mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-29 13:47:23 +00:00
Merge branch 'main' of https://github.com/MicrosoftDocs/windows-docs-pr into ds-api-props-8092737
This commit is contained in:
commit
49bc70dbd9
File diff suppressed because it is too large
Load Diff
@ -236,7 +236,7 @@ Now that you've created your new Office 365 Education subscription, add the doma
|
|||||||
To make it easier for faculty and students to join your Office 365 Education subscription (or *tenant*), allow them to automatically sign up to your tenant (*automatic tenant join*). In automatic tenant join, when a faculty member or student signs up for Office 365, Office 365 automatically adds (joins) the user to your Office 365 tenant.
|
To make it easier for faculty and students to join your Office 365 Education subscription (or *tenant*), allow them to automatically sign up to your tenant (*automatic tenant join*). In automatic tenant join, when a faculty member or student signs up for Office 365, Office 365 automatically adds (joins) the user to your Office 365 tenant.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> By default, automatic tenant join is enabled in Office 365 Education, except for certain areas in Europe, the Middle East, and Africa. These countries require opt-in steps to add new users to existing Office 365 tenants. Check your country requirements to determine the automatic tenant join default configuration. Also, if you use Azure AD Connect, then automatic tenant join is disabled.
|
> By default, automatic tenant join is enabled in Office 365 Education, except for certain areas in Europe, the Middle East, and Africa. These countries/regions require opt-in steps to add new users to existing Office 365 tenants. Check your country/region requirements to determine the automatic tenant join default configuration. Also, if you use Azure AD Connect, then automatic tenant join is disabled.
|
||||||
|
|
||||||
Office 365 uses the domain portion of the user’s email address to know which Office 365 tenant to join. For example, if a faculty member or student provides an email address of user@contoso.edu, then Office 365 automatically performs one of the following tasks:
|
Office 365 uses the domain portion of the user’s email address to know which Office 365 tenant to join. For example, if a faculty member or student provides an email address of user@contoso.edu, then Office 365 automatically performs one of the following tasks:
|
||||||
|
|
||||||
|
@ -78,7 +78,7 @@ The **Billing Summary** shows the charges against the billing profile since the
|
|||||||
| Credits |Credits you received from returns |
|
| Credits |Credits you received from returns |
|
||||||
| Azure credits applied |Your Azure credits that are automatically applied to Azure charges each billing period |
|
| Azure credits applied |Your Azure credits that are automatically applied to Azure charges each billing period |
|
||||||
| Subtotal |The pre-tax amount due |
|
| Subtotal |The pre-tax amount due |
|
||||||
| Tax |The type and amount of tax that you pay, depending on the country of your billing profile. If you don't have to pay tax, then you won't see tax on your invoice. |
|
| Tax |The type and amount of tax that you pay, depending on the country/region of your billing profile. If you don't have to pay tax, then you won't see tax on your invoice. |
|
||||||
| Estimated total savings |The estimated total amount you saved from effective discounts. If applicable, effective discount rates are listed beneath the purchase line items in Details by Invoice Section. |
|
| Estimated total savings |The estimated total amount you saved from effective discounts. If applicable, effective discount rates are listed beneath the purchase line items in Details by Invoice Section. |
|
||||||
|
|
||||||
### Understand your charges
|
### Understand your charges
|
||||||
@ -101,7 +101,7 @@ The total amount due for each service family is calculated by subtracting Azure
|
|||||||
| Qty | Quantity purchased or consumed during the billing period |
|
| Qty | Quantity purchased or consumed during the billing period |
|
||||||
| Charges/Credits | Net amount of charges after credits/refunds are applied |
|
| Charges/Credits | Net amount of charges after credits/refunds are applied |
|
||||||
| Azure Credit | The amount of Azure credits applied to the Charges/Credits|
|
| Azure Credit | The amount of Azure credits applied to the Charges/Credits|
|
||||||
| Tax rate | Tax rate(s) depending on country |
|
| Tax rate | Tax rate(s) depending on country/region |
|
||||||
| Tax amount | Amount of tax applied to purchase based on tax rate |
|
| Tax amount | Amount of tax applied to purchase based on tax rate |
|
||||||
| Total | The total amount due for the purchase |
|
| Total | The total amount due for the purchase |
|
||||||
|
|
||||||
|
@ -29,7 +29,7 @@ You can purchase products and services from Microsoft Store for Business using y
|
|||||||
- Japan Commercial Bureau (JCB)
|
- Japan Commercial Bureau (JCB)
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Not all cards available in all countries. When you add a payment option, Microsoft Store for Business shows which cards are available in your region.
