox^IUjFT9ZcyvL5RiAfA=Z$)(6SP3R^ zXKXm-4&uSA)O*<4K&GzkD%D=@Qm8~qYVd)7*zk(Sc7zZ(7YI%>oisRzM@3?@inS@n z5eY>M`~EtizqDOh?YIH`_{1NwPzh;&WDk?xdMk(u%O{yjzj^06FY^5v>O{>uvX+B6 zj`*(s%n}hPB{BBrFCwT@o*i^d8nE@X*vgJa2uMWj{%Aog4#0dgeG zj(5CK*NcO|W>3x?M?(9r&_nbNU44zuBF~$Qg>7#FLm45tY9}GLbmTy|vv;l8QR0oq zLQYOj&$s&s?wAl~p8pTnm)VO}&}45!Ly|tY75AW+&gqLIz>oohyVLR^TEzMagCgZ& z_&^}8kW(s{kjsdC1=p%i(`?a=D3KNzO%yp*>hXU2yI;wEhaBGB(WGY0J| ze_sL~_(hMxhiH__1tHmE&aU=P)eqMO2yR(MfFG|!81zrl0vj_ktC+*12$*Oev92Ci z(tzC50=k86c}BIYT9k(+QR-r9ci$|Yc4$=Z<~&4`4-HuVF&CKGdJbVo^cj>UENU`f z$#6D`L!UH!ATW+BKlqtg*(4gf)-+q4lqNYjxvQd|=5fQ56xscV*MQmhxIj=Zc8jGj zH_{LkpqX~*fZHu7k15ROos5Ost3W1NHTks5uu!7I&!N}x zbfv>UwC}o(Ei|0*yxDT+!|FFqQke7CF_d7fcVj0)z4VtxmA1?VR5Y_>2|`kgYw2m9 zmpLhd@^Bs>=hP`9e08D7HUlZ55MNef8^cTOsrd!fFLj1Y%VNn|&m?p=I3E%BJvr>Q ziU#n0#5CFBBS@{s$ zj5W^vWn!iF$B#l|)-*jcld4;a4l(>?RfUO{+MhN$kF|jm95CIjTLJJR*r=RL5A(jmb?i+wng;?&De$^$7 z&)j!UfSanS#!qjJ9cfr-DW{o#xC`rg^Vk)FX7CN>1d0eX3{`A$^NZKgQq_E5M1N-q{ z-*TfoKI;|BGe%3$L6snX$v}&LC;SGPxntAgfkag`up;+fyyi4wjl zkeS*YvtflWx!S+S5C%brGcq#=#V{i>ZP_CwbBIjZz}p`$^g_w}Ad2mzeBZ)P=l8~4 z{(%&qv>ACE$zW3tNN{7=`nF-?3#10G%i?zR zwVt{z7-^x!-)dLS-uX5TsplL3LbR(09_* z9ESt>e5%5&eMJ$yG6Se?h6qRQgUGuoo}#n zv3+5m4| zh!&T!gNtwyGn=WQ!^2JHYrPLo$|Isf){n1_yN;z1(d22Ww+l&;{1!9wD)R_Vo~IJp zz{o=7>MPI;m-FsFMD<0iwn2N-tRK=BhD*t?7deScoGHjF`_NCdLXJ^U8+2fS^lPjL zz=;LGf%%5EB>g(Y-1R?rw5N0I(+*#PxnOBIVmv3{lf{D!zL&)5>{D2x}eMp z<|RweIn5yMo zIKt-hzv6?^`o}x7oc%j0M<*oPd33pR=}+#>J5rXt)pZo6E0Y86=o_+i0l9)kc3YhBoU)O;Ze}aqt+>Z13 z*9`OLs+jWcko^DCuLH{JjQ;BpL^eOjr2f8&KaV^#io{uW{>xkHpB3${F_gw~n&p3e zA`s%WePI5_-}}el@PC%RaUQu;bixgsh%jdxzMUwNeJJlAEk7_NiQ_T+%|9x_g>^0w zS9F9kCETUnE&eszPTD?kz56HpD`4DlDEm~+k4rfQnjFbBW22m z$m~vMy4f7%arDJdmjjFO%oNm;t9FsPyY7o+tXwd1TMZXq6IKJ!operq=~m4*FH)8d zKja}uUOkyyTTeyr`d}D?S2qERNjQUi-P&`8K@MM9Ry&cwnZG(HO)r8W z6I&Z7cH|%~J`j(h?!V;n#Phl0a()g7cy*orvpek*d2lv* zd0v(RaC|0+SQ>RE?GwVReoqpSEUqph?Hz{=wcDLBM4P)tcUnt)FjcyiGq-7n=U4Z~ zGUe+CTzC^bLnH4iM!b6Icncegw=9|qN|H#A2612OY*n*}?U{2Hq(ENSxStot(`xoP z$;4%l4_EGZ@4qm607pbT1sug3v1|-xrr9gJ`)hB-E?h+J3!UlkFT4+r9GEkaWTtno z2Oh+|Gw+BSQwPwW4kYe8DCABl`*hGEg!-=e<9-hJr6PQn&78zk$`n)*hLiz@RLzc! z<#IHfJp?sAa6P6s`31MbU8TJ+giX@TPFxKJt#JoT~J}=fpfG_wupx^lTl5c$|!Tw|CTGcaAsl zoIbD;^R!rZPMN>k?q;j~t+Vw*@NM3g;PtBJbp=bm>oMWcdx68uJU8POl4|#<$<2t8 zo?lLM=|P5KKco6>)7*Q;y@|wyKfdr_ln-{5GOy@~d)z=4?mX^AVu*}pUxe2ssvZP4^+S zgcMdWQupm`cu!lNi?XuKc&YvzDG2jAjol2RA~Q1WU0lTx_Yl6bbTEey_I^Xc!H;BB zCoZG2jz>NVjXaRsHgO_eO70S$nhWSCViJJ@&Ibbpb1t%;X{<(}c zx~@ovN+AvvQsCVk9X%lo?kn{N4+KA^oQhUv0X0~_2p|6Yy4L$T<>b1hF}1Lh;NIPG zj~{SR?7kG}{f3NzA9$Oqv`z^NI$65izoY6mJVdNzK?z@O*kRl`o;7=i1x; z9-7VLPsLO#C}e^43Mzv9gWkV796So%N%4zpZ~MxE{rfdr*9bZWw^A7GX*T6#&_|$K z@^a}&QG_@(^LLV`mp~-cA5kD3Yx@`jZGlCg?)oG#RsyjYKPYq4^4Lm_Z;Frit2+fq zat-3NsYHc(_*UWO1|J(Cx@7nuODQ1yIM0b=+{N`52j{G9`*}CpmGb+8dpL;D!l{|D zE*&T!A#)ZNQ3{`1+PtK8jVVcql9MP&5Dbbz_UHGJpuvE$9k^}<5pV;?JkSuNzs9{TKv$oAE=9DqUxqA%q8QF}X)GA2{l!Bq=_bDdt zS@@UZO!~SP1dyhgj;Q8XL=~l=zTb#e)lrq^U6)ikW@dzWzGA6I9XRT9XI}C~OUa1m z456_PgltkzT)iFYQ#p;%#U{Cn;L+#fX@ADEn6SCRz_TcMh=Ub43#C7He>#g zQ^yD@)CQNM&m<`~8Co0-4(F_%@RBI^l^BF@y)U?yGEQLzX`IekfwpG%35b@w5Gw#Q zEN|4sV)7S}c%fnTnB;@YlraF{rp-G2G9fuOA#6qYT~mJt!sq#S$E$xHc|JL)hqG5=~F^Ye_5;`m;^9$~#h z6wG`(H64zk#y?z1%Xr1eB71F8B^kw>NhoXty=!8o$!h!eS^fM#N1=6THJ$rs*Yj2X z`g%4X9qZ=t{uGMg>}GK6Of&$mAZL!v~z5I%Rcq2v*nD zn7p5zIC*$1i&Sj~WAM$^TG$4nu=6sMLWqy9kjGLRFh^|(gl#R~o3p6~?)Y>K*E>kk zxo_|_lEW0pB71BFDth0&KQr1`1?BhfIvw)Bo?x~^Y8q3qdpE#Q2G;27{|bcr=IPaF z!%{)zRJj)iHkR0`;}Z z3olABpsN+K%Ki7GTXHg@C7#|m;uGTT!G@-?QSe=-cLZM+ z?U%;&d#`q$t@MM)XiN6(fjb!h>w<)G4BoeOb?686z#O%oA*7mWJFTc3*`_A&+S;J3 z)&_xxXsa-a|NNF{> z;66{hO)b@9uWQyp#27Hhq&X3!^{SjOitd&N0;gd;DUOtBmamzof@NpylSr8d~l@En>-i}>(n8J zm~M8E$t;iP79?9;Rji<8v$aL7MOl4##@?`c5M-_t!xfP}HJUSHXMN6P^qKF@kY-#EJ!HmE=; z^zaxOp%*T)C)8g`vdu0IM?qfj=}X(;WjY)^59`DRGxwn&sZB_Je7Er8GX-<%^H1im zfpQ3ahpI$Jy|fA|aJPLrQ|V`1J)mrBJ>+lDUJe?|+t80*5aXZ28exS7qzNrH*t64Saxt+35kQWU=UXheGRPNEIOOnptvyD5uhsx`z} z&(dJeLTFR-ii&<1XDo9hsNj|H6Z|3)C5#E%xf~Qb;IfzTCam@3?A(7{zrXk5f}KwG za1v+fg+D6LGm;mK#X12N?}e}Q6$J&&#ZLEwrSQRacqd12rk4fK;l*cTJUqSHfE@Ao zZj*BTsW7l(08v`y#a3)-ZuTkl=*>OlN43-AN|*%~(tQ7CsF+C+A#s!l-1_ciXHCYk zjB<)WPv2k{TLkf@4{e=7C8NFk9K}iM#kyC=x|+FiW!u!V$8!%TX;~YM6paeot#i_Lhfsui*e+eAkoEw?f=}y(NxSHU|d&i!3Gu`5r~Y18ap&3+{W%nAf7g;A9_4wtHVtK zi@OzR+h`#7u@A-h3}1Mbu(O|oUbTPr=*VSL5b8PTqW3lsI5gELR7{J0R#e%2?cV~Z z@lq-9QV-2(qm4IG9gMQYoPt8KM<8|D@hlTR#?)Hwdx3_-wQeJZ$~ z6lfP>>*`5Qv1JJt?Qw8)oI}*r)osx02BG*d{Fn?}Uk-J~m%yvl@0GB(mw8tnRlA&N z?4O;Ld%L{E!P-YeK((h-G*r?Fk01x%GfY=fwm;|JCB< z0w{y6Nrh}{jjl~!m690sC|v6>#jSOB2lp-D%>#H+3Hz`#(4t|v&@Bb1`>@`}#2a*Q z$2O`_Zt(1eVmIiPml@;Gt&OR$N|WdOW+r_3vxY3`t;UY_gxdq*CVDQBVV66Nr7PO` z{9+<+qS%13{25D`O4?i~dL<2cbNIQ@ymuatbFjvN{Pj-8vJhYLOq?FXj-f!Xz^RCMtiS(v2 znYexX@JC}5-p#@N#%4Er+wx_VhTrZR8e+bbG*7VIt;Dcdzd*Fw=_c%WwJM1$MsPgW z>Ns{7QZqMG3|fyZ`EjsUWdp{2ej?eWM4v3CjxRdIqu(qFbmFt9XI*nmJlr5(ROriZ zD<%Kz6kuca8>CJU!kkDfQ&-@W8b9q_ls)P zy)|U@PPh4T%`D!xs~?6|c9r*52Xk0=4aO$@wPu+sli&JFKpnApv(}9MsNfebE@p%2w{JSY{A6DZB73Tl?SFjxC7w76P88`7O5ex|gjB@) zY#HuqWO0EhKaHiVd|dHr1}8)>Ye$mtGz|OqKyG+_!m}0Z;5`1;Y*$_CUPAGEd#bG{ z{B--OM}IemJx2{#FT_JoE>Wbd8pLf{OHMHrVj}_APWRo39qtD~h^u2@N-;HUS*pS6 zY`ES0yN|E6{j^r|6j+|PoOqGR{Bcd)Df{O@yzBV5MA(7G-o-_%7U9pgxA1e7k#$AQ ze0i{tl$eKT5?hDo){C3(Y;EU!A%OIV?@DL1b5vt;-P)a4QK_w;GVsr4M{So&cqn4e z5MiwkXOx-3O1L3hz4B;QSB0G$ha;0pR&)d&H`*bZPZ(tgxUlB;O}xC>5Bct8of;T; z3UfdmEg=^*Xf}7+5d~;7YPi*ks#jw9$rO_k$cqLI7Ty6K&NNnIBgIYR)_+?%MOks{ zuhM3cy3AKGa;Pp;9@q69AFCyZVA8J%b~YXuN*?T2ZQcObEFxUWHHAN#SqlCyDnf4@ z8CABf*ptERULgB|#h1vCPjV9?jPVD7Y`USr?KA_?r?B~<#HC0>P! zH3I|X(}udc)$cJhr7Ce#4o<-6jcr6OA6h(9I;L;(8;P&Q z*`JXWBc<$~l&gf4$z&h|>Z&s~E}xbP-fD9uo49hcrB1fK)MmxPMtWpQ01J*F#nTQGf8vU-NZ5>mM!bg6868SriU~r$x!zz&KR>zT^Ez*>oX(cQYhSQ@VQ%BsvONA{Am#jmQi5AOc*^q(7`G> z;;AnfEkDYlr*O0(V!QgNzgVhK0i4FoeSY&H#@fj8Zg71P)YCPT%P^m zgzr^lX)tu7dZ+c-+=b$!2s%9#t5{bBHA2rqSr&i3U;;i$@8D1&hmXm^RbF>R#q^ud2Rd}}A0*L@$P?(xP&%?+ zj0U#m(ZWZyJkF|w-#W_ay|2ca%C`<$Rb?3*n^+m5J%nAh>?RGp+8OJ(e6@kU-w4~p&$2j#(eL5`Q}Gpq20BK9Zp*+Vjq34o z-R0;m%BysUY0Ju{f4NK0uD4b8xZv~DL0%wOAd)H)Z2y>1(9oD)(TmF`ClYz7m8|bC zxUQ%24PqtzG}yj<**&82IN;5+?tTJaSH-$1R@@GmpGO*?zyS~aRp|^Z1|3)*gdZ$c zB2dRzhDd*R=t3E+!P<9jrEt?ad^~H_<$dX|EV>(vwc^?vdhyU5O_;c)p+^Bnhm&i2fzaf6 zinMJ6Cq6L1$T;OsMgd2Sg8khP1Su&6G(H@C8AvtSJQqmHkE{B6(#)a~b5NqHFL4d+ z;O8$N<*iwg=HU9ktlVdaQG8q`ek}-thZhvJQKTC!J!+pMRH`+f!^g)x+?);n9Y?LQ z0fKuY6a+#oBs8R-c*vBE3KHwS>0%b}Tu8G0$hZ#873pTZk+8 z$52x=>;4 zZ@G-RaP}rJF!}C7QHWi|ERAvM=NwVN9v*SCfX+O(x6BHKPW=wdsuN|j=erZQx0=d( zO9hR%;EhJwfr*>X%hb*}yP!~9FxO9;d=fFd#aQo2^4*j~5-%QeBgY&Csn2Zn)-gFE z8e5lzvX{^@fl&wQE*2=Sc?OrOu3%mY$lf1lymA{7E)^CXZl_D_mqn)P2qfC zn6g8$F;RXG(L|WAq!$UAFlgQ34Cvb`UL1A;%$+L{gBT=+i>!XS6Zjy3xY>8DIH;RUCM}T(!G?LgV&0d>BYdo|pD}VhJ(mThw>+-ZCAsyo2EeSgtcn zHI^{ZJL~KH219*z>A$Nd)VtQa*p#v>yhn$3JW<8sDd)LoNRFBArPSYYuw86)QPjm% z#O3=T?&jISgGYA2s4vPOmB0dvh1ar0wq7;sVY!%<1cfD7PLnt3&z?v&HV58O@tJ$>8d7E17d&_H`FO zR#iK_u2M}_rE|yqZCzpE;`HEH4gGg<7Hz+1D;{lXcKFeyz3tZ28Q{!3eeV*X(t8v` zlJf!HBswcX|1G5FCLBAlTnB{1QADR>!Gc!T+PD~&G?d`ct-Cdhryj3Y0=_$_IIo(R z2=-0aJg1$`UCg=I5ev{$-VBXU@douHBzCZBVLhN}+O6#I7CyO{9zEMV3@<>uig6kW!{Axluqu*~c&{ZN7ZjTbgP{V&gL@ zF=r=srF^5cpf{IzBc1DDy9Lv3 z|7w3Owul?O{C@1hR)$HG>pCtx>=~YK`X{-J5dGy{xy1%O5Zm5?Yj!Ix=2OkwW|x@l zQ?%1p2NZF5+`*NL=|_)AZ5j1jjP$#^%m&%H{m3pT?}2eaj!-x+R%aqxT^*p7_?6XS z4kC3_xpag5L}U58FDU+;c45cUJ}x6aj7rW*9V+mMNcU~65I+vnh?tcVegfE!w^S5> zl2Y9rh6I|i+~^-K3F+{ao1`~4UL649U%{1H=M-WH%7XUw2Qn5xcmPP()D#^3*{Ys- z{@cDfZ~^K@M8aZJWiyWg8f_pJOqMqsl&FYe;6+50 zfah_-0G{Taxt!0U2}uXa{q-~|?Tzu&xmlVFgJ^O2{ls6Gp_%#bf3wtyNjGAc=@mBX zKKAZ|q z5^=iE)p8BHfFgXGKCh@={wvAL>%C=`EWXSo4=94DaG z*-(EF5{RmmfycViGy33_qEebb!b%2nZ_U%Iq!9H>!I#QvB{xC)=|_BtkF9&n7#0{f zWwx@>C(I6kg#6$fKi5rdHy?DPe*X*c!}*5o?9zs3l}XZJA!Pv6jGK%zUD?#k9K4BF zM_kd(Ua9TxcSA4CQymT*>TV{g8T6~gMsFO?gpoa(y}ePjBzcyh@@85XqkeHB`az^K z9!tl-(SsHA?+QWe_!`||u_np6Xy*3BVKO5SQL@uB{V)Qu8NvBFS$Zc6hM7F=(&~m8 zr8a#0pf%9am&2POl3|mZ(P7Y&o%iw&LU-27FSLW2o{f2FJ_M6=*iq%Uc?qSkv#tcb z73(F72pxoI`Q#+D%!wBgUg$3Oc8)d(f!n7R4|I1000(U0H_&)R

