mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-15 23:07:23 +00:00
Merge remote-tracking branch 'origin/master' into atp-auto-ir
This commit is contained in:
commit
3c7f970fc0
@ -4907,7 +4907,7 @@
|
||||
},
|
||||
{
|
||||
"source_path": "windows/manage/configure-windows-telemetry-in-your-organization.md",
|
||||
"redirect_url": "/windows/configuration/configure-windows-telemetry-in-your-organization",
|
||||
"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization",
|
||||
"redirect_document_id": true
|
||||
},
|
||||
{
|
||||
@ -5932,7 +5932,12 @@
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configure/configure-windows-telemetry-in-your-organization.md",
|
||||
"redirect_url": "/windows/configuration/configure-windows-telemetry-in-your-organization",
|
||||
"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization",
|
||||
"redirect_document_id": true
|
||||
},
|
||||
{
|
||||
"source_path": "windows/configuration/configure-windows-telemetry-in-your-organization.md",
|
||||
"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization",
|
||||
"redirect_document_id": true
|
||||
},
|
||||
{
|
||||
|
@ -12,7 +12,7 @@ ms.date: 07/27/2017
|
||||
|
||||
# Enroll HoloLens in MDM
|
||||
|
||||
You can manage multiple Microsoft HoloLens devices simultaneously using solutions like Microsoft Intune. You will be able to manage settings, select apps to install and set security configurations tailored to your organization's need. See the [configuration service providers (CSPs) that are supported in Windows Holographic](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/configuration-service-provider-reference#hololens) and the [policies supported by Windows Holographic for Business](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#hololenspolicies).
|
||||
You can manage multiple Microsoft HoloLens devices simultaneously using solutions like Microsoft Intune. You will be able to manage settings, select apps to install and set security configurations tailored to your organization's need. See [Manage devices running Windows Holographic with Microsoft Intune](https://docs.microsoft.com/intune/windows-holographic-for-business), the [configuration service providers (CSPs) that are supported in Windows Holographic](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/configuration-service-provider-reference#hololens), and the [policies supported by Windows Holographic for Business](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#hololenspolicies).
|
||||
|
||||
>[!NOTE]
|
||||
>Mobile device management (MDM), including the VPN, Bitlocker, and kiosk mode features, is only available when you [upgrade to Windows Holographic for Business](hololens-upgrade-enterprise.md).
|
||||
|
@ -8,7 +8,7 @@ ms.sitesec: library
|
||||
ms.pagetype: surfacehub
|
||||
author: jdeckerms
|
||||
ms.author: jdecker
|
||||
ms.date: 01/17/2018
|
||||
ms.date: 02/16/2018
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
@ -16,6 +16,12 @@ ms.localizationpriority: medium
|
||||
|
||||
This topic lists new and updated topics in the [Surface Hub Admin Guide]( surface-hub-administrators-guide.md).
|
||||
|
||||
## February 2018
|
||||
|
||||
New or changed topic | Description
|
||||
--- | ---
|
||||
[Manage settings with an MDM provider (Surface Hub)](manage-settings-with-mdm-for-surface-hub.md) | Updated instructions for custom settings using Microsoft Intune.
|
||||
|
||||
## January 2018
|
||||
|
||||
New or changed topic | Description
|
||||
|
@ -9,7 +9,7 @@ ms.sitesec: library
|
||||
ms.pagetype: surfacehub, mobility
|
||||
author: jdeckerms
|
||||
ms.author: jdecker
|
||||
ms.date: 01/17/2018
|
||||
ms.date: 02/16/2018
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
@ -212,38 +212,9 @@ The data type is also stated in the CSP documentation. The most common data type
|
||||
<span id="example-intune">
|
||||
## Example: Manage Surface Hub settings with Microsoft Intune
|
||||
|
||||
You can use Microsoft Intune to manage Surface Hub settings.
|
||||
You can use Microsoft Intune to manage Surface Hub settings. For custom settings, follow the instructions in [How to configure custom device settings in Microsoft Intune](https://docs.microsoft.com/intune/custom-settings-configure). For **Platform**, select **Windows 10 and later**, and in **Profile type**, select **Device restrictions (Windows 10 Team)**.
|
||||
|
||||
**To create a configuration policy from a template**
|
||||
|
||||
You'll use the **Windows 10 Team general configuration policy** as the template.
|
||||
|
||||
1. On the [Intune management portal](https://manage.microsoft.com), sign in with your Intune administrator account.
|
||||
2. On the left-hand navigation menu, click **Policy**.
|
||||
3. In the Overview page, click **Add Policy**.
|
||||
4. On **Select a template for the new policy**, expand **Windows**, select **General Configuration (Windows 10 Team and later)**, and then click **Create Policy**.
|
||||
|
||||

|
||||
5. Configure your policy, then click **Save Policy**
|
||||
|
||||

|
||||
6. When prompted, click **Yes** to deploy your new policy to a user or device group. For more information, see [Use groups to manage users and devices in Microsoft Intune](https://docs.microsoft.com/intune/deploy-use/use-groups-to-manage-users-and-devices-with-microsoft-intune).