|
> Not all cards available in all countries/regions. When you add a payment option, Microsoft Store for Business shows which cards are available in your region.
|
||||||
|
|
||||||
## Add a payment method
|
## Add a payment method
|
||||||
|
|
||||||
|
@ -29,7 +29,7 @@ The **Billing account** page allows you to manage organization information, purc
|
|||||||
|
|
||||||
## Organization information
|
## Organization information
|
||||||
|
|
||||||
We need your business address, email contact, and tax-exemption certificates that apply to your country or locale.
|
We need your business address, email contact, and tax-exemption certificates that apply to your country/region or locale.
|
||||||
|
|
||||||
### Business address and email contact
|
### Business address and email contact
|
||||||
|
|
||||||
@ -46,7 +46,7 @@ We need an email address in case we need to contact you about your Microsoft Sto
|
|||||||
4. Make your updates, and then select **Save**.
|
4. Make your updates, and then select **Save**.
|
||||||
|
|
||||||
### Organization tax information
|
### Organization tax information
|
||||||
Taxes for Microsoft Store for Business purchases are determined by your business address. Businesses in these countries can provide their VAT number or local equivalent:
|
Taxes for Microsoft Store for Business purchases are determined by your business address. Businesses in these countries/regions can provide their VAT number or local equivalent:
|
||||||
- Austria
|
- Austria
|
||||||
- Belgium
|
- Belgium
|
||||||
- Bulgaria
|
- Bulgaria
|
||||||
@ -102,7 +102,7 @@ If you qualify for tax-exempt status in your market, start a service request to
|
|||||||
|
|
||||||
You'll need this documentation:
|
You'll need this documentation:
|
||||||
|
|
||||||
|Country or locale | Documentation |
|
|Country/Region or locale | Documentation |
|
||||||
|------------------|----------------|
|
|------------------|----------------|
|
||||||
| United States | Sales Tax Exemption Certificate |
|
| United States | Sales Tax Exemption Certificate |
|
||||||
| Canada | Certificate of Exemption (or equivalent letter of authorization) |
|
| Canada | Certificate of Exemption (or equivalent letter of authorization) |
|
||||||
|
103
windows/client-management/mdm/contribute-csp-reference.md
Normal file
103
windows/client-management/mdm/contribute-csp-reference.md
Normal file
@ -0,0 +1,103 @@
|
|||||||
|
---
|
||||||
|
title: Contributing to CSP reference articles
|
||||||
|
description: Learn more about contributing to the CSP reference articles.
|
||||||
|
author: vinaypamnani-msft
|
||||||
|
manager: aaroncz
|
||||||
|
ms.author: vinpa
|
||||||
|
ms.date: 07/18/2023
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
ms.prod: windows-client
|
||||||
|
ms.technology: itpro-manage
|
||||||
|
ms.topic: reference
|
||||||
|
---
|
||||||
|
|
||||||
|
# Contributing to the CSP reference articles
|
||||||
|
|
||||||
|
CSP reference articles are automatically generated using the [device description framework (DDF)](configuration-service-provider-ddf.md) v2 files that define the CSP. When applicable, the CSP definition includes a mapping to a group policy. The automation uses this mapping, when possible, to provide a friendly description for the CSP policies.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Each automated CSP article provides editable sections to provide additional information about the CSP, the policies within the CSP, and usage examples. Any edits outside the designated editable sections are overwritten by the automation.
|
||||||
|
|
||||||
|
## CSP article structure
|
||||||
|
|
||||||
|
Each automated CSP article is broken into three sections.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> To view these sections, visit the article that you want to update, then select the **Pencil** icon.
|
||||||
|
> :::image type="content" source="images/csp-contribute-link.png" alt-text="Screenshot showing the Pencil icon to edit a published article":::
|
||||||
|
|
||||||
|
1. **Header**: The header includes the CSP name, and provides an editable section where additional information about the CSP can be provided.