k&*6i@F!#6KZ zip1aDCkFP=1kLrrDCFqP=BrL08ZBarJA^|R-`{1b@q}}r? zu*c8bGH$3NfRxFW`&yGR8R$6`NkIaxf^^`M#0l3)^se z|1eo4{NET|6CGUXX&fQ+gkz=3V@VZN>}5{nYmR5qG=M!*-ZdTKSlzo7RY%QhlJ}UE zy5E24@4#b6KQYNSh3koEgpm&->(x6#rdvZ>EAB)8cxzmX!XEIT+!yJaP`JHFL5cH z9o$-UghzmEOBv><<6p8vAo~{)9D(M;_UW1g6e42J+D+)?QYxs~v@IMrcgN$}>5zaT z&cxX>x&*_TxFi7T)mFQwhHZm%x(-tO&OT3$^2s;QA>$8;;meI*KRxN2w|^=IMQ;{( zw^1&7LE*c*ZVQqO(Cij$EPR~`3@)H{HX9az$sqXy_y{>g5Is?TNx;k{szf3`<`1QZ zla12P*B!Sdi^t53!xU740;J-;l?T!q7vnv-gU8V*a}Xg5PIe(th(nZQ9X*38FUWr- zUSJDKQCvcoN}!ITOcY#LZAu4j{o0q3sGRf zJuqSCUx-Z-@!{gM%D-5bh#3;2$Qy+#N-Nz&lo>o|sXE{IkIHv*_v{uQYFzN^=ka?1 z#50NA4I#apXBAH1Th7M`=7Q$*Hedl|5*1M%rILQdnJY0{7CB0_K*R#%$p(# zj0S^3+FdC!8WnsbB6wI!5q*vBTFR5CUva~01VvTQ-H8RB+AcE{VDX#A_A>B?nmSs~ zR5{PX(XRWXm;z*_fQ{E!60ro+eS44gS~s!pqmU-PVy{reh)!zKz$a(ZLmFHg9FgBQ z%p3H<<3IJ!YGmkbtu-+iKk}sV8O9|K52QDEV+f5SDK>AS_z%4@lU2HMZIKs5OWBzC znM`DsPu`2mlwbAD4Wqd}#6L&ynppzom>^K#TQx0mYvROUO-8HT;U)3ulQSQG+6xB% zl0DQ?MCV1JIytufV*L%|YILc4vI45R9PfRlZct-Udt{}WRey)K=jBd}O7h2^#%kEu zuU@?ZdL4GeFN%pIhdnk{Tt0~8%Z~@6+nY}(2wI4eK{W`$^xwY{#bc=`Q zYTYU-7hB+85N?{R)PsX>61Q%D-}db%hLk3zL(K^gO%I`{feRt<>(f= zi@j`6vCP8gXkqO2k1cXp7iiM@t}OSfwr@nc8d;Knp+Q6Cs| zdfaUZl5RM*s^4JiY8xLV`uB`)Ha997?kh{Yh?f!j&#)$1XeCk*yR&7~-4WQh$6e^$?+zo{m<57Da&YGxof8Mm;gIsV$k@+^ zPkY6k1;$iA3wu8%==d+#RuLnG6`u&gcoC8PV`nSZ?%;#V5F{`olwR$al>Dz8F>_nx zIOR4FiWiF&hvG3%gH9GIclI+NC6k6};P@l*i<>@(;AUR6f_R&HcN{R8hMDgyXQBW= zdm8-0`7=pMr@V*`HH15F=BxA9&oc&~_9qZoAKj=%QW3M2suJ1~#BDJZxV9BKYq!n?l?<64hKL&4?wL7d0#v6(Y z2l;%0exX4-D3RJ}st|Ux@$d4w6$FPtHI)Lh?|&KnqTuUI8f?5N{6f#G>aSQVFTXM> z58InDs2?Xu=61b_VeTr!s-eW`1Gx4n%P-6^V2zLet>+OAakBxU7BTqp`Fnxb@mYCO%pm%Lq8I^hWeDJjPuR=~!-09*{)653?cTeu z@at@bA^8Ra2;rKzr~`t-PN3b+fO8Oq^yAAT|1BfZ(UUP(k*JOf3IShBx1lS3$LHyx z%HPx(Qeaw3k)#~3n;kB66n9qOpx)E9O-|N`jRX6~pH=-i2^zEdF1g)R&5!Xa<3tLE zBw+@v=UlW}qvIA?hekb~uB{%Qz=gjv?7e(=^Iqc!Iuw2B$tzE!>6v#pmn|=TwGjGP*7c6{-DGtbGNOa zf55Ne|10=)a>K#@y)d}zWfAo@iw_#Oy^-kU;ghHL?53GObKD^KOcReJRzr2Vz8{mY zaoWxIvGVvftN7SYb0xJfF~tBk@Q~#b5=~%w73O>Cxppm)HsOtIzXj=r#}`^f20gP) z8V@gh>-xKQfsnS#dHsp|*H)ALlSTiYvvqKKej1?mR{FK-j*}pGwXZ@%2MHE$x>dyS5UsG=@`l-~ z!w2>Pimz|ZQVkg?BkJ~%1deWHeFQ-LI(gQ6#3S=7=eo67 zLvVL@3GVK0Aq01KcXxM(U_pZicXxMpcXxN_O7=eI?6=?UZ*=$f6RHMdR8jRj_gdFn za|LkN-vUKHigXImV`z80MuLz}Z1rYmG-eQXmv}XINzvnNbUdBUU=H>nFjhS9Jff3s zc6V*qU3G)G;;%-DQ+~QVoC7hQKuaUyXGL65rtNFcc-UG8;ZNsw#TBRH4V3#XZF*n` zoY5-b$!Wt^t`zzP$wG+{Fs;uxe$MSDCOmL+Rv8ShKzuV~WXX>c#5e=EH;to)Pg`nU zs>gheVB3kGuu5-sN5wcF=q~%J!;unk^>&J2$3lz~Q-SYyP=vDhbVDS9b}U4Gh^l92_UWXGCRu@wDv!8PP&)(w}-4!B5?-0@@*bc!8erzPuw zgo6z1$gC(-COOBV0iQv>UnTAPKKMktjxkRb{ki?Xj#%#1*eMaiWZ8C#lo=g-nVRq1 zfkB+T8*{s=7dE^Xcut)Yop+fv-g95wt{-bcUElFo)1m`AG_Xs|&gc*|hx4OJdLveF zeVa}I?bm_zEcTt%I*3rI5phXHM9}+;seUfMgMM*}GiKGc==4Vj)doW%?^`~Y4GWdc zrxiI;wMJc82ys4+_%4$RISE`3{XF*#cQLf&8GbrZ^?@I%EKTepb6%e(P$9W$pqM*+ ze9d;AyFwcvio4WcC$2cZJLinF>^ypt0$3hl)oM%5)^hCuEA0z$8Lbe#ll8+*UEnXX zV6E@t?h^6@dT+%xcC502TM8}2wMmbO6-AR4Xg7q?84wi$I@szC>lPayqc>+GM>`Eu z#*ea)xfQxg`YxxtFMx7w;PUm35WsNyIUL}d>KBEy+P~~QQ9XS9rn!#QfK-%2fxB`R zR)P^@umCJ$2$_~GK9D3ER8eq0yDA`O^pY%Z^l|{sn_aLS?hs!*nyjLpy7eBWbD8*} z?&_|yH_`$%0iq2#$RJjDex|D}it=a!a4F*5T~q_E3R@MAZ#r`ba0ZJf%vc0xHLI(d zcRdRW$+W7KzC(sg+Teim(T7+uo90|n$?|RWeOtl6a-GGGhK7dwwLMC;oGfyj!{r}k zT%HLToKE3*tJO*0PT7OY_@84FDV}KZpH2^()k;Sen@*K&i{00*x)v61y|sS4Ao1Vt zUJ}onO`;HBt7z|& zUXRgNQ)`kMk5BRV;Ir(n-l2)9pyR)%!kOtndC{LiN{aogTtUzF$Qbb@nXjYu74&|u zmd|pxo0f)3j@1SphNCU<&dZ4dKtPY5zrC|MSZrkBwP19Uwpwy-tJWXoZk5KJNjOuN z98Yw~e_?vjmlS8aTe&Gs_@KS#?|r^M9=_)vliEa-O_s281Kc zePZfqRqGcmHR5(W$n$>m`xVL*0>kb<#rZVl>iD8Kl3t4ba!u< zlUWbK6_22S1e-Lff)f*1!wTBv0aDQ`Pi`)z5>q^vF9ah|YRqQeX;TdDT7QdKBscD5fb1bAJY&?=W^6wnOoszl=(d)%MO@mmMx zF$d)&Jh?S9H^fD#CY4%Be~Wghqg#pj4>R-RP4+#%dhJHM5(&mzU%x$VKN!zME0xvQ zz_?r=!C=Pid`MNj?5gBfF%L!D!EEM3;;-f8DWzKasjHZ!R-%lhJo<)9HYsLa)@%G1 z(`f-V>nZ$pyl}45V&8)sz4B!E{W|N5Pb$cm;4sA6xQhagwJ(H0IZ=!DK9TCn`hvE4;Xd2 zI5tQ~RnL{h4e{^>M#P|=>@5ewPQesXF@z)mK?3Cx!o*7J9F)~*VH0j;x_5#-+K08U za8PXB4JBGU;6R4u*6**aGS#;NLqS2|s6U4+1TUDNrKf!)I~PmTUEIu+MK!#tHWKJ4 z!buIkwmlJKz}M`6Z@9Y9b7f~w`H|Y)T};{kEd$cT;q16LHscZK!3H(w8#9TBxCr4_ z-KYZ33>CUHaXy34#vPFVFb%Dqe=`m2^K^nez16hfu&2-(%nGW@F1?#78lCMox{=3c z!z23s{dgWZ-=jZ;g<&nve4@7Smm?w1RbaMof>n1;^A&`Dl8_kjI^PEmTB786XT)T6 z0p?QJ} zVg82$pqN7I8XS~$+9!sEjncKWgmr_T82UPQVA!WY2$@Zydz?}QUHDnKAfUkNMQ`rkMu+x{WGN>WTKiu|0$N~yae;w zp8?R;xX@Ndc*Y+_h0gQsI@oEBU3qc_o2DZT5eE((dMI1PI5DJQIZ5}k2ngn;AFyz@ zZgeWvGFfhXI)R}y1SZr<>E9;nUo0LsM8q|Dw*pq9r_RrO@O=0sj3(o_V>@j@m+s_$XZ^pVaAv?Ba zFDjU9QT+U_!14NH9wm7uzJRe-BKP-IymH7PD18>IRWvv&Di<<6qc=(TgpZ zegau#RV>M8IY0EVRH4h;TXMWZ?9^-N(EEvlU*N9fn;KO86(bvci&X}U&esEt-*Npd z8t8~f#KT8fpe$)J^z`0KJwNfKuvRa*8X-WX3zIGZ_O5Os5Cyn z+69;nA|^hSw{Uq%VNWSsV(YUWhzqkF-Ur@N{#(d<>wC{9p2=1eQ!5)7-ZL)61&5>X zTi1|9**W%o9OA$rE#Z`uYg1;*>C6%me3^Bq+J;J@Y!(EisIXbiAF^K3Nf%7Vhbh@+ z4hp?}_=~^TRbg^E4ZReG zyJi$GC(|V^V}Ru?{dmnHvo+Vx%P7z@-hfRK?W6E^=QTfj0Zb-?*A%YVtnY_PJ#C8L zsEnNzL54Y5e;nr=bDSI=caLXdfmZV*6o)MBib82}wdMSoDN_`OaDOIVzq0!O1wRn1 z&P}3q`?}PR+!c-h*07I49;rda4w|jaKzeWk2Mo;$O%w78iGR540tAz8wT;*YI${t) zT1c>wrHt=8`6=^4(RFDE#C5+E*C=fk8!{FqQ9>eoNVtK6Z6rybLu&Y0ZW?Ib^P2M4t^F!@H!^c zeMI^Rm`19EbOhJVbnKW*1+&q$p4YLrOqF>?bpIw2@VF8W4zf@2bEhMLa38{ZAgERJ znqKrL zgng<5F(oWZb^Ati2+YUV;!IT!?knhqmuFlh^7fJjAR^3)h7j4zK$$aAH9+K9!?6MP za}0gU4LE}K4G4B`)nE(19}Kmoq3vzlo99)+q2C!Xv2c1i1t8*681f_xC8D7OG>zd! z$dpalO%a=ql8Jd)HP-Y{j>BTpzK4~b;_jl&=lA@Kaju98w0@+tTya7F(Zn>EC*KI^4T5sFtF1AzY#CBliS`6FyOPb z`d$-Sab1cT+(_<%lw=jDC;XD_HdA0)>{WZh1)2+?zWvJS!*O>Wk`p_^;eCW;Z^R_Q zjAG~XfyG0`z5Bq<@IQe9HWtq2JooSQ1b>i#W$r0|jWRr6Ntv`W=%+v;{DQ5Q#U(D^R8}$#w#Y5+XP4xR2cxm1o8Sm5E5Ev&2 z!bmaHu#Os?o}jxGs~f><(rE=kZ0bg;}5wv5{mSp2$87JsAyzYDUx!Uoe%?m5g>3YzhdU=dMl_BZv+w_ zD%xb%0mOh@s~4wMkr$L$oCAWRIcZPQg)=b=kw#mF8Kd`N^9xUU^R0+M2?j^4azN^e z!cXC-vn+hly4u2H&o9&?7;RK5GYlIri%wL~Z_iG_?avZaZgQxsfclSKMEqw&`*;4X zJowJwF^||{hJl2j^Fu4d00gnf&cQDV42FjkqZ&S-YJFUxElxl-k=T(?C}jG#i%qeP z=OL8BTqQC=4yRnWYc)1o0qkU(Ct2{s74i^ORB#$_ea{u^g0Jg|m~5`FfO(?;msJ;{ zwpiYVR(%kR(T`(?LtYMF$^db_*%K6o&AO|{b#5SNKFt3;WT2v)nFEPnqv;oYVsSWM zyM3qVPF9b}+o?0`mCJtJR~nw zJJOW{mCA+9=gcG>gl({N+-K_%MzCPMYz>RvI)|32!L}`^4%{5|fq6q--_`G8qB|H0 zg~@6TO6J*!-eneaY;mt02!F9#lGNbnZgZN+uTaw(ms|PV0FkoOj+?u@TzpVtxrAqc zoACJF_9dmp6iolK7!P@}a@zOAFsU;}lOyNRLyG`_#a35hLWRLpmL3*&6=vhK%~z9? zKEipOsW@f6Ho8DdyMhy;cIBR_3OW3C%B52Ra@?l>1chApplM)Pg$1-b7?aNdRv*5i zbC>ZugTZ)1>zb1}kmC_LuikG#a`W&DN@Xx*Q|%`JiBuJ$l-mz8;!i z*s7o@z4Cc=z5UY1_sks+z!>vzdZ~7u2V{%&ztH%cbRr9o3NP<%*OR1Dd>Iw^gY$+M zN*`b0Qrb-IRfNB*%rz9!PrvUK(almHn6;;SB+)C;+U%3_|Ae#I;m4e*n?~Z3SK%sd zk@C73W0ygg5fc~h>FEKXRw-B1ITQmdyx9=HJ1cH!;VzKLf;TZSIh#E`TdV>p(`Zok zX;dbo9~3gR#ZGUj>#LCg`^;nzfJ6k&Rc8Z25(mEWn^`bo=y#q0=n0Nj`& zo{WTn2N?{^H#-|kbGfNY-ifg}Tqru>Qb5FbP$!#KB=||+zY*e z@n3Dm(o8e687q|)z{Lp;&67ff3959q4=ND`38kW+7}EB_3n!(8my7!ndv%qTnN6$S zTqgi>);1bJ`U8-1ib=--8GlRPG`8>!oxGJ?DN&cAlqY_RwK|M+ZpBR;`b>EVCnH)? zkLPCcHTpj(eOU%>EIKaqjWXWkpj6fXDHxI5lj+KmsKXeV0x|VD6tX1t&l(u|8uxfy zI~muIrFA%II9RG)0m=!{$qZYT!&3Fkf|}CZ6?}|aM4=FA9%r-)6iNlEzq5C|qg0Kb z`8Cur0r$(~qIzgm6%ul(F%sJFW6lXq(^$|B@`#vmp#|1jdL{)U13AdOK_Mic3xOo@ zKvZuUn^`O%<6;-`eHckQP!bbgyg+!N8yj!AUT(v>tvS8)eD*6?jGnqB2XcI` ztX77>=!;-fYJ-r$SCBl>5Mr$b{0!WYk5k|hJ3MGNJvg_YVLDM&#pw^4#*zHfDR|2) z4FLkIa&*GKdasz@Lf9r?kx=+RlcZv;I&t0yOoKm8FpZ*!-ME@$1v4iL~i2M z&4|P1-GIT{sbsZJLlh2scV8bE2so^7^{Nf~yP9HyS>YeU1jO9I?}QKXso|L$Ton*l z{~i6#qWp=!e*YxFoBjK#e-h#UlV2l+GRxP>0KnbY54xaMprvgd#n+>6zw=;kD183t zS-#J|vxbs{(Dog_p|<_5WQ6M9jS2pU&h@g~KiTv3gi<_GuokyZ=UU^ZvjhyKPhlL% zA0HD}*L%O$WaTd-%ixR0DaaOQTu;Q~Jx$ON0RCD>ut2i417Q1B z9yr*x>#8?$Kx;Y+Poo14QI*>ANy@H7IArgb#e(hGxmIte(Q#4nkzEV{5tXQa`Yhz? ze#OQ^lu(=|R029N@g`mQm07#oknA`2V0!u_`U^6h^|}_wNXZ~gk1j=TbtQ*cDgaHi4Nw=ciutmKS^G4~9a@4s0%;t%QD~2BL2G zZB_cz?&SmV^lUrRbt@cBcbIgm zF+m#1?Y0aUJ15PGF6pYwnN1+DzZ-`zu4DBy&{Qd^=v6)HXjgFMf&L_Ym zMm)|o4gh4)l{g~1v)me(EsNd+Xt?Ss@ zZTjA5|B5Mg2&%gjBThuC3?!=m2%f)nC&RY+>p;#@XA)-}hrdroPI<8xf<04QW-Fk) z@6jxcyn64mtK+pe&BhJnh0X2=w;L>Zg}cF?IIrz>NPZ*ok7(zfef^PXgvr%9+9b=> zpez+1aB=EjX8!W73KuZd3n%1(=&b&yj157+MBuAEr>w?x_;p_UpngV`K@53oEB)4s z3;5QtObZe~bw{1Jy&0T;89v!lAK>XW&}#c!4N=f0AAXirPbektpB}sNc-H-`wQh@0 zI&(W_9D>_e% z`$is_#)>rVJkP)kexAt*%)HQbI4KcYTdQbjh~8c1;X%6A2x1p^jLNHUd$@*imVTyd zZXBWg2GQ9hYVh9&R*v$6E?d0u$_6?@w$@g4jg6rd9KOO5e6WeNpzquU2_yhu7fVCP z%c?NHY^2DjC?bIED}Ur+vg!kJ@mMl0KHi@g52e<{BGf~LAh%fK8>R-JPt?%gxik+; zwy%81?8viPS`(L1D5B>Keg4#^ySoZ@xVj2YMn+a?z8lGTW86b?hvbR>Szw?Ow7(m9 zwZ#YHYRQeE!B)V5ni*8s}21A=vGYAh2C4Xc%_R4?BUfD?5*CP?un@o z#cV)1J^|?!aEN<+G~(|W3VmpX_SRYvu=F(6pr5M?-k04)?Wy18j8s!<`y zKO;F7!#~|y8xYsKe>N_uk|^F(hLPMcrj{U+xs#ur6`WD0av9b8I;E-@xNR? zN+^H{166L-=_y9xp8lvwt5YFY+}pt9=rn5Kn^COs-pyKBXVJ9FcW5bBX`0p@4u5XebZ` z@^Q7^gFByc`;u6^hondF8|(y^4xQBS=IsIgg4t4moXE8epQUHaH6p${LB8ydkF53mweYBbta1k@6uyX9KG{9{G7&!w*JEiX!>=>|Os0 z9Os-IEJ6zgbhhQ>!AYSx&t0v$RruY7*>D>%K zB4MzfMuo-Vg1(t25LLc{LH9>F)X+O7|H?Q;2caW9Nn`W4NXda_9%)p9(KDur;l}7v zW!jGziN*YbUpvI588AF!!$R};LQ9=s118k1e|eMh1(VehmrM#Xs^Vd_CqdMv>x(LE z#|?ztTd2?GIG&MDKd3o76oJc+Qw`Xi~5Xt zQlW-f9BOu}=5Jb7@@0fHKOR>kD2OnMUS?tS6K#gpRHu}~S&9&yFebf0fhv5qEGYQ` zpr`w@4bB@dp5$T?Hkzl~OIGAfAO*zzvTtj>uF4BE7VhC67!Q7Us$bzo|NG3<*AG~i zzPSkf?tc+&skyiQ zlU*E49{zI<{d00{h4srxF#D&L3k62upWx$9gJso!TD?#ig#Y>QArgfiFUuBl7aBBkY&=OM}DdoQ(9YT0eO7R|rSz$CC3IzZZBMR+Fsx z!DEBMU=5P}0oVP-%0Pn+L96tdn7(t>{amurKm1>_9T-IppK~r;b?qzu#xP-+?GB!e zP8Irs_*=`@#YDnIUXFG0%dd7AUF~5Y>Ntzt0WB;LtR~Urg%e?|9nFmwU8VPMr&ly+ zTelaL6vmcPZ_O z?;w}At1(#(w7(Hc-QS3%vCrH?O<$<1J-P=%rm%b4Er}$O-5C&{PAe+Ehx_%}a@1H! zM`x|tjV%wU9QVYAfLi!Zn3k%&N8SXAcU{XLpW+bOu8vliFW(QoR=S;dpKf%ZQFo|C z&UK{kXth0O)6mKjFcw$5>wgi$bUu3pcG(%0e9Upu2Gki1%YOU{REYaKQ4{N_Q4>it zee-XrjiryzUukr9f~3woeG;4dDj?eje7gK6YTcSW*yrh=K)>&M1wmB#Sjs*Q{CPXP zW}o;~mXMUby$#!*bPKv_c}C_WbMy{F_i~(E;kBM8*U3qSDiCZxwBd&i0(53?F1%Uv zADVxu-l&-)))(tHP}bKEHg~*`U_7vP*dKHdvowBX>`WL30`I77KWJ_I%nx&({)*BG z7{KK?JR55`p`yF^K=X1Gs(O2=Y306skR80SyBd_%^h^)sXLB}^@NxWfF`*IV`NH@( zbpmR=!5QFiaK8DR-{a~bOAT4)@IGTGzW(o8Np0{&1z>4Igm53MD+#GAdWuZy|j zF?)bwb@Cl*cXyYNkPrw20zOcJbXpovI$qllCy#9H>;%B$adi$4OLEt_$Kdn&mzB|K zYH8IeWXAo4sllc)gGG}CPqMNE1$_ag`#6u#b|B9wircTrQKS>yHShry7a=0z#_8Xm zXPBOGK0ve28wet%AVjUA#A2vq5VyBQ43DDKE3SwTvg5%QG42_k#})F6ex?*U`ngoOmX-CG7RgE%-d2yXOtB$#!1FX(bFXaJDC5)doEVB$b_?Sesi zx}so=X9@^?5oT$a6|5RWt~UmM^@837jGT0`1IdMj#X`dBTA0K7N#~!%4;Y-ievWlY zjk-`74gOxo==f9*_0$u)pz*z*Z8FiM=i&=$#%@fCBB!Mi4^3%dDlxue% zaqF3`)`EeC6E7|<3MAn^m5wV}$f6U|Q6c(uZG}dS`F1XX7W9KpZk?bH@b)rJP{6*p zPS2#%T8=Os+8obYiBh*13Jev>STk5jjhY1dzqe zZb*&5R3l+OV`l43NqqU)FA6WSTuFy7lh{yS3hvK7Q4xXeQkc^)h94 z%5z3$df@*40LvMxo4L6`w12{({moS)k9Q=EF|6Ki4VhKMzcpkOU&oI1m1GOKe9%4C z;-x@;EyTh1FX&|#KUCiyoPEW%(eZS9iBBQkIg79hy3fB}ui)~}h(m??=p^jzCC&8> z(;eR+QKV-;5JV8pHn8?<-Ie8&q0paZ{>x@Ic6hkdZsWTP$?wEhIC!nsb)ueia8u*X zJdpRJ_)Rz(^aIE+0h4EpXpT=S7H8l=w7o<0GqJEdH1+!X(Y2m~5@&gA!PffO35U-T zM5TRDP&6tr4ENy>^VSC;e!+e5y-bavlLqei%62S8FL`J-B3938ukXc3u}VpFQMJ63 z(u>Eh3Id^AgQs@&!3QOc_6l=tkA1b$YJ*Rgq!iFiqOEI{Ea23`K^+^yfdgc@gT4(B z{m-5)Blhw@+nKrL~JA={hl2H)}ZBDMd|d#OuRZR zi2$uO#Qglct-bxH7nt$pNjWgPE`Km7;<(Cx0c%AC|A)BRDO>#7@U%Bw0(zB23!g#R zvv)7CQQz^GplONwon{x+iutw0*siw}jSD)< zOJM5JNWBvD)~;nPOs1M7-o?-)tGxP)hs_PwH3df#q2b> zWBH`yyGO{A8%dA*lQr10goC}`SX6VAE_G7tM010^zL!|VKI1PlJjtZw*T6C_n@ zauxOZ1fVji!nh@tLQ_jgADDmHqh3NvUGyk?WO$hZ%LMtql=QFFuWUnn%ZoR3xEJ$0P z<`Aegn+xwQohAqEs8(QoU0kqvFs^4?Taw|^lLAmG2{c>tHl5^_0 zIin`)C;QcUHrD!P^r}g2S?@7$6|Cc_&9BcrdZjzmv}*iLnec}En(m#^bZK(deE7+F zAWJv|75W5i+&|zpZ`!7dcuzRC;hgCNzWcED6_E>t{8~xwNn5mCZ?9Eppf{kZr%!DfrZhrg=Uvo5d8u4)l>*T@>Rrj7vbw z<#=$v{3XK(m3@>=GaE%N>5HR*ZA0PnKV)c*B=dF;De6&P*)FA7i*1F|5_I zM$uXjRZuqL#u%TbsrGm`R1`8R@3O{p+nR6cT?ZNFYn)`}y(VGz?O3Bbise0|U}``X zQ6)Y+W6UFT1f+I1T6hU?Ec2fd$H4_~IZ()paQ*TrLW_4vP%8n*7f ztwZ;@x^iRNczPfsT)YOB2RA)>56K6n!1no#9N6}LPc|B2SzT^{IuPz#W>+E|g6nyz zF|oT}WPGhW*3b;C?uWP$>yo(B7mPP{>z|{S!9Igf>j7T$x@4fsSd6M~BELG1&)Q;g zf{MoD^+VxKB0TQ~cHM{)j3Y%Y!Jrpz-m%~~^@7h7=drs#Wo!Iv4}hHRGAvB8cSsS4 z=A^-P$mQi?45zS0F5x+Pl4l)Sv_VI&S=J24$i~ZC%KoGG37v>xa>u!lU*s$(Llg6= zx~gfR63KtI2)wU+=#DR3Iqf+`&Xtnzkf1=Y)Ad!MQlCC>#q4MoZdILog-)ZysW?{z zarIJFbYiF#WK>zlkn^z%FOZ8mvfboaWMvRl&C)4TzVX|3oF^=m!4-I>_d%HcJY z4E7r_IG^$aeAh1Abh1ZSl^@?(ykkh1f6TA_boAwlg3?h$A*9-fi8N%j5BMyK1U`!+ zVw6jJUalCmvuuOL^}GX!enNqx^27mEb3JIq4q#?x0NcLU@O=xlLBh0$w{dFd%EsO) z1i=}&cXha@xwSSx(7F>UmXin2dnT19c?8YTConY_G$X-iCzWmW92O_j6?ydc`0ddO z$2@D1UFC3uzdUJvQJ^$<`7=Ie+sLH{L#4>J)@j#lg7Mlf>sJDVqZ%viiZ0k#0h6_yd}>>M%po#e zFV||LXQiE6JqK5}_zc_RjRfYQi5ni9fe(!7+isS&2QH=Du6XwOWJ`HlDgZ4hPKz6# z$A8%xA={yiGRIf8ykY6?70g^%u{En^gS%P-8oe(zx8LYi^1fKPV&tt2TiU}dy z?Q%-1uL5DWhd7JXo}B1DRX``>1DgTgEEo#3gzrksj7D%Y=dN?+MwqKC1AswVy5~nx zlkV{tALr03FL*F>-CMdxXF;R5??uS*z>raxW6`%m7=ExCk7xQBN0qwbO6e|aqj~b! zkP_2p2ul^fJ_n02OwI(!$`FtN93-evNV^WmSN`*dGuf2AYG$ptOO=)@P}hh$fuzP) z=iAJm?l=XCDeKa~N&XE^#$+%GJ#lSQRpdq);{jG$Jl^;J>0zIm7Sg%QD6d^TFTPh! zYBwq-t782dk#y)>MfM8$7Fc4<6Hf{a=_m?Vb)Xo=2_+-*+U|yzM6==h3-`>Tj)9?C z2qrlgviTrNt3+9E=e!M4Mn*6=@6;KM%XGP(pg-y&D!5*Ga%iMetK(pYy-D*G_Ke$L zYC9iuQ+e*F6;|#Y;&T3S3zN?n*0{+g1n{-_+u1rY-RS+D$A~^R-~nW!yPoO?Gvh@Oar=V#NyPcL3$v1=5l7X+MT>A>T;deyV28f8vMo ztFEkli?URG=uoLLIg02W-VUJ9Cs2qMfI^`Aq?k$w0v2}>=bP22o5x{q)`LJm5+0-b zU`Zt-yPuH*`>nmbfUzyEd3#4;aJe5;B-rOhmk+w_nj2l~E#G}*<6}?8a)tI+=6{WS z0(@T!LlKRh=a77O))6Iz(nQocH|lak7qSBbT>}QJ`=dW{-G0Xlf`E7-G&U&}28LOD zUC!e^jsy{_yEJv;glmRbpr`*Hv54OQZEy=D;C7LGvCep_#@@5?QE@(} z(^~MS_;jgv859mSIRXNY;n8+1nuu_@QkoOgWR<|#UXi>It*&bsw?cJ|XqomUn4W?t zJ=raHJfcz@u1i66GWi(`PFw@yF>VpEWq1c9d2`i}Xlc6Yn$gLE{3v&8Ry^Pf++?i^ zxdv6J-!iY|gE_zQ!GvU`7ZW^GBT&7gfs4(WJB-*e3xDS}ZDH~Qd!yncAZ55SHwapA zxvJ$nH0+-vffJW44eZ`)tw3-(n`xJ@A1JN|V=h%UB9M;QtYQ!AZ&NvfPZsTe!L4U` z+c}oIhN=7*{5^$NB^f_5n8ClLhlb4*=siVmRJ!cZurQ;x+p3uloG>xNeVRwN(mc5Y z3-u#9#l@?A`58==btZ`xdn0FawpRk9g?TOgP@@{AYc7}cAUY^D5)_rsOf#B=_fk^i zC5L{nedz*ob^n@$M7aer3D}L&U=R_$aIMNJFeA1v1Cj8z%nYRoH-A~K`S(5>FLn5K zX}%OQeX}uY&GI$}U8nHabV9M2el53kB_8dk0SC?8M%7o(a=X8CB;N*RY}P(hz<@qD zn->Rsvd<$l;AI^^&(7j0o$aCGVC%cpkQ7tstKs>WG|VFYCdnL zRdk3Qt+iqD8X@o7EJhth`n+p_Q14_pvlapay3skuh$lx8x_S%H1hhJEEwRk1bqC1M zsFI<#Wx6YazzX~;u=Mm5g)tk|UJSc!s40RnS`)9~YK0|qNLAtQ-9 zkkJ=Qq28@GO5Sht;~A4vIiN2O?j&uE!Q56?PFP{X#PT;>&)n?6nbus$@p;QnoMhtq znq1Ixg^h1hiye@ES-lkhC#%;%%vU}c-+n9i+_W-W{EjTqW=#+C;%G#7clXJ;lG&Rb zPSq5Z&Jb+%YkkAyq_RSwhL{WyvzoZYS|`^1iL4mL3TMA;>85q^3Pdfwc$$)Lcz8$` zngw%+9m|J5{j?B9<>Ayf++p69*+Q@;-uUH{nh~!AzYE0$1}1Phnm-X1SN@bmt1hf2 z4yb)9{nh44|E=z0zRGJV-WYVVQ3ZEhrwMwak-neXrp*sM2^`JFTUH)aO>apyT!AVs z77}(~#2=7eDz9LGCF-c` z4rgZ24en&BD5_d7Js(~!<1AJ^07aKR5!lncM@GGrFRV;_eN_UrHw*te6f}6TezaXL zX}s!T(u5iPJJZ7lWO`zNOmA=z6C9i?wl`4l?xoC1=j=Z`t6Quw+4k`}v#X*rWTelt z`XXzP-834m4`vs)q}y?eWX6gQKK*rsB3oH=t^o*MI+qB3(kp~hOzxe6p$^`0Fl*-%TzXHpSYJ@ab^TeJD( z*cxW-_9|;jbiA}s@;^XD?ZFGR1N1N*Fb*yr1qUI_if4))6Wl_fVnnm6x1EntxOOsR zObAb=!9DA?R6xZ(18A1Z5KO48_eRe#jERRMCv(k^&Q>gUXNypU4tz1)R8Y58%`1e9 z&D*0D85he_`Cid{)@XZ&%?mGl_D?&tI^xWH zj}$`I(oA_xqOWgZjo$aTnWVgU(YynT)4;qf3%DJvpgN^Gd(qT-O91)U)wYpb5$Cwj z9a6@@4GXS}d`%V{*9hvt_VbX}O`6k=h#gX#DvM4`iP2y+OZHp8Fejv^}$NA zrHj^yv<~xDG zL>!F7__mdLJ!bNR>$YbgBF+bVQ^M|y_ZSc5Cl%KQ*ZDyi6)JxARmFN z()S&%Pr#s_0`c*w!L6Q@8%g#7LgTaboZ2|k&>`$r{xZ7QhON@S<6xHw@6c}=*$yY* z%bXV75Fd=dp(CSygT2sa;P7JXZ}NFJ&-4U2{35?%jH9Ds?N2!9g08JL@A8*0&dp^A z4F8cKU-BFu?E8-XQgmv$yMDS}KpL!O`is3n4)zRoVN9DB@EcP20*{CPT!YwYtppt`w&AS|Ep>z*}l|8wo76ULz ze{|moOfpGN`{z`PgI_TJ8%x;RkgvM6|IcibS)iE%da;1Ok;TRXT**i+3)S@qxC%u_ zx2Hd>=oWw#1wao_C=B~iF+^5Ou+)4$AjZvHh`(vqO#tm`^)K4hbkUqb*^>?Jp}xi7 zu#*v!Sr0Z?Dkb83O!2$_tkov2<~h0Yua44qvc6f+{??2|n4FE^w0dEwiN46kH91j7 zX3XQgU`P!dZlP4!HnE>-Gz6C4qaT=iW*UQ6*=F(nv56)8v57HxG8CN5kO<_6mHkAi zhq#Ez3YB|<&>yN#1Mto8xhu=&2fs4SeKbDiEJ;tb!t??j-`R{|*X=eycG!enqXC@r z4mjI4hISqHRn-?@vJO@p6@Th?o_c`|Xa#^5Nf2YjH|a8~szmY(`uw*6JfQJY{o;B1@ZvRXLzpIE^FU|$_zeVJF< z>G^r|(M(~_(vlh=e&TjM6*!qMn6FL= zX(Gjo)0-Nkp#dNyxZl*ddaC?>Jl`S)wIWt+$;2jT!N%3msCw88Kw0nKQlWf$i_3Axb8P6kZYEj*$VdkhT* zFj6zS&~Pb#sUhx&;Cj=e`A=}8R4#Csq{SPzUlv4Pq&?k?6cX)wdEI<*4agmxt19%| z+$rJ<2uZ03thifD*C!GN{{jV4ANaJ^4LSjEFb{h1j2`qfG7>r#4CTinYi(VC28>Bc z*lUrYT1 zhL7cQYbC-bV<{FJ&S0s}xc&=Mfp(3Yn>ojsC7Og4@N*M1AslwI`=*YR78cA?U~_t~ zcG!tWybUibG(uWLI*f|0pweR7w;&o$_a|>m7^P$!I)?vXo+V!}qv(ioIYnfs?;m9Q zs>@H_FS3zPgmhQH&^U_CT3R9$GAQ4HorQ@`RML@R+Uaa+sA?6C+B__)k^w@-l?J=v z6qLK>x{yYB*yC)L=@cO;zn-JyfHJG_kMj%ME$As8urC63kc_5_JOGE7h%aEmwELv> zZRV}4|GJ2(Xuf(7X$Rw$<=#m6ZWPlekCD69%)0R1s&M%1t3w3M=*bOd@WoZy8oNdWBpNQyAh5m^$Zd1|B&x^q*T1yej&!bja5t7#fmUxp+2 z(BzekR(j2x*)KV`(ouOSU>LrK2rX)BZv_?tzWnM%r?cGob2^HzxY}+tdtnwQ*!)|t}Wwg9q$mm0eTpWexswyL9_5MlraFxCs07Uy7 zEhs+Fyx|uU`%F5hq-y?$L-9ca9;F%k=(lNuBBB=uLb0I6{B>da_%J1xO3c2CJnzkb zQDf2`<#yB1Q#xX4srn9l`t4m}=~h?IOnpbr>94hZO1NvpBEq_Q>Q@gOziAZyG(R_( zQa*dc84u2xBfr2`>ZL6o{&#R;#qOk5SaRRH~;I=sz15<;4+A?~6G8CwpidDm2~b!my_*?de}KYO{w9-17>t0=GkF7f zJ?>5MA>cQ+a|s6}KWOo8mlFiyvHh6EV~QJWF4lJ%@lt%Bv3*d#I7w)tiAve3qhmGDE5!7VaJ`&mBFhcMz-5d^R3B z|937gm zpLO7gMCHdA+o`ViHcIEu%7XqNN9$QhJ=>ef)C5lsf424w@=Gw&XkPt~(#|p}uBOZP zL4tdb#x+22cL`1)xVr`S;O;c;?iO5wyGzjEu8q69+)kdEciuHK_rqOxf9thQSJ$cP zI<E{nMQ1%X|5D##f9@mlQv;U`QDmcn>+eFS)`p{1w4j`MsB{=SPo> z7pt*IV6jgAN`a=3t3Af8$NKbztCJ@)bEEUHyOm>H@BCtC$Ao~0 zSntCh9~0wyd~9{1$0+`PNglbrTX&BKb7R8eM|RFHE`)$6g!;zDKfv@+unt`J+#Ggg zW#!VR3Cs}C1qlnjbHgqg0-MennK_N;*+5r84Lwp|=@~eO7#$t@txLX-f=cAmPrslV zBFCB9kyuQ0f2!yDg&Ae)NII}wXq9`e|9?pG4D?dw0v(|C4{^Ju)(GyLJ$i5J6~MAV z6(@FTjeOi&M1tbjtiiInkk6h_u`~=pk&*8mHPFfYiAb5)@U|5B7t~V{@k!2i`Y(6h zU+nZ33agePN;`m6*FS>`4=Qz<1E*bjem9vT!eNSex;6X;*)k+bqdzPVccUvvZV>nU zO>Qakv^4$LQ~4V9aXFxR8#tCS(}@+~=tPQ%kXu#;gh9sZ>5)hM3lH0YO37p6b0v76 z`-A=KjgwnZ{WH&Zno1E;2~BNkPblHolsE_-5r|4+o*=N+&^*1WcXX^Kg}==gO33FI z^u(0$qp^hfbO`k?5dQ;`7FeP2N%$1_IhQ^gWxb>A_!~6z6FJ#`k?WMXNdqR<@?*Ge z`y@M7u{||1KR(;I6RdY;(NFaC5Wuud3}0a?z503i4etD5)Q!awei)kn5VS%DwV;U?fVI=J zen#436tD2D%VAyp&Afd^+4dK@ca!VsH>_nu8N!E4p0Fq(cXV4lI@hO5ZR2E;=OvAm zNY25OFN86e=Ww~Po^SGS`bOi+Sw&a1nui%hj6VD`^QgI#HEj%tZaPb3gkA|nGy%}G4CwEru z%`ArO&K9E8pZoD#*DnXfY~@4|wDi?oOa&}a7+fm`hOml-WhGq{a_>* z1xE$ui{OMG*kqRmmTc|r+gb$xt2N8Y@z-4HvC6tOqn#wGfxBA4zR3_Pz7BWjtRh+c zy$K+i$`CB1P*Jt}AjC?O9i|}hrJwzX+V9Y+0IY(oq3E(2t1)No4rk(dx&NPHmE@z} zOlzT?O(TTS_>lvgwZL;(CAR*}gL;AXS_GqNcCbjcpP6-LxL%nS(3|;` z_yIoK^9GsE%Vx9tWQ5Cy5hHaH-i&|O$>}-4xaQG+@K6)0#@&J8b|q4{YZb)haETB_ z_=-zq6P#;(Hm^T2RdcsD#^rJXK{kCEi-CpY=S5XlBiq%sMx0wWp?|~keT!IsH7@9W z@`=u~O2=={RwDM>roRv&fg5biBY281LD$hEF>Cge*fOVMu-}$&Xv(BtapBS3j?j|m zv{0(b=IztxpC*;&4HjBBdAQU+V>m%nb=DHa%}A(sf?rc3V;bDgRKit!^xmk`ZR@_HZuAJzWx z-ntG~0JCSGR=r_?koQ60eBq9n&xb!GJX&dEr5QF&{g71dIcCtC$P*F6Zgb_(A#~(R#S%F7JKspUxJQj5yp+@hYa(&t z>9-igULa^-rwmRyj)YzSW3gKFtle+w0BC!=+&xyFmNRQp?K-++R3rOb(Lo4UX*j5Sl}E zfNdn$TzM|Q-9#7-u-lmkJQy18h|;^e>OM$)0jF%zA>la*ajMNm188HmT^a^>7>D8e z{!>?P|JKR%;0YkWn&jr;VY#jo_4D5(lhk^T7OTiE{PtD=qb+HK@fkTGHoQ@!{|HZT}@e^ zuv+<-fR+D5Zn?4B#b~>a#4d}gKr4Rga6ufBv-^>!iK)T3_}E*PSivsK7jejCF57oU zTsBxE)JgwFRWnbb8XGeyx~tGXSw=A&446*ID@YO3TN&oLJ|2t`kTQ02b1Sc-$R^a` z40poiOpVyKItF5S1p*4E&rM|=B>e$w%B;s z>rBwnKgH5V*D0?F;$ea0(|F^sUPy!5Q&+7F?9BSb@Op`BX)_mWeFeYAeod$PR2r$m zyZhULg7*-ozo2c6MOe1BCUdFUO^c!0lj!vM7_-5`9hT!-8kKT9vBrN3gYvILn2T2n zioFz|)nPf=czgSjC1kNeC%aa+*Q6%LYBu=eh10bGYZ9TU+aa=7;lHb1C8-SOAvy2t z8#I_s5Z!>pC3%#nEhYp9{v~pCB{w`0JM26`+$~Ob9~v4C7(wP82iNY74vcE|6AcvB z(!FNYS%BtMTdlEF5@A1H65NjT)RZ6XbB}UrDoJc5P&Yi3nU@b12hmZeReIgAKGdi! zro3h@;G{=Y2h!C%^4D}nYdAg|ao9?lavY4%(=mwsH$f}}>*F!?v%A&B{3f~^zJC)y zb4_Kpx1VJ-tZgLLufg?f{dX+fu#t+U!>OuTM~dU8*7FywQK#!cIyUC?9h~znRYjE! zt`ozWR6f*NqlI0UCuSpji3YPh zjig^AafEL1?d;Y3>Ghj@v~<5J>er;g5ZRV_OIL1psj3-^ZVbqAYz!1aOBc4QeW$fF z*42QuAivZlWa{`qSvrsO#njg7n=BV~&8UbSilFMm+NT;daXNzwKKAWqq58Rp_}*~! zA|a)PF+1ILzDAHDnMO(!P-uZw;htGRNGVzJQLhZH`W7z7*$Ej z{!Q8{Pcw;X?~GF@dd+Kcd=aJ4q+x&7=Us*t+rY-A(PYm!fe8olWUUqsoQP4Zt|D9~ zc+@#w`H{|cVOYUPt28ac`};=brFuXSBXpjq8nh9)NJp&ie-`k`^z}>M{Vw@m3i#Ao zjIz*pAPYN4q025b;R)HSmr+3jcj6*iwEIJfb{F5Bj?M$#2#JTl%8Zvo-PIhN0imJD z?$KT!GEZb?q-lxEP}uuQ)z(V@OOv>Tg_PA!`2H7F9O4$*kYQN90_(c}3F2y8mM`FT z+QlVI(c9`2K8n2^lvHA}P5MK;t>IJjC2NrOF+W9=K7Gu)n`szc}eZ z?S`E!UT(*5+}zlP%-o_TSZznfU+D~NWi;hBF9L-M}G!y=pnz zH=+I%90skjBP5G=`q-~O^S1;sim?}3H8O+QWz8z3P@so>9a_0f2S%iN!kz-)+!tYP zG}*T#^+E(@)8%Gkgvf)FOh*4CnXpZtXtw#kwR3`ndB({pl?rvlKSbbh<7TF5l zT0_EcZlnbAQKCRU+m^p z(Y-)6W6zuAne0YBHR`M1n=@zYuicKb0E*8Ta6)jRkZ@#0LkitjH+fYdGpc?KuUchO zTM8BR{d2V)bA~FIKN^Ur-(x1=$9>lK3k-~TlI3XS=4ee{eG#lp{R}6KK>@da_Vj>s zJYLT_F=~~yK0eAyy{|j&r^xL=&Td3Wq{#)R_hL$$R$hsRd0#?G6v=ed28I5EO)Ud|s_k3dhE zbE__!y{rxT0Iej#e7j8`9Kc0w)B{UCqlL&>y$C@-T){Cf1LwkF?8W}f$eg7~> zB9y>=Gd3}S>aylWH8nLA6CV$1OS8Q_UId^0$6fv0u?>I-4+&uip(H^-<$F~7MiaGB zxop!HP5c7oyffczVk`bdfjR2zo{Ff+hZ&m@d)4a>)O=TqmWTmgtn&gN*4yjj4ZGa2 z76FE)M(4e~LcRYeGfsN@Ix45kku6h2%7=R2;O=f6)(1Y=9Au<8U* z&@t)VXj0#6$I?m2%loiH3>QD?gs6W~2&0^YZFICO=fV&$v)TzsOw3G1vve0BRWH05 zz5q>(nVir&b+o!KrMx%G?khSc~CE*^Rc5*&(TVCVY5?|jTe2EAAaiWeGM z^sjY9YlgVIMd(@>0Zj9RKHxhkmIAZlWb(6Cq9 zBdnM>=0e{L(TG8x?vA$c3B!GFol{P9o}yF(lc(orKP67i)F}9bgqDgNo#GhE5}6x@w_{`o`$dPK!8_ zAuZ59^WyyUS@t~N_Naa=671Pc_72c+37J28!GTc=r@BYU3{;602#(URH8`!{G*~2l zi~8VX%DM8n@(YB^W>1jhmoMGr8nvR5*)*sR&VcHWkYd|MlR78MY{*@PZLenRhK z`Y~z_j&4Ri=qdU~e)EF#JMujHWk$XI1|(v`_Wdl64R=RD*gWMDCW|dcWm{KNy&aV% zBr91%w-wQfrn0m`d(`6{R-4bhfEppa;H0E!hdTDeyr!R5F4x}4v+t{2X7qan8%VCk z^)?>%vbv_8u#KL7Q&S&%apG4fyBTcVuqwPPYI>?D(+n~&I?1^%E`?0`$#Etv?uHNP-C5vHSNdhDKp+3 ze5=Vx;dVHo?v4?>@fkV{yu9{S zs^(ly)eQF3J8X+Ay`=S-oYS-6P-a!I#d=14qUF=joNh{OviiidrUho`(xnBWzFvE@y^PtT zf7P)c97=5j&H8kN-*o!GJ<9m>UfEh7fp8sXG94+8PFv4{XE=g>K2_PQLqcJrqi3cU zC*A`Gd&-`rJ?q|@ienmbaw+tnOCqV`C79EX?CxEOkg!R}1aPOT@DXJ+=+m%l0K85J zha6S?-ElmwlF7*C?A2_l8>05s*<*;b{6==mKc8~mF2$a$S9R5~4iVGz3s<oy89{YCd-8K&xf>4O=Z+H;Ix6)}%>{=Yy4TgE=G>t67QmY?yi7h( z+chMdZ6G=bG>C@1<$xOV%b5kmD8^TB+VMA&d?{J zASRkTT%U*OBQDjYeeH?EJc73SyT}l^3DIvGZW)?KVtP-rlF1`3aD(YfV)wH-U-W?P zHE#_m+G-aQD|#~w^PG%Novxs1;jdYIc&7{#hS>*gQH|a)4a?=;R-EQu$g6XlT-;D< zK{V$FJ^~`OIwx&kmGf(I6{&7lqpsQ`zV7f%FFkRn<(BWGg&kf0c7-+Un<)Vtt@&wQ zc#)ngO+}*@B~OF}F9{RSe+rP<@#{VSF>!yya|%*1)Tg4mE=Oj9OHakpIEo=tp{?~dI!Eo+})~S zZ?!+FIup$U!Vaw6lO)j-MC~Q71RT`j=#OVCs-I7r+7&E8t05oWVDcIgC9QMA5I^s@ z9hcd(Zag>@p(T2nd()n!`F1jD&2V?(?`|CU9QSSw`T)60NXIXpf#39X>j-^1-YDr_ zXK6CnT({=1Xqmh7;ZR4jBJpinu%=B%yQlW%^4C0Xh0Q$ks$F-an@km%*4(}`7nIO^_%i}k57cibmDfZC-}K!w-HY7uKB*dTZyVTH2W$O zch(#;ey64z%$O zY-R4a7@Xd48uXtDh|g4$+8xc&xygAYWg}MJ1}uAbU?BG1+|T-tTRXlyYn>l3Gd|xQ zNW@I#Cw~2+eu>0)m+ql(ITxS8ZcVg1mJakF_JN8_`}VwbA%W)cthD0wLNKaP{qD-f z18pEh!*y$Oc@xZQyW_sD*UPkgu=t9Cgy+D|g6Fc~w~VtvCkSN0xZ?4qZFY^d&}4%wu&Ckdpsgc`<0oukY%yD^Qj|uYkVcb`M(KI^iz;)T z90PqaQR0#P`eKlHP{(C;$Fo5~PuJ^41qq*HR0HDsk5zdf7{>Lxk#-aRLv+FCkC##V zv1|fZx*UkZVW^;Q&5q<97@G?4l3zmt)1PT`Dpq~Bo;{Thm-W?LNhH4tvN4P(!$2S3+mj?v$zH8Y7B?fR*hL#gi@LemeEbGa-qSir2?~9Xw{(^XpkVfio=^9-+JX-b|U8+gbeKMpHGfoLD@oG}mjSlCk00Jzb8 zOze(%8H!Wl-D;pmR`n;0oD`#NZKs96SEXf151ir)xUFsA(mrFjvWd7Mu^2xaUTc+o%2knaWT_-5+`-&0*n)f)@DsTAad}bAtrW0{vv~L90#($}hy7anxzM3%F z|D8K7{dQb*YTD*nV6ub@b|yQ3Fg*I`=;%733}Ri1JdgIQG~iEQyOFVt zFs=4}Inv{`-5@8+qm{F?q|NfWUA*E6NQ{Zu@VtdZN1wdwx2$TvUDYGwa#v0>I%+sE zg{C_|rDsH?AZz*gB^my8n@aG&rHh7v!MPzvR8;iZ%YY>{Ly*Y32!fWwq#9Js@TAFy)`7O}JjKs!-+L z(~2Ju3a_;rlG-JcBF2nY@h`C~9}f1D$*O}_iHTm3OS5+rqSFTe&B_$PJ) zo0%`upK$;iG8)W3jpjl0_=^3#itY0s$NP`{e>9eNzxZ<}swi9iJ+PPb?oT%!Pc^Jj z*tFD%A1a|Op6+;CXDt%-Ci@Fj%XZY-K^zaK#mY3)i7$dwKjf)%?k88J32oc&VgL57 zrNB8s)9$YG=90H1rNFNKpfX25BuP1TVtCjv=#`h{`?lo$!^5w$ae7Wp9GCzhZwZ{~ z9H9U-e0+^{^(!RF!YN$DK_e5ZF6C zt#m34HD*$q+tdUwH#Y|}XkwnSv}9$YuF9qC?5bCQ48cEtvIGVNk&==MolbL_b`7^# zG#P>BTmO#Pe%v8ZwT-N^NJ3-JLmJF@mQ?!w@g8Ay0YYJPbo5FxjHZMHtRv5=+k3hS z)$pMq$!1g?q=$!xaWs!Lh@(NoB3@lr2mZe^sH3)wgQ_)P=1 znt>HbJ-NshzdAu+^CjE&pNSfmDN*(qV*KYXurEvvp}YR|pSeVH?>tZX=c32R|2F$K z-8SsqD<*-uRf4Pab@}~P@q;l72JE311>+2N-)}9&wJce$3sIVho4;}P&R7N3XyHnW znY0!l>qrx?LBy|7yq@Qy|I;p9cVT6{2OHhsWr;qo$H zeW@bC=T3;@XX(ynvS@Ab`PpFFd)tkpJ7)_gSLt;>vEq?+;R|5nUXv z0NK1RM0Zp7-We**B+fOv$P)HLMreoMWvbsS885}o{N9>#ppvjzm&9B?zF~I%U18f{ zA_WDzp2v&oQSL_6!BN>Ezd!?|N{%2=PPgaTloSBW*-DjyRdr6i*2%KL*=OljanJ9< zk>YQT5fgxbYcql3J1Z0P>R~&5ua9i#p#bl(*`b&bwZo}6FqmuqeLWwC4ju{+c}xt} z0C57W4UI=?<6+k%+?PviwRKGRcUEF)QD}e11lS_HY@la=4~+Um!X$N2n=T^p1GZ-@ znfvRIJ!qHonMPdp7wGI}_KfClt+^`4MDKswH&L#YIRG+$%^_Io5OENPitLV-iTOr~ zgz!mXU=T;g{3bE`>OMoX9Pr|C2UdicJOIDOw@Dnd5U;O zM}Z>A9g~>HH(-2oF^^WrXkOz}4FRPWZd9m&M`kagg8E!wrQE$iZSUk{SXl249K2jl z^@SgtbV>hOzBqby%c&G=@5)pNhC-oC%y zsqO^E5KoD0;E*OHWOb2|=&>i|loybH6t7&7suJM^Xc$d1@m6?z%Q+>W7q7!2?p9-! z=%QWNi?DM_gR9zksy>*It~oZ9u5mm7Yq1?-@jb0WrkqR#eS28A+~%=zJ<#!dey}ub z0+?R#yWZ+8a>*3p0VlHU(}9+L zTmAVgr~6)Fq7TNN#HSwj_H=sbkvw|`I_PZz&ya7Avv{7(Ao_Ckix_|@vv=Din6nei zXBt3Rl&Vj?9BHeo6UBMQnak?4XkgA2+BTsEGJTtBhBHn^{b%fOj`J?nwN%1f1?lsi zwX^-ET<^))4r!=WbZ}}^atgNb+a7kszh-lz|3dF33!ZFNAEn&49FD~%g4RQgTxq1T zg+@({N>{V(50=rYaXON4_43B3ql&UL2ne9LN1bOwr##@V+WM^oQXukZlNyH>#~5 zAJ+7IRo~O%7`023EA)d5?8V-P>5I7*xqdF&jc6m^z6srayvz`lBH^Tk-OW!aTrM0O zhX@KrF_bn=4NMv-px}?wis(4*54zt+{&@oU3zvv~mIu&ijuu<8|MHsHEp(RnW`@Sc zruZ37Oj(!`dySX4uyI{T)#j6wYvv+%2|Lj_GE#4-IJqXhYO}2zf-Of3 zddv0OW-90WRyetY0+@S0NnK#n6Jpg5bUNpBc9jRePS0dI9kg%!UhApXY zCK7ALk74FR@9q$g|J1YbVKe$VG+Rh*2?bR0!VAzGQ>IHzj!Fo$Q|J(3;&LJ|S;Y(Z z9)NCba)4w@hCxQTMa5Z2#=#;Q!3vpA6*aK%1%kS~95^;tQPBRp!B0mxZ#5MfVJfPl zg^U!;b9@E}K#$eDZ+6is_jph^T}UPGqyRe+c?<|a7^kGM=fBGQf7B7>F{}sRo>*HK zQ$zMVujVR9V+o)(c?^=0dcjaqagbR`qd1!+Hl-v{NJUa}qF1-wW&5s~`750Iz!<>~ zBcN>ksM12uNC>V0Rdz4LZc4)0ia(Wjl>4J^;RN2>F@C~@>VSZ=sqM~RrJ=c{1eAs; zpc6sZG9tGrUsCAMnWT6IWYy`Yfsuxyr(uWvt9v!SrBMC zui{T5XC?wPI9*i}((=G;DHq`{{Gqf`XLlv@S^UO(dk2fWvr;9&3J39e7TJt$xc}lg zKwXO)5KiQZhFYQS&s!KR>>k6XNqmd~Oo@l|u4iXz2s@dpeX&Kqu{T4qVwG;g#zO-n%s`aV?us4$L20+EiezPS7ZLA!#iE7hP}m27B2=Nss>Sroy{ zKr;L6vxoyZfNa?^8-w1hR$d+|s3V*0Lo9>^jUTD9wg4k`t&9y{-C=z{T zk$K0LH=w^330rNsym#-a#2}Tqv%EnEf?9Tn&CHCJszuKdB9g~LGMmN8+jgZ#__^bD zEd=`Dd)}uow9@*%nfpDL`lqpV5+0?!+9XIa^mX}w>eY39rC6f+$SFJi2y2s+453Zn zh^mTziwUcv3txcRx^B4B(cG_9!Rp;0pq8b0XBli5Z+hM-4QsdN@jmJm4i zo$%5jOJ=E^+0p9_7$p8Hr2l*FP+60Le&~- zrZ&4TFrJSJvAC>*9@jZj6vY0I4i-Jd@b*rZj|jVFPS?3)O0nOd@&%<&KFNycz8)}Rx %v^FV z@3KDVm2)fElk&im0FahfTqJu85(+o~M6^w`DF`bK9}x$H49d1)p$O9 zA1qZV+ps$?U22Pqz^g${r*EGvdghLY7+xy{LkdndC`6|STsVV^57G^B+y z-tGo0>J9HsS0yDSeWNG(+ttVO7{!eviDt)vYF|uQJkb-`;QTtIno`r`OL#-^_ENgR z;y#-vsKuT@@+Ap(6jj!Q*R}Jo+koUN;ZdR&0*=Wtf|mFjGv+VJKT9?XQF?!0o0-x^ z(>Q$4Ogqf%ZFRI+m+x~;SIDyVm9yY#Yg^5{`-WT>6@{|z$W!p+2RHu4zO<|?N}VP> zIN5GT00-Dyf>cofQ}<99_C3jCn1G{{I0yL!PV>-1o<_k;Fg?uYKbF^j<2p1aL@g`Fv&F@mz{1=$8W(`3B`2_W4K%S0{$*vWVOy(rL8=AYw+$wrK*{p(-q&y!>kSfnF2{RN?b zS~HZ_y@%!(v*I57ZjnOJ?yR1EZ{beUM}AGuo&LP>D5WLITJLr%L{u#riaR@bNV-cPI6!Tzy+{x-?TZfAPr5Wd+uV*p_2}AT--wABM-PH&+ zI&o@>#KmOcy$`C#UDRq6NskMiNqMJ^q%yRWjd+%e3&1^z%oBN%KjnanSIpnhaH`3@ z+!w$Eyu`-FLROSiHmI0M2%>5 zrfBQqa+an=IetYr={^7m@?lJUqZIk%?5W|KaPR@`bj^QN?^xnIgvjuC{uGOM1-8nyISyPywGDKq7ZO_4=&(b z-Q9WK1k<4&6$zb*N_s=Ck@|w&c^jMCdm)S2?9|g@Tc0fJ?u!gphPcf7#u;Rc(3Tz7 zH@{OvX8JC?<3$O#Uff+tn%w6}*7A0xy<8S%BIU=jxphBYiU|mTPX!PhIvlb(wsPd~ z8$u3Hz~pP+Av+Gd`%1)1pnHjH09>Vvg867QfN;DLAD%<1My?W376)9!qS@=PwVXCO z%hEX~VnGL!XvWPwEO4Gq8ld_CvCQxa-WCg^dzy`qH8#eVElx?sIAt{ide(wb2B1Mw z%C70f3HjXK+x$oXJ0+At(SS=%elH3qCoD~YQT4!w)cHtXhp;H;{huy*Zy3~IwPm6=Q>e9I^!TUGeD0lCi+RgdL6wV_^$ zxpPBKKBl+q%_9ZG>B1&S5dQltc0v=nG?clY2F*A@*fE$;3VcXxMpCvYFS z-+kVF&UePW=l=11<6g!HNuFe_HP_VNoNGP__$Vv!>q2Fqu0PoQ(B~@)eAdJ?B2SSI%PhAkm zQ&Z}lh@#`yy?T>8y$P!YC+yyrC-hOhG9CzCloV|2M7kcXLrwd(Y?fFI(Wpeo-?V6u z7%2#c8XoQ1MizgGnha*_F-KP4B`I}DaFj9Vi!a-!Q0(bDflTh z{=LY4)k^5iLF4^msy{h#8d}oTI>j9HU~kK6#_eL({$LK$;7{%_XMLgZcEN5VX1``7 z2$SEk@EsB`rKSWWk>!k8<($KU8!D#YQkqutU&( z?%?Zvv7GzyHHrKEu7<pRrKuB?lvfM~1Fm6Fjn(-S^RLQfWB;UVG4Rvv_xNa4>`ny>3CLxPgV$EoI*y zP}~erz!&bD?~fc_b)K+reXK1$@g0;3st9!D>39(*O`TGC&PUg^|l*(8$x$S zJ1<|`oU_grb}p$N$*#7vbTkFkQ0OZ;c`^y)ye(Jg3I;wK>h6&3*>tBb&Q}(N2ZCz?L1i}bg5?HswhLR zm!}zZMp%h;$yPOP7>8A>Ch&~$RJd*8hXRUDEg4}Wn`yd(5lsglA4s!uiX1Gg_(T&d zA{_p->S{d!(2{<<_{AAH=w7khSGdI6hLe+n+W?9i|AqUDyE~Kn7KqbAGvu~2`9Are zYFp)g6=|aJaDL%xpb=in0)Zz$ojdlD?+^WjUK$bAVq-2u)0r+XDmWw3%BU2(`;zOk z2v#gMU4GXhssF&pGe3m@s_j!YLKL<0AZBAli$s82563*HB|t-1vh(o;^a|p74ZA2qr&s+Y(c0pv{QV!?hVr19wP;=`A$sUV^`!71G!(l&B{qrRkO=Nci8 zCvkmkbe4*UIzTu?1_R^{Kl4)@1AN(EGhXz_9>pKMQwhXZndM6%j~cGT63R0g@WHcx zC(xAw&DBFwg4t(238RhaDgnPwe&elCId4T0@|qKeL!M*dy|tB9+@dZ<2rB65>iE}} zh9`r{)PFXXx<*k>OSxaWGY&n$yl)@4Plm2Q8n5vV?gs%Q-c>?Hwcz1)9Du?n+%F36 z_XgmYbOZNt(3>BP$CZLMGx^EzGYB+!Rd*QQ$+Kd;jI6|r(%~>8Kbn;!*JQ@n>)D5o zpU%9q>8!TJJ zH{Wx;b;W3=hBv^ZrNj~Wy7%%0>i zOtSjY1tzf2NrL$Jtmjg*y!m+NnWIHy=P!lh~{@l%b5-3LO*IX#eQazxP4-Q zC`R38r;)AkOJ3r9+{jFJt3HJE<9MD_Uu8svY%m``|1Wr9ASQ>yBT&(vX&7zQm;$K4 zhFgrYxzKg{hlA^F7t6xc;og9{^G4qSyz@2ma-XE}++qPbqhtZSQBtWti#M6S>9cTG z5OoWD7EvKut<5MhLvN9RJ*C#xtWqJWhhDR`flecCS65sRmj)2&l&L)$m78t)mrB3I(1dR3~ zveLr-#nYK50!L<6pr%ktidwQi(PeHM2478_?fM8lv}uH|LGDJQ8XbBjpl9q0Ro8w( zjuY7w_r7xcm-l!5ttxlF@9kO-l5aXC1TO(Ku~`zGr;K@ea5mYE00J?Eq{c4>L8?y- z7VKJ;4sK>y+_y33uY85>GUe`v)C7+ve?hAD7jAn8>NW%#rNb`j59;S<9^*fTh8hS7 zJw$!{=8s_E+b)}h26z(c!qNVM^U2u6Z7|G~i0FF2%iMqeP!DhD;)W`Rj6(eO9N8maw8mJT&H?B8^<+Bl~V?Se<9#OU^M&PHlU2{&g{n0aeDxPOxY38ruF1eC#jTc34Unsd$ zdurS5O(#+jNkwPY5fc@R*C(>ZL{rNV%k~&EI>>4C%|3Nh@NX{(N_iDm$DY*AXQ06k z5amf5i(=@tlsAriZ-`g+>)AN66(-Y#NqOr$Gn6FQTL!H3mgtM9q4Do7uyNVU6lXb^ zHKVSzD1(+vLQlV;4IY|O@^ZGJ_=kkv?`@oxRDc6BnTcxd#x0X3HWqv8RHRdkcKlMs zB3b=C;*>5#LQje&(JNrPL}$A{P;BJ_16W!Zrx%f<*%A;g|;gi%PzlL%myE zCxG0}uRz>xdm8Tp93XJ??yz%XEdacC23grNQDUC4BRcIILA4Rb#~WOcdc`;@eS8rW&L#AW z*Vij92fZbpw1gNO%}l~LPYuFp9VhtQuR{GBTqiOI<}Z$8n6X)0Z-!epENZW^J}lgX z@_%)`TN85I_N=vlS0~@_NZGKe)$fPcD{%TeD}7cxq-~?CkedI+FH<&gDk_&~J8!U( zwlVe{$M^Iz@&bZR%yMrUBlkR5zl6;s*KG_tjUx|0 zPll->m%{{&gec8D1dV6I=yL7{GZ**QE>OLnw2u?0EPQV*s_z+%?m2FL&dEpZDgCVc z`U2cJXenc5UEAY~7aXQB#8Fy1)=6ZB^LY|MC^KY717#>QK8uGn^qk;L#ZjQqwpF#} z^sMj-Wl3QyY*y!oj)Yoix;2LF6RzKzcfZh{aNBK1`{f0PIX374CPQlIrRqUT*iQ*Q z9Gz$o@$w+ATsZlT>9#3$G4D3fvv9Y<;<|*+(s()R0zI3)xa&q;xM8GlJW|_OxLs$r zfQ|_L;6RWWm^+b!95$bS^S=9fLwA-;S@%67K)_F8vkdS=tDt z-ue{Wxcz%?i!3+2d16Sgw_fzGk@|41Ui>%qPZ^c7^84Mm zTTNELfKpm%951iW?ptx3vr(CJMCaw1Wf!qZ+N!O5AZ~ z?BB?}jikLSHz{yBnv$!(L_Kgl>VgD@Wtt$K_-eXFfINN$k0QJFH+*mWg~fbjbMct0 z!8O&uQkr$c8bg*j|H~v#0sqi1#S;N=nFu=H_*&W~Abn~0CVZHEbaVp6SR%a30>P=(O&Z0U_QU3^3)RKD<++a3Kl!|0 zCT*6qy2^bV?=)9!LqT{Gf`$MXo;OFc+}*0&*Q&$(+Wnf-!*r-L5c6Z)H&!671JyPg zf_DL7keej{Fk9TVyUfG)<>38|3)u%`AP_B^B+g(2JuO9&_B4(FY5DQnbe*m?|H=@I ziu^%cM@u}xs$8jW(R!sJ`Lsmz$-S}WE-O~Azm)QT4?}JQZO-GvP?UtT%?FV=L=E=c z792erkq)m8=X?{)FFPd;?xuB?s@!+gVqWcxvn*KlZ6rU2yj^Epn^zOW$JlrL!Iv5M zo3GSugYI2~PiyiEBXa2gNV}%ik*Cdt-+^@aNqm@3e=DxezsxiqdL5taJhvlwQLRSq zaw;SNK1_nZuQrlzCr2=Ehu=~-Pbgf#oI3dCttK`W?!xYmOi}?f0Y5cH6!btM+sN~k z8|IMy_53?OZCLooEcv#vzY$-Uo*&)1wk%Q`f4lMsNo7M?c0AY^@i~$~;ngkmON@6o zn+B^9CKgVivc~c#x==5?<{XxrDC9+(8$Xr=xqa%?XfQ`b{Lr@pCdwN>y3dur52W9b zS&mej6xQDG7<%;q{4Kj3m4lCl-ED@Elat>~hQTMpZac$nFT?IHV84L|Bv6+7h-(JP9sV2>^x!h;=yuimkTXuARA5p7hDs+@f)Q3W?;Gr8&C>G6CY zNljdObv&GXAlIoipN)o?$DVYl%w*)WM6v-+qfg6v&2(PBAsFr^zOnMaMdJt5#m=UI zbErCv93Cae*R_ueL5^adHg;_5RqRE@JPY*RYB6b|B~k-hsCUyq6cnb4Xj5`Y1doTp zy0m&BKO1EioCql=Q2XajC*j9y(DotZY=Rbw5gr*nWgQ#$ZRoR&apkjjVXxb`REy(@ zePJIcMqHkr={{Q^tvZTuBuu{7z10>H`QjnBw9^k=@g-=m+Nm}<1N-de&+BwTEU*ME z_s1=K?!7+#SbmidYgSUj=~+flwNKjMV2S(yJ42(*!9~fRhd!1ffQ4r}I_h{-TU`)V zv`C?!J%mNBBv36sb_c#O3;A~4BR_@1QUX>^6bosQ%}l<$17$!UQu;yU zAKSU4cnL$ud}vUWWu#>I7yM_`0B`@=q$jQ9g3dQv_Xv+k7cf?12iB5>PBbKu@Co2+ z9&oV4!;3>ZuVp^0s0K-4AgrST2-q^?&kIfbKWGjF;+Fq6tb4%A56k`yrT**(_us(g zuUTO>n%veC#G8potr4}4lo9?rbp1bp#{VrW{~r#lh)xDjd=Y|f)R_nEr1^gJbqUha z=-KiN&Ze&mu=l1sVVqqC5lmegOZb?|0`>YEOZcyJe42+eVKB@z#yb_*7TMaS+>+qK zrZi{5_pDi?*&1oNp?9}iBiWF%92FS1mDe3@0zccM^|T!<`-TK8(Jhvv%x^u*6L{AW zX3d`m+6`iaRdEZe6ObQLi|dF#b7a#xo=+JpoMye%a9aDm(GPRk{*}%AwN4Tm1tvch z0;;pmQODbboUU$_-@-sznLVWy8D2e05JJH?D08$`C@MfCr5)>e}F!-~rK zJ)p1{I`?X|dOIiAP;r@Ui7>MDWh7>dm5+49&{gCIC)Y)Ay!+$Qq#yfk3@{_X6}#T~ zPuCqSYck=*`4@&BfQ&udb!$nVX7*;G^(PD6Pfs*(oiB-|_r1kFHcI?#RaMoRDs3O; zR!KI-A30!ZFos;WzAhW>U_cHI=SSP=uE43%dSF@##S}BD7=5Xc*F&k?nv#~tHm=XvT@RgSGYNfHuvNqsqJqBHM%W^K-X9oFCOrX3k3obl)%7=B{a_6mmO z$Ei%AJ)~u))H8ZrA#dkjDI+~l_w}ku_tP+sb||S} zxX)(Vo8}~5+Vm8um_fzNg06|I9~g->Uu1b)ru7mOUWqz)N7+xrVV3?@i5i6ANw zNW2ugv?4ozPgb5CzL+fH&P%lQvzNxKPj}i@_DKbdeuh{5(Qj#UGFH^T^$RTm3GImZ zl^$b*Y*VKd)BR>6b_nAfLdV#5^ZF^Sd0qT1`WX(BUA7rfgntf0z(y2#@@=dWQ92Hc zlPKtRJzH&4j7dOzwjdWCrphZkr@+(keP6gYD#$1KVWO{ZdLrr75?BRU_*NzmZ2nZl z;hpwGKi>)45v4{?aWr3@Y!ucVcgK8nrmv6}aVI{zTkzzez1n8u5x?RdqvAE4!QmE@ zJyE*SI;dc;IHHXj31P|p09KgSC5U=-%d7e5Z%HHNBTnYgQqJG5zlGS1DQO5Ld%UM% z7BkSdk~t>&LYgLOO=DnF;rCmT*k-uz%FJ}7PoLRvp5$kLk1Wi(K~{KB=|yO*UDNg7 zJjd{pUmryt;6DkzBW-<Bas%Y3uPQ>I}lav|&y2m7XjZi-*E}q4}YpzWf{Q z+GPT|fB;PklRK!ye8|8zB`SKFKX%{7YhuS9AS?zUtNpD@z-W|s(C*8>rSf3)h(-S) zc7TKwv?f`^2L}dljfYSgaDaUOe;B+zfxI!0EaY~5n)~%E2Zv5}a6vapq8${A_78?6 z#xG78B)g3y%-gPgS4rY?*#DKCRO5K`0uJVK>b&n|ACM#knf&p>f9*a_0jF;1nT6xb z%=|fEYaQme$LfHnIT)r{ zRFmg&sAN7Dc}u;&oL~sqTycsFYTc>P-1vvV0BK!4>9q7845_Z z@wl52;=Dz}ApK&|AA0HEcz@HFd>88Fam&HGcuzKYqHb!F7DX3tN(jU1i|#?wQ)PT& z$}p+=pSX*-3{)6TlvFgv&Q8!CqJ^t6<5G(325&kS#fqmw_U|?^m26#`=^1axw+(0# z+QA!j8)U8T$EK?+*xS{k78u zh11&%p^H~|7L@wxH$K!65qI(bmMR)H;-ARG1-1lEA}1Qo%O3&^V4NQlyG1C21u|06 z&H*p^$E|+w?nIEo!ir`~pml`rK%nQlQdYbRLBECQQHq-Oo3%p}J-czxc@G)L*B?3z8!?8i+ zTJ(Rod@k@|pi12fuAw%7A99J@R6{KcU`>pR=isMwu0Ig<;$Ks^F<}E{*)!F=|98{_ z{P)y;ACRgmc_40ggUTH5uKL+ImMDq=?b(Pd39bL-e52{ z-X8x62bXTBfM0Gxj7~mH>E#L)(5Wi2AYRAHppZ}p;Dz+mZw`UFK4|H+xOzA^y|^`pUbw1WEO z#l=9AwKSZ->xRl%W`Z5DwcbR%BX0W}wFZmLVD^jlk5XD^`KqWeIu^?6K$>E9hh<%~ zY70@EniZ5MlL6VSg+1vb$yrqm@1|Ty`TEOGrg673t1w1SGQWXmbAf7KQQ_~CQS#qY z_5;QPs^s0~x(%Wk_b@B}#rGRuUF)H8A4GWOb7>C_- zaROcDT=$HNo|;9>kefx{cE##qO9jzdD4%caMQ z0|9$kx14tsD`)*#yr_=xPiniUo>3`%3s>*=Gua|0D1kxW;>4CzeRyX>1~Skpj<>=M z(oJUjPW3VS4OQju@C#r&kHtY(I-Y*?7f)FCFzBr*slEahvOL8Cro8!7GV*oF{B2j9 zJt~pdkm08&G!Y`tcNd2i(-Gr(ZqjNs`#1~HKja<`RZAaz?0a%pcx}FI3 zN*ZlWYaFV07E2$=Qi4b`l;W1ty4f;R9bF~ssQSa#17NZ4@@uAqGr#T5D18-Hzh$@L z#=PK6nt{RY?exQ!aB=CFvO}`KauorLiF>>B*1aEwSYqLLzsRYg#%-%a($U^MMy97! zrbbUe!you+gg8ycu&n<;uId4JT!$-T^GBe$2wHair|uydD2oa;XHQlFm$g*m+he~V zLSi|Sq?PFxZ(nA9uauO!>d>x@_IP^~-@pbR^tO&IN8CYL*$a zzA?tAR^)#6+MZr_S)pDX34Sa`sG(GcW>(6^#W>}5grDTXm>kNl#TF8j+GFp#zpIqi zf<04Z4{h(}B6MKOm8==H^Yl{2`Su+^l|89r$a`67E(Fi;)L!Vc@Gv*O*^0+(D?>+< zZ(;1T%mNMzt%LgwvnncZGfgf+G_nd{?bE+RM^wo>sjIDRrwhKZn)c*GByY9L=V%BGUQdh^uHc#kgM60{=+n#4i53jG4e&KWW z3T!Wzslf6XBD42Pm8(V)bBu$AUQ_`1(rCNlMVM5vWC9HWj5~j9h#2ni64ZnMq*d7e z^3({E)PL|BDv(=A{0W(u0Ei3wgO1Po4p@gEZYsw@h(UsvaCc_CffhpI~!$288L(Qn0 zRf4zXwd=Z=f-)p`z+53)`;S0}zvPZx!4y*X=i8`Xj;ub%0LbTTUT)FiO?yJ`i;vX# zmCWL`aa};G-Dx_wb7HOIi?GI-gz6_iEXpQcMG>(Bv#n0ANrK3zYUiROyQIE|QiC*< zB9I3jU{6JKi%9sOA}_lKfD8itK>F+XzXw%<>s1d4oLA9=0m% zXW~`rkLqvGhN1G%i5SG8%o_$nH;|RxH!x&=&7-qF@N(RUd*q7AvJmzf!+rlcA<+OW zz$rIGe|(};$C(n)rKU!s!Lei^C|EW*debWiKU6+QN)v} z`qZkx`{GK9mp@o8y4B~$`(pe1jwV0e)RH~)w*K<|IthmhXO3n(6?Lj{27t;*=J$qP zw#O1Dhfm=FBncR#bM9rFGBe$Dvp?;EI_SFi{qbn zMda)#(#s`0eeY&qt9UYf$3y!%j>YF#nmW_6fZ%;B>-7ET>FeM5Tk}!YoXrtihB5@P z-%L^)QARB7{eshM3TOJsYh2cY67gN6?vdlS1x8TR!IS{hm^c5k`*uUbdC``0%X8M< zm)COB9G%iGgb70?=deW0M>}Nx8az}7s>Zcj8vS_mLr-dxWpTF#lv)g5h8Z#^m`0>` zvLmF5hT=!@4Sy5<9?9<2CJuBO)-CraOW^aVjr@+(^BYqM8Ezb+GE^=*5f??uk+jQl zzM3y8H4;Wkr~MeXE*YgT9^8MNB*_)m6=;i3-}?Bqc8*?N)Cibnj|;{2VsL_;C*u<* zCv9bt;V{V;Fr_G^Bto%rm)EEG#r6@@Yzy23$J;rf&+1_rIb5Km@XhXFuN6l0=&Js} zaf2U^Ho4%7wG=TyJhAnZn>x|7;q@=~UX?`*>SN!_w$`}3tIy%%?m8Ci892dl?V-ACqEWoF*rX|psdb+b%3rp&2?E~8YW-ui| zUuMrI6GR2=(=ISty+jl~sm9f2+~D#eaC|YRpGf<-c0l#!J)*msr@5qti)wkgqgGtO zr*b;(`k^BHBRqtN`B|CsRp zE>5piqn4AO4$k;HF4DWuRQn5BveNP?^+_b>#CWlNhDlkYJ|RKOjk|!xM{RMPK;F3_ z4l_4s@Z5;^O9eydK=XH-+yG<}M#T}7iuX8W<^ps%sV&(3iH;)rGDNXG>@!t{JC1C1 ztT4|IiePzRw+gR`1m%?@UG(jqQO8@Ds1Al zq$~;Hh7x9MKykcg+~N6#nG47Rqe28{^D08_yCX=io4qxGKf24b=s0xyU1hJd?NU!dH0n^SnZQ(Uq&~2Yif5t8DBTSEHDMttS9hi|))pM_{r+5tdWR#=tLEZ3tc)u$^QBK-Kz&wIa> zC0*M_Qk_SBU(TO{nc$elb_HiaUT-L)eobo6)!ePSEVwudAS-xYqTJm3;b{$~nY04b z(W1a8C$l-!Ypf1e5sWha0M=MNb%u~BwL_Ib`VYl5Rs=&Y9d9B3_KglrcA(qu7JgB_ z5KyTcal4TDO~(!0!-=J3b8PY+#1+|4JMn3}!9@EwgynPky}Pq=Wq*%8Y&N8{IHB4p z1uc~D#LfojD=`hmj$gcdL-Hz)J=d$b)`nZ}WR{>mk!Yf0Qb$v>jzF2*-vHB~T1V&R zz+m3E+poL7f7gwCt_5gw_)J-wgBEJWzNTYepKfQmfwVGHbf#t(chNtf2A=vjH5FGs zkgf)_41&;ggJ}o%XkD{NUxks@QrMy73K1HdZWLykG5J;sg%$p^$j+HT(^+wsV$OW2 z9a5w31<#aNlsYNwFdK==UZLx2D;jjNlFMlq74GaqViO~O?yLrmV0==+c$`E)qiEvZ zW#OQQgz0N5m17=)@ht8IZaq$ll#Z}1dr(>)D_T6;<99ZwLi5N_z?SEOo7ZqrSa8| zrg`F>J+;GxbtFWz?h5h%KU7iGt@ygV)A$}Vwp z14ZmCF}(sC7gXjx+yH&^CYwl>@q8;<^9TNz$VgaX zlp|oPDR8xZ7HTywEGaj0KJ-J!*&3CJuJ)U^JvJl|CwWw09H{%y7H-&zXqRh(YkTAH z%5PIN>)_Y!wB3e}-;`qmA-nH}dNs!}ni+P(<7bZjhqqj7y!uQriQNnp?$E%HS*8aF z7ET{eiDh4hz^BrLoV$Q-U)cjhizaJ>r;gwAHL}7h=Vf5=(i5L8c%90ELb(vLBr60A z`p1U3nB<+tU;Px!VlXKd`=t%lo9L$x^veg99DTZ@sH`}yH4(?0gNc*>JC;iZ*C{AE z?H@~a#e2NsdfUD$kGq3vg00ran~6BVz<8PwZDk%?&Le)^`&uPJ35l^d)Ib%K1>XU_uYG9Vgd1(QWqm) zB}G}0X^#Wk&LLbgfZY{dTdmXP|Jbz0MVe%}O&k?`tlh3?U)4C;KJa4xP*0(Si?Fbz zpW*N&+4p>yg0)B-Plf6PQ*pX{%4VNb%r@?7V}4$?%}6Y-g8m&|E7t^NmkhbG!QHdb z+$UMlvyJRjwWodFTNU{~nS5bu=&7L?#cwp9ROS(9zD~8BYgoNqPk6*{z>tuR>(I`D zR~tnBxF9*P{ail7o_*sl&1^UHO832}?Xxh|WUxJVG|+HK>g%D+COnO_A>sD&wIGwo zM#FHwR5@(Y@h3lSnFCiS;|wy_LT7d{LQ`qUg=#LTbwn6@sogK4 z@E=YFpmH?lt+M!$x2Xs<_wJ_A65d35(_*Ed9X7Q(J!I|Y03PQ*v;>O3K=J{U%Q5*A zQ6I26rYCI^66OX1xTr1fNaO1rvyICBaf1`TzPOu%KB@QodLwg9S%`p%V(eyKeVs}W z2n^gQ){hjg8AMb|h8YYYvajoC@|g-t*OEt;c$3X+CT5aRl3!G8L)K9*@I3Sbj_av^ z%Z&&U-B*XN@cOU|NY_$f)pkuca0^f=>FwZ6?ohhx>`je|B#F*-80MF@MKwi%e#qHd zJ{!JnYiVuU+|QQHfj^3CgLw(NEc9%4&*)s;QVA9`&9>#(#4^V1nc zww6`DXvb;oCl_3lNZMKF&=#;-;|m<(r0@=_vFu*&AAp?IbmbDB5)vNxekWcgD~wwU z4cUV-lHX*aUFOzfUypXWVym9lAIhD$n1X+}zgNPwCi626Hb4_%XI3u{=o&c^Th{(; z_`My8>Ki{AMg&dUM-lx&s>-dL(2x=>Z0520AFQ8hl2?b1_FZP!UFx_pQuj&P2zbEb zuOCo%c{&0?#w0YceRAfL9JM}zq?qz33+s&r@u%k-XnyD zQyMr#t3s~-;{p=bNW8Sxun%9(5Q}KE#SX6yjCM3$cgOg8@~KeYxv259Gu^ZbESJ=H z)t-CIuw68GMbcWSm@$)6jD=;ra71kNp;cd!ygomx6Axtu4-an9ykdhX2p79wm6*Rv z!u(995gFw-S}GAwxm!pyH*1?-#-~xGDP)j&)M6w$*B!wops8`#hiFup;WG6 z!0OA!6g`IQ-Szq=+td1uQbua2l+I1tjR~!xY^LRmmpXb;W0@^?bzd0>n0xDpc20LI{K-}?IX$oD5qQoBxi$uG3T3ik zHf(X9Y{cco=B@WhJxGLHNRFygYU2opawoBS)E)01BA%Z z?CE>_%=w$+CNkvPMt(B6Qh4PNaFo5k>AT9cPhDQhSc5tP93rJIL(DN39JTOFLnxiz za{FXEF1MKe5Bq5TY0+X72ZFAOjo#`n(|*23&MI#a)T6pVlQ9RC(aV}6)PkeNXcTDWt1Y$G`#xtIIGh%#kpd~) zsf~ioe8vEq@3F!>Uiwu;B5AU|YQ)YImw>B#VuND%3t0Sf^|g2jAlQ^d7MT(9@;Sgh zalD%@I{c}ok)ATssBYdSrsv7{c(Yg{-ov5H_?{Zm%= z&r+8C7w`0MelmmZ6cYU)!_O;<5cA)DZ;bGym9lNF%ycbamhpPd0j>?hXQ+ziF z@iM=+u6`Z%3SC`9ILvJrxuorhzk#ig{#&)WHQx&--y>VU*u1i5$3F1TLCTHWzb6 z>$TY&oaXi?tH$kkPh^x#MG6tJ2XIFP>9OhBkWb&LYJ9Oy>sRVe2q#u=dPG>Ov0hM| zAMdfZ?SjxMp^-feuZGcE7i^Rk1?CyYOI*70_8?wCQQ=!o?Z+;tV!RiLqhkCS)%RR7 zUURql%zH{l_lPO^ZD5TQ`yCQppEVitTs35Szg^%rWnXvM3V85j+*5Ty zsc8W$Sa9)5M(vw!zI4`6Z_NT-@&>bAMQ^=*MU`=?G&Jf&aH!*|gzC{k)RZJU2IO+O z^6|f-rbz2G$?}lJuRxgd7m|4K1ar9>dfD}lO021wOY~$Bbr|qBpw|z@qG>n%eL^j|E@4`U(1fiS!wSN z8F?imXl6eQVw1%=oFIt{O?D-~6fSKW6>~?C#^PpxWcF0V|3FVyq#raj)w10@AkMO~ z*cNHLo`MkYB_uu9*Jx+D`BeZrZ;=ZLhSk#KL|3?<F! zz!IE=d&xS(kyoOx3OVGTY&dKAprxPGnU-a_$aRk)OK6`lIY}jUuT=Y}LWB!H=$ws+ zKt#uJ&x@oCQ05^t-ILyu%gwIJwL>4Wqu@-C`Xnd;)?8V|I`c-CdH)!FaXhbZYe_h}$9t+smDB^-i0UXzVbcO4oUr2{r3TJHA$(QO1#pRTEOFL_y(8 zGPzOxD&#vy5f?m|f#HCRx+(pNvGa40&B)WgXQ@ydsi)I=9hdknFP;WiWYCW3(++yn z7_mkL2@lXt^A|FM`G4dqOY_2*0e2U^pSN5R*ROdWHD}Mw=3D2Q8WJ?1uXOgE^hYVo zozT9=Qy$O4G}{Z!MB-%D=QSafoVesgscDVLg~XQ)51Nf~!?#~`F?2d-R1`Le!4+x> zwOGkGs%)-5)Oo+ODS9azhA_{BkTxF~dJP1GRj*IiVP6QCKOS1BIi>#Ic%x--HT&#r z^OIn~)sM0_Iro<-N>A&>$5y64$k}dO>xl)jHYi=ZslV58+l`=ItfxMZU$==dmMC@s z^NlJFTG|_>t>ca9Lf1MCYyPV1DDrsA*Kx($wV}T;`z2{`#K0WMP^~(?e%13t=`-K9 z9eMGur~W>g|7&e%*w}m_OtI$u7;WoAX|u+;CEwKaYz^hn%)JmL@!TK&dFhNGA0=K! z%=jk>M6;c%4`hED#1T>pEx00d9`#k=a&X_vG@&ij1~T6|9A)Eg$!?}ed|Vaxubl>a z&VZ)>`+bK-m!su2po?+~=t9IOT!v`{1GP7alobs{D+LZU8G%)0NfG_hsGt4DT{;rz ze8ZgEswu&R2dizg#R&s*mBU)N%R+Pr%7!u4O)~96?tFgES^~7Io$&3E` za!}WsMpGH)kf7X+bTL()pi*HkI{NK*9J!n|ySp!gth&#wdgD_{T*z@kf1s5jQBhzm-cTgT&74X=mxIW&?o4hBx+yr2Jn% zw_Z@%e5XGe9d&0GSf3~h@TC(7^qV%h!Xrr|2tt5FREa-_Lp&>J1R~LVrav6FM z{4wx-#TKs)?yIxlij%6c61D8&(~oijx?hx(M&F+klrb9LEaaost1p}tI7BcxZl?Mt zLGPRly}t4`h65EN8uwk(h)_W;aLVRJ)>WNUvfh)m>^jExePW4JU-ebL?@T^`mOKbU zxMX1#f4BP0<_Eg4PtPktWE?gM*aQ6}N!r7*#=Np_@s{knU=4mX?%(RU7%PdkFE z08@zZIwaD@TpP76ryt9(Y@R1GJFJPYOjI_)_a?r&>;b=^fetjXPU2L^;~=XwV&x}! zrWYve-OU!@@=Wxpeim2eJfU_Kgz1S~KZJ5#owIsxDj1*aHWm4B>OB{e;IcXc9|vVm ze9;dolrHlJ{`|@QrsTm`m?Ww2ec^jU=g)K$vg?F6HI0anNm_A5P1}PzUId}xx_9Fg+peaTB9-?rXW$%IY4!fJ+$mJQ zAYFZ^gvgyP>@uk^Y2Wc7GMiojnWGNV`l2e7YR1xfvOCDhn3jElY|_tQT<^^G??BGg zu8om&Mo{vM&Og5{Hd~*~X3o>hQC~w@4)sq=*D2&c*uxRM3-h^ZB%p=_jg}fV5N#_RGZ2cLjG=a~! zU7#@eGpyko_aNIu|JL4T!5niA`Y?VYXr5ARl)-jFCVjywHktJd`be2W)+?De0f#$@ zW+GiFmzx@I3bTCTNr%dPu&S4nPQ?3%r^y6PnMR;g-${SbVxfEF8?ZFWel+D;>mPFF zhy_=4YB|(yv*|palKr&zREuL^NC*b$*40a(j&iuIVH0oGH#QJJOZZ9E{sR&g(_@`q z6U#@>*Jjd=qe1_LCu2kU%PW-Fb`A+j$Qw0_A84}cgO|@kBO;DzGrm0Gqv4>77?X_` zAQoq!bvBB`9T&35Yt?z4HD=8HVR)8~hD(1qsw==8bGdJ2YFRjc_MyiU14w#XWS>92 z@tx{MUeHNtHg4RSbvGJ)|%zz%lH)SYD9?J@4gFN#ye87@`V>;Lv(wIHGUtI(Iu1uqX>SfqZGT7LokRkS&OS?Z zNtmelYU5$QyH*yg&9r%)AKUl8={FA*$N8uh=e&ipSX-(Mqp^9*N@lJ>SdOTFRyrfK zK(_PBgcrtd)%EzUE(55x==M6u1>x6@=m%!^iZl>TIyDK&wPKVQsu64!o7o z^zrDEC8QsJXz)a&+3{vGFLUyTP0CI?*{Jsad<2)u_1ek!*{7;UMWQU`+d7%U6w1dR zZPAb8tuNJv*T1b1p$#*(aaLgEbL2hI@D|%vY3H`;gfVra%+h?zex*d`C$lX)N6Mao zO48*CUJ3;K?yuLS1=PCf&tjM1J{$j6b6*`*RlBcCDFPzWk_zIYk#0mlLSWG$64ETX z8z~8;q=iLDx#;dL>Fz~KHwZ`w0(Y+Ex4-W@=j^@5Id_~f?&S}M%AD_f=R4o{#q&Hr z`k}W={fYK(@21KiLLm0})9$Bs@rc9lu?aBpUNmLn`L4+_9%U4Yy++;Y;nlYYI0@!! zWiAcVp0DhFF1o|6MJ^>&civZKogPPs1&e47VdA=#c*%laYR6+s4a>MX;25VFQ!$`# zcm~F!+HyA1GszYII;m+IxJ1wvx0FBfgyZY9o8s-!n0D5%zWrz*y(rx!Me*QOnmp}mzwv5mwggesYr&fGl<=E~7<>)>Ta}30`7HcIcJ=s2IkH7wOr`Ab_ zOJ24=J@!Sx$OQVO+{Y3NtR7W{CP5Y_g%!X1YCI%p;x^QgWJi(1vlbyb$|brZ_d7ho z5FxaxJ2L_wjhltpz>(c%;R5=rDRGn}UF`w{(%@HBg$8*KR2|VMK?N2qL<;RzT@_Y= zBs|;`r7jZ^8-)EljtVKMW^1CDP$wo^L}Y zyMSrA)b`@^WSD0%Nr8GVBQxBWG1_`4(Xp}uH&iW^2RrX$Zm$g~GHSS*z~fiilM`|0 zbn`I!_Hm*SrxkwT2#H!A`#|CHJiDc12zSh79&JAKHnsd#z^~?a*G{M0XJ2v4CAkai z^FH=f8i*&z39&kSm1`2aB~Y~GLxF&k?9y}O=;SIsU+s#6uNgx)rjJ?3Ak@w(oiOQjjk^m&;`R=AnrrZgl^uf%E!? zp?Yhq|JehZ*j#AZ$~0!aR%fBM5%I6|#khJxzU=It%-x%WgNagzKi2M7Ic%0-z)3%S zXSs_xv->bX`zY#JdN}Kr7nt`48aybeyev4?_vG@S-crH=F=E36xN`|t=#FyFM(Ha` zpQIG`1nHs7+Bs^R4ilDm-?TGR9yj_UHZfan)VIb@ek94}`)J!__3}&+bWCXcf`nu^ z=nfA%MN*M#b1N#~zKkJ84OAr|--CsFINa;oA(&fMSg{ch6E~!2?RQb_&Mi>d8PJH_+ z%E&+y=&*DzwNJ{Uy#gyz1L^UY zyBF23BtyX?4%^0DTKM;l>tv756)U12YZf+|Atih=LlKNa6#m^(5M;MR&cwJl9DZI? zE}1bFrV>R7SFL4vuvB6=*()Ki)V5ydqTImO$B)UYCAj5}K0D{aiXn+Juxk;l;*OS` zAHWsJxLFmuLo#MklR6c5a2KW&6j%mT8jcg^A7B6#Bs{^4;?se5e}z|8OV|WLut$u7 zf=C7K0q_PpUr;x%t$}+mYpzS(1DKGGKwjV_)9h^m>sMRp$#w>gy0e0nU-P>Cz;zv( z&V$ByS_8XlI+PT6xm6L%cTd=)v;U*?O|io1H4si4T||*suv7l=Xwxd}Gxa9*Yh|(E zfnD@aO2V!TEXY9O_JX3H?O{$5za@I6nd_Dp)o)bGN&na?fSS{{^2T*(@Q`nS{_N0D z@0-o~xymSwVHGmk% z0?Eh?R4+3mPPPP?LEL1e=^CFO`TVd=942`1^_jWf5yCtMeCWrg#&fu#?VyZ%d5<&giAbF}9|4A5J?7RzZr_=atgXe{A;f-rFJX zW>RM0RnXyCJa-3YZKaZx+N#fMC#rDf$6^RGP9IM|1FVl%s($ZxsQ1c!FhwMJE#l;i%f)$TWw1tpLb^F1-g?u3gtrEP zN25GdBkaHN<1KmguzZKA&`9XvgTmAk#tArUvhDkoKrg zvqIWKvn9f_=fbG%uNH?|N*FnURR~I@bh$>{2amGeirUk;ha5Cb7^ELBn>nb32l_@P zVHyVs)BUJ|(rOY}X^wlJMQW7_j!8GJUI^loGuud}6(!cQ9XsoODZQZ2bRy>FGVz)9 z`ooEVcyuF_+N@ohze6t+a%;Z#vh|%#Y~8sp-nvZc=x7{K8uM{gh6fcz=|?pa0xL)3qlh<}K|3-9 z@f@uw?&$o2V5P%f$3vn&h9!VFz*YUiNfDRX;P5q0i-uUSyvN(o{8+vGr;R_N8|+*I zqJXRnV?%9LN`N(bz3PJ%AX#uA3mVN$WN^f7+*%!B3*o)1GeOi-wR0CX9CT}2V~Sz( zwAiVLZAd|{2?7AKOlse!e5p3Y&&?_4sk7o6eQrY&7C*q=)HPgGUDuyL-CM@3G^i{| z{%dPS1twmVU$&OaOy3J%cIkYjRPmiV0!-+2R=@c6sE3|0ylNil!()-5Xy0n&+&Xz# zJbD0xFg(+-+F-GT7VS(`G(&8vqu0hjCga~G&1X5FIGn3%p`*DaLLnJpfA1h?R5pk? ztjdyX8LMQrpt|lZ&_!Ax|Dw`!a;4(ZXmJL(1692bxZ2nb-7)Ntx+FU~!-?t#GBvs>$-dQyu_rd)=ZTfumhU!OlxwLCL z_a>krMn1_u(X}?iPSgJ-g+yTa$zqy6<tW&z4DuIE#zu`ZDZ+&CkV1?D0p5c4LB`rg2YN3S z=n2gq_Q91Im42*e$vI;mEe1}F)tbwvFml-z{F#FvVFYsUL^mQq`w+d955@7xv-$gF zDf4hWaIP}ZaO~t}S$RwWOyASz4i=q?)ymczTkS{6KfW!z^g|1GT-$S&Gfz0qbfN_# zycQk$2F+6Hl`tk3I-tLhm?x0xCry|wr}%G@4+EKsXXb(EA0T&zF^aMC(tl+P2;&R@ zsPL8r`}Aw-_CFD=yM%}J_bizaTu2fGsrcWZUU@UI&V8OA^0EB%{AB5~;Sf)oIIhiG z71Ogf&{TAS1HSdNF#<>GX9Wb8%}(EeM|zWz44+8AQs?v(m%l@K9USO; zL6Zbp&3x<#X8{1)w%W5BZ};q-(A_IGe@yS1VP(h~b>fLmh-@Zo1f$_5=<^2>Z}`h! zqG0)pY5E=`Z)mE`biM-)=`DJ<28PjN9IyG$ho3Ba)J!UA6GT)=U(Gn%3~kSt)26>Z z)VAqhUfs;|ufjKUe8p2dV41D({W$~NX>^)@Y)oZ}62&0sM7qoW+6=OI#yEOsf@cbv=+7+l8{jLzQ5JfI?-L*Dymnh zM$I8{L=30GB}OhHfsqJxEm9oaJo@x>6Tj4=0VGq1@HBu;d{>_w&7qi-?JWxr*^#lRp$+RRMC8q z@)m?qZS$q8S;Zj6n&}&#R(KHg5pT`z@Jmc);1tyND@ezJ>Q>I@Qe|377gZS$9*`){ ze&&l}woKM$H59gq5tw6*-sR;!Hs8tP6xI{iPGn`F>eAf$2MA7(fw#|lHgJ9|RaI&obqVspFblNlkAXEi zM@_wMwyoN6`910!O?IIVguZwjaL98VPAd_YPSAca8%8T1`;{>Z(lpAO@Q}bFe{btn zVYKJ)J`aOFDE+<_$%|F@4|B$3MC?(o+3RBF7e0p>6Pn10Y+bXczr4_$lK66=e}Q*>{^jc1^|& z00ge33E(}ppiRF8;-&lufrGyT&=H0YA@ZvsJbDnoP-#H}?njYFfbwr4xFQKCz+%Qh z5J~}59&(ZW+qM0_-XMSx0wD6eJzS(;g<=6{yo<@n-9qCO9h4R|@a*kGyEd60IztyAH@(wAVGWDg^<|X0S^sK^Cyn1HElh~r!vj-Ogd;pwI ztx69SgaSFDz(xOM;*n)y4Q~51KMwM8^hPHV3Hu4U30ff3UnqXG zHugf;-<8I<1DKI5Xk@uqqcmO8#|?S<-x96cYd*BMIcwb$B#7`Nk1T*HMwJ-c%H+{sX`QKLFvNH$VF}4&UE3+Tz2B zk?T7C@JZG19ulMpQ=v*;*Dq4dvjpFDq@s2i%26f3DJ|zTT_+Gymd*3Tk?1IPzNafW zmxp3S2D~auBw)rx4Y4{NrHJ%*B~gc-Uhe*UA%E+s_)b1U8k!UzvU|i8i9GB#V;(}bU-9+HXkA`OuCp=-J zVqssQkJ@b{+)-4FyClkDAH;}Oa|X#$;*+riVf|V?c4*dXAZlM-g#L0cn*uK^7`N1cqDUyIe-k0fTx)EUgY|%SxyAO*6XXY9gATvGopy{w#76 zlApj>iVf4WdU77%gx4^NuyAm>4#Ns9nFxrxYvtpj(T$o0sh9nyIWptdV%N_=pWrW_ zDAKEB>PC=p@@g@n_*(xyI;9AADNa{!qY(Wucj|!V(+GcWM`C=ys5>D?>i@5u>z_^W zf7V09lJa!3bJGAXuO{Lg9-XHL&DiLe;pzPf$=8$j*n()H>M{2`doYsLCg zvSwXpaY$~6kh)HV&I#nA#xX&AH`_Y-aq_iV{^}4%jE^gjPLzuo_m}t+7rk4_#?3pVL|x z@#o>rx(+RZtyd)akK-DcJ>d&Xyl|eDVI!QolKe$LrFCVg`L4udda%QqXpCElpFz;xZL>gb z!`cQmiDlFgdwVS0y1=GaZ#F&)_u`j`j#FHY%FG3G{gvhE0^ z#w9EhI(0h4Vcz3K6RSzi80gr@-WD)&`hlF@J`c8YsMgWKjpRP&a#7dNJzJK z;{R`1KS#(F1js_|LMT^Lqj-+WIZ1ZsxPeICZ@|Ugq|?F6S8^bF0pu92k71PctQL08 ze+U7(lSuG=*)d_zwB4yD-1cyrw8}Y1_C&)ReN=uej7a%MX3*4wpAeR7RyK6AueXzR zWGxGAC?{4bZ&eOHgh0oYXSYr~* zhWWW(XL9IPIdeAjX2de;$}zV_x(5c^V?+CjEC@1itw^5GRDxkbwq?M%JLWlHm8MkVw(h2W5-DpQv&=B_-o_G# zqbtizQ3w0!0vYMw0!V-7(|o}9@;25hTb~h}jBpA+ow~cSjIbebe$OSq|H)4W!(1t} z=v+usgN^FLx9-gMZQzFi!X3c!&jzItnyk0m(76! zmpOM#CosAkC|0uYWl-4>x+x^x@`yA2%^&;ne?8Nu!$9Bo@)^4>L@bU6jz$(?Z&t$5 zgsnAgq_r-suiO`uhvmnoCS;bmgjGwUd2BpQ<7tCZwW|kpQx3@l9FV32#TbTp_DZ{v zo;tf*Jzlm|>SbFZ*UH5M&!W3wXKlUZOS?-fu2xnz?diQqF&^a=jUtk-dCwY&rm4+^W6zN@OA}l9bOr>R|X!MjuD&n^jLMmXR^{{!*ze;AHbHJ(BIE`k5fNafp|CJZ@(V zv3gu)rge*Rm0}A7IRr-BsJ3Ed@4m-pcqZC#%Pti3#}l5yD!{jx1J*dr6ZR6~3mrNE z>tf;nKkIz?^%7JdTVaSRNS7<(!T|gcR8aC536M2V@l@q5Yfg(Oo&QmsMRcKQV;MMU z%oSLqW6sp6DkUnU`r;HM@3ClYJMtpptZti;KqaGiFQ*{6bKHC{bmotF{4Qo zWc{`<{ZGSr9^}CTuyh*ISHtP{nCc#CMUTM(bXnVNl6Iz<&73Siy*d&|Qbh(Xx+afg z*`DA##tH+!x(Ocax+}A2`hpyCBTzwwRqE|FNi&qOLGjeN@DvWQXX)n8_lPC2@pNSr zjj`;Nk93@Fvlr2ynV8*Obqg=&=-Gd& z;-=E!hu}pJ;cA;<59N|g<`(1>v=?#dsy+4PK+bn5fFr6idN2Ac-ZbB^K-F5|sRSbJ zCwmYENarI0PDj53PV}$;Y?DtSqf0T1H6$W`#+MpL z5gd=fv*{@Mp^3RNG3H8zq){m;=+A8}hxb!1H__qqngQ(q{lk2k*#jk!d?af(IpQ7 z+4ZzhbPK>^Lzx7&qg~AU9IR1S%mkV@tB5)}1xR$xzvfY|k6`?IJ9I80ceTDI)%JilFZFQ)o4}$#yDmuzQ=p z@mUIkvC1FXwgZJFkghHOZ6(&=bP4f0WNwepHy4plxN@Vo{TBK4gDlZzQuh?4Vp1-E zN;13Zik1wmj#55s+T>g}i%jF$B`;1Ei&cydx#k@_!g!A-CA{|r+J-YwkSwXpTVfGfZ+_AtG|#z|I+Rq1aqbiK zgL&*h&{|}W)4iPs)wb6DQrOciS|(VL-ATv>H&ECd-L$-_jcq)s+jKfTOJH2lcT{UNPij-Hy>dRYYGi%#)EY zi|ITKJ)4prj+|u1CeI2^fI-{-;1r;DB2Rokgx|P2LYsX$*evs1uv5J)ZimOOy`+Yv zi~(>=U*KQ)Mun>YuJNRtwM5h_(m$d7M-{ASy}9Q4`o=8^tJB_x*HA3-Q4gwHkN@EK zV$|C~>W(sC9@;X2DA$r%FhTh1 zxs{J+Xk`^-e$bbh$=^(#CT|}LnL)B@igqeo^>QD3?o{w*b9dx-=fR>KJ#E!=s2edV z9SeutP3$(DblzP-asGJZ7p#zhD!7}ooHg)PVFS*z0;xfXr^(n(4JRy}^>M0<+2YvC zW0C}+)3daRY6?>Q<6qOJJumsHvPe*^HxN}YA|f({6breS1m*N!#RTpVA0#xIt1dH? zZ%94S94r*Xw<>sEE%Yy*$)lhcA??iFY|ytMf z>@>5jj~J;?AIwa+_o94=r|>+0m-n^K@1t`H<43jrDZ#a%>2-nh8JP=?`S`xrf_JQn zLaIQFREk3$7$cXOcE}>|)l9z%DZ5jJhnvhkCwyxdtSOF8L?MG^EvpAs&Dg5XoOOuT zVb`6U_u!kJv04=xcEay2$8hc5^TI~BUGshNjbEN?$M5OPNpXPD1K(v31_uw;IW6p) zmAk2rC)ijSIjf$|RMA;ynPmY*mPRKZ!uJrl(N~XFc*MA&Z(m@R_jtyfyWxc}@>Und zsJ0cU!-kv9LkJ4nw+scj@>)&HXp=W9^RQ$iScI&`h^gb2C^un|<%z?&@VK49j9iP2 zB?l~T<0B}_#{Tr&X;Bu+h2}*OyVhC=-CV7t1@~E3zhS?xV~UE2a_7pdam|?)i=&*j zxD8!(dK{uek}fz1Ti|v7`n_>Rfyb|OjGtHk4mtnfCSAecKidKathbe9T{a<{Gq_<= z0i2xANjt)5L}IilMlIU*h7~ofQmz4x7Q^GjiCPO!1y?NQF?SV-k*FlgJ>!5s9VwQv z|A8abYL8r12-j$06*qe>Po)g##Cg3sey94%e#(v|G<a0WP^^XbSSbtZP4qBQ(r2DH zm1XB9N$_w6uDf#&hE0A~8p{K{b}*hcNGgI0TGTW0sw^#y)^kn`E(<>CVrl&`uwvuU z#E{$edRCAOTEJowLdv|Y1tS;M&KoAk z2)kg`EKOG@-6_PSsIO!sC zG`dj-2&bCmc`{fbZ1s6B-}9De#RiP?Chj-%#4FV)RFB`r4h%Jm&{W6Ejpb#G$Ozx8 zs=DteA9D8fi(Nz4eH0~jDZ+xFD)Q;h7KN7V4qjoSQ@5mGBTq({cHQ~MTgWj@hWfg+ zC-S+JXq}IB6uR}UPhxbPsmND59Y!MpWluO`K=0qA1kl2TE~fU{$=S*M4`8l8WeqJS|Xap_Io599l~bW&|*xu8UEt+hhqXbLz@ z#D4<@*iN;$JuMi&{|DRsbD&WI5puWEAS|H+ig}bKEhYs`iN+UBn@FTom=v0wzQiP1 z{ZG{Qt3kY_2cSSivIi*F@ba!&hOg_?dB@aIFdl5tTTaLpd!$g#wNzgzRW#3CEg%_d zp-%wx>$_0x{a)tq*tS}|2L^4Bd0zslOOjnp}HF4zZcT5VFD?-N8h$PUyMpi zw|eC42mXDMXJbLQqEi^P?d3u|mEi>$qPwc$=7v3-?c4cMTZ@KCV+D|n(16=&QQPt- zHB-A*k|2Spok9;ELMiL>}D7Ujq0-7O4spC zgL^A4AIB)$mfG0)76p{~husq58;Io7af?bU8ZoX1Xy3MrslA!y# z$jT5Nf^~dDchyY*P1$`tnR4Ii`g zUtw4W@IZGxOswk|7ko>1Y*v5@UkD<){}+fAllXTV{Q9i@+F63hLu1Pd<2o6H0%qs4fW9Muk+b1f1y zy3u+2&X8`RpLr}4VfM^*VV&E{SG8LjS^GeIFEAQ?F3JHs48L|qq|+D)*WgL}N| zA|TM;dEAk}D7^8yIuMa5bT-}rOJ$j7p^YZ zO#pOxicCKJE{+LLtG+|uwRzg>ektVq0=DgW3P_dazE%oq*v`ny5HfTDy%j6@vdd7S zR5g2j6Uz-E$@a;_Hb;vfXC`K*osu1S(lylA5twDc1ui7T`MWZi*3+r!#KcZ;`Mq&P zeu>5puT#l}eGL9l4zW1(7KM@m7+w7#1t94H#23X0zo!~iF?a62vCtf>P+Ys}yIoS9 zyX9tR3a3qK-R%Bv#W|psSl2A%hI@Aur+!#@+~*#l0{k#HGYWP5FIpoZFHXa@7H3jb z-+FJ{4JVp%PWh2+AGo|V%Z*&?Kv;xV-0$qOh364(Wik-WaC;M)Fwcsw%b4Y6^eHmq z>dgzw-6mQ}m@T!ukfqO>+E6W?cuuB-)!l?P)_f^*IR;(4MpiH|{BZ-yi56Dh2Q*du zBF;9|acqOo8 zEp|m%=PD!N+bux;{C8l1M@;a=vDrB4GueS0AdvRVVeIGZ8!j=4*ToEwNNPi<1-6e1 z42+j5jE9nj&?F=@kL^v0DJ}@TZo3( zUH{*KCXjA1ga;|-r;%}@hIki53JeAG%>s=XEl-XV7`!TkLSYL=9XG1-w8&pq3|pXy z2Rs*VnE&g)fSbfuTTsM+syhE@XZQ=&dq00)#OJOD{y>pWlSWqD@!bQCfPVoM;YFNp zUH)G8dAr$BP~5DPfDWOc=ocgI2Y&vN=SKYNkHVGzo4Sws7??NfeqWv$2jV`|Vk>LA zO{Pa%)`kGYqv&Hy2-IZ-7nJzji>8m48A7cMmWx0PSj(N|Lq_dg6<<(}F9^|5L`H<= zHpHI<7(A2*K%F-r@d`nN9DMQrTfbx(2?UPFdYeE*Y*jz=l2aKxE1r|g91-Fr&2^KAxrNRa|Ro& zs%t@^OGzWQ!}T+vE!ryP>k>_iiD6`P2p|ede=iIOL!Phe-`S+mkN6;HO3nKPD_Js7 zJ*%9R%GKlAWcFpHvi}PCAczN*M}yXy1UG4;a_A*Bz}v6{yaN;z$1+Cn{f|*juR6I# zD6u(P7AUzWfI-;HxYs@gf zB}r|a5OG$6QO>lOXz`sjc})Nj;Pw@m&H?eW@#bMw#RK2k=5^)s8ii2eKuchY2f7N# z4L)!IjP!G1gu@9a(*wwPj$MDy`$e~{8>Y59$SJG7 zaxXOCs6D<_u{#?XY+`<^pAc&pc-i5WK#Q}b|dv& z@I&thf3@I!xp%hcbJP0xqcHMgB3sz6+bP0)==J^EVb{ZK9O3VPrUCGWk?q4Xpx%8u zo~YM%1Sk9yZUnHyhp&M90U+_5`$h`zMwf-v3l~7Wl{G|Fcc7qp^LfY91*b7EPzB)z zSb!)fE+m4zThFtNQtr75E^nnZ?^Vri&NZJcc)q+Xe6g8{36w1HktzEIlxo=q`Xo-i zQ?+@TH`}iz0D-|NjFyY*X?8 From 7cbb2eadad67044796e7b29c746909034aca597f Mon Sep 17 00:00:00 2001 From: Bill Mcilhargey <19168174+computeronix@users.noreply.github.com> Date: Sat, 9 Nov 2019 02:13:04 -0500 Subject: [PATCH 003/209] Update credential-guard-protection-limits.md Related to PR: https://github.com/MicrosoftDocs/windows-itpro-docs/pull/3789 Sorry for the delay, I have corrected the article to remove the video at the top and then at the bottom replace the video with the LinkedIn video relevant to this article. I also put a note and link to the LinkedIn Learning subscription that is needed. --- .../credential-guard/credential-guard-protection-limits.md | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/windows/security/identity-protection/credential-guard/credential-guard-protection-limits.md b/windows/security/identity-protection/credential-guard/credential-guard-protection-limits.md index bd6b456162..104cadf507 100644 --- a/windows/security/identity-protection/credential-guard/credential-guard-protection-limits.md +++ b/windows/security/identity-protection/credential-guard/credential-guard-protection-limits.md @@ -22,9 +22,6 @@ ms.reviewer: - Windows 10 - Windows Server 2016 -Prefer video? See [Credentials protected by Windows Defender Credential Guard](https://mva.microsoft.com/en-us/training-courses/deep-dive-into-credential-guard-16651?l=pdc37LJyC_1204300474) -in the Deep Dive into Windows Defender Credential Guard video series. - Some ways to store credentials are not protected by Windows Defender Credential Guard, including: - Software that manages credentials outside of Windows feature protection @@ -46,4 +43,6 @@ do not qualify as credentials because they cannot be presented to another comput **Deep Dive into Windows Defender Credential Guard: Related videos** -[Protecting privileged users with Windows Defender Credential Guard](https://mva.microsoft.com/en-us/training-courses/deep-dive-into-credential-guard-16651?l=JNbjYMJyC_8104300474) +[Microsoft Cybersecurity Stack: Advanced Identity and Endpoint Protection: Manage Credential Guard](https://www.linkedin.com/learning/microsoft-cybersecurity-stack-advanced-identity-and-endpoint-protection/manage-credential-guard?u=3322) +> [!NOTE] +> - Note: Requires [LinkedIn Learning subscription](https://www.linkedin.com/learning/subscription/products) to view the full video From 85b5baaf518047fb04ebf8a892d89276c7117cf1 Mon Sep 17 00:00:00 2001 From: illfated Date: Tue, 12 Nov 2019 01:41:37 +0100 Subject: [PATCH 004/209] MSDATP: merge Note into find-machines-by-ip.md Description: As discussed in issue ticket #5400 (included page "Improve request performance" title format & placement), I propose to merge the single Note stub from the file 'improve-request-performance.md' into the file 'find-machines-by-ip.md' and remove the linked include file. I have also added a few formatting improvements like MD quote indent marker compatibility spacing as well as replacing tabs with 4 spaces in the response code block and finally replacing tabs with single spaces in the Permissions table. Proposed changes: - move the MD Note down to directly after the request code block - replace the include link with the actual file content - change the MD heading format from H1 title size to H2 section heading - remove the include source file (redundant after including the Note) - replace all tabs with 4 spaces, for Github source view compatibility - reduce 4 spaces to single spaces in the Permissions table - add MD quote indent marker compatibility spacing to another Note issue ticket closure or reference: Closes #5400 --- .../find-machines-by-ip.md | 54 ++++++++++--------- .../improve-request-performance.md | 26 --------- 2 files changed, 30 insertions(+), 50 deletions(-) delete mode 100644 windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index 56e4cf24a6..d48ffeb2c4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -29,17 +29,17 @@ The given timestamp must be in the past 30 days. ## Permissions One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) -Permission type | Permission | Permission display name +Permission type | Permission | Permission display name :---|:---|:--- -Application | Machine.Read.All | 'Read all machine profiles' -Application | Machine.ReadWrite.All | 'Read and write all machine information' +Application | Machine.Read.All | 'Read all machine profiles' +Application | Machine.ReadWrite.All | 'Read and write all machine information' Delegated (work or school account) | Machine.Read | 'Read machine information' Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine information' ->[!Note] +> [!