|
||||
|
||||
**To create a custom configuration policy**
|
||||
|
||||
You’ll need to create a custom policy using the **Custom Configuration (Windows 10 Desktop and Mobile and later)** template to manage settings that are not available in the **Windows 10 Team general configuration policy** template.
|
||||
|
||||
1. On the [Intune management portal](https://manage.microsoft.com), sign in with your Intune administrator account.
|
||||
2. On the left-hand navigation menu, click **Policy**.
|
||||
3. On the Overview page, click **Add Policy**.
|
||||
4. On **Select a template for the new policy**, expand **Windows**, select **Custom Configuration (Windows 10 Desktop and Mobile and later)**, and then click **Create Policy**.
|
||||
5. Type a name and optional description for the policy.
|
||||
6. Under OMA-URI Settings, click **Add**.
|
||||
7. Complete the form to create a new setting, and then click **OK**.
|
||||
|
||||

|
||||
8. Repeat Steps 6 and 7 for each setting you want to configure with this policy.
|
||||
9. After you're done, click **Save Policy** and deploy it to a user or device group.
|
||||
|
||||
<span id="example-sccm">
|
||||
## Example: Manage Surface Hub settings with System Center Configuration Manager
|
||||
|
@ -28,7 +28,7 @@ The customized Start menu is defined in a Start layout XML file. You have two op
|
||||
- Configure the desired Start menu on a desktop (pinning only apps that are available on Surface Hub), and then [export the layout](https://docs.microsoft.com/windows/configuration/customize-and-export-start-layout#export-the-start-layout).
|
||||
|
||||
>[!TIP]
|
||||
>To add a tile with a web link to your desktop start menu, go the the link in Microsoft Edge, select `...` in the top right corner, and select **Pin this page to Start**. See [a Start layout that includes a Microsoft Edge link](#edge) for an example of how links will appear in the XML.
|
||||
>To add a tile with a web link to your desktop start menu, go to the link in Microsoft Edge, select `...` in the top right corner, and select **Pin this page to Start**. See [a Start layout that includes a Microsoft Edge link](#edge) for an example of how links will appear in the XML.
|
||||
|
||||
To edit the default XML or the exported layout, familiarize yourself with the [Start layout XML](https://docs.microsoft.com/en-us/windows/configuration/start-layout-xml-desktop). There are a few [differences between Start layout on a deskop and a Surface Hub.](#differences)
|
||||
|
||||
|
@ -55,6 +55,7 @@
|
||||
#### [How to Enable BitLocker by Using MBAM as Part of a Windows Deployment](how-to-enable-bitlocker-by-using-mbam-as-part-of-a-windows-deploymentmbam-25.md)
|
||||
#### [How to Deploy the MBAM Client by Using a Command Line](how-to-deploy-the-mbam-client-by-using-a-command-line.md)
|
||||
### [MBAM 2.5 Deployment Checklist](mbam-25-deployment-checklist.md)
|
||||
### [Upgrading to MBAM 2.5 SP1 from MBAM 2.5](upgrading-to-mbam-25-sp1-from-mbam-25.md)
|
||||
### [Upgrading to MBAM 2.5 or MBAM 2.5 SP1 from Previous Versions](upgrading-to-mbam-25-or-mbam-25-sp1-from-previous-versions.md)
|
||||
### [Removing MBAM Server Features or Software](removing-mbam-server-features-or-software.md)
|
||||
## [Operations for MBAM 2.5](operations-for-mbam-25.md)
|
||||
|
44
mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md
Normal file
44
mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md
Normal file
@ -0,0 +1,44 @@
|
||||
---
|
||||
title: Upgrading to MBAM 2.5 SP1 from MBAM 2.5
|
||||
description: Upgrading to MBAM 2.5 SP1 from MBAM 2.5
|
||||
author: kaushika-msft
|
||||
ms.assetid:
|
||||
ms.pagetype: mdop, security
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.prod: w10
|
||||
ms.date: 2/16/2018
|
||||
---
|
||||
|
||||
# Upgrading to MBAM 2.5 SP1 from MBAM 2.5
|
||||
This topic describes the process for upgrading the Microsoft BitLocker Administration and Monitoring (MBAM) Server 2.5 and the MBAM Client from 2.5 to MBAM 2.5 SP1.
|
||||
|
||||
### Before you begin, download the September 2017 servicing release
|
||||
[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=56126)
|
||||
|
||||
#### Steps to upgrade the MBAM Database (SQL Server)
|
||||
1. Using the MBAM Configurator; remove the Reports roll from the SQL server, or wherever the SSRS database is housed (Could be on the same server or different one, depending on your environment)
|
||||
Note: You will not see an option to remove the Databases; this is expected.
|
||||
2. Install 2.5 SP1 (Located with MDOP - Microsoft Desktop Optimization Pack 2015 from the Volume Licensing Service Center site: <https://www.microsoft.com/Licensing/servicecenter/default.aspx>
|
||||
3. Do not configure it at this time
|
||||
4. Install the September Rollup: https://www.microsoft.com/en-us/download/details.aspx?id=56126
|
||||
5. Using the MBAM Configurator; re-add the Reports rollup
|
||||
6. This will configure the SSRS connection using the latest MBAM code from the rollup
|
||||
7. Using the MBAM Configurator; re-add the SQL Database roll on the SQL Server.
|
||||
- At the end, you will be warned that the DBs already exist and weren’t created, but this is expected.