|
||||||
|
|
||||||
|
:::image type="content" source="images/csp-header.png" alt-text="Screenshot of the CSP header section":::
|
||||||
|
|
||||||
|
1. **Policies**: The policies section contains a list of policies, where each policy has an editable section for providing additional information and examples.
|
||||||
|
|
||||||
|
:::image type="content" source="images/csp-policy.png" alt-text="Screenshot of the CSP policy section":::
|
||||||
|
|
||||||
|
1. **Footer**: The footer indicates the end of the CSP article, and provides an editable section where more information about the CSP can be provided.
|
||||||
|
|
||||||
|
:::image type="content" source="images/csp-footer.png" alt-text="Screenshot of the CSP footer section":::
|
||||||
|
|
||||||
|
## Provide feedback on documentation
|
||||||
|
|
||||||
|
CSP articles are automated using the DDF v2 and ADMX files, which are part of the Windows codebase. Intune settings catalog also uses the DDF v2 files to present the settings and help text. As such, the feedback for these articles is best addressed when submitted directly to the engineering team using [Feedback Hub app](#send-feedback-with-the-feedback-hub-app). CSP reference articles and the Intune settings catalog are updated periodically using the latest copy of DDF v2 files, and benefit from the feedback addressed by the engineering team.
|
||||||
|
|
||||||
|
Automated CSP articles also contain [editable content](#csp-article-structure), which is preserved by the automation. For any feedback about the editable content, use the [Microsoft Learn documentation contributor guide][CONTRIB-1].
|
||||||
|
|
||||||
|
:::image type="content" source="images/csp-feedback-flow.svg" alt-text="Diagram showing the feedback flow for CSP articles":::
|
||||||
|
|
||||||
|
Use these sections to determine where you should submit feedback.
|
||||||
|
|
||||||
|
### Feedback for policy description
|
||||||
|
|
||||||
|
Policy descriptions are sourced from DDF or ADMX files and are located within the `<[CSP-Name]-Description-Begin>` section for the policy in the markdown file. `<[CSP-Name]-Description-Begin>` also includes a reference to the source that was used to provide the policy description.
|
||||||
|
|
||||||
|
- `Description-Source-ADMX` or `Description-Source-ADMX-Forced`: The description was captured from the group policy that the CSP setting maps to. If this description is incorrect, [Send feedback with the Feedback Hub app](#send-feedback-with-the-feedback-hub-app).
|
||||||
|
- `Description-Source-DDF` or `Description-Source-DDF-Forced`: The description was captured from the DDF file that defines the CSP. If this description is incorrect, [Send feedback with the Feedback Hub app](#send-feedback-with-the-feedback-hub-app).
|
||||||
|
- `Description-Source-Manual-Forced`: The description is defined in the automation code. If this description is incorrect, [submit an issue](/contribute/#create-quality-issues).
|
||||||
|
|
||||||
|
Any additional information about the policy setting can be provided in the `[Policy-Name]-Editable-Begin` section that immediately follows the `<[CSP-Name]-Description-End>` section. This section allows further expansion of the policy description, and is generated manually. For any feedback for the editable content, use the [Microsoft Learn documentation contributor guide][CONTRIB-1] to update the section or submit an issue.
|
||||||
|
|
||||||
|
### Feedback for policy examples
|
||||||
|
|
||||||
|
Policy examples aren't provided by the automation. Each policy node in the markdown file includes a `[Policy-Name]-Examples-Begin` section that contains the examples. If the example is incorrect or needs to be updated, use the [Microsoft Learn documentation contributor guide][CONTRIB-1] to update the example or submit an issue.
|
||||||
|
|
||||||
|
### Feedback for policy applicability
|
||||||
|
|
||||||
|
Policy applicability is defined in the DDF v2 file for the CSP. Each policy node in the markdown file includes a `[Policy-Name]-Applicability-Begin` section that contains the operating system applicability.
|
||||||
|
|
||||||
|
If it's incorrect or needs to be updated, [Send feedback with the Feedback Hub app](#send-feedback-with-the-feedback-hub-app).
|
||||||
|
|
||||||
|
### Feedback for policy allowed values
|
||||||
|
|
||||||
|
Policy allowed values are defined in the DDF v2 file for the CSP. When applicable, each policy node in the markdown file includes a `[Policy-Name]-AllowedValues-Begin` section that contains a table that describes the allowed values for the policy.
|
||||||
|
|
||||||
|
If these values are incorrect or need to be updated, [Send feedback with the Feedback Hub app](#send-feedback-with-the-feedback-hub-app).
|
||||||
|
|
||||||
|
### Feedback for group policy mapping
|
||||||
|
|
||||||
|
Group policy mappings are defined in the DDF v2 file for the CSP. When applicable, each policy node in the markdown file includes a `[Policy-Name]-AdmxBacked-Begin` or `[Policy-Name]-GpMapping-Begin` section that contains the group policy mapping.
|
||||||
|
|
||||||
|
If this mapping is incorrect, [Send feedback with the Feedback Hub app](#send-feedback-with-the-feedback-hub-app).
|
||||||
|
|
||||||
|
### Other feedback
|
||||||
|
|
||||||
|
For any other feedback, use the [Microsoft Learn documentation contributor guide][CONTRIB-1].
|
||||||
|
|
||||||
|
## Send feedback with the Feedback Hub app
|
||||||
|
|
||||||
|
The Feedback Hub app lets you tell Microsoft about any problems you run into while using Windows. For more information about using Feedback Hub, see [Send feedback to Microsoft with the Feedback Hub app](https://support.microsoft.com/windows/send-feedback-to-microsoft-with-the-feedback-hub-app-f59187f8-8739-22d6-ba93-f66612949332). When you submit feedback for CSP documentation with the Feedback Hub app, use these steps:
|
||||||
|
|
||||||
|
1. **Enter your feedback**: Prefix your feedback summary with `[CSP Documentation]` in the **Summarize your feedback** section. Add details about the feedback, including the link to the CSP article.
|
||||||
|
1. **Choose a category**: Select **Security and Privacy > Work or School Account** as the category.
|
||||||
|
1. **Find similar feedback**: Select an existing feedback that matches your feedback, if applicable.
|
||||||
|
1. **Add more details**: Select **Other** as the subcategory.
|
||||||
|
1. Select **Submit**.
|
||||||
|
|
||||||
|
## Related articles
|
||||||
|
|
||||||
|
- [Contributor guide overview][CONTRIB-1]
|
||||||
|
|
||||||
|
<!-- Links -->
|
||||||
|
|
||||||
|
[CONTRIB-1]: /contribute
|
@ -24,7 +24,7 @@ The table below shows the applicability of Windows:
|
|||||||
|Enterprise|Yes|Yes|
|
|Enterprise|Yes|Yes|
|
||||||
|Education|Yes|Yes|
|
|Education|Yes|Yes|
|
||||||
|
|
||||||
Windows 10 or Windows 11 allows you to manage devices differently depending on location, network, or time. Added in Windows 10, version 1703, the focus is on the most common areas of concern expressed by organizations. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
Windows 10 or Windows 11 allows you to manage devices differently depending on location, network, or time. Added in Windows 10, version 1703, the focus is on the most common areas of concern expressed by organizations. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country/region to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
||||||
|
|
||||||
This CSP was added in Windows 10, version 1703.
|
This CSP was added in Windows 10, version 1703.
|
||||||
|
|
||||||
|
BIN
windows/client-management/mdm/images/csp-contribute-link.png
Normal file
BIN
windows/client-management/mdm/images/csp-contribute-link.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 3.2 KiB |
File diff suppressed because one or more lines are too long
After Width: | Height: | Size: 16 KiB |
BIN
windows/client-management/mdm/images/csp-footer.png
Normal file
BIN
windows/client-management/mdm/images/csp-footer.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 12 KiB |
BIN
windows/client-management/mdm/images/csp-header.png
Normal file
BIN
windows/client-management/mdm/images/csp-header.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 14 KiB |
BIN
windows/client-management/mdm/images/csp-policy.png
Normal file
BIN
windows/client-management/mdm/images/csp-policy.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 62 KiB |
@ -2426,7 +2426,9 @@ Number of days before feature updates are installed on devices automatically reg
|
|||||||
<!-- ConfigureDeadlineForFeatureUpdates-Editable-Begin -->
|
<!-- ConfigureDeadlineForFeatureUpdates-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> After the deadline passes, restarts will occur regardless of active hours and users won't be able to reschedule.
|
>
|
||||||
|
> - After the deadline passes, restarts will occur regardless of active hours and users won't be able to reschedule.
|
||||||
|
> - When this policy is used, the download, installation, and reboot settings from [Update/AllowAutoUpdate](#allowautoupdate) are ignored.
|
||||||
<!-- ConfigureDeadlineForFeatureUpdates-Editable-End -->
|
<!-- ConfigureDeadlineForFeatureUpdates-Editable-End -->
|
||||||
|
|
||||||
<!-- ConfigureDeadlineForFeatureUpdates-DFProperties-Begin -->
|
<!-- ConfigureDeadlineForFeatureUpdates-DFProperties-Begin -->
|
||||||
@ -2483,7 +2485,9 @@ Number of days before quality updates are installed on devices automatically reg
|
|||||||
<!-- ConfigureDeadlineForQualityUpdates-Editable-Begin -->
|
<!-- ConfigureDeadlineForQualityUpdates-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> After the deadline passes, restarts will occur regardless of active hours and users won't be able to reschedule.
|
>
|
||||||
|
> - After the deadline passes, restarts will occur regardless of active hours and users won't be able to reschedule.
|
||||||
|
> - When this policy is used, the download, installation, and reboot settings from [Update/AllowAutoUpdate](#allowautoupdate) are ignored.
|
||||||
<!-- ConfigureDeadlineForQualityUpdates-Editable-End -->
|
<!-- ConfigureDeadlineForQualityUpdates-Editable-End -->
|
||||||
|
|
||||||
<!-- ConfigureDeadlineForQualityUpdates-DFProperties-Begin -->
|
<!-- ConfigureDeadlineForQualityUpdates-DFProperties-Begin -->
|
||||||
|
@ -3,6 +3,8 @@ items:
|
|||||||
href: index.yml
|
href: index.yml
|
||||||
expanded: true
|
expanded: true
|
||||||
items:
|
items:
|
||||||
|
- name: Contributing to CSP reference
|
||||||
|
href: contribute-csp-reference.md
|
||||||
- name: Device description framework (DDF) files
|
- name: Device description framework (DDF) files
|
||||||
href: configuration-service-provider-ddf.md
|
href: configuration-service-provider-ddf.md
|
||||||
- name: Support scenarios
|
- name: Support scenarios
|
||||||
|
@ -81,7 +81,7 @@ Use *Default* to specify a name that matches one of the search providers you ent
|
|||||||
|
|
||||||
#### Specific region guidance
|
#### Specific region guidance
|
||||||
|
|
||||||
Some countries require specific, default search providers. The following table lists the applicable countries and information for configuring the necessary search provider.
|
Some countries/regions require specific, default search providers. The following table lists the applicable countries/regions and information for configuring the necessary search provider.
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>For Russia + Commonwealth of Independent States (CIS), the independent states consist of Russia, Ukraine, Georgia, The Republic of Azerbaijan, Republic Of Belarus, The Republic of Kazakhstan, The Kyrgyz Republic, The Republic of Moldova, The Republic of Tajikistan, The Republic of Armenia, Turkmenistan, The Republic of Uzbekistan, and Turkey.
|
>For Russia + Commonwealth of Independent States (CIS), the independent states consist of Russia, Ukraine, Georgia, The Republic of Azerbaijan, Republic Of Belarus, The Republic of Kazakhstan, The Kyrgyz Republic, The Republic of Moldova, The Republic of Tajikistan, The Republic of Armenia, Turkmenistan, The Republic of Uzbekistan, and Turkey.
|
||||||
|
@ -4,7 +4,7 @@ metadata:
|
|||||||
description: Answers to frequently asked questions about Windows Autopatch.
|
description: Answers to frequently asked questions about Windows Autopatch.
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 05/04/2023
|
ms.date: 07/19/2023
|
||||||
audience: itpro
|
audience: itpro
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dougeby
|
manager: dougeby
|
||||||
@ -31,7 +31,7 @@ sections:
|
|||||||
Autopatch isn't available for 'A' or 'F' series licensing.
|
Autopatch isn't available for 'A' or 'F' series licensing.
|
||||||
- question: Will Windows Autopatch support local domain join Windows 10?
|
- question: Will Windows Autopatch support local domain join Windows 10?
|
||||||
answer: |
|
answer: |
|
||||||
Windows Autopatch doesn't support local (on-premise) domain join. Windows Autopatch supports [Hybrid AD join](/azure/active-directory/devices/concept-azure-ad-join-hybrid) or pure [Azure AD join](/azure/active-directory/devices/concept-azure-ad-join-hybrid).
|
Windows Autopatch doesn't support local (on-premises) domain join. Windows Autopatch supports [Hybrid AD join](/azure/active-directory/devices/concept-azure-ad-join-hybrid) or pure [Azure AD join](/azure/active-directory/devices/concept-azure-ad-join-hybrid).
|
||||||
- question: Will Windows Autopatch be available for state and local government customers?
|
- question: Will Windows Autopatch be available for state and local government customers?
|
||||||
answer: |
|
answer: |
|
||||||
Windows Autopatch is available for all Windows E3 customers using Azure commercial cloud. However, Autopatch isn't currently supported for government cloud (GCC) customers. Although Windows 365 Enterprise is in the Azure Commercial cloud, when Windows 365 Enterprise is used with a GCC customer tenant, Autopatch is not suppported.
|
Windows Autopatch is available for all Windows E3 customers using Azure commercial cloud. However, Autopatch isn't currently supported for government cloud (GCC) customers. Although Windows 365 Enterprise is in the Azure Commercial cloud, when Windows 365 Enterprise is used with a GCC customer tenant, Autopatch is not suppported.
|
||||||
|
@ -66,7 +66,7 @@ The following groups target Windows Autopatch configurations to devices and mana
|
|||||||
| Policy name | Policy description | Properties | Value |
|
| Policy name | Policy description | Properties | Value |
|
||||||
| ----- | ----- | ----- | ----- |
|
| ----- | ----- | ----- | ----- |
|
||||||
| Windows Autopatch - Set MDM to Win Over GPO | Sets mobile device management (MDM) to win over GPO<p>Assigned to:<ul><li>Modern Workplace Devices-Windows Autopatch-Test</li><li>Modern Workplace Devices-Windows Autopatch-First</li><li>Modern Workplace Devices-Windows Autopatch-Fast</li><li>Modern Workplace Devices-Windows Autopatch-Broad</li></ul>| [MDM Wins Over GP](/windows/client-management/mdm/policy-csp-controlpolicyconflict#controlpolicyconflict-MDMWinsOverGP) | <ul><li>MDM policy is used</li><li>GP policy is blocked</li></ul> |
|
| Windows Autopatch - Set MDM to Win Over GPO | Sets mobile device management (MDM) to win over GPO<p>Assigned to:<ul><li>Modern Workplace Devices-Windows Autopatch-Test</li><li>Modern Workplace Devices-Windows Autopatch-First</li><li>Modern Workplace Devices-Windows Autopatch-Fast</li><li>Modern Workplace Devices-Windows Autopatch-Broad</li></ul>| [MDM Wins Over GP](/windows/client-management/mdm/policy-csp-controlpolicyconflict#controlpolicyconflict-MDMWinsOverGP) | <ul><li>MDM policy is used</li><li>GP policy is blocked</li></ul> |
|
||||||
| Windows Autopatch - Data Collection | Windows Autopatch and Telemetry settings processes diagnostic data from the Windows device.<p>Assigned to:<ul><li>Modern Workplace Devices-Windows Autopatch-Test</li><li>Modern Workplace Devices-Windows Autopatch-First</li><li>Modern Workplace Devices-Windows Autopatch-Fast</li><li>Modern Workplace Devices-Windows Autopatch-Broad</li></ul>|<ol><li>[Configure Telemetry Opt In Change Notification](/windows/client-management/mdm/policy-csp-system#system-configuretelemetryoptinchangenotification)</li><li>[Configure Telemetry Opt In Settings UX](/windows/client-management/mdm/policy-csp-system#system-configuretelemetryoptinsettingsux)</li><li>[Allow Telemetry](/windows/client-management/mdm/policy-csp-system#system-allowtelemetry)</li><li>[Limit Enhanced Diagnostic Data Windows Analytics](/windows/client-management/mdm/policy-csp-system#system-limitenhanceddiagnosticdatawindowsanalytics)</li><li>[Limit Dump Collection](/windows/client-management/mdm/policy-csp-system#system-limitdumpcollection)</li><li>[Limit Diagnostic Log Collection](/windows/client-management/mdm/policy-csp-system#system-limitdiagnosticlogcollection)</li></ol>|<ol><li>Enable telemetry change notifications</li><li>Enable Telemetry opt-in Settings</li><li>Full</li><li>Enabled</li><li>Enabled</li><li>Enabled</li></ol> |
|
| Windows Autopatch - Data Collection | Windows Autopatch and Telemetry settings processes diagnostic data from the Windows device.<p>Assigned to:<ul><li>Modern Workplace Devices-Windows Autopatch-Test</li><li>Modern Workplace Devices-Windows Autopatch-First</li><li>Modern Workplace Devices-Windows Autopatch-Fast</li><li>Modern Workplace Devices-Windows Autopatch-Broad</li></ul>|<ol><li>[Allow Telemetry](/windows/client-management/mdm/policy-csp-system#system-allowtelemetry)</li><li>[Limit Enhanced Diagnostic Data Windows Analytics](/windows/client-management/mdm/policy-csp-system#system-limitenhanceddiagnosticdatawindowsanalytics)</li><li>[Limit Dump Collection](/windows/client-management/mdm/policy-csp-system#system-limitdumpcollection)</li><li>[Limit Diagnostic Log Collection](/windows/client-management/mdm/policy-csp-system#system-limitdiagnosticlogcollection)</li></ol>|<ol><li>Full</li><li>Enabled</li><li>Enabled</li><li>Enabled</li></ol> |
|
||||||
|
|
||||||
## Deployment rings for Windows 10 and later
|
## Deployment rings for Windows 10 and later
|
||||||
|
|
||||||
|
@ -1983,7 +1983,7 @@ The following fields are available:
|
|||||||
|
|
||||||
### Microsoft.Windows.Security.CodeIntegrity.State.Current
|
### Microsoft.Windows.Security.CodeIntegrity.State.Current
|
||||||
|
|
||||||
This event indicates the overall CodeIntegrity Policy state and count of policies, fired on reboot and when policy changes rebootlessly. The data collected with this event is used to help keep Windows secure.
|
This event indicates the overall CodeIntegrity Policy state and count of policies, which occur when the device restarts and when policy changes without a restart. The data collected with this event is used to help keep Windows secure.
|
||||||
|
|
||||||
The following fields are available:
|
The following fields are available:
|
||||||
|
|
||||||
@ -2006,7 +2006,7 @@ The following fields are available:
|
|||||||
|
|
||||||
### Microsoft.Windows.Security.CodeIntegrity.State.PolicyDetails
|
### Microsoft.Windows.Security.CodeIntegrity.State.PolicyDetails
|
||||||
|
|
||||||
This individual policy state event fires once per policy on reboot and whenever any policy change occurs rebootlessly. The data collected with this event is used to help keep Windows secure.
|
This individual policy state event occurs once per policy when the device restarts and whenever any policy change occurs without a restart. The data collected with this event is used to help keep Windows secure.
|
||||||
|
|
||||||
The following fields are available:
|
The following fields are available:
|
||||||
|
|
||||||
|
@ -174,7 +174,7 @@ The following table illustrates an analysis of computers in an organization.
|
|||||||
|
|
||||||
### Regulatory requirements
|
### Regulatory requirements
|
||||||
|
|
||||||
Many industries and locales have specific requirements for network operations and how resources are protected. In the health care and financial industries, for example, strict guidelines control who can access records and how the records are used. Many countries have strict privacy rules. To identify regulatory requirements, work with your organization's legal department and other departments responsible for these requirements. Then consider the security configuration and auditing options that you can use to comply with these regulations and verify compliance.
|
Many industries and locales have specific requirements for network operations and how resources are protected. In the health care and financial industries, for example, strict guidelines control who can access records and how the records are used. Many countries/regions have strict privacy rules. To identify regulatory requirements, work with your organization's legal department and other departments responsible for these requirements. Then consider the security configuration and auditing options that you can use to comply with these regulations and verify compliance.
|
||||||
|
|
||||||
For more information, see the [System Center Process Pack for IT GRC](/previous-versions/tn-archive/dd206732(v=technet.10)).
|
For more information, see the [System Center Process Pack for IT GRC](/previous-versions/tn-archive/dd206732(v=technet.10)).
|
||||||
|
|
||||||
|
@ -43,7 +43,7 @@ Intune's built-in Windows Defender Application Control support allows you to con
|
|||||||
> Intune's built-in policies use the pre-1903 single-policy format version of the DefaultWindows policy. You can use Intune's custom OMA-URI feature to deploy your own multiple-policy format WDAC policies and leverage features available on Windows 10 1903+ or Windows 11 as described later in this topic.
|
> Intune's built-in policies use the pre-1903 single-policy format version of the DefaultWindows policy. You can use Intune's custom OMA-URI feature to deploy your own multiple-policy format WDAC policies and leverage features available on Windows 10 1903+ or Windows 11 as described later in this topic.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Intune currently uses the AppLocker CSP to deploy its built-in policies. The AppLocker CSP will always request a reboot when applying WDAC policies. You can use Intune's custom OMA-URI feature with the ApplicationControl CSP to deploy your own WDAC policies rebootlessly.
|
> Intune currently uses the AppLocker CSP to deploy its built-in policies. The AppLocker CSP always requests a device restart when it applies WDAC policies. You can use Intune's custom OMA-URI feature with the ApplicationControl CSP to deploy your own WDAC policies without a restart.
|
||||||
|
|
||||||
To use Intune's built-in WDAC policies, configure [Endpoint Protection for Windows 10 (and later)](/mem/intune/protect/endpoint-protection-windows-10?toc=/intune/configuration/toc.json&bc=/intune/configuration/breadcrumb/toc.json).
|
To use Intune's built-in WDAC policies, configure [Endpoint Protection for Windows 10 (and later)](/mem/intune/protect/endpoint-protection-windows-10?toc=/intune/configuration/toc.json&bc=/intune/configuration/breadcrumb/toc.json).
|
||||||
|
|
||||||
|
@ -55,7 +55,7 @@ To make a policy effectively inactive before removing it, you can first replace
|
|||||||
5. If applicable, remove option **0 Enabled:UMCI** to convert the policy to kernel mode only.
|
5. If applicable, remove option **0 Enabled:UMCI** to convert the policy to kernel mode only.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> After a policy has been removed, you must restart the computer for it to take effect. You can't remove WDAC policies rebootlessly.
|
> After you remove a policy, restart the computer for it to take effect. You can't remove WDAC policies without restarting the device.
|
||||||
|
|
||||||
### Remove WDAC policies using CiTool.exe
|
### Remove WDAC policies using CiTool.exe
|
||||||
|
|
||||||
|
@ -456,7 +456,7 @@ Windows 10 Enterprise LTSC 2019 adds many new [configuration service providers (
|
|||||||
|
|
||||||
Some of the other new CSPs are:
|
Some of the other new CSPs are:
|
||||||
|
|
||||||
- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can't reach the management server when the location or network changes. The dynamic management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country/region to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can't reach the management server when the location or network changes. The dynamic management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
||||||
|
|
||||||
- The [CleanPC CSP](/windows/client-management/mdm/cleanpc-csp) allows removal of user-installed and pre-installed applications, with the option to persist user data.
|
- The [CleanPC CSP](/windows/client-management/mdm/cleanpc-csp) allows removal of user-installed and pre-installed applications, with the option to persist user data.
|
||||||
|
|
||||||
|
@ -212,7 +212,7 @@ Windows 10, version 1703 adds many new [configuration service providers (CSPs)](
|
|||||||
|
|
||||||
Some of the other new CSPs are:
|
Some of the other new CSPs are:
|
||||||
|
|
||||||
- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
- The [DynamicManagement CSP](/windows/client-management/mdm/dynamicmanagement-csp) allows you to manage devices differently depending on location, network, or time. For example, managed devices can have cameras disabled when at a work location, the cellular service can be disabled when outside the country/region to avoid roaming charges, or the wireless network can be disabled when the device isn't within the corporate building or campus. Once configured, these settings will be enforced even if the device can’t reach the management server when the location or network changes. The Dynamic Management CSP enables configuration of policies that change how the device is managed in addition to setting the conditions on which the change occurs.
|
||||||
|
|
||||||
- The [CleanPC CSP](/windows/client-management/mdm/cleanpc-csp) allows removal of user-installed and pre-installed applications, with the option to persist user data.
|
- The [CleanPC CSP](/windows/client-management/mdm/cleanpc-csp) allows removal of user-installed and pre-installed applications, with the option to persist user data.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user