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ->- Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) +> - The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +> - Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` @@ -57,7 +57,7 @@ Empty ## Response If successful and machines were found - 200 OK with list of the machines in the response body. -If no machine found - 404 Not Found. +If no machine found - 404 Not Found. If the timestamp is not in the past 30 days - 400 Bad Request. ## Example @@ -66,12 +66,18 @@ If the timestamp is not in the past 30 days - 400 Bad Request. Here is an example of the request. -[!include[Improve request performance](improve-request-performance.md)] - ``` GET https://api.securitycenter.windows.com/api/machines/findbyip(ip='10.248.240.38',timestamp=2018-09-22T08:44:05Z) ``` +## Improve request performance + +> [!NOTE] +> You can use a server closer to your geolocation for better performance : +> - api-us.securitycenter.windows.com +> - api-eu.securitycenter.windows.com +> - api-uk.securitycenter.windows.com + **Response** Here is an example of the response. @@ -84,21 +90,21 @@ Content-type: application/json "value": [ { "id": "1e5bc9d7e413ddd7902c2932e418702b84d0cc07", - "computerDnsName": "mymachine1.contoso.com", - "firstSeen": "2018-08-02T14:55:03.7791856Z", - "lastSeen": "2018-09-22T08:55:03.7791856Z", - "osPlatform": "Windows10", - "osVersion": "10.0.0.0", - "lastIpAddress": "10.248.240.38", - "lastExternalIpAddress": "167.220.196.71", - "agentVersion": "10.5830.18209.1001", - "osBuild": 18209, - "healthStatus": "Active", - "rbacGroupId": 140, - "rbacGroupName": "The-A-Team", - "riskScore": "Low", - "aadDeviceId": "80fe8ff8-2624-418e-9591-41f0491218f9", - "machineTags": [ "test tag 1", "test tag 2" ] + "computerDnsName": "mymachine1.contoso.com", + "firstSeen": "2018-08-02T14:55:03.7791856Z", + "lastSeen": "2018-09-22T08:55:03.7791856Z", + "osPlatform": "Windows10", + "osVersion": "10.0.0.0", + "lastIpAddress": "10.248.240.38", + "lastExternalIpAddress": "167.220.196.71", + "agentVersion": "10.5830.18209.1001", + "osBuild": 18209, + "healthStatus": "Active", + "rbacGroupId": 140, + "rbacGroupName": "The-A-Team", + "riskScore": "Low", + "aadDeviceId": "80fe8ff8-2624-418e-9591-41f0491218f9", + "machineTags": [ "test tag 1", "test tag 2" ] } ] } diff --git a/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md b/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md deleted file mode 100644 index 880f5e4d11..0000000000 --- a/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: Improve request performance -description: Improve request performance -keywords: server, request, performance -search.product: eADQiWindows 10XVcnh -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: macapara -author: mjcaparas -ms.localizationpriority: medium -manager: dansimp -audience: ITPro -ms.collection: M365-security-compliance -ms.topic: article ---- - -# Improve request performance - - ->[!NOTE] ->For better performance, you can use server closer to your geo location: -> - api-us.securitycenter.windows.com -> - api-eu.securitycenter.windows.com -> - api-uk.securitycenter.windows.com \ No newline at end of file From e0747a05c12aeb98605c56aed2a3c3a3dc619f1b Mon Sep 17 00:00:00 2001 From: "Trond B. Krokli" <38162891+illfated@users.noreply.github.com> Date: Tue, 12 Nov 2019 16:11:15 +0100 Subject: [PATCH 005/209] Update windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md - remove 2 unneeded commas Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../microsoft-defender-atp/find-machines-by-ip.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index d48ffeb2c4..ce180e32f8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -39,7 +39,7 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine > [!Note] > When obtaining a token using user credentials: > - The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) -> - Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) +> - Response will include only machines that the user have access to based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` From 858925051c87407fe9d9be7211d4dfe6c4cf39cd Mon Sep 17 00:00:00 2001 From: "Trond B. Krokli" <38162891+illfated@users.noreply.github.com> Date: Tue, 12 Nov 2019 16:16:18 +0100 Subject: [PATCH 006/209] Update windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md - remove a redundant blank space Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../microsoft-defender-atp/find-machines-by-ip.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index ce180e32f8..da798752be 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -73,7 +73,7 @@ GET https://api.securitycenter.windows.com/api/machines/findbyip(ip='10.248.240. ## Improve request performance > [!NOTE] -> You can use a server closer to your geolocation for better performance : +> You can use a server closer to your geolocation for better performance: > - api-us.securitycenter.windows.com > - api-eu.securitycenter.windows.com > - api-uk.securitycenter.windows.com From f51a2ac3e7445df4842eabd2eb65db718f9f54cd Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Wed, 20 Nov 2019 17:09:24 +0500 Subject: [PATCH 007/209] Update hello-manage-in-organization.md --- .../hello-for-business/hello-manage-in-organization.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md index 6534a2b0bb..46cc476f37 100644 --- a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md +++ b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md @@ -36,7 +36,9 @@ You can create a Group Policy or mobile device management (MDM) policy that will The following table lists the Group Policy settings that you can configure for Windows Hello use in your workplace. These policy settings are available in both **User configuration** and **Computer Configuration** under **Policies** > **Administrative Templates** > **Windows Components** > **Windows Hello for Business**. - +>[!NOTE] +> Starting with Windows 10 1709, location of PIN complexity section of Group Policy is **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**. + From 4b832e9d86ec74bddb985b27b247dc421c89d552 Mon Sep 17 00:00:00 2001 From: Todd Lyon <19413953+tmlyon@users.noreply.github.com> Date: Thu, 21 Nov 2019 17:52:39 -0800 Subject: [PATCH 008/209] Update hololens2-start.md Added info about wifi button combo --- devices/hololens/hololens2-start.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/devices/hololens/hololens2-start.md b/devices/hololens/hololens2-start.md index 783a6af601..75a66d36cf 100644 --- a/devices/hololens/hololens2-start.md +++ b/devices/hololens/hololens2-start.md @@ -58,6 +58,8 @@ HoloLens 2 will walk you through the following steps: HoloLens sets your time zone automatically based on information obtained from the Wi-Fi network. After setup finishes, you can change the time zone by using the Settings app. ![Connect to Wi-Fi](images/11-network.png) +>[!NOTE] +> If you progress past the Wi-Fi step and later realize you need to switch to a different network, you can press the **Volume Down** and **Power** buttons simultaneously to return to this step if you are running an OS version from October 2019 or later. For earlier versions, you may need to restart the device in a location where the Wi-Fi network is not available. 1. Sign in to your user account. You'll choose between **My work or school owns it** and **I own it**. - When you choose **My work or school owns it**, you sign in with an Azure AD account. If your organization uses Azure AD Premium and has configured automatic MDM enrollment, HoloLens automatically enrolls in MDM. If your organization does not use Azure AD Premium, automatic MDM enrollment isn't available. In that case, you need to [manually enroll HoloLens in device management](hololens-enroll-mdm.md#enroll-through-settings-app). From 498a120131b124de00dea5355f30d0b73ad43dad Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 21 Nov 2019 18:40:13 -0800 Subject: [PATCH 009/209] Update manage-windows-1903-endpoints.md --- .../privacy/manage-windows-1903-endpoints.md | 56 ++++++++++++------- 1 file changed, 37 insertions(+), 19 deletions(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index 5400e152f2..8ee7a791a8 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -50,7 +50,9 @@ The following methodology was used to derive these network endpoints: |Area|Description|Protocol|Destination| |----------------|----------|----------|------------| -|Apps|The following endpoints are used to download updates to the Weather app Live Tile. If you turn off traffic to this endpoint, no Live Tiles will be updated.|HTTP|blob.weather.microsoft.com| +|Apps|Go here to learn how [to turn off traffic to all of the following endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +||The following endpoints are used to download updates to the Weather app Live Tile. If you turn off traffic to this endpoint, no Live Tiles will be updated.|HTTP|blob.weather.microsoft.com| +|||HTTP|tile-service.weather.microsoft.com |||HTTP|tile-service.weather.microsoft.com ||The following endpoint is used for OneNote Live Tile. To turn off traffic for this endpoint, either uninstall OneNote or disable the Microsoft Store. If you disable the Microsoft store, other Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.|HTTPS|cdn.onenote.net/livetile/?Language=en-US ||The following endpoint is used for Twitter updates. To turn off traffic for these endpoints, either uninstall Twitter or disable the Microsoft Store. If you disable the Microsoft store, other Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious Store apps and users will still be able to open them.|HTTPS|*.twimg.com*| @@ -65,8 +67,10 @@ The following methodology was used to derive these network endpoints: |Azure |The following endpoints are related to Azure. |HTTPS|wd-prod-*fe*.cloudapp.azure.com| |||HTTPS|ris-prod-atm.trafficmanager.net| |||HTTPS|validation-v2.sls.trafficmanager.net| -|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device.|HTTP|ctldl.windowsupdate.com| -|Cortana and Search|The following endpoint is used to get images that are used for Microsoft Store suggestions. If you turn off traffic for this endpoint, you will block images that are used for Microsoft Store suggestions. |HTTPS|store-images.*microsoft.com| +|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update)||| +|||HTTP|ctldl.windowsupdate.com| +|Cortana and Search| Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana)||| +||The following endpoint is used to get images that are used for Microsoft Store suggestions. If you turn off traffic for this endpoint, you will block images that are used for Microsoft Store suggestions.|HTTPS|store-images.*microsoft.com| ||The following endpoints are related to Cortana and Live Tiles. If you turn off traffic for this endpoint, you will block updates to Cortana greetings, tips, and Live Tiles.|HTTPS|www.bing.com/client| |||HTTPS|www.bing.com| |||HTTPS|www.bing.com/proactive| @@ -76,10 +80,12 @@ The following methodology was used to derive these network endpoints: |||HTTP|fp-vp.azureedge.net| |||HTTP|odinvzc.azureedge.net| |||HTTP|spo-ring.msedge.net| -|Device authentication| +|Device authentication|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| +|Device authentication|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)||| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| -|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft.|HTTP|v10.events.data.microsoft.com| +|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|||HTTP|v10.events.data.microsoft.com| |||HTTPS|v10.vortex-win.data.microsoft.com/collect/v1| |||HTTP|www.microsoft.com| ||The following endpoints are used by Windows Error Reporting. To turn off traffic for these endpoints, enable the following Group Policy: Administrative Templates > Windows Components > Windows Error Reporting > Disable Windows Error Reporting. This means error reporting information will not be sent back to Microsoft.|HTTPS|co4.telecommand.telemetry.microsoft.com| @@ -87,16 +93,21 @@ The following methodology was used to derive these network endpoints: |||HTTPS|cs1137.wpc.gammacdn.net| |||TLS v1.2|modern.watson.data.microsoft.com*| |||HTTPS|watson.telemetry.microsoft.com| -|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work.|HTTPS|*licensing.mp.microsoft.com*| -|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data.|HTTPS|inference.location.live.net| +|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager)||| +|||HTTPS|*licensing.mp.microsoft.com*| +|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| +|||HTTPS|inference.location.live.net| |||HTTP|location-inference-westus.cloudapp.net| -|Maps|The following endpoints are used to check for updates to maps that have been downloaded for offline use. If you turn off traffic for this endpoint, offline maps will not be updated.|HTTPS|*g.akamaiedge.net| +|Maps|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| +||The following endpoints are used to check for updates to maps that have been downloaded for offline use. If you turn off traffic for this endpoint, offline maps will not be updated.|HTTPS|*g.akamaiedge.net| |||HTTP|*maps.windows.com*| -|Microsoft Account|The following endpoints are used for Microsoft accounts to sign in. If you turn off traffic for these endpoints, users cannot sign in with Microsoft accounts. |HTTP|login.msa.akadns6.net| +|Microsoft Account|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account)||| +||The following endpoints are used for Microsoft accounts to sign in. If you turn off traffic for these endpoints, users cannot sign in with Microsoft accounts. |HTTP|login.msa.akadns6.net| |||HTTP|us.configsvc1.live.com.akadns.net| |Microsoft Edge|This traffic is related to the Microsoft Edge browser.|HTTPS|iecvlist.microsoft.com| |Microsoft forward link redirection service (FWLink)|The following endpoint is used by the Microsoft forward link redirection service (FWLink) to redirect permanent web links to their actual, sometimes transitory, URL. FWlinks are similar to URL shorteners, just longer. If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.|HTTPS|go.microsoft.com| -|Microsoft Store|The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| +|Microsoft Store|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)||| +||The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| ||The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft Store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTP|storecatalogrevocation.storequality.microsoft.com| ||The following endpoint is used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps). If you turn off traffic for these endpoints, the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|img-prod-cms-rt-microsoft-com*| |||HTTPS|store-images.microsoft.com| @@ -106,9 +117,10 @@ The following methodology was used to derive these network endpoints: |||HTTP|storeedgefd.dsx.mp.microsoft.com| |||HTTP|markets.books.microsoft.com| |||HTTP |share.microsoft.com| -|Network Connection Status Indicator (NCSI)| +|Network Connection Status Indicator (NCSI)|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi)||| ||Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. NCSI sends a DNS request and HTTP query to this endpoint to determine if the device can communicate with the Internet. If you turn off traffic for this endpoint, NCSI won't be able to determine if the device is connected to the Internet and the network status tray icon will show a warning.|HTTP|www.msftconnecttest.com*| -Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents.|HTTP|*.c-msedge.net| +|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|||HTTP|*.c-msedge.net| |||HTTPS|*.e-msedge.net| |||HTTPS|*.s-msedge.net| |||HTTPS|nexusrules.officeapps.live.com| @@ -120,29 +132,35 @@ Office|The following endpoints are used to connect to the Office 365 portal's sh |||HTTPS|onecollector.cloudapp.aria| |||HTTP|v10.events.data.microsoft.com/onecollector/1.0/| |||HTTPS|self.events.data.microsoft.com| -||The following endpoint is used to connect the Office To-Do app to its cloud service. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store.|HTTPS|to-do.microsoft.com -|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work.|HTTP \ HTTPS|g.live.com/1rewlive5skydrive/*| +||The following endpoint is used to connect the Office To-Do app to its cloud service. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store.|HTTPS|to-do.microsoft.com| +|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive)||| +|||HTTP \ HTTPS|g.live.com/1rewlive5skydrive/*| |||HTTP|msagfx.live.com| |||HTTPS|oneclient.sfx.ms| -|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working.|HTTPS|cy2.settings.data.microsoft.com.akadns.net| +|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|||HTTPS|cy2.settings.data.microsoft.com.akadns.net| |||HTTPS|settings.data.microsoft.com| |||HTTPS|settings-win.data.microsoft.com| -|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|browser.pipe.aria.microsoft.com| +|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|||HTTPS|browser.pipe.aria.microsoft.com| |||HTTP|config.edge.skype.com| |||HTTP|s2s.config.skype.com| |||HTTPS|skypeecs-prod-usw-0-b.cloudapp.net| -|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection.|HTTPS|wdcp.microsoft.com| +|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender)||| +|||HTTPS|wdcp.microsoft.com| |||HTTPS|definitionupdates.microsoft.com| |||HTTPS|go.microsoft.com| ||The following endpoints are used for Windows Defender Smartscreen reporting and notifications. If you turn off traffic for these endpoints, Smartscreen notifications will not appear.|HTTPS|*smartscreen.microsoft.com| |||HTTPS|smartscreen-sn3p.smartscreen.microsoft.com| |||HTTPS|unitedstates.smartscreen-prod.microsoft.com| -|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight.|TLS v1.2|*.search.msn.com| +|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)||| +|||TLS v1.2|*.search.msn.com| |||HTTPS|arc.msn.com| |||HTTPS|g.msn.com*| |||HTTPS|query.prod.cms.rt.microsoft.com| |||HTTPS|ris.api.iris.microsoft.com| -|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction.|HTTPS|*.prod.do.dsp.mp.microsoft.com| +|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates)||| +|||HTTPS|*.prod.do.dsp.mp.microsoft.com| |||HTTP|cs9.wac.phicdn.net| |||HTTP|emdl.ws.microsoft.com| ||The following endpoints are used to download operating system patches, updates, and apps from Microsoft Store. If you turn off traffic for these endpoints, the device will not be able to download updates for the operating system.|HTTP|*.dl.delivery.mp.microsoft.com| From cacf293c13842b4c01d9edf94a684d22a1c39f64 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Fri, 22 Nov 2019 09:49:11 +0500 Subject: [PATCH 010/209] Update windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- .../hello-for-business/hello-manage-in-organization.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md index 46cc476f37..aac728b71a 100644 --- a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md +++ b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md @@ -36,7 +36,7 @@ You can create a Group Policy or mobile device management (MDM) policy that will The following table lists the Group Policy settings that you can configure for Windows Hello use in your workplace. These policy settings are available in both **User configuration** and **Computer Configuration** under **Policies** > **Administrative Templates** > **Windows Components** > **Windows Hello for Business**. ->[!NOTE] +> [!NOTE] > Starting with Windows 10 1709, location of PIN complexity section of Group Policy is **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**.
Policy
@@ -322,4 +322,3 @@ If you want to use Windows Hello for Business with certificates, you’ll need a - [Windows Hello errors during PIN creation](hello-errors-during-pin-creation.md) - [Event ID 300 - Windows Hello successfully created](hello-event-300.md) - [Windows Hello biometrics in the enterprise](hello-biometrics-in-enterprise.md) - From 130aa381f0cbde46c35dc525b6f03cc08ac6727a Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Fri, 22 Nov 2019 09:49:28 +0500 Subject: [PATCH 011/209] Update windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- .../hello-for-business/hello-manage-in-organization.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md index aac728b71a..cdf919ebe0 100644 --- a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md +++ b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md @@ -37,7 +37,7 @@ You can create a Group Policy or mobile device management (MDM) policy that will The following table lists the Group Policy settings that you can configure for Windows Hello use in your workplace. These policy settings are available in both **User configuration** and **Computer Configuration** under **Policies** > **Administrative Templates** > **Windows Components** > **Windows Hello for Business**. > [!NOTE] -> Starting with Windows 10 1709, location of PIN complexity section of Group Policy is **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**. +> Starting with Windows 10 version 1709, the location of the PIN complexity section of Group Policy is: **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**.
From a513936feb68ec32666ca681a2768f4ab7d84643 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Fri, 22 Nov 2019 12:08:48 +0500 Subject: [PATCH 012/209] Update usmt-hard-link-migration-store.md --- windows/deployment/usmt/usmt-hard-link-migration-store.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/windows/deployment/usmt/usmt-hard-link-migration-store.md b/windows/deployment/usmt/usmt-hard-link-migration-store.md index 4b2d8385c2..d43c1fc21a 100644 --- a/windows/deployment/usmt/usmt-hard-link-migration-store.md +++ b/windows/deployment/usmt/usmt-hard-link-migration-store.md @@ -113,6 +113,9 @@ For example, a company has decided to deploy Windows 10 on all of their compute 3. An administrator runs the LoadState command-line tool on each computer. The LoadState tool restores user state back on each computer. +> [!NOTE] +> During the update of domain-joined computer, the profiles of the users which's SID cannot be resolved would not be migrated. In case of using Hard-Link Migration Store, it could cause the data lost. + ## Hard-Link Migration Store Details From 6f38acb6ebdb64ed4cf131c08b4a68e7586ef4c7 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 09:42:12 -0800 Subject: [PATCH 013/209] Update manage-windows-1903-endpoints.md --- .../privacy/manage-windows-1903-endpoints.md | 38 +++++++++---------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index 8ee7a791a8..ba79013f5e 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -50,7 +50,7 @@ The following methodology was used to derive these network endpoints: |Area|Description|Protocol|Destination| |----------------|----------|----------|------------| -|Apps|Go here to learn how [to turn off traffic to all of the following endpoints](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Apps|[Learn how to turn off traffic to the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| ||The following endpoints are used to download updates to the Weather app Live Tile. If you turn off traffic to this endpoint, no Live Tiles will be updated.|HTTP|blob.weather.microsoft.com| |||HTTP|tile-service.weather.microsoft.com |||HTTP|tile-service.weather.microsoft.com @@ -67,9 +67,9 @@ The following methodology was used to derive these network endpoints: |Azure |The following endpoints are related to Azure. |HTTPS|wd-prod-*fe*.cloudapp.azure.com| |||HTTPS|ris-prod-atm.trafficmanager.net| |||HTTPS|validation-v2.sls.trafficmanager.net| -|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update)||| +|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update)||| |||HTTP|ctldl.windowsupdate.com| -|Cortana and Search| Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana)||| +|Cortana and Search| [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana)||| ||The following endpoint is used to get images that are used for Microsoft Store suggestions. If you turn off traffic for this endpoint, you will block images that are used for Microsoft Store suggestions.|HTTPS|store-images.*microsoft.com| ||The following endpoints are related to Cortana and Live Tiles. If you turn off traffic for this endpoint, you will block updates to Cortana greetings, tips, and Live Tiles.|HTTPS|www.bing.com/client| |||HTTPS|www.bing.com| @@ -80,11 +80,11 @@ The following methodology was used to derive these network endpoints: |||HTTP|fp-vp.azureedge.net| |||HTTP|odinvzc.azureedge.net| |||HTTP|spo-ring.msedge.net| -|Device authentication|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Device authentication|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| -|Device authentication|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)||| +|Device authentication|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)||| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| -|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| |||HTTP|v10.events.data.microsoft.com| |||HTTPS|v10.vortex-win.data.microsoft.com/collect/v1| |||HTTP|www.microsoft.com| @@ -93,20 +93,20 @@ The following methodology was used to derive these network endpoints: |||HTTPS|cs1137.wpc.gammacdn.net| |||TLS v1.2|modern.watson.data.microsoft.com*| |||HTTPS|watson.telemetry.microsoft.com| -|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager)||| +|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager)||| |||HTTPS|*licensing.mp.microsoft.com*| -|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| +|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| |||HTTPS|inference.location.live.net| |||HTTP|location-inference-westus.cloudapp.net| -|Maps|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| +|Maps|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| ||The following endpoints are used to check for updates to maps that have been downloaded for offline use. If you turn off traffic for this endpoint, offline maps will not be updated.|HTTPS|*g.akamaiedge.net| |||HTTP|*maps.windows.com*| -|Microsoft Account|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account)||| +|Microsoft Account|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account)||| ||The following endpoints are used for Microsoft accounts to sign in. If you turn off traffic for these endpoints, users cannot sign in with Microsoft accounts. |HTTP|login.msa.akadns6.net| |||HTTP|us.configsvc1.live.com.akadns.net| |Microsoft Edge|This traffic is related to the Microsoft Edge browser.|HTTPS|iecvlist.microsoft.com| |Microsoft forward link redirection service (FWLink)|The following endpoint is used by the Microsoft forward link redirection service (FWLink) to redirect permanent web links to their actual, sometimes transitory, URL. FWlinks are similar to URL shorteners, just longer. If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.|HTTPS|go.microsoft.com| -|Microsoft Store|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)||| +|Microsoft Store|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)||| ||The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| ||The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft Store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTP|storecatalogrevocation.storequality.microsoft.com| ||The following endpoint is used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps). If you turn off traffic for these endpoints, the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|img-prod-cms-rt-microsoft-com*| @@ -117,9 +117,9 @@ The following methodology was used to derive these network endpoints: |||HTTP|storeedgefd.dsx.mp.microsoft.com| |||HTTP|markets.books.microsoft.com| |||HTTP |share.microsoft.com| -|Network Connection Status Indicator (NCSI)|Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi)||| +|Network Connection Status Indicator (NCSI)|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi)||| ||Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. NCSI sends a DNS request and HTTP query to this endpoint to determine if the device can communicate with the Internet. If you turn off traffic for this endpoint, NCSI won't be able to determine if the device is connected to the Internet and the network status tray icon will show a warning.|HTTP|www.msftconnecttest.com*| -|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| |||HTTP|*.c-msedge.net| |||HTTPS|*.e-msedge.net| |||HTTPS|*.s-msedge.net| @@ -133,33 +133,33 @@ The following methodology was used to derive these network endpoints: |||HTTP|v10.events.data.microsoft.com/onecollector/1.0/| |||HTTPS|self.events.data.microsoft.com| ||The following endpoint is used to connect the Office To-Do app to its cloud service. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store.|HTTPS|to-do.microsoft.com| -|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive)||| +|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive)||| |||HTTP \ HTTPS|g.live.com/1rewlive5skydrive/*| |||HTTP|msagfx.live.com| |||HTTPS|oneclient.sfx.ms| -|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| |||HTTPS|cy2.settings.data.microsoft.com.akadns.net| |||HTTPS|settings.data.microsoft.com| |||HTTPS|settings-win.data.microsoft.com| -|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| |||HTTPS|browser.pipe.aria.microsoft.com| |||HTTP|config.edge.skype.com| |||HTTP|s2s.config.skype.com| |||HTTPS|skypeecs-prod-usw-0-b.cloudapp.net| -|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender)||| +|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender)||| |||HTTPS|wdcp.microsoft.com| |||HTTPS|definitionupdates.microsoft.com| |||HTTPS|go.microsoft.com| ||The following endpoints are used for Windows Defender Smartscreen reporting and notifications. If you turn off traffic for these endpoints, Smartscreen notifications will not appear.|HTTPS|*smartscreen.microsoft.com| |||HTTPS|smartscreen-sn3p.smartscreen.microsoft.com| |||HTTPS|unitedstates.smartscreen-prod.microsoft.com| -|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)||| +|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)||| |||TLS v1.2|*.search.msn.com| |||HTTPS|arc.msn.com| |||HTTPS|g.msn.com*| |||HTTPS|query.prod.cms.rt.microsoft.com| |||HTTPS|ris.api.iris.microsoft.com| -|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. Go here to learn how [to turn off traffic to all of the following endpoint(s)](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates)||| +|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates)||| |||HTTPS|*.prod.do.dsp.mp.microsoft.com| |||HTTP|cs9.wac.phicdn.net| |||HTTP|emdl.ws.microsoft.com| From f1ac76f325a14c77e42e6fe31bd61dcfe2ecf74a Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 09:51:19 -0800 Subject: [PATCH 014/209] Update manage-windows-1903-endpoints.md --- .../privacy/manage-windows-1903-endpoints.md | 38 +++++++++---------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index ba79013f5e..662eebb597 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -50,7 +50,7 @@ The following methodology was used to derive these network endpoints: |Area|Description|Protocol|Destination| |----------------|----------|----------|------------| -|Apps|[Learn how to turn off traffic to the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Apps|||[Learn how to turn off traffic to the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)| ||The following endpoints are used to download updates to the Weather app Live Tile. If you turn off traffic to this endpoint, no Live Tiles will be updated.|HTTP|blob.weather.microsoft.com| |||HTTP|tile-service.weather.microsoft.com |||HTTP|tile-service.weather.microsoft.com @@ -67,9 +67,9 @@ The following methodology was used to derive these network endpoints: |Azure |The following endpoints are related to Azure. |HTTPS|wd-prod-*fe*.cloudapp.azure.com| |||HTTPS|ris-prod-atm.trafficmanager.net| |||HTTPS|validation-v2.sls.trafficmanager.net| -|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update)||| +|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update| |||HTTP|ctldl.windowsupdate.com| -|Cortana and Search| [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana)||| +|Cortana and Search| ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana| ||The following endpoint is used to get images that are used for Microsoft Store suggestions. If you turn off traffic for this endpoint, you will block images that are used for Microsoft Store suggestions.|HTTPS|store-images.*microsoft.com| ||The following endpoints are related to Cortana and Live Tiles. If you turn off traffic for this endpoint, you will block updates to Cortana greetings, tips, and Live Tiles.|HTTPS|www.bing.com/client| |||HTTPS|www.bing.com| @@ -80,11 +80,11 @@ The following methodology was used to derive these network endpoints: |||HTTP|fp-vp.azureedge.net| |||HTTP|odinvzc.azureedge.net| |||HTTP|spo-ring.msedge.net| -|Device authentication|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| -|Device authentication|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)||| +|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| -|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| |||HTTP|v10.events.data.microsoft.com| |||HTTPS|v10.vortex-win.data.microsoft.com/collect/v1| |||HTTP|www.microsoft.com| @@ -93,20 +93,20 @@ The following methodology was used to derive these network endpoints: |||HTTPS|cs1137.wpc.gammacdn.net| |||TLS v1.2|modern.watson.data.microsoft.com*| |||HTTPS|watson.telemetry.microsoft.com| -|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager)||| +|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager| |||HTTPS|*licensing.mp.microsoft.com*| -|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| +|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| |||HTTPS|inference.location.live.net| |||HTTP|location-inference-westus.cloudapp.net| -|Maps|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| +|Maps|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| ||The following endpoints are used to check for updates to maps that have been downloaded for offline use. If you turn off traffic for this endpoint, offline maps will not be updated.|HTTPS|*g.akamaiedge.net| |||HTTP|*maps.windows.com*| -|Microsoft Account|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account)||| +|Microsoft Account|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account| ||The following endpoints are used for Microsoft accounts to sign in. If you turn off traffic for these endpoints, users cannot sign in with Microsoft accounts. |HTTP|login.msa.akadns6.net| |||HTTP|us.configsvc1.live.com.akadns.net| |Microsoft Edge|This traffic is related to the Microsoft Edge browser.|HTTPS|iecvlist.microsoft.com| |Microsoft forward link redirection service (FWLink)|The following endpoint is used by the Microsoft forward link redirection service (FWLink) to redirect permanent web links to their actual, sometimes transitory, URL. FWlinks are similar to URL shorteners, just longer. If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.|HTTPS|go.microsoft.com| -|Microsoft Store|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)||| +|Microsoft Store|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles| ||The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| ||The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft Store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTP|storecatalogrevocation.storequality.microsoft.com| ||The following endpoint is used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps). If you turn off traffic for these endpoints, the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|img-prod-cms-rt-microsoft-com*| @@ -117,9 +117,9 @@ The following methodology was used to derive these network endpoints: |||HTTP|storeedgefd.dsx.mp.microsoft.com| |||HTTP|markets.books.microsoft.com| |||HTTP |share.microsoft.com| -|Network Connection Status Indicator (NCSI)|[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi)||| +|Network Connection Status Indicator (NCSI)|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi| ||Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. NCSI sends a DNS request and HTTP query to this endpoint to determine if the device can communicate with the Internet. If you turn off traffic for this endpoint, NCSI won't be able to determine if the device is connected to the Internet and the network status tray icon will show a warning.|HTTP|www.msftconnecttest.com*| -|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore| |||HTTP|*.c-msedge.net| |||HTTPS|*.e-msedge.net| |||HTTPS|*.s-msedge.net| @@ -133,33 +133,33 @@ The following methodology was used to derive these network endpoints: |||HTTP|v10.events.data.microsoft.com/onecollector/1.0/| |||HTTPS|self.events.data.microsoft.com| ||The following endpoint is used to connect the Office To-Do app to its cloud service. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store.|HTTPS|to-do.microsoft.com| -|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive)||| +|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive| |||HTTP \ HTTPS|g.live.com/1rewlive5skydrive/*| |||HTTP|msagfx.live.com| |||HTTPS|oneclient.sfx.ms| -|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)||| +|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| |||HTTPS|cy2.settings.data.microsoft.com.akadns.net| |||HTTPS|settings.data.microsoft.com| |||HTTPS|settings-win.data.microsoft.com| -|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)||| +|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore| |||HTTPS|browser.pipe.aria.microsoft.com| |||HTTP|config.edge.skype.com| |||HTTP|s2s.config.skype.com| |||HTTPS|skypeecs-prod-usw-0-b.cloudapp.net| -|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender)||| +|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender| |||HTTPS|wdcp.microsoft.com| |||HTTPS|definitionupdates.microsoft.com| |||HTTPS|go.microsoft.com| ||The following endpoints are used for Windows Defender Smartscreen reporting and notifications. If you turn off traffic for these endpoints, Smartscreen notifications will not appear.|HTTPS|*smartscreen.microsoft.com| |||HTTPS|smartscreen-sn3p.smartscreen.microsoft.com| |||HTTPS|unitedstates.smartscreen-prod.microsoft.com| -|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)||| +|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight| |||TLS v1.2|*.search.msn.com| |||HTTPS|arc.msn.com| |||HTTPS|g.msn.com*| |||HTTPS|query.prod.cms.rt.microsoft.com| |||HTTPS|ris.api.iris.microsoft.com| -|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. [Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates)||| +|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates| |||HTTPS|*.prod.do.dsp.mp.microsoft.com| |||HTTP|cs9.wac.phicdn.net| |||HTTP|emdl.ws.microsoft.com| From a407735e284c111fcea8ea4bc4953706535ade71 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 10:19:08 -0800 Subject: [PATCH 015/209] Update manage-windows-1903-endpoints.md --- .../privacy/manage-windows-1903-endpoints.md | 36 +++++++++---------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index 662eebb597..461229a474 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -67,9 +67,9 @@ The following methodology was used to derive these network endpoints: |Azure |The following endpoints are related to Azure. |HTTPS|wd-prod-*fe*.cloudapp.azure.com| |||HTTPS|ris-prod-atm.trafficmanager.net| |||HTTPS|validation-v2.sls.trafficmanager.net| -|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update| +|Certificates|The following endpoint is used by the Automatic Root Certificates Update component to automatically check the list of trusted authorities on Windows Update to see if an update is available. It is possible turn off traffic to this endpoint, but that is not recommended because when root certificates are updated over time, applications and websites may stop working because they did not receive an updated root certificate the application uses. Additionally, it is used to download certificates that are publicly known to be fraudulent. These settings are critical for both Windows security and the overall security of the Internet. We do not recommend blocking this endpoint. If traffic to this endpoint is turned off, Windows no longer automatically downloads certificates known to be fraudulent, which increases the attack vector on the device.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#automatic-root-certificates-update)| |||HTTP|ctldl.windowsupdate.com| -|Cortana and Search| ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana| +|Cortana and Search|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-cortana)| ||The following endpoint is used to get images that are used for Microsoft Store suggestions. If you turn off traffic for this endpoint, you will block images that are used for Microsoft Store suggestions.|HTTPS|store-images.*microsoft.com| ||The following endpoints are related to Cortana and Live Tiles. If you turn off traffic for this endpoint, you will block updates to Cortana greetings, tips, and Live Tiles.|HTTPS|www.bing.com/client| |||HTTPS|www.bing.com| @@ -80,11 +80,11 @@ The following methodology was used to derive these network endpoints: |||HTTP|fp-vp.azureedge.net| |||HTTP|odinvzc.azureedge.net| |||HTTP|spo-ring.msedge.net| -|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| +|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| -|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins| +|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| -|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| +|Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| |||HTTP|v10.events.data.microsoft.com| |||HTTPS|v10.vortex-win.data.microsoft.com/collect/v1| |||HTTP|www.microsoft.com| @@ -93,20 +93,20 @@ The following methodology was used to derive these network endpoints: |||HTTPS|cs1137.wpc.gammacdn.net| |||TLS v1.2|modern.watson.data.microsoft.com*| |||HTTPS|watson.telemetry.microsoft.com| -|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager| +|Licensing|The following endpoint is used for online activation and some app licensing. To turn off traffic for this endpoint, disable the Windows License Manager Service. This will also block online activation and app licensing may not work.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#9-license-manager)| |||HTTPS|*licensing.mp.microsoft.com*| -|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location).||| +|Location|The following endpoints are used for location data. If you turn off traffic for this endpoint, apps cannot use location data. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-location)| |||HTTPS|inference.location.live.net| |||HTTP|location-inference-westus.cloudapp.net| -|Maps|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps).||| +|Maps|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-offlinemaps)| ||The following endpoints are used to check for updates to maps that have been downloaded for offline use. If you turn off traffic for this endpoint, offline maps will not be updated.|HTTPS|*g.akamaiedge.net| |||HTTP|*maps.windows.com*| -|Microsoft Account|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account| +|Microsoft Account|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-microsoft-account)| ||The following endpoints are used for Microsoft accounts to sign in. If you turn off traffic for these endpoints, users cannot sign in with Microsoft accounts. |HTTP|login.msa.akadns6.net| |||HTTP|us.configsvc1.live.com.akadns.net| |Microsoft Edge|This traffic is related to the Microsoft Edge browser.|HTTPS|iecvlist.microsoft.com| |Microsoft forward link redirection service (FWLink)|The following endpoint is used by the Microsoft forward link redirection service (FWLink) to redirect permanent web links to their actual, sometimes transitory, URL. FWlinks are similar to URL shorteners, just longer. If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.|HTTPS|go.microsoft.com| -|Microsoft Store|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles| +|Microsoft Store|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)| ||The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| ||The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft Store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTP|storecatalogrevocation.storequality.microsoft.com| ||The following endpoint is used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps). If you turn off traffic for these endpoints, the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|img-prod-cms-rt-microsoft-com*| @@ -117,9 +117,9 @@ The following methodology was used to derive these network endpoints: |||HTTP|storeedgefd.dsx.mp.microsoft.com| |||HTTP|markets.books.microsoft.com| |||HTTP |share.microsoft.com| -|Network Connection Status Indicator (NCSI)|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi| +|Network Connection Status Indicator (NCSI)|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-ncsi)| ||Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. NCSI sends a DNS request and HTTP query to this endpoint to determine if the device can communicate with the Internet. If you turn off traffic for this endpoint, NCSI won't be able to determine if the device is connected to the Internet and the network status tray icon will show a warning.|HTTP|www.msftconnecttest.com*| -|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore| +|Office|The following endpoints are used to connect to the Office 365 portal's shared infrastructure, including Office in a browser. For more info, see Office 365 URLs and IP address ranges. You can turn this off by removing all Microsoft Office apps and the Mail and Calendar apps. If you turn off traffic for these endpoints, users won't be able to save documents to the cloud or see their recently used documents.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)| |||HTTP|*.c-msedge.net| |||HTTPS|*.e-msedge.net| |||HTTPS|*.s-msedge.net| @@ -133,33 +133,33 @@ The following methodology was used to derive these network endpoints: |||HTTP|v10.events.data.microsoft.com/onecollector/1.0/| |||HTTPS|self.events.data.microsoft.com| ||The following endpoint is used to connect the Office To-Do app to its cloud service. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store.|HTTPS|to-do.microsoft.com| -|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive| +|OneDrive|The following endpoints are related to OneDrive. If you turn off traffic for these endpoints, anything that relies on g.live.com to get updated URL information will no longer work.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-onedrive)| |||HTTP \ HTTPS|g.live.com/1rewlive5skydrive/*| |||HTTP|msagfx.live.com| |||HTTPS|oneclient.sfx.ms| -|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback| +|Settings|The following endpoint is used as a way for apps to dynamically update their configuration. Apps such as System Initiated User Feedback and the Xbox app use it. If you turn off traffic for this endpoint, an app that uses this endpoint may stop working.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| |||HTTPS|cy2.settings.data.microsoft.com.akadns.net| |||HTTPS|settings.data.microsoft.com| |||HTTPS|settings-win.data.microsoft.com| -|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore| +|Skype|The following endpoint is used to retrieve Skype configuration values. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-windowsstore)| |||HTTPS|browser.pipe.aria.microsoft.com| |||HTTP|config.edge.skype.com| |||HTTP|s2s.config.skype.com| |||HTTPS|skypeecs-prod-usw-0-b.cloudapp.net| -|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender| +|Windows Defender|The following endpoint is used for Windows Defender when Cloud-based Protection is enabled. If you turn off traffic for this endpoint, the device will not use Cloud-based Protection.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender)| |||HTTPS|wdcp.microsoft.com| |||HTTPS|definitionupdates.microsoft.com| |||HTTPS|go.microsoft.com| ||The following endpoints are used for Windows Defender Smartscreen reporting and notifications. If you turn off traffic for these endpoints, Smartscreen notifications will not appear.|HTTPS|*smartscreen.microsoft.com| |||HTTPS|smartscreen-sn3p.smartscreen.microsoft.com| |||HTTPS|unitedstates.smartscreen-prod.microsoft.com| -|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight| +|Windows Spotlight|The following endpoints are used to retrieve Windows Spotlight metadata that describes content, such as references to image locations, as well as suggested apps, Microsoft account notifications, and Windows tips. If you turn off traffic for these endpoints, Windows Spotlight will still try to deliver new lock screen images and updated content but it will fail; suggested apps, Microsoft account notifications, and Windows tips will not be downloaded. For more information, see Windows Spotlight.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-spotlight)| |||TLS v1.2|*.search.msn.com| |||HTTPS|arc.msn.com| |||HTTPS|g.msn.com*| |||HTTPS|query.prod.cms.rt.microsoft.com| |||HTTPS|ris.api.iris.microsoft.com| -|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates| +|Windows Update|The following endpoint is used for Windows Update downloads of apps and OS updates, including HTTP downloads or HTTP downloads blended with peers. If you turn off traffic for this endpoint, Windows Update downloads will not be managed, as critical metadata that is used to make downloads more resilient is blocked. Downloads may be impacted by corruption (resulting in re-downloads of full files). Additionally, downloads of the same update by multiple devices on the same local network will not use peer devices for bandwidth reduction.||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-updates)| |||HTTPS|*.prod.do.dsp.mp.microsoft.com| |||HTTP|cs9.wac.phicdn.net| |||HTTP|emdl.ws.microsoft.com| From dde0395fa9cd67d73835b5efef1c59f1977dda98 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 10:24:21 -0800 Subject: [PATCH 016/209] Update manage-windows-1903-endpoints.md --- windows/privacy/manage-windows-1903-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index 461229a474..aa3a146b44 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -82,7 +82,7 @@ The following methodology was used to derive these network endpoints: |||HTTP|spo-ring.msedge.net| |Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| -|Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)| +|Device metadata|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| |Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| |||HTTP|v10.events.data.microsoft.com| From 67a6f259d6829255c38c1008cc8d69d822f3a20e Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 10:40:09 -0800 Subject: [PATCH 017/209] Update manage-windows-1903-endpoints.md --- windows/privacy/manage-windows-1903-endpoints.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index aa3a146b44..bc9313582a 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -106,7 +106,7 @@ The following methodology was used to derive these network endpoints: |||HTTP|us.configsvc1.live.com.akadns.net| |Microsoft Edge|This traffic is related to the Microsoft Edge browser.|HTTPS|iecvlist.microsoft.com| |Microsoft forward link redirection service (FWLink)|The following endpoint is used by the Microsoft forward link redirection service (FWLink) to redirect permanent web links to their actual, sometimes transitory, URL. FWlinks are similar to URL shorteners, just longer. If you disable this endpoint, Windows Defender won't be able to update its malware definitions; links from Windows and other Microsoft products to the Web won't work; and PowerShell updateable Help won't update. To disable the traffic, instead disable the traffic that's getting forwarded.|HTTPS|go.microsoft.com| -|Microsoft Store|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#live-tiles)| +|Microsoft Store|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#26-microsoft-store)| ||The following endpoint is used for the Windows Push Notification Services (WNS). WNS enables third-party developers to send toast, tile, badge, and raw updates from their own cloud service. This provides a mechanism to deliver new updates to your users in a power-efficient and dependable way. If you turn off traffic for this endpoint, push notifications will no longer work, including MDM device management, mail synchronization, settings synchronization.|HTTPS|*.wns.windows.com| ||The following endpoint is used to revoke licenses for malicious apps in the Microsoft Store. To turn off traffic for this endpoint, either uninstall the app or disable the Microsoft Store. If you disable the Microsoft Store, other Microsoft Store apps cannot be installed or updated. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTP|storecatalogrevocation.storequality.microsoft.com| ||The following endpoint is used to download image files that are called when applications run (Microsoft Store or Inbox MSN Apps). If you turn off traffic for these endpoints, the image files won't be downloaded, and apps cannot be installed or updated from the Microsoft Store. Additionally, the Microsoft Store won't be able to revoke malicious apps and users will still be able to open them.|HTTPS|img-prod-cms-rt-microsoft-com*| @@ -169,7 +169,6 @@ The following methodology was used to derive these network endpoints: |||HTTPS|*.update.microsoft.com| ||The following endpoint is used for content regulation. If you turn off traffic for this endpoint, the Windows Update Agent will be unable to contact the endpoint and fallback behavior will be used. This may result in content being either incorrectly.|HTTPS|tsfe.trafficshaping.dsp.mp.microsoft.com| - ## Other Windows 10 editions To view endpoints for other versions of Windows 10 Enterprise, see: From c3d0e1b9c0ed12f8dee223fc4ee6451d68718054 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 22 Nov 2019 12:16:05 -0800 Subject: [PATCH 018/209] Update manage-windows-1903-endpoints.md --- windows/privacy/manage-windows-1903-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1903-endpoints.md b/windows/privacy/manage-windows-1903-endpoints.md index bc9313582a..8ab956bb45 100644 --- a/windows/privacy/manage-windows-1903-endpoints.md +++ b/windows/privacy/manage-windows-1903-endpoints.md @@ -82,7 +82,7 @@ The following methodology was used to derive these network endpoints: |||HTTP|spo-ring.msedge.net| |Device authentication|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| ||The following endpoint is used to authenticate a device. If you turn off traffic for this endpoint, the device will not be authenticated.|HTTPS|login.live.com*| -|Device metadata|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-devins)| +|Device metadata|||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#4-device-metadata-retrieval)| ||The following endpoint is used to retrieve device metadata. If you turn off traffic for this endpoint, metadata will not be updated for the device.|HTTP|dmd.metaservices.microsoft.com| |Diagnostic Data|The following endpoints are used by the Connected User Experiences and Telemetry component and connects to the Microsoft Data Management service. If you turn off traffic for this endpoint, diagnostic and usage information, which helps Microsoft find and fix problems and improve our products and services, will not be sent back to Microsoft. ||[Learn how to turn off traffic to all of the following endpoint(s).](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-priv-feedback)| |||HTTP|v10.events.data.microsoft.com| From 4296f19ff9afd30d8d8720e17df65a3d3170e70a Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Sun, 24 Nov 2019 01:57:37 +0500 Subject: [PATCH 019/209] Update windows/deployment/usmt/usmt-hard-link-migration-store.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- windows/deployment/usmt/usmt-hard-link-migration-store.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/deployment/usmt/usmt-hard-link-migration-store.md b/windows/deployment/usmt/usmt-hard-link-migration-store.md index d43c1fc21a..e9bb2376d5 100644 --- a/windows/deployment/usmt/usmt-hard-link-migration-store.md +++ b/windows/deployment/usmt/usmt-hard-link-migration-store.md @@ -114,7 +114,7 @@ For example, a company has decided to deploy Windows 10 on all of their compute 3. An administrator runs the LoadState command-line tool on each computer. The LoadState tool restores user state back on each computer. > [!NOTE] -> During the update of domain-joined computer, the profiles of the users which's SID cannot be resolved would not be migrated. In case of using Hard-Link Migration Store, it could cause the data lost. +> During the update of a domain-joined computer, the profiles of users whose SID cannot be resolved will not be migrated. When using a hard-link migration store, it could cause a data loss. ## Hard-Link Migration Store Details @@ -236,4 +236,3 @@ The following XML sample specifies that files locked by an application under the - From f63267045cb77c9cfff90647864a3672e82c354b Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Sun, 24 Nov 2019 01:58:28 +0500 Subject: [PATCH 020/209] Update windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../hello-for-business/hello-manage-in-organization.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md index cdf919ebe0..c9213a887f 100644 --- a/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md +++ b/windows/security/identity-protection/hello-for-business/hello-manage-in-organization.md @@ -37,7 +37,7 @@ You can create a Group Policy or mobile device management (MDM) policy that will The following table lists the Group Policy settings that you can configure for Windows Hello use in your workplace. These policy settings are available in both **User configuration** and **Computer Configuration** under **Policies** > **Administrative Templates** > **Windows Components** > **Windows Hello for Business**. > [!NOTE] -> Starting with Windows 10 version 1709, the location of the PIN complexity section of Group Policy is: **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**. +> Starting with Windows 10, version 1709, the location of the PIN complexity section of the Group Policy is: **Computer Configuration** > **Administrative Templates** > **System** > **PIN Complexity**.