|
||||
- This process updates the existing databases to the current version being installed
|
||||
|
||||
#### Steps to upgrade the MBAM Server (Running MBAM and IIS)
|
||||
1. Using the MBAM Configurator; remove the Admin and Self Service Portals from the IIS server
|
||||
2. Install MBAM 2.5 SP1
|
||||
3. Do not configure it at this time
|
||||
4. Install the September 2017 Rollup on the IIS server(https://www.microsoft.com/en-us/download/details.aspx?id=56126)
|
||||
5. Using the MBAM Configurator; re-add the Admin and Self Service Portals to the IIS server
|
||||
6. This will configure the sites using the latest MBAM code from the June Rollup
|
||||
- Open an elevated command prompt, Type: **IISRESET** and Hit Enter.
|
||||
|
||||
#### Steps to upgrade the MBAM Clients/Endpoints
|
||||
1. Uninstall the 2.5 Agent from client endpoints
|
||||
2. Install the 2.5 SP1 Agent on the client endpoints
|
||||
3. Push out the September Rollup Client update to clients running the 2.5 SP1 Agent
|
||||
4. There is no need to uninstall existing client prior to installing the September Rollup.
|
BIN
store-for-business/images/msfb-ps-collection-idp.png
Normal file
BIN
store-for-business/images/msfb-ps-collection-idp.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 72 KiB |
BIN
store-for-business/images/perf-improvement-icon.png
Normal file
BIN
store-for-business/images/perf-improvement-icon.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 10 KiB |
BIN
store-for-business/images/private-store-icon.png
Normal file
BIN
store-for-business/images/private-store-icon.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 4.7 KiB |
@ -7,7 +7,7 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: store
|
||||
author: TrudyHa
|
||||
ms.date: 11/30/2017
|
||||
ms.date: 2/15/2018
|
||||
ms.localizationpriority: high
|
||||
---
|
||||
|
||||
@ -25,7 +25,7 @@ The name of your private store is shown on a tab in Microsoft Store app, or on [
|
||||

|
||||
|
||||
You can change the name of your private store in Microsoft Store.
|
||||
<!---
|
||||
|
||||
## Change private store name
|
||||
**To change the name of your private store**
|
||||
|
||||
@ -36,10 +36,14 @@ You can change the name of your private store in Microsoft Store.
|
||||
|
||||

|
||||
|
||||
## Add a Collection
|
||||
## Private store collections
|
||||
You can create collections of apps within your private store. Collections allow you to group or categorize apps - you might want a group of apps for different job functions in your company, or classes in your school.
|
||||
|
||||
**To add a collection to your private store**
|
||||
**To add a Collection to your private store**
|
||||
|
||||
You can add a collection to your private store from the private store, or from the details page for an app.
|
||||
|
||||
**From private store**
|
||||
1. Sign in to [Microsoft Store for Business](http://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com).
|
||||
2. Click your private store.</br>
|
||||
|
||||
@ -48,8 +52,56 @@ You can create collections of apps within your private store. Collections allow
|
||||
|
||||

|
||||
|
||||
4. Enter a name for your collection, and then click **Next**.
|
||||
5. Add products to ytour collection, and then click **Done**.
|
||||
4. Type a name for your collection, and then click **Next**.
|
||||
5. Add at least one product to your collection, and then click **Done**.
|
||||
|
||||
Currently, it takes about thirty-six hours for new collections to be available in your private store.
|
||||
> [!NOTE]
|
||||
> New collections require at least one app, or they will not be created.
|
||||
|
||||
**From app details page**
|
||||
1. Sign in to [Microsoft Store for Business](http://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com).
|
||||
2. Click **Manage**, and then click **Products & services**.
|
||||
3. Under **Apps & software**, choose an app you want to include in a new collection.
|
||||
4. Under **Private Store Collections**, click **Add a collection**.
|
||||
|
||||

|
||||
|
||||
5. Type a name for your collection, and then click **Next**.
|
||||
6. Add at least one product to your collection, and then click **Done**.
|
||||
|
||||
Currently, changes to collections will generally show within minutes in the Microsoft Store app on Windows 10. In some cases, it may take up an hour.
|
||||
|
||||
## Edit Collections
|
||||
If you've already added a Collection to your private store, you can easily add and remove products, or rename the collection.
|
||||
|
||||
**To add or remove products from a collection**
|
||||
1. Sign in to [Microsoft Store for Business](http://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com).
|
||||
2. Click your private store.</br>
|
||||
|
||||

|
||||
|
||||
3. Click the ellipses next to the collection name, and click **Edit collection**.
|
||||
4. Add or remove products from the collection, and then click **Done**.
|
||||
|
||||
You can also add an app to a collection from the app details page.
|
||||
1. Sign in to [Microsoft Store for Business](http://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com).
|
||||
2. Click **Manage**, and then click **Products & services**.
|
||||
3. Under **Apps & software**, choose an app you want to include in a new collection.
|
||||
4. Under **Private Store Collections**, turn on the collection you want to add the app to.
|
||||
|
||||

|
||||
|
||||
<!---
|
||||
## Private store performance
|
||||
We've recently made performance improvements for changes in the private store. This table includes common actions, and the current estimate for amount of time required for the change.