From 72da0abd5827293ba365c3c18637eaeedc6975fd Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Mon, 25 Nov 2019 10:47:39 +0500 Subject: [PATCH 021/209] Update waas-servicing-differences.md --- windows/deployment/update/waas-servicing-differences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/update/waas-servicing-differences.md b/windows/deployment/update/waas-servicing-differences.md index 6a9df9bd4f..80c0b30b04 100644 --- a/windows/deployment/update/waas-servicing-differences.md +++ b/windows/deployment/update/waas-servicing-differences.md @@ -39,7 +39,7 @@ Windows 10 provided an opportunity to end the era of infinite fragmentation. Wit This helps simplify servicing. Devices with the original Release to Market (RTM) version of a feature release installed could get up to date by installing the most recent LCU. -Windows publishes the new LCU packages for each Windows 10 version (1607, 1709, etc.) on the second Tuesday of each month. This package is classified as a required security update and contains contents from the previous LCU as well as new security, non-security and Internet Explorer 11 (IE11) fixes. The security classification, by definition, requires a reboot of the device to complete installation of the update. +Windows publishes the new LCU packages for each Windows 10 version (1607, 1709, etc.) on the second Tuesday of each month. This package is classified as a required security update and contains contents from the previous LCU as well as new security, non-security and Internet Explorer 11 (IE11) fixes. It could require a reboot of the device to complete installation of the update. ![High level cumulative update model](images/servicing-cadence.png) From 74721fd97dfd3aa01f72f857ec465cf23ff247a8 Mon Sep 17 00:00:00 2001 From: VLG17 <41186174+VLG17@users.noreply.github.com> Date: Wed, 27 Nov 2019 10:16:38 +0200 Subject: [PATCH 022/209] update path https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5412 --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index ef6d2bf3ee..b48d74e7ce 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -1413,7 +1413,7 @@ To turn off Inking & Typing data collection (note: there is no Group Policy for -or- -- Set **RestrictImplicitTextCollection** registry REG_DWORD setting in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\InputPersonalization** to a **value of 1 (one)** +- Set **RestrictImplicitTextCollection** registry REG_DWORD setting in **HKEY_CURRENT_USER\\Software\\Microsoft\\InputPersonalization** to a **value of 1 (one)** ### 18.22 Activity History From 70aeb0c58ffe67691556feb30e6d01466ba7ed4d Mon Sep 17 00:00:00 2001 From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com> Date: Wed, 27 Nov 2019 15:06:21 +0530 Subject: [PATCH 023/209] made bold in sentence as per user issue #5529 I created this PR --- windows/client-management/mandatory-user-profile.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/client-management/mandatory-user-profile.md b/windows/client-management/mandatory-user-profile.md index b2e9438fba..9d7b5546ff 100644 --- a/windows/client-management/mandatory-user-profile.md +++ b/windows/client-management/mandatory-user-profile.md @@ -31,6 +31,7 @@ When the server that stores the mandatory profile is unavailable, such as when t User profiles become mandatory profiles when the administrator renames the NTuser.dat file (the registry hive) of each user's profile in the file system of the profile server from `NTuser.dat` to `NTuser.man`. The `.man` extension causes the user profile to be a read-only profile. + ## Profile extension for each Windows version The name of the folder in which you store the mandatory profile must use the correct extension for the operating system it will be applied to. The following table lists the correct extension for each operating system version. From 77de958be555c779c29a44b8338754759ca275cf Mon Sep 17 00:00:00 2001 From: davguent <53222866+davguent@users.noreply.github.com> Date: Wed, 27 Nov 2019 10:43:16 -0500 Subject: [PATCH 024/209] Update hello-hybrid-cert-whfb-settings-pki.md Command line should contain spaces as delimiter not commas. --- .../hello-for-business/hello-hybrid-cert-whfb-settings-pki.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-pki.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-pki.md index 9a5ce9f830..7c4e019e6d 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-pki.md @@ -151,7 +151,7 @@ Sign-in a certificate authority or management workstations with _Domain Admin eq Sign-in to an **AD FS Windows Server 2016** computer with _Enterprise Admin_ equivalent credentials. 1. Open an elevated command prompt. -2. Run `certutil -dsTemplate WHFBAuthentication,msPKI-Private-Key-Flag,+CTPRIVATEKEY_FLAG_HELLO_LOGON_KEY` +2. Run `certutil -dsTemplate WHFBAuthentication msPKI-Private-Key-Flag +CTPRIVATEKEY_FLAG_HELLO_LOGON_KEY` > [!NOTE] > If you gave your Windows Hello for Business Authentication certificate template a different name, then replace **WHFBAuthentication** in the above command with the name of your certificate template. It's important that you use the template name rather than the template display name. You can view the template name on the **General** tab of the certificate template using the Certificate Template management console (certtmpl.msc). Or, you can view the template name using the **Get-CATemplate** ADCS Administration Windows PowerShell cmdlet on our Windows Server 2012 or later certificate authority. From d83fceffe3ac11b846d82b69a215f77f845c778d Mon Sep 17 00:00:00 2001 From: Gergely Szabo Date: Thu, 28 Nov 2019 11:54:32 +0100 Subject: [PATCH 025/209] lockeout -> lockout typo fix --- .../security-policy-settings/account-lockout-threshold.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/security-policy-settings/account-lockout-threshold.md b/windows/security/threat-protection/security-policy-settings/account-lockout-threshold.md index e751b8d90d..3db828212a 100644 --- a/windows/security/threat-protection/security-policy-settings/account-lockout-threshold.md +++ b/windows/security/threat-protection/security-policy-settings/account-lockout-threshold.md @@ -45,7 +45,7 @@ Because vulnerabilities can exist when this value is configured and when it is n The threshold that you select is a balance between operational efficiency and security, and it depends on your organization's risk level. To allow for user error and to thwart brute force attacks, [Windows security baselines](https://docs.microsoft.com/windows/security/threat-protection/windows-security-baselines) recommend a value of 10 could be an acceptable starting point for your organization. -As with other account lockeout settings, this value is more of a guideline than a rule or best practice because there is no "one size fits all." For more information, see [Configuring Account Lockout](https://blogs.technet.microsoft.com/secguide/2014/08/13/configuring-account-lockout/). +As with other account lockout settings, this value is more of a guideline than a rule or best practice because there is no "one size fits all." For more information, see [Configuring Account Lockout](https://blogs.technet.microsoft.com/secguide/2014/08/13/configuring-account-lockout/). Implementation of this policy setting is dependent on your operational environment; threat vectors, deployed operating systems, and deployed apps. For more information, see [Implementation considerations](#bkmk-impleconsiderations) in this topic. From f50e5fcacfcc54359358cf88d553ac55eca7ef93 Mon Sep 17 00:00:00 2001 From: HumanEquivalentUnit Date: Fri, 29 Nov 2019 09:41:45 +0000 Subject: [PATCH 026/209] Typo fix: "better then" -> "better than" --- windows/whats-new/whats-new-windows-10-version-1909.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1909.md b/windows/whats-new/whats-new-windows-10-version-1909.md index 6bba048ef0..a9384caf8b 100644 --- a/windows/whats-new/whats-new-windows-10-version-1909.md +++ b/windows/whats-new/whats-new-windows-10-version-1909.md @@ -116,7 +116,7 @@ This release adds the ability for Narrator and other assistive technologies to r This version of Windows 10 will include optimizations to how instructions are processed by the CPU in order to increase the performance and reliability of the operating system and its applications. -When a CPU is manufactured, not all of the cores are created equal. Some of the cores may have slightly different voltage and power characteristics that could allow them to get a "boost" in performance. These cores are called "favored cores" as they can offer better performance then the other cores on the die. +When a CPU is manufactured, not all of the cores are created equal. Some of the cores may have slightly different voltage and power characteristics that could allow them to get a "boost" in performance. These cores are called "favored cores" as they can offer better performance than the other cores on the die. With Intel Turbo Boost Max Technology 3.0, an operating system will use information stored in the CPU to identify which cores are the fastest and then push more of the CPU intensive tasks to those cores. According to Intel, this technology "delivers more than 15% better single-threaded performance". @@ -139,4 +139,4 @@ General battery life and power efficiency improvements for PCs with certain proc [Windows 10 features we’re no longer developing](https://docs.microsoft.com/windows/deployment/planning/windows-10-deprecated-features): Features that are not being developed.
[How to get the Windows 10 November 2019 Update](https://aka.ms/how-to-get-1909): John Cable blog.
[How to get Windows 10, Version 1909: Enablement Mechanics](https://aka.ms/1909mechanics): Mechanics blog.
-[What’s new for IT pros in Windows 10, version 1909](https://aka.ms/whats-new-in-1909): Windows IT Pro blog.
\ No newline at end of file +[What’s new for IT pros in Windows 10, version 1909](https://aka.ms/whats-new-in-1909): Windows IT Pro blog.
From 0434681a07ecfdd00227117f05ec6b556c5ed68d Mon Sep 17 00:00:00 2001 From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com> Date: Fri, 29 Nov 2019 21:21:50 +0530 Subject: [PATCH 027/209] wrong link is replaced by new link as per user report issue #5552. i replaced the old link by new link old link https://go.microsoft.com/fwlink/?LinkId=99934 replaced link https://docs.microsoft.com/en-in/windows-hardware/drivers/debugger/ added important note under Related topics --- .../dart-v10/planning-to-create-the-dart-10-recovery-image.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md index 6346265cf1..3f2619f988 100644 --- a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md +++ b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md @@ -49,7 +49,7 @@ The following items are required or recommended for creating the DaRT recovery i
- + @@ -61,7 +61,7 @@ The following items are required or recommended for creating the DaRT recovery i ## Related topics - +Note :: Debugging tools in not available for seperate download,Instead you must download Windows Driver Kit (WDK) [Planning to Deploy DaRT 10](planning-to-deploy-dart-10.md) From f3fa4e201e35fe1d13af6ccd1bbe947c0947502b Mon Sep 17 00:00:00 2001 From: Jose Ortega Date: Sat, 30 Nov 2019 03:31:40 -0600 Subject: [PATCH 028/209] Added important note #5453 --- .../system-guard-secure-launch-and-smm-protection.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md index be6c791392..17066961d5 100644 --- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md +++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md @@ -54,6 +54,9 @@ Click **Start** > **Settings** > **Update & Security** > **Windows Security** > ![Secure Launch Registry](images/secure-launch-registry.png) +> [!IMPORTANT] +> If the system guard enabled as a registry key, then standard hardware security is not available for Intel i5 7200U processor". + ## How to verify System Guard Secure Launch is configured and running To verify that Secure Launch is running, use System Information (MSInfo32). Click **Start**, search for **System Information**, and look under **Virtualization-based Security Services Running** and **Virtualization-based Security Services Configured**. From 0323a601ba7131a9bde7a2a88bf2f66cafb39646 Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Sat, 30 Nov 2019 11:37:06 -0600 Subject: [PATCH 029/209] Update windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../system-guard-secure-launch-and-smm-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md index 17066961d5..7f4a831eaa 100644 --- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md +++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md @@ -55,7 +55,7 @@ Click **Start** > **Settings** > **Update & Security** > **Windows Security** > ![Secure Launch Registry](images/secure-launch-registry.png) > [!IMPORTANT] -> If the system guard enabled as a registry key, then standard hardware security is not available for Intel i5 7200U processor". +> If the system guard is enabled as a registry key, then standard hardware security is not available for the Intel i5 7200U processor. ## How to verify System Guard Secure Launch is configured and running From 27ea0b002544bed64a1e83d5dbdf4b717312e000 Mon Sep 17 00:00:00 2001 From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com> Date: Mon, 2 Dec 2019 17:41:07 +0530 Subject: [PATCH 030/209] Update mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md Thanks for correction Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md index 3f2619f988..494b6c080a 100644 --- a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md +++ b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md @@ -61,7 +61,6 @@ The following items are required or recommended for creating the DaRT recovery i ## Related topics -Note :: Debugging tools in not available for seperate download,Instead you must download Windows Driver Kit (WDK) [Planning to Deploy DaRT 10](planning-to-deploy-dart-10.md) @@ -72,4 +71,3 @@ Note :: Debugging tools in not available for seperate download,Instead you must - From ce2efcad49d191fc17ccb8789d4fbd2e640406c7 Mon Sep 17 00:00:00 2001 From: Baard Hermansen Date: Mon, 2 Dec 2019 18:32:37 +0100 Subject: [PATCH 031/209] Update bitlocker-management-for-enterprises.md Updated several URLs. Updated code blocks with syntax for PowerShell. --- .../bitlocker-management-for-enterprises.md | 75 +++++++++---------- 1 file changed, 35 insertions(+), 40 deletions(-) diff --git a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md index 08e059935f..242d5a9908 100644 --- a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md +++ b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md @@ -23,22 +23,22 @@ The ideal for BitLocker management is to eliminate the need for IT admins to set Though much Windows BitLocker [documentation](bitlocker-overview.md) has been published, customers frequently ask for recommendations and pointers to specific, task-oriented documentation that is both easy to digest and focused on how to deploy and manage BitLocker. This article links to relevant documentation, products, and services to help answer this and other related frequently-asked questions, and also provides BitLocker recommendations for different types of computers. ->[!IMPORTANT] -> Microsoft BitLocker Administration and Monitoring (MBAM) capabilities will be offered from [SCCM in on-prem scenarios](https://docs.microsoft.com/microsoft-desktop-optimization-pack/mbam-v25/viewing-mbam-25-reports-for-the-configuration-manager-integration-topology) in the future. +> [!IMPORTANT] +> Microsoft BitLocker Administration and Monitoring (MBAM) capabilities will be offered from [ConfigMgr in on-prem scenarios](https://docs.microsoft.com/en-us/configmgr/core/get-started/2019/technical-preview-1909#bkmk_bitlocker/) in the future. ## Managing domain-joined computers and moving to cloud -Companies that image their own computers using Microsoft System Center 2012 Configuration Manager SP1 (SCCM) or later can use an existing task sequence to [pre-provision BitLocker](https://technet.microsoft.com/library/hh846237.aspx#BKMK_PreProvisionBitLocker) encryption while in Windows Preinstallation Environment (WinPE) and can then [enable protection](https://technet.microsoft.com/library/hh846237.aspx#BKMK_EnableBitLocker). This can help ensure that computers are encrypted from the start, even before users receive them. As part of the imaging process, a company could also decide to use SCCM to pre-set any desired [BitLocker Group Policy](https://technet.microsoft.com/library/ee706521(v=ws.10).aspx). +Companies that image their own computers using Microsoft System Center 2012 Configuration Manager SP1 (SCCM) or later can use an existing task sequence to [pre-provision BitLocker](https://docs.microsoft.com/configmgr/osd/understand/task-sequence-steps#BKMK_PreProvisionBitLocker) encryption while in Windows Preinstallation Environment (WinPE) and can then [enable protection](https://docs.microsoft.com/configmgr/osd/understand/task-sequence-steps#BKMK_EnableBitLocker). This can help ensure that computers are encrypted from the start, even before users receive them. As part of the imaging process, a company could also decide to use SCCM to pre-set any desired [BitLocker Group Policy](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings/). -Enterprises can use [Microsoft BitLocker Administration and Monitoring (MBAM)](https://docs.microsoft.com/microsoft-desktop-optimization-pack/mbam-v25/) to manage client computers with BitLocker that are domain-joined on-premises until [mainstream support ends in July 2019](https://support.microsoft.com/lifecycle/search?alpha=Microsoft%20BitLocker%20Administration%20and%20Monitoring%202.5%20Service%20Pack%201) or they can receive extended support until July 2024. Thus, over the next few years, a good strategy for enterprises will be to plan and move to cloud-based management for BitLocker. Refer to the [PowerShell examples](#powershell-examples) to see how to store recovery keys in Azure Active Directory (Azure AD). +Enterprises can use [Microsoft BitLocker Administration and Monitoring (MBAM)](https://docs.microsoft.com/microsoft-desktop-optimization-pack/mbam-v25/) to manage client computers with BitLocker that are domain-joined on-premises until [mainstream support ends in July 2019](https://support.microsoft.com/lifecycle/search?alpha=Microsoft%20BitLocker%20Administration%20and%20Monitoring%202.5%20Service%20Pack%201/) or they can receive extended support until April 2026. Thus, over the next few years, a good strategy for enterprises will be to plan and move to cloud-based management for BitLocker. Refer to the [PowerShell examples](#powershell-examples) to see how to store recovery keys in Azure Active Directory (Azure AD). ## Managing devices joined to Azure Active Directory -Devices joined to Azure AD are managed using Mobile Device Management (MDM) policy from an MDM solution such as Microsoft Intune. Without Windows 10, version 1809, only local administrators can enable BitLocker via Intune policy. Starting with Windows 10, version 1809, Intune can enable BitLocker for standard users. [BitLocker Device Encryption](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) status can be queried from managed machines via the [Policy Configuration Settings Provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider), which reports on whether BitLocker Device Encryption is enabled on the device. Compliance with BitLocker Device Encryption policy can be a requirement for [Conditional Access](https://www.microsoft.com/cloud-platform/conditional-access) to services like Exchange Online and SharePoint Online. +Devices joined to Azure AD are managed using Mobile Device Management (MDM) policy from an MDM solution such as Microsoft Intune. Without Windows 10, version 1809, only local administrators can enable BitLocker via Intune policy. Starting with Windows 10, version 1809, Intune can enable BitLocker for standard users. [BitLocker Device Encryption](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) status can be queried from managed machines via the [Policy Configuration Settings Provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider/), which reports on whether BitLocker Device Encryption is enabled on the device. Compliance with BitLocker Device Encryption policy can be a requirement for [Conditional Access](https://www.microsoft.com/cloud-platform/conditional-access/) to services like Exchange Online and SharePoint Online. -Starting with Windows 10 version 1703 (also known as the Windows Creators Update), the enablement of BitLocker can be triggered over MDM either by the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider) or the [BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp). The BitLocker CSP adds policy options that go beyond ensuring that encryption has occurred, and is available on computers that run Windows 10 and on Windows phones. +Starting with Windows 10 version 1703 (also known as the Windows Creators Update), the enablement of BitLocker can be triggered over MDM either by the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider/) or the [BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp/). The BitLocker CSP adds policy options that go beyond ensuring that encryption has occurred, and is available on computers that run Windows 10 and on Windows phones. -For hardware that is compliant with Modern Standby and HSTI, when using either of these features, [BitLocker Device Encryption](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) is automatically turned on whenever the user joins a device to Azure AD. Azure AD provides a portal where recovery keys are also backed up, so users can retrieve their own recovery key for self-service, if required. For older devices that are not yet encrypted, beginning with Windows 10 version 1703 (the Windows 10 Creators Update), admins can use the [BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp) to trigger encryption and store the recovery key in Azure AD. +For hardware that is compliant with Modern Standby and HSTI, when using either of these features, [BitLocker Device Encryption](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) is automatically turned on whenever the user joins a device to Azure AD. Azure AD provides a portal where recovery keys are also backed up, so users can retrieve their own recovery key for self-service, if required. For older devices that are not yet encrypted, beginning with Windows 10 version 1703 (the Windows 10 Creators Update), admins can use the [BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp/) to trigger encryption and store the recovery key in Azure AD. This is applicable to Azure Hybrid AD as well. @@ -52,9 +52,9 @@ For Windows PCs and Windows Phones that enroll using **Connect to work or school Servers are often installed, configured, and deployed using PowerShell, so the recommendation is to also use [PowerShell to enable BitLocker on a server](bitlocker-use-bitlocker-drive-encryption-tools-to-manage-bitlocker.md#bitlocker-cmdlets-for-windows-powershell), ideally as part of the initial setup. BitLocker is an Optional Component (OC) in Windows Server, so follow the directions in [BitLocker: How to deploy on Windows Server 2012 and later](bitlocker-how-to-deploy-on-windows-server.md) to add the BitLocker OC. -The Minimal Server Interface is a prerequisite for some of the BitLocker administration tools. On a [Server Core](https://docs.microsoft.com/windows-server/get-started/getting-started-with-server-core) installation, you must add the necessary GUI components first. The steps to add shell components to Server Core are described in [Using Features on Demand with Updated Systems and Patched Images](https://blogs.technet.microsoft.com/server_core/2012/11/05/using-features-on-demand-with-updated-systems-and-patched-images/) and [How to update local source media to add roles and features](https://blogs.technet.microsoft.com/joscon/2012/11/14/how-to-update-local-source-media-to-add-roles-and-features/). +The Minimal Server Interface is a prerequisite for some of the BitLocker administration tools. On a [Server Core](https://docs.microsoft.com/windows-server/get-started/getting-started-with-server-core/) installation, you must add the necessary GUI components first. The steps to add shell components to Server Core are described in [Using Features on Demand with Updated Systems and Patched Images](https://blogs.technet.microsoft.com/server_core/2012/11/05/using-features-on-demand-with-updated-systems-and-patched-images/) and [How to update local source media to add roles and features](https://blogs.technet.microsoft.com/joscon/2012/11/14/how-to-update-local-source-media-to-add-roles-and-features/). -If you are installing a server manually, such as a stand-alone server, then choosing [Server with Desktop Experience](https://docs.microsoft.com/windows-server/get-started/getting-started-with-server-with-desktop-experience) is the easiest path because you can avoid performing the steps to add a GUI to Server Core. +If you are installing a server manually, such as a stand-alone server, then choosing [Server with Desktop Experience](https://docs.microsoft.com/windows-server/get-started/getting-started-with-server-with-desktop-experience/) is the easiest path because you can avoid performing the steps to add a GUI to Server Core. Additionally, lights out data centers can take advantage of the enhanced security of a second factor while avoiding the need for user intervention during reboots by optionally using a combination of BitLocker (TPM+PIN) and BitLocker Network Unlock. BitLocker Network Unlock brings together the best of hardware protection, location dependence, and automatic unlock, while in the trusted location. For the configuration steps, see [BitLocker: How to enable Network Unlock](bitlocker-how-to-enable-network-unlock.md). @@ -65,64 +65,60 @@ If you are installing a server manually, such as a stand-alone server, then choo For Azure AD-joined computers, including virtual machines, the recovery password should be stored in Azure Active Directory. *Example: Use PowerShell to add a recovery password and back it up to Azure AD before enabling BitLocker* -``` -PS C:\>Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector +```powershell +Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector -PS C:\>$BLV = Get-BitLockerVolume -MountPoint "C:" +$BLV = Get-BitLockerVolume -MountPoint "C:" + +BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[0].KeyProtectorId +``` -PS C:\>BackupToAAD-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[0].KeyProtectorId -``` For domain-joined computers, including servers, the recovery password should be stored in Active Directory Domain Services (AD DS). *Example: Use PowerShell to add a recovery password and back it up to AD DS before enabling BitLocker* -``` -PS C:\>Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector +```powershell +Add-BitLockerKeyProtector -MountPoint "C:" -RecoveryPasswordProtector -PS C:\>$BLV = Get-BitLockerVolume -MountPoint "C:" +$BLV = Get-BitLockerVolume -MountPoint "C:" -PS C:\>Backup-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[0].KeyProtectorId - ``` +Backup-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[0].KeyProtectorId +``` Subsequently, you can use PowerShell to enable BitLocker. *Example: Use PowerShell to enable BitLocker with a TPM protector* - ``` -PS C:\>Enable-BitLocker -MountPoint "D:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -TpmProtector - ``` -*Example: Use PowerShell to enable BitLocker with a TPM+PIN protector, in this case with a PIN set to 123456* - ``` -PS C:\>$SecureString = ConvertTo-SecureString "123456" -AsPlainText -Force +```powershell +Enable-BitLocker -MountPoint "D:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -TpmProtector +``` -PS C:\> Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -Pin $SecureString -TPMandPinProtector - ``` +*Example: Use PowerShell to enable BitLocker with a TPM+PIN protector, in this case with a PIN set to 123456* +```powershell +$SecureString = ConvertTo-SecureString "123456" -AsPlainText -Force + +Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -Pin $SecureString -TPMandPinProtector +``` ## Related Articles [BitLocker: FAQs](bitlocker-frequently-asked-questions.md) -[Microsoft BitLocker Administration and Management (MBAM)](https://technet.microsoft.com/windows/hh826072.aspx) +[Microsoft BitLocker Administration and Management (MBAM)](https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/mbam-v25/) [Overview of BitLocker Device Encryption in Windows 10](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) -[System Center 2012 Configuration Manager SP1](https://technet.microsoft.com/library/hh846237.aspx#BKMK_PreProvisionBitLocker) *(Pre-provision BitLocker task sequence)* +[BitLocker Group Policy Reference](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings) -[Enable BitLocker task sequence](https://technet.microsoft.com/library/hh846237.aspx#BKMK_EnableBitLocker) - -[BitLocker Group Policy Reference](https://technet.microsoft.com/library/ee706521(v=ws.10).aspx) - -[Microsoft Intune](https://www.microsoft.com/cloud-platform/microsoft-intune) +[Microsoft Intune](https://www.microsoft.com/cloud-platform/microsoft-intune/) *(Overview)* [Configuration Settings Providers](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider) *(Policy CSP: See [Security-RequireDeviceEncryption](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-security#security-policies))* -[BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp) - -
+[BitLocker CSP](https://docs.microsoft.com/windows/client-management/mdm/bitlocker-csp/) **Windows Server setup tools** -[Windows Server Installation Options](https://technet.microsoft.com/library/hh831786(v=ws.11).aspx) +[Windows Server Installation Options](https://docs.microsoft.com/en-us/windows-server/get-started-19/install-upgrade-migrate-19/) [How to update local source media to add roles and features](https://blogs.technet.microsoft.com/joscon/2012/11/14/how-to-update-local-source-media-to-add-roles-and-features/) @@ -134,10 +130,9 @@ PS C:\> Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpace [Shielded VMs and Guarded Fabric](https://blogs.technet.microsoft.com/windowsserver/2016/05/10/a-closer-look-at-shielded-vms-in-windows-server-2016/) -
**Powershell** [BitLocker cmdlets for Windows PowerShell](bitlocker-use-bitlocker-drive-encryption-tools-to-manage-bitlocker.md#bitlocker-cmdlets-for-windows-powershell) -[Surface Pro Specifications](https://www.microsoft.com/surface/support/surface-pro-specs) +[Surface Pro Specifications](https://www.microsoft.com/surface/support/surface-pro-specs/) From 2f7f6f4dd98aee53be78333c01d7bd978a31473f Mon Sep 17 00:00:00 2001 From: Baard Hermansen Date: Mon, 2 Dec 2019 19:47:34 +0100 Subject: [PATCH 032/209] Update configure-windows-diagnostic-data-in-your-organization.md Updated URLs for the most part. Some minor updates of table formatting and text too. --- ...ws-diagnostic-data-in-your-organization.md | 154 +++++++++--------- 1 file changed, 73 insertions(+), 81 deletions(-) diff --git a/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md b/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md index 260868ca64..52f53de9e4 100644 --- a/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md +++ b/windows/privacy/configure-windows-diagnostic-data-in-your-organization.md @@ -20,9 +20,9 @@ ms.date: 04/29/2019 **Applies to** -- Windows 10 Enterprise -- Windows 10 Mobile -- Windows Server +- Windows 10 Enterprise +- Windows 10 Mobile +- Windows Server This article applies to Windows and Windows Server diagnostic data only. It describes the types of diagnostic data we may gather, the ways you might manage it in your organization, and some examples of how diagnostic data can provide you with valuable insights into your enterprise deployments. Microsoft uses the data to quickly identify and address issues affecting its customers. @@ -54,6 +54,7 @@ Windows as a Service is a fundamental change in how Microsoft plans, builds, and The release cadence of Windows may be fast, so feedback is critical to its success. We rely on diagnostic data at each stage of the process to inform our decisions and prioritize our efforts. ### What is Windows diagnostic data? + Windows diagnostic data is vital technical data from Windows devices about the device and how Windows and related software are performing. It's used in the following ways: - Keep Windows up to date @@ -71,9 +72,10 @@ Here are some specific examples of Windows diagnostic data: Diagnostic data can sometimes be confused with functional data. Some Windows components and apps connect to Microsoft services directly, but the data they exchange is not diagnostic data. For example, exchanging a user’s location for local weather or news is not an example of diagnostic data—it is functional data that the app or service requires to satisfy the user’s request. -There are subtle differences between diagnostic data and functional data. Windows collects and sends diagnostic data in the background automatically. You can control how much information is gathered by setting the diagnostic data level. Microsoft tries to avoid collecting personal information wherever possible (for example, if a crash dump is collected and a document was in memory at the time of the crash). On the other hand, functional data can contain personal information. However, a user action, such as requesting news or asking Cortana a question, usually triggers collection and transmission of functional data. +There are subtle differences between diagnostic data and functional data. Windows collects and sends diagnostic data in the background automatically. You can control how much information is gathered by setting the diagnostic data level. Microsoft tries to avoid collecting personal information wherever possible (for example, if a crash dump is collected and a document was in memory at the time of the crash). +On the other hand, functional data can contain personal information. However, a user action, such as requesting news or asking Cortana a question, usually triggers collection and transmission of functional data. -If you’re an IT pro that wants to manage Windows functional data sent from your organization to Microsoft, see [Manage connections from Windows operating system components to Microsoft services](https://technet.microsoft.com/itpro/windows/manage/manage-connections-from-windows-operating-system-components-to-microsoft-services). +If you’re an IT pro that wants to manage Windows functional data sent from your organization to Microsoft, see [Manage connections from Windows operating system components to Microsoft services](https://docs.microsoft.com/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services/). The following are specific examples of functional data: @@ -90,6 +92,7 @@ Windows and Windows Server diagnostic data gives every user a voice in the opera Our ability to collect diagnostic data that drives improvements to Windows and Windows Server helps raise the bar for app and device driver quality. Diagnostic data helps us to quickly identify and fix critical reliability and security issues with apps and device drivers on given configurations. For example, we can identify an app that hangs on devices using a specific version of a video driver, allowing us to work with the app and device driver vendor to quickly fix the issue. The result is less downtime and reduced costs and increased productivity associated with troubleshooting these issues. #### Real-world example of how Windows diagnostic data helps + There was a version of a video driver that was crashing on some devices running Windows 10, causing the device to reboot. We detected the problem in our diagnostic data, and immediately contacted the third-party developer who builds the video driver. Working with the developer, we provided an updated driver to Windows Insiders within 24 hours. Based on diagnostic data from the Windows Insiders’ devices, we were able to validate the new version of the video driver, and rolled it out to the broad public as an update the next day. Diagnostic data helped us find, fix, and resolve this problem in just 48 hours, providing a better user experience and reducing costly support calls. ### Improve end-user productivity @@ -104,20 +107,19 @@ Windows diagnostic data also helps Microsoft better understand how customers use ### Insights into your own organization -Sharing information with Microsoft helps make Windows and other products better, but it can also help make your internal processes and user experiences better. Microsoft provides a set of solutions that leverage information shared by customers to provide insights customized for your internal use. The first of these was [Upgrade Readiness](/windows/deployment/upgrade/manage-windows-upgrades-with-upgrade-readiness), followed by [Desktop Analytics](https://aka.ms/DADocs) (coming soon). Both help organizations with [Windows as a Service](/windows/deployment/update/wass-overview) adoption and potential compatibility challenges. For E5 customers, [Microsoft Defender Advanced Threat Protection](/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection), a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. - +Sharing information with Microsoft helps make Windows and other products better, but it can also help make your internal processes and user experiences better. Microsoft provides a set of solutions that leverage information shared by customers to provide insights customized for your internal use. The first of these was [Upgrade Readiness](/windows/deployment/upgrade/manage-windows-upgrades-with-upgrade-readiness), followed by [Desktop Analytics](https://aka.ms/DADocs). Both help organizations with [Windows as a Service](/windows/deployment/update/wass-overview) adoption and potential compatibility challenges. For E5 customers, [Microsoft Defender Advanced Threat Protection](/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection), a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. ## How Microsoft handles diagnostic data The diagnostic data is categorized into four levels: -- [**Security**](#security-level). Information that’s required to help keep Windows and Windows Server secure, including data about the Connected User Experiences and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender. +- [**Security**](#security-level). Information that’s required to help keep Windows and Windows Server secure, including data about the Connected User Experiences and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender. -- [**Basic**](#basic-level). Basic device info, including: quality-related data, app compatibility, and data from the **Security** level. +- [**Basic**](#basic-level). Basic device info, including: quality-related data, app compatibility, and data from the **Security** level. -- [**Enhanced**](#enhanced-level). Additional insights, including: how Windows, Windows Server, and apps are used, how they perform, advanced reliability data, and data from both the **Basic** and the **Security** levels. +- [**Enhanced**](#enhanced-level). Additional insights, including: how Windows, Windows Server, and apps are used, how they perform, advanced reliability data, and data from both the **Basic** and the **Security** levels. -- [**Full**](#full-level). Includes information about the websites you browse, how you use apps and features, plus additional information about device health, device activity (sometimes referred to as usage), and enhanced error reporting. At Full, Microsoft also collects the memory state of your device when a system or app crash occurs. It includes data from the **Security**, **Basic**, and **Enhanced** levels. +- [**Full**](#full-level). Includes information about the websites you browse, how you use apps and features, plus additional information about device health, device activity (sometimes referred to as usage), and enhanced error reporting. At Full, Microsoft also collects the memory state of your device when a system or app crash occurs. It includes data from the **Security**, **Basic**, and **Enhanced** levels. Diagnostic data levels are cumulative, meaning each subsequent level includes data collected through lower levels. For more information see the [Diagnostic data levels](#diagnostic-data-levels) section. @@ -126,9 +128,9 @@ Diagnostic data levels are cumulative, meaning each subsequent level includes da Windows 10 and Windows Server includes the Connected User Experiences and Telemetry component, which uses Event Tracing for Windows (ETW) tracelogging technology that gathers and stores diagnostic data events and data. The operating system and some Microsoft management solutions, such as System Center, use the same logging technology. 1. Operating system features and some management applications are instrumented to publish events and data. Examples of management applications include Virtual Machine Manager (VMM), Server Manager, and Storage Spaces. -2. Events are gathered using public operating system event logging and tracing APIs. -3. You can configure the diagnostic data level by using MDM policy, Group Policy, or registry settings. -4. The Connected User Experiences and Telemetry component transmits the diagnostic data. +1. Events are gathered using public operating system event logging and tracing APIs. +1. You can configure the diagnostic data level by using MDM policy, Group Policy, or registry settings. +1. The Connected User Experiences and Telemetry component transmits the diagnostic data. Info collected at the Enhanced and Full levels of diagnostic data is typically gathered at a fractional sampling rate, which can be as low as 1% of devices reporting data at those levels. @@ -136,7 +138,7 @@ Info collected at the Enhanced and Full levels of diagnostic data is typically g All diagnostic data is encrypted using SSL and uses certificate pinning during transfer from the device to the Microsoft Data Management Service. With Windows 10, data is uploaded on a schedule that is sensitive to event priority, battery use, and network cost. Real-time events, such as Windows Defender Advanced Threat Protection, are always sent immediately. Normal events are not uploaded on metered networks, unless you are on a metered server connection. On a free network, normal events can be uploaded every 4 hours if on battery, or every 15 minutes if on A/C power. Diagnostic and crash data are only uploaded on A/C power and free networks. -The data transmitted at the Basic and Enhanced data diagnostic levels is quite small; typically less than 1 MB per device per day, but occasionally up to 2 MB per device per day). +The data transmitted at the Basic and Enhanced data diagnostic levels is quite small; typically less than 1 MB per device per day, but occasionally up to 2 MB per device per day. ### Endpoints @@ -149,24 +151,23 @@ For a complete list of diagnostics endpoints leveraged by Microsoft Defender Adv The following table defines the endpoints for Connected User Experiences and Telemetry component: -| Windows release | Endpoint | -| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | -| Windows 10, versions 1703 or later, with the 2018-09 cumulative update installed | **Diagnostics data:** v10c.vortex-win.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | -| Windows 10, versions 1803 or later, without the 2018-09 cumulative update installed | **Diagnostics data:** v10.events.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | -| Windows 10, version 1709 or earlier | **Diagnostics data:** v10.vortex-win.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | +| Windows release | Endpoint | +| - | - | +| Windows 10, versions 1703 or later, with the 2018-09 cumulative update installed | **Diagnostics data:** v10c.vortex-win.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | +| Windows 10, versions 1803 or later, without the 2018-09 cumulative update installed | **Diagnostics data:** v10.events.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | +| Windows 10, version 1709 or earlier | **Diagnostics data:** v10.vortex-win.data.microsoft.com

**Functional:** v20.vortex-win.data.microsoft.com

**Microsoft Defender Advanced Threat Protection** is country specific and the prefix changes by country,
for example: **de**.vortex-win.data.microsoft.com

**Settings:** settings-win.data.microsoft.com | The following table defines **additional diagnostics endpoints** not covered by services in the links above: -| Service | Endpoint | -| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | -| Onedrive app for Windows 10 | https://vortex.data.microsoft.com/collect/v1 | - +| Service | Endpoint | +| - | - | +| OneDrive app for Windows 10 | | The following table defines the endpoints for other diagnostic data services: | Service | Endpoint | | - | - | -| [Windows Error Reporting](https://msdn.microsoft.com/library/windows/desktop/bb513641.aspx) | watson.telemetry.microsoft.com | +| [Windows Error Reporting](https://msdn.microsoft.com/library/windows/desktop/bb513641.aspx) | watson.telemetry.microsoft.com | | | ceuswatcab01.blob.core.windows.net | | | ceuswatcab02.blob.core.windows.net | | | eaus2watcab01.blob.core.windows.net | @@ -175,7 +176,7 @@ The following table defines the endpoints for other diagnostic data services: | | weus2watcab02.blob.core.windows.net | | [Online Crash Analysis](https://msdn.microsoft.com/library/windows/desktop/ee416349.aspx) | oca.telemetry.microsoft.com | | OneDrive app for Windows 10 | vortex.data.microsoft.com/collect/v1 | -| Microsoft Defender Advanced Threat Protection | https://wdcp.microsoft.com
https://wdcpalt.microsoft.com | +| Microsoft Defender Advanced Threat Protection |
| ### Data use and access @@ -191,11 +192,10 @@ Microsoft believes in and practices information minimization. We strive to gathe Sharing diagnostic data with Microsoft is enabled by default on Windows 10, 1903 and later. Sharing this data provides many benefits to enterprises, so we do not recommend turning it off. For most enterprise customers, simply adjusting the diagnostic data level and managing specific components is the best option. -Customers can set the diagnostic data level in both the user interface and with existing management tools. Users can change the diagnostic data level in the **Diagnostic data** setting. In the **Settings** app, in **Privacy** > **Diagnostics & feedback**. They can choose between Basic and Full. The Enhanced level will only be displayed as an option when Group Policy or Mobile Device Management (MDM) are invoked with this level. The Security level is not available. +Customers can set the diagnostic data level in both the user interface and with existing management tools. Users can change the diagnostic data level in the **Diagnostic data** setting. In the **Settings** app, in **Privacy** > **Diagnostics & feedback**. They can choose between Basic and Full. The Enhanced level will only be displayed as an option when Group Policy or Mobile Device Management (MDM) are invoked with this level. The Security level is not available. IT pros can use various methods, including Group Policy and Mobile Device Management (MDM), to choose a diagnostic data level. If you’re using Windows 10 Enterprise, Windows 10 Education, or Windows Server, the Security diagnostic data level is available when managing the policy. Setting the diagnostic data level through policy sets the upper boundary for the users’ choices. To disable user choice after setting the level with the policy, you will need to use the "Configure telemetry opt-in setting user interface" group policy. The remainder of this article describes how to use group policy to configure levels and settings interface. - #### Manage your diagnostic data settings Use the steps in this article to set and/or adjust the diagnostic data settings for Windows and Windows Server in your organization. @@ -225,41 +225,41 @@ Use the appropriate value in the table below when you configure the management p Use a Group Policy object to set your organization’s diagnostic data level. -1. From the Group Policy Management Console, go to **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Data Collection and Preview Builds**. +1. From the Group Policy Management Console, go to **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Data Collection and Preview Builds**. -2. Double-click **Allow Telemetry**. +1. Double-click **Allow Telemetry**. -3. In the **Options** box, select the level that you want to configure, and then click **OK**. +1. In the **Options** box, select the level that you want to configure, and then click **OK**. ### Use MDM to set the diagnostic data level -Use the [Policy Configuration Service Provider (CSP)](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) to apply the System/AllowTelemetry MDM policy. +Use the [Policy Configuration Service Provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider) to apply the System/AllowTelemetry MDM policy. ### Use Registry Editor to set the diagnostic data level Use Registry Editor to manually set the registry level on each device in your organization or you can write a script to edit the registry. If a management policy already exists, such as Group Policy or MDM, it will override this registry setting. -1. Open Registry Editor, and go to **HKEY\_LOCAL\_MACHINE\\Software\\Policies\\Microsoft\\Windows\\DataCollection**. +1. Open Registry Editor, and go to **HKEY\_LOCAL\_MACHINE\\Software\\Policies\\Microsoft\\Windows\\DataCollection**. -2. Right-click **DataCollection**, click New, and then click **DWORD (32-bit) Value**. +1. Right-click **DataCollection**, click New, and then click **DWORD (32-bit) Value**. -3. Type **AllowTelemetry**, and then press ENTER. +1. Type **AllowTelemetry**, and then press ENTER. -4. Double-click **AllowTelemetry**, set the desired value from the table above, and then click **OK.** +1. Double-click **AllowTelemetry**, set the desired value from the table above, and then click **OK.** -5. Click **File** > **Export**, and then save the file as a .reg file, such as **C:\\AllowTelemetry.reg**. You can run this file from a script on each device in your organization. +1. Click **File** > **Export**, and then save the file as a .reg file, such as **C:\\AllowTelemetry.reg**. You can run this file from a script on each device in your organization. ### Additional diagnostic data controls There are a few more settings that you can turn off that may send diagnostic data information: -- To turn off Windows Update diagnostic data, you have two choices. Either turn off Windows Update, or set your devices to be managed by an on premises update server, such as [Windows Server Update Services (WSUS)](https://technet.microsoft.com/library/hh852345.aspx) or [System Center Configuration Manager](https://www.microsoft.com/server-cloud/products/system-center-2012-r2-configuration-manager/). +- To turn off Windows Update diagnostic data, you have two choices. Either turn off Windows Update, or set your devices to be managed by an on premises update server, such as [Windows Server Update Services (WSUS)](https://docs.microsoft.com/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or [Microsoft Endpoint Configuration Manager](https://docs.microsoft.com/configmgr/index/). -- Turn off **Windows Defender Cloud-based Protection** and **Automatic sample submission** in **Settings** > **Update & security** > **Windows Defender**. +- Turn off **Windows Defender Cloud-based Protection** and **Automatic sample submission** in **Settings** > **Update & security** > **Windows Defender**. -- Manage the Malicious Software Removal Tool in your organization. For more info, see Microsoft KB article [891716](https://support.microsoft.com/kb/891716). +- Manage the Malicious Software Removal Tool in your organization. For more info, see Microsoft KB article [891716](https://support.microsoft.com/kb/891716). -- Turn off **Improve inking and typing** in **Settings** > **Privacy**. At diagnostic data levels **Enhanced** and **Full**, Microsoft uses Linguistic Data Collection info to improve language model features such as autocomplete, spellcheck, suggestions, input pattern recognition, and dictionary. +- Turn off **Improve inking and typing** in **Settings** > **Privacy**. At diagnostic data levels **Enhanced** and **Full**, Microsoft uses Linguistic Data Collection info to improve language model features such as autocomplete, spellcheck, suggestions, input pattern recognition, and dictionary. > [!NOTE] > Microsoft does not intend to gather sensitive information, such as credit card numbers, usernames and passwords, email addresses, or other similarly sensitive information for Linguistic Data Collection. We guard against such events by using technologies to identify and remove sensitive information before linguistic data is sent from the user's device. If we determine that sensitive information has been inadvertently received, we delete the information. @@ -275,23 +275,23 @@ The Security level gathers only the diagnostic data info that is required to kee > [!NOTE] > If your organization relies on Windows Update for updates, you shouldn’t use the **Security** level. Because no Windows Update information is gathered at this level, important information about update failures is not sent. Microsoft uses this information to fix the causes of those failures and improve the quality of our updates. -Windows Server Update Services (WSUS) and System Center Configuration Manager functionality is not affected at this level, nor is diagnostic data about Windows Server features or System Center gathered. +Windows Server Update Services (WSUS) and Microsoft Endpoint Configuration Manager functionality is not affected at this level, nor is diagnostic data about Windows Server features or System Center gathered. The data gathered at this level includes: -- **Connected User Experiences and Telemetry component settings**. If general diagnostic data has been gathered and is queued, it is sent to Microsoft. Along with this diagnostic data, the Connected User Experiences and Telemetry component may download a configuration settings file from Microsoft’s servers. This file is used to configure the Connected User Experiences and Telemetry component itself. The data gathered by the client for this request includes OS information, device id (used to identify what specific device is requesting settings) and device class (for example, whether the device is server or desktop). +- **Connected User Experiences and Telemetry component settings**. If general diagnostic data has been gathered and is queued, it is sent to Microsoft. Along with this diagnostic data, the Connected User Experiences and Telemetry component may download a configuration settings file from Microsoft’s servers. This file is used to configure the Connected User Experiences and Telemetry component itself. The data gathered by the client for this request includes OS information, device id (used to identify what specific device is requesting settings) and device class (for example, whether the device is server or desktop). -- **Malicious Software Removal Tool (MSRT)** The MSRT infection report contains information, including device info and IP address. +- **Malicious Software Removal Tool (MSRT)** The MSRT infection report contains information, including device info and IP address. > [!NOTE] > You can turn off the MSRT infection report. No MSRT information is included if MSRT is not used. If Windows Update is turned off, MSRT will not be offered to users. For more info, see Microsoft KB article [891716](https://support.microsoft.com/kb/891716). -- **Windows Defender/Endpoint Protection**. Windows Defender and System Center Endpoint Protection requires some information to function, including: anti-malware signatures, diagnostic information, User Account Control settings, Unified Extensible Firmware Interface (UEFI) settings, and IP address. +- **Windows Defender/Endpoint Protection**. Windows Defender and System Center Endpoint Protection requires some information to function, including: anti-malware signatures, diagnostic information, User Account Control settings, Unified Extensible Firmware Interface (UEFI) settings, and IP address. > [!NOTE] > This reporting can be turned off and no information is included if a customer is using third-party antimalware software, or if Windows Defender is turned off. For more info, see [Windows Defender](manage-connections-from-windows-operating-system-components-to-microsoft-services.md#bkmk-defender). - Microsoft recommends that Windows Update, Windows Defender, and MSRT remain enabled unless the enterprise uses alternative solutions such as Windows Server Update Services, System Center Configuration Manager, or a third-party antimalware solution. Windows Update, Windows Defender, and MSRT provide core Windows functionality such as driver and OS updates, including security updates. + Microsoft recommends that Windows Update, Windows Defender, and MSRT remain enabled unless the enterprise uses alternative solutions such as Windows Server Update Services, Microsoft Endpoint Configuration Manager, or a third-party antimalware solution. Windows Update, Windows Defender, and MSRT provide core Windows functionality such as driver and OS updates, including security updates. For servers with default diagnostic data settings and no Internet connectivity, you should set the diagnostic data level to **Security**. This stops data gathering for events that would not be uploaded due to the lack of Internet connectivity. @@ -307,42 +307,34 @@ The normal upload range for the Basic diagnostic data level is between 109 KB - The data gathered at this level includes: -- **Basic device data**. Helps provide an understanding about the types of Windows devices and the configurations and types of native and virtualized Windows Servers in the ecosystem. Examples include: +- **Basic device data**. Helps provide an understanding about the types of Windows devices and the configurations and types of native and virtualized Windows Servers in the ecosystem. Examples include: - - Device attributes, such as camera resolution and display type + - Device attributes, such as camera resolution and display type + - Internet Explorer version + - Battery attributes, such as capacity and type + - Networking attributes, such as number of network adapters, speed of network adapters, mobile operator network, and IMEI number + - Processor and memory attributes, such as number of cores, architecture, speed, memory size, and firmware + - Virtualization attribute, such as Second Level Address Translation (SLAT) support and guest operating system + - Operating system attributes, such as Windows edition and virtualization state + - Storage attributes, such as number of drives, type, and size - - Internet Explorer version +- **Connected User Experiences and Telemetry component quality metrics**. Helps provide an understanding about how the Connected User Experiences and Telemetry component is functioning, including % of uploaded events, dropped events, and the last upload time. - - Battery attributes, such as capacity and type +- **Quality-related information**. Helps Microsoft develop a basic understanding of how a device and its operating system are performing. Some examples are the device characteristics of a Connected Standby device, the number of crashes or hangs, and application state change details, such as how much processor time and memory were used, and the total uptime for an app. - - Networking attributes, such as number of network adapters, speed of network adapters, mobile operator network, and IMEI number +- **Compatibility data**. Helps provide an understanding about which apps are installed on a device or virtual machine and identifies potential compatibility problems. - - Processor and memory attributes, such as number of cores, architecture, speed, memory size, and firmware + - **General app data and app data for Internet Explorer add-ons**. Includes a list of apps that are installed on a native or virtualized instance of the OS and whether these apps function correctly after an upgrade. This app data includes the app name, publisher, version, and basic details about which files have been blocked from usage. - - Virtualization attribute, such as Second Level Address Translation (SLAT) support and guest operating system + - **Internet Explorer add-ons**. Includes a list of Internet Explorer add-ons that are installed on a device and whether these apps will work after an upgrade. - - Operating system attributes, such as Windows edition and virtualization state + - **System data**. Helps provide an understanding about whether a device meets the minimum requirements to upgrade to the next version of the operating system. System information includes the amount of memory, as well as information about the processor and BIOS. - - Storage attributes, such as number of drives, type, and size + - **Accessory device data**. Includes a list of accessory devices, such as printers or external storage devices, that are connected to Windows PCs and whether these devices will function after upgrading to a new version of the operating system. -- **Connected User Experiences and Telemetry component quality metrics**. Helps provide an understanding about how the Connected User Experiences and Telemetry component is functioning, including % of uploaded events, dropped events, and the last upload time. - -- **Quality-related information**. Helps Microsoft develop a basic understanding of how a device and its operating system are performing. Some examples are the device characteristics of a Connected Standby device, the number of crashes or hangs, and application state change details, such as how much processor time and memory were used, and the total uptime for an app. - -- **Compatibility data**. Helps provide an understanding about which apps are installed on a device or virtual machine and identifies potential compatibility problems. - - - **General app data and app data for Internet Explorer add-ons**. Includes a list of apps that are installed on a native or virtualized instance of the OS and whether these apps function correctly after an upgrade. This app data includes the app name, publisher, version, and basic details about which files have been blocked from usage. - - - **Internet Explorer add-ons**. Includes a list of Internet Explorer add-ons that are installed on a device and whether these apps will work after an upgrade. - - - **System data**. Helps provide an understanding about whether a device meets the minimum requirements to upgrade to the next version of the operating system. System information includes the amount of memory, as well as information about the processor and BIOS. - - - **Accessory device data**. Includes a list of accessory devices, such as printers or external storage devices, that are connected to Windows PCs and whether these devices will function after upgrading to a new version of the operating system. - - - **Driver data**. Includes specific driver usage that’s meant to help figure out whether apps and devices will function after upgrading to a new version of the operating system. This can help to determine blocking issues and then help Microsoft and our partners apply fixes and improvements. - -- **Microsoft Store**. Provides information about how the Microsoft Store performs, including app downloads, installations, and updates. It also includes Microsoft Store launches, page views, suspend and resumes, and obtaining licenses. + - **Driver data**. Includes specific driver usage that’s meant to help figure out whether apps and devices will function after upgrading to a new version of the operating system. This can help to determine blocking issues and then help Microsoft and our partners apply fixes and improvements. +- **Microsoft Store**. Provides information about how the Microsoft Store performs, including app downloads, installations, and updates. It also includes Microsoft Store launches, page views, suspend and resumes, and obtaining licenses. ### Enhanced level @@ -354,13 +346,13 @@ The normal upload range for the Enhanced diagnostic data level is between 239 KB The data gathered at this level includes: -- **Operating system events**. Helps to gain insights into different areas of the operating system, including networking, Hyper-V, Cortana, storage, file system, and other components. +- **Operating system events**. Helps to gain insights into different areas of the operating system, including networking, Hyper-V, Cortana, storage, file system, and other components. -- **Operating system app events**. A set of events resulting from Microsoft applications and management tools that were downloaded from the Store or pre-installed with Windows or Windows Server, including Server Manager, Photos, Mail, and Microsoft Edge. +- **Operating system app events**. A set of events resulting from Microsoft applications and management tools that were downloaded from the Store or pre-installed with Windows or Windows Server, including Server Manager, Photos, Mail, and Microsoft Edge. -- **Device-specific events**. Contains data about events that are specific to certain devices, such as Surface Hub and Microsoft HoloLens. For example, Microsoft HoloLens sends Holographic Processing Unit (HPU)-related events. +- **Device-specific events**. Contains data about events that are specific to certain devices, such as Surface Hub and Microsoft HoloLens. For example, Microsoft HoloLens sends Holographic Processing Unit (HPU)-related events. -- **Some crash dump types**. All crash dump types, except for heap dumps and full dumps. +- **Some crash dump types**. All crash dump types, except for heap dumps and full dumps. If the Connected User Experiences and Telemetry component detects a problem on Windows 10 that requires gathering more detailed instrumentation, the Connected User Experiences and Telemetry component at the **Enhanced** diagnostic data level will only gather data about the events associated with the specific issue. @@ -374,11 +366,11 @@ If a device experiences problems that are difficult to identify or repeat using However, before more data is gathered, Microsoft’s privacy governance team, including privacy and other subject matter experts, must approve the diagnostics request made by a Microsoft engineer. If the request is approved, Microsoft engineers can use the following capabilities to get the information: -- Ability to run a limited, pre-approved list of Microsoft certified diagnostic tools, such as msinfo32.exe, powercfg.exe, and dxdiag.exe. +- Ability to run a limited, pre-approved list of Microsoft certified diagnostic tools, such as msinfo32.exe, powercfg.exe, and dxdiag.exe. -- Ability to get registry keys. +- Ability to get registry keys. -- All crash dump types, including heap dumps and full dumps. +- All crash dump types, including heap dumps and full dumps. > [!NOTE] > Crash dumps collected at this diagnostic data level may unintentionally contain personal data, such as portions of memory from a documents, a web page, etc. @@ -387,7 +379,7 @@ However, before more data is gathered, Microsoft’s privacy governance team, in > [!IMPORTANT] > The Upgrade Readiness and Device Health solutions of Windows Analytics are being retired on January 31, 2020. [Update Compliance](/windows/deployment/update/update-compliance-get-started) will continue to be supported. -> For more information, see [Windows Analytics retirement on January 31, 2020](https://support.microsoft.com/en-us/help/4521815/windows-analytics-retirement). +> For more information, see [Windows Analytics retirement on January 31, 2020](https://support.microsoft.com/help/4521815/windows-analytics-retirement). Desktop Analytics reports are powered by diagnostic data not included in the **Basic** level, such as crash reports and certain operating system events. @@ -414,7 +406,7 @@ With the retirement of Windows Analytics, this policy will continue to be suppor -AND- -2. Enable the **LimitEnhancedDiagnosticDataWindowsAnalytics** setting, using either Group Policy or MDM. +1. Enable the **LimitEnhancedDiagnosticDataWindowsAnalytics** setting, using either Group Policy or MDM. a. Using Group Policy, set the **Computer Configuration/Administrative Templates/Windows Components/Data collection and Preview builds/Limit Enhanced diagnostic data to the minimum required by Windows Analytics** setting to **Enabled**. From 9ff49e996c61baaf656554f369618649645097c1 Mon Sep 17 00:00:00 2001 From: Baard Hermansen Date: Mon, 2 Dec 2019 20:10:45 +0100 Subject: [PATCH 033/209] Update bitlocker-management-for-enterprises.md Removed en-us specific locale from URLs. --- .../bitlocker/bitlocker-management-for-enterprises.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md index 242d5a9908..a42be4d4dc 100644 --- a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md +++ b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md @@ -24,7 +24,7 @@ Though much Windows BitLocker [documentation](bitlocker-overview.md) has been pu > [!IMPORTANT] -> Microsoft BitLocker Administration and Monitoring (MBAM) capabilities will be offered from [ConfigMgr in on-prem scenarios](https://docs.microsoft.com/en-us/configmgr/core/get-started/2019/technical-preview-1909#bkmk_bitlocker/) in the future. +> Microsoft BitLocker Administration and Monitoring (MBAM) capabilities will be offered from [ConfigMgr in on-prem scenarios](https://docs.microsoft.com/configmgr/core/get-started/2019/technical-preview-1909#bkmk_bitlocker/) in the future. ## Managing domain-joined computers and moving to cloud @@ -102,7 +102,7 @@ Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -Pi [BitLocker: FAQs](bitlocker-frequently-asked-questions.md) -[Microsoft BitLocker Administration and Management (MBAM)](https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/mbam-v25/) +[Microsoft BitLocker Administration and Management (MBAM)](https://docs.microsoft.com/microsoft-desktop-optimization-pack/mbam-v25/) [Overview of BitLocker Device Encryption in Windows 10](bitlocker-device-encryption-overview-windows-10.md#bitlocker-device-encryption) @@ -118,7 +118,7 @@ Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -Pi **Windows Server setup tools** -[Windows Server Installation Options](https://docs.microsoft.com/en-us/windows-server/get-started-19/install-upgrade-migrate-19/) +[Windows Server Installation Options](https://docs.microsoft.com/windows-server/get-started-19/install-upgrade-migrate-19/) [How to update local source media to add roles and features](https://blogs.technet.microsoft.com/joscon/2012/11/14/how-to-update-local-source-media-to-add-roles-and-features/) From 7947a088cb46c7e8e27e5437cce0381603a02c71 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:12:48 -0800 Subject: [PATCH 034/209] ATP for Mac updates --- .../threat-protection/microsoft-defender-atp/preview.md | 4 +--- .../whats-new-in-microsoft-defender-atp.md | 2 +- 2 files changed, 2 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview.md b/windows/security/threat-protection/microsoft-defender-atp/preview.md index 99475c18be..7173007d17 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview.md @@ -42,9 +42,7 @@ Turn on the preview experience setting to be among the first to try upcoming fea ## Preview features The following features are included in the preview release: -- [Endpoint detection and response for Mac devices](endpoint-detection-response-mac-preview.md). Recently, [Microsoft Defender ATP for Mac](microsoft-defender-atp-mac.md) released. Expanding on the protection available in Microsoft Defender ATP for Mac, endpoint detection and response capabilities are now in preview. - - - [Threat & Vulnerability supported operating systems and platforms](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-supported-os)
Ensure that you meet the operating system or platform requisites for Threat & Vulnerability Management so the activities in your devices are properly accounted for. Threat & Vulnerability Management supports Windows 7, Windows 10 1607-1703, Windows 10 1709+, Windows Server 2008R2, Windows Server 2012R2, Windows Server 2016, Windows Server 2019. + - [Threat & Vulnerability supported operating systems and platforms](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-supported-os)
Ensure that you meet the operating system or platform requisites for Threat & Vulnerability Management so the activities in your devices are properly accounted for. Threat & Vulnerability Management supports Windows 7, Windows 10 1607-1703, Windows 10 1709+, Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019. - [Threat & Vulnerability Management Report inaccuracy](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation#report-inaccuracy)
You can report a false positive when you see any vague, inaccurate, incomplete, or already remediated [security recommendation](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation#report-inaccuracy), [software inventory](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory#report-inaccuracy), and [discovered vulnerabilities](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses#report-inaccuracy). diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md index 2782279fcc..73d6f92070 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md @@ -29,7 +29,7 @@ For more information preview features, see [Preview features](https://docs.micro ## November 2019 -- [Microsoft Defender ATP for Mac](microsoft-defender-atp-mac.md)
Microsoft Defender ATP for Mac brings the next-generation protection to Mac devices. Core components of the unified endpoint security platform will now be available for Mac devices. ([Endpoint detection and response is currently in preview](preview.md).) +- [Microsoft Defender ATP for Mac](microsoft-defender-atp-mac.md)
Microsoft Defender ATP for Mac brings the next-generation protection to Mac devices. Core components of the unified endpoint security platform will now be available for Mac devices, including [endpoint detection and response](endpoint-detection-response-mac-preview.md). - [Threat & Vulnerability Management application end-of-life notification](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation)
Applications which have reached their end-of-life are labeled as such so you are aware that they will no longer be supported, and can take action to either uninstall or replace. Doing so will help lessen the risks related to various vulnerability exposures due to unpatched applications. From 8fc5017dbb7d4e8a702dc829b3ed73901021f48c Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:13:51 -0800 Subject: [PATCH 035/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 34 +++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 0d0904ba75..f0f9483449 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -283,6 +283,40 @@ Whether EDR early preview features are enabled or not. | **Data type** | Boolean | | **Possible values** | true (default)
false | +#### Device tags + +Specify the tag name and its desired value, Current supported tags:Group - allows to set machine tag (reflected in the portal) + +||| +|:---|:---| +| **Domain** | com.microsoft.wdav | +| **Key** | tags | +| **Data type** | Dictionary (nested preference) | +| **Comments** | See the following sections for a description of the dictionary contents. | + +**Type of tag** + +Specifies the type of tag + +||| +|:---|:---| +| **Domain** | com.microsoft.wdav | +| **Key** | key | +| **Data type** | String | +| **Possible values** | GROUP | + +**Value of tag** + +Specifies the value of tag + +||| +|:---|:---| +| **Domain** | com.microsoft.wdav | +| **Key** | value | +| **Data type** | String | +| **Possible values** | any string | + + ## Recommended configuration profile To get started, we recommend the following configuration profile for your enterprise to take advantage of all protection features that Microsoft Defender ATP provides. From d47ac428afb0117971c5274c376a6fb59264dd46 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:14:31 -0800 Subject: [PATCH 036/209] Update mac-preferences.md --- .../threat-protection/microsoft-defender-atp/mac-preferences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index f0f9483449..231dc8bc15 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -24,7 +24,7 @@ ms.topic: conceptual - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Mac](microsoft-defender-atp-mac.md) >[!IMPORTANT] ->This topic contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise environments. If you are interested in configuring the product on a device from the command-line, please refer to the [Resources](mac-resources.md#configuring-from-the-command-line) page. +>This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise environments. If you are interested in configuring the product on a device from the command-line, please refer to the [Resources](mac-resources.md#configuring-from-the-command-line) page. In enterprise environments, Microsoft Defender ATP for Mac can be managed through a configuration profile. This profile is deployed from management tool of your choice. Preferences managed by the enterprise take precedence over the ones set locally on the device. In other words, users in your enterprise are not able to change preferences that are set through this configuration profile. From 315810ab2ceb420c09068d2356c7eb965fa2e34f Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:19:05 -0800 Subject: [PATCH 037/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 27 ++++++++++--------- 1 file changed, 14 insertions(+), 13 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 231dc8bc15..637b7de5ac 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -1,6 +1,6 @@ --- title: Set preferences for Microsoft Defender ATP for Mac -description: Configure Microsoft Defender ATP for Mac in enterprises. +description: Configure Microsoft Defender ATP for Mac in enterprise organizations. keywords: microsoft, defender, atp, mac, management, preferences, enterprise, intune, jamf, macos, catalina, mojave, high sierra search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -26,9 +26,11 @@ ms.topic: conceptual >[!IMPORTANT] >This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise environments. If you are interested in configuring the product on a device from the command-line, please refer to the [Resources](mac-resources.md#configuring-from-the-command-line) page. -In enterprise environments, Microsoft Defender ATP for Mac can be managed through a configuration profile. This profile is deployed from management tool of your choice. Preferences managed by the enterprise take precedence over the ones set locally on the device. In other words, users in your enterprise are not able to change preferences that are set through this configuration profile. +In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile, and deployed by using one of several management tools. -This topic describes the structure of this profile (including a recommended profile that you can use to get started) and instructions for how to deploy the profile. +Preferences managed by the enterprise take precedence over the ones set locally on the device. In other words, users in your enterprise are not able to change preferences that are set through this configuration profile. + +This article describes the structure of this profile (including a recommended profile that you can use to get started) and instructions for how to deploy the profile. ## Configuration profile structure @@ -89,7 +91,7 @@ Entities that have been excluded from the scan. Exclusions can be specified by f | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | -**Type of exclusion** +##### Type of exclusion Specifies the type of content excluded from the scan. @@ -100,7 +102,7 @@ Specifies the type of content excluded from the scan. | **Data type** | String | | **Possible values** | excludedPath
excludedFileExtension
excludedFileName | -**Path to excluded content** +##### Path to excluded content Used to exclude content from the scan by full file path. @@ -112,7 +114,7 @@ Used to exclude content from the scan by full file path. | **Possible values** | valid paths | | **Comments** | Applicable only if *$type* is *excludedPath* | -**Path type (file / directory)** +##### Path type (file / directory) Indicates if the *path* property refers to a file or directory. @@ -124,7 +126,7 @@ Indicates if the *path* property refers to a file or directory. | **Possible values** | false (default)
true | | **Comments** | Applicable only if *$type* is *excludedPath* | -**File extension excluded from the scan** +##### File extension excluded from the scan Used to exclude content from the scan by file extension. @@ -136,7 +138,7 @@ Used to exclude content from the scan by file extension. | **Possible values** | valid file extensions | | **Comments** | Applicable only if *$type* is *excludedFileExtension* | -**Name of excluded content** +##### Name of excluded content Used to exclude content from the scan by file name. @@ -169,7 +171,7 @@ The *threatTypeSettings* preference in the antivirus engine is used to control h | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | -**Threat type** +##### Threat type Type of the threat for which the behavior is configured. @@ -180,7 +182,7 @@ Type of the threat for which the behavior is configured. | **Data type** | String | | **Possible values** | potentially_unwanted_application
archive_bomb | -**Action to take** +##### Action to take Action to take when coming across a threat of the type specified in the preceding section. Can be: @@ -294,7 +296,7 @@ Specify the tag name and its desired value, Current supported tags:Group - allow | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | -**Type of tag** +##### Type of tag Specifies the type of tag @@ -305,7 +307,7 @@ Specifies the type of tag | **Data type** | String | | **Possible values** | GROUP | -**Value of tag** +##### Value of tag Specifies the value of tag @@ -316,7 +318,6 @@ Specifies the value of tag | **Data type** | String | | **Possible values** | any string | - ## Recommended configuration profile To get started, we recommend the following configuration profile for your enterprise to take advantage of all protection features that Microsoft Defender ATP provides. From 3f4f30490a844bab2188bb42b1fe67178f9db229 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:19:24 -0800 Subject: [PATCH 038/209] Update mac-preferences.md --- .../threat-protection/microsoft-defender-atp/mac-preferences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 637b7de5ac..fdb4c00182 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -672,7 +672,7 @@ From the JAMF console, open **Computers** > **Configuration Profiles**, navigate 7. Select **Manage** > **Assignments**. In the **Include** tab, select **Assign to All Users & All devices**. >[!CAUTION] ->You must enter the correct custom configuration profile name, otherwise these preferences will not be recognized by the product. +>You must enter the correct custom configuration profile name; otherwise, these preferences will not be recognized by the product. ## Resources From 3b4bc1efb354982b95dd84fcf84f4c8a270d44e5 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:19:47 -0800 Subject: [PATCH 039/209] Update mac-preferences.md --- .../threat-protection/microsoft-defender-atp/mac-preferences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index fdb4c00182..78cf4faaed 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -653,7 +653,7 @@ Once you've built the configuration profile for your enterprise, you can deploy From the JAMF console, open **Computers** > **Configuration Profiles**, navigate to the configuration profile you'd like to use, then select **Custom Settings**. Create an entry with *com.microsoft.wdav* as the preference domain and upload the .plist produced earlier. >[!CAUTION] ->You must enter the correct preference domain (*com.microsoft.wdav*), otherwise the preferences will not be recognized by the product. +>You must enter the correct preference domain (`com.microsoft.wdav`); otherwise, the preferences will not be recognized by the product. ### Intune deployment From 60b20cbd36706df950c428838f60c8746e30a18a Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:20:51 -0800 Subject: [PATCH 040/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 78cf4faaed..4b408495e7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -120,7 +120,7 @@ Indicates if the *path* property refers to a file or directory. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | isDirectory | | **Data type** | Boolean | | **Possible values** | false (default)
true | @@ -132,7 +132,7 @@ Used to exclude content from the scan by file extension. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | extension | | **Data type** | String | | **Possible values** | valid file extensions | @@ -144,7 +144,7 @@ Used to exclude content from the scan by file name. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | name | | **Data type** | String | | **Possible values** | any string | @@ -177,7 +177,7 @@ Type of the threat for which the behavior is configured. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | key | | **Data type** | String | | **Possible values** | potentially_unwanted_application
archive_bomb | From 07f63ce59686be10a91e35a2215a4580aafa09b2 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:21:43 -0800 Subject: [PATCH 041/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 4b408495e7..0323ddee42 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -47,7 +47,7 @@ The *antivirusEngine* section of the configuration profile is used to manage the ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | antivirusEngine | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | @@ -58,7 +58,7 @@ Whether real-time protection (scan files as they are accessed) is enabled or not ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | enableRealTimeProtection | | **Data type** | Boolean | | **Possible values** | true (default)
false | @@ -74,7 +74,7 @@ Whether the antivirus engine runs in passive mode or not. In passive mode: ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | passiveMode | | **Data type** | Boolean | | **Possible values** | false (default)
true | @@ -86,7 +86,7 @@ Entities that have been excluded from the scan. Exclusions can be specified by f ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | exclusions | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | @@ -97,7 +97,7 @@ Specifies the type of content excluded from the scan. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | $type | | **Data type** | String | | **Possible values** | excludedPath
excludedFileExtension
excludedFileName | @@ -108,7 +108,7 @@ Used to exclude content from the scan by full file path. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | path | | **Data type** | String | | **Possible values** | valid paths | From 6e97fcd412613363587556e6656952dd317d6bdb Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:25:46 -0800 Subject: [PATCH 042/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 0323ddee42..0b1ce26f11 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -24,13 +24,13 @@ ms.topic: conceptual - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Mac](microsoft-defender-atp-mac.md) >[!IMPORTANT] ->This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise environments. If you are interested in configuring the product on a device from the command-line, please refer to the [Resources](mac-resources.md#configuring-from-the-command-line) page. +>This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise organizations. To configure Microsoft Defender ATP for Mac using the command-line interface, see the [Resources](mac-resources.md#configuring-from-the-command-line) page. In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile, and deployed by using one of several management tools. -Preferences managed by the enterprise take precedence over the ones set locally on the device. In other words, users in your enterprise are not able to change preferences that are set through this configuration profile. +Preferences managed by your security operations team take precedence over preferences that are set locally on the device. In other words, users in your organization are not able to change preferences that are set through the configuration profile. -This article describes the structure of this profile (including a recommended profile that you can use to get started) and instructions for how to deploy the profile. +This article describes the structure of the configuration profile and includes a recommended profile that you can use to get started, along with instructions on how to deploy the profile. ## Configuration profile structure From fb938c2237e1737c223f20a64753a799516523b3 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:32:37 -0800 Subject: [PATCH 043/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 28 +++++++++---------- 1 file changed, 13 insertions(+), 15 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 0b1ce26f11..9facca590f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -26,9 +26,7 @@ ms.topic: conceptual >[!IMPORTANT] >This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise organizations. To configure Microsoft Defender ATP for Mac using the command-line interface, see the [Resources](mac-resources.md#configuring-from-the-command-line) page. -In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile, and deployed by using one of several management tools. - -Preferences managed by your security operations team take precedence over preferences that are set locally on the device. In other words, users in your organization are not able to change preferences that are set through the configuration profile. +In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile, and deployed by using one of several management tools. Preferences that are managed by your security operations team take precedence over preferences that are set locally on the device. This means that users in your organization are not able to change preferences that are set through the configuration profile. This article describes the structure of the configuration profile and includes a recommended profile that you can use to get started, along with instructions on how to deploy the profile. @@ -197,7 +195,7 @@ Action to take when coming across a threat of the type specified in the precedin | **Data type** | String | | **Possible values** | audit (default)
block
off | -### Cloud delivered protection preferences +### Cloud-delivered protection preferences The *cloudService* entry in the configuration profile is used to configure the cloud driven protection feature of the product. @@ -208,7 +206,7 @@ The *cloudService* entry in the configuration profile is used to configure the c | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | -#### Enable / disable cloud delivered protection +#### Enable / disable cloud-delivered protection Whether cloud delivered protection is enabled on the device or not. To improve the security of your services, we recommend keeping this feature turned on. @@ -263,9 +261,9 @@ Whether the status menu icon (shown in the top-right corner of the screen) is hi | **Data type** | Boolean | | **Possible values** | false (default)
true | -### EDR preferences +### Endpoint detection and response preferences -The *edr* section of the configuration profile is used to manage the preferences of the EDR component of the product. +The *edr* section of the configuration profile is used to manage the preferences of the endpoint detection and response (EDR) component of Microsoft Defender ATP for Mac. ||| |:---|:---| @@ -291,7 +289,7 @@ Specify the tag name and its desired value, Current supported tags:Group - allow ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | tags | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | @@ -302,7 +300,7 @@ Specifies the type of tag ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | key | | **Data type** | String | | **Possible values** | GROUP | @@ -313,7 +311,7 @@ Specifies the value of tag ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | value | | **Data type** | String | | **Possible values** | any string | @@ -327,7 +325,7 @@ The following configuration profile will: - Specify how the following threat types are handled: - **Potentially unwanted applications (PUA)** are blocked - **Archive bombs** (file with a high compression rate) are audited to the product logs -- Enable cloud delivered protection +- Enable cloud-delivered protection - Enable automatic sample submission ### JAMF profile @@ -650,7 +648,7 @@ Once you've built the configuration profile for your enterprise, you can deploy ### JAMF deployment -From the JAMF console, open **Computers** > **Configuration Profiles**, navigate to the configuration profile you'd like to use, then select **Custom Settings**. Create an entry with *com.microsoft.wdav* as the preference domain and upload the .plist produced earlier. +From the JAMF console, open **Computers** > **Configuration Profiles**, navigate to the configuration profile you'd like to use, then select **Custom Settings**. Create an entry with `com.microsoft.wdav` as the preference domain and upload the .plist produced earlier. >[!CAUTION] >You must enter the correct preference domain (`com.microsoft.wdav`); otherwise, the preferences will not be recognized by the product. @@ -661,11 +659,11 @@ From the JAMF console, open **Computers** > **Configuration Profiles**, navigate 2. Choose a name for the profile. Change **Platform=macOS** to **Profile type=Custom**. Select Configure. -3. Save the .plist produced earlier as **com.microsoft.wdav.xml**. +3. Save the .plist produced earlier as `com.microsoft.wdav.xml`. -4. Enter **com.microsoft.wdav** as the **custom configuration profile name**. +4. Enter `com.microsoft.wdav` as the **custom configuration profile name**. -5. Open the configuration profile and upload **com.microsoft.wdav.xml**. This file was created in step 3. +5. Open the configuration profile and upload the `com.microsoft.wdav.xml` file. (This file was created in step 3.) 6. Select **OK**. From f5a01c0e7080b56f0c62cc44bb53f61e4928e863 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:34:34 -0800 Subject: [PATCH 044/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 9facca590f..ae1408a475 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -26,9 +26,11 @@ ms.topic: conceptual >[!IMPORTANT] >This article contains instructions for how to set preferences for Microsoft Defender ATP for Mac in enterprise organizations. To configure Microsoft Defender ATP for Mac using the command-line interface, see the [Resources](mac-resources.md#configuring-from-the-command-line) page. -In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile, and deployed by using one of several management tools. Preferences that are managed by your security operations team take precedence over preferences that are set locally on the device. This means that users in your organization are not able to change preferences that are set through the configuration profile. +## Summary -This article describes the structure of the configuration profile and includes a recommended profile that you can use to get started, along with instructions on how to deploy the profile. +In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile that is deployed by using one of several management tools. Preferences that are managed by your security operations team take precedence over preferences that are set locally on the device. This means that users in your organization are not able to change preferences that are set through the configuration profile. + +This article describes the structure of the configuration profile, includes a recommended profile that you can use to get started, and provides instructions on how to deploy the profile. ## Configuration profile structure From 924b78bb7fd1f89366577e084c27fe4e8495b8b6 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:35:36 -0800 Subject: [PATCH 045/209] Update mac-preferences.md --- .../threat-protection/microsoft-defender-atp/mac-preferences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index ae1408a475..46e4f3d98a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -28,7 +28,7 @@ ms.topic: conceptual ## Summary -In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile that is deployed by using one of several management tools. Preferences that are managed by your security operations team take precedence over preferences that are set locally on the device. This means that users in your organization are not able to change preferences that are set through the configuration profile. +In enterprise organizations, Microsoft Defender ATP for Mac can be managed through a configuration profile that is deployed by using one of several management tools. Preferences that are managed by your security operations team take precedence over preferences that are set locally on the device. Users in your organization are not able to change preferences that are set through the configuration profile. This article describes the structure of the configuration profile, includes a recommended profile that you can use to get started, and provides instructions on how to deploy the profile. From 1d72e5f6f2899911be354b0035e90afcbc24d950 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:52:38 -0800 Subject: [PATCH 046/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 62 +++++++++---------- 1 file changed, 31 insertions(+), 31 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 46e4f3d98a..30add8cdec 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -34,7 +34,7 @@ This article describes the structure of the configuration profile, includes a re ## Configuration profile structure -The configuration profile is a .plist file that consists of entries identified by a key (which denotes the name of the preference), followed by a value, which depends on the nature of the preference. Values can either be simple (such as a numerical value) or complex, such as a nested list of preferences. +The configuration profile is a *.plist* file that consists of entries identified by a key (which denotes the name of the preference), followed by a value, which depends on the nature of the preference. Values can either be simple (such as a numerical value) or complex, such as a nested list of preferences. >[!CAUTION] >The layout of the configuration profile depends on the management console that you are using. The following sections contain examples of configuration profiles for JAMF and Intune. @@ -54,7 +54,7 @@ The *antivirusEngine* section of the configuration profile is used to manage the #### Enable / disable real-time protection -Whether real-time protection (scan files as they are accessed) is enabled or not. +Specify whether to enable real-time protection, which scans files as they are accessed. ||| |:---|:---| @@ -65,7 +65,7 @@ Whether real-time protection (scan files as they are accessed) is enabled or not #### Enable / disable passive mode -Whether the antivirus engine runs in passive mode or not. In passive mode: +Specify whether the antivirus engine runs in passive mode. Passive mode has the following implications: - Real-time protection is turned off - On-demand scanning is turned on - Automatic threat remediation is turned off @@ -82,7 +82,7 @@ Whether the antivirus engine runs in passive mode or not. In passive mode: #### Scan exclusions -Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names. +Specify entities excluded from being scanned. Exclusions can be specified by full paths, extensions, or file names. ||| |:---|:---| @@ -93,7 +93,7 @@ Entities that have been excluded from the scan. Exclusions can be specified by f ##### Type of exclusion -Specifies the type of content excluded from the scan. +Specify content excluded from being scanned by type. ||| |:---|:---| @@ -104,7 +104,7 @@ Specifies the type of content excluded from the scan. ##### Path to excluded content -Used to exclude content from the scan by full file path. +Specify content excluded from being scanned by full file path. ||| |:---|:---| @@ -116,7 +116,7 @@ Used to exclude content from the scan by full file path. ##### Path type (file / directory) -Indicates if the *path* property refers to a file or directory. +Indicate if the *path* property refers to a file or directory. ||| |:---|:---| @@ -128,7 +128,7 @@ Indicates if the *path* property refers to a file or directory. ##### File extension excluded from the scan -Used to exclude content from the scan by file extension. +Specify content excluded from being scanned by file extension. ||| |:---|:---| @@ -140,7 +140,7 @@ Used to exclude content from the scan by file extension. ##### Name of excluded content -Used to exclude content from the scan by file name. +Specify content excluded from being scanned by file name. ||| |:---|:---| @@ -152,28 +152,28 @@ Used to exclude content from the scan by file name. #### Allowed threats -List of threats (identified by their name) that are not blocked by the product and are instead allowed to run. +Specify threats by name that are not blocked by Microsoft Defender ATP for Mac. These threats will be allowed to run. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | allowedThreats | | **Data type** | Array of strings | #### Threat type settings -The *threatTypeSettings* preference in the antivirus engine is used to control how certain threat types are handled by the product. +Specify how certain threat types are handled by Microsoft Defender ATP for Mac. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | threatTypeSettings | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | ##### Threat type -Type of the threat for which the behavior is configured. +Specify threat types. ||| |:---|:---| @@ -184,7 +184,7 @@ Type of the threat for which the behavior is configured. ##### Action to take -Action to take when coming across a threat of the type specified in the preceding section. Can be: +Specify what action to take when a threat of the type specified in the preceding section is detected. Choose from the following options: - **Audit**: your device is not protected against this type of threat, but an entry about the threat is logged. - **Block**: your device is protected against this type of threat and you are notified in the user interface and the security console. @@ -192,29 +192,29 @@ Action to take when coming across a threat of the type specified in the precedin ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | value | | **Data type** | String | | **Possible values** | audit (default)
block
off | ### Cloud-delivered protection preferences -The *cloudService* entry in the configuration profile is used to configure the cloud driven protection feature of the product. +Configure the cloud-driven protection features of Microsoft Defender ATP for Mac. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | cloudService | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | #### Enable / disable cloud-delivered protection -Whether cloud delivered protection is enabled on the device or not. To improve the security of your services, we recommend keeping this feature turned on. +Specify whether to enable cloud-delivered protection the device or not. To improve the security of your services, we recommend keeping this feature turned on. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | enabled | | **Data type** | Boolean | | **Possible values** | true (default)
false | @@ -236,58 +236,58 @@ Determines whether suspicious samples (that are likely to contain threats) are s ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | automaticSampleSubmission | | **Data type** | Boolean | | **Possible values** | true (default)
false | ### User interface preferences -The *userInterface* section of the configuration profile is used to manage the preferences of the user interface of the product. +Manage the preferences for the user interface of Microsoft Defender ATP for Mac. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | userInterface | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | #### Show / hide status menu icon -Whether the status menu icon (shown in the top-right corner of the screen) is hidden or not. +Specify whether to show or hide the status menu icon in the top-right corner of the screen. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | hideStatusMenuIcon | | **Data type** | Boolean | | **Possible values** | false (default)
true | ### Endpoint detection and response preferences -The *edr* section of the configuration profile is used to manage the preferences of the endpoint detection and response (EDR) component of Microsoft Defender ATP for Mac. +Manage the preferences of the endpoint detection and response (EDR) component of Microsoft Defender ATP for Mac. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | edr | | **Data type** | Dictionary (nested preference) | | **Comments** | See the following sections for a description of the dictionary contents. | #### Enable / disable early preview -Whether EDR early preview features are enabled or not. +Specify whether to enable EDR early preview features. ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | earlyPreview | | **Data type** | Boolean | | **Possible values** | true (default)
false | #### Device tags -Specify the tag name and its desired value, Current supported tags:Group - allows to set machine tag (reflected in the portal) +Specify a tag name and its value. ||| |:---|:---| @@ -305,7 +305,7 @@ Specifies the type of tag | **Domain** | `com.microsoft.wdav` | | **Key** | key | | **Data type** | String | -| **Possible values** | GROUP | +| **Possible values** | `GROUP` | ##### Value of tag From 2fe29344b31f7abaeb16f17dd9054dafab169dfd Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 11:55:26 -0800 Subject: [PATCH 047/209] Update mac-preferences.md --- .../microsoft-defender-atp/mac-preferences.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 30add8cdec..2481682ec7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -39,11 +39,11 @@ The configuration profile is a *.plist* file that consists of entries identified >[!CAUTION] >The layout of the configuration profile depends on the management console that you are using. The following sections contain examples of configuration profiles for JAMF and Intune. -The top level of the configuration profile includes product-wide preferences and entries for subareas of the product, which are explained in more detail in the next sections. +The top level of the configuration profile includes product-wide preferences and entries for subareas of Microsoft Defender ATP, which are explained in more detail in the next sections. ### Antivirus engine preferences -The *antivirusEngine* section of the configuration profile is used to manage the preferences of the antivirus component of the product. +The *antivirusEngine* section of the configuration profile is used to manage the preferences of the antivirus component of Microsoft Defender ATP. ||| |:---|:---| @@ -221,7 +221,7 @@ Specify whether to enable cloud-delivered protection the device or not. To impro #### Diagnostic collection level -Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, detect, diagnose and fix problems, and also make product improvements. This setting determines the level of diagnostics sent by the product to Microsoft. +Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, detect, diagnose and fix problems, and also make product improvements. This setting determines the level of diagnostics sent by Microsoft Defender ATP to Microsoft. ||| |:---|:---| @@ -326,7 +326,7 @@ The following configuration profile will: - Enable real-time protection (RTP) - Specify how the following threat types are handled: - **Potentially unwanted applications (PUA)** are blocked - - **Archive bombs** (file with a high compression rate) are audited to the product logs + - **Archive bombs** (file with a high compression rate) are audited to Microsoft Defender ATP logs - Enable cloud-delivered protection - Enable automatic sample submission @@ -449,7 +449,7 @@ The following configuration profile will: ## Full configuration profile example -The following configuration profile contains entries for all settings described in this document and can be used for more advanced scenarios where you want more control over the product. +The following configuration profile contains entries for all settings described in this document and can be used for more advanced scenarios where you want more control over Microsoft Defender ATP for Mac. ### JAMF profile @@ -653,7 +653,7 @@ Once you've built the configuration profile for your enterprise, you can deploy From the JAMF console, open **Computers** > **Configuration Profiles**, navigate to the configuration profile you'd like to use, then select **Custom Settings**. Create an entry with `com.microsoft.wdav` as the preference domain and upload the .plist produced earlier. >[!CAUTION] ->You must enter the correct preference domain (`com.microsoft.wdav`); otherwise, the preferences will not be recognized by the product. +>You must enter the correct preference domain (`com.microsoft.wdav`); otherwise, the preferences will not be recognized by Microsoft Defender ATP. ### Intune deployment @@ -672,7 +672,7 @@ From the JAMF console, open **Computers** > **Configuration Profiles**, navigate 7. Select **Manage** > **Assignments**. In the **Include** tab, select **Assign to All Users & All devices**. >[!CAUTION] ->You must enter the correct custom configuration profile name; otherwise, these preferences will not be recognized by the product. +>You must enter the correct custom configuration profile name; otherwise, these preferences will not be recognized by Microsoft Defender ATP. ## Resources From 4e9d135e2264e57f9ff2ea6e4ce1acf35884c47a Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:03:10 -0800 Subject: [PATCH 048/209] Update iexpress-command-line-options.md --- .../ie11-ieak/iexpress-command-line-options.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md b/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md index 88e151583a..54f7c5ab5e 100644 --- a/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md +++ b/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md @@ -18,7 +18,7 @@ ms.date: 07/27/2017 **Applies to:** - Windows Server 2008 R2 with SP1 -# IExpress Wizard command-line options +## IExpress Wizard command-line options Use command-line options with the IExpress Wizard (IExpress.exe) to control your Internet Explorer custom browser package extraction process. These command-line options work with IExpress:
From 235daa3e7e07d63b78ef89fd249426bd03626c14 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:04:26 -0800 Subject: [PATCH 049/209] Update how-to-revert-extension-points-from-an-app-v-50-package-to-an-app-v-46-package-for-a-specific-user.md --- ...pp-v-50-package-to-an-app-v-46-package-for-a-specific-user.md | 1 + 1 file changed, 1 insertion(+) diff --git a/mdop/appv-v5/how-to-revert-extension-points-from-an-app-v-50-package-to-an-app-v-46-package-for-a-specific-user.md b/mdop/appv-v5/how-to-revert-extension-points-from-an-app-v-50-package-to-an-app-v-46-package-for-a-specific-user.md index c290148b0d..76656d39e1 100644 --- a/mdop/appv-v5/how-to-revert-extension-points-from-an-app-v-50-package-to-an-app-v-46-package-for-a-specific-user.md +++ b/mdop/appv-v5/how-to-revert-extension-points-from-an-app-v-50-package-to-an-app-v-46-package-for-a-specific-user.md @@ -1,3 +1,4 @@ +--- ms.reviewer: title: How to Revert Extension Points From an App-V 5.0 Package to an App-V 4.6 Package for a Specific User description: How to Revert Extension Points From an App-V 5.0 Package to an App-V 4.6 Package for a Specific User From c84728ed1b80554f95122d0bf9b3d63516b87b34 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:04:58 -0800 Subject: [PATCH 050/209] Update how-to-use-an-app-v-46-sp1-application-from-an-app-v-50-application.md --- ...e-an-app-v-46-sp1-application-from-an-app-v-50-application.md | 1 + 1 file changed, 1 insertion(+) diff --git a/mdop/appv-v5/how-to-use-an-app-v-46-sp1-application-from-an-app-v-50-application.md b/mdop/appv-v5/how-to-use-an-app-v-46-sp1-application-from-an-app-v-50-application.md index c265b6155e..0345a45113 100644 --- a/mdop/appv-v5/how-to-use-an-app-v-46-sp1-application-from-an-app-v-50-application.md +++ b/mdop/appv-v5/how-to-use-an-app-v-46-sp1-application-from-an-app-v-50-application.md @@ -1,3 +1,4 @@ +--- ms.reviewer: title: How to Use an App-V 4.6 Application From an App-V 5.0 Application description: How to Use an App-V 4.6 Application From an App-V 5.0 Application From 0608a8238ce20350dc63edba9bed665b5078f178 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:05:48 -0800 Subject: [PATCH 051/209] Update manage-settings-app-with-group-policy.md --- .../client-management/manage-settings-app-with-group-policy.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/client-management/manage-settings-app-with-group-policy.md b/windows/client-management/manage-settings-app-with-group-policy.md index ef2bf77cba..5aced0db2c 100644 --- a/windows/client-management/manage-settings-app-with-group-policy.md +++ b/windows/client-management/manage-settings-app-with-group-policy.md @@ -16,8 +16,7 @@ ms.topic: article - Windows 10, Windows Server 2016 - -# Manage the Settings app with Group Policy +## Manage the Settings app with Group Policy You can now manage the pages that are shown in the Settings app by using Group Policy. This lets you hide specific pages from users. Before Windows 10, version 1703, you could either show everything in the Settings app or hide it completely. To make use of the Settings App group polices on Windows server 2016, install fix [4457127](https://support.microsoft.com/help/4457127/windows-10-update-kb4457127) or a later cumulative update. From c774805958e7b90aadc5943830041a7835c2b035 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:09:41 -0800 Subject: [PATCH 052/209] Update whats-new-in-microsoft-defender-atp.md --- .../whats-new-in-microsoft-defender-atp.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md index 73d6f92070..4ca54961c2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md @@ -27,7 +27,7 @@ The following features are generally available (GA) in the latest release of Mic For more information preview features, see [Preview features](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection). -## November 2019 +## November-December 2019 - [Microsoft Defender ATP for Mac](microsoft-defender-atp-mac.md)
Microsoft Defender ATP for Mac brings the next-generation protection to Mac devices. Core components of the unified endpoint security platform will now be available for Mac devices, including [endpoint detection and response](endpoint-detection-response-mac-preview.md). From 2a771c8e44bec2fa13f795610a79a858c7b1694f Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 2 Dec 2019 12:19:30 -0800 Subject: [PATCH 053/209] Update mac-preferences.md --- .../threat-protection/microsoft-defender-atp/mac-preferences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md index 2481682ec7..c5b8407fc6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-preferences.md @@ -225,7 +225,7 @@ Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, de ||| |:---|:---| -| **Domain** | com.microsoft.wdav | +| **Domain** | `com.microsoft.wdav` | | **Key** | diagnosticLevel | | **Data type** | String | | **Possible values** | optional (default)
required | From 500c0858f69cf9b2be4644da3eff8bf3c3ea8620 Mon Sep 17 00:00:00 2001 From: Tom Bolds Date: Mon, 2 Dec 2019 13:41:09 -0800 Subject: [PATCH 054/209] Changing badly formed comments and correcting capitalization in sample xml The sample xml has a couple of problems that are fixed here. 1. Comments use -- not --- to begin and end. 3 hyphens will cause a parse error. 2. The default values for (Default) and (None) are not capitalized, which doesn't fit with other documentation and tools. --- .../ie11-deploy-guide/what-is-enterprise-mode.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/browsers/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode.md b/browsers/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode.md index 269b2bec06..da309b68cd 100644 --- a/browsers/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode.md +++ b/browsers/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode.md @@ -71,19 +71,19 @@ This is a view of the [raw EMIE v2 schema.xml file](https://gist.github.com/kypf ```xml - + EnterpriseSiteListManager 10586 20150728.135021 - + IE8Enterprise IE11 - default + Default IE11 @@ -92,8 +92,8 @@ This is a view of the [raw EMIE v2 schema.xml file](https://gist.github.com/kypf IE8Enterprise" From 66336fb0984452051e877e8757cdeee311e47936 Mon Sep 17 00:00:00 2001 From: Tom Bolds Date: Mon, 2 Dec 2019 13:59:53 -0800 Subject: [PATCH 055/209] Correcting Schema Attributes section This change fixes 2 issues in the "Schema Attributes" section. 1. This section uses < and > around the attribute names, which is confusing, because that is notation reserved for elements. 2. The description of exclude is a little vague and somewhat misleading. --- .../enterprise-mode-schema-version-1-guidance.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-1-guidance.md b/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-1-guidance.md index ff09fe4405..81e964a54b 100644 --- a/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-1-guidance.md +++ b/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-1-guidance.md @@ -157,13 +157,13 @@ This table includes the attributes used by the Enterprise Mode schema.
- + - - + - +

Windows Debugging Tools for your platform

Required when you run the Crash Analyzer to determine the cause of a computer failure. We recommend that you specify the path of the Windows Debugging Tools at the time that you create the DaRT recovery image. You can download the Windows Debugging Tools here: Download and Install Debugging Tools for Windows.

Required when you run the Crash Analyzer to determine the cause of a computer failure. We recommend that you specify the path of the Windows Debugging Tools at the time that you create the DaRT recovery image. You can download the Windows Debugging Tools here: Download and Install Debugging Tools for Windows.

Optional: Windows symbols files for use with Crash Analyzer

<version>version Specifies the version of the Enterprise Mode Site List. This attribute is supported for the <rules> element. Internet Explorer 11 and Microsoft Edge
<exclude>Specifies the domain or path excluded from applying the behavior and is supported on the <domain> and <path> elements. +excludeSpecifies the domain or path is excluded from applying Enterprise Mode. This attribute is only supported on the <domain> and <path> elements in the <emie> section.

Example

 <emie>
@@ -175,7 +175,7 @@ Where http
 
Internet Explorer 11 and Microsoft Edge
<docMode>docMode Specifies the document mode to apply. This attribute is only supported on <domain> or <path> elements in the <docMode> section.

Example


From e354c4dd2fbaff1c6d45ce0ddb23c75d7b475ff9 Mon Sep 17 00:00:00 2001
From: Teresa-Motiv 
Date: Mon, 2 Dec 2019 15:01:36 -0800
Subject: [PATCH 056/209] Troubleshooting files

---
 .../hololens/hololens-management-overview.md  | 19 ++++
 devices/hololens/hololens-troubleshooting.md  | 91 +++++++++++++++++++
 2 files changed, 110 insertions(+)
 create mode 100644 devices/hololens/hololens-management-overview.md
 create mode 100644 devices/hololens/hololens-troubleshooting.md

diff --git a/devices/hololens/hololens-management-overview.md b/devices/hololens/hololens-management-overview.md
new file mode 100644
index 0000000000..cc052d54b5
--- /dev/null
+++ b/devices/hololens/hololens-management-overview.md
@@ -0,0 +1,19 @@
+---
+title: Update, troubleshoot, or recover HoloLens
+description: 
+author: Teresa-Motiv
+ms.author: v-tea
+ms.date: 11/27/2019
+ms.prod: hololens
+ms.topic: article
+ms.custom: CSSTroubleshooting
+audience: ITPro
+keywords: issues, bug, troubleshoot, fix, help, support, HoloLens
+manager: jarrettr
+appliesto:
+- HoloLens (1st gen)
+- HoloLens 2
+---
+
+# Update, troubleshoot, or recover HoloLens
+
diff --git a/devices/hololens/hololens-troubleshooting.md b/devices/hololens/hololens-troubleshooting.md
new file mode 100644
index 0000000000..3f4cfdc087
--- /dev/null
+++ b/devices/hololens/hololens-troubleshooting.md
@@ -0,0 +1,91 @@
+---
+title: HoloLens troubleshooting
+description: Troubleshooting steps for Microsoft HoloLens.
+author: mattzmsft
+ms.author: mazeller
+ms.date: 11/27/2019
+ms.prod: hololens
+ms.topic: article
+ms.custom: CSSTroubleshooting
+audience: ITPro
+keywords: issues, bug, troubleshoot, fix, help, support, HoloLens
+manager: jarrettr
+appliesto:
+- HoloLens (1st gen)
+- HoloLens 2
+---
+
+# Troubleshooting HoloLens issues
+
+This article describes how to resolve several common HoloLens issues.
+
+## My HoloLens is unresponsive or won’t start
+
+If your HoloLens won't start:
+
+- If the LEDs next to the power button don't light up, or only one LED briefly blinks, you may need to charge your HoloLens.
+- If the LEDs light up when you press the power button but you can't see anything on the displays, hold the power button until all five of the LEDs turn off.
+
+If your HoloLens becomes frozen or unresponsive:
+
+- Turn off your HoloLens by pressing the power button until all five of the LEDs turn themselves off, or for 10 seconds if the LEDs are unresponsive. To start your HoloLens, press the power button again.
+
+If these steps don't work, you can try [recovering your device](hololens-recovery.md).
+
+## Holograms don't look good or are moving around
+
+If your holograms are unstable, jumpy, or don’t look right, try one of these fixes:
+
+- Clean your device visor and make sure that nothing is obstructing the sensors.
+- Make sure that there’s enough light in your room.
+- Try walking around and looking at your surroundings so that HoloLens can scan them more completely.
+- Try running the Calibration app. It calibrates your HoloLens to work best for your eyes. Go to **Settings** > **System** > **Utilities**. Under **Calibration**, select **Open Calibration**.
+
+## HoloLens doesn’t respond to my gestures
+
+To make sure that HoloLens can see your gestures, keep your hand in the gesture frame. The gesture frame extends a couple of feet on either side of you. When HoloLens can see your hand, the cursor changes from a dot to a ring. Learn more about [using gestures](hololens1-basic-usage.md#use-hololens-with-your-hands).
+
+If your environment is too dark, HoloLens might not see your hand, so make sure that there’s enough light.
+
+If your visor has fingerprints or smudges, use the microfiber cleaning cloth that came with the HoloLens to clean your visor gently.
+
+## HoloLens doesn’t respond to my voice commands.
+
+If Cortana isn’t responding to your voice commands, make sure Cortana is turned on. On the All apps list, select **Cortana** > **Menu** > **Notebook** > **Settings** to make changes. To learn more about what you can say, see [Use your voice with HoloLens](hololens-cortana.md).
+
+## I can’t place holograms or see holograms that I previously placed
+
+If HoloLens can’t map or load your space, it enters Limited mode and you won’t be able to place holograms or see holograms that you’ve placed. Here are some things to try:
+
+- Make sure that there’s enough light in your environment so HoloLens can see and map the space.
+- Make sure that you’re connected to a Wi-Fi network. If you’re not connected to Wi-Fi, HoloLens can’t identify and load a known space.
+- If you need to create a new space, connect to Wi-Fi, then restart your HoloLens.
+- To see if the correct space is active, or to manually load a space, go to **Settings** > **System** > **Spaces**.
+- If the correct space is loaded and you’re still having problems, the space may be corrupt. To fix this issue, select the space, then select **Remove**. After you remove the space, HoloLens starts to map your surroundings and create a new space.
+
+## My HoloLens frequently enters Limited mode or shows a “Tracking lost” message
+
+If your device often shows a "Limited mode" or "Tracking lost" message, try the suggestions listed in [My Holograms don't look good or are moving around](#holograms-dont-look-good-or-are-moving-around).
+
+## My HoloLens can’t tell what space I’m in
+
+If your HoloLens can’t identify and load the space you’re in automatically, check the following factors:
+
+- Make sure that you’re connected to Wi-Fi
+- Make sure that there’s plenty of light in the room
+- Make sure that there haven’t been any major changes to the surroundings.
+
+You can also load a space manually or manage your spaces by going to **Settings** > **System** > **Spaces**.
+
+## I’m getting a “low disk space” error
+
+You’ll need to free up some storage space by doing one or more of the following:
+
+- Delete some unused spaces. Go to **Settings** > **System** > **Spaces**, select a space that you no longer need, and then select **Remove**.
+- Remove some of the holograms that you’ve placed.
+- Delete some pictures and videos from the Photos app.
+- Uninstall some apps from your HoloLens. In the **All apps** list, tap and hold the app you want to uninstall, and then select **Uninstall**.
+
+## My HoloLens can’t create a new space
+
+The most likely problem is that you’re running low on storage space. Try one of the [previous tips](#im-getting-a-low-disk-space-error) to free up some disk space.

From 05a54a0cb298c3e73cd07dbd2f38cd49e12597d5 Mon Sep 17 00:00:00 2001
From: Tom Bolds 
Date: Mon, 2 Dec 2019 15:06:50 -0800
Subject: [PATCH 057/209] Correcting samples and deprecated attributes in
 enterprise-mode_schema-version-2-guidance

Correcting the sample xml so that the comments don't break parsing rules. Also, updating the "Default" and "None" captialization to be consistent with our other documentation and tools.

Updating the "Deprecated attributes" section to be more accurate about elements and attributes. Also corrected samples.
---
 ...terprise-mode-schema-version-2-guidance.md | 38 ++++++++++---------
 1 file changed, 21 insertions(+), 17 deletions(-)

diff --git a/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-2-guidance.md b/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-2-guidance.md
index 4bcf595aeb..a321e5a744 100644
--- a/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-2-guidance.md
+++ b/browsers/internet-explorer/ie11-deploy-guide/enterprise-mode-schema-version-2-guidance.md
@@ -46,19 +46,19 @@ The following is an example of the v.2 version of the Enterprise Mode schema.
  