|
||||
|
||||
| Action | Estimated time |
|
||||
| ------------------------------------------------------ | -------------- |
|
||||
| Add a product to the private store <br> - Apps recently added to your inventory, including line-of-business (LOB) apps and new purchases, will take up to 36 hours to add to the private store. That time begins when the product is purchased, or added to your inventory. <br> - It will take an additional 36 hours for the product to be searchable in private store, even if you see the app available from the private store tab. | - 15 minutes: available on private store tab <br> - 36 hours: searchable in private store <br> - 36 hours: available on private store tab, if the product has just been added to inventory |
|
||||
| Remove a product from private store | - 15 minutes: private store tab <br> - 36 hours: searchable in private store |
|
||||
| Accept a new LOB app into your inventory (under **Products & services)**) | 36 hours |
|
||||
| Create a new collection | 15 minutes|
|
||||
| Edit or remove a collection | 15 minutes |
|
||||
| Create private store tab | 4-6 hours |
|
||||
| Rename private store tab | 4-6 hours |
|
||||
-->
|
@ -6,7 +6,7 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: store
|
||||
author: TrudyHa
|
||||
ms.date: 2/8/2018
|
||||
ms.date: 2/16/2018
|
||||
---
|
||||
|
||||
# What's new in Microsoft Store for Business and Education
|
||||
@ -15,11 +15,12 @@ Microsoft Store for Business and Education regularly releases new and improved f
|
||||
|
||||
## Latest updates for Store for Business and Education
|
||||
|
||||
**January 2018**
|
||||
**January & February, 2018**
|
||||
|
||||
| | |
|
||||
|--------------------------------------|---------------------------------|
|
||||
|  |**One place for apps, software, and subscriptions**<br /><br /> The new **Products & services** page in Microsoft Store for Business and Education gives customers a single place to manage all products and services. This includes Apps, Software, and Subscriptions that your organization acquired or manages through Microsoft Store for Business. This change centralizes these products, but the platform changes also improve overall performance. <br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|  |**Create collections of apps in your private store**<br /><br /> Use **collections** to customize your private store. Collections allow you to create groups of apps that are commonly used in your organization or school -- you might create a collection for a Finance department, or a 6th-grade class.<br /><br />[Get more info](https://docs.microsoft.com/microsoft-store/manage-private-store-settings#private-store-collections)<br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|  |**Upgrade Office 365 trial subscription**<br /><br> Customers with Office 365 trials can now transition their trial to a paid subscription in Microsoft Store for Business. This works for trials you acquired from Microsoft Store for Business, or Office Admin Portal. <br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|  |**Supporting Microsoft Product and Services Agreement customers**<br /><br>If you are purchasing under the Microsoft Products and Services Agreement (MPSA), you can use Microsoft Store for Business. Here you will find access to Products & Services purchased, Downloads & Keys, Software Assurance benefits, Order history, and Agreement details. Also, we added the ability to associate your purchasing account to your tenant. <br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|  |**Microsoft Product and Services Agreement customers can invite people to take roles**<br /><br> MPSA admins can invite people to take Microsoft Store for Business roles even if the person is not in their tenant. You provide an email address when you assign the role, and we'll add the account to your tenant and assign the role. <br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
@ -30,6 +31,7 @@ Microsoft Store for Business and Education regularly releases new and improved f
|
||||
We’ve been working on bug fixes and performance improvements to provide you a better experience. Stay tuned for new features!
|
||||
| | |
|
||||
|-----------------------|---------------------------------|
|
||||
|  |**Performance improvements in private store**<br /><br /> We've made it significantly faster for you to update the private store. Many changes to the private store are available immediately after you make them. <br /><br />[Get more info](https://docs.microsoft.com/microsoft-store/manage-private-store-settings#private-store-performance)<br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
| <iframe width="288" height="232" src="https://www.youtube.com/embed/IpLIZU_j7Z0" frameborder="0" allowfullscreen></iframe>| **Manage Windows device deployment with Windows AutoPilot Deployment** <br /><br /> In Microsoft Store for Business, you can manage devices for your organization and apply an AutoPilot deployment profile to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows, based on the AutoPilot deployment profile you applied to the device.<br /><br />[Get more info](add-profile-to-devices.md)<br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|  |**Request an app**<br /><br />People in your organization can reqest additional licenses for apps in your private store, and then Admins or Purchasers can make the purchases. <br /><br />[Get more info](https://docs.microsoft.com/microsoft-store/acquire-apps-microsoft-store-for-business#request-apps)<br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