 ```xml
 
-	
+	
 	
 		EnterpriseSitelistManager
 		10240
 		20150728.135021
 	
-  	 
+  	 
 	
 		IE8Enterprise
 		MSEdge
 	
 	
-		default
+		Default
 		IE11
 	
 	
@@ -66,14 +66,15 @@ The following is an example of the v.2 version of the Enterprise Mode schema.
 		IE11
 	
 	
-		default
+		Default
 		IE11
 	
 	  
-		default
-		none
+		Default
+		None
 	  
 		IE8Enterprise"
+		None
 	
 	
 		IE7
@@ -232,26 +233,26 @@ These v.1 version schema attributes have been deprecated in the v.2 version of t
 
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -259,25 +260,28 @@ These v.1 version schema attributes have been deprecated in the v.2 version of t
 
Deprecated attributeNew attributeDeprecated element/attributeNew element Replacement example
<forceCompatView>forceCompatView <compat-mode>Replace <forceCompatView="true"> with <compat-mode>IE7Enterprise</compat-mode>Replace forceCompatView="true" with <compat-mode>IE7Enterprise</compat-mode>
<docMode>docMode <compat-mode>Replace <docMode="IE5"> with <compat-mode>IE5</compat-mode>Replace docMode="IE5" with <compat-mode>IE5</compat-mode>
<doNotTransition>doNotTransition <open-in>Replace <doNotTransition="true"> with <open-in>none</open-in>Replace doNotTransition="true" with <open-in>none</open-in>
<domain> and <path>Replace:
 <emie>
-  <domain exclude="false">contoso.com</domain>
+  <domain>contoso.com</domain>
 </emie>
With:
 <site url="contoso.com"/>
   <compat-mode>IE8Enterprise</compat-mode>
+  <open-in>IE11</open-in>
 </site>
-AND-

Replace:

 <emie>
-  <domain exclude="true">contoso.com
-     <path exclude="false" forceCompatView="true">/about</path>
+  <domain exclude="true" doNotTransition="true">
+    contoso.com
+    <path forceCompatView="true">/about</path>
   </domain>
 </emie>
With:
 <site url="contoso.com/about">
   <compat-mode>IE7Enterprise</compat-mode>
+  <open-in>IE11</open-in>
 </site>
From bd9aad10bc8ca247c6d3b13357e3575a1867286e Mon Sep 17 00:00:00 2001 From: Teresa-Motiv Date: Mon, 2 Dec 2019 15:23:14 -0800 Subject: [PATCH 058/209] TOC update --- devices/hololens/TOC.md | 4 +++- devices/hololens/hololens-management-overview.md | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/devices/hololens/TOC.md b/devices/hololens/TOC.md index 3ee637cb24..0fcc69849c 100644 --- a/devices/hololens/TOC.md +++ b/devices/hololens/TOC.md @@ -52,9 +52,11 @@ ## [Environment considerations for HoloLens](hololens-environment-considerations.md) ## [Spatial mapping on HoloLens](hololens-spaces.md) -# Update and recovery +# Update, troubleshoot, or recover HoloLens +## [Update, troubleshoot, or recover HoloLens](hololens-management-overview.md) ## [Update HoloLens](hololens-update-hololens.md) ## [Manage updates on many HoloLens](hololens-updates.md) +## [Troubleshoot HoloLens](hololens-troubleshooting.md) ## [Restart, reset, or recover](hololens-recovery.md) ## [Known issues](hololens-known-issues.md) ## [Frequently asked questions](hololens-faq.md) diff --git a/devices/hololens/hololens-management-overview.md b/devices/hololens/hololens-management-overview.md index cc052d54b5..fec665220a 100644 --- a/devices/hololens/hololens-management-overview.md +++ b/devices/hololens/hololens-management-overview.md @@ -10,6 +10,7 @@ ms.custom: CSSTroubleshooting audience: ITPro keywords: issues, bug, troubleshoot, fix, help, support, HoloLens manager: jarrettr +ms.localizationpriority: medium appliesto: - HoloLens (1st gen) - HoloLens 2 From 96af29f8036fcb3f8b68bc2396a5c837ef6704e0 Mon Sep 17 00:00:00 2001 From: Teresa-Motiv Date: Mon, 2 Dec 2019 16:29:59 -0800 Subject: [PATCH 059/209] Edits --- devices/hololens/TOC.md | 2 +- devices/hololens/hololens-management-overview.md | 12 ++++++++++++ devices/hololens/hololens-troubleshooting.md | 5 +++-- 3 files changed, 16 insertions(+), 3 deletions(-) diff --git a/devices/hololens/TOC.md b/devices/hololens/TOC.md index 0fcc69849c..823cfce191 100644 --- a/devices/hololens/TOC.md +++ b/devices/hololens/TOC.md @@ -56,8 +56,8 @@ ## [Update, troubleshoot, or recover HoloLens](hololens-management-overview.md) ## [Update HoloLens](hololens-update-hololens.md) ## [Manage updates on many HoloLens](hololens-updates.md) -## [Troubleshoot HoloLens](hololens-troubleshooting.md) ## [Restart, reset, or recover](hololens-recovery.md) +## [Troubleshoot HoloLens](hololens-troubleshooting.md) ## [Known issues](hololens-known-issues.md) ## [Frequently asked questions](hololens-faq.md) diff --git a/devices/hololens/hololens-management-overview.md b/devices/hololens/hololens-management-overview.md index fec665220a..307b2f7f00 100644 --- a/devices/hololens/hololens-management-overview.md +++ b/devices/hololens/hololens-management-overview.md @@ -18,3 +18,15 @@ appliesto: # Update, troubleshoot, or recover HoloLens +The articles in this section help you keep your HoloLens up-to-date and help you resolve any issues that you encounter. + +**In this section** + +| Article | Description | +| --- | --- | +| [Update HoloLens](hololens-update-hololens.md) | Describes how to identify the build number of your device, and how to update your device manually. | +| [Manage updates on many HoloLens](hololens-updates.md) | Describes how to use policies to manage device updates. | +| [Restart, reset, or recover](hololens-recovery.md) | Describes how to restart, reset, or recover a HoloLens device | +| [Troubleshoot HoloLens](hololens-troubleshooting.md) | Describes solutions to common HoloLens problems. | +| [Known issues](hololens-known-issues.md) | Describes known HoloLens issues. | +| [Frequently asked questions](hololens-faq.md) | Provides answers to common questions about HoloLens.| diff --git a/devices/hololens/hololens-troubleshooting.md b/devices/hololens/hololens-troubleshooting.md index 3f4cfdc087..75b91e51f9 100644 --- a/devices/hololens/hololens-troubleshooting.md +++ b/devices/hololens/hololens-troubleshooting.md @@ -1,13 +1,14 @@ --- title: HoloLens troubleshooting -description: Troubleshooting steps for Microsoft HoloLens. +description: Solutions for common HoloLens issues. author: mattzmsft ms.author: mazeller -ms.date: 11/27/2019 +ms.date: 12/02/2019 ms.prod: hololens ms.topic: article ms.custom: CSSTroubleshooting audience: ITPro +ms.localizationpriority: medium keywords: issues, bug, troubleshoot, fix, help, support, HoloLens manager: jarrettr appliesto: From 13857d1240b4d237cc8d6b4ecf696fd83cca3392 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Tue, 3 Dec 2019 10:03:16 +0500 Subject: [PATCH 060/209] Update windows/deployment/update/waas-servicing-differences.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- windows/deployment/update/waas-servicing-differences.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/update/waas-servicing-differences.md b/windows/deployment/update/waas-servicing-differences.md index 80c0b30b04..66ffdd5dd6 100644 --- a/windows/deployment/update/waas-servicing-differences.md +++ b/windows/deployment/update/waas-servicing-differences.md @@ -39,7 +39,7 @@ Windows 10 provided an opportunity to end the era of infinite fragmentation. Wit This helps simplify servicing. Devices with the original Release to Market (RTM) version of a feature release installed could get up to date by installing the most recent LCU. -Windows publishes the new LCU packages for each Windows 10 version (1607, 1709, etc.) on the second Tuesday of each month. This package is classified as a required security update and contains contents from the previous LCU as well as new security, non-security and Internet Explorer 11 (IE11) fixes. It could require a reboot of the device to complete installation of the update. +Windows publishes the new LCU packages for each Windows 10 version (1607, 1709, etc.) on the second Tuesday of each month. This package is classified as a required security update and contains contents from the previous LCU as well as new security, non-security, and Internet Explorer 11 (IE11) fixes. A reboot of the device might be required to complete installation of the update. ![High level cumulative update model](images/servicing-cadence.png) From 3f031b50b36bbfc5011c0809fbcfd52179f2c0c6 Mon Sep 17 00:00:00 2001 From: Deland-Han Date: Tue, 3 Dec 2019 15:31:50 +0800 Subject: [PATCH 061/209] finish --- devices/surface-hub/index.md | 1 + 1 file changed, 1 insertion(+) diff --git a/devices/surface-hub/index.md b/devices/surface-hub/index.md index f60588a000..5c397a9778 100644 --- a/devices/surface-hub/index.md +++ b/devices/surface-hub/index.md @@ -30,6 +30,7 @@ Surface Hub 2S is an all-in-one digital interactive whiteboard, meetings platfor

Behind the design: Surface Hub 2S

What's new in Surface Hub 2S

Operating system essentials

+

Enable Microsoft Whiteboard on Surface Hub

From 772965e98e24f114f152353f4475f68c408ccf45 Mon Sep 17 00:00:00 2001 From: Will Duff Date: Mon, 2 Dec 2019 23:43:22 -0800 Subject: [PATCH 062/209] Update supported languages for HoloLens 2 Removing Spanish (Mexico) from the list of supported languages. I also fixed up a formatting error and changed an incorrect use of "Windows Mixed Reality" to "HoloLens 2" --- devices/hololens/hololens2-language-support.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md index 760880135d..ef5cb54e31 100644 --- a/devices/hololens/hololens2-language-support.md +++ b/devices/hololens/hololens2-language-support.md @@ -29,15 +29,15 @@ HoloLens 2 supports the following languages. This support includes voice command - German (Germany) - Italian (Italy) - Japanese (Japan) -- Spanish (Mexico) - Spanish (Spain) -Windows Mixed Reality is also available in the following languages. However, this support does not include speech commands or dictation features. +HoloLens 2 is also available in the following languages. However, this support does not include speech commands or dictation features. - Chinese Traditional (Taiwan and Hong Kong) - Dutch (Netherlands) - Korean (Korea) -- Changing language or keyboard + +# Changing language or keyboard > [!NOTE] > Your speech and dictation language depends on the Windows display language. From 15005c6452ac7f432707254a80026848198a1688 Mon Sep 17 00:00:00 2001 From: Jeroen Burgerhout Date: Tue, 3 Dec 2019 11:31:56 +0100 Subject: [PATCH 063/209] Update windows-autopilot-requirements.md Added pki.infineon.com to the TPM manufacturers list. --- .../windows-autopilot/windows-autopilot-requirements.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/deployment/windows-autopilot/windows-autopilot-requirements.md b/windows/deployment/windows-autopilot/windows-autopilot-requirements.md index 80be0dc299..e11c96bd77 100644 --- a/windows/deployment/windows-autopilot/windows-autopilot-requirements.md +++ b/windows/deployment/windows-autopilot/windows-autopilot-requirements.md @@ -82,6 +82,7 @@ If the Microsoft Store is not accessible, the AutoPilot process will still conti
Intel- https://ekop.intel.com/ekcertservice
Qualcomm- https://ekcert.spserv.microsoft.com/EKCertificate/GetEKCertificate/v1
AMD- https://ftpm.amd.com/pki/aia +
Infineon- https://pki.infineon.com
## Licensing requirements From 73d69a39b781d7f455feba6a721912d9d1b8221a Mon Sep 17 00:00:00 2001 From: Will Duff Date: Tue, 3 Dec 2019 07:27:41 -0800 Subject: [PATCH 064/209] Use H2 for secondary content --- devices/hololens/hololens2-language-support.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/hololens/hololens2-language-support.md b/devices/hololens/hololens2-language-support.md index ef5cb54e31..31e4077fbc 100644 --- a/devices/hololens/hololens2-language-support.md +++ b/devices/hololens/hololens2-language-support.md @@ -37,7 +37,7 @@ HoloLens 2 is also available in the following languages. However, this support d - Dutch (Netherlands) - Korean (Korea) -# Changing language or keyboard +## Changing language or keyboard > [!NOTE] > Your speech and dictation language depends on the Windows display language. From 082097578e9e6783e92d9f7b57807ee8adf32b18 Mon Sep 17 00:00:00 2001 From: Todd Lyon <19413953+tmlyon@users.noreply.github.com> Date: Tue, 3 Dec 2019 11:33:22 -0800 Subject: [PATCH 065/209] Update hololens2-start.md Added additional information to respond to feedback and consolidate content from known issues section. --- devices/hololens/hololens2-start.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/devices/hololens/hololens2-start.md b/devices/hololens/hololens2-start.md index 75a66d36cf..c4ea1a7468 100644 --- a/devices/hololens/hololens2-start.md +++ b/devices/hololens/hololens2-start.md @@ -59,7 +59,9 @@ HoloLens 2 will walk you through the following steps: ![Connect to Wi-Fi](images/11-network.png) >[!NOTE] -> If you progress past the Wi-Fi step and later realize you need to switch to a different network, you can press the **Volume Down** and **Power** buttons simultaneously to return to this step if you are running an OS version from October 2019 or later. For earlier versions, you may need to restart the device in a location where the Wi-Fi network is not available. +> If you progress past the Wi-Fi step and later need to switch to a different network while still in setup, you can press the **Volume Down** and **Power** buttons simultaneously to return to this step if you are running an OS version from October 2019 or later. For earlier versions, you may need to [reset the device](hololens-recovery.md) or restart it in a location where the Wi-Fi network is not available to prevent it from automatically connecting. +> +> Also note that during HoloLens Setup, there is a credential timeout of 2 minutes. The username/password needs to be entered within 2 minutes otherwise the username field will be automatically cleared. 1. Sign in to your user account. You'll choose between **My work or school owns it** and **I own it**. - When you choose **My work or school owns it**, you sign in with an Azure AD account. If your organization uses Azure AD Premium and has configured automatic MDM enrollment, HoloLens automatically enrolls in MDM. If your organization does not use Azure AD Premium, automatic MDM enrollment isn't available. In that case, you need to [manually enroll HoloLens in device management](hololens-enroll-mdm.md#enroll-through-settings-app). From cfa453d683d48493063fd2a0ce3178a0b85292d2 Mon Sep 17 00:00:00 2001 From: Todd Lyon <19413953+tmlyon@users.noreply.github.com> Date: Tue, 3 Dec 2019 11:35:46 -0800 Subject: [PATCH 066/209] Update hololens-known-issues.md Removed wi-fi information that has been consolidated in hololens2-start.md in my latest PR --- devices/hololens/hololens-known-issues.md | 9 --------- 1 file changed, 9 deletions(-) diff --git a/devices/hololens/hololens-known-issues.md b/devices/hololens/hololens-known-issues.md index 2fa916f8d0..3cb3f43717 100644 --- a/devices/hololens/hololens-known-issues.md +++ b/devices/hololens/hololens-known-issues.md @@ -123,15 +123,6 @@ If your device is still unable to load apps, you can sideload a version of the . We appreciate your patience as we have gone through the process to get this issue resolved, and we look forward to continued working with our community to create successful Mixed Reality experiences. -## Connecting to WiFi - -During HoloLens Setup, there is a credential timeout of 2 minutes. The username/password needs to be entered within 2 minutes otherwise the username field will be automatically cleared. - -We recommend using a Bluetooth keyboard for entering long passwords. - -> [!NOTE] -> If the wrong network is selected during HoloLens Setup, the device will need to be fully reset. Instructions can be found [here.](hololens-restart-recover.md) - ## Device Update - 30 seconds after a new update, the shell may disappear one time. Please perform the **bloom** gesture to resume your session. From a72804b8f1037532e24102588c83e474e82bde7f Mon Sep 17 00:00:00 2001 From: Lily Hou <20214566+lilyhou@users.noreply.github.com> Date: Tue, 3 Dec 2019 18:06:36 -0800 Subject: [PATCH 067/209] Update kiosk-prepare.md Update Automatic logon section with a note --- windows/configuration/kiosk-prepare.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/configuration/kiosk-prepare.md b/windows/configuration/kiosk-prepare.md index a02ff6ba03..714d5fa832 100644 --- a/windows/configuration/kiosk-prepare.md +++ b/windows/configuration/kiosk-prepare.md @@ -97,6 +97,8 @@ In addition to the settings in the table, you may want to set up **automatic log > [!TIP] > You can also configure automatic sign-in [using the Autologon tool from Sysinternals](https://docs.microsoft.com/sysinternals/downloads/autologon). +> [!NOTE] +> If you are also using [Custom Logon](https://docs.microsoft.com/en-us/windows-hardware/customize/enterprise/custom-logon) with HideAutoLogonUI enabled, to avoid a black screen after password expires, we recommend that you consider [setting the password to never expire](https://docs.microsoft.com/en-us/windows-hardware/customize/enterprise/troubleshooting-custom-logon#the-device-displays-a-black-screen-when-a-password-expiration-screen-is-displayed). ## Interactions and interoperability From 1fc01d9c5a453348110b18a7a556689e74aca860 Mon Sep 17 00:00:00 2001 From: Deland-Han Date: Wed, 4 Dec 2019 11:26:35 +0800 Subject: [PATCH 068/209] u --- devices/surface/support-solutions-surface.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/surface/support-solutions-surface.md b/devices/surface/support-solutions-surface.md index 7234366511..b311e28937 100644 --- a/devices/surface/support-solutions-surface.md +++ b/devices/surface/support-solutions-surface.md @@ -20,7 +20,7 @@ ms.audience: itpro # Top support solutions for Surface devices > [!Note] -> **Home users**: This article is only intended for use by IT professionals and technical support agents. If you're looking for help with a problem with your home device, please see [Surface Devices Help](https://support.microsoft.com/products/surface-devices). +> **Home users**: This article is only intended for use by IT professionals and technical support agents, and applies only to Surface devices. If you're looking for help with a problem with your home device, please see [Surface Devices Help](https://support.microsoft.com/products/surface-devices). Microsoft regularly releases both updates and solutions for Surface devices. To ensure your devices can receive future updates, including security updates, it's important to keep your Surface devices updated. For a complete listing of the update history, see [Surface update history](https://www.microsoft.com/surface/support/install-update-activate/surface-update-history) and [Install Surface and Windows updates](https://www.microsoft.com/surface/support/performance-and-maintenance/install-software-updates-for-surface?os=windows-10&=undefined). From af62b4f37900deb799c33d93a3842b2c17487144 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 4 Dec 2019 09:29:17 -0800 Subject: [PATCH 069/209] Update manage-settings-app-with-group-policy.md --- .../manage-settings-app-with-group-policy.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/windows/client-management/manage-settings-app-with-group-policy.md b/windows/client-management/manage-settings-app-with-group-policy.md index 5aced0db2c..97ea145013 100644 --- a/windows/client-management/manage-settings-app-with-group-policy.md +++ b/windows/client-management/manage-settings-app-with-group-policy.md @@ -12,12 +12,13 @@ ms.author: dansimp ms.topic: article --- +# Manage the Settings app with Group Policy + + **Applies to** - Windows 10, Windows Server 2016 -## Manage the Settings app with Group Policy - You can now manage the pages that are shown in the Settings app by using Group Policy. This lets you hide specific pages from users. Before Windows 10, version 1703, you could either show everything in the Settings app or hide it completely. To make use of the Settings App group polices on Windows server 2016, install fix [4457127](https://support.microsoft.com/help/4457127/windows-10-update-kb4457127) or a later cumulative update. From 8285b91ef58c1dda7a7f962a3de7d06719a7e2cb Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 4 Dec 2019 09:30:13 -0800 Subject: [PATCH 070/209] Update iexpress-command-line-options.md --- .../ie11-ieak/iexpress-command-line-options.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md b/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md index 54f7c5ab5e..cd7c730569 100644 --- a/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md +++ b/browsers/internet-explorer/ie11-ieak/iexpress-command-line-options.md @@ -14,11 +14,11 @@ ms.sitesec: library ms.date: 07/27/2017 --- +# IExpress Wizard command-line options **Applies to:** - Windows Server 2008 R2 with SP1 -## IExpress Wizard command-line options Use command-line options with the IExpress Wizard (IExpress.exe) to control your Internet Explorer custom browser package extraction process. These command-line options work with IExpress:
From 48a6e521446a05ed4dd15934de7413540c7b8a9e Mon Sep 17 00:00:00 2001 From: Rona Song <38082753+qrscharmed@users.noreply.github.com> Date: Wed, 4 Dec 2019 10:05:28 -0800 Subject: [PATCH 071/209] Update faq-wd-app-guard.md --- .../windows-defender-application-guard/faq-wd-app-guard.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 8e16e1695e..3c42dc208a 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -91,4 +91,4 @@ Yes, both the Enterprise Resource domains hosted in the cloud and the Domains ca ### Why does my encryption driver break Windows Defender Application Guard? -Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work. \ No newline at end of file +Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work and result in a ERROR_WRITE_PROTECT dialog. From 7c93218359110a50c4f6055cf1cfb5dbcedd0618 Mon Sep 17 00:00:00 2001 From: martyav Date: Wed, 4 Dec 2019 13:21:06 -0500 Subject: [PATCH 072/209] next and last ~30 on list reviewed --- windows/client-management/mdm/applicationcontrol-csp-ddf.md | 4 ++-- .../mdm/enrollmentstatustracking-csp-ddf.md | 4 ++-- .../client-management/mdm/enrollmentstatustracking-csp.md | 3 +-- .../mdm/policy-csp-devicehealthmonitoring.md | 2 +- windows/deployment/update/waas-morenews.md | 2 +- windows/deployment/update/windows-as-a-service.md | 1 + windows/deployment/windows-autopilot/autopilot-faq.md | 4 ++-- .../hello-for-business/hello-cert-trust-validate-pki.md | 2 +- .../hello-for-business/hello-identity-verification.md | 1 + .../hello-for-business/hello-key-trust-validate-pki.md | 3 ++- .../identity-protection/hello-for-business/hello-overview.md | 5 +++-- .../auditing/advanced-security-audit-policy-settings.md | 2 +- .../threat-protection/intelligence/submission-guide.md | 4 ++-- .../threat-protection/microsoft-defender-atp/files.md | 2 +- .../threat-protection/microsoft-defender-atp/user.md | 2 +- .../secpol-advanced-security-audit-policy-settings.md | 2 +- .../select-types-of-rules-to-create.md | 4 ++-- ...how-hardware-based-root-of-trust-helps-protect-windows.md | 2 +- .../get-support-for-security-baselines.md | 2 +- .../security-compliance-toolkit-10.md | 2 +- .../windows-security-baselines.md | 2 +- 21 files changed, 29 insertions(+), 26 deletions(-) diff --git a/windows/client-management/mdm/applicationcontrol-csp-ddf.md b/windows/client-management/mdm/applicationcontrol-csp-ddf.md index 0cd8b04e7c..60449c917c 100644 --- a/windows/client-management/mdm/applicationcontrol-csp-ddf.md +++ b/windows/client-management/mdm/applicationcontrol-csp-ddf.md @@ -1,6 +1,6 @@ --- -title: ApplicationControl CSP -description: ApplicationControl CSP +title: ApplicationControl CSP DDF +description: This topic shows the OMA DM device description framework (DDF) for the **ApplicationControl** configuration service provider. DDF files are used only with OMA DM provisioning XML. ms.author: dansimp ms.topic: article ms.prod: w10 diff --git a/windows/client-management/mdm/enrollmentstatustracking-csp-ddf.md b/windows/client-management/mdm/enrollmentstatustracking-csp-ddf.md index 429bf2fe21..84b5bb69b0 100644 --- a/windows/client-management/mdm/enrollmentstatustracking-csp-ddf.md +++ b/windows/client-management/mdm/enrollmentstatustracking-csp-ddf.md @@ -1,6 +1,6 @@ --- -title: EnrollmentStatusTracking CSP -description: EnrollmentStatusTracking CSP +title: EnrollmentStatusTracking DDF +description: This topic shows the OMA DM device description framework (DDF) for the EnrollmentStatusTracking configuration service provider. DDF files are used only with OMA DM provisioning XML. ms.author: dansimp ms.topic: article ms.prod: w10 diff --git a/windows/client-management/mdm/enrollmentstatustracking-csp.md b/windows/client-management/mdm/enrollmentstatustracking-csp.md index 080db28b5c..5fba2bac07 100644 --- a/windows/client-management/mdm/enrollmentstatustracking-csp.md +++ b/windows/client-management/mdm/enrollmentstatustracking-csp.md @@ -1,6 +1,6 @@ --- title: EnrollmentStatusTracking CSP -description: EnrollmentStatusTracking CSP +description: During Autopilot deployment, you can configure the Enrollment Status Page (ESP) to block the device use until the required apps are installed. ms.author: dansimp ms.topic: article ms.prod: w10 @@ -11,7 +11,6 @@ ms.date: 05/21/2019 # EnrollmentStatusTracking CSP - During Autopilot deployment, you can configure the Enrollment Status Page (ESP) to block the device use until the required apps are installed. You can select the apps that must be installed before using the device. The EnrollmentStatusTracking configuration service provider (CSP) is used by Intune's agents, such as SideCar to configure ESP for blocking the device use until the required Win32 apps are installed. It tracks the installation status of the required policy providers and the apps they install and sends it to ESP, which displays the installation progress message to the user. For more information on ESP, see [Windows Autopilot Enrollment Status page](https://docs.microsoft.com/windows/deployment/windows-autopilot/enrollment-status). ESP uses the EnrollmentStatusTracking CSP along with the DMClient CSP to track the installation of different apps. The EnrollmentStatusTracking CSP tracks Win32 apps installations and DMClient CSP tracks MSI and Universal Windows Platform apps installations. In DMClient CSP, the **FirstSyncStatus/ExpectedMSIAppPackages** and **FirstSyncStatus/ExpectedModernAppPackages** nodes list the apps to track their installation. See [DMClient CSP](dmclient-csp.md) for more information. diff --git a/windows/client-management/mdm/policy-csp-devicehealthmonitoring.md b/windows/client-management/mdm/policy-csp-devicehealthmonitoring.md index 7d8aeb48ed..0a4dde8690 100644 --- a/windows/client-management/mdm/policy-csp-devicehealthmonitoring.md +++ b/windows/client-management/mdm/policy-csp-devicehealthmonitoring.md @@ -1,5 +1,5 @@ --- -title: Policy CSP - TimeLanguageSettings +title: Policy CSP - DeviceHealthMonitoring description: Policy CSP - TimeLanguageSettings ms.author: dansimp ms.topic: article diff --git a/windows/deployment/update/waas-morenews.md b/windows/deployment/update/waas-morenews.md index cbfbcdff46..c7be3666ed 100644 --- a/windows/deployment/update/waas-morenews.md +++ b/windows/deployment/update/waas-morenews.md @@ -1,5 +1,5 @@ --- -title: Windows as a service +title: Windows as a service news & resources ms.prod: w10 ms.topic: article ms.manager: elizapo diff --git a/windows/deployment/update/windows-as-a-service.md b/windows/deployment/update/windows-as-a-service.md index 3acd3f759a..1cec56cb46 100644 --- a/windows/deployment/update/windows-as-a-service.md +++ b/windows/deployment/update/windows-as-a-service.md @@ -14,6 +14,7 @@ manager: laurawi ms.localizationpriority: high ms.collection: M365-modern-desktop --- + # Windows as a service Find the tools and resources you need to help deploy and support Windows as a service in your organization. diff --git a/windows/deployment/windows-autopilot/autopilot-faq.md b/windows/deployment/windows-autopilot/autopilot-faq.md index c97fb6e3bb..e632c0c89a 100644 --- a/windows/deployment/windows-autopilot/autopilot-faq.md +++ b/windows/deployment/windows-autopilot/autopilot-faq.md @@ -1,6 +1,6 @@ --- -title: Windows Autopilot support -ms.reviewer: +title: Windows Autopilot FAQ +ms.reviewer: This topic provides OEMs, partners, administrators, and end-users with answers to some frequently asked questions about deploying Windows 10 with Windows Autopilot. manager: laurawi description: Support information for Windows Autopilot keywords: mdm, setup, windows, windows 10, oobe, manage, deploy, autopilot, ztd, zero-touch, partner, msfb, intune diff --git a/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md b/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md index 2e79df76db..83ef0c61e4 100644 --- a/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md @@ -1,5 +1,5 @@ --- -title: Validate Public Key Infrastructure (Windows Hello for Business) +title: Validate Public Key Infrastructure - certificate trust model (Windows Hello for Business) description: How to Validate Public Key Infrastructure for Windows Hello for Business keywords: identity, PIN, biometric, Hello, passport ms.prod: w10 diff --git a/windows/security/identity-protection/hello-for-business/hello-identity-verification.md b/windows/security/identity-protection/hello-for-business/hello-identity-verification.md index c1a9b60e79..50074d0a29 100644 --- a/windows/security/identity-protection/hello-for-business/hello-identity-verification.md +++ b/windows/security/identity-protection/hello-for-business/hello-identity-verification.md @@ -17,6 +17,7 @@ ms.topic: article localizationpriority: medium ms.date: 05/05/2018 --- + # Windows Hello for Business In Windows 10, Windows Hello for Business replaces passwords with strong two-factor authentication on PCs and mobile devices. This authentication consists of a new type of user credential that is tied to a device and uses a biometric or PIN.
diff --git a/windows/security/identity-protection/hello-for-business/hello-key-trust-validate-pki.md b/windows/security/identity-protection/hello-for-business/hello-key-trust-validate-pki.md index 8845f97509..df1cdd141d 100644 --- a/windows/security/identity-protection/hello-for-business/hello-key-trust-validate-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-key-trust-validate-pki.md @@ -1,5 +1,5 @@ --- -title: Validate Public Key Infrastructure (Windows Hello for Business) +title: Validate Public Key Infrastructure - key trust model (Windows Hello for Business) description: How to Validate Public Key Infrastructure for Windows Hello for Business keywords: identity, PIN, biometric, Hello, passport ms.prod: w10 @@ -16,6 +16,7 @@ localizationpriority: medium ms.date: 08/19/2018 ms.reviewer: --- + # Validate and Configure Public Key Infrastructure **Applies to** diff --git a/windows/security/identity-protection/hello-for-business/hello-overview.md b/windows/security/identity-protection/hello-for-business/hello-overview.md index e5194ab324..30d604bb53 100644 --- a/windows/security/identity-protection/hello-for-business/hello-overview.md +++ b/windows/security/identity-protection/hello-for-business/hello-overview.md @@ -1,6 +1,6 @@ --- -title: Windows Hello for Business (Windows 10) -ms.reviewer: +title: Windows Hello for Business Overview (Windows 10) +ms.reviewer: An overview of Windows Hello for Business description: An overview of Windows Hello for Business keywords: identity, PIN, biometric, Hello, passport ms.prod: w10 @@ -15,6 +15,7 @@ ms.collection: M365-identity-device-management ms.topic: conceptual localizationpriority: medium --- + # Windows Hello for Business Overview **Applies to** diff --git a/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md b/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md index ad2a9abf62..e36022563e 100644 --- a/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md +++ b/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md @@ -2,7 +2,7 @@ title: Advanced security audit policy settings (Windows 10) description: This reference for IT professionals provides information about the advanced audit policy settings that are available in Windows and the audit events that they generate. ms.assetid: 93b28b92-796f-4036-a53b-8b9e80f9f171 -ms.reviewer: +ms.reviewer: This reference for IT professionals provides information about the advanced audit policy settings that are available in Windows and the audit events that they generate. ms.author: dansimp ms.prod: w10 ms.mktglfcycl: deploy diff --git a/windows/security/threat-protection/intelligence/submission-guide.md b/windows/security/threat-protection/intelligence/submission-guide.md index 05e5ab7db4..7b4028fb4a 100644 --- a/windows/security/threat-protection/intelligence/submission-guide.md +++ b/windows/security/threat-protection/intelligence/submission-guide.md @@ -1,7 +1,7 @@ --- -title: How Microsoft identifies malware and potentially unwanted applications -ms.reviewer: +title: Submit files for analysis by Microsoft description: Learn how to submit files to Microsoft for malware analysis, how to track your submissions, and dispute detections. +ms.reviewer: keywords: security, sample submission help, malware file, virus file, trojan file, submit, send to Microsoft, submit a sample, virus, trojan, worm, undetected, doesn’t detect, email microsoft, email malware, I think this is malware, I think it's a virus, where can I send a virus, is this a virus, MSE, doesn’t detect, no signature, no detection, suspect file, MMPC, Microsoft Malware Protection Center, researchers, analyst, WDSI, security intelligence ms.prod: w10 ms.mktglfcycl: secure diff --git a/windows/security/threat-protection/microsoft-defender-atp/files.md b/windows/security/threat-protection/microsoft-defender-atp/files.md index 87b7a01359..6fed85ab8f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/files.md @@ -1,6 +1,6 @@ --- title: File resource type -description: Retrieves top recent alerts. +description: Retrieves information associated with files alerts. keywords: apis, graph api, supported apis, get, alerts, recent search.product: eADQiWindows 10XVcnh ms.prod: w10 diff --git a/windows/security/threat-protection/microsoft-defender-atp/user.md b/windows/security/threat-protection/microsoft-defender-atp/user.md index 78ca770fa9..2729130721 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/user.md +++ b/windows/security/threat-protection/microsoft-defender-atp/user.md @@ -1,5 +1,5 @@ --- -title: File resource type +title: User resource type description: Retrieves top recent alerts. keywords: apis, graph api, supported apis, get, alerts, recent search.product: eADQiWindows 10XVcnh diff --git a/windows/security/threat-protection/security-policy-settings/secpol-advanced-security-audit-policy-settings.md b/windows/security/threat-protection/security-policy-settings/secpol-advanced-security-audit-policy-settings.md index 6112d8f0f9..5836257990 100644 --- a/windows/security/threat-protection/security-policy-settings/secpol-advanced-security-audit-policy-settings.md +++ b/windows/security/threat-protection/security-policy-settings/secpol-advanced-security-audit-policy-settings.md @@ -1,5 +1,5 @@ --- -title: Advanced security audit policy settings (Windows 10) +title: Advanced security audit policy settings in brief (Windows 10) description: Provides information about the advanced security audit policy settings that are available in Windows and the audit events that they generate. ms.assetid: 6BF9A642-DBC3-4101-94A3-B2316C553CE3 ms.reviewer: diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 4a8db44a9f..9633a7cf60 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -1,6 +1,6 @@ --- -title: Select the types of rules to create (Windows 10) -description: Select the types of rules to create. +title: Understand WDAC policy rules and file rules (Windows 10) +description: Windows Defender Application Control (WDAC) provides control over a computer running Windows 10 by using policies that specify whether a driver or application is trusted and can be run. A policy includes *policy rules* that control options. keywords: whitelisting, security, malware ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb ms.prod: w10 diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md index 0f576ccc0f..d91fbb98a5 100644 --- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md +++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md @@ -1,5 +1,5 @@ --- -title: Windows Defender System Guard How a hardware-based root of trust helps protect Windows 10 (Windows 10) +title: How Windows Defender System Guard protect Windows 10 from firmware exploits description: Windows Defender System Guard in Windows 10 uses a hardware-based root of trust to securely protect systems against firmware exploits. ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb ms.reviewer: diff --git a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md index f2f806c37f..6ef956ed10 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md @@ -1,5 +1,5 @@ --- -title: Get support +title: Get support for Windows security baselines description: This article, and the articles it links to, answers frequently asked question on how to get support for Windows baselines, the Security Compliance Toolkit (SCT), and related topics in your organization keywords: virtualization, security, malware ms.prod: w10 diff --git a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md index 10ee86e0c0..d944485086 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md @@ -1,5 +1,5 @@ --- -title: Microsoft Security Compliance Toolkit 1.0 +title: Microsoft Security Compliance Toolkit 1.0 Guide description: This article describes how to use the Security Compliance Toolkit in your organization keywords: virtualization, security, malware ms.prod: w10 diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md index 34891356ab..723c0bfe49 100644 --- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md +++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md @@ -1,5 +1,5 @@ --- -title: Windows security baselines +title: Windows security baselines guide description: This article, and the articles it links to, describe how to use Windows security baselines in your organization keywords: virtualization, security, malware ms.prod: w10 From 4a2bfe237c4a816a7d38b9a17a33d9024365155f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 10:36:50 -0800 Subject: [PATCH 073/209] Update basic-level-windows-diagnostic-events-and-fields-1903.md --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index f7e901603e..0a7d902c59 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -1,6 +1,6 @@ --- description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1903 basic diagnostic events and fields (Windows 10) +title: Windows 10, version 1903 and Windows 10, version 1909 basic diagnostic events and fields (Windows 10) keywords: privacy, telemetry ms.prod: w10 ms.mktglfcycl: manage @@ -17,11 +17,12 @@ ms.date: 04/23/2019 --- -# Windows 10, version 1903 basic level Windows diagnostic events and fields +# Windows 10, version 1903 and Windows 10, version 1909 basic level Windows diagnostic events and fields **Applies to** - Windows 10, version 1903 +- Windows 10, version 1909 The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. From 890fe4cb25cadfcec8b8062f8ea908784510a125 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 10:37:08 -0800 Subject: [PATCH 074/209] Update basic-level-windows-diagnostic-events-and-fields-1903.md --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 0a7d902c59..d4b218b1ee 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/23/2019 +ms.date: 12/04/2019 --- From 15f6be6c32ac01b5a611e2c6f8b6d8c828d6f97d Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 11:29:50 -0800 Subject: [PATCH 075/209] Update TOC.md --- windows/privacy/TOC.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/TOC.md b/windows/privacy/TOC.md index 8e10f74a84..de11fa6d06 100644 --- a/windows/privacy/TOC.md +++ b/windows/privacy/TOC.md @@ -8,7 +8,7 @@ ### [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md) ### [Diagnostic Data Viewer for PowerShell Overview](Microsoft-DiagnosticDataViewer.md) ## Basic level Windows diagnostic data events and fields -### [Windows 10, version 1903 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1903.md) +### [Windows 10, version 1903 and Windows 10, version 1909 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1903.md) ### [Windows 10, version 1809 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1809.md) ### [Windows 10, version 1803 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) ### [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) From 3c93155f0f3c890d8f42aa55e6ffaa0c211203f2 Mon Sep 17 00:00:00 2001 From: Tina Burden Date: Wed, 4 Dec 2019 11:49:52 -0800 Subject: [PATCH 076/209] pencil edits lines 102, 135 --- windows/deployment/windows-autopilot/autopilot-faq.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopilot/autopilot-faq.md b/windows/deployment/windows-autopilot/autopilot-faq.md index e632c0c89a..b527168e97 100644 --- a/windows/deployment/windows-autopilot/autopilot-faq.md +++ b/windows/deployment/windows-autopilot/autopilot-faq.md @@ -99,7 +99,7 @@ A [glossary](#glossary) of abbreviations used in this topic is provided at the e |How do I know that I received Autopilot?|You can tell that you received Windows Autopilot (as in the device received a configuration but has not yet applied it) when you skip the selection page (as seen below), and are immediately taken to a generic or customized sign-in page.| |Windows Autopilot didn’t work, what do I do now?| Questions and actions to assist in troubleshooting: Did a screen not get skipped? Did a user end up as an admin when configured not to? Remember that AAD Admins will be local admins regardless of whether Windows Autopilot is configured to disable local admin Collection information – run licensingdiag.exe and send the .cab (Cabinet file) file that is generated to AutopilotHelp@microsoft.com. If possible, collect an ETL from WPR. Often in these cases, users are not signing into the right AAD tenant, or are creating local user accounts. For a complete list of support options, refer to [Windows Autopilot support](autopilot-support.md). | | If an Administrator makes changes to an existing profile, will the changes take effect on devices that have that profile assigned to them that have already been deployed? |No. Windows Autopilot profiles are not resident on the device. They are downloaded during OOBE, the settings defined at the time are applied. Then, the profile is discarded on the device. If the device is re-imaged or reset, the new profile settings will take effect the next time the device goes through OOBE.| -|What is the experience if a device isn’t registered or if an IT Admin doesn’t configure Windows Autopilot prior to an end user attempting to self-deploy? |If the device isn’t registered, it will not receive the Windows Autopilot experience and the end user will go through normal OOBE. The Windows Autopilot configurations will NOT be applied until the user runs through OOBE again, after registration. If a device is started before an MDM profile is created, the device will go through standard OOBE experience. The IT Admin would then have to manually enrol that device into the MDM, after which—the next time that device is “reset”—it will go through the Windows Autopilot OOBE experience.| +|What is the experience if a device isn’t registered or if an IT Admin doesn’t configure Windows Autopilot prior to an end user attempting to self-deploy? |If the device isn’t registered, it will not receive the Windows Autopilot experience and the end user will go through normal OOBE. The Windows Autopilot configurations will NOT be applied until the user runs through OOBE again, after registration. If a device is started before an MDM profile is created, the device will go through standard OOBE experience. The IT Admin would then have to manually enroll that device into the MDM, after which—the next time that device is “reset”—it will go through the Windows Autopilot OOBE experience.| |What may be a reason why I did not receive a customized sign-in screen during Autopilot? |Tenant branding must be configured in portal.azure.com to receive a customized sign-in experience.| |What happens if a device is registered with Azure AD but does not have an Windows Autopilot profile assigned? |The regular AAD OOBE will occur since no Windows Autopilot profile was assigned to the device.| |How can I collect logs on Autopilot?|The best way to collect logs on Windows Autopilot performance is to collect a Windows Performance Recorder (WPR) trace during OOBE. The XML file (WPRP extension) for this trace may be provided upon request.| @@ -132,7 +132,7 @@ A [glossary](#glossary) of abbreviations used in this topic is provided at the e |------------------|-----------------| |If I wipe the machine and restart, will I still receive Windows Autopilot?|Yes, if the device is still registered for Windows Autopilot and is running Windows 10, version 1703 7B and above releases, it will receive the Windows Autopilot experience.| |Can I harvest the device fingerprint on existing machines?|Yes, if the device is running Windows 10, version 1703 and above, you can harvest device fingerprints for registration. There are no plans to backport the functionality to previous releases and no way to harvest them on pre-Windows 10 Windows 10, version 1703 devices that have not been updated to Windows 10, version 1703.| -|What is Windows 10, version 1703 7B and why does it matter?| Windows 10, version 1703 7B is a Windows 10, version 1703 image bundled with cumulative updates. To receive Autopilot, clients **must** run Windows 10, version 1703 7B or later. These cumulative updates contain a critical fix for Autopilot. Consider the following:

Windows Autopilot will not apply its profiles to the machine unless AAD credentials match the expected AAD tenant. For the Windows 10, version 1703 release, it was assumed that would be determined by the domain name, so the domain name used to register (for example contoso.com) should match the domain name used to sign in (for example user@contoso.com). But what happens if your tenant has multiple domains (for example us.contoso.com, or fr.contoso.com)? Since these domain names do not match, the device will not be configured for Autopilot. However, both domains are part of the same AAD tenant, and as such it was determined the matching scheme was not useful. This was improved upon by making use of the tenant ID. By using the tenant ID, we can determine that if the user signs into a domain with a tenant matching the one they registered with, we can safely consider this to be a match. The fix for this problem already exists in Windows 10, version 1709 and was backported into the Windows 10, version 1703 7B release.

**Key Take-Aways**: When using pre-Windows 10, version 1703 7B clients the user’s domain **must** match the domain they registered with. This functionality is found in Windows 10 version 1709 clients using build >= 16215, and Windows 10, version 1703 clients >= 7B. | +|What is Windows 10, version 1703 7B and why does it matter?| Windows 10, version 1703 7B is a Windows 10, version 1703 image bundled with cumulative updates. To receive Autopilot, clients **must** run Windows 10, version 1703 7B or later. These cumulative updates contain a critical fix for Autopilot. Consider the following:

Windows Autopilot will not apply its profiles to the machine unless AAD credentials match the expected AAD tenant. For the Windows 10, version 1703 release, it was assumed that would be determined by the domain name, so the domain name used to register (for example contoso.com) should match the domain name used to sign in (for example user@contoso.com). But what happens if your tenant has multiple domains (for example us.contoso.com, or fr.contoso.com)? Since these domain names do not match, the device will not be configured for Autopilot. However, both domains are part of the same AAD tenant, and as such it was determined the matching scheme was not useful. This was improved upon by making use of the tenant ID. By using the tenant ID, we can determine that if the user signs into a domain with a tenant matching the one they registered with, we can safely consider this to be a match. The fix for this problem already exists in Windows 10, version 1709 and was backported into the Windows 10, version 1703 7B release.

**Key takeaways**: When using pre-Windows 10, version 1703 7B clients the user’s domain **must** match the domain they registered with. This functionality is found in Windows 10 version 1709 clients using build >= 16215, and Windows 10, version 1703 clients >= 7B. | |What is the impact of not updating to 7B?|See the detailed scenario described directly above.| |Is Windows Autopilot supported on other SKUs, e.g. Surface Hub, HoloLens, Windows Mobile.|No, Windows Autopilot isn’t supported on other SKUs.| |Does Windows Autopilot work after MBR or image re-installation?|Yes.| From 8f282cfaacb93d298582898dfe55aec399383e23 Mon Sep 17 00:00:00 2001 From: Rebecca Agiewich Date: Wed, 4 Dec 2019 14:08:33 -0600 Subject: [PATCH 077/209] Update basic-level-windows-diagnostic-events-and-fields-1903.md --- ...ndows-diagnostic-events-and-fields-1903.md | 46 +++++++++---------- 1 file changed, 23 insertions(+), 23 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index d4b218b1ee..5b796f00ee 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -1470,7 +1470,7 @@ The following fields are available: - **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. - **RunDate** The date that the telemetry run was stated, expressed as a filetime. - **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and therefore is making decisions using up-to-date driver coverage information. - **RunResult** The hresult of the Appraiser telemetry run. - **ScheduledUploadDay** The day scheduled for the upload. - **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. @@ -1679,7 +1679,7 @@ This event sends Windows Insider data from customers participating in improvemen The following fields are available: - **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **DriverTargetRing** Indicates if the device is participating in receiving pre-release drivers and firmware contrent. +- **DriverTargetRing** Indicates if the device is participating in receiving pre-release drivers and firmware content. - **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. - **FlightIds** A list of the different Windows Insider builds on this device. - **FlightingBranchName** The name of the Windows Insider branch currently used by the device. @@ -1936,7 +1936,7 @@ This event sends data about the current user's default preferences for browser a The following fields are available: - **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultApp** The current user's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. - **DefaultBrowserProgId** The ProgramId of the current user's default browser. - **LongDateFormat** The long date format the user has selected. - **ShortDateFormat** The short date format the user has selected. @@ -5136,7 +5136,7 @@ The following fields are available: - **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** Device model as defined in the system bios - **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeeded, failed, etc. - **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) @@ -5242,7 +5242,7 @@ The following fields are available: - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client - **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was canceled, succeeded, or failed - **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough - **FileId** A hash that uniquely identifies a file @@ -5312,7 +5312,7 @@ The following fields are available: - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was canceled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. - **ExtendedErrorCode** The extended error code. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. @@ -5437,7 +5437,7 @@ The following fields are available: - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventScenario** Indicates the purpose of the event (a scan started, succeeded, failed, etc.). - **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". - **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. @@ -5489,7 +5489,7 @@ The following fields are available: - **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. - **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeeded, failed, etc. - **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. - **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. - **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. @@ -5516,7 +5516,7 @@ The following fields are available: ### Microsoft.Windows.SysReset.FlightUninstallCancel -This event indicates the customer has cancelled uninstallation of Windows. +This event indicates the customer has canceled uninstallation of Windows. @@ -6020,7 +6020,7 @@ The following fields are available: - **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). - **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). - **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** An ID that uniquely identifies a group of events. - **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. @@ -6042,7 +6042,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. - **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** ID that uniquely identifies a group of events. - **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. @@ -6064,7 +6064,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. - **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** ID that uniquely identifies a group of events. - **WuId** Windows Update client ID. @@ -6086,7 +6086,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. - **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled - **TestId** A string to uniquely identify a group of events. - **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. @@ -6130,7 +6130,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. - **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. - **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** ID that uniquely identifies a group of events. - **WuId** Windows Update client ID. @@ -6152,7 +6152,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. - **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** A string to uniquely identify a group of events. - **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. @@ -6174,7 +6174,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. - **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** A string to uniquely identify a group of events. - **WuId** Windows Update client ID. @@ -6289,7 +6289,7 @@ The following fields are available: - **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. - **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. - **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. - **TestId** A string to uniquely identify a group of events. - **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. @@ -6331,7 +6331,7 @@ The following fields are available: ### Microsoft.Windows.WERVertical.OSCrash -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. +This event sends binary data from the collected dump file whenever a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. The following fields are available: @@ -6794,12 +6794,12 @@ The following fields are available: - **CatalogId** The Store Catalog ID for the product being installed. - **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. +- **SkuId** Specific edition of the app being updated. ### Microsoft.Windows.StoreAgent.Telemetry.StateTransition -Products in the process of being fulfilled (installed or updated) are maintained in a list. This event is sent any time there is a change in a product's fulfillment status (pending, working, paused, cancelled, or complete), to help keep Windows up to date and secure. +Products in the process of being fulfilled (installed or updated) are maintained in a list. This event is sent any time there is a change in a product's fulfillment status (pending, working, paused, canceled, or complete), to help keep Windows up to date and secure. The following fields are available: @@ -7178,7 +7178,7 @@ The following fields are available: - **detectionBlockreason** The reason detection did not complete. - **detectionRetryMode** Indicates whether we will try to scan again. - **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was canceled, succeeded, or failed. - **flightID** The specific ID of the Windows Insider build the device is getting. - **interactive** Indicates whether the session was user initiated. - **networkStatus** Error info @@ -7216,7 +7216,7 @@ This event indicates the reboot was postponed due to needing a display. The following fields are available: - **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was canceled, succeeded, or failed. - **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. - **revisionNumber** Revision number of the update. - **updateId** Update ID. @@ -7311,7 +7311,7 @@ The following fields are available: - **batteryLevel** Current battery capacity in mWh or percentage left. - **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. +- **errorCode** The error code represented by a hexadecimal value. - **eventScenario** End-to-end update session ID. - **flightID** The ID of the Windows Insider build the device is getting. - **flightUpdate** Indicates whether the update is a Windows Insider build. From 4c2097664d1725546d53913cf9fe600c291b7970 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 12:18:36 -0800 Subject: [PATCH 078/209] Update basic-level-windows-diagnostic-events-and-fields-1903.md --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 5b796f00ee..53f31463eb 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -5137,7 +5137,7 @@ The following fields are available: - **DeviceModel** Device model as defined in the system bios - **EventInstanceID** A globally unique identifier for event instance - **EventScenario** Indicates the purpose of the event - whether because scan started, succeeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **EventType** Possible values are "Child", "Bundle", "Release" or "Driver". - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content @@ -5275,7 +5275,7 @@ The following fields are available: - **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" - **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any - **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **PowerState** Indicates the power state of the device at the time of heartbeat (DC, AC, Battery Saver, or Connected Standby) - **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one - **ResumeCount** Number of times this active download has resumed from a suspended state - **RevisionNumber** Identifies the revision number of this specific piece of content From 829518231530b07e242958f59826afdbfe49fdb6 Mon Sep 17 00:00:00 2001 From: Rona Song <38082753+qrscharmed@users.noreply.github.com> Date: Wed, 4 Dec 2019 12:18:59 -0800 Subject: [PATCH 079/209] Update faq-wd-app-guard.md --- .../windows-defender-application-guard/faq-wd-app-guard.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 3c42dc208a..dcf479c507 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -91,4 +91,4 @@ Yes, both the Enterprise Resource domains hosted in the cloud and the Domains ca ### Why does my encryption driver break Windows Defender Application Guard? -Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work and result in a ERROR_WRITE_PROTECT dialog. +Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work and result in a 0x80070013 ERROR_WRITE_PROTECT dialog. From 87e97ad26c54f427a2308ca760b9907180a72f7e Mon Sep 17 00:00:00 2001 From: Thomas Raya Date: Wed, 4 Dec 2019 12:26:45 -0800 Subject: [PATCH 080/209] Corrected Spelling Error --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 53f31463eb..824be067b1 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -667,7 +667,7 @@ The following fields are available: - **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? - **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? - **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsDismissAction** Will the file cause an action that can be dismissed? - **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. - **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? - **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. From 8260d535de2858544e6cae3c5ef8c919c25a04ef Mon Sep 17 00:00:00 2001 From: martyav Date: Wed, 4 Dec 2019 15:45:32 -0500 Subject: [PATCH 081/209] fixed missing headlines in 4 items --- .../client-management/img-boot-sequence.md | 6 ++--- .../additional-mitigations.md | 22 +++++++++---------- .../machineactionsnote.md | 2 ++ .../microsoft-defender-atp/prerelease.md | 2 ++ 4 files changed, 18 insertions(+), 14 deletions(-) diff --git a/windows/client-management/img-boot-sequence.md b/windows/client-management/img-boot-sequence.md index e0d86a8a23..dbcd186131 100644 --- a/windows/client-management/img-boot-sequence.md +++ b/windows/client-management/img-boot-sequence.md @@ -1,6 +1,6 @@ --- -description: A full-sized view of the boot sequence flowchart. title: Boot sequence flowchart +description: A full-sized view of the boot sequence flowchart. ms.date: 11/16/2018 ms.reviewer: manager: dansimp @@ -10,8 +10,8 @@ ms.topic: article ms.prod: w10 --- +# Boot sequence flowchart + Return to: [Advanced troubleshooting for Windows boot problems](advanced-troubleshooting-boot-problems.md)
- ![Full-sized boot sequence flowchart](images/boot-sequence.png) - diff --git a/windows/security/identity-protection/credential-guard/additional-mitigations.md b/windows/security/identity-protection/credential-guard/additional-mitigations.md index 63a6a403c2..d42dc24268 100644 --- a/windows/security/identity-protection/credential-guard/additional-mitigations.md +++ b/windows/security/identity-protection/credential-guard/additional-mitigations.md @@ -16,15 +16,15 @@ ms.date: 08/17/2017 ms.reviewer: --- -## Additional mitigations +# Additional mitigations Windows Defender Credential Guard can provide mitigations against attacks on derived credentials and prevent the use of stolen credentials elsewhere. However, PCs can still be vulnerable to certain attacks, even if the derived credentials are protected by Windows Defender Credential Guard. These attacks can include abusing privileges and use of derived credentials directly from a compromised device, re-using previously stolen credentials prior to Windows Defender Device Guard, and abuse of management tools and weak application configurations. Because of this, additional mitigations also must be deployed to make the domain environment more robust. -### Restricting domain users to specific domain-joined devices +## Restricting domain users to specific domain-joined devices Credential theft attacks allow the attacker to steal secrets from one device and use them from another device. If a user can sign on to multiple devices then any device could be used to steal credentials. How do you ensure that users only sign on using devices that have Windows Defender Credential Guard enabled? By deploying authentication policies that restrict them to specific domain-joined devices that have been configured with Windows Defender Credential Guard. For the domain controller to know what device a user is signing on from, Kerberos armoring must be used. -#### Kerberos armoring +### Kerberos armoring Kerberos armoring is part of RFC 6113. When a device supports Kerberos armoring, its TGT is used to protect the user's proof of possession which can mitigate offline dictionary attacks. Kerberos armoring also provides the additional benefit of signed KDC errors this mitigates tampering which can result in things such as downgrade attacks. @@ -34,7 +34,7 @@ Kerberos armoring is part of RFC 6113. When a device supports Kerberos armoring, - All the domain controllers in these domains must be configured to support Kerberos armoring. Set the **KDC support for claims, compound authentication, and Kerberos armoring** Group Policy setting to either **Supported** or **Always provide claims**. - All the devices with Windows Defender Credential Guard that the users will be restricted to must be configured to support Kerberos armoring. Enable the **Kerberos client support for claims, compound authentication and Kerberos armoring** Group Policy settings under **Computer Configuration** -> **Administrative Templates** -> **System** -> **Kerberos**. -#### Protecting domain-joined device secrets +### Protecting domain-joined device secrets Since domain-joined devices also use shared secrets for authentication, attackers can steal those secrets as well. By deploying device certificates with Windows Defender Credential Guard, the private key can be protected. Then authentication policies can require that users sign on devices that authenticate using those certificates. This prevents shared secrets stolen from the device to be used with stolen user credentials to sign on as the user. @@ -46,7 +46,7 @@ Domain-joined device certificate authentication has the following requirements: - Windows 10 devices have the CA issuing the domain controller certificates in the enterprise store. - A process is established to ensure the identity and trustworthiness of the device in a similar manner as you would establish the identity and trustworthiness of a user before issuing them a smartcard. -##### Deploying domain-joined device certificates +#### Deploying domain-joined device certificates To guarantee that certificates with the required issuance policy are only installed on the devices these users must use, they must be deployed manually on each device. The same security procedures used for issuing smart cards to users should be applied to device certificates. @@ -78,7 +78,7 @@ CertReq -EnrollCredGuardCert MachineAuthentication > [!NOTE] > You must restart the device after enrolling the machine authentication certificate.   -##### How a certificate issuance policy can be used for access control +#### How a certificate issuance policy can be used for access control Beginning with the Windows Server 2008 R2 domain functional level, domain controllers support for authentication mechanism assurance provides a way to map certificate issuance policy OIDs to universal security groups. Windows Server 2012 domain controllers with claim support can map them to claims. To learn more about authentication mechanism assurance, see [Authentication Mechanism Assurance for AD DS in Windows Server 2008 R2 Step-by-Step Guide](https://technet.microsoft.com/library/dd378897(v=ws.10).aspx) on TechNet. @@ -100,7 +100,7 @@ Beginning with the Windows Server 2008 R2 domain functional level, domain contro .\set-IssuancePolicyToGroupLink.ps1 –IssuancePolicyName:"" –groupOU:"" –groupName:”" ``` -#### Restricting user sign on +### Restricting user sign on So we now have completed the following: @@ -129,17 +129,17 @@ Authentication policies have the following requirements: > [!NOTE] > When the authentication policy enforces policy restrictions, users will not be able to sign on using devices that do not have a certificate with the appropriate issuance policy deployed. This applies to both local and remote sign on scenarios. Therefore, it is strongly recommended to first only audit policy restrictions to ensure you don't have unexpected failures. -##### Discovering authentication failures due to authentication policies +#### Discovering authentication failures due to authentication policies To make tracking authentication failures due to authentication policies easier, an operational log exists with just those events. To enable the logs on the domain controllers, in Event Viewer, navigate to **Applications and Services Logs\\Microsoft\\Windows\\Authentication, right-click AuthenticationPolicyFailures-DomainController**, and then click **Enable Log**. To learn more about authentication policy events, see [Authentication Policies and Authentication Policy Silos](https://technet.microsoft.com/library/dn486813(v=ws.11).aspx). -### Appendix: Scripts +## Appendix: Scripts Here is a list of scripts mentioned in this topic. -#### Get the available issuance policies on the certificate authority +### Get the available issuance policies on the certificate authority Save this script file as get-IssuancePolicy.ps1. @@ -330,7 +330,7 @@ write-host "There are no issuance policies which are not mapped to groups" > [!NOTE] > If you're having trouble running this script, try replacing the single quote after the ConvertFrom-StringData parameter.   -#### Link an issuance policy to a group +### Link an issuance policy to a group Save the script file as set-IssuancePolicyToGroupLink.ps1. diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md index 551174a844..e414790f9e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md @@ -10,5 +10,7 @@ ms.prod: w10 title: Note --- +# Perform a Machine Action via the Microsoft Defender ATP API + >[!Note] > This page focuses on performing a machine action via API. See [take response actions on a machine](respond-machine-alerts.md) for more information about response actions functionality via Microsoft Defender ATP. diff --git a/windows/security/threat-protection/microsoft-defender-atp/prerelease.md b/windows/security/threat-protection/microsoft-defender-atp/prerelease.md index eb022df5f7..da7e3816d2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/prerelease.md +++ b/windows/security/threat-protection/microsoft-defender-atp/prerelease.md @@ -10,5 +10,7 @@ ms.prod: w10 title: "Prerelease" --- +# Microsoft Defender ATP Pre-release Disclaimer + > [!IMPORTANT] > Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. From 2b09ca8cddd76153cdd61ca13856cd5b3593c4b9 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 4 Dec 2019 12:57:09 -0800 Subject: [PATCH 082/209] Update faq-wd-app-guard.md --- .../windows-defender-application-guard/faq-wd-app-guard.