||  |**Private store collections**<br /><br> You can groups of apps in your private store with **Collections**. This can help you organize apps and help people find apps for their job or classroom. <br /><br />[Get more info](https://review.docs.microsoft.com/microsoft-store/manage-private-store-settings?branch=msfb-14856406#add-a-collection)<br /><br />**Applies to**:<br /> Microsoft Store for Business <br /> Microsoft Store for Education |
|
||||
|
@ -117,7 +117,7 @@ Here are the typical provisioned Windows apps in Windows 10 versions 1607, 1703,
|
||||
| Get Skype/Skype (preview)/Skype | Microsoft.SkypeApp | x | x | x | Yes |
|
||||
| Get Started/Tips | Microsoft.Getstarted | x | x | x | Yes |
|
||||
| Groove | Microsoft.ZuneMusic | x | x | x | No |
|
||||
| Mail and Calendar | Microsoft.windows communicationsapps | x | x | x | No |
|
||||
| Mail and Calendar | microsoft.windowscommunicationsapps | x | x | x | No |
|
||||
| Maps | Microsoft.WindowsMaps | x | x | x | No |
|
||||
| Messaging | Microsoft.Messaging | x | x | x | No |
|
||||
| Microsoft 3D Viewer | Microsoft.Microsoft3DViewer | | x | x | No |
|
||||
@ -132,7 +132,7 @@ Here are the typical provisioned Windows apps in Windows 10 versions 1607, 1703,
|
||||
| Sticky Notes | Microsoft.MicrosoftStickyNotes | x | x | x | No |
|
||||
| Store | Microsoft.WindowsStore | x | x | x | No |
|
||||
| Sway | Microsoft.Office.Sway | * | * | x | Yes |
|
||||
| Voice Recorder | Microsoft.SoundRecorder | x | x | x | No |
|
||||
| Voice Recorder | Microsoft.WindowsSoundRecorder | x | x | x | No |
|
||||
| Wallet | Microsoft.Wallet | | x | x | No |
|
||||
| Weather | Microsoft.BingWeather | x | x | x | Yes |
|
||||
| Xbox | Microsoft.XboxApp | x | x | x | No |
|
||||
|
@ -34,14 +34,18 @@ The following diagram shows the WindowsDefenderApplicationGuard configuration se
|
||||
<a href="" id="clipboardfiletype"></a>**Settings/ClipboardFileType**
|
||||
<p style="margin-left: 20px">Determines the type of content that can be copied from the host to Application Guard environment and vice versa. Value type is integer. Supported operations are Add, Get, Replace, and Delete.</p>
|
||||
|
||||
- 0 - Allow text copying.
|
||||
- 1 - Allow text and image copying.
|
||||
- 0 - Disables content copying.
|
||||
- 1 - Allow text copying.
|
||||
- 2 - Allow image copying.
|
||||
- 3 - Allow text and image copying.
|
||||
|
||||
<a href="" id="clipboardsettings"></a>**Settings/ClipboardSettings**
|
||||
<p style="margin-left: 20px">This policy setting allows you to decide how the clipboard behaves while in Application Guard. Value type is integer. Supported operations are Add, Get, Replace, and Delete</p>
|
||||
|
||||
- 0 (default) - Completely turns Off the clipboard functionality for the Application Guard.
|
||||
- 1 - Turns On the clipboard functionality and lets you choose whether to additionally enable copying of certain content from Application Guard into Microsoft Edge and enable copying of certain content from Microsoft Edge into Application Guard.
|
||||
- 1 - Turns On clipboard operation from an isolated session to the host
|
||||
- 2 - Turns On clipboard operation from the host to an isolated session
|
||||
- 3 - Turns On clipboard operation in both the directions
|
||||
|
||||
> [!Important]
|
||||
> Allowing copied content to go from Microsoft Edge into Application Guard can cause potential security risks and isn't recommended.
|
||||
|
@ -36,6 +36,7 @@ You should not extract this package to the windows\\system32 folder because it w
|
||||
|
||||
Applying the Windows Restricted Traffic Limited Functionality Baseline is the same as applying each setting covered in this article.
|
||||
It is recommended that you restart a device after making configuration changes to it.
|
||||
Note that **Get Help** and **Give us Feedback** links no longer work after the Windows Restricted Traffic Limited Functionality Baseline is applied.
|
||||
|
||||
We are always striving to improve our documentation and welcome your feedback. You can provide feedback by contacting telmhelp@microsoft.com.
|
||||
|
||||
@ -88,17 +89,17 @@ See the following table for a summary of the management settings for Windows 10
|
||||
| Setting | UI | Group Policy | MDM policy | Registry | Command line |
|
||||
| - | :-: | :-: | :-: | :-: | :-: |
|
||||
| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | |  | | | |
|
||||
| [2. Cortana and Search](#bkmk-cortana) |  |  |  |  |  |
|
||||
| [2. Cortana and Search](#bkmk-cortana) |  |  |  |  | |
|
||||
| [3. Date & Time](#bkmk-datetime) |  |  | |  | |
|
||||
| [4. Device metadata retrieval](#bkmk-devinst) | |  | |  | |
|
||||
| [5. Find My Device](#find-my-device) | |  | | | |
|
||||
| [6. Font streaming](#font-streaming) | |  | |  | |
|
||||
| [7. Insider Preview builds](#bkmk-previewbuilds) |  |  |  |  |  |
|
||||
| [7. Insider Preview builds](#bkmk-previewbuilds) |  |  |  |  | |
|
||||
| [8. Internet Explorer](#bkmk-ie) |  |  | |  | |
|
||||
| [9. Live Tiles](#live-tiles) | |  | |  | |
|
||||
| [10. Mail synchronization](#bkmk-mailsync) |  | |  |  | |
|
||||
| [11. Microsoft Account](#bkmk-microsoft-account) | |  |  |  | |
|
||||
| [12. Microsoft Edge](#bkmk-edge) |  |  |  |  |  |
|
||||
| [12. Microsoft Edge](#bkmk-edge) |  |  |  |  | |
|
||||
| [13. Network Connection Status Indicator](#bkmk-ncsi) | |  | |  | |
|
||||
| [14. Offline maps](#bkmk-offlinemaps) |  |  | |  | |
|
||||
| [15. OneDrive](#bkmk-onedrive) | |  | |  | |
|
||||
@ -1065,7 +1066,17 @@ To turn off **Choose apps that can use your microphone**:
|
||||
|
||||
### <a href="" id="bkmk-priv-notifications"></a>17.5 Notifications
|
||||
|
||||
In the **Notifications** area, you can choose which apps have access to notifications.