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index dcf479c507..0684b674b2 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -8,7 +8,7 @@ ms.pagetype: security ms.localizationpriority: medium author: denisebmsft ms.author: deniseb -ms.date: 03/28/2019 +ms.date: 12/04/2019 ms.reviewer: manager: dansimp ms.custom: asr @@ -51,7 +51,7 @@ Currently, the Application Guard Edge session doesn't support Extensions. Howeve ### How do I configure Windows Defender Application Guard to work with my network proxy (IP-Literal Addresses)? -Windows Defender Application Guard requires proxies to have a symbolic name, not just an IP address. IP-Literal proxy settings such as `192.168.1.4:81` can be annotated as `itproxy:81` or using a record such as `P19216810010` for a proxy with an IP address of `192.168.100.10`. This applies to Windows 10 Enterprise edition, 1709 or higher. These would be for the proxy policies under Network Isolation in Group Policy or Intune. +Windows Defender Application Guard requires proxies to have a symbolic name, not just an IP address. IP-Literal proxy settings such as `192.168.1.4:81` can be annotated as `itproxy:81` or using a record such as `P19216810010` for a proxy with an IP address of `192.168.100.10`. This applies to Windows 10 Enterprise edition 1709 or higher. These would be for the proxy policies under Network Isolation in Group Policy or Intune. ### Which Input Method Editors (IME) in 19H1 are not supported? @@ -91,4 +91,4 @@ Yes, both the Enterprise Resource domains hosted in the cloud and the Domains ca ### Why does my encryption driver break Windows Defender Application Guard? -Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work and result in a 0x80070013 ERROR_WRITE_PROTECT dialog. +Windows Defender Application Guard accesses files from a VHD mounted on the host that needs to be written during setup. If an encryption driver prevents a VHD from being mounted or from being written to, WDAG will not work and result in an error message ("0x80070013 ERROR_WRITE_PROTECT"). From 23c8379ab83c4b3852642c4c7f5e3fd7ecc6aeb0 Mon Sep 17 00:00:00 2001 From: martyav Date: Wed, 4 Dec 2019 16:02:28 -0500 Subject: [PATCH 083/209] removed extra title metadata tags --- .../microsoft-defender-atp/machineactionsnote.md | 1 - .../threat-protection/microsoft-defender-atp/prerelease.md | 1 - 2 files changed, 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md index e414790f9e..23f85143c5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md @@ -7,7 +7,6 @@ manager: dansimp ms.author: macapara author: mjcaparas ms.prod: w10 -title: Note --- # Perform a Machine Action via the Microsoft Defender ATP API diff --git a/windows/security/threat-protection/microsoft-defender-atp/prerelease.md b/windows/security/threat-protection/microsoft-defender-atp/prerelease.md index da7e3816d2..7d769b0dd4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/prerelease.md +++ b/windows/security/threat-protection/microsoft-defender-atp/prerelease.md @@ -7,7 +7,6 @@ manager: dansimp ms.author: macapara author: mjcaparas ms.prod: w10 -title: "Prerelease" --- # Microsoft Defender ATP Pre-release Disclaimer From 2875fefef8a79df853fae93b4a78051d5177a885 Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Wed, 4 Dec 2019 13:42:14 -0800 Subject: [PATCH 084/209] Update kiosk-prepare.md --- windows/configuration/kiosk-prepare.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/kiosk-prepare.md b/windows/configuration/kiosk-prepare.md index 714d5fa832..aaa526a014 100644 --- a/windows/configuration/kiosk-prepare.md +++ b/windows/configuration/kiosk-prepare.md @@ -98,7 +98,7 @@ In addition to the settings in the table, you may want to set up **automatic log > You can also configure automatic sign-in [using the Autologon tool from Sysinternals](https://docs.microsoft.com/sysinternals/downloads/autologon). > [!NOTE] -> If you are also using [Custom Logon](https://docs.microsoft.com/en-us/windows-hardware/customize/enterprise/custom-logon) with HideAutoLogonUI enabled, to avoid a black screen after password expires, we recommend that you consider [setting the password to never expire](https://docs.microsoft.com/en-us/windows-hardware/customize/enterprise/troubleshooting-custom-logon#the-device-displays-a-black-screen-when-a-password-expiration-screen-is-displayed). +> If you are also using [Custom Logon](https://docs.microsoft.com/windows-hardware/customize/enterprise/custom-logon) with **HideAutoLogonUI** enabled, you might experience a black screen after a password expires. We recommend that you consider [setting the password to never expire](https://docs.microsoft.com/windows-hardware/customize/enterprise/troubleshooting-custom-logon#the-device-displays-a-black-screen-when-a-password-expiration-screen-is-displayed). ## Interactions and interoperability From 1a3163d419aa3033907213155a881d62b7788b24 Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Wed, 4 Dec 2019 13:54:43 -0800 Subject: [PATCH 085/209] Update system-guard-secure-launch-and-smm-protection.md copyedit --- .../system-guard-secure-launch-and-smm-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md index 7f4a831eaa..5b92c4240f 100644 --- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md +++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md @@ -55,7 +55,7 @@ Click **Start** > **Settings** > **Update & Security** > **Windows Security** > ![Secure Launch Registry](images/secure-launch-registry.png) > [!IMPORTANT] -> If the system guard is enabled as a registry key, then standard hardware security is not available for the Intel i5 7200U processor. +> If System Guard is enabled with a registry key, standard hardware security is not available for the Intel i5 7200U processor. ## How to verify System Guard Secure Launch is configured and running From 5fe7595a3c5e7850de53155df4dc1a418be19870 Mon Sep 17 00:00:00 2001 From: martyav Date: Wed, 4 Dec 2019 17:55:13 -0500 Subject: [PATCH 086/209] first 13 on list reviewed --- .../threat-protection/microsoft-defender-atp/ti-indicator.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md index 1c38ae5395..28e3bd225c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md +++ b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md @@ -32,7 +32,7 @@ Method|Return Type |Description For more information on creating indicators, see [Manage indicators](manage-indicators.md). -# Properties +## Properties Property | Type | Description :---|:---|:--- indicatorValue | String | Identity of the [Indicator](ti-indicator.md) entity. From 2f5f8f955f89c3b6d4a595615c15639f2167a80f Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Wed, 4 Dec 2019 14:56:14 -0800 Subject: [PATCH 087/209] Update bitlocker-management-for-enterprises.md --- .../bitlocker/bitlocker-management-for-enterprises.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md index a42be4d4dc..2314ea2eaf 100644 --- a/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md +++ b/windows/security/information-protection/bitlocker/bitlocker-management-for-enterprises.md @@ -131,7 +131,7 @@ Enable-BitLocker -MountPoint "C:" -EncryptionMethod XtsAes256 -UsedSpaceOnly -Pi [Shielded VMs and Guarded Fabric](https://blogs.technet.microsoft.com/windowsserver/2016/05/10/a-closer-look-at-shielded-vms-in-windows-server-2016/) -**Powershell** +**PowerShell** [BitLocker cmdlets for Windows PowerShell](bitlocker-use-bitlocker-drive-encryption-tools-to-manage-bitlocker.md#bitlocker-cmdlets-for-windows-powershell) From 04a1fd478c089aa8e6030142a1456d7b27b03c87 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 15:49:22 -0800 Subject: [PATCH 088/209] Update windows-diagnostic-data.md --- windows/privacy/windows-diagnostic-data.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/privacy/windows-diagnostic-data.md b/windows/privacy/windows-diagnostic-data.md index a8f66dc068..492e4b91b7 100644 --- a/windows/privacy/windows-diagnostic-data.md +++ b/windows/privacy/windows-diagnostic-data.md @@ -19,6 +19,7 @@ ms.reviewer: # Windows 10, version 1709 and newer diagnostic data for the Full level Applies to: +- Windows 10, version 1909 - Windows 10, version 1903 - Windows 10, version 1809 - Windows 10, version 1803 From 7c382f644edd352c48c1b237d4ccaea4e4604f9d Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 4 Dec 2019 16:06:45 -0800 Subject: [PATCH 089/209] Update windows-diagnostic-data.md --- windows/privacy/windows-diagnostic-data.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/windows-diagnostic-data.md b/windows/privacy/windows-diagnostic-data.md index 492e4b91b7..310a62342c 100644 --- a/windows/privacy/windows-diagnostic-data.md +++ b/windows/privacy/windows-diagnostic-data.md @@ -12,7 +12,7 @@ ms.author: dansimp manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 04/15/2019 +ms.date: 12/04/2019 ms.reviewer: --- From c0a33e1e9a9ab6186fbd4fcc14726d01c5edcc50 Mon Sep 17 00:00:00 2001 From: Gary Moore Date: Wed, 4 Dec 2019 16:21:47 -0800 Subject: [PATCH 090/209] Corrected "peformances", reported by Acrolinx --- windows/privacy/windows-diagnostic-data.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/windows-diagnostic-data.md b/windows/privacy/windows-diagnostic-data.md index 310a62342c..85c77ad883 100644 --- a/windows/privacy/windows-diagnostic-data.md +++ b/windows/privacy/windows-diagnostic-data.md @@ -249,7 +249,7 @@ This type of data includes details about the health of the device, operating sys [Pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example: - Data about the reliability of content that appears in the [Windows Spotlight](https://docs.microsoft.com/windows/configuration/windows-spotlight) (rotating lock screen images) is used for Windows Spotlight reliability investigations. -- Timing data about how quickly Cortana responds to voice commands is used to improve Cortana listening peformance. +- Timing data about how quickly Cortana responds to voice commands is used to improve Cortana listening performance. - Timing data about how quickly the facial recognition feature starts up and finishes is used to improve facial recognition performance. - Data about when an Application Window fails to appear is used to investigate issues with Application Window reliability and performance. From a8878e1d0fc002172601e3705ac4bbc072f142e8 Mon Sep 17 00:00:00 2001 From: Deland-Han Date: Thu, 5 Dec 2019 09:23:46 +0800 Subject: [PATCH 091/209] update --- devices/surface-hub/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/surface-hub/index.md b/devices/surface-hub/index.md index 5c397a9778..e4fa9986f3 100644 --- a/devices/surface-hub/index.md +++ b/devices/surface-hub/index.md @@ -30,7 +30,7 @@ Surface Hub 2S is an all-in-one digital interactive whiteboard, meetings platfor

Behind the design: Surface Hub 2S

What's new in Surface Hub 2S

Operating system essentials

-

Enable Microsoft Whiteboard on Surface Hub

+

Enable Microsoft Whiteboard on Surface Hub

From 5d0b9f8b9b257dfbec746b1dee09cc294aeb5e3c Mon Sep 17 00:00:00 2001 From: Sarah Cooley Date: Wed, 4 Dec 2019 19:33:59 -0800 Subject: [PATCH 092/209] Minor HoloLens TOC fix there was a double entry in the TOC --- devices/hololens/TOC.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/devices/hololens/TOC.md b/devices/hololens/TOC.md index 3ee637cb24..e7dbd1f876 100644 --- a/devices/hololens/TOC.md +++ b/devices/hololens/TOC.md @@ -16,7 +16,7 @@ ## [Install localized version of HoloLens (1st gen)](hololens1-install-localized.md) ## [Getting around HoloLens (1st gen)](hololens1-basic-usage.md) -# Get started with HoloLens in commercial environments +# HoloLens in commercial environments ## [Commercial feature overview](hololens-commercial-features.md) ## [Deployment planning](hololens-requirements.md) ## [Unlock Windows Holographic for Business features](hololens1-upgrade-enterprise.md) @@ -54,7 +54,6 @@ # Update and recovery ## [Update HoloLens](hololens-update-hololens.md) -## [Manage updates on many HoloLens](hololens-updates.md) ## [Restart, reset, or recover](hololens-recovery.md) ## [Known issues](hololens-known-issues.md) ## [Frequently asked questions](hololens-faq.md) From 245d8fa397f7867aca26d5dd41943a07e889a353 Mon Sep 17 00:00:00 2001 From: illfated Date: Thu, 5 Dec 2019 04:59:40 +0100 Subject: [PATCH 093/209] USMT/XML General Conventions: fix example typo Description: As suggested in issue ticket #5603 (USMT XML Ref typo - File.txt => file].txt), the example filename should contain the aforementioned bracket that this section is all about, as well as preferably use the same case (lowercase) as the directly following XML code. Thanks to ChadMcCaffery for reporting this typo. Changes proposed: - add the missing example bracket character - convert the filename "File" to lowercase "file" - add bold text for the filename to be more visible issue ticket closure or reference: Closes #5603 --- windows/deployment/usmt/usmt-general-conventions.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/usmt/usmt-general-conventions.md b/windows/deployment/usmt/usmt-general-conventions.md index 2bffb25cd7..3439d25d7a 100644 --- a/windows/deployment/usmt/usmt-general-conventions.md +++ b/windows/deployment/usmt/usmt-general-conventions.md @@ -50,7 +50,7 @@ Before you modify the .xml files, become familiar with the following guidelines: - **File names with brackets** - If you are migrating a file that has a bracket character (\[ or \]) in the file name, you must insert a carat (^) character directly before the bracket for the bracket character to be valid. For example, if there is a file named File.txt, you must specify `c:\documents\mydocs [file^].txt]` instead of `c:\documents\mydocs [file].txt]`. + If you are migrating a file that has a bracket character (\[ or \]) in the file name, you must insert a carat (^) character directly before the bracket for the bracket character to be valid. For example, if there is a file named **file].txt**, you must specify `c:\documents\mydocs [file^].txt]` instead of `c:\documents\mydocs [file].txt]`. - **Using quotation marks** From 456111a2c3da230dd2fb9469a95d818615343b8d Mon Sep 17 00:00:00 2001 From: illfated Date: Thu, 5 Dec 2019 12:44:21 +0100 Subject: [PATCH 094/209] Configure DC Certificates: Subject Name tab text Description: As reported and shown in issue ticket #5600 (Update text). one of the tabs in Properties of New Template is referred to as Subject, whereas the actual tab name is "Subject Name" in the doc page. Thanks to Rami (drunkrhin0) for reporting this discrepancy. Proposed change: - add the word Name to the "On the **Subject** tab" text (2x) issue ticket closure or reference: Closes #5600 --- .../hello-for-business/hello-cert-trust-validate-pki.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md b/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md index 83ef0c61e4..e0c4077f94 100644 --- a/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md +++ b/windows/security/identity-protection/hello-for-business/hello-cert-trust-validate-pki.md @@ -69,7 +69,7 @@ Sign-in to a certificate authority or management workstations with _Domain Admin 4. On the **Compatibility** tab, clear the **Show resulting changes** check box. Select **Windows Server 2008 R2** from the **Certification Authority** list. Select **Windows 7.Server 2008 R2** from the **Certification Recipient** list. 5. On the **General** tab, type **Domain Controller Authentication (Kerberos)** in Template display name. Adjust the validity and renewal period to meet your enterprise’s needs. **Note**If you use different template names, you’ll need to remember and substitute these names in different portions of the lab. -6. On the **Subject** tab, select the **Build from this Active Directory information** button if it is not already selected. Select **None** from the **Subject name format** list. Select **DNS name** from the **Include this information in alternate subject** list. Clear all other items. +6. On the **Subject Name** tab, select the **Build from this Active Directory information** button if it is not already selected. Select **None** from the **Subject name format** list. Select **DNS name** from the **Include this information in alternate subject** list. Clear all other items. 7. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list. Click **OK**. 8. Close the console. @@ -104,7 +104,7 @@ Sign-in to a certificate authority or management workstations with _Domain Admin 5. On the **General** tab, type **Internal Web Server** in **Template display name**. Adjust the validity and renewal period to meet your enterprise’s needs. **Note:** If you use different template names, you’ll need to remember and substitute these names in different portions of the lab. 6. On the **Request Handling** tab, select **Allow private key to be exported**. -7. On the **Subject** tab, select the **Supply in the request** button if it is not already selected. +7. On the **Subject Name** tab, select the **Supply in the request** button if it is not already selected. 8. On the **Security** tab, Click **Add**. Type **Domain Computers** in the **Enter the object names to select** box. Click **OK**. Select the **Allow** check box next to the **Enroll** permission. 9. On the **Cryptography** tab, select **Key Storage Provider** from the **Provider Category** list. Select **RSA** from the **Algorithm name** list. Type **2048** in the **Minimum key size** text box. Select **SHA256** from the **Request hash** list. Click **OK**. 10. Close the console. From 98f72e32916cbd438c2f9469244d3e398eeaa592 Mon Sep 17 00:00:00 2001 From: John Kaiser <35939694+CoveMiner@users.noreply.github.com> Date: Thu, 5 Dec 2019 07:47:26 -0800 Subject: [PATCH 095/209] Update surface-hub-2s-recover-reset.md Updates a procedure per customer feedback. --- devices/surface-hub/surface-hub-2s-recover-reset.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/devices/surface-hub/surface-hub-2s-recover-reset.md b/devices/surface-hub/surface-hub-2s-recover-reset.md index 414456c4f3..b10fd8367e 100644 --- a/devices/surface-hub/surface-hub-2s-recover-reset.md +++ b/devices/surface-hub/surface-hub-2s-recover-reset.md @@ -9,7 +9,7 @@ ms.author: greglin manager: laurawi audience: Admin ms.topic: article -ms.date: 06/20/2019 +ms.date: 12/05/2019 ms.localizationpriority: Medium --- @@ -38,13 +38,15 @@ New in Surface Hub 2S, you can now reinstall the device using a recovery image. Surface Hub 2S lets you reinstall the device using a recovery image, which allows you to reinstall the device to factory settings if you lost the Bitlocker key or no longer have admin credentials to the Settings app. 1. Begin with a USB 3.0 drive with 8 GB or 16 GB of storage, formatted as FAT32. -2. Download recovery image from the [Surface Recovery website](https://support.microsoft.com/en-us/surfacerecoveryimage?devicetype=surfacehub2s) onto the USB drive and connect it to any USB-C or USB A port on Surface Hub 2S. -3. Turn off the device. While holding down the Volume down button, press the Power button. Keep holding both buttons until you see the Windows logo. Release the Power button but continue to hold the Volume until the Install UI begins. +2. From a separate PC, download the .zip file recovery image from the [Surface Recovery website](https://support.microsoft.com/en-us/surfacerecoveryimage?devicetype=surfacehub2s) and then return to these instructions. +3. Unzip the downloaded file onto the root of the USB drive. +4. Connect the USB drive to any USB-C or USB-A port on Surface Hub 2S. +5. Turn off the device. While holding down the Volume down button, press the Power button. Keep holding both buttons until you see the Windows logo. Release the Power button but continue to hold the Volume until the Install UI begins. ![*Use Volume down and power buttons to initiate recovery*](images/sh2-keypad.png)
-4. In the language selection screen, select the display language for your Surface Hub 2S. -5. Choose **Recover from a drive** and **Fully clean the drive** and then select **Recover**. If prompted for a BitLocker key, select **Skip this drive**. Surface Hub 2S reboots several times and takes approximately 30 minutes to complete the recovery process. +6. In the language selection screen, select the display language for your Surface Hub 2S. +7. Choose **Recover from a drive** and **Fully clean the drive** and then select **Recover**. If prompted for a BitLocker key, select **Skip this drive**. Surface Hub 2S reboots several times and takes approximately 30 minutes to complete the recovery process. Remove the USB drive when the first time setup screen appears. ## Recover a locked Surface Hub From 1de10320f13284052e19bf3aac402ae229269a90 Mon Sep 17 00:00:00 2001 From: Tina Burden Date: Thu, 5 Dec 2019 08:23:41 -0800 Subject: [PATCH 096/209] pencil edit line 41 --- devices/surface-hub/surface-hub-2s-recover-reset.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/surface-hub/surface-hub-2s-recover-reset.md b/devices/surface-hub/surface-hub-2s-recover-reset.md index b10fd8367e..5c28202363 100644 --- a/devices/surface-hub/surface-hub-2s-recover-reset.md +++ b/devices/surface-hub/surface-hub-2s-recover-reset.md @@ -38,7 +38,7 @@ New in Surface Hub 2S, you can now reinstall the device using a recovery image. Surface Hub 2S lets you reinstall the device using a recovery image, which allows you to reinstall the device to factory settings if you lost the Bitlocker key or no longer have admin credentials to the Settings app. 1. Begin with a USB 3.0 drive with 8 GB or 16 GB of storage, formatted as FAT32. -2. From a separate PC, download the .zip file recovery image from the [Surface Recovery website](https://support.microsoft.com/en-us/surfacerecoveryimage?devicetype=surfacehub2s) and then return to these instructions. +2. From a separate PC, download the .zip file recovery image from the [Surface Recovery website](https://support.microsoft.com/surfacerecoveryimage?devicetype=surfacehub2s) and then return to these instructions. 3. Unzip the downloaded file onto the root of the USB drive. 4. Connect the USB drive to any USB-C or USB-A port on Surface Hub 2S. 5. Turn off the device. While holding down the Volume down button, press the Power button. Keep holding both buttons until you see the Windows logo. Release the Power button but continue to hold the Volume until the Install UI begins. From c173a2494f4f94396cdecf2b324377a73a2a796f Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Thu, 5 Dec 2019 08:29:12 -0800 Subject: [PATCH 097/209] Update planning-to-create-the-dart-10-recovery-image.md --- mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md index 494b6c080a..7089ba0bff 100644 --- a/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md +++ b/mdop/dart-v10/planning-to-create-the-dart-10-recovery-image.md @@ -49,7 +49,7 @@ The following items are required or recommended for creating the DaRT recovery i

Windows Debugging Tools for your platform

-

Required when you run the Crash Analyzer to determine the cause of a computer failure. We recommend that you specify the path of the Windows Debugging Tools at the time that you create the DaRT recovery image. You can download the Windows Debugging Tools here: Download and Install Debugging Tools for Windows.

+

Required when you run the Crash Analyzer to determine the cause of a computer failure. We recommend that you specify the path of the Windows Debugging Tools at the time that you create the DaRT recovery image. You can download the Windows Debugging Tools here: Download and Install Debugging Tools for Windows.

Optional: Windows symbols files for use with Crash Analyzer

From b0b08e807efb3923cf9c746d8e8df4907ecba119 Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Thu, 5 Dec 2019 08:34:17 -0800 Subject: [PATCH 098/209] Update hololens2-start.md --- devices/hololens/hololens2-start.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/devices/hololens/hololens2-start.md b/devices/hololens/hololens2-start.md index c4ea1a7468..805956cc37 100644 --- a/devices/hololens/hololens2-start.md +++ b/devices/hololens/hololens2-start.md @@ -58,10 +58,10 @@ HoloLens 2 will walk you through the following steps: HoloLens sets your time zone automatically based on information obtained from the Wi-Fi network. After setup finishes, you can change the time zone by using the Settings app. ![Connect to Wi-Fi](images/11-network.png) ->[!NOTE] +> [!NOTE] > If you progress past the Wi-Fi step and later need to switch to a different network while still in setup, you can press the **Volume Down** and **Power** buttons simultaneously to return to this step if you are running an OS version from October 2019 or later. For earlier versions, you may need to [reset the device](hololens-recovery.md) or restart it in a location where the Wi-Fi network is not available to prevent it from automatically connecting. > -> Also note that during HoloLens Setup, there is a credential timeout of 2 minutes. The username/password needs to be entered within 2 minutes otherwise the username field will be automatically cleared. +> Also note that during HoloLens Setup, there is a credential timeout of 2 minutes. The username/password needs to be entered within two minutes otherwise the username field will be automatically cleared. 1. Sign in to your user account. You'll choose between **My work or school owns it** and **I own it**. - When you choose **My work or school owns it**, you sign in with an Azure AD account. If your organization uses Azure AD Premium and has configured automatic MDM enrollment, HoloLens automatically enrolls in MDM. If your organization does not use Azure AD Premium, automatic MDM enrollment isn't available. In that case, you need to [manually enroll HoloLens in device management](hololens-enroll-mdm.md#enroll-through-settings-app). From b416d3373c6d0c806e2cff763ee5a59f3cb0dbc6 Mon Sep 17 00:00:00 2001 From: Daniel Simpson Date: Thu, 5 Dec 2019 08:35:22 -0800 Subject: [PATCH 099/209] Update hololens2-start.md --- devices/hololens/hololens2-start.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/hololens/hololens2-start.md b/devices/hololens/hololens2-start.md index 805956cc37..3f7c1fe6ae 100644 --- a/devices/hololens/hololens2-start.md +++ b/devices/hololens/hololens2-start.md @@ -61,7 +61,7 @@ HoloLens 2 will walk you through the following steps: > [!NOTE] > If you progress past the Wi-Fi step and later need to switch to a different network while still in setup, you can press the **Volume Down** and **Power** buttons simultaneously to return to this step if you are running an OS version from October 2019 or later. For earlier versions, you may need to [reset the device](hololens-recovery.md) or restart it in a location where the Wi-Fi network is not available to prevent it from automatically connecting. > -> Also note that during HoloLens Setup, there is a credential timeout of 2 minutes. The username/password needs to be entered within two minutes otherwise the username field will be automatically cleared. +> Also note that during HoloLens Setup, there is a credential timeout of two minutes. The username/password needs to be entered within two minutes otherwise the username field will be automatically cleared. 1. Sign in to your user account. You'll choose between **My work or school owns it** and **I own it**. - When you choose **My work or school owns it**, you sign in with an Azure AD account. If your organization uses Azure AD Premium and has configured automatic MDM enrollment, HoloLens automatically enrolls in MDM. If your organization does not use Azure AD Premium, automatic MDM enrollment isn't available. In that case, you need to [manually enroll HoloLens in device management](hololens-enroll-mdm.md#enroll-through-settings-app). From 91df85f689793d166333c8bda8ac13b62fcdd71a Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:47:33 -0800 Subject: [PATCH 100/209] Update manage-windows-1809-endpoints.md --- windows/privacy/manage-windows-1809-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1809-endpoints.md b/windows/privacy/manage-windows-1809-endpoints.md index 2f2f90b82d..0436f58954 100644 --- a/windows/privacy/manage-windows-1809-endpoints.md +++ b/windows/privacy/manage-windows-1809-endpoints.md @@ -15,7 +15,7 @@ ms.topic: article ms.date: 6/26/2018 ms.reviewer: --- -# Manage connection endpoints for Windows 10, version 1809 +# Manage connection endpoints for Windows 10 Enterprise, version 1809 **Applies to** From 41f6cd6859005a508260e354b67cdcb08989d0c1 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:47:58 -0800 Subject: [PATCH 101/209] Update manage-windows-1803-endpoints.md --- windows/privacy/manage-windows-1803-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1803-endpoints.md b/windows/privacy/manage-windows-1803-endpoints.md index c8c4bffe0c..e395bbf711 100644 --- a/windows/privacy/manage-windows-1803-endpoints.md +++ b/windows/privacy/manage-windows-1803-endpoints.md @@ -15,7 +15,7 @@ ms.topic: article ms.date: 6/26/2018 ms.reviewer: --- -# Manage connection endpoints for Windows 10, version 1803 +# Manage connection endpoints for Windows 10 Enterprise, version 1803 **Applies to** From d426248aec698310efc1b64d41d65a61c06eb82a Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:48:24 -0800 Subject: [PATCH 102/209] Update manage-windows-1709-endpoints.md --- windows/privacy/manage-windows-1709-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1709-endpoints.md b/windows/privacy/manage-windows-1709-endpoints.md index 4f007d6da6..b5c4c83bb2 100644 --- a/windows/privacy/manage-windows-1709-endpoints.md +++ b/windows/privacy/manage-windows-1709-endpoints.md @@ -1,5 +1,5 @@ --- -title: Connection endpoints for Windows 10, version 1709 +title: Connection endpoints for Windows 10 Enterprise, version 1709 description: Explains what Windows 10 endpoints are used for, how to turn off traffic to them, and the impact. keywords: privacy, manage connections to Microsoft, Windows 10, Windows Server 2016 ms.prod: w10 From ee1a03d777819c9d7cf420d49ae71b88442309b7 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:49:06 -0800 Subject: [PATCH 103/209] Update manage-windows-1709-endpoints.md --- windows/privacy/manage-windows-1709-endpoints.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/manage-windows-1709-endpoints.md b/windows/privacy/manage-windows-1709-endpoints.md index b5c4c83bb2..90b65b7419 100644 --- a/windows/privacy/manage-windows-1709-endpoints.md +++ b/windows/privacy/manage-windows-1709-endpoints.md @@ -15,11 +15,11 @@ ms.topic: article ms.date: 6/26/2018 ms.reviewer: --- -# Manage connection endpoints for Windows 10, version 1709 +# Manage connection endpoints for Windows 10 Enterprise, version 1709 **Applies to** -- Windows 10, version 1709 +- Windows 10 Enterprise, version 1709 Some Windows components, app, and related services transfer data to Microsoft network endpoints. Some examples include: From 6dedfc36b77fe6151cf992837ec60d84c9c38b10 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:50:30 -0800 Subject: [PATCH 104/209] Update manage-windows-1809-endpoints.md --- windows/privacy/manage-windows-1809-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1809-endpoints.md b/windows/privacy/manage-windows-1809-endpoints.md index 0436f58954..3d3c54d452 100644 --- a/windows/privacy/manage-windows-1809-endpoints.md +++ b/windows/privacy/manage-windows-1809-endpoints.md @@ -19,7 +19,7 @@ ms.reviewer: **Applies to** -- Windows 10, version 1809 +- Windows 10 Enterprise, version 1809 Some Windows components, app, and related services transfer data to Microsoft network endpoints. Some examples include: From a5b87dca42192863a6cc17ef2b5e014a7e1fab39 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 5 Dec 2019 08:50:58 -0800 Subject: [PATCH 105/209] Update manage-windows-1803-endpoints.md --- windows/privacy/manage-windows-1803-endpoints.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-windows-1803-endpoints.md b/windows/privacy/manage-windows-1803-endpoints.md index e395bbf711..30b8437669 100644 --- a/windows/privacy/manage-windows-1803-endpoints.md +++ b/windows/privacy/manage-windows-1803-endpoints.md @@ -19,7 +19,7 @@ ms.reviewer: **Applies to** -- Windows 10, version 1803 +- Windows 10 Enterprise, version 1803 Some Windows components, app, and related services transfer data to Microsoft network endpoints. Some examples include: From 245fc1ee61ec32489cc9dc05e85e76b8a1d069bf Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 5 Dec 2019 10:05:09 -0800 Subject: [PATCH 106/209] updated info about edition downgrades --- windows/deployment/upgrade/windows-10-upgrade-paths.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/windows/deployment/upgrade/windows-10-upgrade-paths.md b/windows/deployment/upgrade/windows-10-upgrade-paths.md index c5cc2c3ba1..d234cf0008 100644 --- a/windows/deployment/upgrade/windows-10-upgrade-paths.md +++ b/windows/deployment/upgrade/windows-10-upgrade-paths.md @@ -22,9 +22,11 @@ ms.topic: article ## Upgrade paths -This topic provides a summary of available upgrade paths to Windows 10. You can upgrade to Windows 10 from Windows 7 or a later operating system. This includes upgrading from one release of Windows 10 to later release of Windows 10. Migrating from one edition of Windows 10 to a different edition of the same release is also supported. For more information about migrating to a different edition of Windows 10, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). +This topic provides a summary of available upgrade paths to Windows 10. You can upgrade to Windows 10 from Windows 7 or a later operating system. This includes upgrading from one release of Windows 10 to later release of Windows 10. Migrating from one edition of Windows 10 to a different edition of the same release is also supported. -> **Windows 10 version upgrade**: You can directly upgrade any semi-annual channel version of Windows 10 to a newer, supported semi-annual channel version of Windows 10, even if it involves skipping versions. Work with your account representative if your current version of Windows is out of support. See the [Windows lifecycle fact sheet](https://support.microsoft.com/help/13853/windows-lifecycle-fact-sheet) for availability and service information. +If you are also migrating to a different edition of Windows, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). Methods and supported paths are described on this page to change the edition of Windows. These methods require that you input a license or product key for the new Windows edition prior to starting the upgade process. Edition downgrade is also supported for some paths, but please note that applications and settings are not maintained when the new Windows edition is a downgrade. + +> **Windows 10 version upgrade**: You can directly upgrade any semi-annual channel version of Windows 10 to a newer, supported semi-annual channel version of Windows 10, even if it involves skipping versions. Work with your account representative if your current version of Windows is out of support. See the [Windows lifecycle fact sheet](https://support.microsoft.com/help/13853/windows-lifecycle-fact-sheet) for availability and service information. > > **Windows 10 LTSC/LTSB**: Due to [naming changes](https://docs.microsoft.com/windows/deployment/update/waas-overview#naming-changes), product versions that display Windows 10 LTSB will be replaced with Windows 10 LTSC in subsequent feature updates. The term LTSC is used here to refer to all long term servicing versions. > From 0b66853e7dfcd3cfdc8cac9385eccce37b98b15e Mon Sep 17 00:00:00 2001 From: ShrCaJesmo <54860945+ShrCaJesmo@users.noreply.github.com> Date: Thu, 5 Dec 2019 13:23:50 -0500 Subject: [PATCH 107/209] Update white-glove.md From testing, this seems to be the tech flow behavior regarding software deployment - additionally, the behavior we've seen is that the green screen appears once enrollment is done, not once everything is applied - this means the screen can go green but the reseal button won't appear until configuration and install is complete. Without ESP, the device enrolls, the screen goes green, the reseal button appears, but launching a command prompt and exploring the disk validates software didn't install. With ESP, the screen goes green within the same period, but there's a 20 minute delay after that before the reseal button appears - in this scenario, at reseal, the software is installed as expected. Mostly just trying to get this behavior documented if it's correct, but if it's incorrect, some clarification on the software install behavior during tech flow would be good, because the expectation that software will install during the technician flow seems to not be consistent and this is the only reason I could find from the documentation that explains the behavior we're seeing. --- windows/deployment/windows-autopilot/white-glove.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index 7aacf56861..9fd9e87869 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -96,6 +96,9 @@ If the pre-provisioning process completes successfully: ![white-glove-result](images/white-glove-result.png) - Click **Reseal** to shut the device down. At that point, the device can be shipped to the end user. +>[!NOTE] +>Technician Flow inherits behavior from [Self-Deploying Mode](self-deploying.md). Per the Self-Deploying Mode documentation, it leverages the Enrollment Status Page to hold the device in a provisioning state and prevent the user from proceeding to the desktop after enrollment but before software and configuration is done applying. As such, if Enrollment Status Page is disabled, the reseal button may appear before software and configuration is done applying letting you proceed to the user flow before technician flow provisioning is complete. The green screen validates that enrollment was successful, not that the technician flow is necessarily complete. + If the pre-provisioning process fails: - A red status screen will be displayed with information about the device, including the same details presented previously (e.g. Autopilot profile, organization name, assigned user, QR code), as well as the elapsed time for the pre-provisioning steps. - Diagnostic logs can be gathered from the device, and then it can be reset to start the process over again. From c95d1323601d1ba70d9892040cf3677cd9a95dc0 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 5 Dec 2019 10:24:01 -0800 Subject: [PATCH 108/209] add not --- .../microsoft-defender-atp/respond-file-alerts.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md index 34d1296ea7..b7fa2c549d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md @@ -78,6 +78,10 @@ This action takes effect on machines with Windows 10, version 1703 or later, whe - **Alerts** - click the corresponding links from the Description or Details in the Artifact timeline - **Search box** - select **File** from the drop–down menu and enter the file name + + >[!NOTE] + >The stop and quarantine file action is limited to a maximum of 1000 machines. To stop a file on a larger number of machines, see [Add indicator to block or allow file](#add-indicator-to-block-or-allow-a-file). + 2. Go to the top bar and select **Stop and Quarantine File**. ![Image of stop and quarantine file action](images/atp-stop-quarantine-file.png) From beea9c4b7df1f2b6dc32f455ca0aa837e8b167c2 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 5 Dec 2019 11:16:53 -0800 Subject: [PATCH 109/209] wording --- windows/deployment/upgrade/windows-10-upgrade-paths.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/upgrade/windows-10-upgrade-paths.md b/windows/deployment/upgrade/windows-10-upgrade-paths.md index d234cf0008..f59df85741 100644 --- a/windows/deployment/upgrade/windows-10-upgrade-paths.md +++ b/windows/deployment/upgrade/windows-10-upgrade-paths.md @@ -24,7 +24,7 @@ ms.topic: article This topic provides a summary of available upgrade paths to Windows 10. You can upgrade to Windows 10 from Windows 7 or a later operating system. This includes upgrading from one release of Windows 10 to later release of Windows 10. Migrating from one edition of Windows 10 to a different edition of the same release is also supported. -If you are also migrating to a different edition of Windows, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). Methods and supported paths are described on this page to change the edition of Windows. These methods require that you input a license or product key for the new Windows edition prior to starting the upgade process. Edition downgrade is also supported for some paths, but please note that applications and settings are not maintained when the new Windows edition is a downgrade. +If you are also migrating to a different edition of Windows, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). Methods and supported paths are described on this page to change the edition of Windows. These methods require that you input a license or product key for the new Windows edition prior to starting the upgade process. Edition downgrade is also supported for some paths, but please note that applications and settings are not maintained when the Windows edition is downgraded. > **Windows 10 version upgrade**: You can directly upgrade any semi-annual channel version of Windows 10 to a newer, supported semi-annual channel version of Windows 10, even if it involves skipping versions. Work with your account representative if your current version of Windows is out of support. See the [Windows lifecycle fact sheet](https://support.microsoft.com/help/13853/windows-lifecycle-fact-sheet) for availability and service information. > From 1c19dca8710d02e2a4c90feb8daf2a57cb33da6e Mon Sep 17 00:00:00 2001 From: Tina Burden Date: Thu, 5 Dec 2019 11:25:15 -0800 Subject: [PATCH 110/209] pencil edit line 27 --- windows/deployment/upgrade/windows-10-upgrade-paths.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/upgrade/windows-10-upgrade-paths.md b/windows/deployment/upgrade/windows-10-upgrade-paths.md index f59df85741..37da456194 100644 --- a/windows/deployment/upgrade/windows-10-upgrade-paths.md +++ b/windows/deployment/upgrade/windows-10-upgrade-paths.md @@ -24,7 +24,7 @@ ms.topic: article This topic provides a summary of available upgrade paths to Windows 10. You can upgrade to Windows 10 from Windows 7 or a later operating system. This includes upgrading from one release of Windows 10 to later release of Windows 10. Migrating from one edition of Windows 10 to a different edition of the same release is also supported. -If you are also migrating to a different edition of Windows, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). Methods and supported paths are described on this page to change the edition of Windows. These methods require that you input a license or product key for the new Windows edition prior to starting the upgade process. Edition downgrade is also supported for some paths, but please note that applications and settings are not maintained when the Windows edition is downgraded. +If you are also migrating to a different edition of Windows, see [Windows 10 edition upgrade](windows-10-edition-upgrades.md). Methods and supported paths are described on this page to change the edition of Windows. These methods require that you input a license or product key for the new Windows edition prior to starting the upgrade process. Edition downgrade is also supported for some paths, but please note that applications and settings are not maintained when the Windows edition is downgraded. > **Windows 10 version upgrade**: You can directly upgrade any semi-annual channel version of Windows 10 to a newer, supported semi-annual channel version of Windows 10, even if it involves skipping versions. Work with your account representative if your current version of Windows is out of support. See the [Windows lifecycle fact sheet](https://support.microsoft.com/help/13853/windows-lifecycle-fact-sheet) for availability and service information. > From 478a21c7607787ce7344a88c85dde147573b4dd3 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 5 Dec 2019 11:27:03 -0800 Subject: [PATCH 111/209] typo --- windows/deployment/planning/windows-10-deprecated-features.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/planning/windows-10-deprecated-features.md b/windows/deployment/planning/windows-10-deprecated-features.md index 6def761bdb..72439c1132 100644 --- a/windows/deployment/planning/windows-10-deprecated-features.md +++ b/windows/deployment/planning/windows-10-deprecated-features.md @@ -28,7 +28,7 @@ The features described below are no longer being actively developed, and might b | Hyper-V vSwitch on LBFO | In a future release, the Hyper-V vSwitch will no longer have the capability to be bound to an LBFO team. Instead, it can be bound via [Switch Embedded Teaming](https://docs.microsoft.com/windows-server/virtualization/hyper-v-virtual-switch/rdma-and-switch-embedded-teaming#bkmk_sswitchembedded) (SET).| 1909 | | Language Community tab in Feedback Hub | The Language Community tab will be removed from the Feedback Hub. The standard feedback process: [Feedback Hub - Feedback](feedback-hub://?newFeedback=true&feedbackType=2) is the recommended way to provide translation feedback. | 1909 | | My People / People in the Shell | My People is no longer being developed. It may be removed in a future update. | 1909 | -| TFS1/TFS2 IME | TSF1 and TSF2 IME will be replaced by TSF3 IME in a future release. [Text Services Framework](https://docs.microsoft.com/windows/win32/tsf/what-is-text-services-framework) (TSF) enables language technologies. TSF IME are Windows components that you can add to enable typing text for Japanese, Simplified Chinese, Traditional Chinese, and Korean languages. ​| 1909 | +| TSF1/TSF2 IME | TSF1 and TSF2 IME will be replaced by TSF3 IME in a future release. [Text Services Framework](https://docs.microsoft.com/windows/win32/tsf/what-is-text-services-framework) (TSF) enables language technologies. TSF IME are Windows components that you can add to enable typing text for Japanese, Simplified Chinese, Traditional Chinese, and Korean languages. ​| 1909 | | Package State Roaming (PSR) | PSR will be removed in a future update. PSR allows non-Microsoft developers to access roaming data on devices, enabling developers of UWP applications to write data to Windows and synchronize it to other instantiations of Windows for that user.
 
The recommended replacement for PSR is [Azure App Service](https://docs.microsoft.com/azure/app-service/). Azure App Service is widely supported, well documented, reliable, and supports cross-platform/cross-ecosystem scenarios such as iOS, Android and web. | 1909 | | XDDM-based remote display driver | Starting with this release, the Remote Desktop Services uses a Windows Display Driver Model (WDDM) based Indirect Display Driver (IDD) for a single session remote desktop. The support for Windows 2000 Display Driver Model (XDDM) based remote display drivers will be removed in a future release. Independent Software Vendors that use an XDDM-based remote display driver should plan a migration to the WDDM driver model. For more information about implementing a remote indirect display driver, ISVs can reach out to [rdsdev@microsoft.com](mailto:rdsdev@microsoft.com). | 1903 | | Taskbar settings roaming | Roaming of taskbar settings is no longer being developed and we plan to remove this capability in a future release. | 1903 | From 07a3a7f16664142a3ad8822f577ec4474fd5a994 Mon Sep 17 00:00:00 2001 From: David Strome Date: Thu, 5 Dec 2019 12:15:10 -0800 Subject: [PATCH 112/209] Update kiosk-prepare.md --- windows/configuration/kiosk-prepare.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/configuration/kiosk-prepare.md b/windows/configuration/kiosk-prepare.md index a02ff6ba03..aaa526a014 100644 --- a/windows/configuration/kiosk-prepare.md +++ b/windows/configuration/kiosk-prepare.md @@ -97,6 +97,8 @@ In addition to the settings in the table, you may want to set up **automatic log > [!TIP] > You can also configure automatic sign-in [using the Autologon tool from Sysinternals](https://docs.microsoft.com/sysinternals/downloads/autologon). +> [!NOTE] +> If you are also using [Custom Logon](https://docs.microsoft.com/windows-hardware/customize/enterprise/custom-logon) with **HideAutoLogonUI** enabled, you might experience a black screen after a password expires. We recommend that you consider [setting the password to never expire](https://docs.microsoft.com/windows-hardware/customize/enterprise/troubleshooting-custom-logon#the-device-displays-a-black-screen-when-a-password-expiration-screen-is-displayed). ## Interactions and interoperability From 85f99e778796c448ee8d33faa3c71e8e9b6d634c Mon Sep 17 00:00:00 2001 From: John Liu <49762389+ShenLanJohn@users.noreply.github.com> Date: Thu, 5 Dec 2019 12:17:34 -0800 Subject: [PATCH 113/209] CAT Auto Pulish for Windows Release Messages - CAT_AutoPublish_20191205113840 (#1653) --- ...olved-issues-windows-10-1809-and-windows-server-2019.yml | 4 ++-- .../release-information/resolved-issues-windows-10-1903.yml | 4 ---- windows/release-information/status-windows-10-1903.yml | 6 ++++-- windows/release-information/status-windows-10-1909.yml | 2 +- 4 files changed, 7 insertions(+), 9 deletions(-) diff --git a/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml b/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml index 5e8590a6eb..f6351c2c0b 100644 --- a/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml +++ b/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml @@ -1,10 +1,10 @@ ### YamlMime:YamlDocument documentType: LandingData -title: Resolved issues in Windows 10 version 1809 & Windows Server 2019 +title: Resolved issues in Windows 10, version 1809 and Windows Server 2019 metadata: document_id: - title: Resolved issues in Windows 10 version 1809 and Windows Server 2019 + title: Resolved issues in Windows 10, version 1809 and Windows Server 2019 description: Resolved issues in Windows 10, version 1809 or Windows Server 2019 keywords: ["Resolved issues in Windows 10", "Windows 10", "Windows 10 1809"] ms.localizationpriority: high diff --git a/windows/release-information/resolved-issues-windows-10-1903.yml b/windows/release-information/resolved-issues-windows-10-1903.yml index 89f8b611f6..5a608fbd84 100644 --- a/windows/release-information/resolved-issues-windows-10-1903.yml +++ b/windows/release-information/resolved-issues-windows-10-1903.yml @@ -60,9 +60,7 @@ sections:
Error attempting to update with external USB device or memory card attached
PCs with an external USB device or SD memory card attached may get error: \"This PC can't be upgraded to Windows 10.\"

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
July 11, 2019
01:53 PM PT
Audio not working with Dolby Atmos headphones and home theater
Users may experience audio loss with Dolby Atmos headphones or Dolby Atmos home theater.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
July 11, 2019
01:53 PM PT
Event Viewer may close or you may receive an error when using Custom Views
When trying to expand, view, or create Custom Views in Event Viewer, you may see an error or the app may close.

See details >OS Build 18362.175

June 11, 2019
KB4503293Resolved
KB4501375June 27, 2019
10:00 AM PT -
Duplicate folders and documents showing in user profile directory
An empty folder with the same name may be created if known folders (e.g. Desktop, Documents) are redirected.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4497935May 29, 2019
02:00 PM PT
Older versions of BattlEye anti-cheat software incompatible
Users may experience a compatibility issue with some games that use older versions of BattlEye anti-cheat software.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
June 07, 2019
04:26 PM PT -
D3D applications and games may fail to enter full-screen mode on rotated displays
Some Direct3D (D3D) applications and games may fail to enter full-screen mode on rotated displays.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4497935May 29, 2019
02:00 PM PT
AMD RAID driver incompatibility
Devices running certain AMD RAID drivers may have difficulty installing the Windows 10, version 1903 update.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
June 06, 2019
11:06 AM PT " @@ -148,9 +146,7 @@ sections:
Loss of functionality in Dynabook Smartphone Link app
Some users may experience a loss of functionality after updating to Windows 10, version 1903 when using the Dynabook Smartphone Link application on Windows devices. Loss of functionality may affect the display of phone numbers in the Call menu and the ability to answer phone calls on the Windows PC.

To safeguard your update experience, we have applied a compatibility hold on devices with Dynabook Smartphone Link from being offered Windows 10, version 1903, until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue is now resolved and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to Windows 10, version 1903.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
Resolved:
July 11, 2019
01:54 PM PT

Opened:
May 24, 2019
03:10 PM PT
Error attempting to update with external USB device or memory card attached
If you have an external USB device or SD memory card attached when installing Windows 10, version 1903, you may get an error message stating \"This PC can't be upgraded to Windows 10.\" This is caused by inappropriate drive reassignment during installation.

Sample scenario: An update to Windows 10, version 1903 is attempted on a computer that has a thumb drive inserted into its USB port. Before the update, the thumb drive is mounted in the system as drive G based on the existing drive configuration. After the feature update is installed; however, the device is reassigned a different drive letter (e.g., drive H).

Note The drive reassignment is not limited to removable drives. Internal hard drives may also be affected.

To safeguard your update experience, we have applied a hold on devices with an external USB device or SD memory card attached from being offered Windows 10, version 1903 until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue is now resolved and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to Windows 10, version 1903.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
Resolved:
July 11, 2019
01:53 PM PT

Opened:
May 21, 2019
07:38 AM PT
Audio not working with Dolby Atmos headphones and home theater
After updating to Windows 10, version 1903, you may experience loss of audio with Dolby Atmos for home theater (free extension) or Dolby Atmos for headphones (paid extension) acquired through the Microsoft Store due to a licensing configuration error.
 
This occurs due to an issue with a Microsoft Store licensing component, where license holders are not able to connect to the Dolby Access app and enable Dolby Atmos extensions.
 
To safeguard your update experience, we have applied protective hold on devices from being offered Windows 10, version 1903 until this issue is resolved. This configuration error will not result in loss of access for the acquired license once the problem is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue is now resolved and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to Windows 10, version 1903.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
Resolved:
July 11, 2019
01:53 PM PT

Opened:
May 21, 2019
07:16 AM PT -
Duplicate folders and documents showing in user profile directory
If you have redirected known folders (e.g. Desktop, Documents, or Pictures folders) you may see an empty folder with the same name in your %userprofile% directories after updating to Windows 10, version 1903. This may occur if known folders were redirected when you chose to back up your content to OneDrive using the OneDrive wizard, or if you chose to back up your content during the Windows Out-of-Box-Experience (OOBE). This may also occur if you redirected your known folders manually through the Properties dialog box in File Explorer. ?This issue does not cause any user files to be deleted and a solution is in progress.

To safeguard your update experience, we have applied a quality hold on devices with redirected known folders from being offered Windows 10, version 1903, until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue was resolved in KB4497935 and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to Windows 10, version 1903.
(Posted June 11, 2019)

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4497935Resolved:
May 29, 2019
02:00 PM PT

Opened:
May 21, 2019
07:16 AM PT
Older versions of BattlEye anti-cheat software incompatible
Microsoft and BattlEye have identified a compatibility issue with some games that use older versions of BattlEye anti-cheat software. When launching a game that uses an older, impacted version of BattlEye anti-cheat software on a device running Windows 10, version 1903, the device may experience a system crash.

To safeguard your gaming experience, we have applied a compatibility hold on devices with the impacted versions of BattlEye software used by games installed on your PC. This will prevent Windows 10, version 1903 from being offered until the incompatible version of BattlEye software is no longer installed on the device. 

Affected platforms:
  • Client: Windows 10, version 1903
Workaround: Before updating your machine, we recommend you do one or more of the following:

  • Verify that your game is up to date with the latest available version of BattlEye software. Some game platforms allow you to validate your game files, which can confirm that your installation is fully up to date.
  • Restart your system and open the game again.
  • Uninstall BattlEye using https://www.battleye.com/downloads/UninstallBE.exe, and then reopen your game.
  • Uninstall and reinstall your game.
Resolution: This issue was resolved externally by BattlEye for all known impacted games. For a list of recent games that use BattlEye, go to https://www.battleye.com/. We recommend following the workaround before updating to Windows 10, version 1903, as games with incompatible versions of BattleEye may fail to open after updating Windows. If you have confirmed your game is up to date and you have any issues with opening games related to a BattlEye error, please see https://www.battleye.com/support/faq/.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
Resolved:
June 07, 2019
04:26 PM PT

Opened:
May 21, 2019
07:34 AM PT -
D3D applications and games may fail to enter full-screen mode on rotated displays
Some Direct3D (D3D) applications and games (e.g., 3DMark) may fail to enter full-screen mode on displays where the display orientation has been changed from the default (e.g., a landscape display in portrait mode).

Affected platforms:
  • Client: Windows 10, version 1903
  • Server: Windows Server, version 1903
Resolution: This issue was resolved in KB4497935

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4497935Resolved:
May 29, 2019
02:00 PM PT

Opened:
May 21, 2019
07:05 AM PT
AMD RAID driver incompatibility
Microsoft and AMD have identified an incompatibility with AMD RAID driver versions earlier than 9.2.0.105. When you attempt to install the Windows 10, version 1903 update on a Windows 10-based computer with an affected driver version, the installation process stops and you get a message like the following:

AMD Ryzen™ or AMD Ryzen™ Threadripper™ configured in SATA or NVMe RAID mode.

“A driver is installed that causes stability problems on Windows. This driver will be disabled. Check with your software/driver provider for an updated version that runs on this version of Windows.”

 
To safeguard your update experience, we have applied a compatibility hold on devices with these AMD drivers from being offered Windows 10, version 1903, until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue has been resolved externally by AMD. To resolve this issue, you will need to download the latest AMD RAID drivers directly from AMD at https://www.amd.com/en/support/chipsets/amd-socket-tr4/x399. The drivers must be version 9.2.0.105 or later. Install the drivers on the affected computer, and then restart the installation process for the Windows 10, version 1903 feature update.
 
Note The safeguard hold will remain in place on machines with the older AMD RAID drivers. We recommend that you do not attempt to manually update using the Update now button or the Media Creation Tool until a new driver has been installed and the Windows 10, version 1903 feature update has been automatically offered to you.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
Resolved:
June 06, 2019
11:06 AM PT

Opened:
May 21, 2019
07:12 AM PT " diff --git a/windows/release-information/status-windows-10-1903.yml b/windows/release-information/status-windows-10-1903.yml index 5164040208..e0aeac5564 100644 --- a/windows/release-information/status-windows-10-1903.yml +++ b/windows/release-information/status-windows-10-1903.yml @@ -72,7 +72,8 @@ sections:
TLS connections might fail or timeout
Transport Layer Security (TLS) connections might fail or timeout when connecting or attempting a resumption.

See details >OS Build 18362.418

October 08, 2019
KB4517389Mitigated External
November 05, 2019
03:36 PM PT
Intel Audio displays an intcdaud.sys notification
Devices with a range of Intel Display Audio device drivers may experience battery drain.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved External
November 12, 2019
08:04 AM PT
Gamma ramps, color profiles, and night light settings do not apply in some cases
Microsoft has identified some scenarios where gamma ramps, color profiles and night light settings may stop working.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4505903July 26, 2019
02:00 PM PT -
Cannot launch Camera app
Microsoft and Intel have identified an issue affecting Intel RealSense SR300 or Intel RealSense S200 camera apps.

See details >OS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4501375June 27, 2019
10:00 AM PT +
D3D applications and games may fail to enter full-screen mode on rotated displays
Some Direct3D (D3D) applications and games may fail to enter full-screen mode on rotated displays.

See details >OS Build 18362.116

May 21, 2019
KB4505057Mitigated
KB4497935May 21, 2019
04:45 PM PT +
Duplicate folders and documents showing in user profile directory
An empty folder with the same name may be created if known folders (e.g. Desktop, Documents) are redirected.

See details >OS Build 18362.116

May 21, 2019
KB4505057Investigating
KB4497935May 21, 2019
07:16 AM PT " @@ -120,6 +121,7 @@ sections:
Unable to discover or connect to Bluetooth devices using some Realtek adapters
Microsoft has identified compatibility issues with some driver versions for Bluetooth radios made by Realtek. To safeguard your update experience, we have applied a compatibility hold on devices with affected driver versions for Realtek Bluetooth radios from being offered Windows 10, version 1903 or Windows Server, version 1903 until the driver has been updated.

Affected platforms:
  • Client: Windows 10, version 1909; Windows 10, version 1903
  • Server: Windows 10, version 1909; Windows Server, version 1903
Resolution: This issue was resolved with an updated driver for the affected Realtek Bluetooth radio and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to offered Windows 10, version 1909 or Windows 10, version 1903.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved External
Last updated:
November 15, 2019
05:59 PM PT

Opened:
May 21, 2019
07:29 AM PT
Intel Audio displays an intcdaud.sys notification
Microsoft and Intel have identified an issue with a range of Intel Display Audio device drivers that may result in higher than normal battery drain. If you see an intcdaud.sys notification or “What needs your attention” notification when trying to update to Windows 10, version 1903, you have an affected Intel Audio Display device driver installed on your machine (intcdaud.sys, versions 10.25.0.3 through 10.25.0.8).
  
To safeguard your update experience, we have applied a compatibility hold on devices with drivers from being offered Windows 10, version 1903 until updated device drivers have been installed.

Affected platforms:
  • Client: Windows 10, version 1903; Windows 10, version 1809
Resolution: This issue was resolved with updated drivers from your device manufacturer (OEM) or Intel. The safeguard hold has been removed.

Note If you are still experiencing the issue described, please contact your device manufacturer (OEM).

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved External
Last updated:
November 12, 2019
08:04 AM PT

Opened:
May 21, 2019
07:22 AM PT
Gamma ramps, color profiles, and night light settings do not apply in some cases
Microsoft has identified some scenarios where gamma ramps, color profiles and night light settings may stop working.

Microsoft has identified some scenarios in which these features may have issues or stop working, for example:
  • Connecting to (or disconnecting from) an external monitor, dock, or projector
  • Rotating the screen
  • Updating display drivers or making other display mode changes
  • Closing full screen applications
  • Applying custom color profiles
  • Running applications that rely on custom gamma ramps
Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue was resolved in KB4505903 and the safeguard hold has been removed.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4505903Resolved:
July 26, 2019
02:00 PM PT

Opened:
May 21, 2019
07:28 AM PT -
Cannot launch Camera app
Microsoft and Intel have identified an issue affecting Intel RealSense SR300 and Intel RealSense S200 cameras when using the Camera app. After updating to the Windows 10 May 2019 Update and launching the Camera app, you may get an error message stating:
        \"Close other apps, error code: 0XA00F4243.”

To safeguard your update experience, we have applied a protective hold on machines with Intel RealSense SR300 or Intel RealSense S200 cameras installed from being offered Windows 10, version 1903, until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Resolution: This issue was resolved in KB4501375 and the safeguard hold has been removed.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Resolved
KB4501375Resolved:
June 27, 2019
10:00 AM PT

Opened:
May 21, 2019
07:20 AM PT +
D3D applications and games may fail to enter full-screen mode on rotated displays
Some Direct3D (D3D) applications and games (e.g., 3DMark) may fail to enter full-screen mode on displays where the display orientation has been changed from the default (e.g., a landscape display in portrait mode).

Affected platforms:
  • Client: Windows 10, version 1903
  • Server: Windows Server, version 1903
Workaround: To work around this issue, do one of the following:
  • Run applications in windowed mode or, if available, on a secondary non-rotated display. 
  • Change compatibility settings for the applications to “Disable Full Screen Optimizations.”
Next steps: Microsoft is working on a resolution and estimates a solution will be available in late May.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Mitigated
KB4497935Last updated:
May 21, 2019
04:45 PM PT

Opened:
May 21, 2019
07:05 AM PT +
Duplicate folders and documents showing in user profile directory
If you have redirected known folders (e.g. Desktop, Documents, or Pictures folders) you may see an empty folder with the same name in your %userprofile% directories after updating to Windows 10, version 1903. This may occur if known folders were redirected when you chose to back up your content to OneDrive using the OneDrive wizard, or if you chose to back up your content during the Windows Out-of-Box-Experience (OOBE). This may also occur if you redirected your known folders manually through the Properties dialog box in File Explorer. ​This issue does not cause any user files to be deleted and a solution is in progress.

To safeguard your update experience, we have applied a quality hold on devices with redirected known folders from being offered Windows 10, version 1903, until this issue is resolved.

Affected platforms:
  • Client: Windows 10, version 1903
Next steps: Microsoft is working on a resolution and estimates a solution will be available in late May.
Note We recommend that you do not attempt to manually update to Windows 10, version 1903 using the Update now button or the Media Creation Tool until this issue has been resolved.

Back to topOS Build 18362.116

May 21, 2019
KB4505057Investigating
KB4497935Last updated:
May 21, 2019
07:16 AM PT

Opened:
May 21, 2019
07:16 AM PT " diff --git a/windows/release-information/status-windows-10-1909.yml b/windows/release-information/status-windows-10-1909.yml index 65eca24a0c..23177c4408 100644 --- a/windows/release-information/status-windows-10-1909.yml +++ b/windows/release-information/status-windows-10-1909.yml @@ -21,7 +21,7 @@ sections: Find information on known issues and the status of the rollout for Windows 10, version 1909 and Windows Server, version 1909. Looking for a specific issue? Press CTRL + F (or Command + F if you are using a Mac) and enter your search term(s). -
Current status as of November 12, 2019:
Windows 10, version 1909 is available for any user on a recent version of Windows 10 who manually selects “Check for updates” via Windows Update. The recommended servicing status is Semi-Annual Channel.
 
For information on how users running Windows 10, version 1903 can update to Windows 10, version 1909 in a new, streamlined way, see this post.
 
Note follow @WindowsUpdate on Twitter to find out when new content is published to the release information dashboard.
+
Current status as of December 5, 2019:
Windows 10, version 1909 is available for any user on a recent version of Windows 10 who manually selects “Check for updates” via Windows Update. The recommended servicing status is Semi-Annual Channel.
 
Beginning today, we will slowly start the phased process to automatically initiate a feature update for devices running the October 2018 Update (Windows 10, version 1809) Home and Pro editions, keeping those devices supported and receiving the monthly updates that are critical to device security and ecosystem health. We are starting this rollout process several months in advance of the end of service date to provide adequate time for a smooth update process.