|
||||
To turn off notifications network usage:
|
||||
|
||||
- Apply the Group Policy: **Computer Configuration** > **Administrative Templates** > **Start Menu and Taskbar** > **Notifications** > **Turn off Notifications network usage**
|
||||
|
||||
- Set to **Enabled**.
|
||||
|
||||
-or-
|
||||
|
||||
- Create a REG\_DWORD registry setting in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\PushNotifications!NoCloudApplicationNotification**, with a value of 1 (one)
|
||||
|
||||
In the **Notifications** area, you can also choose which apps have access to notifications.
|
||||
|
||||
To turn off **Let apps access my notifications**:
|
||||
|
||||
|
@ -425,6 +425,7 @@ The following table shows the scenarios supported by this customization:
|
||||
|
||||
|
||||
Multivariant setting set?|SPN provisioned?|MSISDN (last 4 digits: 1234, for example) provisioned?|Default SIM name
|
||||
--- | --- | --- | ---
|
||||
Yes|Yes|Yes|*MultivariantProvisionedSPN*1234 or *MultivariantProvisionedSPN*" "1234
|
||||
Yes|No|No|*MultivariantProvisionedSPN* (up to 16 characters)
|
||||
Yes|Yes|No|*MultivariantProvisionedSPN* (up to 16 characters)
|
||||
|
@ -15,6 +15,7 @@
|
||||
### [Overview of Windows AutoPilot](windows-autopilot/windows-10-autopilot.md)
|
||||
|
||||
### [Windows 10 upgrade paths](upgrade/windows-10-upgrade-paths.md)
|
||||
#### [Windows 10 downgrade paths](upgrade/windows-10-downgrade-paths.md)
|
||||
### [Windows 10 edition upgrade](upgrade/windows-10-edition-upgrades.md)
|
||||
### [Windows 10 volume license media](windows-10-media.md)
|
||||
|
||||
|
@ -31,7 +31,7 @@ To request an Olympia Corp account, please fill out the survey at [https://aka.m
|
||||
|
||||
## Enrollment guidelines
|
||||
|
||||
Welcome to Olympia Corp. Here are the steps to add your account to your PC.
|
||||
Welcome to Olympia Corp. Here are the steps needed to Enroll.
|
||||
|
||||
As part of Windows Insider Lab for Enterprise, you can upgrade to Windows 10 Enterprise from Windows 10 Pro. This upgrade is optional. Since certain features such as Windows Defender Application Guard are only available on Windows 10 Enterprise, we recommend you to upgrade.
|
||||
|
||||
@ -43,7 +43,9 @@ Choose one of the following two enrollment options:
|
||||
|
||||
<a id="enrollment-keep-current-edition"></a>
|
||||
|
||||
### Keep your current Windows 10 edition
|
||||
### Set up an Azure Active Directory REGISTERED Windows 10 device
|
||||
|
||||
- This is the Bring Your Own Device (BYOD) method - your device will receive Olympia policies and features, but a new account will not be created ([additional info]).(https://docs.microsoft.com/en-us/azure/active-directory/device-management-azuread-registered-devices-windows10-setup)
|
||||
|
||||
1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)).
|
||||
|
||||
@ -77,7 +79,9 @@ Choose one of the following two enrollment options:
|
||||
|
||||
<a id="enrollment-upgrade-to-enterprise"></a>
|
||||
|
||||
### Upgrade your Windows 10 edition from Pro to Enterprise
|
||||
### Set up Azure Active Directory JOINED Windows 10 device
|
||||
|
||||
- This method will upgrade your Windows 10 Pro license to Enterprise and create a new account ([additional info]).(https://docs.microsoft.com/en-us/azure/active-directory/device-management-azuread-joined-devices-setup)
|
||||
|
||||
1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)).
|
||||
|
||||
|
@ -57,7 +57,6 @@ If you are not using OMS:
|
||||
|
||||
5. To add the Upgrade Readiness solution to your workspace, go to the **Solutions Gallery**. Select the **Upgrade Readiness** tile in the gallery and then select **Add** on the solution’s details page. The solution is now visible on your workspace. Note that you may need to scroll to find Upgrade Readiness.
|
||||
|
||||
|
||||
### Copy your commercial ID key
|
||||
|
||||
Microsoft uses a unique commercial ID to map information from user computers to your OMS workspace. This should be generated for you automatically. Copy your commercial ID key in OMS and then deploy it to user computers.
|
||||
@ -85,7 +84,7 @@ To enable data sharing, whitelist the following endpoints. Note that you may nee
|
||||
| `https://v10.vortex-win.data.microsoft.com` | Connected User Experience and Telemetry component endpoint for Windows 10 computers. User computers send data to Microsoft through this endpoint.
|
||||
| `https://vortex-win.data.microsoft.com` | Connected User Experience and Telemetry component endpoint for operating systems older than Windows 10
|
||||
| `https://settings-win.data.microsoft.com` | Enables the compatibility update to send data to Microsoft.
|
||||
| `https://adl.windows.com` | Allows the compatibility update to receive the latest compatibility data from Microsoft. |
|
||||
| `http://adl.windows.com` | Allows the compatibility update to receive the latest compatibility data from Microsoft. |
|
||||
|
||||
Note: The compatibility update KB runs under the computer’s system account.
|
||||
|
||||
|
160
windows/deployment/upgrade/windows-10-downgrade-paths.md
Normal file
160
windows/deployment/upgrade/windows-10-downgrade-paths.md
Normal file
@ -0,0 +1,160 @@
|
||||
---
|
||||
title: Windows 10 downgrade paths (Windows 10)
|
||||
description: You can downgrade Windows 10 if the downgrade path is supported.
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: high
|
||||
ms.pagetype: mobile
|
||||
author: greg-lindsay
|
||||
ms.date: 02/15/2018
|
||||
---
|
||||
|
||||
# Windows 10 downgrade paths
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
|
||||
## Downgrading Windows 10
|
||||
|
||||
This topic provides a summary of supported Windows 10 downgrade paths. You might need to downgrade the edition of Windows 10, for example, if an Enterprise license is expired.
|
||||
|
||||
If a downgrade is supported, then your apps and settings can be migrated from the current edition to the downgraded edition. If a path is not supported, then a clean install is required.
|
||||
|
||||
To perform a downgrade, you can use the same methods as when performing an [edition upgrade](windows-10-edition-upgrades.md).
|
||||
|
||||
Downgrading from any edition of Windows 10 to Windows 7, 8, or 8.1 is not supported, unless you are performing a rollback of a previous upgrade. You also cannot downgrade from a later version to an earlier version of the same edition (Ex: Windows 10 Pro 1709 to 1703) unless the rollback process is used.
|
||||
|
||||
>**Windows 10 LTSC/LTSB**: Due to [naming changes](https://docs.microsoft.com/en-us/windows/deployment/update/waas-overview#naming-changes), product versions that display Windows 10 LTSB will be replaced with Windows 10 LTSC in subsequent feature updates. The term LTSC is used here to refer to all long term servicing versions.
|
||||
|
||||
>**Windows N/KN**: Windows "N" and "KN" SKUs follow the same rules shown below.
|
||||
|
||||
### Supported Windows 10 downgrade paths
|
||||
|
||||
>[!NOTE]
|
||||
>Edition changes that are considered upgrades (Ex: Pro to Enterprise) are not shown here. Switching between different editions of Pro is supported. This is not strictly considered an edition downgrade, but is included here for clarity.
|
||||
|
||||
✔ = Supported downgrade path<br>
|
||||
|
||||
<br>
|
||||
<table border="0" cellpadding="1">
|
||||
<tr>
|
||||
<td colspan="10" align="center">Destination edition</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td> </td>
|
||||
<td></td>
|
||||
<td>Home</td>
|
||||
<td>Pro</td>
|
||||
<td>Pro for Workstations</td>
|
||||
<td>Pro Education</td>
|
||||
<td>S</td>
|
||||
<td>Education</td>
|
||||
<td>Enterprise LTSC</td>
|
||||
<td>Enterprise</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td rowspan="9" nowrap="nowrap" valign="middle">Starting edition</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Home</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Pro</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Pro for Workstations</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Pro Education</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>S</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Education</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Enterprise LTSC</td>
|
||||
<td></td>
|
||||
<td align="center"></td>
|
||||
<td align="center"></td>
|
||||
<td align="center"></td>
|
||||
<td align="center"></td>
|
||||
<td align="center"></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Enterprise</td>
|
||||
<td></td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td align="center">✔</td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
|
||||
## Related Topics
|
||||
|
||||
[Windows 10 deployment scenarios](../windows-10-deployment-scenarios.md)<br>
|
||||
[Windows upgrade and migration considerations](windows-upgrade-and-migration-considerations.md)<br>
|
||||
[Windows 10 edition upgrade](windows-10-edition-upgrades.md)<br>
|
||||
[Windows 10 upgrade paths](windows-10-upgrade-paths.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -91,6 +91,11 @@ You can run the changepk.exe command-line tool to upgrade devices to a supported
|
||||
|
||||
`changepk.exe /ProductKey <enter your new product key here>`
|
||||
|
||||
You can also upgrade using slmgr.vbs and a [KMS client setup key](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj612867(v%3dws.11)). For example, the following command will upgrade to Windows 10 Enterprise.
|
||||
|
||||
`Cscript.exe c:\windows\system32\slmgr.vbs /ipk NPPR9-FWDCX-D2C8J-H872K-2YT43`
|
||||
|
||||
|
||||
## Upgrade by manually entering a product key
|
||||
If you are upgrading only a few devices, you may want to enter a product key for the upgraded edition manually.
|
||||
|
||||
|
@ -29,6 +29,7 @@ This topic provides a summary of available upgrade paths to Windows 10. You can
|
||||
✔ = Full upgrade is supported including personal data, settings, and applications.<BR>
|
||||
D = Edition downgrade; personal data is maintained, applications and settings are removed.
|
||||
|
||||
<br>
|
||||
<table border="0" cellpadding="1">
|
||||
<tr>
|
||||
<td> </td>
|
||||
@ -380,7 +381,8 @@ D = Edition downgrade; personal data is maintained, applications and settings ar
|
||||
|
||||
[Windows 10 deployment scenarios](../windows-10-deployment-scenarios.md)<br>
|
||||
[Windows upgrade and migration considerations](windows-upgrade-and-migration-considerations.md)<br>
|
||||
[Windows 10 edition upgrade](windows-10-edition-upgrades.md)
|
||||
[Windows 10 edition upgrade](windows-10-edition-upgrades.md)<br>
|
||||
[Windows 10 downgrade paths](windows-10-downgrade-paths.md)
|
||||
|
||||
|
||||
|
||||
|
@ -68,7 +68,7 @@ With Windows 10 Enterprise, businesses can benefit from enterprise-level securit
|
||||
You can benefit by moving to Windows as an online service in the following ways:
|
||||
|
||||
1. Licenses for Windows 10 Enterprise are checked based on Azure Active Directory (Azure AD) credentials, so now businesses have a systematic way to assign licenses to end users and groups in their organization.
|
||||
2. Azure AD logon triggers a silent edition upgrade, with no reboot required
|
||||
2. User logon triggers a silent edition upgrade, with no reboot required
|
||||
3. Support for mobile worker/BYOD activation; transition away from on-prem KMS and MAK keys.
|
||||
4. Compliance support via seat assignment.
|
||||
|
||||
|
@ -190,9 +190,6 @@
|
||||
#### [Review events and errors on endpoints with Event Viewer](windows-defender-atp\event-error-codes-windows-defender-advanced-threat-protection.md)
|
||||
### [Windows Defender Antivirus compatibility with Windows Defender ATP](windows-defender-atp\defender-compatibility-windows-defender-advanced-threat-protection.md)
|
||||
|
||||
|
||||
## [Windows Defender Antivirus in Windows 10](windows-defender-antivirus\windows-defender-antivirus-in-windows-10.md)
|
||||
### [Windows Defender AV in the Windows Defender Security Center app](windows-defender-antivirus\windows-defender-security-center-antivirus.md)
|
||||
## [Windows Defender Antivirus in Windows 10](windows-defender-antivirus\windows-defender-antivirus-in-windows-10.md)
|
||||
### [Windows Defender AV in the Windows Defender Security Center app](windows-defender-antivirus\windows-defender-security-center-antivirus.md)
|
||||
|
||||
|
@ -12,6 +12,12 @@ ms.date: 10/31/2017
|
||||
# Change history for threat protection
|
||||
This topic lists new and updated topics in the [Threat protection](index.md) documentation.
|
||||
|
||||
## February 2018
|
||||
|
||||
New or changed topic | Description
|
||||
---------------------|------------
|
||||
[Security Compliance Toolkit](security-compliance-toolkit-10.md) | Added Office 2016 Security Baseline.
|
||||
|
||||
## January 2018
|
||||
|New or changed topic |Description |
|
||||
|---------------------|------------|
|
||||
|
@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
|
||||
ms.localizationpriority: high
|
||||
ms.author: sagaudre
|
||||
author: brianlic-msft
|
||||
ms.date: 10/16/2017
|
||||
ms.date: 02/16/2018
|
||||
---
|
||||
|
||||
# Microsoft Security Compliance Toolkit 1.0
|
||||
@ -32,6 +32,9 @@ The Security Compliance Toolkit consists of:
|
||||
- Windows Server 2016
|
||||
- Windows Server 2012 R2
|
||||
|
||||
- Microsoft Office Security Baselines
|
||||
- Office 2016
|
||||
|
||||
- Tools
|
||||
- Policy Analyzer tool
|
||||
- Local Group Policy Object (LGPO) tool
|
||||
|
@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: tedhardyMSFT
|
||||
ms.date: 10/27/2017
|
||||
ms.date: 02/16/2018
|
||||
---
|
||||
|
||||
# Use Windows Event Forwarding to help with intrusion detection
|
||||
|
@ -72,7 +72,7 @@ The numbers beside the green triangle icon on each recommended action represents
|
||||
>[!IMPORTANT]
|
||||
>Recommendations that do not display a green triangle icon are informational only and no action is required.
|
||||
|
||||
Clicking **View machines** in a specific recommendation opens up the **Machines list** with filters applied to show only the list of machines where the the recommendation is applicable. You can export the list in Excel to create a target collection and apply relevant policies using a management solution of your choice.
|
||||
Clicking **View machines** in a specific recommendation opens up the **Machines list** with filters applied to show only the list of machines where the recommendation is applicable. You can export the list in Excel to create a target collection and apply relevant policies using a management solution of your choice.
|
||||
|
||||
The following image shows an example list of machines where the EDR sensor is not turned on.
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user