For information on how users running Windows 10, version 1903 can update to Windows 10, version 1909 in a new, streamlined way, see this post.
 
Note follow @WindowsUpdate on Twitter to find out when new content is published to the release information dashboard.
" From cffe16c9ae1e1e7b0296d5f06815d940e3e8a643 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Thu, 5 Dec 2019 12:44:42 -0800 Subject: [PATCH 114/209] AIR --- windows/security/threat-protection/index.md | 2 +- .../advanced-features.md | 4 +-- .../attack-simulations.md | 2 +- .../automated-investigations.md | 28 +++++++-------- .../initiate-autoir-investigation.md | 2 +- .../investigate-machines.md | 2 +- .../manage-auto-investigation.md | 34 +++++++++---------- 7 files changed, 37 insertions(+), 37 deletions(-) diff --git a/windows/security/threat-protection/index.md b/windows/security/threat-protection/index.md index 2e982d04c6..7bf9cc9483 100644 --- a/windows/security/threat-protection/index.md +++ b/windows/security/threat-protection/index.md @@ -102,7 +102,7 @@ In conjunction with being able to quickly respond to advanced attacks, Microsoft - [Automated investigation and remediation](microsoft-defender-atp/automated-investigations.md) - [Threat remediation](microsoft-defender-atp/automated-investigations.md#how-threats-are-remediated) -- [Manage automated investigations](microsoft-defender-atp/manage-auto-investigation.md) +- [Manage automated investigation](microsoft-defender-atp/manage-auto-investigation.md) - [Analyze automated investigation](microsoft-defender-atp/manage-auto-investigation.md#analyze-automated-investigations) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md index 85ea675b5d..bf486af90d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md @@ -30,7 +30,7 @@ Use the following advanced features to get better protected from potentially mal ## Automated investigation -When you enable this feature, you'll be able to take advantage of the automated investigation and remediation features of the service. For more information, see [Automated investigations](automated-investigations.md). +When you enable this feature, you'll be able to take advantage of the automated investigation and remediation features of the service. For more information, see [Automated investigation](automated-investigations.md). ## Live response @@ -44,7 +44,7 @@ Enabling this feature allows you to run unsigned scripts in a live response sess ## Auto-resolve remediated alerts -For tenants created on or after Windows 10, version 1809 the automated investigations capability is configured by default to resolve alerts where the automated analysis result status is "No threats found" or "Remediated". If you don’t want to have alerts auto-resolved, you’ll need to manually turn off the feature. +For tenants created on or after Windows 10, version 1809 the automated investigation and remediation capability is configured by default to resolve alerts where the automated analysis result status is "No threats found" or "Remediated". If you don’t want to have alerts auto-resolved, you’ll need to manually turn off the feature. >[!TIP] >For tenants created prior that version, you'll need to manually turn this feature on from the [Advanced features](https://securitycenter.windows.com/preferences2/integration) page. diff --git a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md index ce50cf47b1..26f0706b19 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md @@ -46,7 +46,7 @@ Read the walkthrough document provided with each attack scenario. Each document - **Scenario 2: PowerShell script in fileless attack** - simulates a fileless attack that relies on PowerShell, showcasing attack surface reduction and machine learning detection of malicious memory activity. - - **Scenario 3: Automated incident response** - triggers Automated investigation, which automatically hunts for and remediates breach artifacts to scale your incident response capacity. + - **Scenario 3: Automated incident response** - triggers automated investigation, which automatically hunts for and remediates breach artifacts to scale your incident response capacity. 2. Download and read the corresponding walkthrough document provided with your selected scenario. diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index a8e4541750..a0853866bd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -1,5 +1,5 @@ --- -title: Use Automated investigations to investigate and remediate threats +title: Use automated investigations to investigate and remediate threats description: View the list of automated investigations, its status, detection source and other details. keywords: automated, investigation, detection, source, threat types, id, tags, machines, duration, filter export search.product: eADQiWindows 10XVcnh @@ -17,32 +17,32 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Overview of Automated investigations +# Overview of automated investigations >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-automated-investigations-abovefoldlink) The Microsoft Defender ATP service has a wide breadth of visibility on multiple machines. With this kind of optics, the service generates a multitude of alerts. The volume of alerts generated can be challenging for a typical security operations team to individually address. -To address this challenge, Microsoft Defender ATP uses Automated investigations to significantly reduce the volume of alerts that need to be investigated individually. The Automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. +To address this challenge, Microsoft Defender ATP uses automated investigations to significantly reduce the volume of alerts that need to be investigated individually. The Automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. The Automated investigations list shows all the investigations that have been initiated automatically and shows other details such as its status, detection source, and the date for when the investigation was initiated. -## Understand the Automated investigation flow +## Understand the automated investigation flow -### How the Automated investigation starts +### How the automated investigation starts -Entities are the starting point for Automated investigations. When an alert contains a supported entity for Automated investigation (for example, a file) that resides on a machine that has a supported operating system for Automated investigation then an Automated investigation can start. +Entities are the starting point for automated investigations. When an alert contains a supported entity for automated investigation (for example, a file) that resides on a machine that has a supported operating system for automated investigation then an Automated investigation can start. >[!NOTE] ->Currently, Automated investigation only supports the following OS versions: +>Currently, automated investigation only supports the following OS versions: >- Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/en-us/help/4493441/windows-10-update-kb4493441)) or later >- Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/en-us/help/4493464/windows-10-update-kb4493464)) or later >- Later versions of Windows 10 -The Automated investigation starts by analyzing the supported entities from the alert and also runs a generic machine playbook to see if there is anything else suspicious on that machine. The outcome and details from the investigation is seen in the Automated investigation view. +The automated investigation starts by analyzing the supported entities from the alert and also runs a generic machine playbook to see if there is anything else suspicious on that machine. The outcome and details from the investigation is seen in the automated investigation view. -### Details of an Automated investigation +### Details of an automated investigation As the investigation proceeds, you'll be able to view the details of the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Evidence**, **Entities**, and **Log** tabs. @@ -52,21 +52,21 @@ The **Machines** tab shows where the alert was seen. The **Evidence** tab shows the entities that were found to be malicious during the investigation. -During an Automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean. +During an automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean. The **Log** tab reflects the chronological detailed view of all the investigation actions taken on the alert. -If there are pending actions on the investigation, the **Pending actions** tab will be displayed where you can approve or reject actions. You can also go to the **Action center** to get an aggregated view all pending actions and manage remediaton actions. It also acts as an audit trail for all Automated investigation actions. +If there are pending actions on the investigation, the **Pending actions** tab will be displayed where you can approve or reject actions. You can also go to the **Action center** to get an aggregated view all pending actions and manage remediaton actions. It also acts as an audit trail for all automated investigation actions. -### How an Automated investigation expands its scope +### How an automated investigation expands its scope -While an investigation is running, any other alert generated from the machine will be added to an ongoing Automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation. +While an investigation is running, any other alert generated from the machine will be added to an ongoing automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation. If an incriminated entity is seen in another machine, the Automated investigation will expand the investigation to include that machine and a generic machine playbook will start on that machine. If 10 or more machines are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view. ### How threats are remediated -Depending on how you set up the machine groups and their level of automation, the Automated investigation will either require user approval (default) or automatically remediate threats. +Depending on how you set up the machine groups and their level of automation, the automated investigation will either require user approval (default) or automatically remediate threats. You can configure the following levels of automation: diff --git a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md index 16b8d8a428..7c6f7bbc93 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md @@ -26,7 +26,7 @@ ms.topic: article Initiate AutoIR investigation on a machine. >[!Note] -> This page focuses on performing an automated investigation on a machine. See [Automated Investigation](automated-investigations.md) for more information. +> This page focuses on performing an automated investigation on a machine. See [automated investigation](automated-investigations.md) for more information. ## Limitations 1. The number of executions is limited (up to 5 calls per hour). diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md index 56539b10cf..fe9095c926 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md @@ -54,7 +54,7 @@ The machine details section provides information such as the domain, OS, and hea Response actions run along the top of a specific machine page and include: - Manage tags -- Initiate Automated Investigation +- Initiate automated investigation - Initiate Live Response Session - Collect investigation package - Run antivirus scan diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md index 4b1bc1f541..87208d5142 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md @@ -18,7 +18,7 @@ ms.topic: conceptual --- # Learn about the automated investigations dashboard -By default, the Automated investigations list displays investigations initiated in the last week. You can also choose to select other time ranges from the drop-down menu or specify a custom range. +By default, the automated investigations list displays investigations initiated in the last week. You can also choose to select other time ranges from the drop-down menu or specify a custom range. >[!NOTE] >If your organization has implemented role-based access to manage portal access, only authorized users or user groups who have permission to view the machine or machine group will be able to view the entire investigation. @@ -31,14 +31,14 @@ From this view, you can also download the entire list in CSV format using the ** **Filters**
-You can use the following operations to customize the list of Automated investigations displayed: +You can use the following operations to customize the list of automated investigations displayed: **Triggering alert**
-The alert the initiated the Automated investigation. +The alert the initiated the automated investigation. **Status**
-An Automated investigation can be in one of the following status: +An automated investigation can be in one of the following status: Status | Description :---|:--- @@ -57,26 +57,26 @@ Status | Description **Detection source**
-Source of the alert that initiated the Automated investigation. +Source of the alert that initiated the automated investigation. **Threat**
-The category of threat detected during the Automated investigation. +The category of threat detected during the automated investigation. **Tags**
-Filter using manually added tags that capture the context of an Automated investigation. +Filter using manually added tags that capture the context of an automated investigation. **Machines**
-You can filter the Automated investigations list to zone in a specific machine to see other investigations related to the machine. +You can filter the automated investigations list to zone in a specific machine to see other investigations related to the machine. **Machine groups**
Apply this filter to see specific machine groups that you might have created. **Comments**
-Select between filtering the list between Automated investigations that have comments and those that don't. +Select between filtering the list between automated investigations that have comments and those that don't. -## Analyze Automated investigations -You can view the details of an Automated investigation to see information such as the investigation graph, alerts associated with the investigation, the machine that was investigated, and other information. +## Analyze automated investigations +You can view the details of an automated investigation to see information such as the investigation graph, alerts associated with the investigation, the machine that was investigated, and other information. In this view, you'll see the name of the investigation, when it started and ended. @@ -118,14 +118,14 @@ You'll also have access to the following sections that help you see details of t In any of the sections, you can customize columns to further expand to limit the details you see in a section. ### Investigation graph -The investigation graph provides a graphical representation of an Automated investigation. All investigation related information is simplified and arranged in specific sections. Clicking on any of the icons brings you the relevant section where you can view more information. +The investigation graph provides a graphical representation of an automated investigation. All investigation related information is simplified and arranged in specific sections. Clicking on any of the icons brings you the relevant section where you can view more information. ### Alerts -Shows details such as a short description of the alert that initiated the Automated investigation, severity, category, the machine associated with the alert, user, time in queue, status, investigation state, and who the investigation is assigned to. +Shows details such as a short description of the alert that initiated the automated investigation, severity, category, the machine associated with the alert, user, time in queue, status, investigation state, and who the investigation is assigned to. -Additional alerts seen on a machine can be added to an Automated investigation as long as the investigation is ongoing. +Additional alerts seen on a machine can be added to an automated investigation as long as the investigation is ongoing. -Selecting an alert using the check box brings up the alerts details pane where you have the option of opening the alert page, manage the alert by changing its status, see alert details, Automated investigation details, related machine, logged-on users, and comments and history. +Selecting an alert using the check box brings up the alerts details pane where you have the option of opening the alert page, manage the alert by changing its status, see alert details, automated investigation details, related machine, logged-on users, and comments and history. Clicking on an alert title brings you the alert page. @@ -158,11 +158,11 @@ This tab is only displayed when an investigation is complete and shows all pendi ## Pending actions -If there are pending actions on an Automated investigation, you'll see a pop up similar to the following image. +If there are pending actions on an automated investigation, you'll see a pop up similar to the following image. ![Image of pending actions](images/pending-actions.png) -When you click on the pending actions link, you'll be taken to the Action center. You can also navigate to the page from the navigation page by going to **Automated investigation** > **Action center**. For more information, see [Action center](auto-investigation-action-center.md). +When you click on the pending actions link, you'll be taken to the Action center. You can also navigate to the page from the navigation page by going to **automated investigation** > **Action center**. For more information, see [Action center](auto-investigation-action-center.md). ## Related topic From d9acf71dfb06ff14c0ef3cf029048a9d922e06c0 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Thu, 5 Dec 2019 13:01:58 -0800 Subject: [PATCH 115/209] Update automated-investigations.md --- .../automated-investigations.md | 70 +++++++++---------- 1 file changed, 34 insertions(+), 36 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index a0853866bd..28d3920de1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -8,8 +8,8 @@ ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: security -ms.author: macapara -author: mjcaparas +ms.author: deniseb +author: denisebmsft ms.localizationpriority: medium manager: dansimp audience: ITPro @@ -19,50 +19,46 @@ ms.topic: conceptual # Overview of automated investigations +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) offers a wide breadth of visibility on multiple machines. With this kind of optics, the service generates a multitude of alerts. The volume of alerts generated can be challenging for a typical security operations team to individually address. To address this challenge, Microsoft Defender ATP uses automated investigation and remediation capabilities to significantly reduce the volume of alerts that must be investigated individually. + +The automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. The **Automated investigations** list shows all the investigations that were initiated automatically, and includes details, such as status, detection source, and when the investigation was initiated. + >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-automated-investigations-abovefoldlink) -The Microsoft Defender ATP service has a wide breadth of visibility on multiple machines. With this kind of optics, the service generates a multitude of alerts. The volume of alerts generated can be challenging for a typical security operations team to individually address. - - -To address this challenge, Microsoft Defender ATP uses automated investigations to significantly reduce the volume of alerts that need to be investigated individually. The Automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. - -The Automated investigations list shows all the investigations that have been initiated automatically and shows other details such as its status, detection source, and the date for when the investigation was initiated. ## Understand the automated investigation flow ### How the automated investigation starts -Entities are the starting point for automated investigations. When an alert contains a supported entity for automated investigation (for example, a file) that resides on a machine that has a supported operating system for automated investigation then an Automated investigation can start. +When an alert is triggered, a security playbook goes into effect. Depending on the security playbook, an automated investigation can start. For example, suppose a malicious file resides on a machine. When that file is detected, an alert is triggered. The automated investigation process begins. Microsoft Defender ATP checks to see if the malicious file is present on any other machines in the organization. Details from the investigation, including verdicts (Malicious, Suspicious, and Clean) are available during and after the automated investigation. >[!NOTE] >Currently, automated investigation only supports the following OS versions: ->- Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/en-us/help/4493441/windows-10-update-kb4493441)) or later ->- Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/en-us/help/4493464/windows-10-update-kb4493464)) or later +>- Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/help/4493441/windows-10-update-kb4493441)) or later +>- Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/help/4493464/windows-10-update-kb4493464)) or later >- Later versions of Windows 10 -The automated investigation starts by analyzing the supported entities from the alert and also runs a generic machine playbook to see if there is anything else suspicious on that machine. The outcome and details from the investigation is seen in the automated investigation view. - ### Details of an automated investigation -As the investigation proceeds, you'll be able to view the details of the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Evidence**, **Entities**, and **Log** tabs. +During and after an automated investigation, you can view details about the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Evidence**, **Entities**, and **Log** tabs. -In the **Alerts** tab, you'll see the alert that started the investigation. +|Tab |Description | +|--|--| +|**Alerts**| Shows the alert that started the investigation.| +|**Machines** |Shows where the alert was seen.| +|**Evidence** |Shows the entities that were found to be malicious during the investigation.| +|**Entities** |Provides details about each analyzed entity, including a determination for each entity type (*Malicious*, *Suspicious*, or *Clean*). | +|**Log** |Shows the chronological detailed view of all the investigation actions taken on the alert.| +|**Pending actions** |If there are pending actions on the investigation, the **Pending actions** tab will be displayed where you can approve or reject actions. | -The **Machines** tab shows where the alert was seen. - -The **Evidence** tab shows the entities that were found to be malicious during the investigation. - -During an automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean. - -The **Log** tab reflects the chronological detailed view of all the investigation actions taken on the alert. - -If there are pending actions on the investigation, the **Pending actions** tab will be displayed where you can approve or reject actions. You can also go to the **Action center** to get an aggregated view all pending actions and manage remediaton actions. It also acts as an audit trail for all automated investigation actions. +> [!IMPORTANT] +> Go to the **Action center** to get an aggregated view all pending actions and manage remediation actions. The **Action center** also acts as an audit trail for all automated investigation actions. ### How an automated investigation expands its scope -While an investigation is running, any other alert generated from the machine will be added to an ongoing automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation. +While an investigation is running, any other alerts generated from the machine are added to an ongoing automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation. -If an incriminated entity is seen in another machine, the Automated investigation will expand the investigation to include that machine and a generic machine playbook will start on that machine. If 10 or more machines are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view. +If an incriminated entity is seen in another machine, the automated investigation process will expand its scope to include that machine, and a general security playbook will start on that machine. If 10 or more machines are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view. ### How threats are remediated @@ -70,19 +66,21 @@ Depending on how you set up the machine groups and their level of automation, th You can configure the following levels of automation: -Automation level | Description -:---|:--- -Not protected | Machines will not get any automated investigations run on them. -Semi - require approval for any remediation | This is the default automation level.

An approval is needed for any remediation action. -Semi - require approval for non-temp folders remediation | An approval is required on files or executables that are not in temporary folders.

Files or executables in temporary folders, such as the user's download folder or the user's temp folder, will automatically be remediated if needed. -Semi - require approval for core folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.

Files or executables in all other folders will automatically be remediated if needed. -Full - remediate threats automatically | All remediation actions will be performed automatically. +|Automation level | Description| +|---|---| +|Not protected | Machines do not get any automated investigations run on them. | +|Semi - require approval for any remediation | This is the default automation level.

An approval is needed for any remediation action. | +|Semi - require approval for non-temp folders remediation | An approval is required on files or executables that are not in temporary folders.

Files or executables in temporary folders, such as the user's download folder or the user's temp folder, will automatically be remediated if needed.| +|Semi - require approval for core folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.

Files or executables in all other folders will automatically be remediated if needed.| +|Full - remediate threats automatically | All remediation actions will be performed automatically.| -For more information on how to configure these automation levels, see [Create and manage machine groups](machine-groups.md). +> [!TIP] +> For more information on how to configure these automation levels, see [Create and manage machine groups](machine-groups.md). -The default machine group is configured for semi-automatic remediation. This means that any malicious entity that needs to be remediated requires an approval and the investigation is added to the **Pending actions** section, this can be changed to fully automatic so that no user approval is needed. +The default machine group is configured for semi-automatic remediation. This means that any malicious entity that calls for remediation requires an approval and the investigation is added to the **Pending actions** section. This can be changed to fully automatic so that no user approval is needed. When a pending action is approved, the entity is then remediated and this new state is reflected in the **Entities** tab of the investigation. -## Related topic +## Next step + - [Learn about the automated investigations dashboard](manage-auto-investigation.md) From db49915fb74af97713755921ded30e1bd8659998 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Thu, 5 Dec 2019 13:02:35 -0800 Subject: [PATCH 116/209] Update auto-investigation-action-center.md --- .../microsoft-defender-atp/auto-investigation-action-center.md | 3 --- 1 file changed, 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/auto-investigation-action-center.md b/windows/security/threat-protection/microsoft-defender-atp/auto-investigation-action-center.md index 8945fc0931..67192e12e8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/auto-investigation-action-center.md +++ b/windows/security/threat-protection/microsoft-defender-atp/auto-investigation-action-center.md @@ -29,9 +29,6 @@ The action center consists of two main tabs: - All commands ran and remediation actions applied in Live Response with ability to undo actions that support this capability. - Remediation actions applied by Windows Defender AV with ability to undo actions that support this capability. - - - Use the Customize columns drop-down menu to select columns that you'd like to show or hide. From this view, you can also download the entire list in CSV format using the **Export** feature, specify the number of items to show per page, and navigate between pages. From f6f108f1b6776b3aa2c81f209256efbc73c62309 Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:10:54 -0800 Subject: [PATCH 117/209] Updated based on SME feedback --- windows/security/threat-protection/TOC.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index d50923659c..403e6ddf69 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -4,8 +4,8 @@ ### [What is Microsoft Defender Advanced Threat Protection?](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) ### [Overview of Microsoft Defender ATP capabilities](microsoft-defender-atp/overview.md) ### [Threat & Vulnerability Management]() -#### [Supported operating systems and platforms](microsoft-defender-atp/tvm-supported-os.md) #### [Next-generation capabilities](microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md) +#### [Supported operating systems and platforms](microsoft-defender-atp/tvm-supported-os.md) #### [What's in the dashboard and what it means for my organization](microsoft-defender-atp/tvm-dashboard-insights.md) #### [Exposure score](microsoft-defender-atp/tvm-exposure-score.md) #### [Configuration score](microsoft-defender-atp/configuration-score.md) From 126043aa58e7bd7b43d62afec4094150c96cd9fc Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:13:02 -0800 Subject: [PATCH 118/209] Updated based on SME feedback --- .../microsoft-defender-atp/tvm-security-recommendation.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md index 9aac993067..ace7b85957 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md @@ -53,7 +53,7 @@ You can click on each one of them and see the details, the description, the pote From that page, you can do any of the following depending on what you need to do: -- Open software page - Drill down and open the software page to get more context of the software details, prevalence in the organization, weaknesses discovered, version distribution, application end-of-life, and charts so you can see the exposure trend over time. +- Open software page - Drill down and open the software page to get more context of the software details, prevalence in the organization, weaknesses discovered, version distribution, software end-of-life, and charts so you can see the exposure trend over time. - Choose from remediation options - Submit a remediation request to open a ticket in Microsoft Intune for your IT Administrator to pick up and address. From b4d1cbf5eb28c93414cd6442de44ae13607dc621 Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:16:46 -0800 Subject: [PATCH 119/209] Update tvm-remediation.md --- .../threat-protection/microsoft-defender-atp/tvm-remediation.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation.md index 76ff7e6cd0..1d7a8392e8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation.md @@ -50,7 +50,7 @@ You can access the remediation page in a few places in the portal: If you want to check how the ticket shows up in Intune, see [Use Intune to remediate vulnerabilities identified by Microsoft Defender ATP](https://docs.microsoft.com/intune/atp-manage-vulnerabilities) for details. *Remediation in the navigation menu* -1. Go to the Threat & Vulnerability Management navigation menu and select **Remediation** to open up the list of remediation activities and exceptions found in your organization. You can filter your view based on remediation type, machine remediation progress, and exception justification. If you want to see the remediation activities of applications which have reached their end-of-life, select **Software uninstall** from the **Remediation type** filter. +1. Go to the Threat & Vulnerability Management navigation menu and select **Remediation** to open up the list of remediation activities and exceptions found in your organization. You can filter your view based on remediation type, machine remediation progress, and exception justification. If you want to see the remediation activities of software which have reached their end-of-life, select **Software uninstall** from the **Remediation type** filter. 2. Select the remediation activity that you need to see or process. *Top remediation activities widget in the dashboard* From 633b4918cb7b85fc02daa18d235611f11272004b Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:18:43 -0800 Subject: [PATCH 120/209] Update tvm-software-inventory.md --- .../microsoft-defender-atp/tvm-software-inventory.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md index 56439c7b45..4d74df5c5b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md @@ -28,14 +28,14 @@ ms.date: 04/11/2019 Microsoft Defender ATP Threat & Vulnerability management's discovery capability shows in the **Software inventory** page. The software inventory includes the name of the product or vendor, the latest version it is in, and the number of weaknesses and vulnerabilities detected with it. ## Navigate through your software inventory -1. Select **Software inventory** from the Threat & Vulnerability management navigation menu. The **Software inventory** page opens with a list of applications installed in your network, vendor name, weaknesses found, threats associated with them, exposed machines, impact, tags. You can also filter the software inventory list view based on weaknesses found in the applications, threats associated with them, and whether the applications have reached their end-of-life. -2. In the **Software inventory** page, select the application that you want to investigate and a flyout panel opens up with the same details mentioned above but in a more compact view. You can either dive deeper into the investigation and select **Open software page** or flag any technical inconsistencies by selecting **Report inaccuracy**. -3. Select **Open software page** to dive deeper into your software inventory to see how many weaknesses are discovered in the application, devices exposed, installed machines, version distribution, and the corresponding security recommendations for the weaknesses and vulnerabilities identified. +1. Select **Software inventory** from the Threat & Vulnerability management navigation menu. The **Software inventory** page opens with a list of software installed in your network, vendor name, weaknesses found, threats associated with them, exposed machines, impact, tags. You can also filter the software inventory list view based on weaknesses found in the software, threats associated with them, and whether the software have reached their end-of-life. +2. In the **Software inventory** page, select the software that you want to investigate and a flyout panel opens up with the same details mentioned above but in a more compact view. You can either dive deeper into the investigation and select **Open software page** or flag any technical inconsistencies by selecting **Report inaccuracy**. +3. Select **Open software page** to dive deeper into your software inventory to see how many weaknesses are discovered in the software, devices exposed, installed machines, version distribution, and the corresponding security recommendations for the weaknesses and vulnerabilities identified. ## How it works In the field of discovery, we are leveraging the same set of signals in Microsoft Defender ATP's endpoint detection and response that's responsible for detection, for vulnerability assessment. -Since it is real-time, in a matter of minutes, you will see vulnerability information as they get discovered. The engine automatically grabs information from multiple security feeds. In fact, you'll will see if a particular application is connected to a live campaign. It also provides a link to a Threat Analytics report soon as it's available. +Since it is real-time, in a matter of minutes, you will see vulnerability information as they get discovered. The engine automatically grabs information from multiple security feeds. In fact, you'll will see if a particular software is connected to a live threat campaign. It also provides a link to a Threat Analytics report soon as it's available. ## Report inaccuracy From da33e5cbd6a84ad7ccb06306327f1c32728e2402 Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:21:09 -0800 Subject: [PATCH 121/209] Update tvm-dashboard-insights.md --- .../microsoft-defender-atp/tvm-dashboard-insights.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md index f634b03320..f9f7644204 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md @@ -52,9 +52,9 @@ Area | Description (1) Menu | Select menu to expand the navigation pane and see the names of the Threat & Vulnerability Management capabilities. (2) Threat & Vulnerability Management navigation pane | Use the navigation pane to move across the **Threat and Vulnerability Management Dashboard**, **Security recommendations**, **Remediation**, **Software inventory**, and **Weaknesses**. **Dashboards** | Get a high-level view of the organization exposure score, organization configuration score, machine exposure distribution, top security recommendations, top vulnerable software, top remediation activities, and top exposed machines data. -**Security recommendations** | See the list of security recommendations, their related components, whether applications in your network have reached their end-of-life, insights, number or exposed devices, impact, and request for remediation. You can click each item on the list, a flyout panel opens with vulnerability details, open the software page, see the remediation, and exception options. You can also open a ticket in Intune if your machines are joined through Azure Active Directory and you have enabled your Intune connections in Microsoft Defender ATP. See [Security recommendations](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation) for more information. +**Security recommendations** | See the list of security recommendations, their related components, whether software in your network have reached their end-of-life, insights, number or exposed devices, impact, and request for remediation. You can click each item on the list, a flyout panel opens with vulnerability details, open the software page, see the remediation, and exception options. You can also open a ticket in Intune if your machines are joined through Azure Active Directory and you have enabled your Intune connections in Microsoft Defender ATP. See [Security recommendations](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation) for more information. **Remediation** | See the remediation activity, related component, remediation type, status, due date, option to export the remediation and process data to CSV, and active exceptions. See [Remediation and exception](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation) for more information. -**Software inventory** | See the list of applications, versions, weaknesses, whether there’s an exploit found on the application, whether the application has reached its end-of-life, prevalence in the organization, how many were installed, how many exposed devices are there, and the numerical value of the impact. You can select each item in the list and opt to open the software page which shows the associated vulnerabilities, misconfigurations, affected machine, version distribution details, and missing KBs or security updates. See [Software inventory](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory) for more information. +**Software inventory** | See the list of software, versions, weaknesses, whether there’s an exploit found on the software, whether the software has reached its end-of-life, prevalence in the organization, how many were installed, how many exposed devices are there, and the numerical value of the impact. You can select each item in the list and opt to open the software page which shows the associated vulnerabilities, misconfigurations, affected machine, version distribution details, and missing KBs or security updates. See [Software inventory](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory) for more information. **Weaknesses** | See the list of common vulnerabilities and exposures, the severity, its common vulnerability scoring system (CVSS) V3 score, related software, age, when it was published, related threat alerts, and how many exposed machines are there. You can select each item in the list and it opens a flyout panel with the vulnerability description and other details. See [Weaknesses](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses) for more information. (3) Threat & Vulnerability Management dashboard | Access the **Exposure score**, **Configuration score**, **Exposure distribution**, **Top security recommendations**, **Top vulnerable software**, **Top remediation activities**, and **Top exposed machines**. **Selected machine groups (#/#)** | Filter the Threat & Vulnerability Management data that you want to see in the dashboard and widgets by machine groups. What you select in the filter applies throughout the Threat & Vulnerability management pages only. @@ -62,7 +62,7 @@ Area | Description **Organization Configuration score** | See the security posture of the operating system, applications, network, accounts and security controls of your organization. The goal is to remediate the related security configuration issues to increase your configuration score. You can click the bars and it takes you to the **Security recommendation** page for details. See [Configuration score](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configuration-score) for more information. **Machine exposure distribution** | See how many machines are exposed based on their exposure level. You can click the sections in the doughnut chart and it takes you to the **Machines list** page where you'll see the affected machine names, exposure level side by side with risk level, among other details such as domain, operating system platform, its health state, when it was last seen, and its tags. **Top security recommendations** | See the collated security recommendations which are sorted and prioritized based on your organization’s risk exposure and the urgency that it requires. Useful icons also quickly calls your attention on possible active alerts ![Possible active alert](images/tvm_alert_icon.png), associated public exploits ![Threat insight](images/tvm_bug_icon.png), and recommendation insights ![Recommendation insight](images/tvm_insight_icon.png). You can drill down on the security recommendation to see the potential risks, list of exposed machines, and read the insights. Thus, providing you with an informed decision to either proceed with a remediation request. Click **Show more** to see the rest of the security recommendations in the list. -**Top vulnerable software** | Get real-time visibility into the organizational software inventory, with stack-ranked list of vulnerable software installed on your network’s devices and how they impact on your organizational exposure score. Click each item for details or **Show more** to see the rest of the vulnerable application list in the **Software inventory** page. +**Top vulnerable software** | Get real-time visibility into the organizational software inventory, with stack-ranked list of vulnerable software installed on your network’s devices and how they impact on your organizational exposure score. Click each item for details or **Show more** to see the rest of the vulnerable software list in the **Software inventory** page. **Top remediation activities** | Track the remediation activities generated from the security recommendations. You can click each item on the list to see the details in the **Remediation** page or click **Show more** to see the rest of the remediation activities, and active exceptions. **Top exposed machines** | See the exposed machine names and their exposure level. You can click each machine name from the list and it will take you to the machine page where you can view the alerts, risks, incidents, security recommendations, installed software, discovered vulnerabilities associated with the exposed machines. You can also do other EDR-related tasks in it, such as: manage tags, initiate automated investigations, initiate a live response session, collect an investigation package, run antivirus scan, restrict app execution, and isolate machine. You can also click **Show more** to see the rest of the exposed machines list. From 34b9d3025220d680f521a1c54d4b02befee04e56 Mon Sep 17 00:00:00 2001 From: Dulce Montemayor Date: Thu, 5 Dec 2019 13:22:21 -0800 Subject: [PATCH 122/209] Update tvm-dashboard-insights.md --- .../microsoft-defender-atp/tvm-dashboard-insights.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md index f9f7644204..07bd73d2d2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md @@ -52,7 +52,7 @@ Area | Description (1) Menu | Select menu to expand the navigation pane and see the names of the Threat & Vulnerability Management capabilities. (2) Threat & Vulnerability Management navigation pane | Use the navigation pane to move across the **Threat and Vulnerability Management Dashboard**, **Security recommendations**, **Remediation**, **Software inventory**, and **Weaknesses**. **Dashboards** | Get a high-level view of the organization exposure score, organization configuration score, machine exposure distribution, top security recommendations, top vulnerable software, top remediation activities, and top exposed machines data. -**Security recommendations** | See the list of security recommendations, their related components, whether software in your network have reached their end-of-life, insights, number or exposed devices, impact, and request for remediation. You can click each item on the list, a flyout panel opens with vulnerability details, open the software page, see the remediation, and exception options. You can also open a ticket in Intune if your machines are joined through Azure Active Directory and you have enabled your Intune connections in Microsoft Defender ATP. See [Security recommendations](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation) for more information. +**Security recommendations** | See the list of security recommendations, their related components, whether the software in your network have reached their end-of-life, insights, number or exposed devices, impact, and request for remediation. You can click each item on the list, a flyout panel opens with vulnerability details, open the software page, see the remediation, and exception options. You can also open a ticket in Intune if your machines are joined through Azure Active Directory and you have enabled your Intune connections in Microsoft Defender ATP. See [Security recommendations](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation) for more information. **Remediation** | See the remediation activity, related component, remediation type, status, due date, option to export the remediation and process data to CSV, and active exceptions. See [Remediation and exception](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-remediation) for more information. **Software inventory** | See the list of software, versions, weaknesses, whether there’s an exploit found on the software, whether the software has reached its end-of-life, prevalence in the organization, how many were installed, how many exposed devices are there, and the numerical value of the impact. You can select each item in the list and opt to open the software page which shows the associated vulnerabilities, misconfigurations, affected machine, version distribution details, and missing KBs or security updates. See [Software inventory](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory) for more information. **Weaknesses** | See the list of common vulnerabilities and exposures, the severity, its common vulnerability scoring system (CVSS) V3 score, related software, age, when it was published, related threat alerts, and how many exposed machines are there. You can select each item in the list and it opens a flyout panel with the vulnerability description and other details. See [Weaknesses](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses) for more information. From ea2b16b77d5460ca0efc98f4b972e9d458e231f2 Mon Sep 17 00:00:00 2001 From: martyav Date: Thu, 5 Dec 2019 16:43:18 -0500 Subject: [PATCH 123/209] rest of list reviewed --- windows/client-management/mdm/networkproxy-csp.md | 2 +- ...xes-with-the-query-tool-in-compatibility-administrator.md | 5 ----- windows/deployment/update/update-compliance-wd-av-status.md | 2 +- ...trusted-platform-module-services-group-policy-settings.md | 2 +- windows/security/threat-protection/auditing/audit-sam.md | 3 --- .../threat-protection/microsoft-defender-atp/files.md | 1 - .../microsoft-defender-atp/get-domain-related-alerts.md | 1 - 7 files changed, 3 insertions(+), 13 deletions(-) diff --git a/windows/client-management/mdm/networkproxy-csp.md b/windows/client-management/mdm/networkproxy-csp.md index 8d7aa80999..c82e246263 100644 --- a/windows/client-management/mdm/networkproxy-csp.md +++ b/windows/client-management/mdm/networkproxy-csp.md @@ -84,7 +84,7 @@ Valid values: The data type is integer. Supported operations are Get and Replace. Starting in Windows 10, version 1803, the Delete operation is also supported. -# Configuration Example +## Configuration Example These generic code portions for the options **ProxySettingsPerUser**, **Autodetect**, and **SetupScriptURL** can be used for a specific operation, for example Replace. Only enter the portion of code needed in the **Replace** section. ```xml diff --git a/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md b/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md index 5bc84062d1..6135a8daf8 100644 --- a/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md +++ b/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md @@ -30,13 +30,8 @@ You can access the Query tool from within Compatibility Administrator. The Query For information about the Search feature, see [Searching for Fixed Applications in Compatibility Administrator](searching-for-fixed-applications-in-compatibility-administrator.md). However, the Query tool provides more detailed search criteria, including tabs that enable you to search the program properties, the compatibility fix properties, and the fix description. You can perform a search by using SQL SELECT and WHERE clauses, in addition to searching specific types of databases. -<<<<<<< HEAD > [!IMPORTANT] > You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator. -======= ->[!IMPORTANT] ->You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator. ->>>>>>> bfaab3359a63dde24e6d0dca11b841e045c481f6 ## Querying by Using the Program Properties Tab diff --git a/windows/deployment/update/update-compliance-wd-av-status.md b/windows/deployment/update/update-compliance-wd-av-status.md index a6c324c71c..edc9156531 100644 --- a/windows/deployment/update/update-compliance-wd-av-status.md +++ b/windows/deployment/update/update-compliance-wd-av-status.md @@ -23,7 +23,7 @@ The Windows Defender AV Status section deals with data concerning signature and >[!NOTE] >Update Compliance's Windows Defender Antivirus status is compatible with E3, B, F1, VL Professional and below licenses. Devices with an E5 license are not shown here; devices with an E5 license can be monitored using the [Windows Defender ATP portal](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection). If you'd like to learn more about Windows 10 licensing, see the [Windows 10 product licensing options](https://www.microsoft.com/Licensing/product-licensing/windows10.aspx). -# Windows Defender AV Status sections +## Windows Defender AV Status sections The **Protection Status** blade gives a count for devices that have either out-of-date signatures or real-time protection turned off. Below, it gives a more detailed breakdown of the two issues. Selecting any of these statuses will navigate you to a Log Search view containing the query. The **Threat Status** blade shows, among devices that have encountered threats, how many were and were not remediated successfully. It also provides a detailed count. Selecting either of these will take you to the respective query in Log Search for further investigation. diff --git a/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md b/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md index f8b477aa62..e39a4d1c9a 100644 --- a/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md +++ b/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md @@ -131,7 +131,7 @@ Introduced in Windows 10, version 1703, this policy setting configures the TPM t > - Disable it from group policy > - Clear the TPM on the system -# TPM Group Policy settings in the Windows Security app +## TPM Group Policy settings in the Windows Security app You can change what users see about TPM in the Windows Security app. The Group Policy settings for the TPM area in the Windows Security app are located at: diff --git a/windows/security/threat-protection/auditing/audit-sam.md b/windows/security/threat-protection/auditing/audit-sam.md index 31d65aafb1..10c0796852 100644 --- a/windows/security/threat-protection/auditing/audit-sam.md +++ b/windows/security/threat-protection/auditing/audit-sam.md @@ -56,6 +56,3 @@ For information about reducing the number of events generated in this subcategor **Events List:** - [4661](event-4661.md)(S, F): A handle to an object was requested. - -# - diff --git a/windows/security/threat-protection/microsoft-defender-atp/files.md b/windows/security/threat-protection/microsoft-defender-atp/files.md index d5014d44ed..2bb588f0ce 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/files.md @@ -50,4 +50,3 @@ signer | String | File signer. issuer | String | File issuer. signerHash | String | Hash of the signing certificate. isValidCertificate | Boolean | Was signing certificate successfully verified by Microsoft Defender ATP agent. - diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md index 1b7847ce57..18ead32cb5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md @@ -123,4 +123,3 @@ Content-type: application/json ] } ``` - From 07c59aefb6ae448135ce20325693e14527060958 Mon Sep 17 00:00:00 2001 From: Gary Moore Date: Thu, 5 Dec 2019 14:27:58 -0800 Subject: [PATCH 124/209] Indented a note in a procedure step --- .../microsoft-defender-atp/tvm-software-inventory.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md index 4d74df5c5b..860a12a293 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md @@ -55,8 +55,8 @@ You can report a false positive when you see any vague, inaccurate version, inco 5. Include your machine name for investigation context. ->[!NOTE] -> You can also provide details regarding the inaccuracy you reported in the **Tell us more (optional)** field to give the threat and vulnerability management investigators context. + >[!NOTE] + > You can also provide details regarding the inaccuracy you reported in the **Tell us more (optional)** field to give the threat and vulnerability management investigators context. 6. Click **Submit**. Your feedback is immediately sent to the Threat & Vulnerability Management experts with its context. From e5fd1e5a6d54f42239c78eb90da2ca0fe48991da Mon Sep 17 00:00:00 2001 From: Gary Moore Date: Thu, 5 Dec 2019 14:41:18 -0800 Subject: [PATCH 125/209] Demoted two headings that were subordinate Since "TPM Group Policy settings in the Windows Security app" has been moved from H1 to H2, I change the two subordinate headings from H2 to H3. --- .../trusted-platform-module-services-group-policy-settings.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md b/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md index e39a4d1c9a..94634c4b79 100644 --- a/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md +++ b/windows/security/information-protection/tpm/trusted-platform-module-services-group-policy-settings.md @@ -137,10 +137,10 @@ You can change what users see about TPM in the Windows Security app. The Group P **Computer Configuration\\Administrative Templates\\Windows Components\\Windows Security\\Device security** -## Disable the Clear TPM button +### Disable the Clear TPM button If you don't want users to be able to click the **Clear TPM** button in the Windows Security app, you can disable it with this Group Policy setting. Select **Enabled** to make the **Clear TPM** button unavailable for use. -## Hide the TPM Firmware Update recommendation +### Hide the TPM Firmware Update recommendation If you don't want users to see the recommendation to update TPM firmware, you can disable it with this setting. Select **Enabled** to prevent users from seeing a recommendation to update their TPM firmware when a vulnerable firmware is detected. ## Related topics From 38bbf60be67e9c2e0e78502c4785d51686580030 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 5 Dec 2019 16:10:44 -0800 Subject: [PATCH 126/209] updating applies to --- windows/privacy/Microsoft-DiagnosticDataViewer.md | 3 +-- windows/privacy/diagnostic-data-viewer-overview.md | 3 +-- windows/privacy/gdpr-it-guidance.md | 8 ++------ windows/privacy/windows-10-and-privacy-compliance.md | 6 ++---- .../windows-personal-data-services-configuration.md | 2 +- 5 files changed, 7 insertions(+), 15 deletions(-) diff --git a/windows/privacy/Microsoft-DiagnosticDataViewer.md b/windows/privacy/Microsoft-DiagnosticDataViewer.md index f1560f3a73..98e412e213 100644 --- a/windows/privacy/Microsoft-DiagnosticDataViewer.md +++ b/windows/privacy/Microsoft-DiagnosticDataViewer.md @@ -21,8 +21,7 @@ ms.reviewer: **Applies to** -- Windows 10, version 1809 -- Windows 10, version 1803 +- Windows 10, version 1803 and newer - Windows Server, version 1803 - Windows Server 2019 diff --git a/windows/privacy/diagnostic-data-viewer-overview.md b/windows/privacy/diagnostic-data-viewer-overview.md index 31d91bd6a5..64cfa25866 100644 --- a/windows/privacy/diagnostic-data-viewer-overview.md +++ b/windows/privacy/diagnostic-data-viewer-overview.md @@ -21,8 +21,7 @@ ms.reviewer: **Applies to** -- Windows 10, version 1809 -- Windows 10, version 1803 +- Windows 10, version 1803 and newer ## Introduction The Diagnostic Data Viewer is a Windows app that lets you review the Windows diagnostic data your device is sending to Microsoft, grouping the info into simple categories based on how it's used by Microsoft. diff --git a/windows/privacy/gdpr-it-guidance.md b/windows/privacy/gdpr-it-guidance.md index b268fb53f1..892203bace 100644 --- a/windows/privacy/gdpr-it-guidance.md +++ b/windows/privacy/gdpr-it-guidance.md @@ -19,13 +19,9 @@ ms.reviewer: # Windows and the GDPR: Information for IT Administrators and Decision Makers Applies to: -- Windows 10, version 1809 -- Windows 10, version 1803 -- Windows 10, version 1709 -- Windows 10, version 1703 +- Windows 10, version 1703 and newer - Windows 10 Team Edition, version 1703 for Surface Hub -- Windows Server 2019 -- Windows Server 2016 +- Windows Server 2016 and newer - Desktop Analytics This topic provides IT Decision Makers with a basic understanding of the relationship between users in an organization and Microsoft in the context of the GDPR (General Data Protection Regulation). You will also learn what role an IT organization plays for that relationship. diff --git a/windows/privacy/windows-10-and-privacy-compliance.md b/windows/privacy/windows-10-and-privacy-compliance.md index 04e1b3af64..50ebcf0f14 100644 --- a/windows/privacy/windows-10-and-privacy-compliance.md +++ b/windows/privacy/windows-10-and-privacy-compliance.md @@ -19,11 +19,9 @@ ms.date: 05/21/2019 # Windows 10 & Privacy Compliance:
A Guide for IT and Compliance Professionals Applies to: -- Windows 10, version 1903 -- Windows 10, version 1809 +- Windows 10, version 1809 and newer - Windows 10 Team Edition, version 1703 for Surface Hub -- Windows Server 2019 -- Windows Server 2016 +- Windows Server 2016 and newer - Windows Analytics For more information about the GDPR, see: diff --git a/windows/privacy/windows-personal-data-services-configuration.md b/windows/privacy/windows-personal-data-services-configuration.md index 93c2b4da00..1366bdd1e6 100644 --- a/windows/privacy/windows-personal-data-services-configuration.md +++ b/windows/privacy/windows-personal-data-services-configuration.md @@ -19,7 +19,7 @@ ms.reviewer: # Windows 10 personal data services configuration Applies to: -- Windows 10, version 1803 +- Windows 10, version 1803 and newer Microsoft assembled a list of Windows 10 services configuration settings that are useful for personal data privacy protection and related regulations, such as the General Data Protection Regulation (GDPR). There is one section with settings for service data that is managed at Microsoft and a section for local data that is managed by an IT organization. From 5560ed6f6e95c3891566a08ff7da54f8165e2deb Mon Sep 17 00:00:00 2001 From: David Strome Date: Thu, 5 Dec 2019 16:36:37 -0800 Subject: [PATCH 127/209] Revert "MSDATP: merge Note into find-machines-by-ip.md" This reverts commit 85b5baaf518047fb04ebf8a892d89276c7117cf1. --- .../find-machines-by-ip.md | 51 +++++++++---------- .../improve-request-performance.md | 26 ++++++++++ 2 files changed, 49 insertions(+), 28 deletions(-) create mode 100644 windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index da798752be..99d7204f17 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -29,15 +29,16 @@ The given timestamp must be in the past 30 days. ## Permissions One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) -Permission type | Permission | Permission display name +Permission type | Permission | Permission display name :---|:---|:--- -Application | Machine.Read.All | 'Read all machine profiles' -Application | Machine.ReadWrite.All | 'Read and write all machine information' +Application | Machine.Read.All | 'Read all machine profiles' +Application | Machine.ReadWrite.All | 'Read and write all machine information' Delegated (work or school account) | Machine.Read | 'Read machine information' Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine information' -> [!Note] +>[!Note] > When obtaining a token using user credentials: +> - Response will include only machines that the user have access to based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) > - The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) > - Response will include only machines that the user have access to based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) @@ -57,7 +58,7 @@ Empty ## Response If successful and machines were found - 200 OK with list of the machines in the response body. -If no machine found - 404 Not Found. +If no machine found - 404 Not Found. If the timestamp is not in the past 30 days - 400 Bad Request. ## Example @@ -66,18 +67,12 @@ If the timestamp is not in the past 30 days - 400 Bad Request. Here is an example of the request. +[!include[Improve request performance](improve-request-performance.md)] + ``` GET https://api.securitycenter.windows.com/api/machines/findbyip(ip='10.248.240.38',timestamp=2018-09-22T08:44:05Z) ``` -## Improve request performance - -> [!NOTE] -> You can use a server closer to your geolocation for better performance: -> - api-us.securitycenter.windows.com -> - api-eu.securitycenter.windows.com -> - api-uk.securitycenter.windows.com - **Response** Here is an example of the response. @@ -90,21 +85,21 @@ Content-type: application/json "value": [ { "id": "1e5bc9d7e413ddd7902c2932e418702b84d0cc07", - "computerDnsName": "mymachine1.contoso.com", - "firstSeen": "2018-08-02T14:55:03.7791856Z", - "lastSeen": "2018-09-22T08:55:03.7791856Z", - "osPlatform": "Windows10", - "osVersion": "10.0.0.0", - "lastIpAddress": "10.248.240.38", - "lastExternalIpAddress": "167.220.196.71", - "agentVersion": "10.5830.18209.1001", - "osBuild": 18209, - "healthStatus": "Active", - "rbacGroupId": 140, - "rbacGroupName": "The-A-Team", - "riskScore": "Low", - "aadDeviceId": "80fe8ff8-2624-418e-9591-41f0491218f9", - "machineTags": [ "test tag 1", "test tag 2" ] + "computerDnsName": "mymachine1.contoso.com", + "firstSeen": "2018-08-02T14:55:03.7791856Z", + "lastSeen": "2018-09-22T08:55:03.7791856Z", + "osPlatform": "Windows10", + "osVersion": "10.0.0.0", + "lastIpAddress": "10.248.240.38", + "lastExternalIpAddress": "167.220.196.71", + "agentVersion": "10.5830.18209.1001", + "osBuild": 18209, + "healthStatus": "Active", + "rbacGroupId": 140, + "rbacGroupName": "The-A-Team", + "riskScore": "Low", + "aadDeviceId": "80fe8ff8-2624-418e-9591-41f0491218f9", + "machineTags": [ "test tag 1", "test tag 2" ] } ] } diff --git a/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md b/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md new file mode 100644 index 0000000000..880f5e4d11 --- /dev/null +++ b/windows/security/threat-protection/microsoft-defender-atp/improve-request-performance.md @@ -0,0 +1,26 @@ +--- +title: Improve request performance +description: Improve request performance +keywords: server, request, performance +search.product: eADQiWindows 10XVcnh +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: macapara +author: mjcaparas +ms.localizationpriority: medium +manager: dansimp +audience: ITPro +ms.collection: M365-security-compliance +ms.topic: article +--- + +# Improve request performance + + +>[!NOTE] +>For better performance, you can use server closer to your geo location: +> - api-us.securitycenter.windows.com +> - api-eu.securitycenter.windows.com +> - api-uk.securitycenter.windows.com \ No newline at end of file From 5722474f1087bfa636751dce12c8b1886b137ef2 Mon Sep 17 00:00:00 2001 From: David Strome Date: Thu, 5 Dec 2019 16:37:25 -0800 Subject: [PATCH 128/209] remove extra space --- .../microsoft-defender-atp/find-machines-by-ip.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index 99d7204f17..4f66d7199a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -58,7 +58,7 @@ Empty ## Response If successful and machines were found - 200 OK with list of the machines in the response body. -If no machine found - 404 Not Found. +If no machine found - 404 Not Found. If the timestamp is not in the past 30 days - 400 Bad Request. ## Example From 924d07341a0f70104b3e3907b5bbf2e95e26884d Mon Sep 17 00:00:00 2001 From: David Strome Date: Thu, 5 Dec 2019 16:49:34 -0800 Subject: [PATCH 129/209] http -> https --- devices/hololens/hololens2-start.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/devices/hololens/hololens2-start.md b/devices/hololens/hololens2-start.md index 3f7c1fe6ae..78d3697f03 100644 --- a/devices/hololens/hololens2-start.md +++ b/devices/hololens/hololens2-start.md @@ -26,9 +26,9 @@ Before you get started, make sure you have the following available: **A network connection**. You'll need to connect your HoloLens to a network to set it up. With HoloLens 2, you can connect with Wi-Fi or by using ethernet (you'll need a USB-C-to-Ethernet adapter). The first time you connect, you'll need an open or password-protected network that doesn't require navigating to a website or using certificates to connect. [Learn more about the websites that HoloLens uses](hololens-offline.md). -**A Microsoft account**. You'll also need to sign in to HoloLens with a Microsoft account (or with your work account, if your organization owns the device). If you don't have a Microsoft account, go to [account.microsoft.com](http://account.microsoft.com) and set one up for free. +**A Microsoft account**. You'll also need to sign in to HoloLens with a Microsoft account (or with your work account, if your organization owns the device). If you don't have a Microsoft account, go to [account.microsoft.com](https://account.microsoft.com) and set one up for free. -**A safe, well-lit space with no tripping hazards**. [Health and safety info](http://go.microsoft.com/fwlink/p/?LinkId=746661). +**A safe, well-lit space with no tripping hazards**. [Health and safety info](https://go.microsoft.com/fwlink/p/?LinkId=746661). **The optional comfort accessories** that came with your HoloLens, to help you get the most comfortable fit. [More on fit and comfort](hololens2-setup.md#adjust-fit). From b97d876daed94d8506b0232a7ad038b954a8334d Mon Sep 17 00:00:00 2001 From: Deland-Han Date: Fri, 6 Dec 2019 14:16:17 +0800 Subject: [PATCH 130/209] finished --- .../threat-protection/auditing/event-4716.md | 66 +++++++++++++++++++ 1 file changed, 66 insertions(+) diff --git a/windows/security/threat-protection/auditing/event-4716.md b/windows/security/threat-protection/auditing/event-4716.md index 505106fe5e..5f387634cc 100644 --- a/windows/security/threat-protection/auditing/event-4716.md +++ b/windows/security/threat-protection/auditing/event-4716.md @@ -154,3 +154,69 @@ For 4716(S): Trusted domain information was modified. - Any changes in Active Directory domain trust settings must be monitored and alerts should be triggered. If this change was not planned, investigate the reason for the change. +## Anonymous Logon + +If the account reported in the event is **Anonymous Logon**, it means the password is changed by system automatic password reset. For example: + +``` +Log Name: Security +Source: Microsoft-Windows-Security-Auditing +Date: