diff --git a/.openpublishing.redirection.education.json b/.openpublishing.redirection.education.json index ad621f161f..95ef6b4693 100644 --- a/.openpublishing.redirection.education.json +++ b/.openpublishing.redirection.education.json @@ -92,7 +92,7 @@ }, { "source_path": "education/windows/enable-s-mode-on-surface-go-devices.md", - "redirect_url": "/windows/deployment/s-mode", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/index", "redirect_document_id": false }, { @@ -147,7 +147,7 @@ }, { "source_path": "education/windows/test-windows10s-for-edu.md", - "redirect_url": "/windows/deployment/s-mode", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/index", "redirect_document_id": false }, { diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 0cde1bb400..ee3a92a1fd 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -5077,7 +5077,7 @@ }, { "source_path": "windows/keep-secure/app-behavior-with-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/app-behavior-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/app-behavior-with-wip", "redirect_document_id": false }, { @@ -5727,7 +5727,7 @@ }, { "source_path": "windows/keep-secure/collect-wip-audit-event-logs.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/collect-wip-audit-event-logs", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/collect-wip-audit-event-logs", "redirect_document_id": false }, { @@ -6037,7 +6037,7 @@ }, { "source_path": "windows/keep-secure/create-and-verify-an-efs-dra-certificate.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate", "redirect_document_id": false }, { @@ -6052,7 +6052,7 @@ }, { "source_path": "windows/keep-secure/create-edp-policy-using-sccm.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/create-wip-policy-using-sccm", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr", "redirect_document_id": false }, { @@ -6097,7 +6097,7 @@ }, { "source_path": "windows/keep-secure/create-wip-policy-using-sccm.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/create-wip-policy-using-sccm", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr", "redirect_document_id": false }, { @@ -6547,12 +6547,12 @@ }, { "source_path": "windows/keep-secure/enlightened-microsoft-apps-and-edp.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", "redirect_document_id": false }, { "source_path": "windows/keep-secure/enlightened-microsoft-apps-and-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", "redirect_document_id": false }, { @@ -7917,12 +7917,12 @@ }, { "source_path": "windows/keep-secure/guidance-and-best-practices-edp.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/guidance-and-best-practices-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", "redirect_document_id": false }, { "source_path": "windows/keep-secure/guidance-and-best-practices-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/guidance-and-best-practices-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", "redirect_document_id": false }, { @@ -8177,7 +8177,7 @@ }, { "source_path": "windows/keep-secure/limitations-with-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/limitations-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/limitations-with-wip", "redirect_document_id": false }, { @@ -8282,7 +8282,7 @@ }, { "source_path": "windows/keep-secure/mandatory-settings-for-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/mandatory-settings-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/mandatory-settings-for-wip", "redirect_document_id": false }, { @@ -8662,12 +8662,12 @@ }, { "source_path": "windows/keep-secure/overview-create-edp-policy.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/overview-create-wip-policy", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy", "redirect_document_id": false }, { "source_path": "windows/keep-secure/overview-create-wip-policy.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/overview-create-wip-policy", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy", "redirect_document_id": false }, { @@ -8837,12 +8837,12 @@ }, { "source_path": "windows/keep-secure/protect-enterprise-data-using-edp.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", "redirect_document_id": false }, { "source_path": "windows/keep-secure/protect-enterprise-data-using-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", "redirect_document_id": false }, { @@ -8867,7 +8867,7 @@ }, { "source_path": "windows/keep-secure/recommended-network-definitions-for-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/recommended-network-definitions-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip", "redirect_document_id": false }, { @@ -9232,12 +9232,12 @@ }, { "source_path": "windows/keep-secure/testing-scenarios-for-edp.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/testing-scenarios-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/testing-scenarios-for-wip", "redirect_document_id": false }, { "source_path": "windows/keep-secure/testing-scenarios-for-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/testing-scenarios-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/testing-scenarios-for-wip", "redirect_document_id": false }, { @@ -9522,7 +9522,7 @@ }, { "source_path": "windows/keep-secure/using-owa-with-wip.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/using-owa-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/using-owa-with-wip", "redirect_document_id": false }, { @@ -9757,12 +9757,12 @@ }, { "source_path": "windows/keep-secure/wip-app-enterprise-context.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/wip-app-enterprise-context", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/wip-app-enterprise-context", "redirect_document_id": false }, { "source_path": "windows/keep-secure/wip-enterprise-overview.md", - "redirect_url": "/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", "redirect_document_id": false }, { @@ -10997,7 +10997,7 @@ }, { "source_path": "windows/plan/act-technical-reference.md", - "redirect_url": "/windows/deployment/planning/compatibility-administrator-users-guide", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-administrator-users-guide", "redirect_document_id": false }, { @@ -11042,12 +11042,12 @@ }, { "source_path": "windows/plan/applying-filters-to-data-in-the-sua-tool.md", - "redirect_url": "/windows/deployment/planning/applying-filters-to-data-in-the-sua-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/applying-filters-to-data-in-the-sua-tool", "redirect_document_id": false }, { "source_path": "windows/plan/available-data-types-and-operators-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/available-data-types-and-operators-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/available-data-types-and-operators-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11082,17 +11082,17 @@ }, { "source_path": "windows/plan/compatibility-administrator-users-guide.md", - "redirect_url": "/windows/deployment/planning/compatibility-administrator-users-guide", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-administrator-users-guide", "redirect_document_id": false }, { "source_path": "windows/plan/compatibility-fix-database-management-strategies-and-deployment.md", - "redirect_url": "/windows/deployment/planning/compatibility-fix-database-management-strategies-and-deployment", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-fix-database-management-strategies-and-deployment", "redirect_document_id": false }, { "source_path": "windows/plan/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md", - "redirect_url": "/windows/deployment/planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-fixes-for-windows-8-windows-7-and-windows-vista", "redirect_document_id": false }, { @@ -11112,12 +11112,12 @@ }, { "source_path": "windows/plan/creating-a-custom-compatibility-fix-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/creating-a-custom-compatibility-fix-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-a-custom-compatibility-fix-in-compatibility-administrator", "redirect_document_id": false }, { "source_path": "windows/plan/creating-a-custom-compatibility-mode-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/creating-a-custom-compatibility-mode-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-a-custom-compatibility-mode-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11127,7 +11127,7 @@ }, { "source_path": "windows/plan/creating-an-apphelp-message-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/creating-an-apphelp-message-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-an-apphelp-message-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11202,7 +11202,7 @@ }, { "source_path": "windows/plan/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11222,7 +11222,7 @@ }, { "source_path": "windows/plan/fixing-applications-by-using-the-sua-tool.md", - "redirect_url": "/windows/deployment/planning/fixing-applications-by-using-the-sua-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/fixing-applications-by-using-the-sua-tool", "redirect_document_id": false }, { @@ -11242,7 +11242,7 @@ }, { "source_path": "windows/plan/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11267,7 +11267,7 @@ }, { "source_path": "windows/plan/managing-application-compatibility-fixes-and-custom-fix-databases.md", - "redirect_url": "/windows/deployment/planning/managing-application-compatibility-fixes-and-custom-fix-databases", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/managing-application-compatibility-fixes-and-custom-fix-databases", "redirect_document_id": false }, { @@ -11317,12 +11317,12 @@ }, { "source_path": "windows/plan/searching-for-fixed-applications-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/searching-for-fixed-applications-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/searching-for-fixed-applications-in-compatibility-administrator", "redirect_document_id": false }, { "source_path": "windows/plan/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator", "redirect_document_id": false }, { @@ -11367,7 +11367,7 @@ }, { "source_path": "windows/plan/showing-messages-generated-by-the-sua-tool.md", - "redirect_url": "/windows/deployment/planning/showing-messages-generated-by-the-sua-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/showing-messages-generated-by-the-sua-tool", "redirect_document_id": false }, { @@ -11382,12 +11382,12 @@ }, { "source_path": "windows/plan/sua-users-guide.md", - "redirect_url": "/windows/deployment/planning/sua-users-guide", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/sua-users-guide", "redirect_document_id": false }, { "source_path": "windows/plan/tabs-on-the-sua-tool-interface.md", - "redirect_url": "/windows/deployment/planning/tabs-on-the-sua-tool-interface", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/tabs-on-the-sua-tool-interface", "redirect_document_id": false }, { @@ -11402,7 +11402,7 @@ }, { "source_path": "windows/plan/testing-your-application-mitigation-packages.md", - "redirect_url": "/windows/deployment/planning/testing-your-application-mitigation-packages", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/testing-your-application-mitigation-packages", "redirect_document_id": false }, { @@ -11427,7 +11427,7 @@ }, { "source_path": "windows/plan/understanding-and-using-compatibility-fixes.md", - "redirect_url": "/windows/deployment/planning/understanding-and-using-compatibility-fixes", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/understanding-and-using-compatibility-fixes", "redirect_document_id": false }, { @@ -11442,27 +11442,27 @@ }, { "source_path": "windows/plan/using-the-compatibility-administrator-tool.md", - "redirect_url": "/windows/deployment/planning/using-the-compatibility-administrator-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-compatibility-administrator-tool", "redirect_document_id": false }, { "source_path": "windows/plan/using-the-sdbinstexe-command-line-tool.md", - "redirect_url": "/windows/deployment/planning/using-the-sdbinstexe-command-line-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sdbinstexe-command-line-tool", "redirect_document_id": false }, { "source_path": "windows/plan/using-the-sua-tool.md", - "redirect_url": "/windows/deployment/planning/using-the-sua-tool", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sua-tool", "redirect_document_id": false }, { "source_path": "windows/plan/using-the-sua-wizard.md", - "redirect_url": "/windows/deployment/planning/using-the-sua-wizard", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sua-wizard", "redirect_document_id": false }, { "source_path": "windows/plan/viewing-the-events-screen-in-compatibility-administrator.md", - "redirect_url": "/windows/deployment/planning/viewing-the-events-screen-in-compatibility-administrator", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/viewing-the-events-screen-in-compatibility-administrator", "redirect_document_id": false }, { @@ -12377,22 +12377,22 @@ }, { "source_path": "windows/threat-protection/windows-information-protection/app-behavior-with-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/app-behavior-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/app-behavior-with-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/collect-wip-audit-event-logs.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/collect-wip-audit-event-logs", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure", "redirect_document_id": false }, { @@ -12402,7 +12402,7 @@ }, { "source_path": "windows/threat-protection/windows-information-protection/create-wip-policy-using-intune-azure.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", "redirect_document_id": false }, { @@ -12417,12 +12417,12 @@ }, { "source_path": "windows/threat-protection/windows-information-protection/create-wip-policy-using-sccm.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-wip-policy-using-sccm", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure", "redirect_document_id": false }, { @@ -12432,57 +12432,57 @@ }, { "source_path": "windows/threat-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/guidance-and-best-practices-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/limitations-with-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/limitations-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/limitations-with-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/mandatory-settings-for-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/mandatory-settings-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/mandatory-settings-for-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/overview-create-wip-policy-sccm.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/overview-create-wip-policy-sccm", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/overview-create-wip-policy.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/overview-create-wip-policy", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/recommended-network-definitions-for-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/testing-scenarios-for-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/testing-scenarios-for-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/testing-scenarios-for-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/using-owa-with-wip.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/using-owa-with-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/using-owa-with-wip", "redirect_document_id": false }, { "source_path": "windows/threat-protection/windows-information-protection/wip-app-enterprise-context.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/wip-app-enterprise-context", "redirect_document_id": false }, { diff --git a/.openpublishing.redirection.store-for-business.json b/.openpublishing.redirection.store-for-business.json index 9d89cf78d7..f825112907 100644 --- a/.openpublishing.redirection.store-for-business.json +++ b/.openpublishing.redirection.store-for-business.json @@ -119,6 +119,181 @@ "source_path": "store-for-business/work-with-partner-microsoft-store-business.md", "redirect_url": "/microsoft-365/commerce/manage-partners", "redirect_document_id": false + }, + { + "source_path": "store-for-business/acquire-apps-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/add-profile-to-devices.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/app-inventory-management-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/apps-in-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/assign-apps-to-employees.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/billing-payments-overview.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/billing-profile.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/billing-understand-your-invoice-msfb.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/configure-mdm-provider-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/distribute-apps-from-your-private-store.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/distribute-apps-with-management-tool.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/distribute-offline-apps.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/find-and-acquire-apps-overview.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/index.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-access-to-private-store.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-apps-microsoft-store-for-business-overview.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-orders-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-private-store-settings.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-settings-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/manage-users-and-groups-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/microsoft-store-for-business-education-powershell-module.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/microsoft-store-for-business-overview.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/notifications-microsoft-store-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/payment-methods.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/prerequisites-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/release-history-microsoft-store-business-education.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/roles-and-permissions-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/settings-reference-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/sfb-change-history.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/sign-up-microsoft-store-for-business-overview.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/troubleshoot-microsoft-store-for-business.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/update-microsoft-store-for-business-account-settings.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/whats-new-microsoft-store-business-education.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false + }, + { + "source_path": "store-for-business/working-with-line-of-business-apps.md", + "redirect_url": "/microsoft-365/admin/", + "redirect_document_id": false } ] } diff --git a/.openpublishing.redirection.windows-deployment.json b/.openpublishing.redirection.windows-deployment.json index 76f5946caf..b603a54613 100644 --- a/.openpublishing.redirection.windows-deployment.json +++ b/.openpublishing.redirection.windows-deployment.json @@ -127,7 +127,7 @@ }, { "source_path": "windows/deployment/planning/act-technical-reference.md", - "redirect_url": "/windows/deployment/planning/compatibility-administrator-users-guide", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-administrator-users-guide", "redirect_document_id": false }, { @@ -1369,6 +1369,141 @@ "source_path": "windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-signals.md", "redirect_url": "/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-overview", "redirect_document_id": true + }, + { + "source_path": "windows/deployment/planning/available-data-types-and-operators-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/available-data-types-and-operators-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/compatibility-administrator-users-guide.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-administrator-users-guide", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/compatibility-fix-database-management-strategies-and-deployment.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-fix-database-management-strategies-and-deployment", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/creating-a-custom-compatibility-fix-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-a-custom-compatibility-fix-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/creating-a-custom-compatibility-mode-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-a-custom-compatibility-mode-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/creating-an-apphelp-message-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/creating-an-apphelp-message-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/managing-application-compatibility-fixes-and-custom-fix-databases.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/managing-application-compatibility-fixes-and-custom-fix-databases", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/searching-for-fixed-applications-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/searching-for-fixed-applications-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/testing-your-application-mitigation-packages.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/testing-your-application-mitigation-packages", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/understanding-and-using-compatibility-fixes.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/understanding-and-using-compatibility-fixes", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/using-the-compatibility-administrator-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-compatibility-administrator-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/using-the-sdbinstexe-command-line-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sdbinstexe-command-line-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/viewing-the-events-screen-in-compatibility-administrator.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/viewing-the-events-screen-in-compatibility-administrator", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/compatibility-fixes-for-windows-8-windows-7-and-windows-vista", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/applying-filters-to-data-in-the-sua-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/applying-filters-to-data-in-the-sua-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/fixing-applications-by-using-the-sua-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/fixing-applications-by-using-the-sua-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/showing-messages-generated-by-the-sua-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/showing-messages-generated-by-the-sua-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/sua-users-guide.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/sua-users-guide", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/tabs-on-the-sua-tool-interface.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/tabs-on-the-sua-tool-interface", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/using-the-sua-tool.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sua-tool", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/planning/using-the-sua-wizard.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/compatibility/using-the-sua-wizard", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/windows-10-pro-in-s-mode.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/switch-edition-from-s-mode", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/s-mode.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/index", + "redirect_document_id": false + }, + { + "source_path": "windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-manage-autopatch-groups.md", + "redirect_url": "/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-autopatch-groups", + "redirect_document_id": true } ] } diff --git a/.openpublishing.redirection.windows-security.json b/.openpublishing.redirection.windows-security.json index 4e67945cc9..fc3a796e95 100644 --- a/.openpublishing.redirection.windows-security.json +++ b/.openpublishing.redirection.windows-security.json @@ -852,27 +852,27 @@ }, { "source_path": "windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure", "redirect_document_id": false }, { "source_path": "windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", "redirect_document_id": false }, { "source_path": "windows/security/information-protection/windows-information-protection/create-wip-policy-using-mam-intune-azure.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", "redirect_document_id": false }, { "source_path": "windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure", "redirect_document_id": false }, { "source_path": "windows/security/information-protection/windows-information-protection/how-wip-works-with-labels.md", - "redirect_url": "/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", "redirect_document_id": false }, { @@ -5127,7 +5127,7 @@ }, { "source_path": "windows/security/threat-protection/windows-defender-application-control/LOB-win32-apps-on-s.md", - "redirect_url": "/windows/security/application-security/application-control/windows-defender-application-control/deployment/LOB-win32-apps-on-s", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/wdac-allow-lob-win32-apps", "redirect_document_id": false }, { @@ -9184,6 +9184,111 @@ "source_path": "windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md", "redirect_url": "/windows/security/identity-protection/hello-for-business/dual-enrollment", "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/app-behavior-with-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/app-behavior-with-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/collect-wip-audit-event-logs", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/how-to-disable-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/how-to-disable-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/limitations-with-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/limitations-with-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/mandatory-settings-for-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/mandatory-settings-for-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/overview-create-wip-policy.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/testing-scenarios-for-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/testing-scenarios-for-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/using-owa-with-wip.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/using-owa-with-wip", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/wip-app-enterprise-context.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/wip-app-enterprise-context", + "redirect_document_id": false + }, + { + "source_path": "windows/security/information-protection/windows-information-protection/wip-learning.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/wip-learning", + "redirect_document_id": false + }, + { + "source_path": "windows/security/application-security/application-control/windows-defender-application-control/deployment/LOB-win32-apps-on-s.md", + "redirect_url": "/previous-versions/windows/it-pro/windows-10/deployment/s-mode/wdac-allow-lob-win32-apps", + "redirect_document_id": false } ] } diff --git a/.openpublishing.redirection.windows-whats-new.json b/.openpublishing.redirection.windows-whats-new.json index b72627e6c6..80f7068d98 100644 --- a/.openpublishing.redirection.windows-whats-new.json +++ b/.openpublishing.redirection.windows-whats-new.json @@ -42,7 +42,7 @@ }, { "source_path":"windows/whats-new/edp-whats-new-overview.md", - "redirect_url":"/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip", + "redirect_url":"/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip", "redirect_document_id":false }, { diff --git a/education/images/EDU-ITJourney.svg b/education/images/EDU-ITJourney.svg deleted file mode 100644 index e42fe12104..0000000000 --- a/education/images/EDU-ITJourney.svg +++ /dev/null @@ -1,31 +0,0 @@ - - - - -EDUAdmins-50px - - - - MapPin-blue - - - - - - - diff --git a/education/windows/images/icons/windows-os.svg b/education/windows/images/icons/windows-os.svg deleted file mode 100644 index da64baf975..0000000000 --- a/education/windows/images/icons/windows-os.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - \ No newline at end of file diff --git a/education/windows/toc.yml b/education/windows/toc.yml index 9442e1c3fc..1774ae6103 100644 --- a/education/windows/toc.yml +++ b/education/windows/toc.yml @@ -16,14 +16,6 @@ items: href: windows-11-se-settings-list.md - name: Frequently Asked Questions (FAQ) href: windows-11-se-faq.yml - - name: Windows in S Mode - items: - - name: Overview - href: /windows/deployment/s-mode?context=/education/context/context - - name: Switch Windows edition from S mode - href: /windows/deployment/windows-10-pro-in-s-mode?context=/education/context/context - - name: Deploy Win32 apps to S Mode devices - href: /windows/security/threat-protection/windows-defender-application-control/lob-win32-apps-on-s?context=/education/context/context - name: Shared devices and guests access href: /windows/configuration/shared-devices-concepts?context=/education/context/context - name: Take tests and assessments in Windows diff --git a/includes/configure/tab-intro.md b/includes/configure/tab-intro.md index c9c293a8c5..31046b2203 100644 --- a/includes/configure/tab-intro.md +++ b/includes/configure/tab-intro.md @@ -1,9 +1,9 @@ --- author: paolomatarazzo ms.author: paoloma -ms.date: 08/15/2023 +ms.date: 08/20/2024 ms.topic: include ms.service: windows-client --- -The following instructions provide details how to configure your devices. Select the option that best suits your needs. \ No newline at end of file +The following instructions provide details about how to configure your devices. Select the option that best suits your needs. \ No newline at end of file diff --git a/store-for-business/TOC.yml b/store-for-business/TOC.yml deleted file mode 100644 index 03ce31fa9e..0000000000 --- a/store-for-business/TOC.yml +++ /dev/null @@ -1,84 +0,0 @@ -- name: Microsoft Store for Business - href: index.md - items: - - name: What's new in Microsoft Store for Business and Education - href: whats-new-microsoft-store-business-education.md - - name: Sign up and get started - href: sign-up-microsoft-store-for-business-overview.md - items: - - name: Microsoft Store for Business and Microsoft Store for Education overview - href: microsoft-store-for-business-overview.md - - name: Prerequisites for Microsoft Store for Business and Education - href: prerequisites-microsoft-store-for-business.md - - name: Roles and permissions in the Microsoft Store for Business and Education - href: roles-and-permissions-microsoft-store-for-business.md - - name: "Settings reference: Microsoft Store for Business and Education" - href: settings-reference-microsoft-store-for-business.md - - name: Find and acquire apps - href: find-and-acquire-apps-overview.md - items: - - name: Apps in the Microsoft Store for Business and Education - href: apps-in-microsoft-store-for-business.md - - name: Acquire apps - href: acquire-apps-microsoft-store-for-business.md - - name: Working with line-of-business apps - href: working-with-line-of-business-apps.md - - name: Distribute apps - href: distribute-apps-to-your-employees-microsoft-store-for-business.md - items: - - name: Distribute apps using your private store - href: distribute-apps-from-your-private-store.md - - name: Assign apps to employees - href: assign-apps-to-employees.md - - name: Distribute apps with a management tool - href: distribute-apps-with-management-tool.md - - name: Distribute offline apps - href: distribute-offline-apps.md - - name: Manage products and services - href: manage-apps-microsoft-store-for-business-overview.md - items: - - name: App inventory management - href: app-inventory-management-microsoft-store-for-business.md - - name: Manage orders - href: manage-orders-microsoft-store-for-business.md - - name: Manage access to private store - href: manage-access-to-private-store.md - - name: Manage private store settings - href: manage-private-store-settings.md - - name: Configure MDM provider - href: configure-mdm-provider-microsoft-store-for-business.md - - name: Manage Windows device deployment with Windows Autopilot Deployment - href: add-profile-to-devices.md - - name: Microsoft Store for Business and Education PowerShell module - preview - href: microsoft-store-for-business-education-powershell-module.md - - name: Working with solution providers - href: /microsoft-365/commerce/manage-partners - - name: Billing and payments - href: billing-payments-overview.md - items: - - name: Understand your invoice - href: billing-understand-your-invoice-msfb.md - - name: Payment methods - href: payment-methods.md - - name: Understand billing profiles - href: billing-profile.md - - name: Manage settings in the Microsoft Store for Business and Education - href: manage-settings-microsoft-store-for-business.md - items: - - name: Update account settings - href: update-microsoft-store-for-business-account-settings.md - - name: Manage user accounts - href: manage-users-and-groups-microsoft-store-for-business.md - - name: Device Guard signing portal - href: device-guard-signing-portal.md - items: - - name: Add unsigned app to code integrity policy - href: add-unsigned-app-to-code-integrity-policy.md - - name: Sign code integrity policy with Device Guard signing - href: sign-code-integrity-policy-with-device-guard-signing.md - - name: Troubleshoot - href: troubleshoot-microsoft-store-for-business.md - - name: Notifications - href: notifications-microsoft-store-business.md - - name: Change history - href: sfb-change-history.md diff --git a/store-for-business/acquire-apps-microsoft-store-for-business.md b/store-for-business/acquire-apps-microsoft-store-for-business.md deleted file mode 100644 index a5cee55a8b..0000000000 --- a/store-for-business/acquire-apps-microsoft-store-for-business.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: Acquire apps in Microsoft Store for Business (Windows 10) -description: As an admin, you can acquire apps from the Microsoft Store for Business for your employees. Some apps are free, and some have a price. For info on app types that are supported, see Apps in the Microsoft Store for Business. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.reviewer: -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Acquire apps in Microsoft Store for Business and Education - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -> [!NOTE] -> As of April 14th, 2021, only free apps are available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md). - -As an admin, you can acquire apps from the Microsoft Store for Business and Education for your employees. Some apps are free, and some have a price. For info on app types that are supported, see [Apps in the Microsoft Store for Business](apps-in-microsoft-store-for-business.md). The following sections explain some of the settings for shopping. - -## App licensing model - -The Microsoft Store supports two options to license apps: online and offline. **Online** licensing is the default licensing model. Online licensed apps require users and devices to connect to the Microsoft Store services to acquire an app and its license. **Offline** licensing is a new licensing option for Windows 10. With offline licenses, organizations can cache apps and their licenses to deploy within their network. ISVs or devs can opt-in their apps for offline licensing when they submit them to the developer center. Admins control whether or not offline apps are available in Microsoft Store with an offline app visibility setting. - -For more information on the Microsoft Store licensing model, see [licensing model](./apps-in-microsoft-store-for-business.md#licensing-model). - -## Payment options - -Some apps are free, and some have a price. Apps can be purchased in the Microsoft Store using your credit card. You can enter your credit card information on **Account Information**, or when you purchase an app. Currently, we accept these credit cards: - -- VISA -- MasterCard -- Discover -- American Express -- Japan Commercial Bureau (JCB) - -## Organization info - -There are a couple of things we need to know when you pay for apps. You can add this info to the **Account information** or **Payments & billing** page before you buy apps. If you haven't provided it, we'll ask when you make a purchase. Either way works. Here's the info you'll need to provide: - -- Legal business address -- Payment option (credit card) - -## Allow users to shop - -**Allow users to shop** controls the shopping experience in Microsoft Store for Education. When this setting is on, **Purchasers** and **Basic Purchasers** can purchase products and services from Microsoft Store for Education. If your school chooses to closely control how purchases are made, admins can turn off **Allow users to shop**. When the setting is off: - -- The shopping experience is not available -- **Purchasers** and **Basic Purchasers** can't purchase products and services from Microsoft Store for Education -- Admins can't assign shopping roles to users -- Products and services previously purchased by **Basic Purchasers** can be managed by admins. - -**To manage Allow users to shop setting** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com) -2. Select **Manage**, and then select **Settings**. -3. On **Shop**, , under **Shopping behavior**, turn on or turn off **Allow users to shop**. - -![manage settings to control Basic Purchaser role assignment.](images/sfb-allow-shop-setting.png) - -## Allow app requests - -People in your org can request license for apps that they need, or that others need. When **Allow app requests** is turned on, app requests are sent to org admins. Admins for your tenant will receive an email with the request, and can decide about making the purchase. - -**To manage Allow app requests** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com) -2. Select **Manage**, and then select **Settings**. -3. On **Shop**, under **Shopping behavior** turn on or turn off **Allow app requests**. - -## Acquire apps - -**To acquire an app** - -1. Sign in to https://businessstore.microsoft.com -2. Select **Shop for my group**, or use Search to find an app. -3. Select the app you want to purchase. -4. On the product description page, choose your license type - either online or offline. -5. Free apps will be added to **Products & services**. For apps with a price, you can set the quantity you want to buy. Type the quantity and select **Next**. -6. If you don't have a payment method saved in **Billing & payments**, we will prompt you for one. -7. Add your credit card or debit card info, and select **Next**. Your card info is saved as a payment option on **Billing & payments - Payment methods**. - -You'll also need to have your business address saved on **My organization - Profile**. The address is used to generate tax rates. For more information on taxes for apps, see [organization tax information](./update-microsoft-store-for-business-account-settings.md#organization-tax-information). - -Microsoft Store adds the app to your inventory. From **Products & services**, you can: - -- Distribute the app: add to private store, or assign licenses -- View app licenses: review current licenses, reclaim and reassign licenses -- View app details: review the app details page and purchase more licenses - -For info on distributing apps, see [Distribute apps to your employees from the Microsoft Store for Business](distribute-apps-to-your-employees-microsoft-store-for-business.md). - -For info on offline-licensed apps, see [Distribute offline apps](distribute-offline-apps.md). \ No newline at end of file diff --git a/store-for-business/add-profile-to-devices.md b/store-for-business/add-profile-to-devices.md deleted file mode 100644 index 73cb1cafc3..0000000000 --- a/store-for-business/add-profile-to-devices.md +++ /dev/null @@ -1,148 +0,0 @@ ---- -title: Manage Windows device deployment with Windows Autopilot Deployment -description: Add an Autopilot profile to devices. Autopilot profiles control what is included in Windows set up experience for your employees. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.date: 05/24/2023 -ms.reviewer: -ms.topic: conceptual -ms.localizationpriority: medium ---- - -# Manage Windows device deployment with Windows Autopilot Deployment - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Windows Autopilot simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows Autopilot](/windows/deployment/windows-autopilot/windows-10-autopilot). - -Watch this video to learn more about Windows Autopilot in Microsoft Store for Business.
- -> [!video https://www.microsoft.com/videoplayer/embed/3b30f2c2-a3e2-4778-aa92-f65dbc3ecf54?autoplay=false] - -## What is Windows Autopilot? -In Microsoft Store for Business, you can manage devices for your organization and apply an *Autopilot deployment profile* to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows based on the Autopilot deployment profile you applied to the device. - -You can create and apply Autopilot deployment profiles to these devices. The overall process looks like this. - -![Block diagram with main steps for using Autopilot in Microsoft Store for Business: upload device list; group devices (this step is optional); add profile; and apply profile.](images/autopilot-process.png) - -Figure 1 - Windows Autopilot Deployment Program process - -Autopilot deployment profiles have two main parts: default settings that can't be changed, and optional settings that you can include. - -### Autopilot deployment profiles - default settings -These settings are configured with all Autopilot deployment profiles: -- Skip Cortana, OneDrive, and OEM registration setup pages -- Automatically setup for work or school -- Sign in experience with company or school brand - -### Autopilot deployment profiles - optional settings -These settings are off by default. You can turn them on for your Autopilot deployment profiles: -- Skip privacy settings - -### Support for Autopilot profile settings -Autopilot profile settings are supported beginning with the version of Windows they were introduced in. This table summarizes the settings and what they are supported on. - -| Setting | Supported on | -| ------- | ------------- | -| Deployment default features| Windows 10, version 1703 or later | -| Skip privacy settings | Windows 10, version 1703 or later | -| Disable local admin account creation on the device | Windows 10, version 1703 or later | -| Skip End User License Agreement (EULA) | Windows 10, version 1709 or later.
[Learn about Windows Autopilot EULA dismissal](/windows/deployment/Windows-Autopilot-EULA-note) | - - -## Windows Autopilot deployment profiles in Microsoft Store for Business and Education -You can manage new devices in Microsoft Store for Business or Microsoft Store for Education. Devices need to meet these requirements: -- Windows 10, version 1703 or later -- New devices that have not been through Windows out-of-box experience. - -## Add devices and apply Autopilot deployment profile -To manage devices through Microsoft Store for Business and Education, you'll need a .csv file that contains specific information about the devices. You should be able to get this from your Microsoft account contact, or the store where you purchased the devices. Upload the .csv file to Microsoft Store to add the devices. - -### Device information file format -Columns in the device information file need to use this naming and be in this order: -- Column A: Device Serial Number -- Column B: Windows Product ID (optional, typically blank) -- Column C: Hardware Hash - -Here's a sample device information file: - -![Notepad file showing example entries for Column A (Device Serial Number), Column B (Windows Product ID), and Column C (Hardware Hash).](images/msfb-autopilot-csv.png) - -When you add devices, you need to add them to an *Autopilot deployment group*. Use these groups to apply Autopilot deployment profiles to a group of devices. The first time you add devices to a group, you'll need to create an Autopilot deployment group. - -> [!NOTE] -> You can only add devices to a group when you add devices to **Microsoft Store for Business and Education**. If you decide to reorganize devices into different groups, you'll need to delete them from **Devices** in **Microsoft Store**, and add them again. - -**Add and group devices** -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then click **Devices**. -3. Click **Add devices**, navigate to the *.csv file and select it. -4. Type a name for a new Autopilot deployment group, or choose one from the list, and then click **Add**.
-If you don't add devices to a group, you can select the individual devices to apply a profile to.
-![Screenshot of Add devices to a group dialog. You can create a new group, or select a current group.](images/add-devices.png)
- -5. Click the devices or Autopilot deployment group that you want to manage. You need to select devices before you can apply an Autopilot deployment profile. You can switch between seeing groups or devices by clicking **View groups** or **View devices**. - -**Apply Autopilot deployment profile** -1. When you have devices selected, click **Autopilot deployment**. -2. Choose the Autopilot deployment profile to apply to the selected devices. - - > [!NOTE] - > The first time you use Autopilot deployment profiles, you'll need to create one. See [Create Autopilot profile](#create-autopilot-profile). - -3. Microsoft Store for Business applies the profile to your selected devices, and shows the profile name on **Devices**. - -## Manage Autopilot deployment profiles -You can manage the Autopilot deployment profiles created in Microsoft Store. You can create a new profile, edit, or delete a profile. - -### Create Autopilot profile - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then click **Devices**. -3. Click **Autopilot deployment**, and then click **Create new profile**. -4. Name the profile, choose the settings to include, and then click **Create**.
-The new profile is added to the **Autopilot deployment** list. - -### Edit or delete Autopilot profile - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then click **Devices**. -3. Click **Autopilot deployment**, click **Edit your profiles**, and then choose the profile to edit. -TBD: art -4. Change settings for the profile, and then click **Save**.
--or-
-Click **Delete profile** to delete the profile. - -## Apply a different Autopilot deployment profile to devices -After you've applied an Autopilot deployment profile to a device, if you decide to apply a different profile, you can remove the profile and apply a new profile. - -> [!NOTE] -> The new profile will only be applied if the device has not been started, and gone through the out-of-box experience. Settings from a different profile can't be applied when another profile has been applied. Windows would need to be reinstalled on the device for the second profile to be applied to the device. - -## Autopilot device information file error messages -Here's info on some of the errors you might see while working with Autopilot deployment profiles in **Microsoft Store for Business and Education**. - -| Message Id | Message explanation | -| ---------- | ------------------- | -| wadp001 | Check your file, or ask your device partner for a complete .csv file. This file is missing Serial Number and Product Id info. | -| wadp002 | Check your file, or ask your device partner for updated hardware hash info in the .csv file. Hardware hash info is invalid in the current .csv file. | -| wadp003 | Looks like you need more than one .csv file for your devices. The maximum allowed is 1,000 items. You're over the limit! Divide this device data into multiple .csv files. | -| wadp004 | Try that again. Something happened on our end. Waiting a bit might help. | -| wadp005 | Check your .csv file with your device provider. One of the devices on your list has been claimed by another organization. | -| wadp006 | Try that again. Something happened on our end. Waiting a bit might help. | -| wadp007 | Check the info for this device in your .csv file. The device is already registered in your organization. | -| wadp008 | The device does not meet Autopilot Deployment requirements. | -| wadp009 | Check with your device provider for an update .csv file. The current file doesn't work | -| wadp010 | Try that again. Something happened on our end. Waiting a bit might help. | \ No newline at end of file diff --git a/store-for-business/app-inventory-management-microsoft-store-for-business.md b/store-for-business/app-inventory-management-microsoft-store-for-business.md deleted file mode 100644 index 950fe7b629..0000000000 --- a/store-for-business/app-inventory-management-microsoft-store-for-business.md +++ /dev/null @@ -1,206 +0,0 @@ ---- -title: App inventory management for Microsoft Store for Business and Microsoft Store for Education (Windows 10) -description: You can manage all apps that you've acquired on your Apps & Software page. -ms.assetid: 44211937-801B-4B85-8810-9CA055CDB1B2 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.date: 05/24/2023 ---- - -# App inventory management for Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -You can manage all apps that you've acquired on your **Apps & software** page. This page shows all of the content you've acquired, including apps that from Microsoft Store, and line-of-business (LOB) apps that you've accepted into your inventory. After LOB apps are submitted to your organization, you'll see a notification on your **Apps & software** page. On the **New LOB apps** tab, you can accept, or reject the LOB apps. For more information on LOB apps, see [Working with line-of-business apps](working-with-line-of-business-apps.md). The inventory page includes apps acquired by all people in your organization with the Store for Business Admin role. - -All of these apps are treated the same once they are in your inventory and you can perform app lifecycle tasks for them: distribute apps, add apps to private store, review license details, and reclaim app licenses. - - - -Microsoft Store for Business and Education shows this info for each app in your inventory: -- Name -- Last modified -- Private store status -- Available licenses -- Supported devices -- Access to actions for the app - -The last modified date tracks changes about the app as an item in your inventory. The last modified date changes when one of the following happens: -- First purchase (the date you acquire the app from Microsoft Store for Business) -- Purchase additional licenses -- Assign license -- Reclaim license -- Refund order (applies to purchased apps, not free apps) - -The last modified date does not correspond to when an app was last updated in Microsoft Store. It tracks activity for that app, as an item in your inventory. - -## Find apps in your inventory - -There are a couple of ways to find specific apps, or groups of apps in your inventory. - -**Search** - Use the Search box to search for an app.
-**Refine results** - Use **Refine results** to scope your list of apps by one or more of these app attributes: -- **License type** - Online or offline licenses. For more info, see [Apps in Microsoft Store for Business](apps-in-microsoft-store-for-business.md#licensing-model). -- **Supported devices** - Lists the devices that apps in your inventory were originally written to support. This list is cumulative for all apps in your inventory. -- **Source** - **Store**, for apps acquired from Store for Business, or LOB, for line-of-business apps. -- **Product type** - Product categories, such as app, or game. -- **Private store** - Whether or not the app is in the private store, or status if the app is being added or removed from private store. - -## Manage apps in your inventory -Each app in the Store for Business has an online, or an offline license. For more information on Store for Business licensing model, see [Apps in the Microsoft Store for Business](apps-in-microsoft-store-for-business.md#licensing-model). There are different actions you can take depending on the app license type. They're summarized in this table. - -| Action | Online-licensed app | Offline-licensed app | -| ------ | ------------------- | -------------------- | -| Assign to employees | ✔️ | | -| Add to private store | ✔️ | | -| Remove from private store | ✔️ | | -| View license details | ✔️ | | -| View product details | ✔️ | ✔️ | -| Download for offline use | | ✔️ | - -The actions in the table are how you distribute apps, and manage app licenses. We'll cover those in the next sections. Working with offline-licensed apps has different steps. For more information on distributing offline-licensed apps, see [Distribute offline apps](distribute-offline-apps.md). - -## Assign apps -For online-licensed apps, you can assign apps directly to people in your organization. - -**To assign an app to an employee** - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://businessstore.microsoft.com). -2. Click **Manage**, and then choose **Inventory**. -3. Find an app, click the ellipses, and then choose **Assign to people**. -4. Type the email address for the employee that you're assigning the app to, and click **Confirm**. - -Employees will receive an email with a link that will install the app on their device. Click the link to start the Microsoft Store app, and then click **Install**. Also, in the Microsoft Store app, they can find the app under **My Library**. - -There are other options for distributing apps: -- **Use a management tool** - If you use a management tool that supports Microsoft Store, you can distribute apps with your management tool. Once it is configured to work with Store for Business, your management tool will have access to all apps in your inventory. For more information, see [Distribute apps with a management tool](distribute-apps-with-management-tool.md). -- **Distribute from private store** - You can also add apps to your private store, and let people get them on their own. For more information, see [Distribute apps from private store](#distribute-apps-from-private-store) - -## Distribute apps from private store -Once an app is in your private store, people in your org can install the app on their devices. For more information, see [Distribute apps using your private store](distribute-apps-from-your-private-store.md). - -### Add apps to your private store -**To make an app in Apps & software available in your private store** - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://businessstore.microsoft.com). -2. Click **Manage**, and then choose **Apps & software**. -3. Use **Refine results** to search for online-licensed apps under **License type**. -4. From the list of online-licensed apps, click the ellipses for the app you want, and then choose **Add to private store**. - -The value under **Private store** for the app will change to pending. It will take approximately thirty-six hours before the app is available in the private store. -Employees can claim apps that admins added to the private store by doing the following. - -### Get and remove private store apps -**To claim an app from the private store** - -1. Sign in to your computer with your Microsoft Entra credentials, and start the Microsoft Store app. -2. Click the private store tab. -3. Click the app you want to install, and then click **Install**. - -Another way to distribute apps is by assigning them to people in your organization. - -If you decide that you don't want an app available for employees to install on their own, you can remove it from your private store. - -**To remove an app from the private store** - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://businessstore.microsoft.com). -2. Click **Manage**, and then choose **Products & services**. -3. Find an app, click the ellipses, choose **Remove from private store**, and then click **Remove**. -4. Choose the private store collection, and then under **In collection**, switch to **Off**. - -The app will still be in your inventory, but your employees will not have access to the app from your private store. - -### Private store availability -On the details page for each app, you can directly assign an app to a user, or for apps in your private store, you can set **Private store availability**. - -**Private store availability** allows you to choose which groups of people can see an app in the private store: -- No one - The app isn't in your private store -- Everyone - The app is available to anyone in your organization -- Specific groups - The app is available to all users in assigned security groups - -**To assign security groups to an app** -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://businessstore.microsoft.com). -2. Click **Manage**, and then choose **Products & services**. -3. Find an app, choose the ellipses, and then choose **View license details**. -4. Click **Private store availability**, select **Specific groups**, and then click **Assign groups**. -5. Enter a name or email address for the security group you want to use, and then click **Add groups**. - -## Manage app licenses - -For each app in your inventory, you can view and manage license details. This give you another way to assign apps to people in your organization. It also allows you to reclaim app licenses after they've been assigned to people, or claimed by people in your organization. - -**To view license details** - -1. Sign in to [Microsoft Store for Business](https://go.microsoft.com/fwlink/p/?LinkId=691845) or [Microsoft Store for Education](https://businessstore.microsoft.com). -2. Click **Manage**, and then choose **Products & services**. -3. Click an app you want to manage. -4. On the app details page, you'll see the names of people in your organization who have installed the app and are using one of the licenses. From here, you can: - - - Assign the app to other people in your organization. - - Reclaim app licenses. - - View app details. - - Add the app to your private store, if it is not in the private store. - -You can assign the app to more people in your organization, or reclaim licenses. - -**To assign an app to more people** - -- On the app page, click **Assign users**, type the email address for the person that you're assigning the app to, and click **Assign**. - -Microsoft Store updates the list of assigned licenses. - -**To reclaim licenses** - -- On the app page, choose the person you want to reclaim the license from, click the ellipses, and then click **Reclaim licenses**. - -Microsoft Store updates the list of assigned licenses. - -## Purchase additional licenses -You can purchase additional licenses for apps in your Inventory. - -**To purchase additional app licenses** - -1. Sign in to [Microsoft Store for Business](https://go.microsoft.com/fwlink/p/?LinkId=691845) or [Microsoft Store for Education](https://businessstore.microsoft.com) -2. Click **Manage**, and then choose **Apps & software**. -3. From **Apps & software**, click an app. -4. On the app page, click **Buy more** for additional licenses, or click **Assign users** to manage your current licenses. - -You'll have a summary of current license availability. - -## Download offline-licensed app -Offline licensing is a new feature in Windows 10 and allows apps to be deployed to devices that are not connected to the Internet. This means organizations can deploy apps when users or devices do not have connectivity to the Store. - -You can download offline-licensed apps from your inventory. You'll need to download these items: -- App metadata -- App package -- App license -- App framework - -For more information about online and offline licenses, see [Apps in the Microsoft Store for Business](apps-in-microsoft-store-for-business.md#licensing-model). - -For more information about downloading offline-licensed apps, see [Download offline apps](distribute-offline-apps.md). - -## Manage products programmatically - -Microsoft Store for Business and Education provides a set of Admin management APIs. If you organization develops scripts or tools, these APIs allow Admins to programmatically manage items in **Apps & software**. For more information, see [REST API reference for Microsoft Store for Business](/windows/client-management/mdm/rest-api-reference-windows-store-for-business). - -You can download a preview PowerShell script that uses REST APIs. The script is available from PowerShell Gallery. You can use to the script to: -- View items in inventory (**Apps & software**) -- Manage licenses - assigning and removing -- Perform bulk options using .csv files - this automates license management for customers with large numbers of licenses - -> [!NOTE] -> The Microsoft Store for Business and Education Admin role is required to manage products and to use the MSStore module. This requires advanced knowledge of PowerShell. diff --git a/store-for-business/apps-in-microsoft-store-for-business.md b/store-for-business/apps-in-microsoft-store-for-business.md deleted file mode 100644 index 4438a5efb2..0000000000 --- a/store-for-business/apps-in-microsoft-store-for-business.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: Apps in Microsoft Store for Business and Education (Windows 10) -description: Microsoft Store for Business has thousands of apps from many different categories. -ms.assetid: CC5641DA-3CEA-4950-AD81-1AF1AE876926 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Apps in Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Microsoft Store for Business and Education has thousands of apps from many different categories. - -These app types are supported in Microsoft Store for Business and Education: - -- Universal Windows apps for Windows 10 -- Universal Windows apps, by device: phone, Surface Hub, IoT, HoloLens - -Apps in your inventory will have at least one of these supported platforms listed for the app: - -- Windows 10 desktops -- Windows 10 phones -- Windows 10 xbox -- Windows 10 IOT devices -- Windows 10 servers -- Windows 10 \*all devices\* -- Windows 10 Surface Hub -- Windows 10 HoloLens - -Apps that you acquire from Microsoft Store only work on Windows 10-based devices. Even though an app might list Windows 8 as its supported platform, that tells you what platform the app was originally written for. Apps developed for Windows 8, or Windows Phone 8 will work on Windows 10. - -Some apps are free, and some apps charge a price. Currently, you can pay for apps with a credit card. We'll be adding more payment options over time. - -Some apps which are available to consumers in Microsoft Store might not be available to organizations in Microsoft Store for Business and Education. App developers can opt-out their apps, and they also need to meet eligibility requirements for Microsoft Store for Business and Education. For more information, see [Organizational licensing options](/windows/uwp/publish/organizational-licensing). - -Line-of-business (LOB) apps are also supported using Microsoft Store. Admins can invite IT devs and ISVs to be LOB publishers. Apps developed by your LOB publishers that are submitted to Microsoft Store are only available to your organization. Once an administrator accepts an app submitted by one of their LOB publishers, the app can be distributed just like any other app. For more information, see [Working with Line-of-Business apps](working-with-line-of-business-apps.md). - -## In-app purchases - -Some apps offer you the option to make in-app purchases. In-app purchases are not currently supported for apps that are acquired through Microsoft Store and distributed to employees. - -If an employee makes an in-app purchase, they'll make it with their personal Microsoft account and pay for it with a personal payment method. The employee will own the item purchased, and it cannot be transferred to your organization's inventory. - -## Licensing model: online and offline licenses - -Microsoft Store supports two options to license apps: online and offline. - -### Online licensing -Online licensing is the default licensing model and is similar to the model used by Microsoft Store. Online licensed apps require customers and devices to connect to Microsoft Store service to acquire an app and its license. License management is enforced based on the user's Microsoft Entra identity and maintained by Microsoft Store as well as the management tool. By default app updates are handled by Windows Update. - -Distribution options for online-licensed apps include the ability to: - -- Assign an app to employees. -- Add an app to your private store, allowing employees to download the app. -- Distribute through a management tool. - -### Offline licensing -Offline licensing is a new licensing option for Windows 10. With offline licenses, organizations can cache apps and their licenses to deploy within their network. ISVs or devs can opt-in their apps for offline licensing when they submit them to the developer center. Only apps that are opted in to offline licensing will show that they are available for offline licensing in Microsoft Store. This model means organizations can deploy apps when users or devices do not have connectivity to Microsoft Store. Admins control whether or not offline apps are available in Microsoft Store with an offline app visibility setting. - -You have the following distribution options for offline-licensed apps: - -- Include the app in a provisioning package, and then use it as part of imaging a device. -- Distribute the app through a management tool. - -For more information, see [Distribute apps to your employees from Microsoft Store for Business](distribute-apps-to-your-employees-microsoft-store-for-business.md). diff --git a/store-for-business/assign-apps-to-employees.md b/store-for-business/assign-apps-to-employees.md deleted file mode 100644 index db0e139ab0..0000000000 --- a/store-for-business/assign-apps-to-employees.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: Assign apps to employees (Windows 10) -description: Administrators can assign online-licensed apps to employees and students in their organization. -ms.assetid: A0DF4EC2-BE33-41E1-8832-DBB0EBECA31A -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/27/2023 ---- - -# Assign apps to employees - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Admins, Purchasers, and Basic Purchasers can assign online-licensed apps to employees or students in their organization. - -**To assign an app to an employee** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then choose **Apps & software**. -3. Find an app, click the ellipses under **Action**, and then choose **Assign to people**. --OR- - Click the app, and then click **Assign User**. -4. Type the email address for the person you're assigning the app to, and click **Assign**. - -Employees will receive an email with a link that will install the app on their device. Click the link to start Microsoft Store app, and then click **Install**. Also, in Microsoft Store app, they can find the app under **My Library**. - -  - -  - - - - - diff --git a/store-for-business/billing-payments-overview.md b/store-for-business/billing-payments-overview.md deleted file mode 100644 index 08d60c558e..0000000000 --- a/store-for-business/billing-payments-overview.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: Billing and payments overview -description: Find topics about billing and payment support in Microsoft Store for Business. -keywords: billing, payment methods, invoices, credit card, debit card -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Billing and payments - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Access invoices and managed your payment methods. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Understand your invoice](billing-understand-your-invoice-msfb.md) | Information about invoices provided by Microsoft Store for Business. | -| [Understand billing profiles](billing-profile.md) | Information about billing profiles and how they relate to invoices. | -| [Payment methods](payment-methods.md) | Information about managing payment methods. | diff --git a/store-for-business/billing-profile.md b/store-for-business/billing-profile.md deleted file mode 100644 index 43924342b2..0000000000 --- a/store-for-business/billing-profile.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: Understand billing profiles -description: Learn how billing profiles support invoices -keywords: billing profile, invoices, charges, managed charges -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/23/2023 -ms.reviewer: ---- - -# Understand billing profiles - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -For commercial customers purchasing software or hardware products from Microsoft using a Microsoft customer agreement, billing profiles let you customize what products are included on your invoice, and how you pay your invoices. - -Billing profiles include: - -- **Payment methods** – Credit cards or check/wire transfer -- **Contact info** - Billing address and a contact name -- **Permissions** – Permissions that allow you to change the billing profile, pay bills, or use the payment method on the billing profile to make purchases - -Use billing profiles to control your purchases and customize your invoice. A monthly invoice is generated for the products bought using the billing profile. You can customize the invoice such as update the purchase order number and email invoice preference. - -A billing profile is automatically created for your billing account during your first purchase. You can create new billing profiles to set up additional invoices when you make a purchase. For example, you use different billing profiles when you make purchases for each department in your organization. On your next billing date, you'll receive an invoice for each billing profile. - -Roles on the billing profiles have permissions to control purchases, and view and manage invoices. Assign these roles to users who track, organize, and pay invoices like members of the procurement team in your organization. - -## View billing profile -**To view billing profiles** -1. Sign in to [Microsoft Store for Business]( https://businessstore.microsoft.com/), or M365 admin center. -2. Select **Manage**, and then select **Billing and payments**. -3. Select **Billing profiles**, and then select a billing profile from the list to see details. - - On **Overview**, you can edit billing profile details, and turn on or off sending an invoice by email. - - On **Permissions**, you can assign roles to users to pay invoices. - - On **Azure credit balance**, Azure customers can see transaction balance history for the azure credits used by that billing profile. - - On **Azure credits**, Azure customers can see a list of Azure credits associated with that billing profile, and their expiration dates. - -## Need help? Contact us. -If you have questions or need help with your Azure charges, [create a support request with Azure support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/newsupportrequest). - -If you have questions or need help with your invoice in Microsoft Store for Business, [create a support request with Store for Business support](https://businessstore.microsoft.com). diff --git a/store-for-business/billing-understand-your-invoice-msfb.md b/store-for-business/billing-understand-your-invoice-msfb.md deleted file mode 100644 index 7a196272c8..0000000000 --- a/store-for-business/billing-understand-your-invoice-msfb.md +++ /dev/null @@ -1,121 +0,0 @@ ---- -title: Understand your Microsoft Customer Agreement invoice -description: Learn how to read and understand your MCA bill -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 -ms.reviewer: ---- - -# Understand your Microsoft Customer Agreement invoice - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -The invoice provides a summary of your charges and provides instructions for payment. It's available for -download in the Portable Document Format (.pdf) for commercial customers from Microsoft Store for Business [Microsoft Store for Business - Invoice](https://businessstore.microsoft.com/manage/payments-billing/invoices) or can be sent via email. This article applies to invoices generated for a Microsoft Customer Agreement billing account. Check if you have a [Microsoft Customer Agreement](https://businessstore.microsoft.com/manage/organization/agreements). - -## General invoice information - -Invoices are your bill from Microsoft. A few things to note: - -- **Invoice schedule** - You're invoiced on a monthly basis. You can find out which day of the month you receive invoices by checking invoice date under billing profile overview in [Microsoft Store for Business](https://businessstore.microsoft.com/manage/payments-billing/billing-profiles). Charges that occur between the end of the billing period and the invoice date are included in the next month's invoice, since they are in the next billing period. The billing period start and end dates for each invoice are listed in the invoice PDF above **Billing Summary**. -- **Billing profile** - Billing profiles are created during your purchase. Invoices are created for each billing profile. Billing profiles let you customize what products are purchased, how you pay for them, and who can make purchases. For more information, see [Understand billing profiles](billing-profile.md) -- **Items included** - Your invoice includes total charges for all first and third-party software and hardware products purchased under a Microsoft Customer Agreement. That includes items purchased from Microsoft Store for Business and Azure Marketplace. -- **Charges** - Your invoice provides information about products purchased and their related charges and taxes. Purchases are aggregated to provide a concise view of your bill. - -## Online invoice -For Store for Business customers, invoices are also available online. A few things to note: -- **Link to online invoice** - Available from your PDF invoice, and from an email notification. -- **Invoice details** - Expandable view of the charges on your invoice, so you can see more details for each item. -- **Pricing details** - Additional information including discounting and pricing details. -- **Pay online** - Option to make a payment online from the invoice. -- **Azure cost management** - For Azure customers, online invoices include a link to Azure cost management. - -**To view your online invoice** -1. Sign in to [Microsoft Store for Business]( https://businessstore.microsoft.com/). -2. Select **Manage**, and then select **Billing and payments**. -3. Select an invoice from the list to view your online invoice. - -## Detailed terms and descriptions of your invoice -The following sections list the important terms that you see on your -invoice and descriptions for each term. - -### Understand the invoice summary - -The **Invoice Summary** is on the top of the first page and shows information about your billing profile and how you pay. - -![Invoice summary section.](images/invoicesummary.png) - - -| Term | Description | -| --- | --- | -| Sold to |Address of your legal entity, found in billing account properties| -| Bill to |Billing address of the billing profile receiving the invoice, found in billing profile properties| -| Billing Profile |The name of the billing profile receiving the invoice | -| P.O. number |An optional purchase order number, assigned by you for tracking | -| Invoice number |A unique, Microsoft-generated invoice number used for tracking purposes | -| Invoice date |Date that the invoice is generated, typically five to 12 days after end of the Billing cycle. You can check your invoice date in billing profile properties.| -| Payment terms |How you pay for your Microsoft bill. *Net 30 days* means you pay by following instructions on your invoice, within 30 days of the invoice date. | - -### Understand the billing summary -The **Billing Summary** shows the charges against the billing profile since the previous billing period, any credits that were applied, tax, and the total amount due. - - -![Billing summary section.](images/billingsummary.png) - -| Term | Description | -| --- | --- | -| Charges|Total number of Microsoft charges for this billing profile since the last billing period | -| Credits |Credits you received from returns | -| Azure credits applied |Your Azure credits that are automatically applied to Azure charges each billing period | -| Subtotal |The pre-tax amount due | -| Tax |The type and amount of tax that you pay, depending on the country/region of your billing profile. If you don't have to pay tax, then you won't see tax on your invoice. | -| Estimated total savings |The estimated total amount you saved from effective discounts. If applicable, effective discount rates are listed beneath the purchase line items in Details by Invoice Section. | - -### Understand your charges -You'll see the charges, tax, and the total amount due. Azure customers will also see the amount of Azure credits applied. - -`Total = Charges - Azure Credit + Tax` - -The details show the cost broken down by product order name. For Azure customers, this might be organized by invoice section. For more information about how invoice sections are used with Azure products, see [Understand invoice sections](/azure/billing/billing-mca-overview#understand-invoice-sections). -Within each product order, cost is broken down by service family. - -The total amount due for each service family is calculated by subtracting Azure credits from credits/charges and adding tax: - -`Total = Charges/Credits - Azure Credit + Tax` - -![Details by invoice section.](images/invoicesectiondetails.png) - -| Term |Description | -| --- | --- | -| Unit price | The effective unit price of the service (in pricing currency) that is used to the rate the usage. This is unique for a product, service family, meter, and offer. | -| Qty | Quantity purchased or consumed during the billing period | -| Charges/Credits | Net amount of charges after credits/refunds are applied | -| Azure Credit | The amount of Azure credits applied to the Charges/Credits| -| Tax rate | Tax rate(s) depending on country/region | -| Tax amount | Amount of tax applied to purchase based on tax rate | -| Total | The total amount due for the purchase | - -### How to pay -At the bottom of the invoice, there are instructions for paying your bill. You can pay by wire or online. If you pay online, you can use a credit or debit card, or Azure credits, if applicable. - -### Publisher information -If you have third-party services in your bill, the name and address of each publisher is listed at the bottom of your invoice. - -## Next steps -If there are Azure charges on your invoice that you would like more details on, see [Understand the Azure charges on your Microsoft Customer Agreement invoice](/azure/cost-management-billing/understand/mca-understand-your-invoice). - -## Need help? Contact us. - -If you have questions or need help with your Azure charges, [create a support request with Azure support](https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/newsupportrequest). - -If you have questions or need help with your invoice in Microsoft Store for Business, [create a support request with Store for Business support](https://businessstore.microsoft.com/manage/support/summary). diff --git a/store-for-business/configure-mdm-provider-microsoft-store-for-business.md b/store-for-business/configure-mdm-provider-microsoft-store-for-business.md deleted file mode 100644 index 74d05180b7..0000000000 --- a/store-for-business/configure-mdm-provider-microsoft-store-for-business.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: Configure an MDM provider (Windows 10) -description: For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. -ms.assetid: B3A45C8C-A96C-4254-9659-A9B364784673 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Configure an MDM provider - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content. - -Your management tool needs to be installed and configured with Microsoft Entra ID, in the same directory that you are using for Store for Business. Once that's done, you can configure it to work with Store for Business - -**To configure a management tool in Microsoft Entra ID** - -1. Sign in to the Azure Portal as an Administrator. -2. Click **Microsoft Entra ID**, and then choose your directory. -4. Click **Mobility (MDM and MAM)**.   -3. Click **+Add Applications**, find the application, and add it to your directory. - -After your management tool is added to your Microsoft Entra directory, you can configure it to work with Microsoft Store. You can configure multiple management tools - just repeat the following procedure. - -**To configure a management tool in Microsoft Store for Business** - -1. Sign in to the [Store for Business](https://businessstore.microsoft.com) or [Store for Education](https://educationstore.microsoft.com) -2. Click **Manage**, click **Settings**. -3. Under **Distribute**, click **Management tools**. -3. From the list of MDM tools, select the one you want to synchronize with Microsoft Store, and then click **Activate.** - -Your MDM tool is ready to use with Microsoft Store. To learn how to configure synchronization and deploy apps, see these topics: -- [Manage apps you purchased from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business) -- [Manage apps from Microsoft Store for Business with Microsoft Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - -For third-party MDM providers or management servers, check your product documentation. diff --git a/store-for-business/distribute-apps-from-your-private-store.md b/store-for-business/distribute-apps-from-your-private-store.md deleted file mode 100644 index a7c0db425c..0000000000 --- a/store-for-business/distribute-apps-from-your-private-store.md +++ /dev/null @@ -1,72 +0,0 @@ ---- -title: Distribute apps using your private store (Windows 10) -description: The private store is a feature in Microsoft Store for Business and Microsoft Store for Education that organizations receive during the signup process. -ms.assetid: C4644035-845C-4C84-87F0-D87EA8F5BA19 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Distribute apps using your private store - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -The private store is a feature in Microsoft Store for Business and Education that organizations receive during the signup process. When admins add apps to the private store, all employees in the organization can view and download the apps. Your private store is available as a tab in Microsoft Store app, and is usually named for your company or organization. Only apps with online licenses can be added to the private store. - -You can make an app available in your private store when you acquire the app, or you can do it later from your inventory. Once the app is in your private store, employees can claim and install the app. - -**To acquire an app and make it available in your private store** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). - -2. Click an app, choose the license type, and then click **Get the app** to acquire the app for your organization. - - - -Microsoft Store adds the app to **Products and services**. Click **Manage**, **Apps & software** for app distribution options. - -**To make an app in Apps & software available in your private store** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then choose **Products and services**. - - - -3. Click on the application to open the application settings, then select **Private store availability**. -4. Select **Everyone** to make application available for all people in your organization. - - - ->[!Note] - > If you are working with a new Line-of-Business (LOB) app, you have to wait for the app to be available in **Products & services** before adding it to your private store. For more information, see [Working with line-of-business apps](working-with-line-of-business-apps.md). - -## Private store availability -You can use security groups to scope which users can install an app from your private store. For more information, see [Private store availability](app-inventory-management-microsoft-store-for-business.md#private-store-availability). - -Employees can claim apps that admins added to the private store by doing the following. - -**To claim an app from the private store** - -1. Sign in to your computer with your Microsoft Entra credentials, and start Microsoft Store app. -2. Click the **private store** tab. -3. Click the app you want to install, and then click **Install**. - - -## Related topics -- [Manage access to private store](manage-access-to-private-store.md) -- [Manage private store settings](manage-private-store-settings.md) -- [Configure access to Microsoft Store](/windows/configuration/stop-employees-from-using-microsoft-store) diff --git a/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md b/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md deleted file mode 100644 index ed5f058ffe..0000000000 --- a/store-for-business/distribute-apps-to-your-employees-microsoft-store-for-business.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: Distribute apps to your employees from the Microsoft Store for Business and Education (Windows 10) -description: Distribute apps to your employees from Microsoft Store for Business or Microsoft Store for Education. You can assign apps to employees,or let employees install them from your private store. -ms.assetid: E591497C-6DFA-49C1-8329-4670F2164E9E -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Distribute apps to your employees from Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Distribute apps to your employees from Microsoft Store for Business and Microsoft Store for Education. You can assign apps to employees, or let employees install them from your private store. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Distribute apps using your private store](distribute-apps-from-your-private-store.md) | The private store is a feature in Microsoft Store that organizations and schools receive during the signup process. When admins add apps to the private store, all people in the organization can view and download the apps. Only apps with online licenses can be added to the private store. | -| [Assign apps to employees](assign-apps-to-employees.md) | Admins can assign online-licensed apps to people in their organization. | -| [Distribute apps with a management tool](distribute-apps-with-management-tool.md) | Admins can configure a mobile device management (MDM) tool to synchronize your Microsoft Store inventory. Microsoft Store management tool services work with MDM tools to manage content. | -| [Distribute offline apps](distribute-offline-apps.md) | Offline licensing is a new licensing option for Windows 10. With offline licenses, organizations can download apps and their licenses to deploy within their network, or on devices that are not connected to the Internet. This allows organizations to deploy apps to devices without connectivity to the Store. | diff --git a/store-for-business/distribute-apps-with-management-tool.md b/store-for-business/distribute-apps-with-management-tool.md deleted file mode 100644 index 0d0f36b0db..0000000000 --- a/store-for-business/distribute-apps-with-management-tool.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: Distribute apps with a management tool (Windows 10) -description: You can configure a mobile device management (MDM) tool to synchronize your Microsoft Store for Business or Microsoft Store for Education inventory. Microsoft Store management tool services work with MDM tools to manage content. -ms.assetid: 006F5FB1-E688-4769-BD9A-CFA6F5829016 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Distribute apps with a management tool - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -You can configure a mobile device management (MDM) tool to synchronize your Microsoft Store for Business or Microsoft Store for Education inventory. Microsoft Store management tool services work with MDM tools to manage content. - -Your MDM tool needs to be installed and configured in Microsoft Entra ID, in the same Microsoft Entra directory used with Microsoft Store. - -In Microsoft Entra management portal, find the MDM application, and then add it to your directory. Once the MDM has been configured in Microsoft Entra ID, you can authorize the tool to work with the Microsoft Store for Business or Microsoft Store for Education. This allows the MDM tool to call Microsoft Store management tool services. For more information, see [Configure MDM provider](configure-mdm-provider-microsoft-store-for-business.md) and [Manage apps you purchased from the Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business). - -Microsoft Store services provide: - -- Services for third-party MDM tools. -- Synchronize app purchases and updates. -- Synchronize metadata. For offline-licensed apps, also synchronize offline app package and offline licenses. -- The ability to download offline-licensed apps from Store for Business. - -MDM tool requirements: - -- Must be a Microsoft Entra application to authenticate against the Store for Business services. -- Must be configured in Microsoft Entra ID, and Microsoft Store. -- Microsoft Entra identity is required to authorize Microsoft Store services. - -## Distribute offline-licensed apps - -If your vendor doesn't support the ability to synchronize applications from the management tool services, or can't connect to the management tool services, your vendor may support the ability to deploy offline licensed applications by downloading the application and license from the store and then deploying the app through your MDM. For more information on online and offline licensing with Store for Business, see [Apps in the Microsoft Store for Business](./apps-in-microsoft-store-for-business.md#licensing-model). - -This diagram shows how you can use a management tool to distribute offline-licensed app to employees in your organization. Once synchronized from Store for Business, management tools can use the Windows Management framework to distribute applications to devices. - -![Image showing flow for distributing offline-licensed app from Microsoft Store for Business to employees in your organization.](images/wsfb-offline-distribute-mdm.png) - -## Distribute online-licensed apps - -This diagram shows how you can use a management tool to distribute an online-licensed app to employees in your organization. Once synchronized from Microsoft Store, management tools use the Windows Management framework to distribute applications to devices. For online-licensed applications, the management tool calls back to Microsoft Store management services to assign an application prior to issuing the policy to install the application. - -![Image showing flow for distributing online-licensed app from Microsoft Store for Business.](images/wsfb-online-distribute-mdm.png) - -## Related topics - -[Configure MDM Provider](configure-mdm-provider-microsoft-store-for-business.md) - -[Manage apps you purchased from the Microsoft Store for Business and Education with Microsoft Intune](/mem/intune/apps/windows-store-for-business) diff --git a/store-for-business/distribute-offline-apps.md b/store-for-business/distribute-offline-apps.md deleted file mode 100644 index eefa9c7b90..0000000000 --- a/store-for-business/distribute-offline-apps.md +++ /dev/null @@ -1,82 +0,0 @@ ---- -title: Distribute offline apps (Windows 10) -description: Offline licensing is a new licensing option for Windows 10. -ms.assetid: 6B9F6876-AA66-4EE4-A448-1371511AC95E -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Distribute offline apps - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Offline licensing is a new licensing option for Windows 10 with Microsoft Store for Business and Microsoft Store for Education. With offline licenses, organizations can download apps and their licenses to deploy within their network, or on devices that are not connected to the Internet. ISVs or devs can opt-in their apps for offline licensing when they submit them to the Windows Dev Center. Only apps that are opted in to offline licensing will show that they are available for offline licensing in Microsoft Store for Business and Microsoft Store for Education. This model allows organizations to deploy apps when users or devices do not have connectivity to the Store. - -## Why offline-licensed apps? - -Offline-licensed apps offer an alternative to online apps, and provide additional deployment options. Some reasons to use offline-licensed apps: - -- **You don't have access to Microsoft Store services** - If your employees don't have access to the Internet and Microsoft Store services, downloading offline-licensed apps and deploying them with imaging is an alternative to online-licensed apps. - -- **You use imaging to manage devices in your organization** - Offline-licensed apps can be added to images and deployed with Deployment Image Servicing and Management (DISM), or Windows Imaging and Configuration Designer (ICD). - -- **Your employees do not have Microsoft Entra accounts** - Microsoft Entra accounts are required for employees that install apps assigned to them from Microsoft Store or that claim apps from a private store. - -## Distribution options for offline-licensed apps - -You can't distribute offline-licensed apps directly from Microsoft Store. Once you download the items for the offline-licensed app, you have options for distributing the apps: - -- **Deployment Image Servicing and Management**. DISM is a command-line tool that is used to mount and service Microsoft Windows images before deployment. You can also use DISM to install, uninstall, configure, and update Windows features, packages, drivers, and international settings in a .wim file or VHD using the DISM servicing commands. DISM commands are used on offline images. For more information, see [Deployment Image Servicing and Management](/windows-hardware/manufacture/desktop/dism---deployment-image-servicing-and-management-technical-reference-for-windows). - -- **Create provisioning package**. You can use Windows Imaging and Configuration Designer (ICD) to create a provisioning package for your offline app. Once you have the package, there are options to [apply the provisioning package](/windows/configuration/provisioning-packages/provisioning-apply-package). For more information, see [Provisioning Packages for Windows 10](/windows/configuration/provisioning-packages/provisioning-packages). - -- **Mobile device management provider or management server.** You can use a mobile device management (MDM) provider or management server to distribute offline apps. For more information, see these topics: - - - [Manage apps from Microsoft Store for Business with Microsoft Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - - [Manage apps from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business) - -For third-party MDM providers or management servers, check your product documentation. - -## Download an offline-licensed app - -There are several items to download or create for offline-licensed apps. The app package and app license are required; app metadata and app frameworks are optional. This section includes more info on each item, and tells you how to download an offline-licensed app. - -- **App metadata** - App metadata is optional. The metadata includes app details, links to icons, product id, localized product ids, and other items. Devs who plan to use an app as part of another app or tool, might want the app metadata. - -- **App package** - App packages are required for distributing offline apps. There are app packages for different combinations of app platform and device architecture. You'll need to know what device architectures you have in your organization to know if there are app packages to support your devices. - -- **App license** - App licenses are required for distributing offline apps. Use encoded licenses when you distribute offline-licensed apps using a management tool or ICD. Use unencoded licenses when you distribute offline-licensed apps using DISM. - -- **App frameworks** - App frameworks are optional. If you already have the required framework, you don't need to download another copy. The Store for Business will select the app framework needed for the app platform and architecture that you selected. - -**To download an offline-licensed app** - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com/) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**. -3. Click **Settings**. -4. Click **Shop**. Search for the **Shopping experience** section, change the License type to **Offline**, and click **Get the app**, which will add the app to your inventory. -5. Click **Manage**. You now have access to download the appx bundle package metadata and license file. -6. Go to **Products & services**, and select **Apps & software**. (The list may be empty, but it will auto-populate after some time.) - - - **To download app metadata**: Choose the language for the app metadata, and then click **Download**. Save the downloaded app metadata. This is optional. - - **To download app package**: Click to expand the package details information, choose the Platform and Architecture combination that you need for your organization, and then click **Download**. Save the downloaded app package. This is required. - - **To download an app license**: Choose either **Encoded**, or **Unencoded**, and then click **Generate license**. Save the downloaded license. This is required. - - **To download an app framework**: Find the framework you need to support your app package, and click **Download**. This is optional. - -> [!NOTE] -> You need the framework to support your app package, but if you already have a copy, you don't need to download it again. Frameworks are backward compatible. diff --git a/store-for-business/docfx.json b/store-for-business/docfx.json index 882a3d8111..e29e3bfdae 100644 --- a/store-for-business/docfx.json +++ b/store-for-business/docfx.json @@ -37,7 +37,10 @@ "tier2" ], "breadcrumb_path": "/microsoft-store/breadcrumb/toc.json", - "uhfHeaderId": "MSDocsHeader-M365-IT", + "uhfHeaderId": "MSDocsHeader-Archive", + "is_archived": true, + "is_retired": true, + "ROBOTS": "NOINDEX,NOFOLLOW", "ms.author": "trudyha", "audience": "ITPro", "ms.service": "store-for-business", diff --git a/store-for-business/education/TOC.yml b/store-for-business/education/TOC.yml deleted file mode 100644 index edb38bce1a..0000000000 --- a/store-for-business/education/TOC.yml +++ /dev/null @@ -1,86 +0,0 @@ -- name: Microsoft Store for Education - href: ../index.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: What's new in Microsoft Store for Business and Education - href: ../whats-new-microsoft-store-business-education.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Sign up and get started - href: ../sign-up-microsoft-store-for-business-overview.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: Microsoft Store for Business and Education overview - href: ../microsoft-store-for-business-overview.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Prerequisites for Microsoft Store for Business and Education - href: ../prerequisites-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Sign up for Microsoft Store for Business or Microsoft Store for Education - href: /microsoft-store/sign-up-microsoft-store-for-business?toc=/microsoft-store/education/toc.json - - name: Roles and permissions in the Microsoft Store for Business and Education - href: ../roles-and-permissions-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: "Settings reference: Microsoft Store for Business and Education" - href: ../settings-reference-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Working with Microsoft Store for Education - href: /education/windows/education-scenarios-store-for-business?toc=/microsoft-store/education/toc.json - - name: Find and acquire apps - href: ../find-and-acquire-apps-overview.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: Apps in the Microsoft Store for Business and Education - href: ../apps-in-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Acquire apps in the Microsoft Store for Business and Education - href: ../acquire-apps-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Working with line-of-business apps - href: ../working-with-line-of-business-apps.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: "Get Minecraft: Education Edition" - href: /education/windows/get-minecraft-for-education?toc=/microsoft-store/education/toc.json - items: - - name: "For teachers: get Minecraft Education Edition" - href: /education/windows/teacher-get-minecraft?toc=/microsoft-store/education/toc.json - - name: "For IT administrators: get Minecraft Education Edition" - href: /education/windows/school-get-minecraft?toc=/microsoft-store/education/toc.json - - name: "Get Minecraft: Education Edition with Windows 10 device promotion" - href: /education/windows/get-minecraft-device-promotion?toc=/microsoft-store/education/toc.json - - name: Distribute apps to your employees from the Microsoft Store for Business and Education - href: ../distribute-apps-to-your-employees-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: Distribute apps using your private store - href: ../distribute-apps-from-your-private-store.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Assign apps to employees - href: ../assign-apps-to-employees.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Distribute apps with a management tool - href: ../distribute-apps-with-management-tool.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Distribute offline apps - href: ../distribute-offline-apps.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage products and services - href: ../manage-apps-microsoft-store-for-business-overview.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: App inventory management for Microsoft Store for Business - href: ../app-inventory-management-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage app orders in Microsoft Store for Business and Education - href: ../manage-orders-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage access to private store - href: ../manage-access-to-private-store.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage private store settings - href: ../manage-private-store-settings.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Configure MDM provider - href: ../configure-mdm-provider-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage Windows device deployment with Windows Autopilot Deployment - href: ../add-profile-to-devices.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Microsoft Store for Business and Education PowerShell module - preview - href: ../microsoft-store-for-business-education-powershell-module.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage software purchased with Microsoft Products and Services agreement in Microsoft Store for Business - href: ../manage-mpsa-software-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Device Guard signing portal - href: ../device-guard-signing-portal.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: Add unsigned app to code integrity policy - href: ../add-unsigned-app-to-code-integrity-policy.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Sign code integrity policy with Device Guard signing - href: ../sign-code-integrity-policy-with-device-guard-signing.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage settings in the Microsoft Store for Business and Education - href: ../manage-settings-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - items: - - name: Update Microsoft Store for Business and Microsoft Store for Education account settings - href: ../update-microsoft-store-for-business-account-settings.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Manage user accounts in Microsoft Store for Business and Education - href: ../manage-users-and-groups-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Troubleshoot Microsoft Store for Business - href: ../troubleshoot-microsoft-store-for-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json - - name: Notifications in Microsoft Store for Business and Education - href: ../notifications-microsoft-store-business.md?toc=%2fmicrosoft-store%2feducation%2ftoc.json diff --git a/store-for-business/find-and-acquire-apps-overview.md b/store-for-business/find-and-acquire-apps-overview.md deleted file mode 100644 index 0226497186..0000000000 --- a/store-for-business/find-and-acquire-apps-overview.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: Find and acquire apps (Windows 10) -description: Use the Microsoft Store for Business and Education to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization. -ms.assetid: 274A5003-5F15-4635-BB8B-953953FD209A -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Find and acquire apps - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Use the Microsoft Store for Business and Education to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Apps in the Microsoft Store for Business and Education](apps-in-microsoft-store-for-business.md) | Store for Business and Education has thousands of apps from many different categories. | -| [Acquire apps in the Microsoft Store for Business and Education](acquire-apps-microsoft-store-for-business.md) | You can acquire apps from the Microsoft Store for Business and Education for your employees. | -| [Working with line-of-business apps](working-with-line-of-business-apps.md) | Your company can make line-of-business (LOB) applications available through Microsoft Store for Business and Education. These apps are custom to your company – they might be internal business apps, or apps specific to your business or industry. | - diff --git a/store-for-business/images/aadjwsfb.jpg b/store-for-business/images/aadjwsfb.jpg deleted file mode 100644 index 428f1a26d4..0000000000 Binary files a/store-for-business/images/aadjwsfb.jpg and /dev/null differ diff --git a/store-for-business/images/add-devices.png b/store-for-business/images/add-devices.png deleted file mode 100644 index b8f274c600..0000000000 Binary files a/store-for-business/images/add-devices.png and /dev/null differ diff --git a/store-for-business/images/autopilot-process.png b/store-for-business/images/autopilot-process.png deleted file mode 100644 index 56c379fd5f..0000000000 Binary files a/store-for-business/images/autopilot-process.png and /dev/null differ diff --git a/store-for-business/images/bank-account-icon.png b/store-for-business/images/bank-account-icon.png deleted file mode 100644 index 664f8c7a6f..0000000000 Binary files a/store-for-business/images/bank-account-icon.png and /dev/null differ diff --git a/store-for-business/images/billing-acct-roles.png b/store-for-business/images/billing-acct-roles.png deleted file mode 100644 index 6977bef250..0000000000 Binary files a/store-for-business/images/billing-acct-roles.png and /dev/null differ diff --git a/store-for-business/images/billingsummary.png b/store-for-business/images/billingsummary.png deleted file mode 100644 index 9f45179ead..0000000000 Binary files a/store-for-business/images/billingsummary.png and /dev/null differ diff --git a/store-for-business/images/edu-icon.png b/store-for-business/images/edu-icon.png deleted file mode 100644 index 49009f7085..0000000000 Binary files a/store-for-business/images/edu-icon.png and /dev/null differ diff --git a/store-for-business/images/invite-people.png b/store-for-business/images/invite-people.png deleted file mode 100644 index b004d3ad7f..0000000000 Binary files a/store-for-business/images/invite-people.png and /dev/null differ diff --git a/store-for-business/images/invoicesectiondetails.png b/store-for-business/images/invoicesectiondetails.png deleted file mode 100644 index cdaac8423e..0000000000 Binary files a/store-for-business/images/invoicesectiondetails.png and /dev/null differ diff --git a/store-for-business/images/invoicesummary.png b/store-for-business/images/invoicesummary.png deleted file mode 100644 index c17e7f0713..0000000000 Binary files a/store-for-business/images/invoicesummary.png and /dev/null differ diff --git a/store-for-business/images/license-assign-icon.png b/store-for-business/images/license-assign-icon.png deleted file mode 100644 index 4a5daa933c..0000000000 Binary files a/store-for-business/images/license-assign-icon.png and /dev/null differ diff --git a/store-for-business/images/lob-sku.png b/store-for-business/images/lob-sku.png deleted file mode 100644 index 8637fd3f3d..0000000000 Binary files a/store-for-business/images/lob-sku.png and /dev/null differ diff --git a/store-for-business/images/lob-workflow.png b/store-for-business/images/lob-workflow.png deleted file mode 100644 index 954b787e6d..0000000000 Binary files a/store-for-business/images/lob-workflow.png and /dev/null differ diff --git a/store-for-business/images/mc-ee-video-icon.png b/store-for-business/images/mc-ee-video-icon.png deleted file mode 100644 index 61c8a0f681..0000000000 Binary files a/store-for-business/images/mc-ee-video-icon.png and /dev/null differ diff --git a/store-for-business/images/mpsa-link.png b/store-for-business/images/mpsa-link.png deleted file mode 100644 index 74f1496935..0000000000 Binary files a/store-for-business/images/mpsa-link.png and /dev/null differ diff --git a/store-for-business/images/msfb-add-collection.png b/store-for-business/images/msfb-add-collection.png deleted file mode 100644 index 0cf1a7d0af..0000000000 Binary files a/store-for-business/images/msfb-add-collection.png and /dev/null differ diff --git a/store-for-business/images/msfb-autopilot-csv.png b/store-for-business/images/msfb-autopilot-csv.png deleted file mode 100644 index d150ae4f42..0000000000 Binary files a/store-for-business/images/msfb-autopilot-csv.png and /dev/null differ diff --git a/store-for-business/images/msfb-click-private-store.png b/store-for-business/images/msfb-click-private-store.png deleted file mode 100644 index 35642c740e..0000000000 Binary files a/store-for-business/images/msfb-click-private-store.png and /dev/null differ diff --git a/store-for-business/images/msfb-find-partner.png b/store-for-business/images/msfb-find-partner.png deleted file mode 100644 index 23759cfb5f..0000000000 Binary files a/store-for-business/images/msfb-find-partner.png and /dev/null differ diff --git a/store-for-business/images/msfb-products-services.png b/store-for-business/images/msfb-products-services.png deleted file mode 100644 index 1ddba79518..0000000000 Binary files a/store-for-business/images/msfb-products-services.png and /dev/null differ diff --git a/store-for-business/images/msfb-provider-list.png b/store-for-business/images/msfb-provider-list.png deleted file mode 100644 index 2fbafca80f..0000000000 Binary files a/store-for-business/images/msfb-provider-list.png and /dev/null differ diff --git a/store-for-business/images/msfb-ps-collection-idp.png b/store-for-business/images/msfb-ps-collection-idp.png deleted file mode 100644 index ddd8907d6b..0000000000 Binary files a/store-for-business/images/msfb-ps-collection-idp.png and /dev/null differ diff --git a/store-for-business/images/msfb-settings-icon.png b/store-for-business/images/msfb-settings-icon.png deleted file mode 100644 index 1601965566..0000000000 Binary files a/store-for-business/images/msfb-settings-icon.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-app-request.png b/store-for-business/images/msfb-wn-1709-app-request.png deleted file mode 100644 index e454aca9a9..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-app-request.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-edge-ext.png b/store-for-business/images/msfb-wn-1709-edge-ext.png deleted file mode 100644 index 15170ecfc3..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-edge-ext.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-my-org.png b/store-for-business/images/msfb-wn-1709-my-org.png deleted file mode 100644 index ecb47b6e8a..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-my-org.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-o365-csp.png b/store-for-business/images/msfb-wn-1709-o365-csp.png deleted file mode 100644 index b51d32923a..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-o365-csp.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-o365-prepaid.png b/store-for-business/images/msfb-wn-1709-o365-prepaid.png deleted file mode 100644 index 9bdb360a31..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-o365-prepaid.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1709-search-result-sub-cat.png b/store-for-business/images/msfb-wn-1709-search-result-sub-cat.png deleted file mode 100644 index de246824f5..0000000000 Binary files a/store-for-business/images/msfb-wn-1709-search-result-sub-cat.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1711-export-user.png b/store-for-business/images/msfb-wn-1711-export-user.png deleted file mode 100644 index 61efc7307e..0000000000 Binary files a/store-for-business/images/msfb-wn-1711-export-user.png and /dev/null differ diff --git a/store-for-business/images/msfb-wn-1801-products-services.png b/store-for-business/images/msfb-wn-1801-products-services.png deleted file mode 100644 index dc98ffd2e4..0000000000 Binary files a/store-for-business/images/msfb-wn-1801-products-services.png and /dev/null differ diff --git a/store-for-business/images/msft-accept-partner.png b/store-for-business/images/msft-accept-partner.png deleted file mode 100644 index 6b04d822a4..0000000000 Binary files a/store-for-business/images/msft-accept-partner.png and /dev/null differ diff --git a/store-for-business/images/office-logo.png b/store-for-business/images/office-logo.png deleted file mode 100644 index 04d970bb47..0000000000 Binary files a/store-for-business/images/office-logo.png and /dev/null differ diff --git a/store-for-business/images/perf-improvement-icon.png b/store-for-business/images/perf-improvement-icon.png deleted file mode 100644 index 74be488894..0000000000 Binary files a/store-for-business/images/perf-improvement-icon.png and /dev/null differ diff --git a/store-for-business/images/private-store-icon.png b/store-for-business/images/private-store-icon.png deleted file mode 100644 index f09679693f..0000000000 Binary files a/store-for-business/images/private-store-icon.png and /dev/null differ diff --git a/store-for-business/images/product-and-service-icon.png b/store-for-business/images/product-and-service-icon.png deleted file mode 100644 index c18d3c8266..0000000000 Binary files a/store-for-business/images/product-and-service-icon.png and /dev/null differ diff --git a/store-for-business/images/products-and-services-photoshop.png b/store-for-business/images/products-and-services-photoshop.png deleted file mode 100644 index f20c074aeb..0000000000 Binary files a/store-for-business/images/products-and-services-photoshop.png and /dev/null differ diff --git a/store-for-business/images/products-and-services-ppt.png b/store-for-business/images/products-and-services-ppt.png deleted file mode 100644 index 9b4d77fb7c..0000000000 Binary files a/store-for-business/images/products-and-services-ppt.png and /dev/null differ diff --git a/store-for-business/images/purchasing-roles.png b/store-for-business/images/purchasing-roles.png deleted file mode 100644 index e45d9294f5..0000000000 Binary files a/store-for-business/images/purchasing-roles.png and /dev/null differ diff --git a/store-for-business/images/security-groups-icon.png b/store-for-business/images/security-groups-icon.png deleted file mode 100644 index 328a60837d..0000000000 Binary files a/store-for-business/images/security-groups-icon.png and /dev/null differ diff --git a/store-for-business/images/sfb-allow-shop-setting.png b/store-for-business/images/sfb-allow-shop-setting.png deleted file mode 100644 index 52320751ac..0000000000 Binary files a/store-for-business/images/sfb-allow-shop-setting.png and /dev/null differ diff --git a/store-for-business/images/skype-icon-wn.png b/store-for-business/images/skype-icon-wn.png deleted file mode 100644 index d9819ae0ae..0000000000 Binary files a/store-for-business/images/skype-icon-wn.png and /dev/null differ diff --git a/store-for-business/images/wsfb-distribute.png b/store-for-business/images/wsfb-distribute.png deleted file mode 100644 index d0482f6ebe..0000000000 Binary files a/store-for-business/images/wsfb-distribute.png and /dev/null differ diff --git a/store-for-business/images/wsfb-firstrun.png b/store-for-business/images/wsfb-firstrun.png deleted file mode 100644 index 2673567a1e..0000000000 Binary files a/store-for-business/images/wsfb-firstrun.png and /dev/null differ diff --git a/store-for-business/images/wsfb-inventory-viewlicense.png b/store-for-business/images/wsfb-inventory-viewlicense.png deleted file mode 100644 index 9fafad1aff..0000000000 Binary files a/store-for-business/images/wsfb-inventory-viewlicense.png and /dev/null differ diff --git a/store-for-business/images/wsfb-inventory.png b/store-for-business/images/wsfb-inventory.png deleted file mode 100644 index b060fb30e4..0000000000 Binary files a/store-for-business/images/wsfb-inventory.png and /dev/null differ diff --git a/store-for-business/images/wsfb-inventoryaddprivatestore.png b/store-for-business/images/wsfb-inventoryaddprivatestore.png deleted file mode 100644 index bb1152e35b..0000000000 Binary files a/store-for-business/images/wsfb-inventoryaddprivatestore.png and /dev/null differ diff --git a/store-for-business/images/wsfb-landing.png b/store-for-business/images/wsfb-landing.png deleted file mode 100644 index beae0b52af..0000000000 Binary files a/store-for-business/images/wsfb-landing.png and /dev/null differ diff --git a/store-for-business/images/wsfb-licenseassign.png b/store-for-business/images/wsfb-licenseassign.png deleted file mode 100644 index 5904abb3b9..0000000000 Binary files a/store-for-business/images/wsfb-licenseassign.png and /dev/null differ diff --git a/store-for-business/images/wsfb-licensedetails.png b/store-for-business/images/wsfb-licensedetails.png deleted file mode 100644 index 53e0f5c935..0000000000 Binary files a/store-for-business/images/wsfb-licensedetails.png and /dev/null differ diff --git a/store-for-business/images/wsfb-licensereclaim.png b/store-for-business/images/wsfb-licensereclaim.png deleted file mode 100644 index 9f94cd3600..0000000000 Binary files a/store-for-business/images/wsfb-licensereclaim.png and /dev/null differ diff --git a/store-for-business/images/wsfb-manageinventory.png b/store-for-business/images/wsfb-manageinventory.png deleted file mode 100644 index 9a544ddc21..0000000000 Binary files a/store-for-business/images/wsfb-manageinventory.png and /dev/null differ diff --git a/store-for-business/images/wsfb-offline-distribute-mdm.png b/store-for-business/images/wsfb-offline-distribute-mdm.png deleted file mode 100644 index ec0e77a9a9..0000000000 Binary files a/store-for-business/images/wsfb-offline-distribute-mdm.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-1.png b/store-for-business/images/wsfb-onboard-1.png deleted file mode 100644 index 012e91a845..0000000000 Binary files a/store-for-business/images/wsfb-onboard-1.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-2.png b/store-for-business/images/wsfb-onboard-2.png deleted file mode 100644 index 2ff98fb1f7..0000000000 Binary files a/store-for-business/images/wsfb-onboard-2.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-3.png b/store-for-business/images/wsfb-onboard-3.png deleted file mode 100644 index ed9a61d353..0000000000 Binary files a/store-for-business/images/wsfb-onboard-3.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-4.png b/store-for-business/images/wsfb-onboard-4.png deleted file mode 100644 index d99185ddc6..0000000000 Binary files a/store-for-business/images/wsfb-onboard-4.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-5.png b/store-for-business/images/wsfb-onboard-5.png deleted file mode 100644 index 68049f4425..0000000000 Binary files a/store-for-business/images/wsfb-onboard-5.png and /dev/null differ diff --git a/store-for-business/images/wsfb-onboard-7.png b/store-for-business/images/wsfb-onboard-7.png deleted file mode 100644 index 38b7348b21..0000000000 Binary files a/store-for-business/images/wsfb-onboard-7.png and /dev/null differ diff --git a/store-for-business/images/wsfb-online-distribute-mdm.png b/store-for-business/images/wsfb-online-distribute-mdm.png deleted file mode 100644 index 4b0f7cbf3a..0000000000 Binary files a/store-for-business/images/wsfb-online-distribute-mdm.png and /dev/null differ diff --git a/store-for-business/images/wsfb-paid-app-temp.png b/store-for-business/images/wsfb-paid-app-temp.png deleted file mode 100644 index 89e3857d07..0000000000 Binary files a/store-for-business/images/wsfb-paid-app-temp.png and /dev/null differ diff --git a/store-for-business/images/wsfb-permissions-assignrole.png b/store-for-business/images/wsfb-permissions-assignrole.png deleted file mode 100644 index de2e1785ba..0000000000 Binary files a/store-for-business/images/wsfb-permissions-assignrole.png and /dev/null differ diff --git a/store-for-business/images/wsfb-private-store-gpo.png b/store-for-business/images/wsfb-private-store-gpo.png deleted file mode 100644 index 5e7fe44ec2..0000000000 Binary files a/store-for-business/images/wsfb-private-store-gpo.png and /dev/null differ diff --git a/store-for-business/images/wsfb-privatestore.png b/store-for-business/images/wsfb-privatestore.png deleted file mode 100644 index 74c9f1690d..0000000000 Binary files a/store-for-business/images/wsfb-privatestore.png and /dev/null differ diff --git a/store-for-business/images/wsfb-privatestoreapps.png b/store-for-business/images/wsfb-privatestoreapps.png deleted file mode 100644 index 1ddb543796..0000000000 Binary files a/store-for-business/images/wsfb-privatestoreapps.png and /dev/null differ diff --git a/store-for-business/images/wsfb-renameprivatestore.png b/store-for-business/images/wsfb-renameprivatestore.png deleted file mode 100644 index c6db282581..0000000000 Binary files a/store-for-business/images/wsfb-renameprivatestore.png and /dev/null differ diff --git a/store-for-business/images/wsfb-settings-mgmt.png b/store-for-business/images/wsfb-settings-mgmt.png deleted file mode 100644 index 2a7b590d19..0000000000 Binary files a/store-for-business/images/wsfb-settings-mgmt.png and /dev/null differ diff --git a/store-for-business/images/wsfb-settings-permissions.png b/store-for-business/images/wsfb-settings-permissions.png deleted file mode 100644 index 63d04d270b..0000000000 Binary files a/store-for-business/images/wsfb-settings-permissions.png and /dev/null differ diff --git a/store-for-business/images/wsfb-wsappaddacct.png b/store-for-business/images/wsfb-wsappaddacct.png deleted file mode 100644 index 5c0bd9a4ce..0000000000 Binary files a/store-for-business/images/wsfb-wsappaddacct.png and /dev/null differ diff --git a/store-for-business/images/wsfb-wsappprivatestore.png b/store-for-business/images/wsfb-wsappprivatestore.png deleted file mode 100644 index 48d9f79892..0000000000 Binary files a/store-for-business/images/wsfb-wsappprivatestore.png and /dev/null differ diff --git a/store-for-business/images/wsfb-wsappsignin.png b/store-for-business/images/wsfb-wsappsignin.png deleted file mode 100644 index c2c2631a94..0000000000 Binary files a/store-for-business/images/wsfb-wsappsignin.png and /dev/null differ diff --git a/store-for-business/images/wsfb-wsappworkacct.png b/store-for-business/images/wsfb-wsappworkacct.png deleted file mode 100644 index 5eb9035124..0000000000 Binary files a/store-for-business/images/wsfb-wsappworkacct.png and /dev/null differ diff --git a/store-for-business/index.md b/store-for-business/index.md deleted file mode 100644 index b018c5e595..0000000000 --- a/store-for-business/index.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: Microsoft Store for Business and Education (Windows 10) -description: Welcome to the Microsoft Store for Business and Education. You can use Microsoft Store, to find, acquire, distribute, and manage apps for your organization or school. -ms.assetid: 527E611E-4D47-44F0-9422-DCC2D1ACBAB8 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: high -ms.date: 05/24/2023 ---- - -# Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Welcome to the Microsoft Store for Business and Education! You can use Microsoft Store to find, acquire, distribute, and manage apps for your organization or school. - -> [!NOTE] -> -> - As of April 14, 2021, all apps that charge a base price above free are no longer available to buy in the Microsoft Store for Business and Education. If you've already bought a paid app, you can still use it, but no new purchases are possible from businessstore.microsoft.com or educationstore.microsoft.com. Also, you can't buy additional licenses for apps you already bought. You can still assign and reassign licenses for apps that you already own and use from the private store. Apps with a base price of "free" are still available. This change doesn't impact apps in the Microsoft Store on Windows 10. -> -> - Also as of April 14, 2021, you must sign in with your Microsoft Entra account before you browse Microsoft Store for Business and Education. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Sign up and get started](sign-up-microsoft-store-for-business-overview.md) | IT admins can sign up for the Microsoft Store for Business and Education, and get started working with apps. | -| [Find and acquire apps](find-and-acquire-apps-overview.md) | Use the Microsoft Store for Business and Education to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization. | -| [Manage apps](manage-apps-microsoft-store-for-business-overview.md) | Manage settings and access to apps in Microsoft Store for Business and Education. | -| [Device Guard signing portal](device-guard-signing-portal.md) | Device Guard signing is a Device Guard feature that is available in the Microsoft Store for Business and Education. It gives admins a single place to sign catalog files and code integrity policies. After admins have created catalog files for unsigned apps and signed the catalog files, they can add the signers to a code integrity policy. You can merge the code integrity policy with your existing policy to include your custom signing certificate. This allows you to trust the catalog files. | -| [Manage settings in the Microsoft Store for Business and Education](manage-settings-microsoft-store-for-business.md) | You can add users and groups, as well as update some of the settings associated with the Microsoft Entra tenant | -| [Troubleshoot Microsoft Store for Business and Education](troubleshoot-microsoft-store-for-business.md) | Troubleshooting topics for Microsoft Store for Business and Education. | diff --git a/store-for-business/manage-access-to-private-store.md b/store-for-business/manage-access-to-private-store.md deleted file mode 100644 index 7ebf151814..0000000000 --- a/store-for-business/manage-access-to-private-store.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: Manage access to private store (Windows 10) -description: You can manage access to your private store in Microsoft Store for Business and Microsoft Store for Education. -ms.assetid: 4E00109C-2782-474D-98C0-02A05BE613A5 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.date: 05/24/2023 ---- - -# Manage access to private store - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). - -## Microsoft Store for Business tab removed - -In April 2023, the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. The Microsoft Store for Business tab will continue to be available on Hololens devices. Users will no longer be able to see products added to the private store within the Microsoft Store app and will need to go to the [Microsoft Store for Business](https://businessstore.microsoft.com/) website to access the private store. - -The [ApplicationManagement/RequirePrivateStoreOnly](/windows/client-management/mdm/policy-configuration-service-provider#ApplicationManagement_RequirePrivateStoreOnly) MDM policy and **Only display the private store within the Microsoft Store app** Group policy will block access to the Microsoft Store app entirely. With those policies in place, users may see one of the following errors in the Microsoft Store app. - -1. Microsoft Store is blocked + Check with your IT or system administrator + Report this problem + Code 0x700704E -2. Try that again + Page could not be loaded. Please try that again + Refresh the page + Code 0x80131500 -3. This place is off-limits + Not sure how you got here, but there's nothing for you here. + Report this problem + Refresh this Page. - -## Manage private store access - -You can manage access to your private store in Microsoft Store for Business and Microsoft Store for Education. - -You can control the set of apps that are available to your employees and students, and not show the full set of applications that are in Microsoft Store. Using the private store with the Microsoft Store for Business and Education, admins can curate the set of apps that are available. - -The private store is a feature in Store for Business that organizations receive during the sign up process. When admins add apps to the private store, all employees in the organization can view and download the apps. Your private store is available as a tab on the [Microsoft Store for Business site](https://businessstore.microsoft.com/store/private-store), and is usually named for your company or organization. Only apps with online licenses can be added to the private store. - -## Related topics - -[Distribute apps using your private store](distribute-apps-from-your-private-store.md)\ -[Configure access to Microsoft Store](/windows/configuration/stop-employees-from-using-microsoft-store) diff --git a/store-for-business/manage-apps-microsoft-store-for-business-overview.md b/store-for-business/manage-apps-microsoft-store-for-business-overview.md deleted file mode 100644 index ead437bd5b..0000000000 --- a/store-for-business/manage-apps-microsoft-store-for-business-overview.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -title: Manage products and services in Microsoft Store for Business (Windows 10) -description: Manage apps, software, devices, products and services in Microsoft Store for Business. -ms.assetid: 2F65D4C3-B02C-41CC-92F0-5D9937228202 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Manage apps in Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Manage products and services in Microsoft Store for Business and Microsoft Store for Education. This includes apps, software, products, devices, and services available under **Products & services**. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Manage access to private store](manage-access-to-private-store.md) | You can manage access to your private store in Store for Business. | -| [App inventory management for Microsoft Store for Business and Education](app-inventory-management-microsoft-store-for-business.md) | You can manage all apps that you've acquired on your **Apps & software** page. | -| [Manage private store settings](manage-private-store-settings.md) | The private store is a feature in Microsoft Store for Business and Education that organizations receive during the sign up process. When admins add apps to the private store, all employees in the organization can view and download the apps. Only online-licensed apps can be distributed from your private store. | -| [Configure MDM provider](configure-mdm-provider-microsoft-store-for-business.md) | For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. Microsoft Store management tool services work with your third-party management tool to manage content. | -| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | In Microsoft Store for Business, you can manage devices for your organization and apply an Autopilot deployment profile to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows based on the Autopilot deployment profile you applied to the device. | -| [Microsoft Store for Business and Education PowerShell module - preview](microsoft-store-for-business-education-powershell-module.md) | Use PowerShell cmdlets to automate basic app license assignment. | -| [Manage software purchased with Microsoft Products and Services agreement in Microsoft Store for Business](manage-mpsa-software-microsoft-store-for-business.md) | Software purchased with the Microsoft Products and Services Agreement (MPSA) can be managed in Microsoft Store for Business and Education. This allows customers to manage online software purchases in one location. | diff --git a/store-for-business/manage-orders-microsoft-store-for-business.md b/store-for-business/manage-orders-microsoft-store-for-business.md deleted file mode 100644 index 22ae3cf389..0000000000 --- a/store-for-business/manage-orders-microsoft-store-for-business.md +++ /dev/null @@ -1,72 +0,0 @@ ---- -title: Manage app orders in Microsoft Store for Business or Microsoft Store for Education (Windows 10) -description: You can view your order history with Microsoft Store for Business or Microsoft Store for Education. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 -ms.reviewer: ---- - -# Manage app orders in Microsoft Store for Business and Education - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -After you've acquired apps, you can review order information and invoices on **Order history**. On this page, you can view invoices, and request refunds. - -**Order history** lists orders in chronological order and shows: - -- Date ordered -- Product name -- Product publisher -- Total cost -- Order status. - -Click to expand an order, and the following info is available: - -- Who purchased the app -- Order number -- Quantity purchased -- Cost breakdown -- Links to view your invoice, buy more, or request a refund - -## Invoices - -Invoices for orders are available approximately 24 hours after your purchase. The link opens a .pdf that you can save for your records. - -## Refund an order - -Refunds work a little differently for free apps, and apps that have a price. In both cases, you must reclaim licenses before requesting a refund. - -**Refunds for free apps** - -For free apps, there isn't really a refund to request -- you're removing the app from your inventory. You must first reclaim any assigned licenses, and then you can remove the app from your organization's inventory. - -**Refunds for apps that have a price** - -There are a few requirements for apps that have a price: - -- **Timing** - Refunds are available for the first 30 days after you place your order. For example, if your order is placed on June 1, you can self-refund through June 30. -- **Available licenses** - You need to have enough available licenses to cover the number of licenses in the order you are refunding. For example, if you purchased 10 copies of an app and you want to request a refund, you must have at least 10 licenses of the app available in your inventory -- those 10 licenses can't be assigned to people in your organization. -- **Whole order refunds only** - You must refund the complete amount of apps in an order. You can't refund a part of an order. For example, if you purchased 10 copies of an app, but later found you only needed 5 copies, you'll need to request a refund for the 10 apps, and then make a separate order for 5 apps. If you have had multiple orders of the same app, you can refund one order but still keep the rest of the inventory. - -**To refund an order** - -Reclaim licenses, and then request a refund. If you haven't assigned licenses, start on step 5. -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then choose **Apps & software**. -3. Find the app you want to refund, click the ellipses under **Actions**, and then choose **View license details**. -4. Select the people who you want to reclaim license from, click the ellipses under **Actions**, and then choose **Reclaim licenses**. -5. Click **Order history**, click the order you want to refund, and click **Refund order**. - -For free apps, the app will be removed from your inventory in **Apps & software**. - -For apps with a price, your payment option will be refunded with the cost of the app, and the app will be removed from your inventory. diff --git a/store-for-business/manage-private-store-settings.md b/store-for-business/manage-private-store-settings.md deleted file mode 100644 index fe4d105828..0000000000 --- a/store-for-business/manage-private-store-settings.md +++ /dev/null @@ -1,115 +0,0 @@ ---- -title: Manage private store settings (Windows 10) -description: The private store is a feature in the Microsoft Store for Business and Microsoft Store for Education that organizations receive during the sign up process. -ms.assetid: 2D501538-0C6E-4408-948A-2BF5B05F7A0C -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.date: 05/24/2023 -ms.localizationpriority: medium ---- - -# Manage private store settings - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -The private store is a feature in Microsoft Store for Business and Education that organizations receive during the sign up process. When admins add apps to the private store, all people in the organization can view and download the apps. Only online-licensed apps can be distributed from your private store. - -The name of your private store is shown on a tab in Microsoft Store app, or on [Microsoft Store for Business](https://businessstore.microsoft.com), or [Microsoft Store for Education](https://educationstore.microsoft.com). - -![Image showing Microsoft Store app with private store tab highlighted.](images/wsfb-wsappprivatestore.png) - -You can change the name of your private store in Microsoft Store. - -## Change private store name -**To change the name of your private store** - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Settings**, click **Distribute**. -3. In the **Private store** section, click **Change**. -4. Type a new display name for your private store, and click **Save**. - - ![Image showing Private store dialog used to change private store display name.](images/wsfb-renameprivatestore.png) - -## Private store collections -You can create collections of apps within your private store. Collections allow you to group or categorize apps - you might want a group of apps for different job functions in your company, or classes in your school. - -**To add a Collection to your private store** - -You can add a collection to your private store from the private store, or from the details page for an app. - -**From private store** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click your private store.
- - ![Image showing private store name on Microsoft Store for Business store UI.](images/msfb-click-private-store.png) -3. Click **Add a Collection**.
- - ![Image showing Add a Collection.](images/msfb-add-collection.png) - -4. Type a name for your collection, and then click **Next**. -5. Add at least one product to your collection, and then click **Done**. You can search for apps and refine results based on the source of the app, or the supported devices. - -> [!NOTE] -> New collections require at least one app, or they will not be created. - -**From app details page** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then click **Products & services**. -3. Under **Apps & software**, choose an app you want to include in a new collection. -4. Under **Private Store Collections**, click **Add a collection**. - - ![Image showing app details page with Add a Collection.](images/msfb-ps-collection-idp.png) - -5. Type a name for your collection, and then click **Next**. -6. Add at least one product to your collection, and then click **Done**. - -Currently, changes to collections will generally show within minutes in the Microsoft Store app on Windows 10. In some cases, it may take up an hour. - -## Edit Collections -If you've already added a Collection to your private store, you can easily add and remove products, or rename the collection. - -**To add or remove products from a collection** -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click your private store.
- - ![Image showing private store name on Microsoft Store for Business store UI.](images/msfb-click-private-store.png) - -3. Click the ellipses next to the collection name, and click **Edit collection**. -4. Add or remove products from the collection, and then click **Done**. - -You can also add an app to a collection from the app details page. - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, and then click **Products & services**. -3. Under **Apps & software**, choose an app you want to include in a new collection. -4. Under **Private Store Collections**, turn on the collection you want to add the app to. - - ![Image showing app details page with Add a Collection.](images/msfb-ps-collection-idp.png) - -## Private store performance -We've recently made performance improvements for changes in the private store. This table includes common actions, and the current estimate for amount of time required for the change. - -| Action | Estimated time | -| ------------------------------------------------------ | -------------- | -| Add a product to the private store
- Apps recently added to your inventory, including line-of-business (LOB) apps and new purchases, will take up to 36 hours to add to the private store. That time begins when the product is purchased, or added to your inventory.
- It will take an additional 36 hours for the product to be searchable in private store, even if you see the app available from the private store tab. | - 15 minutes: available on private store tab
- 36 hours: searchable in private store
- 36 hours: searchable in private store tab | -| Remove a product from private store | - 15 minutes: private store tab
- 36 hours: searchable in private store | -| Accept a new LOB app into your inventory (under **Products & services**) | - 15 minutes: available on private store tab
- 36 hours: searchable in private store | -| Create a new collection | 15 minutes| -| Edit or remove a collection | 15 minutes | -| Create private store tab | 4-6 hours | -| Rename private store tab | 4-6 hours | diff --git a/store-for-business/manage-settings-microsoft-store-for-business.md b/store-for-business/manage-settings-microsoft-store-for-business.md deleted file mode 100644 index 7ae3789d4b..0000000000 --- a/store-for-business/manage-settings-microsoft-store-for-business.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: Manage settings for Microsoft Store for Business and Microsoft Store for Education (Windows 10) -description: You can add users and groups, as well as update some of the settings associated with the Microsoft Entra tenant. -ms.assetid: E3283D77-4DB2-40A9-9479-DDBC33D5A895 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Manage settings for Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -You can add users and groups, as well as update some of the settings associated with the Microsoft Entra tenant. - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Update Microsoft Store for Business and Education account settings](update-microsoft-store-for-business-account-settings.md) | **Billing - Account profile** in Microsoft Store for Business shows information about your organization that you can update. Payment options can be managed on **Billing - Payment methods**, and offline license settings can be managed on **Settings - Shop**. | -| [Manage user accounts in Microsoft Store for Business and Education](manage-users-and-groups-microsoft-store-for-business.md) | Microsoft Store for Business manages permissions with a set of roles. You can [assign these roles to individuals in your organization](roles-and-permissions-microsoft-store-for-business.md) and to groups.| -| [Understand your invoice](billing-understand-your-invoice-msfb.md) | Information on invoices for products and services bought under the Microsoft Customer Agreement.| diff --git a/store-for-business/manage-users-and-groups-microsoft-store-for-business.md b/store-for-business/manage-users-and-groups-microsoft-store-for-business.md deleted file mode 100644 index 792c6de5e0..0000000000 --- a/store-for-business/manage-users-and-groups-microsoft-store-for-business.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: Manage user accounts in Microsoft Store for Business and Microsoft Store for Education (Windows 10) -description: Microsoft Store for Business and Microsoft Store for Education manages permissions with a set of roles. Currently, you can assign these roles to individuals in your organization, but not to groups. -ms.assetid: 5E7FA071-CABD-4ACA-8AAE-F549EFCE922F -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Manage user accounts in Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Microsoft Store for Business and Education manages permissions with a set of roles. Currently, you can [assign these roles to individuals in your organization](roles-and-permissions-microsoft-store-for-business.md), but not to groups. - - - -## Why Microsoft Entra accounts? -For organizations planning to use the private store feature with Store for Business, we recommend that you also configure cloud domain join. This provides a seamless integration between the identity your admin and employees will use to sign in to Windows and Microsoft Store for Business. - -Microsoft Entra ID is an Azure service that provides identity and access management capabilities using the cloud. It is primarily designed to provide this service for cloud- or web-based applications that need to access your local Active Directory information. Microsoft Entra identity and access management includes: - -- Single sign-on to any cloud and on-premises web app. -- Works with multiple platforms and devices. -- Integrate with on-premises Active Directory. - -For more information on Microsoft Entra ID, see [About Office 365 and Microsoft Entra ID](/previous-versions//dn509517(v=technet.10)), and [Intro to Azure: identity and access](https://go.microsoft.com/fwlink/p/?LinkId=708611). - - - -## Add user accounts to your Microsoft Entra directory -If you created a new Microsoft Entra directory when you signed up for Store for Business, you'll have a directory set up with one user account - the global administrator. That global administrator can add user accounts to your Microsoft Entra directory. However, adding user accounts to your Microsoft Entra directory will not give those employees access to Store for Business. You'll need to assign Store for Business roles to your employees. For more information, see [Roles and permissions in the Store for Business.](roles-and-permissions-microsoft-store-for-business.md) - -You can use the [Office 365 admin dashboard](https://portal.office.com/adminportal) or [Azure management portal](https://portal.azure.com/) to add user accounts to your Microsoft Entra directory. If you'll be using Azure management portal, you'll need an active subscription to [Azure management portal](https://go.microsoft.com/fwlink/p/?LinkId=708617). - -For more information, see: -- [Add user accounts using Office 365 admin dashboard](/microsoft-365/admin/add-users) -- [Add user accounts using Azure management portal](/azure/active-directory/fundamentals/add-users-azure-active-directory) diff --git a/store-for-business/microsoft-store-for-business-education-powershell-module.md b/store-for-business/microsoft-store-for-business-education-powershell-module.md deleted file mode 100644 index cc4aa9686d..0000000000 --- a/store-for-business/microsoft-store-for-business-education-powershell-module.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: Microsoft Store for Business and Education PowerShell module - preview -description: Preview version of PowerShell module -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done -ms.date: 05/24/2023 -ms.reviewer: ---- - -# Microsoft Store for Business and Education PowerShell module - preview - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Microsoft Store for Business and Education PowerShell module (preview) is now available on [PowerShell Gallery](https://go.microsoft.com/fwlink/?linkid=853459). - -> [!NOTE] -> This is a preview and not intended for production environments. For production environments, continue to use **Microsoft Store for Business and Education** or your MDM tool to manage licenses. The sample scripts are not supported under any Microsoft standard support program or service. The sample scripts are provided AS IS without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample scripts and documentation remains with you. In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the scripts be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample scripts or documentation, even if Microsoft has been advised of the possibility of such damages. - -You can use the PowerShell module to: -- View items you've purchased - shown in **Products & services** -- Manage licenses - assigning and removing -- Perform bulk operations with .csv files - automates license management for customers with larger numbers of licenses - ->[!NOTE] ->Assigning apps to groups is not supported via this module. Instead, we recommend leveraging the Microsoft Entra ID or [Microsoft Graph PowerShell](/powershell/microsoftgraph/overview) Modules to save members of a group to a CSV file and follow instructions below on how to use CSV file to manage assignments. - -## Requirements -To use the Microsoft Store for Business and Education PowerShell module, you'll need: -- Administrator permission for the device -- Admin role for Microsoft Store for Business and Education - - -## Get started with Microsoft Store for Business and Education PowerShell module -All of the **Microsoft Store for Business and Education** PowerShell cmdlets follow the *Verb*-MSStore*Noun* pattern to clearly indicate that they work with **Microsoft Store for Business and Education** PowerShell module. You will need to install the module on your Windows 10 device once and then import it into each PowerShell session you start. - -## Install Microsoft Store for Business and Education PowerShell module -> [!NOTE] -> Installing **Microsoft Store for Business and Education** PowerShell model using **PowerShellGet** requires [Windows Management Framework 5.0](https://www.microsoft.com/download/details.aspx?id=54616). The framework is included with Windows 10 by default). - -To install **Microsoft Store for Business and Education PowerShell** with PowerShellGet, run this command: - -```powershell -# Install the Microsoft Store for Business and Education PowerShell module from PowerShell Gallery - -Install-Module -Name MSStore -``` - -## Import Microsoft Store for Business and Education PowerShell module into the PowerShell session -Once you install the module on your Windows 10 device, you will need to then import it into each PowerShell session you start. - -```powershell -# Import the MSStore module into this session - -Import-Module -Name MSStore -``` - -Next, authorize the module to call **Microsoft Store for Business and Education** on your behalf. This step is required once, per user of the PowerShell module. - -To authorize the PowerShell module, run this command. You'll need to sign-in with your work or school account, and authorize the module to access your tenant. - -```powershell -# Grant MSStore Access to your Microsoft Store for Business and Education - -Grant-MSStoreClientAppAccess -``` -You will be prompted to sign in with your work or school account and then to authorize the PowerShell Module to access your **Microsoft Store for Business and Education** account. Once the module has been imported into the current PowerShell session and authorized to call into your **Microsoft Store for Business and Education** account, Microsoft Graph PowerShell cmdlets are loaded and ready to be used. - -## View items in Products and Services -Service management should encounter no breaking changes as a result of the separation of Azure Service Management and **Microsoft Store for Business and Education PowerShell** preview. - -```powershell -# View items in inventory (Apps & software) - -Get-MSStoreInventory -``` - ->[!TIP] ->**Get-MSStoreInventory** won't return the product name for line-of-business apps. To get the product ID and SKU for a line-of-business app: -> ->1. Sign in to [Microsoft Store for Business](https://go.microsoft.com/fwlink/p/?LinkId=691845) or [Microsoft Store for Education](https://businessstore.microsoft.com/). ->2. Click **Manage** and then choose **Apps & software**. ->3. Click the line-of-business app. The URL of the page will contain the product ID and SKU as part of the URL. For example: ->![Url after apps/ is product id and next is SKU.](images/lob-sku.png) - -## View people assigned to a product -Most items in **Products and Services** in **Microsoft Store for Business and Education** need to be assigned to people in your org. You can view the people in your org assigned to a specific product by using these commands: - -```powershell -# View products assigned to people - -Get-MSStoreSeatAssignments -ProductId 9NBLGGH4R2R6 -SkuId 0016 -``` - -> [!Important] -> Microsoft Store for Business and Education identifies Minecraft: Education Edition license types using a combination of Product ID and SKU ID. To manage license assignments for your Minecraft: Education Edition, you need to specify Product and SKU IDs for the licenses you want to manage in the cmdlet. The following table lists the Product and SKU IDs. - - -| License Type | Product ID | SKU ID | -| ------------ | -----------| -------| -| Purchased through Microsoft Store for Business and Education with a credit card | CFQ7TTC0K5DR | 0001 | -| Purchased through Microsoft Store for Business and Education with an invoice | CFQ7TTC0K5DR | 0004 | -| Purchased through Microsoft Volume Licensing Agreement | CFQ7TTC0K5DR | 0002 | -| Acquired through Windows 10 device promotion | CFQ7TTC0K5DR | 0005 | - -## Assign or reclaim products -Once you have enumerated items in **Products and Service**, you can assign or reclaim licenses to and from people in your org. - -These commands assign a product to a user and then reclaim it. - -```powershell -# Assign Product (Product ID and SKU ID combination) to a User (user@host.com) - -Add-MSStoreSeatAssignment -ProductId 9NBLGGH4R2R6 -SkuId 0016 -Username 'user@myorganization.onmicrosoft.com' - -# Reclaim a product (Product ID and SKU ID combination) from a User (user@host.com) - -Remove-MSStoreSeatAssignment -ProductId 9NBLGGH4R2R6 -SkuId 0016 -Username 'user@myorganization.onmicrosoft.com' -``` - -## Assign or reclaim a product with a .csv file -You can also use the PowerShell module to perform bulk operations on items in **Product and Services**. You'll need a .CSV file with at least one column for "Principal Names" (for example, user@host.com). You can create such a CSV using the AzureAD PowerShell Module. - -**To assign or reclaim seats in bulk:** - -```powershell -# Assign Product (Product ID and SKU ID combination) to a User (user@host.com) - -Add-MSStoreSeatAssignments -ProductId 9NBLGGH4R2R6 -SkuId 0016 -PathToCsv C:\People.csv -ColumnName UserPrincipalName - -# Reclaim a product (Product ID and SKU ID combination) from a User (user@host.com) - -Remove-MSStoreSeatAssignments -ProductId 9NBLGGH4R2R6 -SkuId 0016 -PathToCsv C:\People.csv -ColumnName UserPrincipalName -``` - -## Uninstall Microsoft Store for Business and Education PowerShell module -You can remove **Microsoft Store for Business and Education PowerShell** from your computer by running the following PowerShell Command. - -```powershell -# Uninstall the MSStore Module - -Get-InstalledModule -Name "MSStore" -RequiredVersion 1.0 | Uninstall-Module -``` diff --git a/store-for-business/microsoft-store-for-business-overview.md b/store-for-business/microsoft-store-for-business-overview.md deleted file mode 100644 index c0e3db882e..0000000000 --- a/store-for-business/microsoft-store-for-business-overview.md +++ /dev/null @@ -1,389 +0,0 @@ ---- -title: Microsoft Store for Business and Microsoft Store for Education overview (Windows 10) -description: With Microsoft Store for Business and Microsoft Store for Education, organizations and schools can make volume purchases of Windows apps. -ms.assetid: 9DA71F6B-654D-4121-9A40-D473CC654A1C -ms.reviewer: -ms.pagetype: store -ms.mktglfcycl: manage -ms.sitesec: library -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Microsoft Store for Business and Microsoft Store for Education overview - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -> [!NOTE] -> As of April 14th, 2021, only free apps are available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md). - -Designed for organizations, Microsoft Store for Business and Microsoft Store for Education give IT decision makers and administrators in businesses or schools a flexible way to find, acquire, manage, and distribute free and paid apps in select markets to Windows 10 devices in volume. IT administrators can manage Microsoft Store apps and private line-of-business apps in one inventory, plus assign and re-use licenses as needed. You can choose the best distribution method for your organization: directly assign apps to individuals and teams, publish apps to private pages in Microsoft Store, or connect with management solutions for more options. There will be no support for Microsoft Store for Business and Education on Windows 11. - -> [!IMPORTANT] -> Customers who are in the Office 365 GCC environment or are eligible to buy with government pricing cannot use Microsoft Store for Business. - -## Features -Organizations or schools of any size can benefit from using Microsoft Store for Business or Microsoft Store for Education: - -- **Scales to fit the size of your business** - For smaller businesses, with Microsoft Entra accounts or Office 365 accounts and Windows 10 devices, you can quickly have an end-to-end process for acquiring and distributing content using the Store for Business. For larger businesses, all the capabilities of the Store for Business are available to you, or you can integrate Microsoft Store for Business with management tools, for greater control over access to apps and app updates. You can use existing work or school accounts. -- **Bulk app acquisition** - Acquire apps in volume from Microsoft Store for Business. -- **Centralized management** – Microsoft Store provides centralized management for inventory, billing, permissions, and order history. You can use Microsoft Store to view, manage and distribute items purchased from: - - **Microsoft Store for Business** – Apps acquired from Microsoft Store for Business - - **Microsoft Store for Education** – Apps acquired from Microsoft Store for Education - - **Office 365** – Subscriptions - - **Volume licensing** - Apps purchased with volume licensing -- **Private store** - Create a private store for your business that's easily available from any Windows 10 device. Your private store is available from Microsoft Store on Windows 10, or with a browser on the Web. People in your organization can download apps from your organization's private store on Windows 10 devices. -- **Flexible distribution options** - Flexible options for distributing content and apps to your employee devices: - - Distribute through Microsoft Store services. You can assign apps to individual employees, or make apps available to all employees in your private store. - - Use a management tool from Microsoft, or a 3rd-party tool for advanced distribution and management functions, or for managing images. - - Offline licensing model allows you to distribute apps without connecting to Store services, and for managing images. -- **Line-of-business apps** - Privately add and distribute your internal line-of-business apps using any of the distribution options. -- **App license management**: Admins can reclaim and reuse app licenses. Online and offline licenses allow you to customize how you decide to deploy apps. -- **Up-to-date apps** - Microsoft Store manages the update process for apps with online licenses. Apps are automatically updated so you are always current with the most recent software updates and product features. Store for Business apps also uninstall cleanly, without leaving behind extra files, for times when you need to switch apps for specific employees. -- **Office app launcher** Office apps while working with Microsoft Store for Business. -- **Find a partner** – Search and find a Microsoft Partner who can assist you with Microsoft solutions for your business. - -## Prerequisites - -You'll need this software to work with Store for Business and Education. - -### Required - -- Admins working with Store for Business and Education need a browser compatible with Microsoft Store running on a PC or mobile device. Supported browsers include: Internet Explorer 10 or later, or current versions of Microsoft Edge, Chrome or Firefox. JavaScript must be supported and enabled. -- Employees using apps from Store for Business and Education need at least Windows 10, version 1511 running on a PC or mobile device. - -Microsoft Entra accounts for your employees: - -- Admins need Microsoft Entra accounts to sign up for Store for Business and Education, and then to sign in, get apps, distribute apps, and manage app licenses. You can sign up for Microsoft Entra accounts as part of signing up for Store for Business and Education. -- Employees need Microsoft Entra account when they access Store for Business content from Windows devices. -- If you use a management tool to distribute and manage online-licensed apps, all employees will need a Microsoft Entra account -- For offline-licensed apps, Microsoft Entra accounts are not required for employees. -- Admins can add or remove user accounts in the Microsoft 365 admin center, even if you don't have an Office 365 subscription. You can access the Office 365 admin portal directly from the Store for Business and Education. - -For more information on Microsoft Entra ID, see [About Office 365 and Microsoft Entra ID](/previous-versions//dn509517(v=technet.10)), and [Intro to Azure: identity and access](https://go.microsoft.com/fwlink/p/?LinkId=708611). - -### Optional - -While not required, you can use a management tool to distribute and manage apps. Using a management tool allows you to distribute content, scope app availability, and control when app updates are installed. This might make sense for larger organizations that already use a management tool. A couple of things to note about management tools: - -- Need to integrate with Windows 10 management framework and Microsoft Entra ID. -- Need to sync with the Store for Business inventory to distribute apps. - -## How does the Store for Business and Education work? - -## Sign up! - -The first step for getting your organization started with Store for Business and Education is signing up. Sign up using an existing account (the same one you use for Office 365, Dynamics 365, Intune, Azure, etc.) or we'll quickly create an account for you. You must be a Global Administrator for your organization. - -## Set up - -After your admin signs up for the Store for Business and Education, they can assign roles to other employees in your company or school. The admin needs Microsoft Entra user Admin permissions to assign Microsoft Store for Business and Education roles. These are the roles and their permissions. - -| Permission | Account settings | Acquire apps | Distribute apps | Device Guard signing | -| ---------- | ---------------- | ------------ | --------------- | -------------------- | -| Admin | ✔️ | ✔️ | ✔️ | | -| Purchaser | | ✔️ | ✔️ | | -| Device Guard signer | | | | ✔️ | -| Basic purchaser | | ✔️ | ✔️ | | - -> [!NOTE] -> Currently, the Basic purchaser role is only available for schools using Microsoft Store for Education. For more information, see [Microsoft Store for Education permissions](/education/windows/education-scenarios-store-for-business?toc=%2fmicrosoft-store%2feducation%2ftoc.json#manage-domain-settings). - -In some cases, admins will need to add Microsoft Entra accounts for their employees. For more information, see [Manage user accounts and groups](manage-users-and-groups-microsoft-store-for-business.md). - -Also, if your organization plans to use a management tool, you'll need to configure your management tool to sync with Store for Business and Education. - -## Get apps and content - -Once signed in to the Microsoft Store, you can browse and search for all products in the Store for Business and Education catalog. Some apps are free, and some apps charge a price. We're continuing to add more paid apps to the Store for Business and Education. Check back if you don't see the app that you're looking for. Currently, you can pay for apps with a credit card, and some items can be paid for with an invoice. We'll be adding more payment options over time. - -**App types** - These app types are supported in the Store for Business and Education: - -- Universal Windows Platform apps -- Universal Windows apps, by device: Phone, Surface Hub, IOT devices, HoloLens - -Apps purchased from the Store for Business and Education only work on Windows 10 devices. - -Line-of-business (LOB) apps are also supported through Microsoft Store. You can invite IT developers or ISVs to be LOB publishers for your organization. This allows them to submit apps via the developer center that are only available to your organization through Store for Business and Education. These apps can be distributed using the distribution methods discussed in this topic. For more information, see [Working with Line-of-Business apps](working-with-line-of-business-apps.md). - -**App licensing model** - - Store for Business and Education supports two license options for apps: online and offline. **Online** licensing is the default licensing model and is similar to the licensing model for Microsoft Store. Online licensed apps require users and devices to connect to Microsoft Store services to acquire an app and its license. **Offline** licensing is a new licensing option for Windows 10. With offline licenses, organizations can cache apps and their licenses to deploy within their network. ISVs or devs can opt in their apps for offline licensing when they submit them to the developer center. - -For more information, see [Apps in Microsoft Store for Business](apps-in-microsoft-store-for-business.md#licensing-model). - -## Distribute apps and content - -App distribution is handled through two channels, either through the Microsoft Store for Business, or using a management tool. You can use either, or both distribution methods in your organization. - -**Distribute with Store for Business and Education**: -- Email link – After purchasing an app, Admins can send employees a link in an email message. Employees can click the link to install the app. -- Curate private store for all employees – A private store can include content you've purchased from Microsoft Store for Business, and your line-of-business apps that you've submitted to Microsoft Store for Business. Apps in your private store are available to all of your employees. They can browse the private store and install apps when needed. -- To use the options above users must be signed in with a Microsoft Entra account on a Windows 10 device. Licenses are assigned as individuals install apps. - -**Using a management tool** – For larger organizations that want a greater level of control over how apps are distributed and managed, a management tools provides other distribution options: -- Scoped content distribution – Ability to scope content distribution to specific groups of employees. -- Install apps for employees – Employees are not responsible for installing apps. Management tool installs apps for employees. - -Management tools can synchronize content that has been acquired in the Store for Business. If an offline application has been purchased this will also include the app package, license and metadata for the app (like, icons, count, or localized product descriptions). Using the metadata, management tools can enable portals or apps as a destination for employees to acquire apps. - -For more information, see [Distribute apps to your employees from Microsoft Store for Business](distribute-apps-to-your-employees-microsoft-store-for-business.md). - -## Manage Microsoft Store for Business settings and content - -Once you are signed up with the Business store and have purchased apps, Admins can manage Store for Business settings and inventory. - -**Manage Microsoft Store for Business settings** -- Assign and change roles for employees or groups -- Device Guard signing -- Register a management server to deploy and install content -- Manage relationships with LOB publishers -- Manage offline licenses -- Update the name of your private store - -**Manage inventory** -- Assign app licenses to employees -- Reclaim and reassign app licenses -- Manage app updates for all apps, or customize updates for each app. Online apps will automatically update from the Store. Offline apps can be updated using a management server. -- Download apps for offline installs - -For more information, see [Manage settings in the Store for Business](manage-settings-microsoft-store-for-business.md) and [Manage apps](manage-apps-microsoft-store-for-business-overview.md). - -## Supported markets - -Store for Business and Education is currently available in these markets. - -### Support for free and paid products - -- Afghanistan -- Algeria -- Andorra -- Angola -- Anguilla -- Antigua and Barbuda -- Argentina -- Australia -- Austria -- Bahamas -- Bahrain -- Bangladesh -- Barbados -- Belgium -- Belize -- Bermuda -- Benin -- Bhutan -- Bolivia -- Bonaire -- Botswana -- Brunei Darussalam -- Bulgaria -- Burundi -- Cambodia -- Cameroon -- Canada -- Cayman Islands -- Chile -- Colombia -- Comoros -- Costa Rica -- Côte D'ivoire -- Croatia -- Curçao -- Cyprus -- Czech Republic -- Denmark -- Dominican Republic -- Ecuador -- Egypt -- El Salvador -- Estonia -- Ethiopia -- Faroe Islands -- Fiji -- Finland -- France -- French Guiana -- French Polynesia -- Germany -- Ghana -- Greece -- Greenland -- Guadeloupe -- Guatemala -- Honduras -- Hong Kong SAR -- Hungary -- Iceland -- Indonesia -- Iraq -- Ireland -- Israel -- Italy -- Jamaica -- Japan -- Jersey -- Jordan -- Kenya -- Kuwait -- Laos -- Latvia -- Lebanon -- Libya -- Liechtenstein -- Lithuania -- Luxembourg -- Madagascar -- Malawi -- Malaysia -- Maldives -- Mali -- Malta -- Marshall Islands -- Martinique -- Mauritius -- Mayotte -- Mexico -- Mongolia -- Montenegro -- Morocco -- Mozambique -- Myanamar -- Namibia -- Nepal -- Netherlands -- New Caledonia -- New Zealand -- Nicaragua -- Nigeria -- North Macedonia -- Norway -- Oman -- Pakistan -- Palestinian Authority -- Panama -- Papua New Guinea -- Paraguay -- Peru -- Philippines -- Poland -- Portugal -- Qatar -- Republic of Cabo Verde -- Reunion -- Romania -- Rwanda -- Saint Kitts and Nevis -- Saint Lucia -- Saint Martin -- Saint Vincent and the Grenadines -- San marino -- Saudi Arabia -- Senegal -- Serbia -- Seychelles -- Singapore -- Sint Maarten -- Slovakia -- Slovenia -- South Africa -- Spain -- Sri Lanka -- Suriname -- Sweden -- Switzerland -- Tanzania -- Thailand -- Timor-Leste -- Togo -- Tonga -- Trinidad and Tobago -- Tunisia -- Türkiye -- Turks and Caicos Islands -- Uganda -- United Arab Emirates -- United Kingdom -- United States -- Uruguay -- Vatican City -- Viet Nam -- Virgin Islands, U.S. -- Zambia -- Zimbabwe - - -### Support for free apps -Customers in these markets can use Microsoft Store for Business and Education to acquire free apps: -- Russia - -### Support for free apps and Minecraft: Education Edition -Customers in these markets can use Microsoft Store for Business and Education to acquire free apps and Minecraft: Education Edition: -- Albania -- Aremenia -- Azerbaijan -- Belarus -- Bosnia and Herzegovina -- Brazil -- Georgia -- India -- Isle of Man -- Kazakhstan -- Korea -- Monaco -- Republic of Moldova -- Taiwan -- Tajikistan -- Ukraine - -### Support to only manage products -Customers in these markets can use Microsoft Store for Business and Education only to manage products that they've purchased from other channels. For example, they might have purchased products through Volume Licensing Service Center. However, they can't purchase apps directly from Microsoft Store for Business and Education. -- Puerto Rico - -This table summarize what customers can purchase, depending on which Microsoft Store they are using. - -| Store | Free apps | Minecraft: Education Edition | -| ----- | --------- | ---------------------------- | -| Microsoft Store for Business | supported | not supported | -| Microsoft Store for Education | supported | supported; invoice payment required | - -> [!NOTE] -> **Microsoft Store for Education customers with support for free apps and Minecraft: Education Edition** -> - Admins can acquire free apps from **Microsoft Store for Education**. -> - Admins need to use an invoice to purchase **Minecraft: Education Edition**. For more information, see [Invoice payment option](/education/windows/school-get-minecraft#invoices). -> - Teachers, or people with the Basic Purchaser role, can acquire free apps, but not **Minecraft: Education Edition**. - -## Privacy notice - -Store for Business and Education services get names and email addresses of people in your organization from Microsoft Entra ID. This information is needed for these admin functions: -- Granting and managing permissions -- Managing app licenses -- Distributing apps to people (names appear in a list that admins can select from) - -Store for Business and Education does not save names, or email addresses. - -Your use of Store for Business and Education is also governed by the [Microsoft Store for Business and Education Services Agreement](https://businessstore.microsoft.com/servicesagreement). - -Information sent to Store for Business and Education is subject to the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement/). - -## ISVs and Store for Business and Education - -Developers in your organization, or ISVs can create content specific to your organization. In Store for Business and Education, we call these line-of-business (LOB) apps, and the devs that create them are LOB publishers. The process looks like this: -- Admin invites devs to be LOB publishers for your organization. These devs can be internal devs, or external ISVs. -- LOB publishers accept the invitation, develop apps, and submits the app to the Windows Dev Center. LOB publishers use Enterprise associations when submitting the app to make the app exclusive to your organization. -- Admin adds the app to Microsoft Store for Business or Microsoft Store for Education inventory. - -Once the app is in inventory, admins can choose how to distribute the app. ISVs creating apps through the dev center can make their apps available in Store for Business and Education. ISVs can opt-in their apps to make them available for offline licensing. Apps purchased in Store for Business and Education will work only on Windows 10. - -For more information on line-of-business apps, see [Working with Line-of-Business apps](working-with-line-of-business-apps.md). diff --git a/store-for-business/notifications-microsoft-store-business.md b/store-for-business/notifications-microsoft-store-business.md deleted file mode 100644 index e1edf848cc..0000000000 --- a/store-for-business/notifications-microsoft-store-business.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -title: Notifications in Microsoft Store for Business and Education (Windows 10) -description: Notifications alert you to issues or outages with Microsoft Store for Business and Education. -keywords: notifications, alerts -ms.assetid: -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Notifications in Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Microsoft Store for Business and Microsoft Store for Education use a set of notifications to alert admins if there is an issue or outage with Microsoft Store. - -## Notifications for admins - -| Store area | Notification message | Customer impact | -| ---------- | -------------------- | --------------- | -| General | We're on it. Something happened on our end with the Store. Waiting a bit might help. | You might be unable to sign in. There might be an intermittent Microsoft Entra outage. | -| Manage | We're on it. Something happened on our end with management for apps and software. We're working to fix the problem. | You might be unable to manage inventory, including viewing inventory, distributing apps, assigning licenses, or viewing and managing order history. | -| Shop | We're on it. Something happened on our end with purchasing. We're working to fix the problem. | Shop might not be available. You might not be able to purchase new, or additional licenses. | -| Private store | We're on it. Something happened on our end with your organization's private store. People in your organization can't download apps right now. We're working to fix the problem. | People in your organization might not be able to view the private store, or get apps. | -| Acquisition and licensing | We're on it. People in your org might not be able to install or use certain apps. We're working to fix the problem. | People in your org might not be able to claim a license from your private store. | -| Partner | We're on it. Something happened on our end with Find a Partner. We're working to fix the problem. | You might not be able to search for a partner. | diff --git a/store-for-business/payment-methods.md b/store-for-business/payment-methods.md deleted file mode 100644 index 0e5b708958..0000000000 --- a/store-for-business/payment-methods.md +++ /dev/null @@ -1,59 +0,0 @@ ---- -title: Payment methods for commercial customers -description: Learn what payment methods are available in Store for Business and M365 admin center -keywords: payment method, credit card, debit card, add credit card, update payment method -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 -ms.reviewer: ---- - -# Payment methods - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -You can purchase products and services from Microsoft Store for Business using your credit card. You can enter your credit card information on **Payment methods**, or when you purchase an app. We currently accept these credit cards: -- VISA -- MasterCard -- Discover -- American Express -- Japan Commercial Bureau (JCB) - -> [!NOTE] -> Not all cards available in all countries/regions. When you add a payment option, Microsoft Store for Business shows which cards are available in your region. - -## Add a payment method - -**To add a new payment option** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Store for Education](https://educationstore.microsoft.com). -2. Select **Manage**, select **Billing & payments**, and then select **Payments methods**. -3. Select **Add a payment options**, and then select the type of credit card that you want to add. -4. Add information to required fields, and then select **Add**. - -Once you select **Add**, the information you provided will be validated with a test authorization transaction and, if validated, the payment option will be added to your list of available payment options. Otherwise, you will be prompted for additional information or notified if there are any issues. - -> [!NOTE] -> When adding credit or debit cards, you may be prompted to enter a CVV. The CVV is only used for verification purposes and is not stored in our systems after validation. - -## Edit payment method -**To update a payment option** - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com) or [Store for Education](https://educationstore.microsoft.com). -2. Click **Manage**, click **Billing & payments**, and then click **Payments methods**. -3. Select the payment option that you want to update, select the ellipses, and then choose **Edit payment method**. -4. Enter any updated information in the appropriate fields, and then se;ect**Save**. - -Once you click **Update**, the information you provided will be validated with a test authorization transaction and, if validated, the payment option will be added to your list of available payment options. Otherwise, you will be prompted for additional information or notified if there are any problems. - -> [!NOTE] -> Certain actions, like updating or adding a payment option, require temporary "test authorization" transactions to validate the payment option. These may appear on your statement as $0.00 authorizations or as small pending transactions. These transactions are temporary and should not impact your account unless you make several changes in a short period of time, or have a low balance. diff --git a/store-for-business/prerequisites-microsoft-store-for-business.md b/store-for-business/prerequisites-microsoft-store-for-business.md deleted file mode 100644 index ac4b271b5d..0000000000 --- a/store-for-business/prerequisites-microsoft-store-for-business.md +++ /dev/null @@ -1,74 +0,0 @@ ---- -title: Prerequisites for Microsoft Store for Business and Education (Windows 10) -description: There are a few prerequisites for using Microsoft Store for Business or Microsoft Store for Education. -ms.assetid: CEBC6870-FFDD-48AD-8650-8B0DC6B2651D -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Prerequisites for Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -> [!NOTE] -> As of April 14th, 2021, only free apps are available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md). - -> [!IMPORTANT] -> Customers who are in the Office 365 GCC environment or are eligible to buy with government pricing cannot use Microsoft Store for Business. - -There are a few prerequisites for using Microsoft Store for Business or Microsoft Store for Education. - -## Prerequisites - -You'll need this software to work with Microsoft Store for Business or Education. - -### Required - -- IT Pros that are administering Microsoft Store for Business and Education need a browser compatible with Microsoft Store for Business and Education running on a PC or mobile device. Supported browsers include: Internet Explorer 10 or later, Microsoft Edge, or current versions of Chrome or Firefox. Javascript needs to be supported and enabled. -- Employees using apps from Microsoft Store for Business and Education need at least Windows 10, version 1511 running on a PC or mobile device. - -Microsoft Entra ID or Office 365 accounts for your employees: -- IT Pros need Microsoft Entra ID or Office 365 accounts to sign up for Microsoft Store for Business and Education, and then to sign in, get apps, distribute apps, and manage app licenses. -- Employees need Microsoft Entra accounts when they access Microsoft Store for Business or Education content from Windows-based devices. -- If you use a management tool to distribute and manage online-licensed apps, all employees will need a Microsoft Entra account. - -For more information on Microsoft Entra ID, see [About Office 365 and Microsoft Entra ID](/previous-versions//dn509517(v=technet.10)), and [Intro to Azure: identity and access](https://go.microsoft.com/fwlink/p/?LinkId=708611). - -### Optional - -While not required, you can use a management tool to distribute and manage apps. Using a management tool allows you to distribute content, scope app availability, and control when app updates are installed. This might make sense for larger organizations that already use a management tool. If you're considering using management tools, check with the management tool vendor to see if they support Microsoft Store for Business and Education. The management tool will need to: - -- Integrate with the Windows 10 management framework and Microsoft Entra ID. -- Sync with Microsoft Store for Business and Education inventory to distribute apps. - -## Proxy configuration - -If your organization restricts computers on your network from connecting to the Internet, there is a set of URLs that need to be available for devices to use Microsoft Store. Some of the Microsoft Store features use Store services. Devices using Microsoft Store – either to acquire, install, or update apps – will need access to these URLs. If you use a proxy server to block traffic, your configuration needs to allow these URLs: - -- `login.live.com` -- `login.windows.net` -- `account.live.com` -- `clientconfig.passport.net` -- `windowsphone.com` -- `*.wns.windows.com` -- `*.microsoft.com` -- `*.s-microsoft.com` -- `www.msftncsi.com` (prior to Windows 10, version 1607) -- `www.msftconnecttest.com/connecttest.txt` (replaces `www.msftncsi.com` starting with Windows 10, version 1607) - -Store for Business requires Microsoft Windows HTTP Services (WinHTTP) to install, or update apps. diff --git a/store-for-business/release-history-microsoft-store-business-education.md b/store-for-business/release-history-microsoft-store-business-education.md deleted file mode 100644 index 368df86b94..0000000000 --- a/store-for-business/release-history-microsoft-store-business-education.md +++ /dev/null @@ -1,125 +0,0 @@ ---- -title: Microsoft Store for Business and Education release history -description: Know the release history of Microsoft Store for Business and Microsoft Store for Education. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.date: 01/11/2024 -ms.reviewer: ---- - -# Microsoft Store for Business and Education release history - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). - -Because Microsoft Store for Business and Education will be retired, we no longer release new and improved features. Here's a summary of new or updated features in previous releases. - -Looking for info on the latest release? Check out [What's new in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) - -## January 2024 - -**Removal of private store capability from Microsoft Store for Business and Education** - -The private store tab and associated functionality was removed from the Microsoft Store for Business and Education portal. This includes the ability to add apps to private groups and to download and install apps from the private store. - -We recommend customers use the [Private app repository, Windows Package Manager, and Company Portal app](/windows/application-management/private-app-repository-mdm-company-portal-windows-11) to provide a private app repository within their organization. - -## May 2023 - -**Removal of Microsoft Store for Business tab from Microsoft Store app on Windows 10 PCs** - -The Microsoft Store for Business tab was removed from the Microsoft Store app on Windows 10. The Microsoft Store for Business tab is still available on HoloLens devices. - -Users on Windows 10 PCs can no longer do the following tasks: - -- see Line of Business (LOB) products listed in the Microsoft Store for Business tab -- acquire or install [online apps](/mem/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business#online-and-offline-apps) -- assign licenses for existing [online apps](/mem/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business#online-and-offline-apps) using the Store for Business portal or Store for Business app - -[Offline app](/mem/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business#online-and-offline-apps) distribution and licensing scenarios aren't impacted by this change. - -We recommend that you add your apps through the new Microsoft Store app experience in Intune. If an app isn’t available in the Microsoft Store, you must retrieve an app package from the vendor and install it as an LOB app or Win32 app. For instructions, read the following articles: - -- [Add Microsoft Store apps to Microsoft Intune](/mem/intune/apps/store-apps-microsoft) -- [Add a Windows line-of-business app to Microsoft Intune](/mem/intune/apps/lob-apps-windows) -- [Add, assign, and monitor a Win32 app in Microsoft Intune](/mem/intune/apps/apps-win32-add) - -Follow the [Intune Customer Success blog](https://aka.ms/IntuneCustomerSuccess) where we will publish more information about this change. - -## April 2023 - -- **Tab removed from Microsoft Store apps on Windows 11 PCs** – The Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. [Get more info](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed) - -## October 2018 - -- **Use security groups with Private store apps** - On the details page for apps in your private store, you can set Private store availability. This allows you to choose which security groups can see an app in the private store. [Get more info](app-inventory-management-microsoft-store-for-business.md) - -## September 2018 - -- **Performance improvements** - With updates and improvements in the private store, most changes, like adding an app, will take fifteen minutes or less. [Get more info](/microsoft-store/manage-private-store-settings#private-store-performance) - -## August 2018 -- **App requests** - People in your organization can make requests for apps that they need. hey can also request them on behalf of other people. Admins review requests and can decide on purchases. [Get more info](./acquire-apps-microsoft-store-for-business.md#allow-app-requests) - -## July 2018 - -- Bug fixes and performance improvements. - -## June 2018 - -- **Change order within private store collection** - Continuing our focus on improvements for private store, now you can customize the order of products in each private store collection. -- **Performance improvements in private store** - We continue to work on performance improvements in the private store. Now, most products new to your inventory are available in your private store within 15 minutes of adding them. [Get more info](./manage-private-store-settings.md#private-store-performance) - -## May 2018 - -- **Immersive Reader app available in Microsoft Store for Education** - This app is a free tool that uses proven techniques to improve reading and writing for people regardless of their age or ability. You can add the app to your private store, so students can easily install and use it. - -## April 2018 - -- **Assign apps to larger groups** - We're making it easier for admins to assign apps to groups of people. Admins can assign licenses to groups of any size, and include subgroups within those groups. We'll figure out who's in those groups, and assign licenses to people in the groups (skipping people who already have licenses). Along the way, we'll let you know how many licenses are needed, and provide an estimate on the time required to assign licenses. -- **Change collection order in private store** - Private store collections make it easy for groups of people to find the apps that they need. Now, you can customize the order of your private store collections. -- **Office 365 subscription management** - We know that sometimes customers need to cancel a subscription. While we don't want to lose a customer, we want the process for managing subscriptions to be easy. Now, you can delete your Office 365 subscription without calling Support. From Microsoft Store for Business and Education, you can request to delete an Office 365 subscription. We'll wait three days before permanently deleting the subscription. In case of a mistake, customers are welcome to reactivate subscriptions during the three-day period. - -## March 2018 - -- **Performance improvements in private store** - We've made it significantly faster for you to update the private store. Many changes to the private store are available immediately after you make them. [Get more info](./manage-private-store-settings.md#private-store-performance) -- **Private store collection updates** - We've made it easier to find apps when creating private store collections – now you can search and filter results. - [Get more info](./manage-private-store-settings.md#private-store-collections) -- **Manage Skype Communication credits** - Office 365 customers that own Skype Communication Credits can now see and manage them in Microsoft Store for Business. You can view your account, add funds to your account, and manage auto-recharge settings. -- **Upgrade Microsoft 365 trial subscription** - Customers with Office 365 can upgrade their subscription and automatically re-assign their user licenses over to a new target subscription. For example, you could upgrade your Office 365 for business subscription to a Microsoft 365 for business subscription. - -## January and February 2018 - -- **One place for apps, software, and subscriptions** - The new **Products & services** page in Microsoft Store for Business and Education gives customers a single place to manage all products and services. -- **Create collections of apps in your private store** - Use **collections** to customize your private store. Collections allow you to create groups of apps that are commonly used in your organization or school -- you might create a collection for a Finance department, or a 6th-grade class. [Get more info](./manage-private-store-settings.md#private-store-collections) -- **Upgrade Office 365 trial subscription** - Customers with Office 365 trials can now transition their trial to a paid subscription in Microsoft Store for Business. This works for trials you acquired from Microsoft Store for Business, or Office Admin Portal. -- **Supporting Microsoft Product and Services Agreement customers** - If you are purchasing under the Microsoft Products and Services Agreement (MPSA), you can use Microsoft Store for Business. Here you will find access to Products & Services purchased, Downloads & Keys, Software Assurance benefits, Order history, and Agreement details. -- **Microsoft Product and Services Agreement customers can invite people to take roles** - MPSA admins can invite people to take Microsoft Store for Business roles even if the person is not in their tenant. You provide an email address when you assign the role, and we'll add the account to your tenant and assign the role. - -## December 2017 - -- Bug fixes and performance improvements. - -## November 2017 - -- **Export list of Minecraft: Education Edition users** - Admins and teachers can now export a list of users who have Minecraft: Education Edition licenses assigned to them. Click **Export users**, and Store for Education creates an Excel spreadsheet for you, and saves it as a .csv file. - -## October 2017 - -- Bug fixes and performance improvements. - -## September 2017 - -- **Manage Windows device deployment with Windows Autopilot Deployment** - In Microsoft Store for Business, you can manage devices for your organization and apply an Autopilot deployment profile to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows, based on the Autopilot deployment profile you applied to the device. [Get more info](add-profile-to-devices.md) -- **Request an app** - People in your organization can request additional licenses for apps in your private store, and then Admins or Purchasers can make the purchases. [Get more info](./acquire-apps-microsoft-store-for-business.md#acquire-apps) -- **My organization** - **My organization** shows you all Agreements that apply to your organization. You can also update profile info for you org, such as mailing address and email associated with your account. -- **Manage prepaid Office 365 subscriptions** - Office 365 prepaid subscriptions can be redeemed using a prepaid token. Tokens are available through 3rd-party businesses, outside of Microsoft Store for Business or the Office 365 Admin portal. After redeeming prepaid subscriptions, Admins can add more licenses or extend the subscription's expiration date. -- **Manage Office 365 subscriptions acquired by partners** - Office 365 subscriptions purchased for your organization by a partner or reseller can be managed in Microsoft Store for Business. Admins can assign and manage licenses for these subscriptions. -- **Edge extensions in Microsoft Store** - Edge Extensions are now available from Microsoft Store! You can acquire and distribute them from Microsoft Store for Business just like any other app. -- **Search results in Microsoft Store for Business** - Search results now have sub categories to help you refine search results. diff --git a/store-for-business/roles-and-permissions-microsoft-store-for-business.md b/store-for-business/roles-and-permissions-microsoft-store-for-business.md deleted file mode 100644 index 842c7e3e8e..0000000000 --- a/store-for-business/roles-and-permissions-microsoft-store-for-business.md +++ /dev/null @@ -1,103 +0,0 @@ ---- -title: Roles and permissions in Microsoft Store for Business and Education (Windows 10) -description: The first person to sign in to Microsoft Store for Business or Microsoft Store for Education must be a Global Admin of the Microsoft Entra tenant. Once the Global Admin has signed in, they can give permissions to others employees. -keywords: roles, permissions -ms.assetid: CB6281E1-37B1-4B8B-991D-BC5ED361F1EE -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Roles and permissions in Microsoft Store for Business and Education - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -> [!NOTE] -> As of April 14th, 2021, only free apps are available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md). - -The first person to sign in to Microsoft Store for Business or Microsoft Store for Education must be a Global Admin of the Microsoft Entra tenant. Once the Global Admin has signed in, they can give permissions to others employees. - -Microsoft Store for Business and Education has a set of roles that help admins and employees manage access to apps and tasks for Microsoft Store. Employees with these roles will need to use their Microsoft Entra account to access the Store. Global Administrators and global user accounts that are used with other Microsoft services, such as Azure, or Office 365 can sign in to Microsoft Store. Global user accounts have some permissions in Microsoft Store, and Microsoft Store has a set of roles that help IT admins and employees manage access to apps and tasks for Microsoft Store. - -## Global user account permissions in Microsoft Store - -This table lists the global user accounts and the permissions they have in Microsoft Store. - -|| Global Administrator | Billing Administrator | -| ------------------------------ | --------------------- | --------------------- | -| **Sign up for Microsoft Store for Business and Education** | ✔️ | ✔️ | -| **Modify company profile settings** | ✔️ | ✔️ | -| **Purchase apps** | ✔️ | ✔️ | -| **Distribute apps** | ✔️ | ✔️ | -| **Purchase subscription-based software** | ✔️ | ✔️ | - -- **Global Administrator** and **Billing Administrator** - IT Pros with these accounts have full access to Microsoft Store. They can do everything allowed in the Microsoft Store Admin role, plus they can sign up for Microsoft Store. - -## Microsoft Store roles and permissions - -Microsoft Store for Business has a set of roles that help IT admins and employees manage access to apps and tasks for Microsoft Store. Employees with these roles will need to use their Microsoft Entra account to access Microsoft Store. - -This table lists the roles and their permissions. - -|| Admin | Purchaser | Device Guard signer | -| ------------------------------ | ------ | -------- | ------------------- | -| **Assign roles** | ✔️ | | | -| **Manage Microsoft Store for Business and Education settings** | ✔️ | | | -| **Acquire apps** | ✔️ | ✔️ | | -| **Distribute apps** | ✔️ | ✔️ | | -| **Sign policies and catalogs** | ✔️ | | | -| **Sign Device Guard changes** | ✔️ | | ✔️ | - -These permissions allow people to: - -- **Manage Microsoft Store settings**: - - Account information (view only) - - Device Guard signing - - LOB publishers - - Management tools - - Offline licensing - - Permissions - - Private store - -- **Acquire apps** - Acquire apps from Microsoft Store and add them to your inventory. - -- **Distribute apps** - Distribute apps that are in your inventory. - - Admins can assign apps to people, add apps to the private store, or use a management tool. - - Purchasers can assign apps to people. - -**To assign roles to people** - -1. Sign in to Microsoft Store for Business or Microsoft Store for Education. - - >[!Note] - >You need to be a Global Administrator, or have the Microsoft Store Admin role to access the **Permissions** page. - - To assign roles, you need to be a Global Administrator or a Store Administrator. - -2. Click **Settings**, and then choose **Permissions**. - - OR - - Click **Manage**, and then click **Permissions** on the left-hand menu. - - - -3. Click **Add people**, type a name, choose the role you want to assign, and click **Save**. - - - -4. If you don't find the name you want, you might need to add people to your Microsoft Entra directory. For more information, see [Manage user accounts in Microsoft Store for Business and Education](manage-users-and-groups-microsoft-store-for-business.md). diff --git a/store-for-business/settings-reference-microsoft-store-for-business.md b/store-for-business/settings-reference-microsoft-store-for-business.md deleted file mode 100644 index 365a4304f2..0000000000 --- a/store-for-business/settings-reference-microsoft-store-for-business.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: Settings reference Microsoft Store for Business and Education (Windows 10) -description: The Microsoft Store for Business and Education has a group of settings that admins use to manage the store. -ms.assetid: 34F7FA2B-B848-454B-AC00-ECA49D87B678 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Settings reference: Microsoft Store for Business and Education - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -The Microsoft Store for Business and Education has a group of settings that admins use to manage the store. - -| Setting | Description | Location under **Manage** | -| ------- | ----------- | ------------------------------ | -| Billing account information | Manage organization information. For more information, see [Manage settings for the Microsoft Store for Business and Education](update-microsoft-store-for-business-account-settings.md).| **Billing accounts** | -| Payment options | Manage payment options. For more information, see [Manage settings for the Microsoft Store for Business and Education](payment-methods.md).| **Billing & payments - Payment methods** | -| Private store | Update the name for your private store. The new name will be displayed on a tab in the Store. For more information, see [Manage private store settings](manage-private-store-settings.md). | **Settings - Distribute** | -| Offline licensing | Configure whether or not to make offline-licensed apps available in the Microsoft Store for Business and Education. For more information, see [Distribute offline apps](distribute-offline-apps.md). | **Settings - Shop** | -| Allow users to shop | Configure whether or not people in your organization or school can see and use the shop function in Store for Business or Store for Education. For more information, see [Allow users to shop](acquire-apps-microsoft-store-for-business.md#allow-users-to-shop). | **Settings - Shop** | -| Make everyone a Basic Purchaser | Allow everyone in your organization to automatically become a Basic Purchaser. This allows them to purchase apps and manage them. For more information, see [Make everyone a Basic Purchaser](/education/windows/education-scenarios-store-for-business#basic-purchaser-role). | **Settings - Shop** | -| App request | Configure whether or not people in your organization can request apps for admins to purchase. For more information, see [Distribute offline apps](acquire-apps-microsoft-store-for-business.md). | **Settings - Shop** | -| Management tools | Management tools that are synced with Microsoft Entra ID are listed on this page. You can choose one to use for managing app updates and distribution. For more information, see [Configure MDM provider](configure-mdm-provider-microsoft-store-for-business.md). | **Settings - Distribute** | -| Device Guard signing | Use the Device Guard signing portal to add unsigned apps to a code integrity policy, or to sign code integrity policies. For more information, see [Device Guard signing portal](device-guard-signing-portal.md). | **Settings - Devices** | -| Permissions | Manage permissions for your employees. For more information, see [Roles and permissions in the Microsoft Store for Business and Education](roles-and-permissions-microsoft-store-for-business.md). | **Permissions - Roles**, **Permissions - Purchasing roles**, and **Permissions - Blocked basic purchasers** | -| Line-of-business (LOB) publishers | Invite devs to become LOB publishers for your organization. Existing LOB publishers are listed on the page, and you can deactivate or invite them again. For more information, see [Work with line-of-business apps](working-with-line-of-business-apps.md). | **Permissions - Line-of-business apps** | diff --git a/store-for-business/sfb-change-history.md b/store-for-business/sfb-change-history.md deleted file mode 100644 index 0bd887f0d4..0000000000 --- a/store-for-business/sfb-change-history.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: Change history for Microsoft Store for Business and Education -description: Summary of topic changes for Microsoft Store for Business and Microsoft Store for Education. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -author: TrudyHa -ms.author: TrudyHa -ms.topic: conceptual -ms.date: 3/2/2019 -ms.reviewer: -manager: dansimp -ms.localizationpriority: medium ---- - -# Change history for Microsoft Store for Business and Microsoft Store for Education - -## March 2019 - -| New or changed topic | Description | -| --- | --- | -| [Understand your Microsoft Customer Agreement invoice](billing-understand-your-invoice-msfb.md) | New topic | -| [Understand billing profiles](billing-profile.md) | New topic | -| [Payment methods](payment-methods.md) | New topic | -| [Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Update with information on billing accounts. | -| [Roles and permissions in Microsoft Store for Business and Education](roles-and-permissions-microsoft-store-for-business.md) | Add info for purchasing roles and permissions. | - -## April 2018 - -| New or changed topic | Description | -| --- | --- | -| [Configure access to Microsoft Store](/windows/configuration/stop-employees-from-using-microsoft-store#a-href-idblock-store-group-policyablock-microsoft-store-using-group-policy) | Update on app updates when Microsoft Store is blocked. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## March 2018 - -| New or changed topic | Description | -| --- | --- | -| [Manage software purchased with Microsoft Products and Services agreement in Microsoft Store for Business](manage-mpsa-software-microsoft-store-for-business.md) | New | -| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store performance improvements. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | -| [Roles and permissions in Microsoft Store for Business](roles-and-permissions-microsoft-store-for-business.md) | Update | - -## February 2018 - -| New or changed topic | Description | -| --- | --- | -| [Manage private store settings](manage-private-store-settings.md) | Update for adding private store collections. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## November 2017 - -| New or changed topic | Description | -| --- | --- | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## October 2017 - -| New or changed topic | Description | -| --- | --- | -| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | Update. Add profile settings with supported build info. | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | Update | - -## September 2017 - -| New or changed topic | Description | -| --- | --- | -| [What's New in Microsoft Store for Business and Education](whats-new-microsoft-store-business-education.md) | New | -| [Acquire apps](acquire-apps-microsoft-store-for-business.md#acquire-apps) | New | -| [Settings reference: Microsoft Store for Business and Education](manage-settings-microsoft-store-for-business.md)
and
[Update Microsoft Store for Business and Microsoft Store for Education account settings](update-microsoft-store-for-business-account-settings.md) | Updates for UI changes in **Settings**. | - -## July 2017 - -| New or changed topic | Description | -| --- | --- | -| [Microsoft Store for Business and Education PowerShell module - preview](microsoft-store-for-business-education-powershell-module.md) | New | -| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | -| [Manage Windows device deployment with Windows Autopilot Deployment](add-profile-to-devices.md) | New. Information about Windows Autopilot Deployment Program and how it is used in Microsoft Store for Business and Education. | - -## June 2017 - -| New or changed topic | Description | -| -------------------- | ----------- | -| [Notifications in Microsoft Store for Business and Education](notifications-microsoft-store-business.md) | New. Information about notification model in Microsoft Store for Business and Education. | -| [Get Minecraft: Education Edition with Windows 10 device promotion](/education/windows/get-minecraft-device-promotion) | New. Information about redeeming Minecraft: Education Edition licenses with qualifying purchases of Windows 10 devices. | -| [Microsoft Store for Business and Education overview - supported markets](./microsoft-store-for-business-overview.md#supported-markets) | Updates for added market support. | diff --git a/store-for-business/sign-up-microsoft-store-for-business-overview.md b/store-for-business/sign-up-microsoft-store-for-business-overview.md deleted file mode 100644 index 7a1837372b..0000000000 --- a/store-for-business/sign-up-microsoft-store-for-business-overview.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -title: Sign up and get started (Windows 10) -description: IT admins can sign up for the Microsoft Store for Business or Microsoft Store for Education and get started working with apps. -ms.assetid: 87C6FA60-3AB9-4152-A85C-6A1588A20C7B -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Sign up and get started - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -IT admins can sign up for Microsoft Store for Business and Education, and get started working with apps. - -> [!NOTE] -> As of April 14th, 2021, only free apps are available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md). - -## In this section - -| Topic | Description | -| ----- | ----------- | -| [Microsoft Store for Business and Education overview](./microsoft-store-for-business-overview.md) | Learn about Microsoft Store for Business. | -| [Prerequisites for Microsoft Store for Business and Education](./prerequisites-microsoft-store-for-business.md) | There are a few prerequisites for using [Microsoft Store for Business and Education.](/microsoft-store/prerequisites-microsoft-store-for-business) | -| [Roles and permissions in Microsoft Store for Business and Education](./roles-and-permissions-microsoft-store-for-business.md)| The first person to sign in to Microsoft Store for Business and Education must be a Global Admin of the Microsoft Entra tenant. Once the Global Admin has signed in, they can give permissions to others employees. | -| [Settings reference: Microsoft Store for Business and Education](./settings-reference-microsoft-store-for-business.md) | Microsoft Store for Business and Education has a group of settings that admins use to manage the store. | diff --git a/store-for-business/troubleshoot-microsoft-store-for-business.md b/store-for-business/troubleshoot-microsoft-store-for-business.md deleted file mode 100644 index 80b2786116..0000000000 --- a/store-for-business/troubleshoot-microsoft-store-for-business.md +++ /dev/null @@ -1,70 +0,0 @@ ---- -title: Troubleshoot Microsoft Store for Business (Windows 10) -description: Troubleshooting topics for Microsoft Store for Business. -ms.assetid: 243755A3-9B20-4032-9A77-2207320A242A -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Troubleshoot Microsoft Store for Business - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Troubleshooting topics for Microsoft Store for Business. - -## Can't find apps in private store - -The private store for your organization is a page in Microsoft Store app that contains apps that are private to your organization. After your organization acquires an app, your Store for Business admin can add it to your organization's private store. Your private store usually has a name that is close to the name of your organization or company. If you can't see your private store, there are a couple of things to check: - -- **No apps in the private store** - The private store page is only available in Microsoft Store on Windows 10 if there are apps added to your private store. You won't see your private store page with no apps listed on it. If your Microsoft Store for Business admin has added an app to the private store, and the private store page is still not available, they can check the private store status for the app on **Product & services - Apps**. If the status under **Private store** is **Add in progress**, wait and check back. -- **Signed in with the wrong account** - If you have multiple accounts that you use in your organization, you might be signed in with the wrong account. Or, you might not be signed in. Use this procedure to sign in with your organization account. - -**To sign in with organization account in Microsoft Store app** - -1. Click the people icon in Microsoft Store app, and click **Sign in**. - - ![Sign in to Store app with a different account.](images/wsfb-wsappsignin.png) - -2. Click **Add account**, and then click **Work or school account**. - - ![Choose an account to use.](images/wsfb-wsappaddacct.png) - -3. Type the email account and password, and click **Sign in**. - - ![Sign in for work or school account.](images/wsfb-wsappworkacct.png) - -4. You should see the private store for your organization. In our example, the page is named **Contoso publishing**. - - ![Private store with name highlighted.](images/wsfb-wsappprivatestore.png) - - Click the private store to see apps in your private store. - - ![Private store for Contoso publishing.](images/wsfb-privatestoreapps.png) - -## Troubleshooting Microsoft Store for Business integration with Microsoft Configuration Manager - -If you encounter any problems when integrating Microsoft Store for Business with Configuration Manager, use the [troubleshooting guide](/troubleshoot/mem/configmgr/troubleshoot-microsoft-store-for-business-integration). - -## Still having trouble? - -If you are still having trouble using Microsoft Store or installing an app, Admins can sign in and look for topics on our **Support** page. - -**To view Support page**  - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com). -2.Choose **Manage**> **Support**. diff --git a/store-for-business/update-microsoft-store-for-business-account-settings.md b/store-for-business/update-microsoft-store-for-business-account-settings.md deleted file mode 100644 index 03b03469ee..0000000000 --- a/store-for-business/update-microsoft-store-for-business-account-settings.md +++ /dev/null @@ -1,146 +0,0 @@ ---- -title: Update your Billing account settings -description: The billing account page in Microsoft Store for Business and Microsoft Store for Education, and M365 admin center shows information about your organization that you can update, including country or region, organization contact info, agreements with Microsoft and admin approvals. -keywords: billing accounts, organization info -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Update Billing account settings - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -A billing account contains defining information about your organization. - -> [!NOTE] -> Billing accounts are available in Microsoft Store for Business, and the Microsoft 365 admin center. For more information, see [Understand your Microsoft billing account](/microsoft-365/commerce/manage-billing-accounts). - -The **Billing account** page allows you to manage organization information, purchasing agreements that you have with Microsoft, and admin approvals. The organization information and payment options are required before you can shop for products that have a price. - -## Organization information - -We need your business address, email contact, and tax-exemption certificates that apply to your country/region or locale. - -### Business address and email contact - -Before purchasing apps that have a fee, you need to add or update your organization's business address, contact email address, and contact name. - -We use the Business address to calculate sales tax. If your organization's address has already been entered for other commercial purchases through Microsoft Store, or through other online purchases such as Office 365 or Azure subscriptions, then we'll use the same address in Microsoft Store for Business and Microsoft Store for Education. If we don't have an address, we'll ask you to enter it during your first purchase. - -We need an email address in case we need to contact you about your Microsoft Store for Business and for Education account. This email account should reach the admin for your organization's Office 365 or Microsoft Entra tenant that is used with Microsoft Store. - -**To update billing account information** -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com) or [Microsoft Store for Education](https://educationstore.microsoft.com) -2. Select **Manage**, and then select **Billing accounts**. -3. On **Overview**, select **Edit billing account information**. -4. Make your updates, and then select **Save**. - -### Organization tax information -Taxes for Microsoft Store for Business purchases are determined by your business address. Businesses in these countries/regions can provide their VAT number or local equivalent: -- Austria -- Belgium -- Bulgaria -- Croatia -- Cyprus -- Czech Republic -- Denmark -- Estonia -- Finland -- France -- Germany -- Greece -- Hungary -- Ireland -- Italy -- Latvia -- Liechtenstein -- Lithuania -- Luxembourg -- Malta -- Monaco -- Netherlands -- Norway -- Poland -- Portugal -- Romania -- Slovakia -- South Africa -- Spain -- Sweden -- Switzerland -- United Kingdom - -These countries can provide their VAT number or local equivalent on their **Billing account** information. - -|Market| Tax identifier | -|------|----------------| -| Australia | ABN (optional) | -| Brazil | CNPJ (required) | -| India | GSTIN (optional), PAN ID (required) | -| Isle of Man | VAT ID (optional) | -| New Zealand | GST Registration number (optional) | -| Monaco | VAT ID (optional) | -| Taiwan | VAT ID (optional) | - -### Tax-exempt status - -If you qualify for tax-exempt status in your market, start a service request to establish tax exempt status for your organization. - -**To start a service request** -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com). -2. Select **Manage**, click **Support**, and then under **Store settings & configuration** select **Create technical support ticket**. - -You'll need this documentation: - -|Country/Region or locale | Documentation | -|------------------|----------------| -| United States | Sales Tax Exemption Certificate | -| Canada | Certificate of Exemption (or equivalent letter of authorization) | -| Ireland | 13B/56A Tax Exemption Certificate| -| International organizations that hold tax exemption | Certification / letter confirmation from local tax authorities | - -### Calculating tax - -Sales taxes are calculated against the unit price, and then aggregated. - -For example:
-(unit price X tax rate) X quantity = total sales tax - --or- - -($1.29 X .095) X 100 = $12.25 - -## Agreements -Each billing account includes access to the purchasing agreements your organization has signed with Microsoft. This could include: -- Microsoft Enterprise Agreement -- Select agreements -- Open agreements -- Microsoft customer agreement - -If you there is an updated version of the Microsoft customer agreement for you to sign, you'll be prompted to on **Agreements**, or during a purchase. - diff --git a/store-for-business/whats-new-microsoft-store-business-education.md b/store-for-business/whats-new-microsoft-store-business-education.md deleted file mode 100644 index 4af32aae83..0000000000 --- a/store-for-business/whats-new-microsoft-store-business-education.md +++ /dev/null @@ -1,93 +0,0 @@ ---- -title: Whats new in Microsoft Store for Business and Education -description: Learn about the newest features in Microsoft Store for Business and Microsoft Store for Education. -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.date: 06/21/2024 -ms.reviewer: ---- - -# What's new in Microsoft Store for Business and Education - -## Latest updates for Store for Business and Education - -**June 2024** - -The Microsoft Store for Business and Microsoft Store for Education portals will retire on August 15, 2024. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-intune-integration-with-the-microsoft-store-on-windows/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). If you are using offline licensing, you can use the [WinGet Download command](/windows/package-manager/winget/download) to continue to access offline apps and license files. - -## Previous releases and updates - -**January 2024** - -**Removal of private store capability from Microsoft Store for Business and Education** - -The private store tab and associated functionality was removed from the Microsoft Store for Business and Education portal. This includes the ability to add apps to private groups and to download and install apps from the private store. - -We recommend customers use the [Private app repository, Windows Package Manager, and Company Portal app](/windows/application-management/private-app-repository-mdm-company-portal-windows-11) to provide a private app repository within their organization. - -[May 2023](release-history-microsoft-store-business-education.md#may-2023) -- Tab removed from Microsoft Store apps on Windows 10 PCs. - -[April 2023](release-history-microsoft-store-business-education.md#april-2023) -- Tab removed from Microsoft Store apps on Windows 11 PCs. - -[October 2018](release-history-microsoft-store-business-education.md#october-2018) -- Use security groups with Private store apps - -[September 2018](release-history-microsoft-store-business-education.md#september-2018) -- Performance improvements - -[August 2018](release-history-microsoft-store-business-education.md#august-2018) -- App requests - -[July 2018](release-history-microsoft-store-business-education.md#july-2018) -- Bug fixes and performance improvements - -[June 2018](release-history-microsoft-store-business-education.md#june-2018) -- Change order within private store collection -- Performance improvements in private store - -[May 2018](release-history-microsoft-store-business-education.md#may-2018) -- Immersive Reading app available in Microsoft Store for Education - -[April 2018](release-history-microsoft-store-business-education.md#april-2018) -- Assign apps to larger groups -- Change collection order in private store -- Office 365 subscription management - -[March 2018](release-history-microsoft-store-business-education.md#march-2018) -- Performance improvements in private store -- Private store collection updates -- Manage Skype communication credits -- Upgrade Office 365 trial subscription - -[January & February, 2018](release-history-microsoft-store-business-education.md#january-and-february-2018) -- One place for apps, software, and subscriptions -- Create collections of apps in your private store -- Upgrade Office 365 trial subscription -- Supporting Microsoft Product and Services Agreement customers -- Microsoft Product and Services Agreement customers can invite people to take roles - -[December 2017](release-history-microsoft-store-business-education.md#december-2017) -- Bug fixes and performance improvements - -[November 2017](release-history-microsoft-store-business-education.md#november-2017) -- Export list of Minecraft: Education Edition users -- Bug fixes and performance improvements - -[October 2017](release-history-microsoft-store-business-education.md#october-2017) -- Bug fixes and performance improvements - -[September 2017](release-history-microsoft-store-business-education.md#september-2017) -- Manage Windows device deployment with Windows Autopilot Deployment -- Request an app -- My organization -- Manage prepaid Office 365 subscriptions -- Manage Office 365 subscriptions acquired by partners -- Edge extensions in Microsoft Store -- Search results in Microsoft Store for Business diff --git a/store-for-business/working-with-line-of-business-apps.md b/store-for-business/working-with-line-of-business-apps.md deleted file mode 100644 index 408165a16a..0000000000 --- a/store-for-business/working-with-line-of-business-apps.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: Working with line-of-business apps (Windows 10) -description: Your company or school can make line-of-business (LOB) applications available through Microsoft Store for Business or Microsoft Store for Education. These apps are custom to your organization – they might be internal business apps, or apps specific to your school, business, or industry. -ms.assetid: 95EB7085-335A-447B-84BA-39C26AEB5AC7 -ms.reviewer: -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: store -ms.author: cmcatee -author: cmcatee-MSFT -manager: scotv -ms.topic: conceptual -ms.localizationpriority: medium -ms.date: 05/24/2023 ---- - -# Working with line-of-business apps - -**Applies to:** - -- Windows 10 - -> [!IMPORTANT] -> -> - The retirement of Microsoft Store for Business and Microsoft Store for Education has been postponed. We will update this notice when a new retirement date is announced. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286). -> - In April 2023 the Microsoft Store for Business tab was removed from Microsoft Store apps on Windows 10 and Windows 11 PCs. An interaction with existing MDM and GPO policies may lead to customers seeing errors when accessing the Microsoft Store app. For more information see [Microsoft Store for Business tab removed](manage-access-to-private-store.md#microsoft-store-for-business-tab-removed). - -Your company or school can make line-of-business (LOB) applications available through Microsoft Store for Business or Microsoft Store for Education. These apps are custom to your school or organization – they might be internal apps, or apps specific to your school, business, or industry. - -Developers within your organization, or ISVs that you invite, can become LOB publishers and submit apps to Microsoft Store for your company or school. Once an LOB publisher submits an app for your company, the app is only available to your company. LOB publishers submit apps through the Windows Dev Center using the same process as all apps that are in Microsoft Store, and then can be managed or deployed using the same process as any other app that has been acquired through Microsoft Store. - -One advantage of making apps available through Microsoft Store for Business is that the app has been signed by Microsoft Store, and uses the standard Microsoft Store policies. For organizations that can't submit their application through the Windows Dev Center (for example, those needing additional capabilities or due to compliance purposes), [Sideloading](/windows/application-management/sideload-apps-in-windows-10) is also supported on Windows 10. - -## Adding LOB apps to your private store - -Admins and ISVs each own different parts of the process for getting LOB apps created, submitted, and deployed to your employees or students. Admins use Microsoft Store for Business or Microsoft Store for Education portal; ISVs or devs use the Windows Dev center on MSDN. - -Here's what's involved: - -- Microsoft Store for Business admin invites a developer or ISV to become an LOB publisher for your company. -- LOB publisher develops and submits app to Microsoft Store, tagging the app so it is only available to your company. -- Microsoft Store for Business admin accepts the app and can distribute the app to employees in your company. - -You'll need to set up: - -- Your company needs to be signed up with Microsoft Store for Business or Microsoft Store for Education. -- LOB publishers need to have an active developer account. To learn more about account options, see [Ready to sign up](https://go.microsoft.com/fwlink/p/?LinkId=623432). -- LOB publishers need to have an app in Microsoft Store, or have an app ready to submit to the Store. - -The process and timing look like this: -![Process showing LOB workflow in Microsoft Store for Business. Includes workflow for Microsoft Store for Business admin, LOB publisher, and Developer.](images/lob-workflow.png) - -## Add an LOB publisher (Admin) - -Admins need to invite developer or ISVs to become an LOB publisher. - -### To invite a developer to become an LOB publisher - -1. Sign in to [Microsoft Store for Business](https://businessstore.microsoft.com). -2. Click **Manage**, click **Permissions**, and then choose **Line-of-business publishers**. -3. On the Line-of business publishers page, click **Invite** to send an email invitation to a developer. - - >[!Note] - > This needs to be the email address listed in contact info for the developer account. - -## Submit apps (LOB publisher) - -The developer receives an email invite to become an LOB publisher for your company. Once they accept the invite, they can log in to the Windows Dev Center to create an app submission for your company. The info here assumes that devs or ISVs have an active developer account. - -After an app is published and available in the Store, ISVs publish an updated version by creating another submission in their dashboard. Creating a new submission allows the ISV to make the changes required to create a LOB app for your company. To learn more about updates to an app submission, see [App submissions](/windows/uwp/publish/app-submissions) and [Distributing LOB apps to enterprises](/windows/uwp/publish/distribute-lob-apps-to-enterprises). - -## To create a new submission for an app - -1. Sign in to the [Windows Dev Center](https://go.microsoft.com/fwlink/p/?LinkId=623486), go to your Dashboard, and click the app you want to make available as an LOB app. -2. On the App overview page, under **Action**, click **Update**. - - -OR- - - Submit your app following the guidelines in [App submissions](/windows/uwp/publish/app-submissions). Be sure to completed steps 3 and 4 when you set app pricing and availability options. - -3. On the **Pricing and availability** page, under **Distribution and visibility**, click **Line-of-business (LOB) distribution**, and then choose the enterprise(s) who will get the LOB app. No one else will have access to the app. -4. Under **Organizational licensing**, click **Show options**. - - Organizational licensing options apply to all apps, not just LOB apps: - - - **Store-managed (online) volume licensing** - This is required. You must select this item to make your app available as an a LOB app. By default, it will be selected. This won't make the app available to anyone outside of the enterprise(s) that you selected in **Distribution and visibility**. - - - **Disconnected (offline) licensing** - This is optional for LOB apps. - -5. Click **Save** to save your changes and start the app submission process. - -For more information, see [Organizational licensing options]( https://go.microsoft.com/fwlink/p/?LinkId=708615) and [Distributing LOB apps to enterprises](/windows/uwp/publish/distribute-lob-apps-to-enterprises). - - >[!Note] - > In order to get the LOB app, the organization must be located in a [supported market](./microsoft-store-for-business-overview.md#supported-markets), and you must not have excluded that market when submitting your app. - -## Add app to inventory (admin) - -After an ISV submits the LOB app for your company or school, someone with Microsoft Store for Business and Education admin permissions needs to accept the app. - -### To add the LOB app to your inventory - -1. Sign in to the [Microsoft Store for Business](https://businessstore.microsoft.com). -2. Click **Manage**, click **Products & services**, and then choose **New LOB apps**. -3. Click the ellipses under **Action** for the app you want to add to your inventory, and then choose **Add to inventory**. - -After you add the app to your inventory, you can choose how to distribute the app. For more information, see: - -- [Distribute apps to your employees from the Microsoft Store for Business](distribute-apps-to-your-employees-microsoft-store-for-business.md) -- [Distribute apps from your private store](distribute-apps-from-your-private-store.md) -- [Assign apps to employees](assign-apps-to-employees.md) -- [Distribute offline apps](distribute-offline-apps.md) diff --git a/windows/client-management/client-tools/images/allow-rdp.png b/windows/client-management/client-tools/images/allow-rdp.png deleted file mode 100644 index 55c13b53bc..0000000000 Binary files a/windows/client-management/client-tools/images/allow-rdp.png and /dev/null differ diff --git a/windows/client-management/client-tools/images/crossmark.png b/windows/client-management/client-tools/images/crossmark.png deleted file mode 100644 index 69432ff71c..0000000000 Binary files a/windows/client-management/client-tools/images/crossmark.png and /dev/null differ diff --git a/windows/client-management/client-tools/images/quick-assist-get.png b/windows/client-management/client-tools/images/quick-assist-get.png deleted file mode 100644 index fc7ccdd1a4..0000000000 Binary files a/windows/client-management/client-tools/images/quick-assist-get.png and /dev/null differ diff --git a/windows/client-management/client-tools/images/rdp.png b/windows/client-management/client-tools/images/rdp.png deleted file mode 100644 index ac088d0b06..0000000000 Binary files a/windows/client-management/client-tools/images/rdp.png and /dev/null differ diff --git a/windows/client-management/client-tools/images/systemcollage.png b/windows/client-management/client-tools/images/systemcollage.png deleted file mode 100644 index d1400e19f4..0000000000 Binary files a/windows/client-management/client-tools/images/systemcollage.png and /dev/null differ diff --git a/windows/client-management/images/autoenrollment-gpedit.png b/windows/client-management/images/autoenrollment-gpedit.png deleted file mode 100644 index e863dfc945..0000000000 Binary files a/windows/client-management/images/autoenrollment-gpedit.png and /dev/null differ diff --git a/windows/client-management/images/autoenrollment-mdm-policies.png b/windows/client-management/images/autoenrollment-mdm-policies.png deleted file mode 100644 index 6833b4ac8b..0000000000 Binary files a/windows/client-management/images/autoenrollment-mdm-policies.png and /dev/null differ diff --git a/windows/client-management/images/autoenrollment-task-schedulerapp.png b/windows/client-management/images/autoenrollment-task-schedulerapp.png deleted file mode 100644 index 56f071dcda..0000000000 Binary files a/windows/client-management/images/autoenrollment-task-schedulerapp.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant1.png b/windows/client-management/images/azure-ad-add-tenant1.png deleted file mode 100644 index 3e32d82f7b..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant1.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant10.png b/windows/client-management/images/azure-ad-add-tenant10.png deleted file mode 100644 index a6e7c07f67..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant10.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant11.png b/windows/client-management/images/azure-ad-add-tenant11.png deleted file mode 100644 index 4648df15d8..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant11.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant12.png b/windows/client-management/images/azure-ad-add-tenant12.png deleted file mode 100644 index 1b234faef0..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant12.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant13.png b/windows/client-management/images/azure-ad-add-tenant13.png deleted file mode 100644 index b44e7370cd..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant13.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant14.png b/windows/client-management/images/azure-ad-add-tenant14.png deleted file mode 100644 index d295c71a69..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant14.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant15.png b/windows/client-management/images/azure-ad-add-tenant15.png deleted file mode 100644 index d0639750c2..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant15.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant2.png b/windows/client-management/images/azure-ad-add-tenant2.png deleted file mode 100644 index 3099043171..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant2.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant3-b.png b/windows/client-management/images/azure-ad-add-tenant3-b.png deleted file mode 100644 index e845896e37..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant3-b.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant3.png b/windows/client-management/images/azure-ad-add-tenant3.png deleted file mode 100644 index 7ede724ff0..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant3.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant4.png b/windows/client-management/images/azure-ad-add-tenant4.png deleted file mode 100644 index 8c6f4bbbdd..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant4.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant5.png b/windows/client-management/images/azure-ad-add-tenant5.png deleted file mode 100644 index ad951c46b2..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant5.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant6.png b/windows/client-management/images/azure-ad-add-tenant6.png deleted file mode 100644 index 169df32316..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant6.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant7.png b/windows/client-management/images/azure-ad-add-tenant7.png deleted file mode 100644 index 73a1319eb9..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant7.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant8.png b/windows/client-management/images/azure-ad-add-tenant8.png deleted file mode 100644 index b36d089a48..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant8.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-add-tenant9.png b/windows/client-management/images/azure-ad-add-tenant9.png deleted file mode 100644 index 6589bda706..0000000000 Binary files a/windows/client-management/images/azure-ad-add-tenant9.png and /dev/null differ diff --git a/windows/client-management/images/azure-ad-app-gallery.png b/windows/client-management/images/azure-ad-app-gallery.png deleted file mode 100644 index f96d2b7f89..0000000000 Binary files a/windows/client-management/images/azure-ad-app-gallery.png and /dev/null differ diff --git a/windows/client-management/images/azure-mdm-intune.png b/windows/client-management/images/azure-mdm-intune.png deleted file mode 100644 index b0f08a51bd..0000000000 Binary files a/windows/client-management/images/azure-mdm-intune.png and /dev/null differ diff --git a/windows/client-management/images/businessstoreportalservices2.png b/windows/client-management/images/businessstoreportalservices2.png deleted file mode 100644 index 56d8981fc0..0000000000 Binary files a/windows/client-management/images/businessstoreportalservices2.png and /dev/null differ diff --git a/windows/client-management/images/businessstoreportalservices3.png b/windows/client-management/images/businessstoreportalservices3.png deleted file mode 100644 index ac74b64ab1..0000000000 Binary files a/windows/client-management/images/businessstoreportalservices3.png and /dev/null differ diff --git a/windows/client-management/images/businessstoreportalservicesflow.png b/windows/client-management/images/businessstoreportalservicesflow.png deleted file mode 100644 index 6a215fc076..0000000000 Binary files a/windows/client-management/images/businessstoreportalservicesflow.png and /dev/null differ diff --git a/windows/client-management/images/faq-max-devices.png b/windows/client-management/images/faq-max-devices.png deleted file mode 100644 index f2d177b92f..0000000000 Binary files a/windows/client-management/images/faq-max-devices.png and /dev/null differ diff --git a/windows/client-management/images/push-notification1.png b/windows/client-management/images/push-notification1.png deleted file mode 100644 index 74388704f5..0000000000 Binary files a/windows/client-management/images/push-notification1.png and /dev/null differ diff --git a/windows/client-management/images/push-notification10.png b/windows/client-management/images/push-notification10.png deleted file mode 100644 index d76ed273d0..0000000000 Binary files a/windows/client-management/images/push-notification10.png and /dev/null differ diff --git a/windows/client-management/images/push-notification2.png b/windows/client-management/images/push-notification2.png deleted file mode 100644 index ba2c1c008e..0000000000 Binary files a/windows/client-management/images/push-notification2.png and /dev/null differ diff --git a/windows/client-management/images/push-notification3.png b/windows/client-management/images/push-notification3.png deleted file mode 100644 index d5a233353a..0000000000 Binary files a/windows/client-management/images/push-notification3.png and /dev/null differ diff --git a/windows/client-management/images/push-notification4.png b/windows/client-management/images/push-notification4.png deleted file mode 100644 index 49633b7c4d..0000000000 Binary files a/windows/client-management/images/push-notification4.png and /dev/null differ diff --git a/windows/client-management/images/push-notification5.png b/windows/client-management/images/push-notification5.png deleted file mode 100644 index 5abdfbf0bc..0000000000 Binary files a/windows/client-management/images/push-notification5.png and /dev/null differ diff --git a/windows/client-management/images/push-notification6.png b/windows/client-management/images/push-notification6.png deleted file mode 100644 index 380863d930..0000000000 Binary files a/windows/client-management/images/push-notification6.png and /dev/null differ diff --git a/windows/client-management/images/push-notification7.png b/windows/client-management/images/push-notification7.png deleted file mode 100644 index 5185b49323..0000000000 Binary files a/windows/client-management/images/push-notification7.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-10.png b/windows/client-management/images/unifiedenrollment-rs1-10.png deleted file mode 100644 index 046fba9228..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-10.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-2.png b/windows/client-management/images/unifiedenrollment-rs1-2.png deleted file mode 100644 index ea02fe5541..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-2.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-3.png b/windows/client-management/images/unifiedenrollment-rs1-3.png deleted file mode 100644 index 2c6a240864..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-3.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-37-c.png b/windows/client-management/images/unifiedenrollment-rs1-37-c.png deleted file mode 100644 index 5ed04fb4a2..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-37-c.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-4.png b/windows/client-management/images/unifiedenrollment-rs1-4.png deleted file mode 100644 index 214a6c5c2c..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-4.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-5.png b/windows/client-management/images/unifiedenrollment-rs1-5.png deleted file mode 100644 index ca53b739d5..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-5.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-6.png b/windows/client-management/images/unifiedenrollment-rs1-6.png deleted file mode 100644 index e865f66efe..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-6.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-7.png b/windows/client-management/images/unifiedenrollment-rs1-7.png deleted file mode 100644 index 26f4c4320d..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-7.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-8.png b/windows/client-management/images/unifiedenrollment-rs1-8.png deleted file mode 100644 index fefb595eec..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-8.png and /dev/null differ diff --git a/windows/client-management/images/unifiedenrollment-rs1-9.png b/windows/client-management/images/unifiedenrollment-rs1-9.png deleted file mode 100644 index b3f9e58129..0000000000 Binary files a/windows/client-management/images/unifiedenrollment-rs1-9.png and /dev/null differ diff --git a/windows/client-management/implement-server-side-mobile-application-management.md b/windows/client-management/implement-server-side-mobile-application-management.md index 6d2acde09e..f5969415ed 100644 --- a/windows/client-management/implement-server-side-mobile-application-management.md +++ b/windows/client-management/implement-server-side-mobile-application-management.md @@ -9,7 +9,7 @@ ms.date: 07/08/2024 Windows Information Protection (WIP) is a lightweight solution for managing company data access and security on personal devices. WIP support is built into Windows. -[!INCLUDE [Deprecate Windows Information Protection](../security/information-protection/windows-information-protection/includes/wip-deprecation.md)] +[!INCLUDE [Deprecate Windows Information Protection](mdm/includes/wip-deprecation.md)] ## Integration with Microsoft Entra ID @@ -23,7 +23,7 @@ Regular non administrator users can enroll to MAM. ## Understand Windows Information Protection -WIP takes advantage of [built-in policies](/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) to protect company data on the device. To protect user-owned applications on personal devices, WPJ limits enforcement of WIP policies to [enlightened apps](/windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip) and WIP-aware apps. Enlightened apps can differentiate between corporate and personal data, correctly determining which to protect based on WIP policies. WIP-aware apps indicate to Windows that they don't handle personal data, and therefore, it's safe for Windows to protect data on their behalf. +WIP takes advantage of [built-in policies](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) to protect company data on the device. To protect user-owned applications on personal devices, WPJ limits enforcement of WIP policies to [enlightened apps](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip) and WIP-aware apps. Enlightened apps can differentiate between corporate and personal data, correctly determining which to protect based on WIP policies. WIP-aware apps indicate to Windows that they don't handle personal data, and therefore, it's safe for Windows to protect data on their behalf. To make applications WIP-aware, app developers need to include the following data in the app resource file. diff --git a/windows/client-management/mdm/enterprisedataprotection-csp.md b/windows/client-management/mdm/enterprisedataprotection-csp.md index 0b411fed30..959a529d1f 100644 --- a/windows/client-management/mdm/enterprisedataprotection-csp.md +++ b/windows/client-management/mdm/enterprisedataprotection-csp.md @@ -1,12 +1,13 @@ --- title: EnterpriseDataProtection CSP description: Learn how the EnterpriseDataProtection configuration service provider (CSP) configures Windows Information Protection (formerly, Enterprise Data Protection) settings. -ms.assetid: E2D4467F-A154-4C00-9208-7798EF3E25B3 ms.date: 08/09/2017 --- # EnterpriseDataProtection CSP +[!INCLUDE [wip-deprecation](includes/wip-deprecation.md)] + The table below shows the applicability of Windows: |Edition|Windows 10|Windows 11| @@ -18,12 +19,7 @@ The table below shows the applicability of Windows: |Enterprise|Yes|Yes| |Education|Yes|Yes| -The EnterpriseDataProtection configuration service provider (CSP) is used to configure settings for Windows Information Protection (WIP), formerly known as Enterprise Data Protection. For more information about WIP, see [Protect your enterprise data using Windows Information Protection (WIP)](/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip). - -> [!NOTE] -> Starting in July 2022, Microsoft is deprecating Windows Information Protection (WIP) and the APIs that support WIP. Microsoft will continue to support WIP on supported versions of Windows. New versions of Windows won't include new capabilities for WIP, and it won't be supported in future versions of Windows. For more information, see [Announcing sunset of Windows Information Protection](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/announcing-the-sunset-of-windows-information-protection-wip/ba-p/3579282). -> -> For your data protection needs, Microsoft recommends that you use [Microsoft Purview Information Protection](/microsoft-365/compliance/information-protection) and [Microsoft Purview Data Loss Prevention](/microsoft-365/compliance/dlp-learn-about-dlp). Purview simplifies the configuration set-up and provides an advanced set of capabilities. +The EnterpriseDataProtection configuration service provider (CSP) is used to configure settings for Windows Information Protection (WIP), formerly known as Enterprise Data Protection. For more information about WIP, see [Protect your enterprise data using Windows Information Protection (WIP)](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip). > [!NOTE] > To make Windows Information Protection functional, the AppLocker CSP and the network isolation-specific settings must also be configured. For more information, see [AppLocker CSP](applocker-csp.md) and NetworkIsolation policies in [Policy CSP](policy-configuration-service-provider.md). @@ -32,8 +28,8 @@ While Windows Information Protection has no hard dependency on VPN, for best res To learn more about Windows Information Protection, see the following articles: -- [Create a Windows Information Protection (WIP) policy](/windows/security/information-protection/windows-information-protection/overview-create-wip-policy) -- [General guidance and best practices for Windows Information Protection (WIP)](/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip) +- [Create a Windows Information Protection (WIP) policy](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/overview-create-wip-policy) +- [General guidance and best practices for Windows Information Protection (WIP)](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/guidance-and-best-practices-wip) The following example shows the EnterpriseDataProtection CSP in tree format. @@ -52,13 +48,16 @@ EnterpriseDataProtection ----Status ``` -**./Device/Vendor/MSFT/EnterpriseDataProtection** +## `./Device/Vendor/MSFT/EnterpriseDataProtection` + The root node for the CSP. -**Settings** +### Settings + The root node for the Windows Information Protection (WIP) configuration settings. -**Settings/EDPEnforcementLevel** +#### Settings/EDPEnforcementLevel + Set the WIP enforcement level. > [!NOTE] @@ -66,15 +65,16 @@ Set the WIP enforcement level. The following list shows the supported values: -- 0 (default) – Off / No protection (decrypts previously protected data). -- 1 – Silent mode (encrypt and audit only). -- 2 – Allow override mode (encrypt, prompt and allow overrides, and audit). -- 3 – Hides overrides (encrypt, prompt but hide overrides, and audit). +- 0 (default) - Off / No protection (decrypts previously protected data). +- 1 - Silent mode (encrypt and audit only). +- 2 - Allow override mode (encrypt, prompt and allow overrides, and audit). +- 3 - Hides overrides (encrypt, prompt but hide overrides, and audit). Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Settings/EnterpriseProtectedDomainNames** -A list of domains used by the enterprise for its user identities separated by pipes ("|"). The first domain in the list must be the primary enterprise ID, that is, the one representing the managing authority for Windows Information Protection. User identities from one of these domains is considered an enterprise managed account and data associated with it should be protected. For example, the domains for all email accounts owned by the enterprise would be expected to appear in this list. Attempts to change this value will fail when the WIP cleanup is running. +#### Settings/EnterpriseProtectedDomainNames + +A list of domains used by the enterprise for its user identities separated by pipes (`|`). The first domain in the list must be the primary enterprise ID, that is, the one representing the managing authority for Windows Information Protection. User identities from one of these domains is considered an enterprise managed account and data associated with it should be protected. For example, the domains for all email accounts owned by the enterprise would be expected to appear in this list. Attempts to change this value will fail when the WIP cleanup is running. Changing the primary enterprise ID isn't supported and may cause unexpected behavior on the client. @@ -89,7 +89,8 @@ Here are the steps to create canonical domain names: Supported operations are Add, Get, Replace, and Delete. Value type is string. -**Settings/AllowUserDecryption** +#### Settings/AllowUserDecryption + Allows the user to decrypt files. If this is set to 0 (Not Allowed), then the user won't be able to remove protection from enterprise content through the operating system or the application user experiences. > [!IMPORTANT] @@ -97,17 +98,18 @@ Allows the user to decrypt files. If this is set to 0 (Not Allowed), then the us The following list shows the supported values: -- 0 – Not allowed. -- 1 (default) – Allowed. +- 0 - Not allowed. +- 1 (default) - Allowed. Most restricted value is 0. Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Settings/DataRecoveryCertificate** +#### Settings/DataRecoveryCertificate + Specifies a recovery certificate that can be used for data recovery of encrypted files. This certificate is the same as the data recovery agent (DRA) certificate for encrypting file system (EFS), only delivered through mobile device management (MDM) instead of Group Policy. -> [!Note] +> [!NOTE] > If this policy and the corresponding Group Policy setting are both configured, the Group Policy setting is enforced. DRA information from MDM policy must be a serialized binary blob identical to what we expect from GP. @@ -115,37 +117,37 @@ The binary blob is the serialized version of following structure: ```cpp // -//  Recovery Policy Data Structures +// Recovery Policy Data Structures // typedef struct _RECOVERY_POLICY_HEADER { - USHORT      MajorRevision; - USHORT      MinorRevision; - ULONG       RecoveryKeyCount; + USHORT MajorRevision; + USHORT MinorRevision; + ULONG RecoveryKeyCount; } RECOVERY_POLICY_HEADER, *PRECOVERY_POLICY_HEADER; -typedef struct _RECOVERY_POLICY_1_1    { - RECOVERY_POLICY_HEADER  RecoveryPolicyHeader; - RECOVERY_KEY_1_1        RecoveryKeyList[1]; -}   RECOVERY_POLICY_1_1, *PRECOVERY_POLICY_1_1; +typedef struct _RECOVERY_POLICY_1_1 { + RECOVERY_POLICY_HEADER RecoveryPolicyHeader; + RECOVERY_KEY_1_1 RecoveryKeyList[1]; +} RECOVERY_POLICY_1_1, *PRECOVERY_POLICY_1_1; -#define EFS_RECOVERY_POLICY_MAJOR_REVISION_1   (1) -#define EFS_RECOVERY_POLICY_MINOR_REVISION_0   (0) +#define EFS_RECOVERY_POLICY_MAJOR_REVISION_1 (1) +#define EFS_RECOVERY_POLICY_MINOR_REVISION_0 (0) -#define EFS_RECOVERY_POLICY_MINOR_REVISION_1   (1) +#define EFS_RECOVERY_POLICY_MINOR_REVISION_1 (1) /////////////////////////////////////////////////////////////////////////////// -//                                                                            / -//  RECOVERY_KEY Data Structure                                               / -//                                                                            / +// / +// RECOVERY_KEY Data Structure / +// / /////////////////////////////////////////////////////////////////////////////// // // Current format of recovery data. // -typedef struct _RECOVERY_KEY_1_1   { - ULONG               TotalLength; +typedef struct _RECOVERY_KEY_1_1 { + ULONG TotalLength; EFS_PUBLIC_KEY_INFO PublicKeyInfo; } RECOVERY_KEY_1_1, *PRECOVERY_KEY_1_1; @@ -180,7 +182,7 @@ typedef struct _EFS_PUBLIC_KEY_INFO { // // The following fields contain offsets based at the - // beginning of the structure.  Each offset is to + // beginning of the structure. Each offset is to // a NULL terminated WCHAR string. // @@ -205,16 +207,16 @@ typedef struct _EFS_PUBLIC_KEY_INFO { struct { - ULONG CertificateLength;       // in bytes - ULONG Certificate;             // offset from start of structure + ULONG CertificateLength; // in bytes + ULONG Certificate; // offset from start of structure } CertificateInfo; struct { - ULONG ThumbprintLength;        // in bytes - ULONG CertHashData;            // offset from start of structure + ULONG ThumbprintLength; // in bytes + ULONG CertHashData; // offset from start of structure } CertificateThumbprint; }; @@ -238,17 +240,19 @@ For EFSCertificate KeyTag, it's expected to be a DER ENCODED binary certificate. Supported operations are Add, Get, Replace, and Delete. Value type is base-64 encoded certificate. -**Settings/RevokeOnUnenroll** +#### Settings/RevokeOnUnenroll + This policy controls whether to revoke the Windows Information Protection keys when a device unenrolls from the management service. If set to 0 (Don't revoke keys), the keys won't be revoked and the user will continue to have access to protected files after unenrollment. If the keys aren't revoked, there will be no revoked file cleanup, later. Prior to sending the unenroll command, when you want a device to do a selective wipe when it's unenrolled, then you should explicitly set this policy to 1. The following list shows the supported values: -- 0 – Don't revoke keys. -- 1 (default) – Revoke keys. +- 0 - Don't revoke keys. +- 1 (default) - Revoke keys. Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Settings/RevokeOnMDMHandoff** +#### Settings/RevokeOnMDMHandoff + Added in Windows 10, version 1703. This policy controls whether to revoke the Windows Information Protection keys when a device upgrades from mobile application management (MAM) to MDM. If set to 0 (Don't revoke keys), the keys won't be revoked and the user will continue to have access to protected files after upgrade. This setting is recommended if the MDM service is configured with the same WIP EnterpriseID as the MAM service. - 0 - Don't revoke keys. @@ -256,25 +260,29 @@ Added in Windows 10, version 1703. This policy controls whether to revoke the Wi Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Settings/RMSTemplateIDForEDP** +#### Settings/RMSTemplateIDForEDP + TemplateID GUID to use for Rights Management Service (RMS) encryption. The RMS template allows the IT admin to configure the details about who has access to RMS-protected file and how long they have access. Supported operations are Add, Get, Replace, and Delete. Value type is string (GUID). -**Settings/AllowAzureRMSForEDP** +#### Settings/AllowAzureRMSForEDP + Specifies whether to allow Azure RMS encryption for Windows Information Protection. -- 0 (default) – Don't use RMS. -- 1 – Use RMS. +- 0 (default) - Don't use RMS. +- 1 - Use RMS. Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Settings/SMBAutoEncryptedFileExtensions** +#### Settings/SMBAutoEncryptedFileExtensions + Added in Windows 10, version 1703. Specifies a list of file extensions, so that files with these extensions are encrypted when copying from a Server Message Block (SMB) share within the corporate boundary as defined in the Policy CSP nodes for [NetworkIsolation/EnterpriseIPRange](policy-csp-networkisolation.md) and [NetworkIsolation/EnterpriseNetworkDomainNames](policy-csp-networkisolation.md). Use semicolon (;) delimiter in the list. When this policy isn't specified, the existing auto-encryption behavior is applied. When this policy is configured, only files with the extensions in the list will be encrypted. Supported operations are Add, Get, Replace and Delete. Value type is string. -**Settings/EDPShowIcons** +#### Settings/EDPShowIcons + Determines whether overlays are added to icons for WIP protected files in Explorer and enterprise only app tiles on the **Start** menu. Starting in Windows 10, version 1703 this setting also configures the visibility of the Windows Information Protection icon in the title bar of a WIP-protected app. The following list shows the supported values: @@ -283,7 +291,8 @@ The following list shows the supported values: Supported operations are Add, Get, Replace, and Delete. Value type is integer. -**Status** +### Status + A read-only bit mask that indicates the current state of Windows Information Protection on the Device. The MDM service can use this value to determine the current overall state of WIP. WIP is only on (bit 0 = 1) if WIP mandatory policies and WIP AppLocker settings are configured. Suggested values: @@ -310,8 +319,8 @@ Bits 2 and 4 are reserved for future use. Supported operation is Get. Value type is integer. -## Related topics +## Related articles [Configuration service provider reference](index.yml) - +[Protect your enterprise data using Windows Information Protection (WIP)](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) diff --git a/windows/client-management/mdm/images/applocker-screenshot1.png b/windows/client-management/mdm/images/applocker-screenshot1.png deleted file mode 100644 index 9de9e74f70..0000000000 Binary files a/windows/client-management/mdm/images/applocker-screenshot1.png and /dev/null differ diff --git a/windows/client-management/mdm/images/applocker-screenshot2.png b/windows/client-management/mdm/images/applocker-screenshot2.png deleted file mode 100644 index 33b794f9b4..0000000000 Binary files a/windows/client-management/mdm/images/applocker-screenshot2.png and /dev/null differ diff --git a/windows/client-management/mdm/images/applocker-screenshot3.png b/windows/client-management/mdm/images/applocker-screenshot3.png deleted file mode 100644 index d9de466e2d..0000000000 Binary files a/windows/client-management/mdm/images/applocker-screenshot3.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/includes/wip-deprecation.md b/windows/client-management/mdm/includes/wip-deprecation.md similarity index 100% rename from windows/security/information-protection/windows-information-protection/includes/wip-deprecation.md rename to windows/client-management/mdm/includes/wip-deprecation.md diff --git a/windows/client-management/mdm/surfacehub-csp.md b/windows/client-management/mdm/surfacehub-csp.md index 0507eb55c9..663982ef0f 100644 --- a/windows/client-management/mdm/surfacehub-csp.md +++ b/windows/client-management/mdm/surfacehub-csp.md @@ -1,7 +1,7 @@ --- title: SurfaceHub CSP description: Learn more about the SurfaceHub CSP. -ms.date: 08/06/2024 +ms.date: 08/16/2024 --- @@ -84,6 +84,7 @@ The following list shows the SurfaceHub configuration service provider nodes: - [SleepTimeout](#propertiessleeptimeout) - [SurfaceHubMeetingMode](#propertiessurfacehubmeetingmode) - [VtcAppPackageId](#propertiesvtcapppackageid) + - [UpdateBootManager](#updatebootmanager) @@ -2878,6 +2879,55 @@ App name. + +## UpdateBootManager + + +| Scope | Editions | Applicable OS | +|:--|:--|:--| +| ✅ Device
❌ User | ✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 10, version 22H2 [10.0.19045] and later | + + + +```Device +./Vendor/MSFT/SurfaceHub/UpdateBootManager +``` + + + + +Enables new boot manager usage. + + + + + + + +**Description framework properties**: + +| Property name | Property value | +|:--|:--| +| Format | `int` | +| Access Type | Get, Replace | +| Default Value | 0 | + + + +**Allowed values**: + +| Value | Description | +|:--|:--| +| 0 (Default) | Disable new boot manager. | +| 320 | Enable new boot manager. | + + + + + + + + diff --git a/windows/client-management/mdm/surfacehub-ddf-file.md b/windows/client-management/mdm/surfacehub-ddf-file.md index 3222bade2d..1193b28214 100644 --- a/windows/client-management/mdm/surfacehub-ddf-file.md +++ b/windows/client-management/mdm/surfacehub-ddf-file.md @@ -1,7 +1,7 @@ --- title: SurfaceHub DDF file description: View the XML file containing the device description framework (DDF) for the SurfaceHub configuration service provider. -ms.date: 04/22/2024 +ms.date: 08/16/2024 --- @@ -1574,6 +1574,43 @@ The following XML file contains the device description framework (DDF) for the S + + UpdateBootManager + + + + + + Enables new boot manager usage. + 0 + + + + + + + + + + + text/plain + + + 10.0.19045 + 1.0 + + + + 0 + Disable new boot manager + + + 320 + Enable new boot manager + + + + Management diff --git a/windows/configuration/accessibility/index.md b/windows/configuration/accessibility/index.md index 4691dba7a0..815d514593 100644 --- a/windows/configuration/accessibility/index.md +++ b/windows/configuration/accessibility/index.md @@ -1,8 +1,9 @@ --- title: Windows accessibility for IT pros description: Basic guidance for IT administrators on accessibility features available in Windows client. -ms.date: 07/25/2024 +ms.date: 08/22/2024 ms.topic: concept-article +ms.subservice: accessibility ms.collection: tier1 --- diff --git a/windows/configuration/images/icons/notification.svg b/windows/configuration/images/icons/notification.svg deleted file mode 100644 index 0da0f9814d..0000000000 --- a/windows/configuration/images/icons/notification.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/configuration/images/icons/package.svg b/windows/configuration/images/icons/package.svg deleted file mode 100644 index 99c1148922..0000000000 --- a/windows/configuration/images/icons/package.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/configuration/provisioning-packages/images/csp-placeholder.png b/windows/configuration/provisioning-packages/images/csp-placeholder.png deleted file mode 100644 index fe6bcf4720..0000000000 Binary files a/windows/configuration/provisioning-packages/images/csp-placeholder.png and /dev/null differ diff --git a/windows/configuration/provisioning-packages/images/csptable.png b/windows/configuration/provisioning-packages/images/csptable.png deleted file mode 100644 index ee210cad69..0000000000 Binary files a/windows/configuration/provisioning-packages/images/csptable.png and /dev/null differ diff --git a/windows/configuration/provisioning-packages/images/icd-simple-edit.png b/windows/configuration/provisioning-packages/images/icd-simple-edit.png deleted file mode 100644 index 3608dc18f3..0000000000 Binary files a/windows/configuration/provisioning-packages/images/icd-simple-edit.png and /dev/null differ diff --git a/windows/configuration/provisioning-packages/images/policytocsp.png b/windows/configuration/provisioning-packages/images/policytocsp.png deleted file mode 100644 index 80ca76cb62..0000000000 Binary files a/windows/configuration/provisioning-packages/images/policytocsp.png and /dev/null differ diff --git a/windows/configuration/provisioning-packages/images/provisioning-csp-assignedaccess.png b/windows/configuration/provisioning-packages/images/provisioning-csp-assignedaccess.png deleted file mode 100644 index 14d49cdd89..0000000000 Binary files a/windows/configuration/provisioning-packages/images/provisioning-csp-assignedaccess.png and /dev/null differ diff --git a/windows/configuration/start/images/windows-10-secondary-tile.png b/windows/configuration/start/images/windows-10-secondary-tile.png deleted file mode 100644 index 01e25ef3bc..0000000000 Binary files a/windows/configuration/start/images/windows-10-secondary-tile.png and /dev/null differ diff --git a/windows/configuration/start/images/windows-11-secondary-tile.png b/windows/configuration/start/images/windows-11-secondary-tile.png deleted file mode 100644 index 7e7600dcc3..0000000000 Binary files a/windows/configuration/start/images/windows-11-secondary-tile.png and /dev/null differ diff --git a/windows/deployment/TOC.yml b/windows/deployment/TOC.yml index cb3fd2076a..462ea5e08c 100644 --- a/windows/deployment/TOC.yml +++ b/windows/deployment/TOC.yml @@ -1,3 +1,4 @@ +items: - name: Deploy and update Windows client href: index.yml items: @@ -367,10 +368,6 @@ href: do/waas-delivery-optimization-reference.md?context=/windows/deployment/context/context - name: FoD and language packs for WSUS and Configuration Manager href: update/fod-and-lang-packs.md - - name: Windows client in S mode - href: s-mode.md - - name: Switch to Windows client Pro or Enterprise from S mode - href: windows-10-pro-in-s-mode.md - name: Windows client deployment tools items: - name: Windows client deployment scenarios and tools @@ -494,63 +491,7 @@ - name: USMT Resources href: usmt/usmt-resources.md - - name: Application Compatibility Toolkit (ACT) Technical Reference - items: - - name: SUA User's Guide - items: - - name: Overview - href: planning/sua-users-guide.md - - name: Use the SUA Wizard - href: planning/using-the-sua-wizard.md - - name: Use the SUA Tool - href: planning/using-the-sua-tool.md - - name: Tabs on the SUA Tool Interface - href: planning/tabs-on-the-sua-tool-interface.md - - name: Show Messages Generated by the SUA Tool - href: planning/showing-messages-generated-by-the-sua-tool.md - - name: Apply Filters to Data in the SUA Tool - href: planning/applying-filters-to-data-in-the-sua-tool.md - - name: Fix apps using the SUA Tool - href: planning/fixing-applications-by-using-the-sua-tool.md - - name: Compatibility Fixes for Windows 10, Windows 8, Windows 7, and Windows Vista - href: planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md - - name: Compatibility Administrator User's Guide - items: - - name: Overview - href: planning/compatibility-administrator-users-guide.md - - name: Use the Compatibility Administrator Tool - href: planning/using-the-compatibility-administrator-tool.md - - name: Available Data Types and Operators in Compatibility Administrator - href: planning/available-data-types-and-operators-in-compatibility-administrator.md - - name: Search for Fixed Applications in Compatibility Administrator - href: planning/searching-for-fixed-applications-in-compatibility-administrator.md - - name: Search for Installed Compatibility Fixes with the Query Tool in Compatibility Administrator - href: planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md - - name: Create a Custom Compatibility Fix in Compatibility Administrator - href: planning/creating-a-custom-compatibility-fix-in-compatibility-administrator.md - - name: Create a Custom Compatibility Mode in Compatibility Administrator - href: planning/creating-a-custom-compatibility-mode-in-compatibility-administrator.md - - name: Create an AppHelp Message in Compatibility Administrator - href: planning/creating-an-apphelp-message-in-compatibility-administrator.md - - name: View the Events Screen in Compatibility Administrator - href: planning/viewing-the-events-screen-in-compatibility-administrator.md - - name: Enable and Disable Compatibility Fixes in Compatibility Administrator - href: planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md - - name: Install and Uninstall Custom Compatibility Databases in Compatibility Administrator - href: planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md - - name: Manage Application-Compatibility Fixes and Custom Fix Databases - items: - - name: Overview - href: planning/managing-application-compatibility-fixes-and-custom-fix-databases.md - - name: Understand and Use Compatibility Fixes - href: planning/understanding-and-using-compatibility-fixes.md - - name: Compatibility Fix Database Management Strategies and Deployment - href: planning/compatibility-fix-database-management-strategies-and-deployment.md - - name: Test Your Application Mitigation Packages - href: planning/testing-your-application-mitigation-packages.md - - name: Use the Sdbinst.exe Command-Line Tool - href: planning/using-the-sdbinstexe-command-line-tool.md - name: Add fonts in Windows href: windows-missing-fonts.md - name: Customize Windows PE boot images - href: customize-boot-image.md \ No newline at end of file + href: customize-boot-image.md diff --git a/windows/deployment/customize-boot-image.md b/windows/deployment/customize-boot-image.md index f49b063823..31420e8890 100644 --- a/windows/deployment/customize-boot-image.md +++ b/windows/deployment/customize-boot-image.md @@ -7,7 +7,7 @@ author: frankroj manager: aaroncz ms.author: frankroj ms.topic: conceptual -ms.date: 05/09/2024 +ms.date: 08/16/2024 ms.subservice: itpro-deploy appliesto: - ✅ Windows 11 @@ -25,6 +25,10 @@ The Windows PE (WinPE) boot images that are included with the Windows ADK have a Microsoft recommends updating Windows PE boot images with the latest cumulative update for maximum security and protection. The latest cumulative updates may also resolve known issues. For example, the Windows PE boot image can be updated with the latest cumulative update to address the BlackLotus UEFI bootkit vulnerability as documented in [KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932](https://prod.support.services.microsoft.com/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d) and [CVE-2023-24932](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932). +> [!TIP] +> +> The boot images from the [ADK 10.1.26100.1 (May 2024)](/windows-hardware/get-started/adk-install) and later already contain the cumulative update to address the BlackLotus UEFI bootkit vulnerability. + This walkthrough describes how to customize a Windows PE boot image including updating with the latest cumulative update, adding drivers, and adding optional components. Additionally this walkthrough goes over how customizations in boot images affect several different popular products that utilize boot images, such as Microsoft Configuration Manager, Microsoft Deployment Toolkit (MDT), and Windows Deployment Services (WDS). ## Prerequisites @@ -78,6 +82,10 @@ This walkthrough describes how to customize a Windows PE boot image including up 1. When searching the [Microsoft Update Catalog](https://catalog.update.microsoft.com/) site, use the search term `"- cumulative update for windows "` where `year` is the four-digit current year, `` is the two-digit current month, and `` is the version of Windows that Windows PE is based on. Make sure to include the quotes (`"`). For example, to search for the latest cumulative update for Windows 11 in August 2023, use the search term `"2023-08 cumulative update for Windows 11"`, again making sure to include the quotes. If the cumulative update hasn't been released yet for the current month, then search for the previous month. + > [!TIP] + > + > The boot images in the **ADK 10.1.25398.1 (September 2023)** are based off **Microsoft server operating system, version 22H2 for x64-based Systems**. Make sure to update the search term appropriately. + 1. Once the cumulative update has been found, download the appropriate version for the version and architecture of Windows that matches the Windows PE boot image. For example, if the version of the Windows PE boot image is Windows 11 22H2 64-bit, then download the **Cumulative Update for Windows 11 Version 22H2 for x64-based Systems** version of the update. 1. Store the downloaded cumulative update in a known location for later use, for example `C:\Updates`. @@ -662,6 +670,10 @@ This step doesn't update or change the boot image. However, it makes sure that t In particular, this step is needed when addressing the BlackLotus UEFI bootkit vulnerability as documented in [KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932](https://prod.support.services.microsoft.com/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d) and [CVE-2023-24932](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932). +> [!TIP] +> +> The boot images from the [ADK 10.1.26100.1 (May 2024)](/windows-hardware/get-started/adk-install) and later already contain the cumulative update to address the BlackLotus UEFI bootkit vulnerability. + > [!NOTE] > > **Microsoft Configuration Manager** and **Windows Deployment Services (WDS)** automatically extract the bootmgr boot files from the boot images when the boot images are updated in these products. They don't use the bootmgr boot files from the Windows ADK. @@ -902,7 +914,7 @@ For more information, see [Modify a Windows image using DISM: Unmounting an imag ## Step 13: Update boot image in products that utilize it (if applicable) -After the default `winpe.wim` boot image from the Windows ADK has been updated, additional steps usually need to take place in the product(s) that utilize the boot image. The following links contain information on how to update the boot image for several popular products that utilize boot images: +After the default `winpe.wim` boot image from the Windows ADK has been updated, additional steps usually need to take place in the products that utilize the boot image. The following links contain information on how to update the boot image for several popular products that utilize boot images: - [Microsoft Configuration Manager](#updating-the-boot-image-in-configuration-manager) - [Microsoft Deployment Toolkit (MDT)](#updating-the-boot-image-and-boot-media-in-mdt) @@ -1112,10 +1124,10 @@ For more information, see [wdsutil stop-server](/windows-server/administration/w In the following boot image replacement scenario for WDS: -- The boot image modified as part of this guide is outside of the `` folder. For example, the `winpe.wim` boot image that comes with the Windows ADK -- An existing boot image in WDS is being replaced with the updated boot image +- The boot image modified as part of this guide is outside of the `` folder. For example, the `winpe.wim` boot image that comes with the Windows ADK. +- An existing boot image in WDS is being replaced with the updated boot image. -then follow these steps to update the boot image in WDS: +Follow these steps to update the boot image in WDS: 1. Replace the existing boot image in WDS with the modified boot image using the following command lines: @@ -1194,7 +1206,7 @@ In the following boot image scenario for WDS: - The boot image modified as part of this guide is outside of the `` folder. For example, the `winpe.wim` boot image that comes with the Windows ADK - The updated boot image is being added as a new boot image in WDS -then follow these steps to add the boot image in WDS: +Follow these steps to add the boot image in WDS: 1. Add the updated boot image to WDS using the following command lines: diff --git a/windows/deployment/deploy-enterprise-licenses.md b/windows/deployment/deploy-enterprise-licenses.md index 2e0cc4d984..6d810f08ee 100644 --- a/windows/deployment/deploy-enterprise-licenses.md +++ b/windows/deployment/deploy-enterprise-licenses.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.topic: how-to ms.date: 03/04/2024 diff --git a/windows/deployment/do/images/checklistbox.gif b/windows/deployment/do/images/checklistbox.gif deleted file mode 100644 index cbcf4a4f11..0000000000 Binary files a/windows/deployment/do/images/checklistbox.gif and /dev/null differ diff --git a/windows/deployment/do/images/checklistdone.png b/windows/deployment/do/images/checklistdone.png deleted file mode 100644 index 7e53f74d0e..0000000000 Binary files a/windows/deployment/do/images/checklistdone.png and /dev/null differ diff --git a/windows/deployment/do/images/ent-mcc-deployment-complete.png b/windows/deployment/do/images/ent-mcc-deployment-complete.png deleted file mode 100644 index 3586c6019f..0000000000 Binary files a/windows/deployment/do/images/ent-mcc-deployment-complete.png and /dev/null differ diff --git a/windows/deployment/do/images/ent-mcc-portal-create.png b/windows/deployment/do/images/ent-mcc-portal-create.png deleted file mode 100644 index 194220be72..0000000000 Binary files a/windows/deployment/do/images/ent-mcc-portal-create.png and /dev/null differ diff --git a/windows/deployment/do/images/ent-mcc-portal-resource.png b/windows/deployment/do/images/ent-mcc-portal-resource.png deleted file mode 100644 index 383db09303..0000000000 Binary files a/windows/deployment/do/images/ent-mcc-portal-resource.png and /dev/null differ diff --git a/windows/deployment/do/images/ent-mcc-provisioning.png b/windows/deployment/do/images/ent-mcc-provisioning.png deleted file mode 100644 index 1c1dc4f0d0..0000000000 Binary files a/windows/deployment/do/images/ent-mcc-provisioning.png and /dev/null differ diff --git a/windows/deployment/do/images/ent-mcc-script-device-code.png b/windows/deployment/do/images/ent-mcc-script-device-code.png deleted file mode 100644 index 30046d2616..0000000000 Binary files a/windows/deployment/do/images/ent-mcc-script-device-code.png and /dev/null differ diff --git a/windows/deployment/do/images/mcc-isp-migrate.png b/windows/deployment/do/images/mcc-isp-migrate.png deleted file mode 100644 index 02b9afd16c..0000000000 Binary files a/windows/deployment/do/images/mcc-isp-migrate.png and /dev/null differ diff --git a/windows/deployment/do/images/portal-installation-instructions-6.png b/windows/deployment/do/images/portal-installation-instructions-6.png deleted file mode 100644 index 201a1aa1d6..0000000000 Binary files a/windows/deployment/do/images/portal-installation-instructions-6.png and /dev/null differ diff --git a/windows/deployment/images/acroread.png b/windows/deployment/images/acroread.png deleted file mode 100644 index 142e7b6d74..0000000000 Binary files a/windows/deployment/images/acroread.png and /dev/null differ diff --git a/windows/deployment/images/after.png b/windows/deployment/images/after.png deleted file mode 100644 index 1e446f7cf5..0000000000 Binary files a/windows/deployment/images/after.png and /dev/null differ diff --git a/windows/deployment/images/al01.png b/windows/deployment/images/al01.png deleted file mode 100644 index b779b59ac9..0000000000 Binary files a/windows/deployment/images/al01.png and /dev/null differ diff --git a/windows/deployment/images/al02.png b/windows/deployment/images/al02.png deleted file mode 100644 index 6d2216a377..0000000000 Binary files a/windows/deployment/images/al02.png and /dev/null differ diff --git a/windows/deployment/images/captureimage.png b/windows/deployment/images/captureimage.png deleted file mode 100644 index e9ebbf3aad..0000000000 Binary files a/windows/deployment/images/captureimage.png and /dev/null differ diff --git a/windows/deployment/images/check_blu.png b/windows/deployment/images/check_blu.png deleted file mode 100644 index d5c703760f..0000000000 Binary files a/windows/deployment/images/check_blu.png and /dev/null differ diff --git a/windows/deployment/images/check_grn.png b/windows/deployment/images/check_grn.png deleted file mode 100644 index f9f04cd6bd..0000000000 Binary files a/windows/deployment/images/check_grn.png and /dev/null differ diff --git a/windows/deployment/images/dart.png b/windows/deployment/images/dart.png deleted file mode 100644 index f5c099e9a0..0000000000 Binary files a/windows/deployment/images/dart.png and /dev/null differ diff --git a/windows/deployment/images/deploy-finish.png b/windows/deployment/images/deploy-finish.png deleted file mode 100644 index 4f0d5cb859..0000000000 Binary files a/windows/deployment/images/deploy-finish.png and /dev/null differ diff --git a/windows/deployment/images/deployment-workbench01.png b/windows/deployment/images/deployment-workbench01.png deleted file mode 100644 index c68ee25db1..0000000000 Binary files a/windows/deployment/images/deployment-workbench01.png and /dev/null differ diff --git a/windows/deployment/images/download.png b/windows/deployment/images/download.png deleted file mode 100644 index 266a2a196b..0000000000 Binary files a/windows/deployment/images/download.png and /dev/null differ diff --git a/windows/deployment/images/ent.png b/windows/deployment/images/ent.png deleted file mode 100644 index e9d571ed15..0000000000 Binary files a/windows/deployment/images/ent.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-ad-connect.png b/windows/deployment/images/enterprise-e3-ad-connect.png deleted file mode 100644 index 195058f6f6..0000000000 Binary files a/windows/deployment/images/enterprise-e3-ad-connect.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-choose-how.png b/windows/deployment/images/enterprise-e3-choose-how.png deleted file mode 100644 index 8e84535bfd..0000000000 Binary files a/windows/deployment/images/enterprise-e3-choose-how.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-connect-to-work-or-school.png b/windows/deployment/images/enterprise-e3-connect-to-work-or-school.png deleted file mode 100644 index 90e1b1131f..0000000000 Binary files a/windows/deployment/images/enterprise-e3-connect-to-work-or-school.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-lets-get-2.png b/windows/deployment/images/enterprise-e3-lets-get-2.png deleted file mode 100644 index ef523d4af8..0000000000 Binary files a/windows/deployment/images/enterprise-e3-lets-get-2.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-lets-get.png b/windows/deployment/images/enterprise-e3-lets-get.png deleted file mode 100644 index 582da1ab2d..0000000000 Binary files a/windows/deployment/images/enterprise-e3-lets-get.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-set-up-work-or-school.png b/windows/deployment/images/enterprise-e3-set-up-work-or-school.png deleted file mode 100644 index 72844d7622..0000000000 Binary files a/windows/deployment/images/enterprise-e3-set-up-work-or-school.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-sign-in.png b/windows/deployment/images/enterprise-e3-sign-in.png deleted file mode 100644 index 3029d3ef2b..0000000000 Binary files a/windows/deployment/images/enterprise-e3-sign-in.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-who-owns.png b/windows/deployment/images/enterprise-e3-who-owns.png deleted file mode 100644 index c3008869d2..0000000000 Binary files a/windows/deployment/images/enterprise-e3-who-owns.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-active.png b/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-active.png deleted file mode 100644 index eb888b23b5..0000000000 Binary files a/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-active.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-not-active.png b/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-not-active.png deleted file mode 100644 index e4ac7398be..0000000000 Binary files a/windows/deployment/images/enterprise-e3-win-10-activated-enterprise-subscription-not-active.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-active.png b/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-active.png deleted file mode 100644 index 5fedfe5d06..0000000000 Binary files a/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-active.png and /dev/null differ diff --git a/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-not-active.png b/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-not-active.png deleted file mode 100644 index 84e39071db..0000000000 Binary files a/windows/deployment/images/enterprise-e3-win-10-not-activated-enterprise-subscription-not-active.png and /dev/null differ diff --git a/windows/deployment/images/feedback.png b/windows/deployment/images/feedback.png deleted file mode 100644 index 15e171c4ed..0000000000 Binary files a/windows/deployment/images/feedback.png and /dev/null differ diff --git a/windows/deployment/images/fig10-unattend.png b/windows/deployment/images/fig10-unattend.png deleted file mode 100644 index 54f0b0f86f..0000000000 Binary files a/windows/deployment/images/fig10-unattend.png and /dev/null differ diff --git a/windows/deployment/images/fig2-importedos.png b/windows/deployment/images/fig2-importedos.png deleted file mode 100644 index 90cf910c24..0000000000 Binary files a/windows/deployment/images/fig2-importedos.png and /dev/null differ diff --git a/windows/deployment/images/fig2-taskseq.png b/windows/deployment/images/fig2-taskseq.png deleted file mode 100644 index bdd81ddbde..0000000000 Binary files a/windows/deployment/images/fig2-taskseq.png and /dev/null differ diff --git a/windows/deployment/images/fig4-oob-drivers.png b/windows/deployment/images/fig4-oob-drivers.png deleted file mode 100644 index 14d93fb278..0000000000 Binary files a/windows/deployment/images/fig4-oob-drivers.png and /dev/null differ diff --git a/windows/deployment/images/fig5-selectprofile.png b/windows/deployment/images/fig5-selectprofile.png deleted file mode 100644 index 452ab4f581..0000000000 Binary files a/windows/deployment/images/fig5-selectprofile.png and /dev/null differ diff --git a/windows/deployment/images/fig6-taskseq.png b/windows/deployment/images/fig6-taskseq.png deleted file mode 100644 index 8696cc04c4..0000000000 Binary files a/windows/deployment/images/fig6-taskseq.png and /dev/null differ diff --git a/windows/deployment/images/fig8-cust-tasks.png b/windows/deployment/images/fig8-cust-tasks.png deleted file mode 100644 index 3ab40d730a..0000000000 Binary files a/windows/deployment/images/fig8-cust-tasks.png and /dev/null differ diff --git a/windows/deployment/images/fig8-suspend.png b/windows/deployment/images/fig8-suspend.png deleted file mode 100644 index 8094f01274..0000000000 Binary files a/windows/deployment/images/fig8-suspend.png and /dev/null differ diff --git a/windows/deployment/images/fig9-resumetaskseq.png b/windows/deployment/images/fig9-resumetaskseq.png deleted file mode 100644 index 0a83019f69..0000000000 Binary files a/windows/deployment/images/fig9-resumetaskseq.png and /dev/null differ diff --git a/windows/deployment/images/image-captured.png b/windows/deployment/images/image-captured.png deleted file mode 100644 index 69c5d5ef15..0000000000 Binary files a/windows/deployment/images/image-captured.png and /dev/null differ diff --git a/windows/deployment/images/image.png b/windows/deployment/images/image.png deleted file mode 100644 index 0bbadcb68f..0000000000 Binary files a/windows/deployment/images/image.png and /dev/null differ diff --git a/windows/deployment/images/iso-data.png b/windows/deployment/images/iso-data.png deleted file mode 100644 index f188046b7f..0000000000 Binary files a/windows/deployment/images/iso-data.png and /dev/null differ diff --git a/windows/deployment/images/m365da.png b/windows/deployment/images/m365da.png deleted file mode 100644 index 8f83c3bf8a..0000000000 Binary files a/windows/deployment/images/m365da.png and /dev/null differ diff --git a/windows/deployment/images/m365e.png b/windows/deployment/images/m365e.png deleted file mode 100644 index 2f3ea14906..0000000000 Binary files a/windows/deployment/images/m365e.png and /dev/null differ diff --git a/windows/deployment/images/mbr2gpt-volume.png b/windows/deployment/images/mbr2gpt-volume.png deleted file mode 100644 index d69bed87fb..0000000000 Binary files a/windows/deployment/images/mbr2gpt-volume.png and /dev/null differ diff --git a/windows/deployment/images/mdt-01-fig02.jpg b/windows/deployment/images/mdt-01-fig02.jpg deleted file mode 100644 index 1533bdd336..0000000000 Binary files a/windows/deployment/images/mdt-01-fig02.jpg and /dev/null differ diff --git a/windows/deployment/images/mdt-03-fig01.png b/windows/deployment/images/mdt-03-fig01.png deleted file mode 100644 index fc68fb0c25..0000000000 Binary files a/windows/deployment/images/mdt-03-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-03-fig02.png b/windows/deployment/images/mdt-03-fig02.png deleted file mode 100644 index 934be09dc1..0000000000 Binary files a/windows/deployment/images/mdt-03-fig02.png and /dev/null differ diff --git a/windows/deployment/images/mdt-03-fig03.png b/windows/deployment/images/mdt-03-fig03.png deleted file mode 100644 index a387923d80..0000000000 Binary files a/windows/deployment/images/mdt-03-fig03.png and /dev/null differ diff --git a/windows/deployment/images/mdt-03-fig04.png b/windows/deployment/images/mdt-03-fig04.png deleted file mode 100644 index 437531d2f6..0000000000 Binary files a/windows/deployment/images/mdt-03-fig04.png and /dev/null differ diff --git a/windows/deployment/images/mdt-03-fig05.png b/windows/deployment/images/mdt-03-fig05.png deleted file mode 100644 index a7b8d6ca2e..0000000000 Binary files a/windows/deployment/images/mdt-03-fig05.png and /dev/null differ diff --git a/windows/deployment/images/mdt-04-fig01.png b/windows/deployment/images/mdt-04-fig01.png deleted file mode 100644 index 8a90c1a934..0000000000 Binary files a/windows/deployment/images/mdt-04-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig02.png b/windows/deployment/images/mdt-05-fig02.png deleted file mode 100644 index 1223432581..0000000000 Binary files a/windows/deployment/images/mdt-05-fig02.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig03.png b/windows/deployment/images/mdt-05-fig03.png deleted file mode 100644 index a0ffbec429..0000000000 Binary files a/windows/deployment/images/mdt-05-fig03.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig04.png b/windows/deployment/images/mdt-05-fig04.png deleted file mode 100644 index 778cbae1b7..0000000000 Binary files a/windows/deployment/images/mdt-05-fig04.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig05.png b/windows/deployment/images/mdt-05-fig05.png deleted file mode 100644 index e172a29754..0000000000 Binary files a/windows/deployment/images/mdt-05-fig05.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig07.png b/windows/deployment/images/mdt-05-fig07.png deleted file mode 100644 index 135a2367c1..0000000000 Binary files a/windows/deployment/images/mdt-05-fig07.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig08.png b/windows/deployment/images/mdt-05-fig08.png deleted file mode 100644 index 1f4534e89b..0000000000 Binary files a/windows/deployment/images/mdt-05-fig08.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig09.png b/windows/deployment/images/mdt-05-fig09.png deleted file mode 100644 index a3d0155096..0000000000 Binary files a/windows/deployment/images/mdt-05-fig09.png and /dev/null differ diff --git a/windows/deployment/images/mdt-05-fig10.png b/windows/deployment/images/mdt-05-fig10.png deleted file mode 100644 index 576da23ea6..0000000000 Binary files a/windows/deployment/images/mdt-05-fig10.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig01.png b/windows/deployment/images/mdt-07-fig01.png deleted file mode 100644 index 90635678e8..0000000000 Binary files a/windows/deployment/images/mdt-07-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig08.png b/windows/deployment/images/mdt-07-fig08.png deleted file mode 100644 index 2cbfc47271..0000000000 Binary files a/windows/deployment/images/mdt-07-fig08.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig09.png b/windows/deployment/images/mdt-07-fig09.png deleted file mode 100644 index 245b59072d..0000000000 Binary files a/windows/deployment/images/mdt-07-fig09.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig10.png b/windows/deployment/images/mdt-07-fig10.png deleted file mode 100644 index 2c61e0eb3d..0000000000 Binary files a/windows/deployment/images/mdt-07-fig10.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig11.png b/windows/deployment/images/mdt-07-fig11.png deleted file mode 100644 index ce70374271..0000000000 Binary files a/windows/deployment/images/mdt-07-fig11.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig13.png b/windows/deployment/images/mdt-07-fig13.png deleted file mode 100644 index dae9bd23b8..0000000000 Binary files a/windows/deployment/images/mdt-07-fig13.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig14.png b/windows/deployment/images/mdt-07-fig14.png deleted file mode 100644 index 788e609cf6..0000000000 Binary files a/windows/deployment/images/mdt-07-fig14.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig15.png b/windows/deployment/images/mdt-07-fig15.png deleted file mode 100644 index 5271690c89..0000000000 Binary files a/windows/deployment/images/mdt-07-fig15.png and /dev/null differ diff --git a/windows/deployment/images/mdt-07-fig16.png b/windows/deployment/images/mdt-07-fig16.png deleted file mode 100644 index 995eaa51c7..0000000000 Binary files a/windows/deployment/images/mdt-07-fig16.png and /dev/null differ diff --git a/windows/deployment/images/mdt-08-fig01.png b/windows/deployment/images/mdt-08-fig01.png deleted file mode 100644 index 7e9e650633..0000000000 Binary files a/windows/deployment/images/mdt-08-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-08-fig02.png b/windows/deployment/images/mdt-08-fig02.png deleted file mode 100644 index 7a0a4a1bbb..0000000000 Binary files a/windows/deployment/images/mdt-08-fig02.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig01.png b/windows/deployment/images/mdt-09-fig01.png deleted file mode 100644 index 0549174435..0000000000 Binary files a/windows/deployment/images/mdt-09-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig02.png b/windows/deployment/images/mdt-09-fig02.png deleted file mode 100644 index dd69922d80..0000000000 Binary files a/windows/deployment/images/mdt-09-fig02.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig03.png b/windows/deployment/images/mdt-09-fig03.png deleted file mode 100644 index 56102b2031..0000000000 Binary files a/windows/deployment/images/mdt-09-fig03.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig04.png b/windows/deployment/images/mdt-09-fig04.png deleted file mode 100644 index f123d85af5..0000000000 Binary files a/windows/deployment/images/mdt-09-fig04.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig06.png b/windows/deployment/images/mdt-09-fig06.png deleted file mode 100644 index 49042d95f3..0000000000 Binary files a/windows/deployment/images/mdt-09-fig06.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig07.png b/windows/deployment/images/mdt-09-fig07.png deleted file mode 100644 index a2a9093ff0..0000000000 Binary files a/windows/deployment/images/mdt-09-fig07.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig08.png b/windows/deployment/images/mdt-09-fig08.png deleted file mode 100644 index c73ef398e4..0000000000 Binary files a/windows/deployment/images/mdt-09-fig08.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig09.png b/windows/deployment/images/mdt-09-fig09.png deleted file mode 100644 index 14614aaa42..0000000000 Binary files a/windows/deployment/images/mdt-09-fig09.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig10.png b/windows/deployment/images/mdt-09-fig10.png deleted file mode 100644 index cdcb9709ce..0000000000 Binary files a/windows/deployment/images/mdt-09-fig10.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig11.png b/windows/deployment/images/mdt-09-fig11.png deleted file mode 100644 index dd38911dfc..0000000000 Binary files a/windows/deployment/images/mdt-09-fig11.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig12.png b/windows/deployment/images/mdt-09-fig12.png deleted file mode 100644 index ed363ae01a..0000000000 Binary files a/windows/deployment/images/mdt-09-fig12.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig13.png b/windows/deployment/images/mdt-09-fig13.png deleted file mode 100644 index 5155b0ecf0..0000000000 Binary files a/windows/deployment/images/mdt-09-fig13.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig14.png b/windows/deployment/images/mdt-09-fig14.png deleted file mode 100644 index f294a8d69f..0000000000 Binary files a/windows/deployment/images/mdt-09-fig14.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig15.png b/windows/deployment/images/mdt-09-fig15.png deleted file mode 100644 index f8de66afbd..0000000000 Binary files a/windows/deployment/images/mdt-09-fig15.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig16.png b/windows/deployment/images/mdt-09-fig16.png deleted file mode 100644 index ad04b64077..0000000000 Binary files a/windows/deployment/images/mdt-09-fig16.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig17.png b/windows/deployment/images/mdt-09-fig17.png deleted file mode 100644 index fe4503b950..0000000000 Binary files a/windows/deployment/images/mdt-09-fig17.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig18.png b/windows/deployment/images/mdt-09-fig18.png deleted file mode 100644 index 4f087172d9..0000000000 Binary files a/windows/deployment/images/mdt-09-fig18.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig19.png b/windows/deployment/images/mdt-09-fig19.png deleted file mode 100644 index 917444c811..0000000000 Binary files a/windows/deployment/images/mdt-09-fig19.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig20.png b/windows/deployment/images/mdt-09-fig20.png deleted file mode 100644 index 6c2d1c4dba..0000000000 Binary files a/windows/deployment/images/mdt-09-fig20.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig21.png b/windows/deployment/images/mdt-09-fig21.png deleted file mode 100644 index 628ea98ad9..0000000000 Binary files a/windows/deployment/images/mdt-09-fig21.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig22.png b/windows/deployment/images/mdt-09-fig22.png deleted file mode 100644 index 9d71f62796..0000000000 Binary files a/windows/deployment/images/mdt-09-fig22.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig23.png b/windows/deployment/images/mdt-09-fig23.png deleted file mode 100644 index 4cd29dc389..0000000000 Binary files a/windows/deployment/images/mdt-09-fig23.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig24.png b/windows/deployment/images/mdt-09-fig24.png deleted file mode 100644 index 89cb67a048..0000000000 Binary files a/windows/deployment/images/mdt-09-fig24.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig25.png b/windows/deployment/images/mdt-09-fig25.png deleted file mode 100644 index fb308c0be5..0000000000 Binary files a/windows/deployment/images/mdt-09-fig25.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig26.png b/windows/deployment/images/mdt-09-fig26.png deleted file mode 100644 index 681c6516cd..0000000000 Binary files a/windows/deployment/images/mdt-09-fig26.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig27.png b/windows/deployment/images/mdt-09-fig27.png deleted file mode 100644 index 396290346d..0000000000 Binary files a/windows/deployment/images/mdt-09-fig27.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig28.png b/windows/deployment/images/mdt-09-fig28.png deleted file mode 100644 index d36dda43fa..0000000000 Binary files a/windows/deployment/images/mdt-09-fig28.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig29.png b/windows/deployment/images/mdt-09-fig29.png deleted file mode 100644 index 404842d49c..0000000000 Binary files a/windows/deployment/images/mdt-09-fig29.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig30.png b/windows/deployment/images/mdt-09-fig30.png deleted file mode 100644 index be962f40ec..0000000000 Binary files a/windows/deployment/images/mdt-09-fig30.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig31.png b/windows/deployment/images/mdt-09-fig31.png deleted file mode 100644 index a40aa9d3bb..0000000000 Binary files a/windows/deployment/images/mdt-09-fig31.png and /dev/null differ diff --git a/windows/deployment/images/mdt-09-fig32.png b/windows/deployment/images/mdt-09-fig32.png deleted file mode 100644 index 446812a3e8..0000000000 Binary files a/windows/deployment/images/mdt-09-fig32.png and /dev/null differ diff --git a/windows/deployment/images/mdt-10-fig01.png b/windows/deployment/images/mdt-10-fig01.png deleted file mode 100644 index 8a3ebd9711..0000000000 Binary files a/windows/deployment/images/mdt-10-fig01.png and /dev/null differ diff --git a/windows/deployment/images/mdt-10-fig05.png b/windows/deployment/images/mdt-10-fig05.png deleted file mode 100644 index 8625f2972b..0000000000 Binary files a/windows/deployment/images/mdt-10-fig05.png and /dev/null differ diff --git a/windows/deployment/images/mdt-10-fig06.png b/windows/deployment/images/mdt-10-fig06.png deleted file mode 100644 index 91dc7c5c33..0000000000 Binary files a/windows/deployment/images/mdt-10-fig06.png and /dev/null differ diff --git a/windows/deployment/images/mdt-10-fig09.png b/windows/deployment/images/mdt-10-fig09.png deleted file mode 100644 index bb5010a93d..0000000000 Binary files a/windows/deployment/images/mdt-10-fig09.png and /dev/null differ diff --git a/windows/deployment/images/mdt-apps.png b/windows/deployment/images/mdt-apps.png deleted file mode 100644 index 72ee2268f2..0000000000 Binary files a/windows/deployment/images/mdt-apps.png and /dev/null differ diff --git a/windows/deployment/images/mdt-monitoring.png b/windows/deployment/images/mdt-monitoring.png deleted file mode 100644 index c49732223a..0000000000 Binary files a/windows/deployment/images/mdt-monitoring.png and /dev/null differ diff --git a/windows/deployment/images/mdt-offline-media.png b/windows/deployment/images/mdt-offline-media.png deleted file mode 100644 index d81ea4e0d8..0000000000 Binary files a/windows/deployment/images/mdt-offline-media.png and /dev/null differ diff --git a/windows/deployment/images/mdt-post-upg.png b/windows/deployment/images/mdt-post-upg.png deleted file mode 100644 index f41d2ff32b..0000000000 Binary files a/windows/deployment/images/mdt-post-upg.png and /dev/null differ diff --git a/windows/deployment/images/mdt-replace.png b/windows/deployment/images/mdt-replace.png deleted file mode 100644 index d731037d38..0000000000 Binary files a/windows/deployment/images/mdt-replace.png and /dev/null differ diff --git a/windows/deployment/images/mdt-rules.png b/windows/deployment/images/mdt-rules.png deleted file mode 100644 index b01c519635..0000000000 Binary files a/windows/deployment/images/mdt-rules.png and /dev/null differ diff --git a/windows/deployment/images/mdt-upgrade-proc.png b/windows/deployment/images/mdt-upgrade-proc.png deleted file mode 100644 index 07a968aed0..0000000000 Binary files a/windows/deployment/images/mdt-upgrade-proc.png and /dev/null differ diff --git a/windows/deployment/images/mdt-upgrade.png b/windows/deployment/images/mdt-upgrade.png deleted file mode 100644 index c794526ad5..0000000000 Binary files a/windows/deployment/images/mdt-upgrade.png and /dev/null differ diff --git a/windows/deployment/images/monitor-pc0001.png b/windows/deployment/images/monitor-pc0001.png deleted file mode 100644 index 072b9cb58c..0000000000 Binary files a/windows/deployment/images/monitor-pc0001.png and /dev/null differ diff --git a/windows/deployment/images/office-folder.png b/windows/deployment/images/office-folder.png deleted file mode 100644 index 722cc4d664..0000000000 Binary files a/windows/deployment/images/office-folder.png and /dev/null differ diff --git a/windows/deployment/images/pc0005-vm-office.png b/windows/deployment/images/pc0005-vm-office.png deleted file mode 100644 index bb8e96f5af..0000000000 Binary files a/windows/deployment/images/pc0005-vm-office.png and /dev/null differ diff --git a/windows/deployment/images/pc0005-vm.png b/windows/deployment/images/pc0005-vm.png deleted file mode 100644 index 4b2af635c4..0000000000 Binary files a/windows/deployment/images/pc0005-vm.png and /dev/null differ diff --git a/windows/deployment/images/pc0006.png b/windows/deployment/images/pc0006.png deleted file mode 100644 index 6162982966..0000000000 Binary files a/windows/deployment/images/pc0006.png and /dev/null differ diff --git a/windows/deployment/images/s-mode-flow-chart.png b/windows/deployment/images/s-mode-flow-chart.png deleted file mode 100644 index c3c43cc027..0000000000 Binary files a/windows/deployment/images/s-mode-flow-chart.png and /dev/null differ diff --git a/windows/deployment/images/smodeconfig.png b/windows/deployment/images/smodeconfig.png deleted file mode 100644 index 2ab1fc0813..0000000000 Binary files a/windows/deployment/images/smodeconfig.png and /dev/null differ diff --git a/windows/deployment/images/support-cycle.png b/windows/deployment/images/support-cycle.png deleted file mode 100644 index 3f4b4e87c0..0000000000 Binary files a/windows/deployment/images/support-cycle.png and /dev/null differ diff --git a/windows/deployment/images/thinkstation.png b/windows/deployment/images/thinkstation.png deleted file mode 100644 index 7a144ec5b3..0000000000 Binary files a/windows/deployment/images/thinkstation.png and /dev/null differ diff --git a/windows/deployment/images/upgrademdt-fig5-winupgrade.png b/windows/deployment/images/upgrademdt-fig5-winupgrade.png deleted file mode 100644 index f3bc05508a..0000000000 Binary files a/windows/deployment/images/upgrademdt-fig5-winupgrade.png and /dev/null differ diff --git a/windows/deployment/images/wds-deprecation.png b/windows/deployment/images/wds-deprecation.png deleted file mode 100644 index 2c6b02022e..0000000000 Binary files a/windows/deployment/images/wds-deprecation.png and /dev/null differ diff --git a/windows/deployment/images/x_blk.png b/windows/deployment/images/x_blk.png deleted file mode 100644 index 69432ff71c..0000000000 Binary files a/windows/deployment/images/x_blk.png and /dev/null differ diff --git a/windows/deployment/planning/applying-filters-to-data-in-the-sua-tool.md b/windows/deployment/planning/applying-filters-to-data-in-the-sua-tool.md deleted file mode 100644 index 34bf0d7f22..0000000000 --- a/windows/deployment/planning/applying-filters-to-data-in-the-sua-tool.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: Applying Filters to Data in the SUA Tool (Windows 10) -description: Learn how to apply filters to results from the Standard User Analyzer (SUA) tool while testing your application. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Applying Filters to Data in the SUA Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -On the user interface for the Standard User Analyzer (SUA) tool, you can apply filters to the issues that the tool has found so that you can view only the information that interests you. - -**To apply filters to data in the SUA tool** - -1. Use the SUA tool to test an application. For more information, see [Using the SUA Tool](using-the-sua-tool.md). - -2. After you finish testing, in the SUA tool, click a tab that shows issues that the SUA tool has found. All tabs except the **App Info** tab can show issues. - -3. On the **Options** menu, click a command that corresponds to the filter that you want to apply. The following table describes the commands. - - |Options menu command|Description| - |--- |--- | - |**Filter Noise**|Filters noise from the issues.

This command is selected by default.| - |**Load Noise Filter File**|Opens the **Open Noise Filter File** dialog box, in which you can load an existing noise filter (.xml) file.| - |**Export Noise Filter File**|Opens the **Save Noise Filter File** dialog box, in which you can save filter settings as a noise filter (.xml) file.| - |**Only Display Records with Application Name in StackTrace**|Filters out records that do not have the application name in the stack trace.

However, because the SUA tool captures only the first 32 stack frames, this command can also filter out real issues with the application where the call stack is deeper than 32 frames.| - |**Show More Details in StackTrace**|Shows additional stack frames that are related to the SUA tool, but not related to the diagnosed application.| - |**Warn Before Deleting AppVerifier Logs**|Displays a warning message before the SUA tool deletes all of the existing SUA-related log files on the computer.

This command is selected by default.| - |**Logging**|Provides the following logging-related options:

  • Show or hide log errors.
  • Show or hide log warnings.
  • Show or hide log information.

To maintain a manageable file size, we recommend that you do not select the option to show informational messages.| - - diff --git a/windows/deployment/planning/available-data-types-and-operators-in-compatibility-administrator.md b/windows/deployment/planning/available-data-types-and-operators-in-compatibility-administrator.md deleted file mode 100644 index 1b714e4247..0000000000 --- a/windows/deployment/planning/available-data-types-and-operators-in-compatibility-administrator.md +++ /dev/null @@ -1,76 +0,0 @@ ---- -title: Available Data Types and Operators in Compatibility Administrator (Windows 10) -description: The Compatibility Administrator tool provides a way to query your custom-compatibility databases. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Available Data Types and Operators in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Compatibility Administrator tool provides a way to query your custom-compatibility databases. - -## Available Data Types - -Customized-compatibility databases in Compatibility Administrator contain the following data types. - -- **Integer**. A numerical value with no fractional part. All integers are unsigned because none of the attributes can have a negative value. - -- **String**. A series of alphanumeric characters manipulated as a group. - -- **Boolean**. A value of True or False. - -## Available Attributes - -The following table shows the attributes you can use for querying your customized-compatibility databases in Compatibility Administrator. - -|Attribute|Description|Data type| -|--- |--- |--- | -|APP_NAME|Name of the application.|String| -|DATABASE_GUID|Unique ID for your compatibility database.|String| -|DATABASE_INSTALLED|Specifies if you have installed the database.|Boolean| -|DATABASE_NAME|Descriptive name of your database.|String| -|DATABASE_PATH|Location of the database on your computer.|String| -|FIX_COUNT|Number of compatibility fixes applied to a specific application.|Integer| -|FIX_NAME|Name of your compatibility fix.|String| -|MATCH_COUNT|Number of matching files for a specific, fixed application.|Integer| -|MATCHFILE_NAME|Name of a matching file used to identify a specific, fixed application.|String| -|MODE_COUNT|Number of compatibility modes applied to a specific, fixed application.|Integer| -|MODE_NAME|Name of your compatibility mode.|String| -|PROGRAM_APPHELPTYPE|Type of AppHelp message applied to an entry. The value can be 1 or 2, where 1 enables the program to run and 2 blocks the program.|Integer| -|PROGRAM_DISABLED|Specifies if you disabled the compatibility fix for an application. If True, Compatibility Administrator does not apply the fixes to the application.|Boolean| -|PROGRAM_GUID|Unique ID for an application.|String| -|PROGRAM_NAME|Name of the application that you are fixing.|String| - -## Available Operators - -The following table shows the operators that you can use for querying your customized-compatibility databases in the Compatibility Administrator. - -|Symbol|Description|Data type|Precedence| -|--- |--- |--- |--- | -|>|Greater than|Integer or string|1| -|>=|Greater than or equal to|Integer or string|1| -|<|Less than|Integer or string|1| -|<=|Less than or equal to|Integer or string|1| -|<>|Not equal to|Integer or string|1| -|=|Equal to|Integer, string, or Boolean|1| -|HAS|A special SQL operator used to check if the left-hand operand contains a substring specified by the right-hand operand.|Left-hand operand. MATCHFILE_NAME, MODE_NAME, FIX_NAME

Note: Only the HAS operator can be applied to the MATCHFILE_NAME, MODE_NAME, and FIX_NAME attributes.

Right-hand operand. String|1| -|OR|Logical OR operator|Boolean|2| -|AND|Logical AND operator|Boolean|2| - -## Related topics - -[Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md) diff --git a/windows/deployment/planning/compatibility-administrator-users-guide.md b/windows/deployment/planning/compatibility-administrator-users-guide.md deleted file mode 100644 index 4e8ee9cb22..0000000000 --- a/windows/deployment/planning/compatibility-administrator-users-guide.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: Compatibility Administrator User's Guide (Windows 10) -manager: aaroncz -ms.author: frankroj -description: The Compatibility Administrator tool helps you resolve potential application-compatibility issues before deploying a new version of Windows. -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Compatibility Administrator User's Guide - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Compatibility Administrator tool helps you resolve potential application-compatibility issues before deploying a new version of Windows to your organization. Compatibility Administrator provides: - -- Compatibility fixes, compatibility modes, and AppHelp messages that you can use to resolve specific compatibility issues. - -- Tools for creating customized compatibility fixes, compatibility modes, AppHelp messages, and compatibility databases. - -- A query tool that you can use to search for installed compatibility fixes on your local computers. - -The following flowchart shows the steps for using the Compatibility Administrator tool to create your compatibility fixes, compatibility modes, and AppHelp messages. - -![act compatibility admin flowchart.](images/dep-win8-l-act-compatadminflowchart.jpg) - -> [!IMPORTANT] -> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create and work with custom databases for 32-bit applications, and the 64-bit version to create and work with custom databases for 64-bit applications. - -## In this section - -|Topic|Description| -|--- |--- | -|[Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md)|This section provides information about using the Compatibility Administrator tool.| -|[Managing Application-Compatibility Fixes and Custom Fix Databases](managing-application-compatibility-fixes-and-custom-fix-databases.md)|This section provides information about managing your application-compatibility fixes and custom-compatibility fix databases. This section explains the reasons for using compatibility fixes and how to deploy custom-compatibility fix databases.| -|[Using the Sdbinst.exe Command-Line Tool](using-the-sdbinstexe-command-line-tool.md)|Ensure that you deploy your customized database (.Sdb) files to other computers in your organization before your compatibility fixes, compatibility modes, and AppHelp messages are applied. You can deploy your customized database files in several ways, including, by using a logon script, by using Group Policy, or by performing file copy operations.| diff --git a/windows/deployment/planning/compatibility-fix-database-management-strategies-and-deployment.md b/windows/deployment/planning/compatibility-fix-database-management-strategies-and-deployment.md deleted file mode 100644 index acd338e940..0000000000 --- a/windows/deployment/planning/compatibility-fix-database-management-strategies-and-deployment.md +++ /dev/null @@ -1,163 +0,0 @@ ---- -title: Compatibility Fix Database Management Strategies and Deployment (Windows 10) -manager: aaroncz -ms.author: frankroj -description: Learn how to deploy your compatibility fixes into an application-installation package or through a centralized compatibility-fix database. -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Compatibility Fix Database Management Strategies and Deployment - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -To use fixes in application-compatibility mitigation strategy, define a strategy to manage your custom compatibility-fix database. Typically, you can use one of the two following approaches: - -- Deploying your compatibility fixes as part of an application-installation package. - -- Deploying your compatibility fixes through a centralized compatibility-fix database. - -Microsoft provides general recommends the following remedies for improving the management of your custom compatibility-fix databases. - -> [!NOTE] -> These recommendations are not based on irrespective of the approach you decide to use. The following are the general recommendations. - -- **Define standards for when you will apply compatibility fixes** - - Ensure that the standards and scenarios for using compatibility fixes are defined, based on your specific business and technology needs. - -- **Define standards for your custom compatibility-fix databases** - - Compatibility fixes must include a version check, so that mapping to particular applications becomes easy. Ensure that your compatibility fixes always, so that the fix won't be applied to newer versions of your applications. - -- **Define your resources responsible for addressing questions and enforcing your standards** - - Ensure you determine who will be responsible for staying current with the technology and standards that are related to your compatibility fixes and custom compatibility-fix databases. As your databases are managed over time, ensure that someone in your organization stays current with the relevant technology. - -## Strategies for Deploying Your Compatibility Fixes - - -We recommend the usage of one of the two strategies to deploy your compatibility fixes into your organization. They are: - -- Deploying your compatibility fixes as part of an application-installation package. - -- Deploying your compatibility fixes through a centralized compatibility-fix database. - -Determine which method best meets your organization's deployment needs. - -### Deploying Fixes as Part of an Application-Installation Package - -One strategy to deploy compatibility fixes is to create a custom compatibility-fix database that contains a single entry that is applied directly to the application-installation package. While this method is the most straightforward one for deployment, it has been shown that this method can become overly complex, especially if you are fixing a large number of applications. - -If the following considerations apply to your organization, you should avoid this strategy and instead consider using a centralized compatibility-fix database, as described in the next section. - -- **How many applications require compatibility fixes?** - - Custom compatibility-fix databases are actual databases. Therefore, if you have 1000 applications to be fixed, it will take longer to open and query 1000 single-row databases for a match, instead of a single database with 1000 rows. - -- **Will you be able to track which applications are installed on which computer?** - - You might determine that your initial set of compatibility fixes isn't comprehensive, and that you must deploy an updated version of the compatibility-fix database to resolve the other issues. If you deployed the initial set by using the application-installation package, you'll be required to locate each client computer that is running the application and replace the compatibility fix. - -### Deploying Fixes Through a Centralized Compatibility-Fix Database - -The other recommended strategy for deploying compatibility fixes into your organization is to create and manage either a single custom compatibility-fix database, or else to create and manage several custom databases for large subsets of your organization. This strategy will help to enforce your company policy and to provide consistent updates for application fixes that you discover later. - -This approach tends to work best for organizations that have a well-developed deployment infrastructure in place, with centralized ownership of the process. We recommend that you consider the following before using this approach: - -- Does your organization have the tools required to deploy and update a compatibility-fix database for all of the affected computers? - - If you intend to manage a centralized compatibility-fix database, you must verify that your organization has the required tools to deploy and update all of the affected computers in your organization. - -- Do you have centralized resources that can manage and update the centralized compatibility-fix database? - - Ensure that you've identified the appropriate owners for the deployment process, for the applications, and for the database updates, in addition to determining the process by which compatibility issues can be deployed to specific computers. - -### Merging Centralized Compatibility-Fix Databases - -If you decide to use the centralized compatibility-fix database deployment strategy, you can merge any of your individual compatibility-fix databases. This provision enables you to create a single custom compatibility-fix database that can be used to search for and determine whether Windows® should apply a fix to a specific executable (.exe) file. We recommend merging your databases based on the following process. - -**To merge your custom-compatibility databases** - -1. Verify that your application-compatibility testers are performing their tests on computers with the latest version of your compatibility-fix database. For example, Custom DB1. - -2. If the tester determines that an application requires an extra compatibility fix that isn't a part of the original compatibility-fix database, the tester must create a new custom compatibility database with all of the required information for that single fix, for example, Custom DB2. - -3. The tester applies the new Custom DB2 information to the application and then tests for both the functionality and integration, to ensure that the compatibility issues are addressed. - -4. After the application passes all of the required functionality and integration tests, the tester can send Custom DB2 to the team that manages the central compatibility-fix database. - -5. The team that manages the centralized database opens Custom DB1 and uses the Compatibility Administrator to include the new compatibility fixes that were included in Custom DB2. - - > [!NOTE] - > Custom DB1 contains a unique GUID that makes updating the database easier. For example, if you install a new version of the custom compatibility-fix database that uses the same GUID as the previous version, the computer will automatically uninstall the old version. - - - -6. The centralized management team then redeploys the new version of Custom DB1 to all of the end users in your organization. - -### Deploying Your Custom Compatibility-Fix Databases - -Deploying your custom compatibility-fix database into your organization requires you to perform the following actions: - -1. Store your custom compatibility-fix database (.sib file) in a location that is accessible to all of your organization's computers. - -2. Use the Sdbinst.exe command-line tool to install the custom compatibility-fix database locally. - -In order to meet the two requirements above, we recommend that you use one of the following two methods: - -- **Using a Windows Installer package and a custom script** - - You can package your .sib file and a custom deployment script into a file with the .msi extension, and then deploy the .msi file into your organization. - - > [!IMPORTANT] - > Ensure that you mark your custom script so that it does not impersonate the calling user. For example, if you use Microsoft® Visual Basic® Scripting Edition (VBScript), the custom action type would be: - >`msidbCustomActionTypeVBScript + msidbCustomActionTypeInScript + msidbCustomActionTypeNoImpersonate = 0x0006 + 0x0400 + 0x0800 = 0x0C06 = 3078 decimal)` - - -- **Using a network share and a custom script** - -You can store the .sib file on your network share, and then call to a script available on your specified computers. - -> [!IMPORTANT] -> Ensure that you call the script at a time when it can receive elevated rights. For example, you should call the script by using computer startup scripts instead of a user logon script. You must also ensure that the installation of the custom compatibility-fix database occurs with Administrator rights. - - - -### Example Script for installation of .sib File based on .msi File - -The following examples show an installation of a custom compatibility-fix database based on a .msi file. - -``` -'InstallSDB.vbs -Function Install -Dim WshShell -Set WshShell = CreateObject("WScript.Shell") -WshShell.Run "sdbinst.exe -q " & CHR(34) & "%ProgramFiles%\MyOrganizationSDB\MyOrg.sdb" & CHR(34), 0, true -WshShell.Run "cmd.exe /c " & CHR(34) & "del " & CHR(34) & "%ProgramFiles%\MyOrganizationSDB\MyOrg.sdb" & CHR(34) & CHR(34), 0 -WshShell.Run "reg.exe delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{guidFromMyOrgsSdb}.sdb /f", 0 -End Function - -Function UnInstall -Dim WshShell -Set WshShell = CreateObject("WScript.Shell") -WshShell.Run "sdbinst.exe -q -u -g {guidFromMyOrgsSdb}", 0 -End Function -``` - -### Initial Deployment and Updates - -Application-compatibility is tested, from which issues are reported, even before a new Windows operating system is deployed. To handle these issues, include the custom compatibility-fix database, which includes all of your known issues, in your corporate image. Later, update your compatibility-fix database; provide the updates by using one of the two mechanisms that are described in the "Deploying Your Custom Compatibility Fix Databases" section. - -## Related articles -[Managing Application-Compatibility Fixes and Custom Fix Databases](managing-application-compatibility-fixes-and-custom-fix-databases.md) diff --git a/windows/deployment/planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md b/windows/deployment/planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md deleted file mode 100644 index 6148602a62..0000000000 --- a/windows/deployment/planning/compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: Compatibility Fixes for Windows 10, Windows 8, Windows 7, & Windows Vista -description: Find released compatibility fixes for all Windows operating systems from Windows Vista through Windows 10. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Compatibility Fixes for Windows 10, Windows 8, Windows 7, and Windows Vista - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -You can fix some compatibility issues that are due to the changes made between Windows operating system versions. These issues can include User Account Control (UAC) restrictions. - -> [!IMPORTANT] -> The Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator. You must use the 32-bit version for 32-bit applications and the 64-bit version to work for 64-bit applications. You will receive an error message if you try to use the wrong version. - -If you start the Compatibility Administrator as an Administrator (with elevated privileges), all repaired applications can run successfully; however, virtualization and redirection might not occur as expected. To verify that a compatibility fix addresses an issue, you must test the repaired application by running it under the destination user account. - -## Compatibility Fixes - -The following table lists the known released compatibility fixes for all Windows operating systems from Windows Vista through Windows 10. The fixes are listed in alphabetical order. - -|Fix|Fix Description| -|--- |--- | -|8And16BitAggregateBlts|8/16-bit mitigation can cause performance issues in applications. This layer aggregates all the blt operations and improves performance.| -|8And16BitDXMaxWinMode|The 8/16-bit mitigation runs applications that use DX8/9 in a maximized windowed mode. This layer mitigates applications that exhibit graphical corruption in full screen mode.| -|8And16BitGDIRedraw|This fix repairs applications that use GDI and that work in 8-bit color mode. The application is forced to repaint its window on RealizePalette.| -|AccelGdipFlush|This fix increases the speed of GdipFlush, which has perf issues in DWM.| -|AoaMp4Converter|This fix resolves a display issue for the AoA Mp4 Converter.| -|BIOSRead|This problem is indicated when an application can't access the **Device\PhysicalMemory** object beyond the kernel-mode drivers, on any of the Windows Server® 2003 operating systems.

The fix enables OEM executable (.exe) files to use the GetSystemFirmwareTable function instead of the NtOpenSection function when the BIOS is queried for the **\Device\Physical** memory information.| -|BlockRunasInteractiveUser|This problem occurs when **InstallShield** creates installers and uninstallers that fail to complete and that generate error messages or warnings.

The fix blocks **InstallShield** from setting the value of RunAs registry keys to InteractiveUser Because InteractiveUser no longer has Administrator rights.

**Note:** For more detailed information about this application fix, see [Using the BlockRunAsInteractiveUser Fix](/previous-versions/windows/it-pro/windows-7/dd638336(v=ws.10)).
| -|ChangeFolderPathToXPStyle|This fix is required when an application can't return shell folder paths when it uses the **SHGetFolder** API.

The fix intercepts the **SHGetFolder**path request to the common **appdata** file path and returns the Windows® XP-style file path instead of the Windows Vista-style file path.| -|ClearLastErrorStatusonIntializeCriticalSection|This fix is indicated when an application fails to start.

The fix modifies the InitializeCriticalSection function call so that it checks the NTSTATUS error code, and then sets the last error to ERROR_SUCCESS.| -|CopyHKCUSettingsFromOtherUsers|This problem occurs when an application's installer must run in elevated mode and depends on the HKCU settings that are provided for other users.

The fix scans the existing user profiles and tries to copy the specified keys into the HKEY_CURRENT_USER registry area.

You can control this fix further by entering the relevant registry keys as parameters that are separated by the ^ Symbol; for example: Software\MyCompany\Key1^Software\MyCompany\Key2.

**Note:** For more detailed information about this application fix, see [Using the CopyHKCUSettingsFromOtherUsers Fix](/previous-versions/windows/it-pro/windows-7/dd638375(v=ws.10)).
| -|CorrectCreateBrushIndirectHatch|This problem occurs when an access violation error message displays and the application fails when you select or crop an image.

The fix corrects the brush style hatch value, which is passed to the CreateBrushIndirect() function and enables the information to be correctly interpreted.| -|CorrectFilePaths|This problem occurs when:

  • An application tries to write files to the hard disk and is denied access.
  • An application receives a file not found or path not found error message.

The fix modifies the file path names to point to a new location on the hard disk.

**Note:** For more detailed information about the CorrectFilePaths application fix, see [Using the CorrectFilePaths Fix](/previous-versions/windows/it-pro/windows-7/cc766201(v=ws.10)). We recommend that you use this fix together with the CorrectFilePathsUninstall fix if you're applying it to a setup installation file.
| -|CorrectFilePathsUninstall|This problem occurs when an uninstalled application leaves behind files, directories, and links.

The fix corrects the file paths that are used by the uninstallation process of an application.

**Note:** For more detailed information about this fix, see [Using the CorrectFilePathsUninstall Fix](/previous-versions/windows/it-pro/windows-7/dd638414(v=ws.10)). We recommend that you use this fix together with the CorrectFilePaths fix if you're applying it to a setup installation file.
| -|CorrectShellExecuteHWND|This problem occurs when you start an executable (.exe) and:
  • A taskbar item blinks instead of an elevation prompt being opened, or when the application doesn't provide a valid HWND value when it calls the ShellExecute(Ex) function.

    The fix intercepts the ShellExecute(Ex) calls, and then inspects the HWND value. If the value is invalid, this fix enables the call to use the currently active HWND value.

    **Note:** For more detailed information about the CorrectShellExecuteHWND application fix, see [Using the CorrectShellExecuteHWND Fix](/previous-versions/windows/it-pro/windows-7/cc722028(v=ws.10)).
    | -|CustomNCRender|This fix instructs DWM to not render the non-client area forcing the application to do its own NC rendering. This issue often gives windows an XP look.| -|DelayApplyFlag|This fix applies a KERNEL, USER, or PROCESS flag if the specified DLL is loaded.

    You can control this fix further by typing the following command at the command prompt:

    `DLL_Name;Flag_Type;Hexidecimal_Value`
    Where the DLL_Name is the name of the specific DLL, including the file extension. Flag_Type is KERNEL, USER, or PROCESS, and a Hexidecimal_Value, starting with 0x and up to 64 bits long.

    **Note:** The PROCESS flag type can have a 32-bit length only. You can separate multiple entries with a backslash ().
    | -|DeprecatedServiceShim|The problem is indicated when an application tries to install a service that has a dependency on a deprecated service. An error message displays.

    The fix intercepts the CreateService function calls and removes the deprecated dependency service from the lpDependencies parameter.

    You can control this fix further by typing the following command at the command prompt:

    `Deprecated_Service\App_Service/Deprecated_Service2 \App_Service2` where:

    • Deprecated_Service is the name of the deprecated service
    • App_Service is the name of the specific application service that is to be modified
    For example, NtLmSsp\WMI.
    **Note:** If you don't provide an App_Service name, the deprecated service is removed from all newly created services.
    **Note:** You can separate multiple entries with a forward slash (/).
    | -|DirectXVersionLie|This problem occurs when an application fails because it doesn't find the correct version number for DirectX®.

    The fix modifies the DXDIAGN GetProp function call to return the correct DirectX version.

    You can control this fix further by typing the following command at the command prompt:
    `MAJORVERSION.MINORVERSION.LETTER`

    For example, 9.0.c.| -|DetectorDWM8And16Bit|This fix offers mitigation for applications that work in 8/16-bit display color mode because these legacy color modes aren't supported in Windows 8 .| -|Disable8And16BitD3D|This fix improves performance of 8/16-bit color applications that render using D3D and don't mix direct draw.| -|Disable8And16BitModes|This fix disables 8/16-bit color mitigation and enumeration of 8/16-bit color modes.| -|DisableDWM|The problem occurs when some objects aren't drawn or object artifacts remain on the screen in an application.

    The fix temporarily disables the Windows Aero menu theme functionality for unsupported applications.

    **Note:** For more detailed information about this application fix, see [Using the DisableDWM Fix](/previous-versions/windows/it-pro/windows-7/cc722418(v=ws.10)).
    | -|DisableFadeAnimations|The problem is indicated when an application fades animation, buttons, or other controls don't function properly.

    The fix disables the fade animations functionality for unsupported applications.| -|DisableThemeMenus|The problem occurs when an application behaves unpredictably when it tries to detect and use the correct Windows settings.

    The fix temporarily disables the Windows Aero menu theme functionality for unsupported applications.| -|DisableWindowsDefender|The fix disables Windows Defender for security applications that don't work with Windows Defender.| -|DWM8And16BitMitigation|The fix offers mitigation for applications that work in 8/16-bit display color mode because these legacy color modes aren't supported in Windows 8.| -|DXGICompat|The fix allows application-specific compatibility instructions to be passed to the DirectX engine.| -|DXMaximizedWindowedMode|Applications that use DX8/9 are run in a maximized windowed mode. This is required for applications that use GDI/DirectDraw in addition to Direct3D.| -|ElevateCreateProcess|The problem is indicated when:

    • installations
    • de-installations
    • updates
    fail because the host process calls the CreateProcess function and it returns an ERROR_ELEVATION_REQUIRED error message.

    The fix handles the error code and attempts to recall the CreateProcess function together with requested elevation. If the fixed application already has a UAC manifest, the error code is returned unchanged.

    **Note:** For more detailed information about this application fix, see [Using the ElevateCreateProcess Fix](/previous-versions/windows/it-pro/windows-7/cc722422(v=ws.10)).
    | -|EmulateOldPathIsUNC|The problem occurs when an application fails because of an incorrect UNC path.

    The fix exchanges the PathIsUNC function to return a value of True for UNC paths in Windows.| -|EmulateGetDiskFreeSpace|The problem is indicated when an application fails to install or to run. An error message is generated that there isn't enough free disk space to install or use the application. The error message occurs even though there's enough free disk space to meet the application requirements.

    The fix determines the amount of free space. If the amount of free space is larger than 2 GB, the compatibility fix returns a value of 2 GB. However, if the amount of free space is smaller than 2 GB, the compatibility fix returns the actual-free space amount.

    **Note:** For more detailed information about this application fix, see [Using the EmulateGetDiskFreeSpace Fix](/previous-versions/windows/it-pro/windows-7/ff720129(v=ws.10)).
    | -|EmulateSorting|The problem occurs when an application experiences search functionality issues.

    The fix forces applications that use the CompareStringW/LCMapString sorting table to use an older version of the table.

    **Note:** For more detailed information about this e application fix, see [Using the EmulateSorting Fix](/previous-versions/windows/it-pro/windows-7/cc749209(v=ws.10)).
    | -|EmulateSortingWindows61|The fix emulates the sorting order of Windows 7 and Windows Server 2008 R2 for various APIs.| -|EnableRestarts|The problem is indicated when an application and computer appear to hang because processes can't end to allow the computer to complete its restart processes.

    The fix enables the computer to restart and finish the installation process by verifying and enabling that the SeShutdownPrivilege service privilege exists.

    **Note:** For more detailed information about this application fix, see [Using the EnableRestarts Fix](/previous-versions/windows/it-pro/windows-7/ff720128(v=ws.10)).
    | -|ExtraAddRefDesktopFolder|The problem occurs when an application invokes the Release() method too many times and causes an object to be prematurely destroyed.

    The fix invokes the AddRef() method on the Desktop folder, which the SHGetDesktopFolder function returns, to counteract the problem.| -|FailObsoleteShellAPIs|The problem occurs when an application fails because it generated deprecated API calls.

    The fix either fully implements the obsolete functions or implements the obsolete functions with stubs that fail.

    **Note:** You can type FailAll=1 at the command prompt to suppress the function implementation and force all functions to fail.
    | -|FailRemoveDirectory|The problem occurs when an application uninstall process doesn't remove all of the application files and folders.

    This fix fails calls to RemoveDirectory() when called with a path matching the one specified in the shim command line. Only a single path is supported. The path can contain environment variables, but must be an exact path - no partial paths are supported.

    The fix resolves an issue where an application expects RemoveDirectory() to delete a folder immediately even though a handle is open to it.| -|FakeLunaTheme|The problem occurs when a theme application doesn't properly display: the colors are washed out or the user interface isn't detailed.

    The fix intercepts the GetCurrentThemeName API and returns the value for the Windows XP default theme (Luna).

    **Note:** For more detailed information about the FakeLunaTheme application fix, see [Using the FakeLunaTheme Fix](/previous-versions/windows/it-pro/windows-7/cc766315(v=ws.10)).
    | -|FlushFile|This problem is indicated when a file is updated and changes don't immediately appear on the hard disk. Applications can't see the file changes.

    The fix enables the WriteFile function to call to the FlushFileBuffers APIs, which flush the file cache onto the hard disk.| -|FontMigration|The fix replaces an application-requested font with a better font selection, to avoid text truncation.| -|ForceAdminAccess|The problem occurs when an application fails to function during an explicit administrator check.

    The fix allows the user to temporarily imitate being a part of the Administrators group by returning a value of True during the administrator check.

    **Note:** For more detailed information about this application fix, see [Using the ForceAdminAccess Fix](/previous-versions/windows/it-pro/windows-7/cc766024(v=ws.10)).
    | -|ForceInvalidateOnClose|The fix invalidates any windows that exist under a closing or hiding window for applications that rely on the invalidation messages.| -|ForceLoadMirrorDrvMitigation|The fix loads the Windows 8-mirror driver mitigation for applications where the mitigation isn't automatically applied.| -|FreestyleBMX|The fix resolves an application race condition that is related to window message order.| -|GetDriveTypeWHook|The application presents unusual behavior during installation; for example, the setup program states that it can't install to a user-specified location.

    The fix exchanges GetDriveType() so that only the root information appears for the file path. This is required when an application passes an incomplete or badly formed file path when it tries to retrieve the drive type on which the file path exists.| -|GlobalMemoryStatusLie|The problem occurs when a Computer memory full error message that displays when you start an application.

    The fix modifies the memory status structure, so that it reports a swap file that is 400 MB, regardless of the true swap file size.| -|HandleBadPtr|The problem occurs when an access violation error message that displays because an API is performing pointer validation before it uses a parameter.

    The fix supports using lpBuffer validation from the InternetSetOptionA and InternetSetOptionW functions to perform the more parameter validation.| -|HandleMarkedContentNotIndexed|The problem occurs when an application that fails when it changes an attribute on a file or directory.

    The fix intercepts any API calls that return file attributes and directories that are invoked from the %TEMP% directory. The fix then resets the FILE_ATTRIBUTE_NOT_CONTENT_INDEXED attribute to its original state.| -|HeapClearAllocation|The problem is indicated when the allocation process shuts down unexpectedly.

    The fix uses zeros to clear out the heap allocation for an application.| -|IgnoreAltTab|The problem occurs when an application fails to function when special key combinations are used.

    The fix intercepts the RegisterRawInputDevices API and prevents the delivery of the WM_INPUT messages. This delivery failure forces the included hooks to be ignored and forces DInput to use Windows-specific hooks.

    **Note:** For more detailed information about this application fix, see [Using the IgnoreAltTab Fix](/previous-versions/windows/it-pro/windows-7/cc722093(v=ws.10)).
    | -|IgnoreChromeSandbox|The fix allows Google Chrome to run on systems where ntdll is loaded above 4 GB.| -|IgnoreDirectoryJunction|The problem occurs when a read or access violation error message that displays when an application tries to find or open files.

    The fix links the FindNextFileW, FindNextFileA, FindFirstFileExW, FindFirstFileExA, FindFirstFileW, and FindFirstFileA APIs to prevent them from returning directory junctions.

    **Note:** Symbolic links appear to start in Windows Vista.
    | -|IgnoreException|The problem is indicated when an application stops functioning immediately after it starts, or the application starts with only a cursor appearing on the screen.

    The fix enables the application to ignore specified exceptions. By default, this fix ignores privileged-mode exceptions; however, it can be configured to ignore any exception.

    You can control this fix further by typing the following command at the command prompt:

    `Exception1;Exception2`
    Where Exception1 and Exception2 are specific exceptions to be ignored. For example: ACCESS_VIOLATION_READ:1;ACCESS_VIOLATION_WRITE:1.

    **Important:** You should use this compatibility fix only if you're certain that it's acceptable to ignore the exception. You might experience more compatibility issues if you choose to incorrectly ignore an exception.

    **Note:** For more detailed information about this application fix, see [Using the IgnoreException Fix](/previous-versions/windows/it-pro/windows-7/cc766154(v=ws.10)).
    | -|IgnoreFloatingPointRoundingControl|This fix enables an application to ignore the rounding control request and to behave as expected in previous versions of the application.

    Before the C runtime library supported floating point SSE2, it ignored the rounding control request and used the round to nearest option by default. This shim ignores the rounding control request to support applications relying on old behavior.| -|IgnoreFontQuality|The problem occurs when application text appears to be distorted.

    The fix enables color-keyed fonts to properly work with anti-aliasing.| -|IgnoreMessageBox|The problem occurs when a message box that displays with debugging or extraneous content when the application runs on an unexpected operating system.

    The fix intercepts the MessageBox* APIs and inspects them for specific message text. If matching text is found, the application continues without showing the message box.

    **Note:** For more detailed information about this application fix, see [Using the IgnoreMessageBox Fix](/previous-versions/windows/it-pro/windows-7/cc749044(v=ws.10)).
    | -|IgnoreMSOXMLMF|The problem occurs when an error message that states that the operating system can't locate the MSVCR80D.DLL file.

    The fix ignores the registered MSOXMLMF.DLL object, which Microsoft® Office 2007 loads into the operating system anytime that you load an XML file, and then it fails the CoGetClassObject for its CLSID. This compatibility fix ignores the registered MSOXMLMF and fails the CoGetClassObject for its CLSID.| -|IgnoreSetROP2|The fix ignores read-modify-write operations on the desktop to avoid performance issues.| -|InstallComponent|The fix prompts the user to install.Net 3.5 or .NET 2.0 because .NET isn't included with Windows 8.| -|LoadLibraryRedirect|The fix forces an application to load system versions of libraries instead of loading redistributable versions that shipped with the application.| -|LocalMappedObject|The problem occurs when an application unsuccessfully tries to create an object in the Global namespace.

    The fix intercepts the function call to create the object and replaces the word Global with Local.

    **Note:** For more detailed information about this application fix, see [Using the LocalMappedObject Fix](/previous-versions/windows/it-pro/windows-7/cc749287(v=ws.10)).
    | -|MakeShortcutRunas|The problem is indicated when an application fails to uninstall because of access-related errors.

    The fix locates any RunDLL.exe-based uninstallers and forces them to run with different credentials during the application installation. After it applies this fix, the installer will create a shortcut that specifies a matching string to run during the application installationenabling the uninstallation to occur later.

    **Note:** For more detailed information about this application fix, see [Using the MakeShortcutRunas Fix](/previous-versions/windows/it-pro/windows-7/dd638338(v=ws.10))
    | -|ManageLinks|The fix intercepts common APIs that are going to a directory or to an executable (.exe) file, and then converts any symbolic or directory junctions before passing it back to the original APIs.| -|MirrorDriverWithComposition|The fix allows mirror drivers to work properly with acceptable performance with desktop composition.| -|MoveToCopyFileShim|The problem occurs when an application experiences security access issues during setup.

    The fix forces the CopyFile APIs to run instead of the MoveFile APIs. CopyFile APIs avoid moving the security descriptor, which enables the application files to get the default descriptor of the destination folder and prevents the security access issue.| -|OpenDirectoryAcl|The problem occurs when an error message that states that you don't have the appropriate permissions to access the application.

    The fix reduces the security privilege levels on a specified set of files and folders.

    **Note:** For more detailed information about this application fix, see [Using the OpenDirectoryACL Fix](/previous-versions/windows/it-pro/windows-7/dd638417(v=ws.10)).
    | -|PopCapGamesForceResPerf|The fix resolves the performance issues in PopCap games like Bejeweled2. The performance issues are visible in certain low-end cards at certain resolutions where the 1024x768 buffer is scaled to fit the display resolution.| -|PreInstallDriver|The fix preinstalls drivers for applications that would otherwise try to install or start drivers during the initial start process.| -|PreInstallSmarteSECURE|The fix preinstalls computer-wide CLSIDs for applications that use SmartSECURE copy protection, which would otherwise try to install the CLSIDs during the initial start process.| -|ProcessPerfData|The problem occurs because the application tried to read the process performance data registry value to determine if another instance of the application is running. This problem results in an Unhandled Exception error message.

    The fix handles the failure case by passing a fake process performance data registry key, so that the application perceives that it's the only instance running.

    **Note:** This issue seems to occur most frequently with .NET applications.| -|PromoteDAM|The fix registers an application for power state change notifications.
    | -|PropagateProcessHistory|The problem occurs when an application incorrectly fails to apply an application fix.

    The fix sets the _PROCESS_HISTORY environment variable so that child processes can look in the parent directory for matching information while searching for application fixes.| -|ProtectedAdminCheck|The problem occurs when an application fails to run because of incorrect Protected Administrator permissions.

    The fix addresses the issues that occur when applications use non-standard Administrator checks. This issue can result in false positives for user accounts that are being run as Protected Administrators. In this case, the associated SID exists, but the SID is set as deny-only.| -|RedirectCRTTempFile|The fix intercepts failing CRT calls that try to create a temporary file at the root of the volume. The fix instead redirects the calls to a temporary file in the user's temporary directory.| -|RedirectHKCUKeys|The problem occurs when an application can't be accessed because of User Account Control (UAC) restrictions.

    The fix duplicates any newly created HKCU keys to other users' HKCU accounts. This fix is generic for UAC restrictions, whereby the HKCU keys are required, but are unavailable to an application at runtime.| -|RedirectMP3Codec|This problem occurs when you can't play MP3 files.

    The fix intercepts the CoCreateInstance call for the missing filter and then redirects it to a supported version.| -|RedirectShortcut|The problem occurs when an application's shortcut can't be accessed, or the application uninstallation process doesn't remove application shortcuts.

    The fix redirects all of the shortcuts created during the application setup to appear according to a specified path.

    Start Menu shortcuts: Appear in the \ProgramData\Microsoft\Windows\Start Menu directory for all users.
    Desktop or Quick Launch shortcuts: You must manually place the shortcuts on the individual user's desktop or Quick Launch bar.

    This issue occurs because of UAC restrictions: specifically, when an application setup runs by using elevated privileges and stores the shortcuts according to the elevated user's context. In this situation, a restricted user can't access the shortcuts.

    You can't apply this fix to an .exe file that includes a manifest and provides a run level.| -|RelaunchElevated|The problem occurs when installers, uninstallers, or updaters fail when they're started from a host application.

    The fix enables a child .exe file to run with elevated privileges when it's difficult to determine the parent process with either the ElevateCreateProcess fix or by marking the .exe files to RunAsAdmin.

    **Note:** For more detailed information about this application fix, see [Using the RelaunchElevated Fix](/previous-versions/windows/it-pro/windows-7/dd638373(v=ws.10)).
    | -|RetryOpenSCManagerWithReadAccess|The problem occurs when an application tries to open the Service Control Manager (SCM) and receives an Access Denied error message.

    The fix retries the call and requests a more restricted set of rights that include the following items:

  • SC_MANAGER_CONNECT
  • SC_MANAGER_ENUMERATE_SERVICE
  • SC_MANAGER_QUERY_LOCK_STATUS
  • STANDARD_READ_RIGHTS
    **Note:** For more detailed information about this application fix, see [Using the RetryOpenSCManagerwithReadAccess Fix](/previous-versions/windows/it-pro/windows-7/cc721915(v=ws.10)).
    | -|RetryOpenServiceWithReadAccess|The problem occurs when an Unable to open service due to your application using the OpenService() API to test for the existence of a particular service error message displays.

    The fix retries the OpenService() API call and verifies that the user has Administrator rights, isn't a Protected Administrator, and by using read-only access. Applications can test for the existence of a service by calling the OpenService() API but some applications ask for all access when making this check. This fix retries the call but only asking for read-only access. The user needs to be an administrator for this fix to work

    **Note:** For more detailed information about this application fix, see [Using the RetryOpenServiceWithReadAccess Fix](/previous-versions/windows/it-pro/windows-7/cc766423(v=ws.10)).
    | -|RunAsAdmin|The problem occurs when an application fails to function by using the Standard User or Protected Administrator account.

    The fix enables the application to run by using elevated privileges. The fix is the equivalent of specifying requireAdministrator in an application manifest.

    **Note:** For more detailed information about this application fix, see [Using the RunAsAdmin Fix](/previous-versions/windows/it-pro/windows-7/dd638315(v=ws.10)).
    | -|RunAsHighest|The problem occurs when administrators can't view the read/write version of an application that presents a read-only view to standard users.

    The fix enables the application to run by using the highest available permissions. This fix is the equivalent of specifying highestAvailable in an application manifest.

    **Note:** For more detailed information about this application fix, see [Using the RunAsHighest Fix](/previous-versions/windows/it-pro/windows-7/dd638322(v=ws.10)).
    | -|RunAsInvoker|The problem occurs when an application isn't detected as requiring elevation.

    The fix enables the application to run by using the privileges that are associated with the creation process, without requiring elevation. This fix is the equivalent of specifying asInvoker in an application manifest.

    **Note:** For more detailed information about this application fix, see [Using the RunAsInvoker Fix](/previous-versions/windows/it-pro/windows-7/dd638389(v=ws.10)).
    | -|SecuROM7|The fix repairs applications by using SecuROM7 for copy protection.| -|SessionShim|The fix intercepts API calls from applications that are trying to interact with services that are running in another session, by using the terminal service name prefix (Global or Local) as the parameter.

    At the command prompt, you can supply a list of objects to modify, separating the values by a double backslash (). Or, you can choose not to include any parameters, so that all of the objects are modified.

    **Important:** Users can't sign in as Session 0 (Global Session) in Windows Vista and later. Therefore, applications that require access to Session 0 automatically fail.

    **Note:** For more detailed information about this application fix, see [Using the SessionShim Fix](/previous-versions/windows/it-pro/windows-7/cc722085(v=ws.10)).
    | -|SetProtocolHandler|The fix registers an application as a protocol handler.

    You can control this fix further by typing the following command at the command prompt:`Client;Protocol;App`
    Where the Client is the name of the email protocol, Protocol is mailto, and App is the name of the application.

    **Note:** Only the mail client and the mailto protocol are supported. You can separate multiple clients by using a backslash ().
    | -|SetupCommitFileQueueIgnoreWow|The problem occurs when a 32-bit setup program fails to install because it requires 64-bit drivers.

    The fix disables the Wow64 file system that is used by the 64-bit editions of Windows, to prevent 32-bit applications from accessing 64-bit file systems during the application setup.| -|SharePointDesigner2007|The fix resolves an application bug that severely slows the application when it runs in DWM.| -|ShimViaEAT|The problem occurs when an application fails, even after applying a compatibility fix that is known to fix an issue. Applications that use unicows.dll or copy protection often present this issue.

    The fix applies the specified compatibility fixes by modifying the export table and by nullifying the use of module inclusion and exclusion.

    **Note:** For more information about this application fix, see [Using the ShimViaEAT Fix](/previous-versions/windows/it-pro/windows-7/cc766286(v=ws.10)).
    | -|ShowWindowIE|The problem occurs when a web application experiences navigation and display issues because of the tabbing feature.

    The fix intercepts the ShowWindow API call to address the issues that can occur when a web application determines that it is in a child window. This fix calls the real ShowWindow API on the top-level parent window.| -|SierraWirelessHideCDROM|The fix repairs the Sierra Wireless Driver installation preventing bugcheck.| -|Sonique2|The application uses an invalid window style, which breaks in DWM. This fix replaces the window style with a valid value.| -|SpecificInstaller|The problem occurs when the GenericInstaller function fails to pick up an application installation file.

    The fix flags the application as being an installer file (for example, setup.exe), and then prompts for elevation.

    **Note:** For more detailed information about this application fix, see [Using the SpecificInstaller Fix](/previous-versions/windows/it-pro/windows-7/dd638397(v=ws.10)).
    | -|SpecificNonInstaller|The problem occurs when an application that isn't an installer (and has sufficient privileges) generates a false positive from the GenericInstaller function.

    The fix flags the application to exclude it from detection by the GenericInstaller function.

    **Note:** For more detailed information about this application fix, see [Using the SpecificNonInstaller Fix](/previous-versions/windows/it-pro/windows-7/dd638326(v=ws.10)).
    | -|SystemMetricsLie|The fix replaces SystemMetrics values and SystemParametersInfo values with the values of previous Windows versions.| -|TextArt|The application receives different mouse coordinates with DWM ON versus DWM OFF, which causes the application to hang. This fix resolves the issue.| -|TrimDisplayDeviceNames|The fix trims the names returned by the EnumDisplayDevices API of the display devices.| -|UIPICompatLogging|The fix enables the logging of Windows messages from Internet Explorer and other processes.| -|UIPIEnableCustomMsgs|The problem occurs when an application doesn't properly communicate with other processes because customized Windows messages aren't delivered.

    The fix enables customized Windows messages to pass through to the current process from a lower Desktop integrity level. This fix is the equivalent of calling the RegisterWindowMessage function, followed by the ChangeWindowMessageFilter function in the code.

    You can control this fix further by typing the following command at the command prompt:

    `MessageString1 MessageString2`
    Where MessageString1 and MessageString2 reflect the message strings that can pass.

    **Note:** You must separate multiple message strings by spaces. For more detailed information about this application fix, see [Using the UIPIEnableCustomMsgs Fix](/previous-versions/windows/it-pro/windows-7/dd638320(v=ws.10)).
    | -|UIPIEnableStandardMsgs|The problem occurs when an application doesn't communicate properly with other processes because standard Windows messages aren't delivered.

    The fix enables standard Windows messages to pass through to the current process from a lower Desktop integrity level. This fix is the equivalent of calling the ChangeWindowMessageFilter function in the code.

    You can control this fix further by typing the following command at the command prompt:

    `1055 1056 1069`

    Where 1055 reflects the first message ID, 1056 reflects the second message ID, and 1069 reflects the third message ID that can pass.

    **Note:** You can separate multiple messages with spaces. For more detailed information about this application fix, see [Using the UIPIEnableStandardMsgs Fix [act]](/previous-versions/windows/it-pro/windows-7/dd638361(v=ws.10)).
    | -|VirtualizeDeleteFileLayer|The fix virtualizes DeleteFile operations for applications that try to delete protected files.| -|VirtualizeDesktopPainting|This fix improves the performance of several operations on the Desktop DC while using DWM.| -|VirtualRegistry|The problem is indicated when a Component failed to be located error message displays when an application is started.

    The fix enables the registry functions to allow for virtualization, redirection, expansion values, version spoofing, the simulation of performance data counters, and so on.

    For more detailed information about this application fix, see [Using the VirtualRegistry Fix](/previous-versions/windows/it-pro/windows-7/cc749368(v=ws.10)).| -|VirtualizeDeleteFile|The problem occurs when several error messages display and the application can't delete files.

    The fix makes the application's DeleteFile function call a virtual call to remedy the UAC and file virtualization issues that were introduced with Windows Vista. This fix also links other file APIs (for example, GetFileAttributes) to ensure that the virtualization of the file is deleted.

    **Note:** For more detailed information about this application fix, see [Using the VirtualizeDeleteFile Fix](/previous-versions/windows/it-pro/windows-7/dd638360(v=ws.10)).
    | -|VirtualizeHKCRLite|The problem occurs when an application fails to register COM components at runtime.

    The fix redirects the HKCR write calls (HKLM) to the HKCU hive for a per-user COM registration. This fix operates much like the VirtualRegistry fix when you use the VirtualizeHKCR parameter; however, VirtualizeHKCRLite provides better performance.

    HKCR is a virtual merge of the HKCU\Software\Classes and HKLM\Software\Classes directories. The use of HKCU is preferred if an application isn't elevated and is ignored if the application is elevated.

    You typically use this compatibility fix with the VirtualizeRegisterTypeLib fix.
    For more detailed information about this application fix, see [Using the VirtualizeHKCRLite Fix](/previous-versions/windows/it-pro/windows-7/dd638327(v=ws.10)).| -|VirtualizeRegisterTypeLib|The fix when used with the VirtualizeHKCRLite fix, ensures that the type library and the COM class registration happen simultaneously. This fix functions much like the RegistryTypeLib fix when the RegisterTypeLibForUser parameter is used.

    **Note:** For more detailed information about this application fix, see [Using the VirtualizeRegisterTypelib Fix](/previous-versions/windows/it-pro/windows-7/dd638385(v=ws.10)).
    | -|WaveOutIgnoreBadFormat|When this problem occurs when an Unable to initialize sound device from your audio driver error occurs; the application then closes.

    The fix enables the application to ignore the format error and continue to function properly.| -|WerDisableReportException|The fix turns off the silent reporting of exceptions, including those exceptions reported by Object Linking and Embedding-Database (OLE DB), to the Windows Error Reporting tool. The fix intercepts the RtlReportException API and returns a STATUS_NOT_SUPPORTED error message.| -|Win7RTM/Win8RTM|The layer provides the application with Windows 7/Windows 8 compatibility mode.| -|WinxxRTMVersionLie|The problem occurs when an application fails because it doesn't find the correct version number for the required Windows operating system.

    All version lie compatibility fixes address the issue whereby an application fails to function because it's checking for, but not finding, a specific version of the operating system. The version lie fix returns the appropriate operating system version information. For example, the VistaRTMVersionLie returns the Windows Vista version information to the application, regardless of the actual operating system version that is running on the computer.| -|Wing32SystoSys32|The problem occurs when an error message that states that the WinG library wasn't properly installed.

    The fix detects whether the WinG32 library exists in the correct directory. If the library is located in the wrong location, this fix copies the information (typically during the runtime of the application) into the %WINDIR% \system32 directory.

    **Important:** The application must have Administrator privileges for this fix to work.| -|WinSrv08R2RTM|| -|WinXPSP2VersionLie|The problem occurs when an application experiences issues because of a VB runtime DLL.

    The fix forces the application to follow these steps:

  • Open the Compatibility Administrator, and then select None for Operating System Mode.
  • On the Compatibility Fixes page, select WinXPSP2VersionLie, and then select Parameters.
  • The Options for /; dialog box appears.
  • Type vbrun60.dll into the Module Name box, select Include, and then select Add.
  • Save the custom database.
    **Note:** For more information about the WinXPSP2VersionLie application fix, see [Using the WinXPSP2VersionLie Fix](/previous-versions/windows/it-pro/windows-7/cc749518(v=ws.10)).
    | -|WRPDllRegister|The application fails when it tries to register a COM component that is released together with Windows Vista and later.

    The fix skips the processes of registering and unregistering WRP-protected COM components when calling the DLLRegisterServer and DLLUnregisterServer functions.

    You can control this fix further by typing the following command at the command prompt:

    `Component1.dll;Component2.dll`
    Where Component1.dll and Component2.dll reflect the components to be skipped.

    **Note:** For more detailed information about this application fix, see [Using the WRPDllRegister Fix](/previous-versions/windows/it-pro/windows-7/dd638345(v=ws.10)).
    | -|WRPMitigation|The problem is indicated when an access denied error message displays when the application tries to access a protected operating system resource by using more than read-only access.

    The fix emulates the successful authentication and modification of file and registry APIs, so that the application can continue.

    **Note:** For more detailed information about WRPMitigation, see [Using the WRPMitigation Fix](/previous-versions/windows/it-pro/windows-7/dd638325(v=ws.10)).
    | -|WRPRegDeleteKey|The problem occurs when an access denied error message that displays when the application tries to delete a registry key.

    The fix verifies whether the registry key is WRP-protected. If the key is protected, this fix emulates the deletion process.| -|XPAfxIsValidAddress|The fix emulates the behavior of Windows XP for MFC42!AfxIsValidAddress.| - -## Compatibility Modes - -The following table lists the known compatibility modes. - -|Compatibility Mode Name|Description|Included Compatibility Fixes| -|--- |--- |--- | -|WinSrv03|Emulates the Windows Server 2003 operating system.|

  • Win2k3RTMVersionLie
  • VirtualRegistry
  • ElevateCreateProcess
  • EmulateSorting
  • FailObsoleteShellAPIs
  • LoadLibraryCWD
  • HandleBadPtr
  • GlobalMemoryStatus2 GB
  • RedirectMP3Codec
  • EnableLegacyExceptionHandlinginOLE
  • NoGhost
  • HardwareAudioMixer| -|WinSrv03Sp1|Emulates the Windows Server 2003 with Service Pack 1 (SP1) operating system.|
  • Win2K3SP1VersionLie
  • VirtualRegistry
  • ElevateCreateProcess
  • EmulateSorting
  • FailObsoleteShellAPIs
  • LoadLibraryCWD
  • HandleBadPtr
  • EnableLegacyExceptionHandlinginOLE
  • RedirectMP3Codec
  • HardwareAudioMixer| diff --git a/windows/deployment/planning/creating-a-custom-compatibility-fix-in-compatibility-administrator.md b/windows/deployment/planning/creating-a-custom-compatibility-fix-in-compatibility-administrator.md deleted file mode 100644 index d008653378..0000000000 --- a/windows/deployment/planning/creating-a-custom-compatibility-fix-in-compatibility-administrator.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: Creating a Custom Compatibility Fix in Compatibility Administrator (Windows 10) -description: The Compatibility Administrator tool uses the term fix to describe the combination of compatibility information added to a customized database for a specific application. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Creating a Custom Compatibility Fix in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Compatibility Administrator tool uses the term *fix* to describe the combination of compatibility information added to a customized database for a specific application. This combination can include single application fixes, groups of fixes that work together as a compatibility mode, and blocking and non-blocking AppHelp messages. - -> [!IMPORTANT] -> Fixes apply to a single application only; therefore, you must create multiple fixes if you need to fix the same issue in multiple applications. - -## What is a Compatibility Fix? - -A compatibility fix, previously known as a shim, is a small piece of code that intercepts API calls from applications. The fix transforms the API calls so that the current version of the operating system supports the application in the same way as previous versions of the operating system. This can mean anything from disabling a new feature in the current version of the operating system to emulating a particular behavior of an older version of the Windows API. - -## Searching for Existing Compatibility Fixes - -The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new compatibility fix, you can search for an existing application and then copy and paste the known fixes into your customized database. - -> [!IMPORTANT] -> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications. - -**To search for an existing application** - -1. In the left-side pane of Compatibility Administrator, expand the **Applications** folder and search for your application name. -2. Click the application name to view the preloaded compatibility fixes, compatibility modes, or AppHelp messages. - -## Creating a New Compatibility Fix - -If you are unable to find a preloaded compatibility fix for your application, you can create a new one for use by your customized database. - -**To create a new compatibility fix** - -1. In the left-side pane of Compatibility Administrator underneath the **Custom Databases** heading, right-click the name of the database to which you want to apply the compatibility fix, click **Create New**, and then click **Application Fix**. -2. Type the name of the application to which the compatibility fix applies, type the name of the application vendor, browse to the location of the application file (.exe) on your computer, and then click **Next**. -3. Select the operating system for which your compatibility fix applies, click any applicable compatibility modes to apply to your compatibility fix, and then click **Next**. -4. Select any additional compatibility fixes to apply to your compatibility fix, and then click **Next**. -5. Select any additional criteria to use to match your applications to the AppHelp message, and then click **Finish**. - - By default, Compatibility Administrator selects the basic matching criteria for your application. As a best practice, use a limited set of matching information to represent your application, because it reduces the size of the database. However, make sure you have enough information to correctly identify your application. - -## Related topics - -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/planning/creating-a-custom-compatibility-mode-in-compatibility-administrator.md b/windows/deployment/planning/creating-a-custom-compatibility-mode-in-compatibility-administrator.md deleted file mode 100644 index ffbac4b896..0000000000 --- a/windows/deployment/planning/creating-a-custom-compatibility-mode-in-compatibility-administrator.md +++ /dev/null @@ -1,67 +0,0 @@ ---- -title: Create a Custom Compatibility Mode (Windows 10) -description: Windows® provides several compatibility modes, groups of compatibility fixes found to resolve many common application-compatibility issues. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Creating a Custom Compatibility Mode in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -Windows® provides several *compatibility modes*, groups of compatibility fixes found to resolve many common application-compatibility issues. While working with Compatibility Administrator, you might decide to group some of your individual compatibility fixes into a custom-compatibility mode, which you can then deploy and use on any of your compatibility databases. - -## What Is a Compatibility Mode? - -A compatibility mode is a group of compatibility fixes. A compatibility fix, previously known as a shim, is a small piece of code that intercepts API calls from applications. The fix transforms the API calls so that the current version of the operating system supports the application in the same way as previous versions of the operating system. This can be anything from disabling a new feature in Windows to emulating a particular behavior of an older version of the Windows API. - -## Searching for Existing Compatibility Modes - -The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new compatibility mode, you can search for an existing application and then copy and paste the known fixes into your custom database. - -> [!IMPORTANT] -> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications. - -**To search for an existing application** - -1. In the left-side pane of Compatibility Administrator, expand the **Applications** folder and search for your application name. - -2. Click the application name to view the preloaded compatibility modes, compatibility fixes, or AppHelp messages. - -## Creating a New Compatibility Mode - -If you are unable to find a preloaded compatibility mode for your application, you can create a new one for use by your custom database. - -> [!IMPORTANT] -> A compatibility mode includes a set of compatibility fixes and must be deployed as a group. Therefore, you should include only fixes that you intend to deploy together to the database. - -**To create a new compatibility mode** - -1. In the left-side pane of Compatibility Administrator, underneath the **Custom Databases** heading, right-click the name of the database to which you will apply the compatibility mode, click **Create New**, and then click **Compatibility Mode**. - -2. Type the name of your custom-compatibility mode into the **Name of the compatibility mode** text box. - -3. Select each of the available compatibility fixes to include in your custom-compatibility mode and then click **>**. - - > [!IMPORTANT] - > If you are unsure which compatibility fixes to add, you can click **Copy Mode**. The **Select Compatibility Mode** dialog box appears and enables you to select from the preloaded compatibility modes. After you select a compatibility mode and click **OK**, any compatibility fixes that are included in the preloaded compatibility mode will be automatically added to your custom-compatibility mode. - > If you have any compatibility fixes that require additional parameters, you can select the fix, and then click **Parameters**. The **Options for <Compatibility\_Fix\_Name>** dialog box appears, enabling you to update the parameter fields. - -4. After you are done selecting the compatibility fixes to include, click **OK**. - - The compatibility mode is added to your custom database. - -## Related topics -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) \ No newline at end of file diff --git a/windows/deployment/planning/creating-an-apphelp-message-in-compatibility-administrator.md b/windows/deployment/planning/creating-an-apphelp-message-in-compatibility-administrator.md deleted file mode 100644 index 5ba7a9cf41..0000000000 --- a/windows/deployment/planning/creating-an-apphelp-message-in-compatibility-administrator.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: Create AppHelp Message in Compatibility Administrator (Windows 10) -description: Create an AppHelp text message with Compatibility Administrator; a message that appears upon starting an app with major issues on the Windows® operating system. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Creating an AppHelp Message in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Compatibility Administrator tool enables you to create an AppHelp text message. This is a blocking or non-blocking message that appears when a user starts an application that you know has major functionality issues on the Windows® operating system. - -## Blocking Versus Non-Blocking AppHelp Messages - -A blocking AppHelp message prevents the application from starting and displays a message to the user. You can define a specific URL where the user can download an updated driver or other fix to resolve the issue. When using a blocking AppHelp message, you must also define the file-matching information to identify the version of the application and enable the corrected version to continue. - -A non-blocking AppHelp message doesn't prevent the application from starting, but provides a message to the user that includes information such as security issues, updates to the application, or changes to the location of network resources. - -## Searching for Existing Compatibility Fixes - -The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new AppHelp message, you can search for an existing application and then copy and paste the known fixes into your custom database. - -> [!IMPORTANT] -> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications. - -**To search for an existing application** - -1. In the left-side pane of Compatibility Administrator, expand the **Applications** folder and search for your application name. - -2. Click the application name to view the preloaded AppHelp messages, compatibility fixes, and compatibility modes. - -## Creating a New AppHelp Message - -If you're unable to find a preloaded AppHelp message for your application, you can create a new one for use by your custom database. - -**To create a new AppHelp message** - -1. In the left-side pane of Compatibility Administrator, below the **Custom Databases** heading, right-click the name of the database to which you'll apply the AppHelp message, click **Create New**, and then click **AppHelp Message**. - -2. Type the name of the application to which this AppHelp message applies, type the name of the application vendor, browse to the location of the application file (.exe) on your computer, and then click **Next**. - - The wizard shows the known **Matching Information**, which is used for program identification. - -3. Select any other criteria to use to match your applications to the AppHelp message, and then click **Next**. - - By default, Compatibility Administrator selects the basic matching criteria for your application. - - The wizard shows the **Enter Message Type** options. - -4. Click one of the following options: - - - **Display a message and allow this program to run**. This message is non-blocking, which means that you can alert the user that there might be a problem, but the application isn't prevented from starting. - - - **Display a message and do not allow this program to run**. This message is blocking, which means that the application won't start. Instead, this message points the user to a location that provides more information about fixing the issue. - -5. Click **Next**. - - The wizard then shows the **Enter Message Information** fields. - -6. Type the website URL and the message text to appear when the user starts the application, and then click **Finish**. - -## Issues with AppHelp Messages and Computers Running Windows 2000 - -The following issues might occur with computers running Windows 2000: - -- You might be unable to create a custom AppHelp message. - -- The AppHelp message text used for system database entries might not appear. - -- Copying an AppHelp entry for a system database or a custom-compatibility fix from a system database might cause Compatibility Administrator to hide the descriptive text. - -## Related topics -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md b/windows/deployment/planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md deleted file mode 100644 index 1767d6c21b..0000000000 --- a/windows/deployment/planning/enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md +++ /dev/null @@ -1,58 +0,0 @@ ---- -title: Enabling and Disabling Compatibility Fixes in Compatibility Administrator -description: You can disable and enable individual compatibility fixes in your customized databases for testing and troubleshooting purposes. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Enabling and Disabling Compatibility Fixes in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -You can disable and enable individual compatibility fixes in your customized databases for testing and troubleshooting purposes. - -## Disabling Compatibility Fixes - -Customized compatibility databases can become quite complex as you add your fixes for the multiple applications found in your organization. Over time, you may find you need to disable a particular fix in your customized database. For example, if a software vendor releases a fix for an issue addressed in one of your compatibility fixes, you must validate that the vendor's fix is correct and that it resolves your issue. To do this, you must temporarily disable the compatibility fix and then test your application. - ->[!IMPORTANT] ->Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications. - -**To disable a compatibility fix within a database** - -1. In the left-sde pane of Compatibility Administrator, expand the custom database that includes the compatibility fix that you want to disable, and then select the specific compatibility fix. - - The compatibility fix details appear in the right-hand pane. - -2. On the **Database** menu, click **Disable Entry**. - - **Important** - When you disable an entry, it will remain disabled even if you do not save the database file. - -## Enabling Compatibility Fixes - -You can enable your disabled compatibility fixes at any time. - -**To enable a compatibility fix within a database** - -1. In the left-side pane of Compatibility Administrator, expand the custom database that includes the compatibility fix that you want to enable, and then select the specific compatibility fix. - - The compatibility fix details appear in the right-side pane. - -2. On the **Database** menu, click **Enable Entry**. - -## Related topics - -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/planning/fixing-applications-by-using-the-sua-tool.md b/windows/deployment/planning/fixing-applications-by-using-the-sua-tool.md deleted file mode 100644 index ebb8501b13..0000000000 --- a/windows/deployment/planning/fixing-applications-by-using-the-sua-tool.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: Fixing Applications by Using the SUA Tool (Windows 10) -description: On the user interface for the Standard User Analyzer (SUA) tool, you can apply fixes to an application. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Fixing Applications by Using the SUA Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -On the user interface for the Standard User Analyzer (SUA) tool, you can apply fixes to an application. - -**To fix an application by using the SUA tool** - -1. Use the SUA tool to test an application. For more information, see [Using the SUA Tool](using-the-sua-tool.md). - -2. After you finish testing, open the SUA tool. - -3. On the **Mitigation** menu, click the command that corresponds to the action that you want to take. The following table describes the commands. - - |Mitigation menu command|Description| - |--- |--- | - |**Apply Mitigations**|Opens the **Mitigate AppCompat Issues** dialog box, in which you can select the fixes that you intend to apply to the application.| - |**Undo Mitigations**|Removes the application fixes that you just applied.

    This option is available only after you apply an application fix and before you close the SUA tool. Alternatively, you can manually remove application fixes by using **Programs and Features** in Control Panel.| - |**Export Mitigations as Windows Installer file**|Exports your application fixes as a Windows® Installer (.msi) file, which can then be deployed to other computers that are running the application.| \ No newline at end of file diff --git a/windows/deployment/planning/images/dep-win8-l-act-appcallosthroughiat.jpg b/windows/deployment/planning/images/dep-win8-l-act-appcallosthroughiat.jpg deleted file mode 100644 index 2ab0b3c13d..0000000000 Binary files a/windows/deployment/planning/images/dep-win8-l-act-appcallosthroughiat.jpg and /dev/null differ diff --git a/windows/deployment/planning/images/dep-win8-l-act-appredirectwithcompatfix.jpg b/windows/deployment/planning/images/dep-win8-l-act-appredirectwithcompatfix.jpg deleted file mode 100644 index a4a4f4f616..0000000000 Binary files a/windows/deployment/planning/images/dep-win8-l-act-appredirectwithcompatfix.jpg and /dev/null differ diff --git a/windows/deployment/planning/images/dep-win8-l-act-compatadminflowchart.jpg b/windows/deployment/planning/images/dep-win8-l-act-compatadminflowchart.jpg deleted file mode 100644 index a6b484d53c..0000000000 Binary files a/windows/deployment/planning/images/dep-win8-l-act-compatadminflowchart.jpg and /dev/null differ diff --git a/windows/deployment/planning/images/dep-win8-l-act-suaflowchart.jpg b/windows/deployment/planning/images/dep-win8-l-act-suaflowchart.jpg deleted file mode 100644 index 07865c7c75..0000000000 Binary files a/windows/deployment/planning/images/dep-win8-l-act-suaflowchart.jpg and /dev/null differ diff --git a/windows/deployment/planning/images/dep-win8-l-act-suawizardflowchart.jpg b/windows/deployment/planning/images/dep-win8-l-act-suawizardflowchart.jpg deleted file mode 100644 index 9357e6f3bb..0000000000 Binary files a/windows/deployment/planning/images/dep-win8-l-act-suawizardflowchart.jpg and /dev/null differ diff --git a/windows/deployment/planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md b/windows/deployment/planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md deleted file mode 100644 index e7265156ef..0000000000 --- a/windows/deployment/planning/installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: Install/Uninstall Custom Databases (Windows 10) -description: The Compatibility Administrator tool enables the creation and the use of custom-compatibility and standard-compatibility databases. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Installing and Uninstalling Custom Compatibility Databases in Compatibility Administrator - - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Compatibility Administrator tool enables the creation and the use of custom-compatibility and standard-compatibility databases. Both the custom databases and the standard databases store the known compatibility fixes, compatibility modes, and AppHelp messages. They also store the required application-matching information for installation on your local computers. - -By default, the Windows® operating system installs a System Application Fix database for use with the Compatibility Administrator. This database can be updated through Windows Update, and is stored in the %WINDIR% \\AppPatch directory. Your custom databases are automatically stored in the %WINDIR% \\AppPatch\\Custom directory and are installed by using the Sdbinst.exe tool provided with the Compatibility Administrator. - -> [!IMPORTANT] -> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications. - -In addition, you must deploy your databases to your organization's computers before the included fixes will have any effect on the application issue. For more information about deploying your database, see [Using the Sdbinst.exe Command-Line Tool](using-the-sdbinstexe-command-line-tool.md). - - - -## Installing a Custom Database - - -Installing your custom-compatibility database enables you to fix issues with your installed applications. - -**To install a custom database** - -1. In the left-side pane of Compatibility Administrator, click the custom database to install to your local computers. - -2. On the **File** menu, click **Install**. - - The Compatibility Administrator installs the database, which appears in the **Installed Databases** list. - - The relationship between your database file and an included application occurs in the registry. Every time you start an application, the operating system checks the registry for compatibility-fix information and, if found, retrieves the information from your customized database file. - -## Uninstalling a Custom Database - - -When a custom database is no longer necessary, either because the applications are no longer used or because the vendor has provided a fix that resolves the compatibility issues, you can uninstall the custom database. - -**To uninstall a custom database** - -1. In the **Installed Databases** list, which appears in the left-side pane of Compatibility Administrator, click the database to uninstall from your local computers. - -2. On the **File** menu, click **Uninstall**. - -## Related topics -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/planning/managing-application-compatibility-fixes-and-custom-fix-databases.md b/windows/deployment/planning/managing-application-compatibility-fixes-and-custom-fix-databases.md deleted file mode 100644 index 6f9d7dae92..0000000000 --- a/windows/deployment/planning/managing-application-compatibility-fixes-and-custom-fix-databases.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: Managing Application-Compatibility Fixes and Custom Fix Databases (Windows 10) -description: Learn why you should use compatibility fixes, and how to deploy and manage custom-compatibility fix databases. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Managing Application-Compatibility Fixes and Custom Fix Databases - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -This section provides information about managing your application-compatibility fixes and custom-compatibility fix databases. This section explains the reasons for using compatibility fixes and how to deploy custom-compatibility fix databases. - -## In this section - -|Topic|Description| -|--- |--- | -|[Understanding and Using Compatibility Fixes](understanding-and-using-compatibility-fixes.md)|As the Windows operating system evolves to support new technology and functionality, the implementations of some functions may change. This can cause problems for applications that relied upon the original implementation. You can avoid compatibility issues by using the Microsoft Windows Application Compatibility (Compatibility Fix) infrastructure to create a specific application fix for a particular version of an application.| -|[Compatibility Fix Database Management Strategies and Deployment](compatibility-fix-database-management-strategies-and-deployment.md)|After you determine that you will use compatibility fixes in your application-compatibility mitigation strategy, you must define a strategy to manage your custom compatibility-fix database. Typically, you can use one of two approaches:| -|[Testing Your Application Mitigation Packages](testing-your-application-mitigation-packages.md)|This topic provides details about testing your application-mitigation packages, including recommendations about how to report your information and how to resolve any outstanding issues.| - -## Related topics - -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) - -[Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md) diff --git a/windows/deployment/planning/searching-for-fixed-applications-in-compatibility-administrator.md b/windows/deployment/planning/searching-for-fixed-applications-in-compatibility-administrator.md deleted file mode 100644 index a65742c0f2..0000000000 --- a/windows/deployment/planning/searching-for-fixed-applications-in-compatibility-administrator.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: Searching for Fixed Applications in Compatibility Administrator (Windows 10) -description: Compatibility Administrator can locate specific executable (.exe) files with previously applied compatibility fixes, compatibility modes, or AppHelp messages. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Searching for Fixed Applications in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -With the search functionality in Compatibility Administrator, you can locate specific executable (.exe) files with previously applied compatibility fixes, compatibility modes, or AppHelp messages. This is particularly useful if you are trying to identify applications with a specific compatibility fix or identifying which fixes are applied to a specific application. - -The **Query Compatibility Databases** tool provides additional search options. For more information, see [Searching for Installed Compatibility Fixes with the Query Tool in Compatibility Administrator](searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md). - -## Searching for Previously Applied Compatibility Fixes - -> [!IMPORTANT] -> You must perform your search with the correct version of the Compatibility Administrator tool. If you are searching for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. If you are searching for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator. - -**To search for previous fixes** - -1. On the Compatibility Administrator toolbar, click **Search**. - -2. Click **Browse** to locate the directory location to search for .exe files. - -3. Select at least one check box from **Entries with Compatibility Fixes**, **Entries with Compatibility Modes**, or **Entries with AppHelp**. - -4. Click **Find Now**. - - The query runs, returning your results in the lower pane. - -## Viewing Your Query Results - -Your query results display the affected files, the application location, the application name, the type of compatibility fix, and the custom database that provided the fix. - -## Exporting Your Query Results - -You can export your search results to a text (.txt) file for later review or archival. - -**To export your search results** - -1. In the **Search for Fixes** dialog box, click **Export**. - -2. Browse to the location where you want to store your search result file, and then click **Save**. - -## Related topics -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) \ No newline at end of file diff --git a/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md b/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md deleted file mode 100644 index c7cd8de1b8..0000000000 --- a/windows/deployment/planning/searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md +++ /dev/null @@ -1,143 +0,0 @@ ---- -title: Searching for Installed Compatibility Fixes with the Query Tool in Compatibility Administrator (Windows 10) -description: You can access the Query tool from within Compatibility Administrator. The Query tool provides the same functionality as using the Search feature. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Searching for Installed Compatibility Fixes with the Query Tool in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -You can access the Query tool from within Compatibility Administrator. The Query tool provides the same functionality as using the Search feature. - -For information about the Search feature, see [Searching for Fixed Applications in Compatibility Administrator](searching-for-fixed-applications-in-compatibility-administrator.md). However, the Query tool provides more detailed search criteria, including tabs that enable you to search the program properties, the compatibility fix properties, and the fix description. You can perform a search by using SQL SELECT and WHERE clauses, in addition to searching specific types of databases. - -> [!IMPORTANT] -> You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator. - -## Querying by Using the Program Properties Tab - -You can use the **Program Properties** tab of the Query tool to search for any compatibility fix, compatibility mode, or AppHelp for a specific application. - -**To query by using the Program Properties tab** - -1. On the Compatibility Administrator toolbar, click **Query**. -2. In the **Look in** drop-down list, select the appropriate database type to search. -3. Type the location of the application you are searching for into the **Search for the Application** field. - - This name should be the same as the name in the **Applications** area (left pane) of Compatibility Administrator. - -4. Type the application executable (.exe) file name into the **Search for the File** box. If you leave this box blank, the percent (%) sign appears as a wildcard to search for any file. - - You must designate the executable name that was given when the compatibility fix was added to the database. - -5. Optionally, select the check box for one of the following types of compatibility fix: - - - **Compatibility Modes** - - **Compatibility Fixes** - - **Application Helps** - - > [!IMPORTANT] - > If you do not select any of the check boxes, the search will look for all types of compatibility fixes. Do not select multiple check boxes because only applications that match all of the requirements will appear. - -6. Click **Find Now**. - - The query runs and the results of the query are displayed in the lower pane. - -## Querying by Using the Fix Properties Tab - - -You can use the **Fix Properties** tab of the Query tool to search for any application affected by a specific compatibility fix or a compatibility mode. For example, you can search for any application affected by the ProfilesSetup compatibility mode. - -**To query by using the Fix Properties tab** - -1. On the Compatibility Administrator toolbar, click **Query**. -2. Click the **Fix Properties** tab. -3. In the **Look in** drop-down list, select the appropriate database type to search. -4. Type the name of the compatibility fix or compatibility mode into the **Search for programs fixed using** field. - - >[!NOTE] - >You can use the percent (%) symbol as a wildcard in your fix-properties query, as a substitute for any string of zero or more characters - -5. Select the check box for either **Search in Compatibility Fixes** or **Search in Compatibility Modes**. - - >[!IMPORTANT] - >Your text must match the type of compatibility fix or mode for which you are performing the query. For example, entering the name of a compatibility fix and selecting the compatibility mode check box will not return any results. Additionally, if you select both check boxes, the query will search for the fix by compatibility mode and compatibility fix. Only applications that match both requirements appear. - -6. Click **Find Now**. - - The query runs and the results of the query are displayed in the lower pane. - -## Querying by Using the Fix Description Tab - -You can use the **Fix Description** tab of the Query tool to add parameters that enable you to search your compatibility databases by application title or solution description text. - -**To query by using the Fix Description tab** - -1. On the Compatibility Administrator toolbar, click **Query**. -2. Click the **Fix Description** tab. -3. In the **Look in** drop-down list, select the appropriate database type to search. -4. Type your search keywords into the box **Words to look for**. Use commas to separate multiple keywords. - - >[!IMPORTANT] - >You cannot use wildcards as part of the Fix Description search query because the default behavior is to search for any entry that meets your search criteria. - -5. Refine your search by selecting **Match any word** or **Match all words** from the drop-down list. -6. Click **Find Now**. - - The query runs and the results of the query are displayed in the lower pane. - -## Querying by Using the Advanced Tab - -You can use the **Fix Description** tab of the Query tool to add additional SQL Server SELECT and WHERE clauses to your search criteria. - -**To query by using the Advanced tab** - -1. On the Compatibility Administrator toolbar, click **Query**. -2. Click the **Advanced** tab. -3. In the **Look in** drop-down list, select the appropriate database type to search. -4. Select the appropriate SELECT clause for your search from the **Select clauses** box. For example, **APP\_NAME**. - - The **APP\_NAME** clause appears in the **SELECT** field. You can add as many additional clauses as you require. They will appear as columns in your search results. - -5. Select the appropriate WHERE clause for your search from the **Where clauses** box. For example, **DATABASE\_NAME**. - - The **DATABASE\_NAME =** clause appears in the **WHERE** box. - -6. Type the appropriate clause criteria after the equal (=) sign in the **WHERE** box. For example, **DATABASE\_NAME = "Custom\_Database"**. - - You must surround your clause criteria text with quotation marks (") for the clause to function properly. - -7. Click **Find Now**. - - The query runs and the results of the query are displayed in the lower pane. - -## Exporting Your Search Results - - -You can export any of your search results into a tab-delimited text (.txt) file for later review or for archival purposes. - -**To export your results** - -1. After you have completed your search by using the Query tool, click **Export**. - - The **Save results to a file** dialog box appears. - -2. Browse to the location where you intend to store the search results file, and then click **Save**. - -## Related topics - -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/planning/showing-messages-generated-by-the-sua-tool.md b/windows/deployment/planning/showing-messages-generated-by-the-sua-tool.md deleted file mode 100644 index 53428226ac..0000000000 --- a/windows/deployment/planning/showing-messages-generated-by-the-sua-tool.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: Showing Messages Generated by the SUA Tool (Windows 10) -description: On the user interface for the Standard User Analyzer (SUA) tool, you can show the messages that the tool has generated. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Showing Messages Generated by the SUA Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -On the user interface for the Standard User Analyzer (SUA) tool, you can show the messages that the tool has generated. - -**To show the messages that the SUA tool has generated** - -1. Use the SUA tool to test an application. For more information, see [Using the SUA Tool](using-the-sua-tool.md). - -2. After you finish testing, in the SUA tool, click the **App Info** tab. - -3. On the **View** menu, click the command that corresponds to the messages that you want to see. The following table describes the commands. - -|View menu command|Description| -|--- |--- | -|**Error Messages**|When this command is selected, the user interface shows error messages that the SUA tool has generated. Error messages are highlighted in pink.

    This command is selected by default.| -|**Warning Messages**|When this command is selected, the user interface shows warning messages that the SUA tool has generated. Warning messages are highlighted in yellow.| -|**Information Messages**|When this command is selected, the user interface shows informational messages that the SUA tool has generated. Informational messages are highlighted in green.| -|**Detailed Information**|When this command is selected, the user interface shows information that the SUA tool has generated, such as debug, stack trace, stop code, and severity information.| \ No newline at end of file diff --git a/windows/deployment/planning/sua-users-guide.md b/windows/deployment/planning/sua-users-guide.md deleted file mode 100644 index 3933f9c2d5..0000000000 --- a/windows/deployment/planning/sua-users-guide.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: SUA User's Guide (Windows 10) -description: Learn how to use Standard User Analyzer (SUA). SUA can test your apps and monitor API calls to detect compatibility issues related to the Windows User Account Control (UAC) feature. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# SUA User's Guide - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -You can use Standard User Analyzer (SUA) to test your applications and monitor API calls to detect compatibility issues related to the User Account Control (UAC) feature in Windows. - -You can use SUA in either of the following ways: - -- **Standard User Analyzer Wizard.** A wizard that guides you through a step-by-step process to locate and fix issues, without options for more analysis. - -- **Standard User Analyzer Tool.** A full-function tool in which you can perform in-depth analysis and fix issues. - -## In this section - -|Topic|Description| -|--- |--- | -|[Using the SUA wizard](using-the-sua-wizard.md)|The Standard User Analyzer (SUA) wizard works much like the SUA tool to evaluate User Account Control (UAC) issues. However, the SUA wizard doesn't offer detailed analysis, and it can't disable virtualization or elevate your permissions.| -|[Using the SUA Tool](using-the-sua-tool.md)|By using the Standard User Analyzer (SUA) tool, you can test your applications and monitor API calls to detect compatibility issues with the User Account Control (UAC) feature.| \ No newline at end of file diff --git a/windows/deployment/planning/tabs-on-the-sua-tool-interface.md b/windows/deployment/planning/tabs-on-the-sua-tool-interface.md deleted file mode 100644 index 6c189c6d79..0000000000 --- a/windows/deployment/planning/tabs-on-the-sua-tool-interface.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: Tabs on the SUA Tool Interface (Windows 10) -description: The tabs in the Standard User Analyzer (SUA) tool show the User Account Control (UAC) issues for the applications that you analyze. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Tabs on the SUA Tool Interface - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The tabs in the Standard User Analyzer (SUA) tool show the User Account Control (UAC) issues for the applications that you analyze. - -The following table provides a description of each tab on the user interface for the SUA tool. - -|Tab name|Description| -|--- |--- | -|App Info|Provides the following information for the selected application:

  • Debugging information
  • Error, warning, and informational messages (if they are enabled)
  • Options for running the application| -|File|Provides information about access to the file system.

    For example, this tab might show an attempt to write to a file that only administrators can typically access.| -|Registry|Provides information about access to the system registry.

    For example, this tab might show an attempt to write to a registry key that only administrators can typically access.| -|INI|Provides information about WriteProfile API issues.

    For example, in the Calculator tool (Calc.exe) in Windows® XP, when you change the view from **Standard** to **Scientific**, Calc.exe calls the WriteProfile API to write to the Windows\Win.ini file. The Win.ini file is writable only for administrators.| -|Token|Provides information about access-token checking.

    For example, this tab might show an explicit check for the Builtin\Administrators security identifier (SID) in the user's access token. This operation may not work for a standard user.| -|Privilege|Provides information about permissions.

    For example, this tab might show an attempt to explicitly enable permissions that do not work for a standard user.| -|Name Space|Provides information about creation of system objects.

    For example, this tab might show an attempt to create a new system object, such as an event or a memory map, in a restricted namespace. Applications that attempt this kind of operation do not function for a standard user.| -|Other Objects|Provides information related to applications accessing objects other than files and registry keys.| -|Process|Provides information about process elevation.

    For example, this tab might show the use of the CreateProcess API to open an executable (.exe) file that, in turn, requires process elevation that will not function for a standard user.| - diff --git a/windows/deployment/planning/testing-your-application-mitigation-packages.md b/windows/deployment/planning/testing-your-application-mitigation-packages.md deleted file mode 100644 index fcc32044a3..0000000000 --- a/windows/deployment/planning/testing-your-application-mitigation-packages.md +++ /dev/null @@ -1,82 +0,0 @@ ---- -title: Testing Your Application Mitigation Packages (Windows 10) -description: Learn how to test your application-mitigation packages, including how to report your information and how to resolve any outstanding issues. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Testing Your Application Mitigation Packages - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -This topic provides details about testing your application-mitigation packages, including recommendations about how to report your information and how to resolve any outstanding issues. - -## Testing Your Application Mitigation Packages - -Testing your application mitigation package strategies is an iterative process, whereby the mitigation strategies that prove unsuccessful will need to be revised and retested. The testing process includes a series of tests in the test environment and one or more pilot deployments in the production environment. - -**To test your mitigation strategies** - -1. Perform the following steps for each of the applications for which you have developed mitigations. - - 1. Test the mitigation strategy in your test environment. - - 2. If the mitigation strategy is unsuccessful, revise the mitigation strategy and perform step 1 again. - - At the end of this step, you will have successfully tested all of your mitigation strategies in your test environment and can move to your pilot deployment environment. - -2. Perform the following steps in the pilot deployments for each of the applications for which you have developed mitigations. - - 1. Test the mitigation strategy in your pilot deployment. - - 2. If the mitigation strategy is unsuccessful, revise the mitigation strategy and perform Step 2 again. - - At the end of this step, you will have successfully tested all of your mitigation strategies in your pilot environment. - -## Reporting the Compatibility Mitigation Status to Stakeholders - -After testing your application mitigation package, you must communicate your status to the appropriate stakeholders before deployment begins. We recommend that you perform this communication by using the following status ratings. - -- **Resolved application compatibility issues**. This status indicates that the application compatibility issues are resolved and that these applications represent no risk to your environment. - -- **Unresolved application compatibility issues**. This status indicates that there are unresolved issues for the specifically defined applications. Because these applications are a risk to your environment, more discussion is required before you can resolve the compatibility issues. - -- **Changes to user experience**. This status indicates that the fix will change the user experience for the defined applications, possibly requiring your staff to receive further training. More investigation is required before you can resolve the compatibility issues. - -- **Changes in help desk procedures and processes**. This status indicates that the fix will require changes to your help desk's procedures and processes, possibly requiring your support staff to receive further training. More investigation is required before you can resolve the compatibility issues. - -## Resolving Outstanding Compatibility Issues - -At this point, you probably cannot resolve any unresolved application compatibility issues by automated mitigation methods or by modifying the application. Resolve any outstanding application compatibility issues by using one of the following methods. - -- Apply specific compatibility modes, or run the program as an Administrator, by using the Compatibility Administrator tool. - - > [!NOTE] - > For more information about using Compatibility Administrator to apply compatibility fixes and compatibility modes, see [Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md). - -- Run the application in a virtual environment. - - Run the application in a version of Windows supported by the application in a virtualized environment. This method ensures application compatibility, because the application is running on a supported operating system. - -- Resolve application compatibility by using non-Microsoft tools. - - If the application was developed in an environment other than Microsoft Visual Studio®, you must use non-Microsoft debugging and analysis tools to help resolve the remaining application compatibility issues. - -- Outsource the application compatibility mitigation. - - If your developers have insufficient resources to resolve the application compatibility issues, outsource the mitigation effort to another organization within your company. - -## Related topics -[Managing Application-Compatibility Fixes and Custom Fix Databases](managing-application-compatibility-fixes-and-custom-fix-databases.md) diff --git a/windows/deployment/planning/understanding-and-using-compatibility-fixes.md b/windows/deployment/planning/understanding-and-using-compatibility-fixes.md deleted file mode 100644 index 6fa5f46c8c..0000000000 --- a/windows/deployment/planning/understanding-and-using-compatibility-fixes.md +++ /dev/null @@ -1,88 +0,0 @@ ---- -title: Understanding and Using Compatibility Fixes (Windows 10) -description: As the Windows operating system evolves to support new technology and functionality, the implementations of some functions may change. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Understanding and Using Compatibility Fixes - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -As the Windows operating system evolves to support new technology and functionality, the implementations of some functions may change. This can cause problems for applications that relied upon the original implementation. You can avoid compatibility issues by using the Microsoft Windows Application Compatibility (Compatibility Fix) infrastructure to create a specific application fix for a particular version of an application. - -## How the Compatibility Fix Infrastructure Works - -The Compatibility Fix infrastructure uses the linking ability of APIs to redirect an application from Windows code directly to alternative code that implements the compatibility fix. - -The Windows Portable Executable File Format includes headers that contain the data directories that are used to provide a layer of indirection between the application and the linked file. API calls to the external binary files take place through the Import Address Table (IAT), which then directly calls the Windows operating system, as shown in the following figure. - -![act app calls operating system through iat.](images/dep-win8-l-act-appcallosthroughiat.jpg) - -Specifically, the process modifies the address of the affected Windows function in the IAT to point to the compatibility fix code, as shown in the following figure. - -![act app redirect with compatibility fix.](images/dep-win8-l-act-appredirectwithcompatfix.jpg) - ->[!NOTE] ->For statically linked DLLs, the code redirection occurs as the application loads. You can also fix dynamically linked DLLs by hooking into the GetProcAddress API. - -## Design Implications of the Compatibility Fix Infrastructure - -There are important considerations to keep in mind when determining your application fix strategy, due to certain characteristics of the Compatibility Fix infrastructure. - -- The compatibility fix is not part of the Windows operating system (as shown in the previous figure). Therefore, the same security restrictions apply to the compatibility fix as apply to the application code, which means that you cannot use compatibility fixes to bypass any of the security mechanisms of the operating system. Therefore, compatibility fixes do not increase your security exposure, nor do you need to lower your security settings to accommodate compatibility fixes. - -- The Compatibility Fix infrastructure injects additional code into the application before it calls the operating system. This means that any remedy that can be accomplished by a compatibility fix can also be addressed by fixing the application code. - -- The compatibility fixes run as user-mode code inside of a user-mode application process. This means that you cannot use a compatibility fix to fix kernel-mode code issues. For example, you cannot use a compatibility fix to resolve device-driver issues. - - > [!NOTE] - > Some antivirus, firewall, and anti-spyware code runs in kernel mode. - -## Determining When to Use a Compatibility Fix - -The decision to use compatibility fixes to remedy your compatibility issues may involve more than just technical issues. The following scenarios reflect other common reasons for using a compatibility fix. - -### Scenario 1 - -**The compatibility issue exists on an application which is no longer supported by the vendor.** - -As in many companies, you may run applications for which the vendor has ended support. In this situation, you cannot have the vendor make the fix, nor can you access the source code to modify the issue yourself. However, it is possible that the use of a compatibility fix might resolve the compatibility issue. - -### Scenario 2 - -**The compatibility issue exists on an internally created application.** - -While it is preferable to fix the application code to resolve the issue, this is not always possible. Your internal team might not be able to fix all of the issues prior to the deployment of the new operating system. Instead, they might choose to employ a compatibility fix anywhere that it is possible. They can then fix the code only for issues that cannot be resolved in this manner. Through this method, your team can modify the application as time permits, without delaying the deployment of the new operating system into your environment. - -### Scenario 3 - -**The compatibility issue exists on an application for which a compatible version is to be released in the near future, or an application that is not critical to the organization, regardless of its version.** - -In the situation where an application is either unimportant to your organization, or for which a newer, compatible version is to be released shortly, you can use a compatibility fix as a temporary solution. This means that you can continue to use the application without delaying the deployment of a new operating system, with the intention of updating your configuration as soon as the new version is released. - -## Determining Which Version of an Application to Fix - -You can apply a compatibility fix to a particular version of an application, either by using the "up to or including" clause or by selecting that specific version. This means that the next version of the application will not have the compatibility fix automatically applied. This is important, because it allows you to continue to use your application, but it also encourages the vendor to fix the application. - -## Support for Compatibility Fixes - -Compatibility fixes are shipped as part of the Windows operating system and are updated by using Windows Update. Therefore, they receive the same level of support as Windows itself. - -You can apply the compatibility fixes to any of your applications. However, Microsoft does not provide the tools to use the Compatibility Fix infrastructure to create your own custom fixes. - -## Related topics - -[Managing Application-Compatibility Fixes and Custom Fix Databases](managing-application-compatibility-fixes-and-custom-fix-databases.md) diff --git a/windows/deployment/planning/using-the-compatibility-administrator-tool.md b/windows/deployment/planning/using-the-compatibility-administrator-tool.md deleted file mode 100644 index d938b218f9..0000000000 --- a/windows/deployment/planning/using-the-compatibility-administrator-tool.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: Using the Compatibility Administrator Tool (Windows 10) -description: This section provides information about using the Compatibility Administrator tool. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Using the Compatibility Administrator Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -This section provides information about using the Compatibility Administrator tool. - -## In this section - -|Topic|Description| -|--- |--- | -|[Available Data Types and Operators in Compatibility Administrator](available-data-types-and-operators-in-compatibility-administrator.md)|The Compatibility Administrator tool provides a way to query your custom-compatibility databases.| -|[Searching for Fixed Applications in Compatibility Administrator](searching-for-fixed-applications-in-compatibility-administrator.md)|With the search functionality in Compatibility Administrator, you can locate specific executable (.exe) files with previously applied compatibility fixes, compatibility modes, or AppHelp messages. This is particularly useful if you are trying to identify applications with a specific compatibility fix or identifying which fixes are applied to a specific application.| -|[Searching for Installed Compatibility Fixes with the Query Tool in Compatibility Administrator](searching-for-installed-compatibility-fixes-with-the-query-tool-in-compatibility-administrator.md)|You can access the Query tool from within Compatibility Administrator. The Query tool provides the same functionality as using the Search feature.| -|[Creating a Custom Compatibility Fix in Compatibility Administrator](creating-a-custom-compatibility-fix-in-compatibility-administrator.md)|The Compatibility Administrator tool uses the term fix to describe the combination of compatibility information added to a customized database for a specific application. This combination can include single application fixes, groups of fixes that work together as a compatibility mode, and blocking and non-blocking AppHelp messages.| -|[Creating a Custom Compatibility Mode in Compatibility Administrator](creating-a-custom-compatibility-mode-in-compatibility-administrator.md)|Windows® provides several compatibility modes, groups of compatibility fixes found to resolve many common application-compatibility issues. While working with Compatibility Administrator, you might decide to group some of your individual compatibility fixes into a custom-compatibility mode, which you can then deploy and use on any of your compatibility databases.| -|[Creating an AppHelp Message in Compatibility Administrator](creating-an-apphelp-message-in-compatibility-administrator.md)|The Compatibility Administrator tool enables you to create an AppHelp text message. This is a blocking or non-blocking message that appears when a user starts an application that you know has major functionality issues on the Windows® operating system.| -|[Viewing the Events Screen in Compatibility Administrator](viewing-the-events-screen-in-compatibility-administrator.md)|The **Events** screen enables you to record and to view your activities in the Compatibility Administrator tool, provided that the screen is open while you perform the activities.| -|[Enabling and Disabling Compatibility Fixes in Compatibility Administrator](enabling-and-disabling-compatibility-fixes-in-compatibility-administrator.md)|You can disable and enable individual compatibility fixes in your customized databases for testing and troubleshooting purposes.| -|[Installing and Uninstalling Custom Compatibility Databases in Compatibility Administrator](installing-and-uninstalling-custom-compatibility-databases-in-compatibility-administrator.md)|The Compatibility Administrator tool enables the creation and the use of custom-compatibility and standard-compatibility databases. Both the custom databases and the standard databases store the known compatibility fixes, compatibility modes, and AppHelp messages. They also store the required application-matching information for installation on your local computers.| \ No newline at end of file diff --git a/windows/deployment/planning/using-the-sdbinstexe-command-line-tool.md b/windows/deployment/planning/using-the-sdbinstexe-command-line-tool.md deleted file mode 100644 index d9152b5782..0000000000 --- a/windows/deployment/planning/using-the-sdbinstexe-command-line-tool.md +++ /dev/null @@ -1,68 +0,0 @@ ---- -title: Using the Sdbinst.exe Command-Line Tool (Windows 10) -description: Learn how to deploy customized database (.sdb) files using the Sdbinst.exe Command-Line Tool. Review a list of command-line options. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Using the Sdbinst.exe Command-Line Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2016 -- Windows Server 2012 -- Windows Server 2008 R2 - -Deploy your customized database (.sdb) files to other computers in your organization. That is, before your compatibility fixes, compatibility modes, and AppHelp messages are applied. You can deploy your customized database files in several ways. By using a logon script, by using Group Policy, or by performing file copy operations. - -After you deploy and store the customized databases on each of your local computers, you must register the database files. -Until you register the database files, the operating system is unable to identify the available compatibility fixes when starting an application. - -## Command-Line Options for Deploying Customized Database Files - -Sample output from the command `Sdbinst.exe /?` in an elevated CMD window: - -```console -Microsoft Windows [Version 10.0.14393] -(c) 2016 Microsoft Corporation. All rights reserved. - -C:\Windows\system32>Sdbinst.exe /? -Usage: Sdbinst.exe [-?] [-q] [-u] [-g] [-p] [-n[:WIN32|WIN64]] myfile.sdb | {guid} | "name" - - -? - print this help text. - -p - Allow SDBs containing patches. - -q - Quiet mode: prompts are auto-accepted. - -u - Uninstall. - -g {guid} - GUID of file (uninstall only). - -n "name" - Internal name of file (uninstall only). - -C:\Windows\system32>_ -``` - -The command-line options use the following conventions: - -Sdbinst.exe \[-?\] \[-p\] \[-q\] \[-u\] \[-g\] \[-u filepath\] \[-g *GUID*\] \[-n *"name"*\] - -The following table describes the available command-line options. - -|Option|Description| -|--- |--- | -|-?|Displays the Help for the Sdbinst.exe tool.

    For example,
    `sdbinst.exe -?`| -|-p|Allows SDBs' installation with Patches.

    For example,
    `sdbinst.exe -p C:\Windows\AppPatch\Myapp.sdb`| -|-q|Does a silent installation with no visible window, status, or warning information. Fatal errors appear only in Event Viewer (Eventvwr.exe).

    For example,
    `sdbinst.exe -q`| -|-u *filepath*|Does an uninstallation of the specified database.

    For example,
    `sdbinst.exe -u C:\example.sdb`| -|-g *GUID*|Specifies the customized database to uninstall by a globally unique identifier (GUID).

    For example,
    `sdbinst.exe -g 6586cd8f-edc9-4ea8-ad94-afabea7f62e3`| -|-n *"name"*|Specifies the customized database to uninstall by file name.

    For example,
    `sdbinst.exe -n "My_Database"`| - -## Related articles - -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) \ No newline at end of file diff --git a/windows/deployment/planning/using-the-sua-tool.md b/windows/deployment/planning/using-the-sua-tool.md deleted file mode 100644 index c67a5ba90a..0000000000 --- a/windows/deployment/planning/using-the-sua-tool.md +++ /dev/null @@ -1,77 +0,0 @@ ---- -title: Using the SUA Tool (Windows 10) -description: The Standard User Analyzer (SUA) tool can test applications and monitor API calls to detect compatibility issues with the User Account Control (UAC) feature. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Using the SUA Tool - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -By using the Standard User Analyzer (SUA) tool, you can test your applications and monitor API calls to detect compatibility issues with the User Account Control (UAC) feature. - -The SUA Wizard also addresses UAC-related issues. In contrast to the SUA tool, the SUA Wizard guides you through the process step by step, without the in-depth analysis of the SUA tool. For information about the SUA Wizard, see [Using the SUA Wizard](using-the-sua-wizard.md). - -In the SUA tool, you can turn virtualization on and off. When you turn virtualization off, the tested application may function more like the way it does in earlier versions of Windows®. - -In the SUA tool, you can choose to run the application as **Administrator** or as **Standard User**. Depending on your selection, you may locate different types of UAC-related issues. - -## Testing an Application by Using the SUA Tool - -Before you can use the SUA tool, you must install Application Verifier. You must also install the Microsoft® .NET Framework 3.5 or later. - -The following flowchart shows the process of using the SUA tool. - -![act sua flowchart.](images/dep-win8-l-act-suaflowchart.jpg) - -**To collect UAC-related issues by using the SUA tool** - -1. Close any open instance of the SUA tool or SUA Wizard on your computer. - - If there is an existing SUA instance on the computer, the SUA tool opens in log viewer mode instead of normal mode. In log viewer mode, you cannot start applications, which prevents you from collecting UAC issues. - -2. Run the Standard User Analyzer. - -3. In the **Target Application** box, browse to the executable file for the application that you want to analyze, and then double-click to select it. - -4. Clear the **Elevate** check box, and then click **Launch**. - - If a **Permission denied** dialog box appears, click **OK**. The application starts, despite the warning. - -5. Exercise the aspects of the application for which you want to gather information about UAC issues. - -6. Exit the application. - -7. Review the information from the various tabs in the SUA tool. For information about each tab, see [Tabs on the SUA Tool Interface](tabs-on-the-sua-tool-interface.md). - -**To review and apply the recommended mitigations** - -1. In the SUA tool, on the **Mitigation** menu, click **Apply Mitigations**. - -2. Review the recommended compatibility fixes. - -3. Click **Apply**. - - The SUA tool generates a custom compatibility-fix database and automatically applies it to the local computer, so that you can test the fixes to see whether they worked. - -## Related topics -[Tabs on the SUA Tool Interface](tabs-on-the-sua-tool-interface.md) - -[Showing Messages Generated by the SUA Tool](showing-messages-generated-by-the-sua-tool.md) - -[Applying Filters to Data in the SUA Tool](applying-filters-to-data-in-the-sua-tool.md) - -[Fixing Applications by Using the SUA Tool](fixing-applications-by-using-the-sua-tool.md) \ No newline at end of file diff --git a/windows/deployment/planning/using-the-sua-wizard.md b/windows/deployment/planning/using-the-sua-wizard.md deleted file mode 100644 index 5107afeb74..0000000000 --- a/windows/deployment/planning/using-the-sua-wizard.md +++ /dev/null @@ -1,75 +0,0 @@ ---- -title: Using the SUA wizard (Windows 10) -description: The Standard User Analyzer (SUA) wizard, although it doesn't offer deep analysis, works much like the SUA tool to test for User Account Control (UAC) issues. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.date: 10/28/2022 -ms.topic: conceptual -ms.subservice: itpro-deploy ---- - -# Using the SUA wizard - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The Standard User Analyzer (SUA) wizard works much like the SUA tool to evaluate User Account Control (UAC) issues. However, the SUA wizard doesn't offer detailed analysis, and it can't disable virtualization or elevate your permissions. - -For information about the SUA tool, see [Using the SUA Tool](using-the-sua-tool.md). - -## Testing an Application by Using the SUA wizard - -Install Application Verifier before you can use the SUA wizard. If Application Verifier isn't installed on the computer that is running the SUA wizard, the SUA wizard notifies you. In addition, install the Microsoft® .NET Framework 3.5 or later before you can use the SUA wizard. - -The following flowchart shows the process of using the SUA wizard. - -![act sua wizard flowchart.](images/dep-win8-l-act-suawizardflowchart.jpg) - -**To test an application by using the SUA wizard** - -1. On the computer where the SUA wizard is installed, sign in by using a non-administrator account. - -2. Run the Standard User Analyzer wizard. - -3. Click **Browse for Application**, browse to the folder that contains the application that you want to test, and then double-click the executable file for the application. - -4. Click **Launch**. - - If you're prompted, elevate your permissions. The SUA wizard may require elevation of permissions to correctly diagnose the application. - - If a **Permission denied** dialog box appears, click **OK**. The application starts, despite the warning. - -5. In the application, exercise the functionality that you want to test. - -6. After you finish testing, exit the application. - - The SUA wizard displays a message that asks whether the application ran without any issues. - -7. Click **No**. - - The SUA wizard shows a list of potential remedies that you might use to fix the application. - -8. Select the fixes that you want to apply, and then click **Launch**. - - The application appears again, with the fixes applied. - -9. Test the application again, and after you finish testing, exit the application. - - The SUA wizard displays a message that asks whether the application ran without any issues. - -10. If the application ran correctly, click **Yes**. - - The SUA wizard closes the issue as resolved on the local computer. - - If the remedies don't fix the issue with the application, click **No** again, and the wizard may offer another remedies. If the other remedies don't fix the issue, the wizard informs you that there are no more remedies available. For information about how to run the SUA tool for more investigation, see [Using the SUA Tool](using-the-sua-tool.md). - -## Related articles -[SUA User's Guide](sua-users-guide.md) \ No newline at end of file diff --git a/windows/deployment/planning/viewing-the-events-screen-in-compatibility-administrator.md b/windows/deployment/planning/viewing-the-events-screen-in-compatibility-administrator.md deleted file mode 100644 index cf1a19004e..0000000000 --- a/windows/deployment/planning/viewing-the-events-screen-in-compatibility-administrator.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: Viewing the Events Screen in Compatibility Administrator (Windows 10) -description: You can use the Events screen to record and view activities in the Compatibility Administrator tool. -manager: aaroncz -ms.author: frankroj -ms.service: windows-client -author: frankroj -ms.topic: conceptual -ms.subservice: itpro-deploy -ms.date: 10/28/2022 ---- - -# Viewing the Events Screen in Compatibility Administrator - -**Applies to** - -- Windows 10 -- Windows 8.1 -- Windows 8 -- Windows 7 -- Windows Server 2012 -- Windows Server 2008 R2 - -The **Events** screen enables you to record and to view your activities in the Compatibility Administrator tool, provided that the screen is open while you perform the activities. - ->[!IMPORTANT] ->The **Events** screen only records your activities when the screen is open. If you perform an action before opening the **Events** screen, the action will not appear in the list. - - **To open the Events screen** - -- On the **View** menu, click **Events**. - -## Handling Multiple Copies of Compatibility Fixes - -Compatibility Administrator enables you to copy your compatibility fixes from one database to another, which can become confusing after adding multiple fixes, compatibility modes, and databases. For example, you can copy a fix called MyFix from Database 1 to Database 2. However, if there is already a fix called MyFix in Database 2, Compatibility Administrator renames the fix as MyFix (1) to avoid duplicate names. - -If you open the **Events** screen and then perform the copy operation, you can see a description of the action, along with the time stamp, which enables you to view your fix information without confusion. - -## Related topics -[Creating a Custom Compatibility Mode in Compatibility Administrator](creating-a-custom-compatibility-mode-in-compatibility-administrator.md)
    -[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md) diff --git a/windows/deployment/s-mode.md b/windows/deployment/s-mode.md deleted file mode 100644 index 8e5e27c8df..0000000000 --- a/windows/deployment/s-mode.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -title: Windows Pro in S mode -description: Overview of Windows Pro and Enterprise in S mode. -ms.localizationpriority: high -ms.service: windows-client -manager: aaroncz -author: frankroj -ms.author: frankroj -ms.topic: conceptual -ms.date: 04/26/2023 -ms.subservice: itpro-deploy ---- - -# Windows Pro in S mode - -S mode is a configuration that's available on all Windows Editions, and it's enabled at the time of manufacturing. Windows can be switched out of S mode at any time, as shown in the picture below. However, the switch is a one-time operation, and can only be undone by a wipe and reload of the operating system. - -:::image type="content" source="images/smodeconfig.png" alt-text="Table listing the capabilities of S mode across the different Windows editions."::: - -## S mode key features - -### Microsoft-verified security - -With Windows in S mode, you'll find your favorite applications in the Microsoft Store, where they're Microsoft-verified for security. You can also feel secure when you're online. Microsoft Edge, your default browser, gives you protection against phishing and socially-engineered malware. - -### Performance that lasts - -Start-ups are quick, and S mode is built to keep them that way. With Microsoft Edge as your browser, your online experience is fast and secure. You'll enjoy a smooth, responsive experience, whether you're streaming videos, opening apps, or being productive on the go. - -### Choice and flexibility - -Save your files to your favorite cloud, like OneDrive or Dropbox, and access them from any device you choose. Browse the Microsoft Store for thousands of apps, and if you don't find exactly what you want, you can easily [switch out of S mode](./windows-10-pro-in-s-mode.md) to Windows Home, Pro, or Enterprise editions at any time and search the web for more choices, as shown below. - -:::image type="content" source="images/s-mode-flow-chart.png" alt-text="Switching out of S mode flow chart."::: - -## Deployment - -Windows in S mode is built for [modern management](/windows/client-management/manage-windows-10-in-your-organization-modern-management), which means using [Windows Autopilot](/mem/autopilot/windows-autopilot) for deployment, and a Mobile Device Management (MDM) solution for management, like Microsoft Intune. - -Windows Autopilot lets you deploy the device directly to a user without IT having to touch the physical device. Instead of manually deploying a custom image, Windows Autopilot will start with a generic device that can only be used to join the company Microsoft Entra tenant or Active Directory domain. Policies are then deployed automatically through MDM, to customize the device to the user and the desired environment. - -For the devices that are shipped in S mode, you can either keep them in S mode, use Windows Autopilot to switch them out of S mode during the first run process, or later using MDM, if desired. - -## Keep line of business apps functioning with Desktop Bridge - -[Desktop Bridge](/windows/uwp/porting/desktop-to-uwp-root) enables you to convert your line of business apps to a packaged app with UWP manifest. After testing and validating the apps, you can distribute them through an MDM solution like Microsoft Intune. - -## Repackage Win32 apps into the MSIX format - -The [MSIX Packaging Tool](/windows/application-management/msix-app-packaging-tool), available from the Microsoft Store, enables you to repackage existing Win32 applications to the MSIX format. You can run your desktop installers through the MSIX Packaging Tool interactively, and obtain an MSIX package that you can deploy through and MDM solution like Microsoft Intune. The MSIX Packaging Tool is another way to get your apps ready to run on Windows in S mode. - -## Related links - -- [Consumer applications for S mode](https://www.microsoft.com/windows/s-mode) -- [S mode devices](https://www.microsoft.com/windows/view-all-devices) -- [Windows Defender Application Control deployment guide](/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide) -- [Microsoft Defender for Endpoint documentation](/microsoft-365/security/defender-endpoint/) diff --git a/windows/deployment/update/images/WIP4Biz_Deployment.png b/windows/deployment/update/images/WIP4Biz_Deployment.png deleted file mode 100644 index bf267aa9eb..0000000000 Binary files a/windows/deployment/update/images/WIP4Biz_Deployment.png and /dev/null differ diff --git a/windows/deployment/update/images/champs-2.png b/windows/deployment/update/images/champs-2.png deleted file mode 100644 index bb87469a35..0000000000 Binary files a/windows/deployment/update/images/champs-2.png and /dev/null differ diff --git a/windows/deployment/update/images/deploy-land.png b/windows/deployment/update/images/deploy-land.png deleted file mode 100644 index bf104b6843..0000000000 Binary files a/windows/deployment/update/images/deploy-land.png and /dev/null differ diff --git a/windows/deployment/update/images/discover-land.png b/windows/deployment/update/images/discover-land.png deleted file mode 100644 index 8f9e30ce10..0000000000 Binary files a/windows/deployment/update/images/discover-land.png and /dev/null differ diff --git a/windows/deployment/update/images/plan-land.png b/windows/deployment/update/images/plan-land.png deleted file mode 100644 index 7569da7ac1..0000000000 Binary files a/windows/deployment/update/images/plan-land.png and /dev/null differ diff --git a/windows/deployment/update/images/update-catalog.png b/windows/deployment/update/images/update-catalog.png deleted file mode 100644 index e199b3a23a..0000000000 Binary files a/windows/deployment/update/images/update-catalog.png and /dev/null differ diff --git a/windows/deployment/vda-subscription-activation.md b/windows/deployment/vda-subscription-activation.md index 922c1e32b5..c84c5ffc60 100644 --- a/windows/deployment/vda-subscription-activation.md +++ b/windows/deployment/vda-subscription-activation.md @@ -6,7 +6,7 @@ ms.author: kaushika author: kaushika-msft manager: cshepard ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.topic: how-to ms.date: 11/14/2023 diff --git a/windows/deployment/volume-activation/activate-forest-by-proxy-vamt.md b/windows/deployment/volume-activation/activate-forest-by-proxy-vamt.md index 1d89c61ebf..77b2422ad4 100644 --- a/windows/deployment/volume-activation/activate-forest-by-proxy-vamt.md +++ b/windows/deployment/volume-activation/activate-forest-by-proxy-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Activate by proxy an Active Directory forest diff --git a/windows/deployment/volume-activation/activate-forest-vamt.md b/windows/deployment/volume-activation/activate-forest-vamt.md index f264dc644b..38a2b96e60 100644 --- a/windows/deployment/volume-activation/activate-forest-vamt.md +++ b/windows/deployment/volume-activation/activate-forest-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Activate an Active Directory forest online diff --git a/windows/deployment/volume-activation/activate-using-active-directory-based-activation-client.md b/windows/deployment/volume-activation/activate-using-active-directory-based-activation-client.md index 6be9e26b91..9db83f0d61 100644 --- a/windows/deployment/volume-activation/activate-using-active-directory-based-activation-client.md +++ b/windows/deployment/volume-activation/activate-using-active-directory-based-activation-client.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: how-to diff --git a/windows/deployment/volume-activation/activate-using-key-management-service-vamt.md b/windows/deployment/volume-activation/activate-using-key-management-service-vamt.md index 9d68177a96..8b7cb6f4a1 100644 --- a/windows/deployment/volume-activation/activate-using-key-management-service-vamt.md +++ b/windows/deployment/volume-activation/activate-using-key-management-service-vamt.md @@ -2,7 +2,7 @@ title: Activate using Key Management Service description: Learn how to use Key Management Service (KMS) to activate Windows. ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.author: kaushika author: kaushika-msft manager: cshepard diff --git a/windows/deployment/volume-activation/activate-windows-clients-vamt.md b/windows/deployment/volume-activation/activate-windows-clients-vamt.md index 73375ba2c1..73e7931626 100644 --- a/windows/deployment/volume-activation/activate-windows-clients-vamt.md +++ b/windows/deployment/volume-activation/activate-windows-clients-vamt.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation appliesto: - ✅ Windows 11 - ✅ Windows 10 diff --git a/windows/deployment/volume-activation/active-directory-based-activation-overview.md b/windows/deployment/volume-activation/active-directory-based-activation-overview.md index ddce9806a9..fd7cd2b724 100644 --- a/windows/deployment/volume-activation/active-directory-based-activation-overview.md +++ b/windows/deployment/volume-activation/active-directory-based-activation-overview.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Active Directory-Based Activation overview diff --git a/windows/deployment/volume-activation/add-remove-computers-vamt.md b/windows/deployment/volume-activation/add-remove-computers-vamt.md index d643fe3e46..b65f84be73 100644 --- a/windows/deployment/volume-activation/add-remove-computers-vamt.md +++ b/windows/deployment/volume-activation/add-remove-computers-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Add and remove computers diff --git a/windows/deployment/volume-activation/add-remove-product-key-vamt.md b/windows/deployment/volume-activation/add-remove-product-key-vamt.md index 653312d500..d9c59f7363 100644 --- a/windows/deployment/volume-activation/add-remove-product-key-vamt.md +++ b/windows/deployment/volume-activation/add-remove-product-key-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Add and remove a product key diff --git a/windows/deployment/volume-activation/appendix-information-sent-to-microsoft-during-activation-client.md b/windows/deployment/volume-activation/appendix-information-sent-to-microsoft-during-activation-client.md index d9f10dc1ba..e6b79a4fad 100644 --- a/windows/deployment/volume-activation/appendix-information-sent-to-microsoft-during-activation-client.md +++ b/windows/deployment/volume-activation/appendix-information-sent-to-microsoft-during-activation-client.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: reference diff --git a/windows/deployment/volume-activation/configure-client-computers-vamt.md b/windows/deployment/volume-activation/configure-client-computers-vamt.md index 0c71f80635..738815801b 100644 --- a/windows/deployment/volume-activation/configure-client-computers-vamt.md +++ b/windows/deployment/volume-activation/configure-client-computers-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Configure client computers diff --git a/windows/deployment/volume-activation/import-export-vamt-data.md b/windows/deployment/volume-activation/import-export-vamt-data.md index 641da415d0..86d27603bc 100644 --- a/windows/deployment/volume-activation/import-export-vamt-data.md +++ b/windows/deployment/volume-activation/import-export-vamt-data.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.date: 11/07/2022 ms.topic: how-to --- diff --git a/windows/deployment/volume-activation/install-kms-client-key-vamt.md b/windows/deployment/volume-activation/install-kms-client-key-vamt.md index 8643b3908a..4ef1a2e420 100644 --- a/windows/deployment/volume-activation/install-kms-client-key-vamt.md +++ b/windows/deployment/volume-activation/install-kms-client-key-vamt.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Install a KMS client key diff --git a/windows/deployment/volume-activation/install-product-key-vamt.md b/windows/deployment/volume-activation/install-product-key-vamt.md index cbd82fea0b..e18cd1b595 100644 --- a/windows/deployment/volume-activation/install-product-key-vamt.md +++ b/windows/deployment/volume-activation/install-product-key-vamt.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Install a product key diff --git a/windows/deployment/volume-activation/install-vamt.md b/windows/deployment/volume-activation/install-vamt.md index ab6ee683e6..625715f83d 100644 --- a/windows/deployment/volume-activation/install-vamt.md +++ b/windows/deployment/volume-activation/install-vamt.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation appliesto: - ✅ Windows 11 - ✅ Windows 10 diff --git a/windows/deployment/volume-activation/introduction-vamt.md b/windows/deployment/volume-activation/introduction-vamt.md index e07192b464..22f9870649 100644 --- a/windows/deployment/volume-activation/introduction-vamt.md +++ b/windows/deployment/volume-activation/introduction-vamt.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.date: 11/07/2022 ms.topic: overview --- diff --git a/windows/deployment/volume-activation/kms-activation-vamt.md b/windows/deployment/volume-activation/kms-activation-vamt.md index af2b05e15d..600f82bc55 100644 --- a/windows/deployment/volume-activation/kms-activation-vamt.md +++ b/windows/deployment/volume-activation/kms-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Run KMS activation diff --git a/windows/deployment/volume-activation/local-reactivation-vamt.md b/windows/deployment/volume-activation/local-reactivation-vamt.md index 13e63058a6..648bc3fb1a 100644 --- a/windows/deployment/volume-activation/local-reactivation-vamt.md +++ b/windows/deployment/volume-activation/local-reactivation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Run local reactivation diff --git a/windows/deployment/volume-activation/monitor-activation-client.md b/windows/deployment/volume-activation/monitor-activation-client.md index db0510c320..c55011bfdc 100644 --- a/windows/deployment/volume-activation/monitor-activation-client.md +++ b/windows/deployment/volume-activation/monitor-activation-client.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.localizationpriority: medium ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.date: 03/29/2024 appliesto: - ✅ Windows 11 diff --git a/windows/deployment/volume-activation/online-activation-vamt.md b/windows/deployment/volume-activation/online-activation-vamt.md index 8aa4cd5cf7..1fe1d34886 100644 --- a/windows/deployment/volume-activation/online-activation-vamt.md +++ b/windows/deployment/volume-activation/online-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Run online activation diff --git a/windows/deployment/volume-activation/plan-for-volume-activation-client.md b/windows/deployment/volume-activation/plan-for-volume-activation-client.md index cf6a3cdced..73cd02164b 100644 --- a/windows/deployment/volume-activation/plan-for-volume-activation-client.md +++ b/windows/deployment/volume-activation/plan-for-volume-activation-client.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.localizationpriority: medium ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.date: 03/29/2024 appliesto: - ✅ Windows 11 diff --git a/windows/deployment/volume-activation/proxy-activation-vamt.md b/windows/deployment/volume-activation/proxy-activation-vamt.md index 0d266aef27..4c5908840c 100644 --- a/windows/deployment/volume-activation/proxy-activation-vamt.md +++ b/windows/deployment/volume-activation/proxy-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Run proxy activation diff --git a/windows/deployment/volume-activation/remove-products-vamt.md b/windows/deployment/volume-activation/remove-products-vamt.md index f8fb84dc37..1800bc6d71 100644 --- a/windows/deployment/volume-activation/remove-products-vamt.md +++ b/windows/deployment/volume-activation/remove-products-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Remove products diff --git a/windows/deployment/volume-activation/scenario-kms-activation-vamt.md b/windows/deployment/volume-activation/scenario-kms-activation-vamt.md index 1d99684233..8fd2902673 100644 --- a/windows/deployment/volume-activation/scenario-kms-activation-vamt.md +++ b/windows/deployment/volume-activation/scenario-kms-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Scenario 3: KMS client activation diff --git a/windows/deployment/volume-activation/scenario-online-activation-vamt.md b/windows/deployment/volume-activation/scenario-online-activation-vamt.md index 03d969a3eb..543fd58ec8 100644 --- a/windows/deployment/volume-activation/scenario-online-activation-vamt.md +++ b/windows/deployment/volume-activation/scenario-online-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Scenario 1: online activation diff --git a/windows/deployment/volume-activation/scenario-proxy-activation-vamt.md b/windows/deployment/volume-activation/scenario-proxy-activation-vamt.md index 167e5b1693..f9c365a5d9 100644 --- a/windows/deployment/volume-activation/scenario-proxy-activation-vamt.md +++ b/windows/deployment/volume-activation/scenario-proxy-activation-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Scenario 2: proxy activation diff --git a/windows/deployment/volume-activation/update-product-status-vamt.md b/windows/deployment/volume-activation/update-product-status-vamt.md index b28a561baf..77abfb5a82 100644 --- a/windows/deployment/volume-activation/update-product-status-vamt.md +++ b/windows/deployment/volume-activation/update-product-status-vamt.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 03/29/2024 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Update product status diff --git a/windows/deployment/volume-activation/use-the-volume-activation-management-tool-client.md b/windows/deployment/volume-activation/use-the-volume-activation-management-tool-client.md index 3b7ff4e572..87c0ac0170 100644 --- a/windows/deployment/volume-activation/use-the-volume-activation-management-tool-client.md +++ b/windows/deployment/volume-activation/use-the-volume-activation-management-tool-client.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation appliesto: - ✅ Windows 11 - ✅ Windows 10 diff --git a/windows/deployment/volume-activation/use-vamt-in-windows-powershell.md b/windows/deployment/volume-activation/use-vamt-in-windows-powershell.md index 3a0a898af4..0c5c3a2d37 100644 --- a/windows/deployment/volume-activation/use-vamt-in-windows-powershell.md +++ b/windows/deployment/volume-activation/use-vamt-in-windows-powershell.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: how-to ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # Use VAMT in Windows PowerShell diff --git a/windows/deployment/volume-activation/vamt-known-issues.md b/windows/deployment/volume-activation/vamt-known-issues.md index 60a69603fb..22960108f4 100644 --- a/windows/deployment/volume-activation/vamt-known-issues.md +++ b/windows/deployment/volume-activation/vamt-known-issues.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 11/07/2022 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # VAMT known issues diff --git a/windows/deployment/volume-activation/vamt-requirements.md b/windows/deployment/volume-activation/vamt-requirements.md index 1c9c294528..04d10c166e 100644 --- a/windows/deployment/volume-activation/vamt-requirements.md +++ b/windows/deployment/volume-activation/vamt-requirements.md @@ -8,7 +8,7 @@ ms.reviewer: nganguly ms.date: 03/29/2024 ms.topic: concept-article ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation --- # VAMT requirements diff --git a/windows/deployment/volume-activation/volume-activation-management-tool.md b/windows/deployment/volume-activation/volume-activation-management-tool.md index 5d8233348d..c087146a5a 100644 --- a/windows/deployment/volume-activation/volume-activation-management-tool.md +++ b/windows/deployment/volume-activation/volume-activation-management-tool.md @@ -6,7 +6,7 @@ author: kaushika-msft manager: cshepard ms.reviewer: nganguly ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.date: 03/29/2024 ms.topic: overview --- diff --git a/windows/deployment/volume-activation/volume-activation-windows.md b/windows/deployment/volume-activation/volume-activation-windows.md index ca9a9b6811..311c6869d2 100644 --- a/windows/deployment/volume-activation/volume-activation-windows.md +++ b/windows/deployment/volume-activation/volume-activation-windows.md @@ -9,7 +9,7 @@ ms.localizationpriority: medium ms.date: 03/29/2024 ms.topic: overview ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation appliesto: - ✅ Windows 11 - ✅ Windows 10 diff --git a/windows/deployment/windows-10-pro-in-s-mode.md b/windows/deployment/windows-10-pro-in-s-mode.md deleted file mode 100644 index f4b7f66792..0000000000 --- a/windows/deployment/windows-10-pro-in-s-mode.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: Switch to Windows 10 Pro/Enterprise from S mode -description: Overview of Windows 10 Pro/Enterprise in S mode. S mode switch options are also outlined in this document. Switching out of S mode is optional. -author: frankroj -ms.author: frankroj -manager: aaroncz -ms.localizationpriority: medium -ms.service: windows-client -ms.topic: conceptual -ms.date: 11/23/2022 -ms.subservice: itpro-deploy ---- - -# Switch to Windows 10 Pro or Enterprise from S mode - -We recommend staying in S mode. However, in some limited scenarios, you might need to switch to Windows 10 Pro, Home, or Enterprise (not in S mode). You can switch devices running Windows 10, version 1709 or later. - -Many other transformations are possible depending on which version and edition of Windows 10 you're starting with. Depending on the details, you might *switch* between S mode and the ordinary version or *convert* between different editions while staying in or out of S mode. The following quick reference table summarizes all of the switches or conversions that are supported by various means: - -| If a device is running this version of Windows 10 | and this edition of Windows 10 | then you can switch or convert it to this edition of Windows 10 by these methods: |   |  | -|-------------|---------------------|-----------------------------------|-------------------------------|--------------------------------------------| -| | | **Store for Education** (switch/convert all devices in your tenant) | **Microsoft Store** (switch/convert one device at a time) | **Intune** (switch/convert any number of devices selected by admin) | -| **Windows 10, version 1709** | Pro in S mode | Pro EDU | Pro | Not by this method | -| | Pro | Pro EDU | Not by any method | Not by any method | -| | Home | Not by any method | Not by any method | Not by any method | -| | | | | | -| **Windows 10, version 1803** | Pro in S mode | Pro EDU in S mode | Pro | Not by this method | -| | Pro | Pro EDU | Not by any method | Not by any method | -| | Home in S mode | Not by any method | Home | Not by this method | -| | Home | Not by any method | Not by any method | Not by any method | -| | | | | | -| **Windows 10, version 1809** | Pro in S mode | Pro EDU in S mode | Pro | Pro | -| | Pro | Pro EDU | Not by any method | Not by any method | -| | Home in S mode | Not by any method | Home | Home | -| | Home | Not by any method | Not by any method | Not by any method | - -Use the following information to switch to Windows 10 Pro through the Microsoft Store. - -> [!IMPORTANT] -> While it's free to switch to Windows 10 Pro, it's not reversible. The only way to rollback this kind of switch is through a [bare-metal recovery (BMR)](/windows-hardware/manufacture/desktop/create-media-to-run-push-button-reset-features-s14) reset. This restores a Windows device to the factory state, even if the user needs to replace the hard drive or completely wipe the drive clean. If a device is switched out of S mode via the Microsoft Store, it will remain out of S mode even after the device is reset. - -## Switch one device through the Microsoft Store - -Use the following information to switch to Windows 10 Pro through the Microsoft Store or by navigating to **Settings** and then **Activation** on the device. - -Note these differences affecting switching modes in various releases of Windows 10: - -- In Windows 10, version 1709, you can switch devices one at a time from Windows 10 Pro in S mode to Windows 10 Pro by using the Microsoft Store or **Settings**. No other switches are possible. - -- In Windows 10, version 1803, you can switch devices running any S mode edition to the equivalent non-S mode edition one at a time by using the Microsoft Store or **Settings**. - -- Windows 10, version 1809, you can switch devices running any S mode edition to the equivalent non-S mode edition one at a time by using the Microsoft Store, **Settings**, or you can switch multiple devices in bulk by using Intune. You can also block users from switching devices themselves. - -1. Sign into the Microsoft Store using your Microsoft account. - -2. Search for "S mode". - -3. In the offer, select **Buy**, **Get**, or **Learn more.** - -You'll be prompted to save your files before the switch starts. Follow the prompts to switch to Windows 10 Pro. - -## Switch one or more devices by using Microsoft Intune - -Starting with Windows 10, version 1809, if you need to switch multiple devices in your environment from Windows 10 Pro in S mode to Windows 10 Pro, you can use Microsoft Intune or any other supported mobile device management software. You can configure devices to switch out of S mode during OOBE or post-OOBE. Switching out of S mode gives you flexibility to manage Windows 10 in S mode devices at any point during the device lifecycle. - -1. Start Microsoft Intune. - -2. Navigate to **Device configuration** > **Profiles** > **Windows 10 and later** > **Edition upgrade and mode switch**. - -3. Follow the instructions to complete the switch. - -## Block users from switching - -You can control which devices or users can use the Microsoft Store to switch out of S mode in Windows 10. To set this policy, go to **Device configuration** > **Profiles** > **Windows 10 and later** > **Edition upgrade and mode switch in Microsoft Intune**, and then choose **Keep in S mode**. - -## S mode management with CSPs - -In addition to using Microsoft Intune or another modern device management tool to manage S mode, you can also use the [WindowsLicensing](/windows/client-management/mdm/windowslicensing-csp) configuration service provider (CSP). In Windows 10, version 1809, we added S mode functionality that lets you switch devices, block devices from switching, and check the status (whether a device is in S mode). - -## Related articles - -[FAQs](https://support.microsoft.com/help/4020089/windows-10-in-s-mode-faq)
    -[Compare Windows 10 editions](https://www.microsoft.com/WindowsForBusiness/Compare)
    -[Windows 10 Pro Education](/education/windows/test-windows10s-for-edu)
    -[Introduction to Microsoft Intune in the Azure portal](/intune/what-is-intune) diff --git a/windows/deployment/windows-autopatch/TOC.yml b/windows/deployment/windows-autopatch/TOC.yml index f4de9aac02..a678f8d182 100644 --- a/windows/deployment/windows-autopatch/TOC.yml +++ b/windows/deployment/windows-autopatch/TOC.yml @@ -42,14 +42,13 @@ href: deploy/windows-autopatch-register-devices.md - name: Windows Autopatch groups overview href: deploy/windows-autopatch-groups-overview.md - items: - - name: Manage Windows Autopatch groups - href: deploy/windows-autopatch-groups-manage-autopatch-groups.md - name: Post-device registration readiness checks href: deploy/windows-autopatch-post-reg-readiness-checks.md - name: Manage href: items: + - name: Manage Windows Autopatch groups + href: manage/windows-autopatch-manage-autopatch-groups.md - name: Customize Windows Update settings href: manage/windows-autopatch-customize-windows-update-settings.md - name: Windows feature updates diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-admin-contacts.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-admin-contacts.md index be8a0b2063..e6ddc81d67 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-admin-contacts.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-admin-contacts.md @@ -3,7 +3,7 @@ title: Add and verify admin contacts description: This article explains how to add and verify admin contacts ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md index 3b2702240b..1c6f73eb6b 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-device-registration-overview.md @@ -3,7 +3,7 @@ title: Device registration overview description: This article provides an overview on how to register devices in Autopatch. ms.date: 02/15/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan @@ -46,7 +46,7 @@ See the following detailed workflow diagram. The diagram covers the Windows Auto | Step | Description | | ----- | ----- | | **Step 1: Identify devices** | IT admin identifies devices to be managed by the Windows Autopatch service. | -| **Step 2: Add devices** | IT admin adds devices through Direct membership or nests other Microsoft Entra ID assigned or dynamic groups into the **Windows Autopatch Device Registration** Microsoft Entra ID assigned group when using adding existing device-based Microsoft Entra groups while [creating](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#create-a-custom-autopatch-group)/[editing](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) Custom Autopatch groups, or [editing](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) the Default Autopatch group

| +| **Step 2: Add devices** | IT admin adds devices through Direct membership or nests other Microsoft Entra ID assigned or dynamic groups into the **Windows Autopatch Device Registration** Microsoft Entra ID assigned group when using adding existing device-based Microsoft Entra groups while [creating](../manage/windows-autopatch-manage-autopatch-groups.md#create-a-custom-autopatch-group)/[editing](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) Custom Autopatch groups, or [editing](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) the Default Autopatch group | | **Step 3: Discover devices** | The Windows Autopatch Discover Devices function discovers devices (hourly) that were previously added by the IT admin into the **Windows Autopatch Device Registration** Microsoft Entra ID assigned group or from Microsoft Entra groups used with Autopatch groups in **step #2**. The Microsoft Entra device ID is used by Windows Autopatch to query device attributes in both Microsoft Intune and Microsoft Entra ID when registering devices into its service.
  1. Once devices are discovered from the Microsoft Entra group, the same function gathers additional device attributes and saves it into its memory during the discovery operation. The following device attributes are gathered from Microsoft Entra ID in this step:
    1. **AzureADDeviceID**
    2. **OperatingSystem**
    3. **DisplayName (Device name)**
    4. **AccountEnabled**
    5. **RegistrationDateTime**
    6. **ApproximateLastSignInDateTime**
  2. In this same step, the Windows Autopatch discover devices function calls another function, the device prerequisite check function. The device prerequisite check function evaluates software-based device-level prerequisites to comply with Windows Autopatch device readiness requirements before registration.
| | **Step 4: Check prerequisites** | The Windows Autopatch prerequisite function makes an Intune Graph API call to sequentially validate device readiness attributes required for the registration process. For detailed information, see the [Detailed prerequisite check workflow diagram](#detailed-prerequisite-check-workflow-diagram) section. The service checks the following device readiness attributes, and/or prerequisites:
  1. **If the device is Intune-managed or not.**
    1. Windows Autopatch looks to see **if the Microsoft Entra device ID has an Intune device ID associated with it**.
      1. If **yes**, it means this device is enrolled into Intune.
      2. If **not**, it means the device isn't enrolled into Intune, hence it can't be managed by the Windows Autopatch service.
    2. **If the device is not managed by Intune**, the Windows Autopatch service can't gather device attributes such as operating system version, Intune enrollment date, device name and other attributes. When this happens, the Windows Autopatch service uses the Microsoft Entra device attributes gathered and saved to its memory in **step 3a**.
      1. Once it has the device attributes gathered from Microsoft Entra ID in **step 3a**, the device is flagged with the **Prerequisite failed** status, then added to the **Not registered** tab so the IT admin can review the reason(s) the device wasn't registered into Windows Autopatch. The IT admin will remediate these devices. In this case, the IT admin should check why the device wasn't enrolled into Intune.
      2. A common reason is when the Microsoft Entra device ID is stale, it doesn't have an Intune device ID associated with it anymore. To remediate, [clean up any stale Microsoft Entra device records from your tenant](windows-autopatch-register-devices.md#clean-up-dual-state-of-hybrid-azure-ad-joined-and-azure-registered-devices-in-your-azure-ad-tenant).
    3. **If the device is managed by Intune**, the Windows Autopatch prerequisite check function continues to the next prerequisite check, which evaluates whether the device has checked into Intune in the last 28 days.
  2. **If the device is a Windows device or not.**
    1. Windows Autopatch looks to see if the device is a Windows and corporate-owned device.
      1. **If yes**, it means this device can be registered with the service because it's a Windows corporate-owned device.
      2. **If not**, it means the device is a non-Windows device, or it's a Windows device but it's a personal device.
  3. **Windows Autopatch checks the Windows SKU family**. The SKU must be either:
    1. **Enterprise**
    2. **Pro**
    3. **Pro Workstation**
  4. **If the device meets the operating system requirements**, Windows Autopatch checks whether the device is either:
    1. **Only managed by Intune.**
      1. If the device is only managed by Intune, the device is marked as Passed all prerequisites.
    2. **Co-managed by both Configuration Manager and Intune.**
      1. If the device is co-managed by both Configuration Manager and Intune, an additional prerequisite check is evaluated to determine if the device satisfies the co-management-enabled workloads required by Windows Autopatch to manage devices in a co-managed state. The required co-management workloads evaluated in this step are:
        1. **Windows Updates Policies**
        2. **Device Configuration**
        3. **Office Click to Run**
      2. If Windows Autopatch determines that one of these workloads isn't enabled on the device, the service marks the device as **Prerequisite failed** and moves the device to the **Not registered** tab.
| | **Step 5: Calculate deployment ring assignment** | Once the device passes all prerequisites described in **step #4**, Windows Autopatch starts its deployment ring assignment calculation. The following logic is used to calculate the Windows Autopatch deployment ring assignment:
  1. If the Windows Autopatch tenant's existing managed device size is **≤ 200**, the deployment ring assignment is **First (5%)**, **Fast (15%)**, remaining devices go to the **Broad ring (80%)**.
  2. If the Windows Autopatch tenant's existing managed device size is **>200**, the deployment ring assignment will be **First (1%)**, **Fast (9%)**, remaining devices go to the **Broad ring (90%)**.
| diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-overview.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-overview.md index acdf9129ce..b7800e6cab 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-overview.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-overview.md @@ -3,7 +3,7 @@ title: Windows Autopatch groups overview description: This article explains what Autopatch groups are ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan @@ -190,7 +190,7 @@ The following are the Microsoft Entra ID assigned groups that represent the soft ### About device registration -Autopatch groups register devices with the Windows Autopatch service when you either [create](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#create-a-custom-autopatch-group) or [edit a Custom Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group), and/or when you [edit the Default Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) to use your existing Microsoft Entra groups instead of the Windows Autopatch Device Registration group provided by the service. +Autopatch groups register devices with the Windows Autopatch service when you either [create](../manage/windows-autopatch-manage-autopatch-groups.md#create-a-custom-autopatch-group) or [edit a Custom Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group), and/or when you [edit the Default Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) to use your existing Microsoft Entra groups instead of the Windows Autopatch Device Registration group provided by the service. ## Common ways to use Autopatch groups diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-post-reg-readiness-checks.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-post-reg-readiness-checks.md index 922580d930..a8ddab157a 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-post-reg-readiness-checks.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-post-reg-readiness-checks.md @@ -3,7 +3,7 @@ title: Post-device registration readiness checks description: This article details how post-device registration readiness checks are performed in Windows Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md index 5836f3979a..703d4ddb4b 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md @@ -3,7 +3,7 @@ title: Register your devices description: This article details how to register devices in Autopatch. ms.date: 07/10/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan @@ -35,7 +35,7 @@ When you either create/edit a [Custom Autopatch group](../deploy/windows-autopat If devices aren't registered, Autopatch groups starts the device registration process by using your existing device-based Microsoft Entra groups instead of the Windows Autopatch Device Registration group. -For more information, see [create Custom Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#create-a-custom-autopatch-group) and [edit Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) to register devices using the Autopatch groups device registration method. +For more information, see [create Custom Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md#create-a-custom-autopatch-group) and [edit Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group) to register devices using the Autopatch groups device registration method. diff --git a/windows/deployment/windows-autopatch/index.yml b/windows/deployment/windows-autopatch/index.yml index 3385e19bee..d8f637c20b 100644 --- a/windows/deployment/windows-autopatch/index.yml +++ b/windows/deployment/windows-autopatch/index.yml @@ -13,7 +13,7 @@ metadata: manager: aaroncz ms.date: 05/30/2022 #Required; mm/dd/yyyy format. ms.service: windows-client - ms.subservice: itpro-updates + ms.subservice: autopatch ms.collection: - highpri - tier2 diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-customize-windows-update-settings.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-customize-windows-update-settings.md index 8425bd6056..bfd579ee3b 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-customize-windows-update-settings.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-customize-windows-update-settings.md @@ -3,7 +3,7 @@ title: Customize Windows Update settings Autopatch groups experience description: How to customize Windows Updates with Autopatch groups ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-edge.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-edge.md index e72d188447..a8274a7d80 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-edge.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-edge.md @@ -3,7 +3,7 @@ title: Microsoft Edge description: This article explains how Microsoft Edge updates are managed in Windows Autopatch ms.date: 09/15/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-exclude-device.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-exclude-device.md index 3bd258dff3..ce0f4a6c0b 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-exclude-device.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-exclude-device.md @@ -3,7 +3,7 @@ title: Exclude a device description: This article explains how to exclude a device from the Windows Autopatch service ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-manage-autopatch-groups.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-autopatch-groups.md similarity index 98% rename from windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-manage-autopatch-groups.md rename to windows/deployment/windows-autopatch/manage/windows-autopatch-manage-autopatch-groups.md index cd9cd8132d..f160717b52 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-groups-manage-autopatch-groups.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-autopatch-groups.md @@ -3,7 +3,7 @@ title: Manage Windows Autopatch groups description: This article explains how to manage Autopatch groups ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan @@ -180,4 +180,4 @@ When you create or edit the Custom or Default Autopatch group, Windows Autopatch #### Device conflict post device registration -Autopatch groups will keep monitoring for all device conflict scenarios listed in the [Manage device conflict scenarios when using Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#manage-device-conflict-scenarios-when-using-autopatch-groups) section even after devices were successfully registered with the service. +Autopatch groups will keep monitoring for all device conflict scenarios listed in the [Manage device conflict scenarios when using Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md#manage-device-conflict-scenarios-when-using-autopatch-groups) section even after devices were successfully registered with the service. diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-driver-and-firmware-updates.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-driver-and-firmware-updates.md index d3a0379d03..50979877ff 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-driver-and-firmware-updates.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-driver-and-firmware-updates.md @@ -3,7 +3,7 @@ title: Manage driver and firmware updates description: This article explains how you can manage driver and firmware updates with Windows Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-windows-feature-update-releases.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-windows-feature-update-releases.md index 8c21ff7513..dbdbcdcdc5 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-windows-feature-update-releases.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-windows-feature-update-releases.md @@ -3,7 +3,7 @@ title: Manage Windows feature update releases description: This article explains how you can manage Windows feature updates with Autopatch groups ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-apps-enterprise.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-apps-enterprise.md index faa825d861..7cfc8cb222 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-apps-enterprise.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-apps-enterprise.md @@ -3,7 +3,7 @@ title: Microsoft 365 Apps for enterprise description: This article explains how Windows Autopatch manages Microsoft 365 Apps for enterprise updates ms.date: 10/27/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-policies.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-policies.md index fab099ab47..2311528bed 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-policies.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-microsoft-365-policies.md @@ -3,7 +3,7 @@ title: Microsoft 365 Apps for enterprise update policies description: This article explains the Microsoft 365 Apps for enterprise policies in Windows Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-support-request.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-support-request.md index 13b19e6e47..c6eb294c1a 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-support-request.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-support-request.md @@ -3,7 +3,7 @@ title: Submit a support request description: Details how to contact the Windows Autopatch Service Engineering Team and submit support requests ms.date: 09/06/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-teams.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-teams.md index 3945ea4bca..37a7cc46c9 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-teams.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-teams.md @@ -3,7 +3,7 @@ title: Microsoft Teams description: This article explains how Microsoft Teams updates are managed in Windows Autopatch ms.date: 09/15/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-unenroll-tenant.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-unenroll-tenant.md index 52ae00fad6..2101b7f827 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-unenroll-tenant.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-unenroll-tenant.md @@ -3,7 +3,7 @@ title: Unenroll your tenant description: This article explains what unenrollment means for your organization and what actions you must take. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-feature-update-overview.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-feature-update-overview.md index 24c4fc7e02..677478a775 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-feature-update-overview.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-feature-update-overview.md @@ -3,7 +3,7 @@ title: Windows feature updates overview description: This article explains how Windows feature updates are managed with Autopatch groups ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: overview ms.localizationpriority: medium author: tiaraquan @@ -98,8 +98,8 @@ There are two scenarios that the Global release is used: | Scenario | Description | | ----- | ----- | -| Scenario #1 | You assign Microsoft Entra groups to be used with the deployment ring (Last) or you add additional deployment rings when you customize the [Default Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group).

A global Windows feature update policy is automatically assigned behind the scenes to the newly added deployment rings or when you assigned Microsoft Entra groups to the deployment ring (Last) in the Default Autopatch group.

| -| Scenario #2 | You create new [Custom Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#create-a-custom-autopatch-group).

The global Windows feature policy is automatically assigned behind the scenes to all deployment rings as part of the Custom Autopatch groups you create.

| +| Scenario #1 | You assign Microsoft Entra groups to be used with the deployment ring (Last) or you add additional deployment rings when you customize the [Default Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#edit-the-default-or-a-custom-autopatch-group).

A global Windows feature update policy is automatically assigned behind the scenes to the newly added deployment rings or when you assigned Microsoft Entra groups to the deployment ring (Last) in the Default Autopatch group.

| +| Scenario #2 | You create new [Custom Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md#create-a-custom-autopatch-group).

The global Windows feature policy is automatically assigned behind the scenes to all deployment rings as part of the Custom Autopatch groups you create.

| > [!NOTE] > Global releases don't show up in the Windows feature updates release management blade. @@ -124,7 +124,7 @@ The differences in between the global and the default Windows feature update pol | Default Windows feature update policy | Global Windows feature update policy | | ----- | ----- | -|
  • Set by default with the Default Autopatch group and assigned to Test, Ring1, Ring2, Ring3. The default policy isn't automatically assigned to the Last ring in the Default Autopatch group.
  • The Windows Autopatch service keeps its minimum Windows OS version updated following the recommendation of minimum Windows OS version [currently serviced by the Windows servicing channels](/windows/release-health/release-information?msclkid=ee885719baa511ecb838e1a689da96d2).
|
  • Set by default and assigned to all new deployment rings added as part of the Default Autopatch group customization.
  • Set by default and assigned to all deployment rings created as part of Custom Autopatch groups.
+|
  • Set by default with the Default Autopatch group and assigned to Test, Ring1, Ring2, Ring3. The default policy isn't automatically assigned to the Last ring in the Default Autopatch group.
  • The Windows Autopatch service keeps its minimum Windows OS version updated following the recommendation of minimum Windows OS version [currently serviced by the Windows servicing channels](/windows/release-health/release-information?msclkid=ee885719baa511ecb838e1a689da96d2).
|
  • Set by default and assigned to all new deployment rings added as part of the Default Autopatch group customization.
  • Set by default and assigned to all deployment rings created as part of Custom Autopatch groups.
| ### Custom release diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-communications.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-communications.md index 139508380f..a606ae1c4c 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-communications.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-communications.md @@ -3,7 +3,7 @@ title: Windows quality update communications description: This article explains Windows quality update communications ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-end-user-exp.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-end-user-exp.md index 5e617d6e2c..44bd7e2167 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-end-user-exp.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-end-user-exp.md @@ -3,7 +3,7 @@ title: Windows quality update end user experience description: This article explains the Windows quality update end user experience ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: conceptual ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-overview.md b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-overview.md index cf05f0f72f..5e98dae0ea 100644 --- a/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-overview.md +++ b/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-quality-update-overview.md @@ -3,7 +3,7 @@ title: Windows quality updates overview with Autopatch groups experience description: This article explains how Windows quality updates are managed with Autopatch ms.date: 05/24/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: conceptual ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/media/release-process-timeline.png b/windows/deployment/windows-autopatch/media/release-process-timeline.png deleted file mode 100644 index 693ad5ecf9..0000000000 Binary files a/windows/deployment/windows-autopatch/media/release-process-timeline.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-historical-report.png b/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-historical-report.png deleted file mode 100644 index 4a7cf97197..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-historical-report.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-report.png b/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-report.png deleted file mode 100644 index 31350b563f..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-autopatch-all-devices-report.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-eligible-devices-historical-report.png b/windows/deployment/windows-autopatch/media/windows-autopatch-eligible-devices-historical-report.png deleted file mode 100644 index cb56852f3d..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-autopatch-eligible-devices-historical-report.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-ineligible-devices-historical-report.png b/windows/deployment/windows-autopatch/media/windows-autopatch-ineligible-devices-historical-report.png deleted file mode 100644 index 2aeacfd0d5..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-autopatch-ineligible-devices-historical-report.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-autopatch-summary-dashboard.png b/windows/deployment/windows-autopatch/media/windows-autopatch-summary-dashboard.png deleted file mode 100644 index 82cb1b1fcd..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-autopatch-summary-dashboard.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-feature-force-update.png b/windows/deployment/windows-autopatch/media/windows-feature-force-update.png deleted file mode 100644 index 2f0dd5f089..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-feature-force-update.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-feature-typical-update-experience.png b/windows/deployment/windows-autopatch/media/windows-feature-typical-update-experience.png deleted file mode 100644 index a49f39ce2c..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-feature-typical-update-experience.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/media/windows-feature-update-grace-period.png b/windows/deployment/windows-autopatch/media/windows-feature-update-grace-period.png deleted file mode 100644 index d0829576f6..0000000000 Binary files a/windows/deployment/windows-autopatch/media/windows-feature-update-grace-period.png and /dev/null differ diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-device-alerts.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-device-alerts.md index 4556c227ea..4e75b89b16 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-device-alerts.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-device-alerts.md @@ -3,7 +3,7 @@ title: Device alerts description: Provide notifications and information about the necessary steps to keep your devices up to date. ms.date: 07/08/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-maintain-environment.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-maintain-environment.md index 6273ceb86d..960e0011c7 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-maintain-environment.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-maintain-environment.md @@ -3,7 +3,7 @@ title: Maintain the Windows Autopatch environment description: This article details how to maintain the Windows Autopatch environment ms.date: 09/15/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-policy-health-and-remediation.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-policy-health-and-remediation.md index 16dd0cc679..e7228e6c3e 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-policy-health-and-remediation.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-policy-health-and-remediation.md @@ -3,7 +3,7 @@ title: policy health and remediation description: Describes what Autopatch does it detects policies in the tenant are either missing or modified to states that affect the service ms.date: 07/10/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-reliability-report.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-reliability-report.md index e3a3f4b0c5..71129f797d 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-reliability-report.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-reliability-report.md @@ -3,10 +3,10 @@ title: Reliability report description: This article describes the reliability score for each Windows quality update cycle based on stop error codes detected on managed devices. ms.date: 04/09/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium -author: tiaraquan +author: tiaraquan ms.author: tiaraquan manager: aaroncz ms.reviewer: hathind diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-resolve-policy-conflicts.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-resolve-policy-conflicts.md index 3967e6a3f5..d878aa4411 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-resolve-policy-conflicts.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-resolve-policy-conflicts.md @@ -3,10 +3,10 @@ title: Resolve policy conflicts description: This article describes how to resolve Windows Autopatch policy conflicts. ms.date: 04/09/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium -author: tiaraquan +author: tiaraquan ms.author: tiaraquan manager: aaroncz ms.reviewer: hathind @@ -38,20 +38,20 @@ With this feature, IT admins can view: Alerts are raised when devices report policy conflicts. Autopatch policies are assigned to Autopatch groups. Devices that are members of Autopatch groups are expected to receive only Windows Autopatch policies. -Once you resolve the conflict, it takes effect on the device at the next Intune sync. This view is refreshed every 24 hours. It can take up to 72 hours after the conflict is resolved for the view to be updated. +Once you resolve the conflict, it takes effect on the device at the next Intune sync. This view is refreshed every 24 hours. It can take up to 72 hours after the conflict is resolved for the view to be updated. > [!NOTE] > This view only includes policy conflicts between Microsoft Intune policies. This view doesn’t include policy issues caused by other configurations, for example, group policy settings, registry settings that are changed by scripts and prevent Windows Autopatch from deploying updates.

When Windows Autopatch detects Intune based policies are missing or modified, this information is displayed with detailed recommended actions, and described in [Policy health and remediation](../operate/windows-autopatch-policy-health-and-remediation.md).

To ensure devices remain healthy and not affected by group policies, see [Post-device registration readiness checks](../deploy/windows-autopatch-post-reg-readiness-checks.md#details-about-the-post-device-registration-readiness-checks).

## Policy conflict view -This view includes the list of Windows Autopatch policies ([Expected policies](#policy-conflict-alert-details)) that are assigned to various Windows Autopatch groups that include devices. When the Expected policy can't be successfully assigned to one or more devices, because of an equivalent setting in another Intune policy targeting the device, the conflict is detected, and reported as a [Conflicting policy](#policy-conflict-alert-details). +This view includes the list of Windows Autopatch policies ([Expected policies](#policy-conflict-alert-details)) that are assigned to various Windows Autopatch groups that include devices. When the Expected policy can't be successfully assigned to one or more devices, because of an equivalent setting in another Intune policy targeting the device, the conflict is detected, and reported as a [Conflicting policy](#policy-conflict-alert-details). -If the Expected policy conflicts with multiple Intune policies, each conflict is displayed in different lines in the Policy conflict view. +If the Expected policy conflicts with multiple Intune policies, each conflict is displayed in different lines in the Policy conflict view. **To view all policies conflicting with the expected policies:** -1. Go to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). +1. Go to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). 2. Navigate to **Devices** > **Windows Autopatch** > **Policy health**. 3. In the **Policy conflicts** tab, the list of expected policies and conflicting policies is displayed. 4. Select **View alert** and review the details of the **Recommended action** and alert details. @@ -71,7 +71,7 @@ All alerts displayed in this flyout include the following details. You must revi ## Affected devices view -This view includes the list of devices with policy conflicts with the [Expected policy](#policy-conflict-alert-details). It’s possible for devices to have multiple conflicting policies, due to their membership in various groups. +This view includes the list of devices with policy conflicts with the [Expected policy](#policy-conflict-alert-details). It’s possible for devices to have multiple conflicting policies, due to their membership in various groups. You can navigate to this view from the Affected devices column link in the Policy conflicts view, or directly from Policy health blade. This page displays a filtered device list, when navigating from the Policy conflicts view. Affected devices only include devices that have a successful Intune sync status in the last 28 days. diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-status-report.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-status-report.md index d8e5c7be2a..5b210062a3 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-status-report.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-status-report.md @@ -3,7 +3,7 @@ title: Feature update status report description: Provides a per device view of the current Windows OS upgrade status for all devices registered with Windows Autopatch. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-summary-dashboard.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-summary-dashboard.md index 38af149ad8..f630537c12 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-summary-dashboard.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-summary-dashboard.md @@ -3,7 +3,7 @@ title: Windows feature update summary dashboard description: Provides a broader view of the current Windows OS upgrade status for all devices registered with Windows Autopatch. ms.date: 01/22/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-trending-report.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-trending-report.md index 2d724d0af1..39ffb54eff 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-trending-report.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-feature-update-trending-report.md @@ -3,7 +3,7 @@ title: Feature update trending report description: Provides a visual representation of Windows OS upgrade trends for all devices over the last 90 days. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-and-feature-update-reports-overview.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-and-feature-update-reports-overview.md index 7d2cb8b29e..fadb440d95 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-and-feature-update-reports-overview.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-and-feature-update-reports-overview.md @@ -1,9 +1,9 @@ --- title: Windows quality and feature update reports overview description: This article details the types of reports available and info about update device eligibility, device update health, device update trends in Windows Autopatch. -ms.date: 07/10/2024 +ms.date: 07/10/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: overview ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-status-report.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-status-report.md index 34b11def99..7c1283c329 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-status-report.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-status-report.md @@ -3,7 +3,7 @@ title: Quality update status report description: Provides a per device view of the current update status for all Windows Autopatch enrolled devices. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-summary-dashboard.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-summary-dashboard.md index 21c684b548..4752f080ec 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-summary-dashboard.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-summary-dashboard.md @@ -3,7 +3,7 @@ title: Windows quality update summary dashboard description: Provides a summary view of the current update status for all devices enrolled into Windows Autopatch ms.date: 01/22/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-trending-report.md b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-trending-report.md index a956837968..df4024c72f 100644 --- a/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-trending-report.md +++ b/windows/deployment/windows-autopatch/monitor/windows-autopatch-windows-quality-update-trending-report.md @@ -3,7 +3,7 @@ title: Quality update trending report description: Provides a visual representation of the update status trend for all devices over the last 90 days. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide.md b/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide.md index c1b7be42ba..caed55c6e2 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide.md +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide.md @@ -3,7 +3,7 @@ title: Windows Autopatch deployment guide description: This guide explains how to successfully deploy Windows Autopatch in your environment ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml b/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml index 2aea84859d..da46669845 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-faq.yml @@ -11,7 +11,7 @@ metadata: author: tiaraquan ms.author: tiaraquan ms.reviwer: hathind - ms.subservice: itpro-updates + ms.subservice: autopatch title: Frequently Asked Questions about Windows Autopatch summary: This article answers frequently asked questions about Windows Autopatch. sections: @@ -79,7 +79,7 @@ sections: No. Don't change, edit, add to, or remove any of the configurations. Doing so might cause unintended configuration conflicts and impact the Windows Autopatch service. For more information about policies and configurations, see [Changes made at tenant enrollment](/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant). - question: How can I represent our organizational structure with our own deployment cadence? answer: | - [Windows Autopatch groups](../deploy/windows-autopatch-groups-overview.md) helps you manage updates in a way that makes sense for your businesses. For more information, see [Windows Autopatch groups overview](../deploy/windows-autopatch-groups-overview.md) and [Manage Windows Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md). + [Windows Autopatch groups](../deploy/windows-autopatch-groups-overview.md) helps you manage updates in a way that makes sense for your businesses. For more information, see [Windows Autopatch groups overview](../deploy/windows-autopatch-groups-overview.md) and [Manage Windows Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md). - name: Update management questions: - question: What systems does Windows Autopatch update? diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-overview.md b/windows/deployment/windows-autopatch/overview/windows-autopatch-overview.md index f8f71f9db2..e608764ac9 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-overview.md +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-overview.md @@ -3,7 +3,7 @@ title: What is Windows Autopatch? description: Details what the service is and shortcuts to articles. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: overview ms.localizationpriority: medium author: tiaraquan @@ -63,7 +63,7 @@ Microsoft remains committed to the security of your data and the [accessibility] | Area | Description | | ----- | ----- | | Prepare | The following articles describe the mandatory steps to prepare and enroll your tenant into Windows Autopatch:
  • [Prerequisites](../prepare/windows-autopatch-prerequisites.md)
  • [Configure your network](../prepare/windows-autopatch-configure-network.md)
  • [Enroll your tenant](../prepare/windows-autopatch-enroll-tenant.md)
  • [Fix issues found by the Readiness assessment tool](../prepare/windows-autopatch-fix-issues.md)
  • [Roles and responsibilities](../overview/windows-autopatch-roles-responsibilities.md)
| -| Deploy | Once you've enrolled your tenant, this section instructs you to:
  • [Add and verify admin contacts](../deploy/windows-autopatch-admin-contacts.md)
  • [Register your devices](../deploy/windows-autopatch-register-devices.md)
  • [Manage Windows Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md)
| +| Deploy | Once you've enrolled your tenant, this section instructs you to:
  • [Add and verify admin contacts](../deploy/windows-autopatch-admin-contacts.md)
  • [Register your devices](../deploy/windows-autopatch-register-devices.md)
  • [Manage Windows Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md)
| | Operate | This section includes the following information about your day-to-day life with the service:
  • [Update management](../operate/windows-autopatch-groups-update-management.md)
  • [Windows quality and feature update reports](../operate/windows-autopatch-groups-windows-quality-and-feature-update-reports-overview.md)
  • [Maintain your Windows Autopatch environment](../operate/windows-autopatch-maintain-environment.md)
  • [Submit a support request](../operate/windows-autopatch-support-request.md)
  • [Exclude a device](../operate/windows-autopatch-exclude-device.md)
| References | This section includes the following articles:
  • [Changes made at tenant enrollment](../references/windows-autopatch-changes-to-tenant.md)
  • [Windows update policies](../references/windows-autopatch-windows-update-unsupported-policies.md)
  • [Microsoft 365 Apps for enterprise update policies](../references/windows-autopatch-microsoft-365-policies.md)
| diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-privacy.md b/windows/deployment/windows-autopatch/overview/windows-autopatch-privacy.md index 267c55bde3..8c3ecf4bbe 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-privacy.md +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-privacy.md @@ -3,7 +3,7 @@ title: Privacy description: This article provides details about the data platform and privacy compliance for Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/overview/windows-autopatch-roles-responsibilities.md b/windows/deployment/windows-autopatch/overview/windows-autopatch-roles-responsibilities.md index 215fef87ca..792d91220e 100644 --- a/windows/deployment/windows-autopatch/overview/windows-autopatch-roles-responsibilities.md +++ b/windows/deployment/windows-autopatch/overview/windows-autopatch-roles-responsibilities.md @@ -3,7 +3,7 @@ title: Roles and responsibilities description: This article describes the roles and responsibilities provided by Windows Autopatch and what the customer must do ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan @@ -15,7 +15,7 @@ ms.collection: - tier1 --- -# Roles and responsibilities +# Roles and responsibilities This article outlines your responsibilities and Windows Autopatch's responsibilities when: @@ -58,7 +58,7 @@ For more information and assistance with preparing for your Windows Autopatch de | Remediate registration issues
  • [For devices displayed in the **Not ready** tab](../deploy/windows-autopatch-post-reg-readiness-checks.md#about-the-three-tabs-in-the-devices-blade)
  • [For devices displayed in the **Not registered** tab](../deploy/windows-autopatch-post-reg-readiness-checks.md#about-the-three-tabs-in-the-devices-blade)
  • [For devices with conflicting configurations](../references/windows-autopatch-conflicting-configurations.md)
| :heavy_check_mark: | :x: | | Populate the Test and Last deployment ring membership
  • [Default Windows Autopatch group deployment rings](../deploy/windows-autopatch-groups-overview.md#about-the-default-autopatch-group)
  • [Custom Windows Autopatch group deployment rings](../deploy/windows-autopatch-groups-overview.md#about-custom-autopatch-groups)
| :heavy_check_mark: | :x: | | [Manually override device assignments to deployment rings](../operate/windows-autopatch-update-management.md#moving-devices-in-between-deployment-rings) | :heavy_check_mark: | :x: | -| Review device conflict scenarios
  • [Device conflict in deployment rings within an Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#device-conflict-in-deployment-rings-within-an-autopatch-group)
  • [Device conflict across different Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#device-conflict-across-different-autopatch-groups)
| :heavy_check_mark: | :x: | +| Review device conflict scenarios
  • [Device conflict in deployment rings within an Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#device-conflict-in-deployment-rings-within-an-autopatch-group)
  • [Device conflict across different Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md#device-conflict-across-different-autopatch-groups)
| :heavy_check_mark: | :x: | | Communicate to end-users, help desk and stakeholders | :heavy_check_mark: | :x: | ## Manage @@ -68,8 +68,8 @@ For more information and assistance with preparing for your Windows Autopatch de | [Maintain contacts in the Microsoft Intune admin center](../deploy/windows-autopatch-admin-contacts.md) | :heavy_check_mark: | :x: | | [Maintain and manage the Windows Autopatch service configuration](../monitor/windows-autopatch-maintain-environment.md) | :x: | :heavy_check_mark: | | [Maintain customer configuration to align with the Windows Autopatch service configuration](../monitor/windows-autopatch-maintain-environment.md) | :heavy_check_mark: | :x: | -| Resolve service remediated device conflict scenarios
  • [Device conflict in deployment rings within an Autopatch group](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#device-conflict-in-deployment-rings-within-an-autopatch-group)
  • [Default to Custom Autopatch group device conflict](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#default-to-custom-autopatch-group-device-conflict)
| :x: | :heavy_check_mark: | -| Resolve remediated device conflict scenarios
  • [Custom to Custom Autopatch group device conflict](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#custom-to-custom-autopatch-group-device-conflict)
  • [Device conflict prior to device registration](../deploy/windows-autopatch-groups-manage-autopatch-groups.md#device-conflict-prior-to-device-registration)
| :heavy_check_mark: | :x: | +| Resolve service remediated device conflict scenarios
  • [Device conflict in deployment rings within an Autopatch group](../manage/windows-autopatch-manage-autopatch-groups.md#device-conflict-in-deployment-rings-within-an-autopatch-group)
  • [Default to Custom Autopatch group device conflict](../manage/windows-autopatch-manage-autopatch-groups.md#default-to-custom-autopatch-group-device-conflict)
| :x: | :heavy_check_mark: | +| Resolve remediated device conflict scenarios
  • [Custom to Custom Autopatch group device conflict](../manage/windows-autopatch-manage-autopatch-groups.md#custom-to-custom-autopatch-group-device-conflict)
  • [Device conflict prior to device registration](../manage/windows-autopatch-manage-autopatch-groups.md#device-conflict-prior-to-device-registration)
| :heavy_check_mark: | :x: | | Maintain the Test and Last deployment ring membership
  • [Default Windows Autopatch deployment rings](../deploy/windows-autopatch-groups-overview.md#about-the-default-autopatch-group)
  • [Custom Windows Autopatch group deployment rings](../deploy/windows-autopatch-groups-overview.md#about-custom-autopatch-groups)
| :heavy_check_mark: | :x: | | Monitor [Windows update signals](../manage/windows-autopatch-windows-quality-update-signals.md) for safe update release
  • [Pre-release signals](../manage/windows-autopatch-windows-quality-update-signals.md#pre-release-signals)
  • [Early signals](../manage/windows-autopatch-windows-quality-update-signals.md#early-signals)
  • [Device reliability signals](../manage/windows-autopatch-windows-quality-update-signals.md#device-reliability-signals)
| :x: | :heavy_check_mark: | | Test specific [business update scenarios](../manage/windows-autopatch-windows-quality-update-signals.md) | :heavy_check_mark: | :x: | diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-configure-network.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-configure-network.md index dcbb1ae24c..a2149153e3 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-configure-network.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-configure-network.md @@ -3,7 +3,7 @@ title: Configure your network description: This article details the network configurations needed for Windows Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-enroll-tenant.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-enroll-tenant.md index f623474036..7985e205fd 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-enroll-tenant.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-enroll-tenant.md @@ -3,7 +3,7 @@ title: Enroll your tenant description: This article details how to enroll your tenant ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-enrollment-support-request.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-enrollment-support-request.md index 6cd8d98e22..e403b61921 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-enrollment-support-request.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-enrollment-support-request.md @@ -3,7 +3,7 @@ title: Submit a tenant enrollment support request description: This article details how to submit a tenant enrollment support request ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md index d973c0f991..27125d29bd 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-fix-issues.md @@ -3,7 +3,7 @@ title: Fix issues found by the Readiness assessment tool description: This article details how to fix issues found by the Readiness assessment tool. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: how-to ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md index eaccb006f5..b9577e833f 100644 --- a/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md +++ b/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites.md @@ -3,7 +3,7 @@ title: Prerequisites description: This article details the prerequisites needed for Windows Autopatch ms.date: 01/11/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant.md b/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant.md index b91a7f24ed..311771b8a5 100644 --- a/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant.md +++ b/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant.md @@ -3,7 +3,7 @@ title: Changes made at tenant enrollment description: This reference article details the changes made to your tenant when enrolling into Windows Autopatch ms.date: 12/13/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/references/windows-autopatch-conflicting-configurations.md b/windows/deployment/windows-autopatch/references/windows-autopatch-conflicting-configurations.md index aa25114a3d..1b9f1d5647 100644 --- a/windows/deployment/windows-autopatch/references/windows-autopatch-conflicting-configurations.md +++ b/windows/deployment/windows-autopatch/references/windows-autopatch-conflicting-configurations.md @@ -3,7 +3,7 @@ title: Conflicting configurations description: This article explains how to remediate conflicting configurations affecting the Windows Autopatch service. ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/references/windows-autopatch-driver-and-firmware-updates-public-preview-addendum.md b/windows/deployment/windows-autopatch/references/windows-autopatch-driver-and-firmware-updates-public-preview-addendum.md index 9023597983..d18412ab3c 100644 --- a/windows/deployment/windows-autopatch/references/windows-autopatch-driver-and-firmware-updates-public-preview-addendum.md +++ b/windows/deployment/windows-autopatch/references/windows-autopatch-driver-and-firmware-updates-public-preview-addendum.md @@ -3,7 +3,7 @@ title: Driver and firmware updates for Windows Autopatch Public Preview Addendum description: This article explains how driver and firmware updates are managed in Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: legal ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/references/windows-autopatch-windows-update-unsupported-policies.md b/windows/deployment/windows-autopatch/references/windows-autopatch-windows-update-unsupported-policies.md index 708985a6bf..03072b748f 100644 --- a/windows/deployment/windows-autopatch/references/windows-autopatch-windows-update-unsupported-policies.md +++ b/windows/deployment/windows-autopatch/references/windows-autopatch-windows-update-unsupported-policies.md @@ -3,7 +3,7 @@ title: Windows update policies description: This article explains Windows update policies in Windows Autopatch ms.date: 07/08/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: concept-article ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2022.md b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2022.md index 7bda20114c..fbf6ff1953 100644 --- a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2022.md +++ b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2022.md @@ -3,7 +3,7 @@ title: What's new 2022 description: This article lists the 2022 feature releases and any corresponding Message center post numbers. ms.date: 12/09/2022 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: whats-new ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md index 3774758175..41e1b7cfd2 100644 --- a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md +++ b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2023.md @@ -3,7 +3,7 @@ title: What's new 2023 description: This article lists the 2023 feature releases and any corresponding Message center post numbers. ms.date: 12/14/2023 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: whats-new ms.localizationpriority: medium author: tiaraquan @@ -100,7 +100,7 @@ Minor corrections such as typos, style, or formatting issues aren't listed. | ----- | ----- | | [Roles and responsibilities](../overview/windows-autopatch-roles-responsibilities.md) | Updated article to include Windows Autopatch groups | | [Windows Autopatch groups overview](../deploy/windows-autopatch-groups-overview.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| -| [Manage Windows Autopatch groups](../deploy/windows-autopatch-groups-manage-autopatch-groups.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| +| [Manage Windows Autopatch groups](../manage/windows-autopatch-manage-autopatch-groups.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| | [Customize Windows Update settings](../operate/windows-autopatch-groups-windows-update.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| | [Windows quality updates](../operate/windows-autopatch-groups-windows-quality-update-overview.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| | [Windows feature updates](../operate/windows-autopatch-groups-windows-feature-update-overview.md) | General Availability
  • [MC628172](https://admin.microsoft.com/adminportal/home#/MessageCenter)
| diff --git a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2024.md b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2024.md index 011615d29b..af94349898 100644 --- a/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2024.md +++ b/windows/deployment/windows-autopatch/whats-new/windows-autopatch-whats-new-2024.md @@ -3,7 +3,7 @@ title: What's new 2024 description: This article lists the 2024 feature releases and any corresponding Message center post numbers. ms.date: 04/09/2024 ms.service: windows-client -ms.subservice: itpro-updates +ms.subservice: autopatch ms.topic: whats-new ms.localizationpriority: medium author: tiaraquan diff --git a/windows/deployment/windows-enterprise-e3-overview.md b/windows/deployment/windows-enterprise-e3-overview.md index fb356d9ce9..f4532464b5 100644 --- a/windows/deployment/windows-enterprise-e3-overview.md +++ b/windows/deployment/windows-enterprise-e3-overview.md @@ -2,7 +2,7 @@ title: Windows Enterprise E3 in CSP description: Describes Windows Enterprise E3, an offering that delivers, by subscription, the features of Windows Enterprise edition. ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.date: 02/13/2024 ms.author: kaushika diff --git a/windows/deployment/windows-subscription-activation.md b/windows/deployment/windows-subscription-activation.md index 824847523c..4d30ca0571 100644 --- a/windows/deployment/windows-subscription-activation.md +++ b/windows/deployment/windows-subscription-activation.md @@ -2,7 +2,7 @@ title: Windows subscription activation description: Learn how to step up from Windows Pro to a Windows Enterprise subscription or from Windows Eduction Pro to a Windows Education subscription. ms.service: windows-client -ms.subservice: itpro-fundamentals +ms.subservice: activation ms.localizationpriority: medium ms.author: kaushika author: kaushika-msft diff --git a/windows/privacy/images/ddv-event-feedback.png b/windows/privacy/images/ddv-event-feedback.png deleted file mode 100644 index 61c1c15e99..0000000000 Binary files a/windows/privacy/images/ddv-event-feedback.png and /dev/null differ diff --git a/windows/privacy/images/ddv-event-view-basic.png b/windows/privacy/images/ddv-event-view-basic.png deleted file mode 100644 index 5668e13bec..0000000000 Binary files a/windows/privacy/images/ddv-event-view-basic.png and /dev/null differ diff --git a/windows/privacy/images/ddv-event-view-filter.png b/windows/privacy/images/ddv-event-view-filter.png deleted file mode 100644 index addd53271d..0000000000 Binary files a/windows/privacy/images/ddv-event-view-filter.png and /dev/null differ diff --git a/windows/privacy/images/ddv-export.png b/windows/privacy/images/ddv-export.png deleted file mode 100644 index 25e62858db..0000000000 Binary files a/windows/privacy/images/ddv-export.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-azure-info-protection.png b/windows/privacy/images/gdpr-azure-info-protection.png deleted file mode 100644 index ff4581286d..0000000000 Binary files a/windows/privacy/images/gdpr-azure-info-protection.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-comp-info-protection.png b/windows/privacy/images/gdpr-comp-info-protection.png deleted file mode 100644 index a332b3476f..0000000000 Binary files a/windows/privacy/images/gdpr-comp-info-protection.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-cve-graph.png b/windows/privacy/images/gdpr-cve-graph.png deleted file mode 100644 index ebc3e7e36b..0000000000 Binary files a/windows/privacy/images/gdpr-cve-graph.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-intelligent-security-graph.png b/windows/privacy/images/gdpr-intelligent-security-graph.png deleted file mode 100644 index 9448465c08..0000000000 Binary files a/windows/privacy/images/gdpr-intelligent-security-graph.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-security-center.png b/windows/privacy/images/gdpr-security-center.png deleted file mode 100644 index 26936520a9..0000000000 Binary files a/windows/privacy/images/gdpr-security-center.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-security-center2.png b/windows/privacy/images/gdpr-security-center2.png deleted file mode 100644 index 971a9918a5..0000000000 Binary files a/windows/privacy/images/gdpr-security-center2.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-security-center3.png b/windows/privacy/images/gdpr-security-center3.png deleted file mode 100644 index 2c5e279211..0000000000 Binary files a/windows/privacy/images/gdpr-security-center3.png and /dev/null differ diff --git a/windows/privacy/images/gdpr-steps-diagram.png b/windows/privacy/images/gdpr-steps-diagram.png deleted file mode 100644 index 8fce18bccd..0000000000 Binary files a/windows/privacy/images/gdpr-steps-diagram.png and /dev/null differ diff --git a/windows/privacy/images/priv-telemetry-levels.png b/windows/privacy/images/priv-telemetry-levels.png deleted file mode 100644 index 9581cee54d..0000000000 Binary files a/windows/privacy/images/priv-telemetry-levels.png and /dev/null differ diff --git a/windows/security/application-security/application-control/windows-defender-application-control/TOC.yml b/windows/security/application-security/application-control/windows-defender-application-control/TOC.yml index c2302c6e47..91cc8b46d0 100644 --- a/windows/security/application-security/application-control/windows-defender-application-control/TOC.yml +++ b/windows/security/application-security/application-control/windows-defender-application-control/TOC.yml @@ -100,8 +100,6 @@ href: deployment/create-code-signing-cert-for-wdac.md - name: Disable WDAC policies href: deployment/disable-wdac-policies.md - - name: LOB Win32 Apps on S Mode - href: deployment/LOB-win32-apps-on-s.md - name: WDAC operational guide href: operations/wdac-operational-guide.md items: diff --git a/windows/security/application-security/application-control/windows-defender-application-control/deployment/LOB-win32-apps-on-s.md b/windows/security/application-security/application-control/windows-defender-application-control/deployment/LOB-win32-apps-on-s.md deleted file mode 100644 index 965a20c625..0000000000 --- a/windows/security/application-security/application-control/windows-defender-application-control/deployment/LOB-win32-apps-on-s.md +++ /dev/null @@ -1,252 +0,0 @@ ---- -title: Allow LOB Win32 apps on Intune-managed S Mode devices -description: Using Windows Defender Application Control (WDAC) supplemental policies, you can expand the S Mode base policy on your Intune-managed devices. -ms.localizationpriority: medium -ms.date: 04/05/2023 -ms.topic: how-to ---- - -# Allow line-of-business Win32 apps on Intune-managed S Mode devices - -> [!NOTE] -> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. For more information, see [Windows Defender Application Control feature availability](../feature-availability.md). - -You can use Microsoft Intune to deploy and run critical Win32 applications, and Windows components that are normally blocked in S mode, on your Intune-managed Windows 10 in S mode devices. For example, PowerShell.exe. - -With Intune, you can configure managed S mode devices using a Windows Defender Application Control (WDAC) supplemental policy that expands the S mode base policy to authorize the apps your organization uses. This feature changes the S mode security posture from "Microsoft has verified every app" to "Microsoft or your organization has verified every app". - -For an overview and brief demo of this feature, see this video: - -> [!VIDEO https://www.microsoft.com/videoplayer/embed/RE4mlcp] - -## Policy authorization process - -![Basic diagram of the policy authorization flow.](../images/wdac-intune-policy-authorization.png) - -The general steps for expanding the S mode base policy on your Intune-managed Windows 10 in S mode devices are to generate a supplemental policy, sign that policy, upload the signed policy to Intune, and assign it to user or device groups. Because you need access to PowerShell cmdlets to generate your supplemental policy, you should create and manage your policies on a non-S mode device. Once the policy has been uploaded to Intune, before deploying the policy more broadly, assign it to a single test Windows 10 in S mode device to verify expected functioning. - -1. Generate a supplemental policy with WDAC tooling. - - This policy expands the S mode base policy to authorize more applications. Anything authorized by either the S mode base policy or your supplemental policy is allowed to run. Your supplemental policies can specify filepath rules, trusted publishers, and more. - - For more information on creating supplemental policies, see [Deploy multiple WDAC policies](../design/deploy-multiple-wdac-policies.md). For more information on the right type of rules to create for your policy, see [Deploy WDAC policy rules and file rules](../design/select-types-of-rules-to-create.md). - - The following instructions are a basic set for creating an S mode supplemental policy: - - - Create a new base policy using [New-CIPolicy](/powershell/module/configci/new-cipolicy?view=win10-ps&preserve-view=true). - - ```powershell - New-CIPolicy -MultiplePolicyFormat -ScanPath -UserPEs -FilePath "\SupplementalPolicy.xml" -Level FilePublisher -Fallback SignedVersion,Publisher,Hash - ``` - - - Change it to a supplemental policy using [Set-CIPolicyIdInfo](/powershell/module/configci/set-cipolicyidinfo?view=win10-ps&preserve-view=true). - - ```powershell - Set-CIPolicyIdInfo -SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784 -FilePath "\SupplementalPolicy.xml" - ``` - - For policies that supplement the S mode base policy, use `-SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784`. This ID is the S mode policy ID. - - - Put the policy in enforce mode using [Set-RuleOption](/powershell/module/configci/set-ruleoption?view=win10-ps&preserve-view=true). - - ```powershell - Set-RuleOption -FilePath "\SupplementalPolicy.xml>" -Option 3 -Delete - ``` - - This command deletes the 'audit mode' qualifier. - - - Since you're signing your policy, you must authorize the signing certificate you use to sign the policy. Optionally, also authorize one or more extra signers that can be used to sign updates to the policy in the future. The next step in the overall process, **Sign the policy**, describes it in more detail. - - To add the signing certificate to the WDAC policy, use [Add-SignerRule](/powershell/module/configci/add-signerrule?view=win10-ps&preserve-view=true). - - ```powershell - Add-SignerRule -FilePath -CertificatePath -User -Update - ``` - - - Convert to `.bin` using [ConvertFrom-CIPolicy](/powershell/module/configci/convertfrom-cipolicy?view=win10-ps&preserve-view=true). - - ```powershell - ConvertFrom-CIPolicy -XmlFilePath "\SupplementalPolicy.xml" -BinaryFilePath "\SupplementalPolicy.bin> - ``` - -2. Sign the policy. - - Supplemental S mode policies must be digitally signed. To sign your policy, use your organization's custom Public Key Infrastructure (PKI). For more information on signing using an internal CA, see [Create a code signing cert for WDAC](create-code-signing-cert-for-wdac.md). - - > [!TIP] - > For more information, see [Azure Code Signing, democratizing trust for developers and consumers](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/azure-code-signing-democratizing-trust-for-developers-and/ba-p/3604669). - - After you've signed it, rename your policy to `{PolicyID}.p7b`. Get the **PolicyID** from the supplemental policy XML. - -3. Deploy the signed supplemental policy using Microsoft Intune. - - Go to the Microsoft Intune portal, go to the Client apps page, and select **S mode supplemental policies**. Upload the signed policy to Intune and assign it to user or device groups. Intune generates authorization tokens for the tenant and specific devices. Intune then deploys the corresponding authorization token and supplemental policy to each device in the assigned group. Together, these tokens and policies expand the S mode base policy on the device. - -> [!NOTE] -> When you update your supplemental policy, make sure that the new version number is strictly greater than the previous one. Intune doesn't allow using the same version number. For more information on setting the version number, see [Set-CIPolicyVersion](/powershell/module/configci/set-cipolicyversion?view=win10-ps&preserve-view=true). - -## Standard process for deploying apps through Intune - -![Basic diagram for deploying apps through Intune.](../images/wdac-intune-app-deployment.png) - -For more information on the existing procedure of packaging signed catalogs and app deployment, see [Win32 app management in Microsoft Intune](/mem/intune/apps/apps-win32-app-management). - -## Optional: Process for deploying apps using catalogs - -![Basic diagram for deploying Apps using catalogs.](../images/wdac-intune-app-catalogs.png) - -Your supplemental policy can be used to significantly relax the S mode base policy, but there are security trade-offs you must consider in doing so. For example, you can use a signer rule to trust an external signer, but that authorizes all apps signed by that certificate, which may include apps you don't want to allow as well. - -Instead of authorizing signers external to your organization, Intune has functionality to make it easier to authorize existing applications by using signed catalogs. This feature doesn't require repackaging or access to the source code. It works for apps that may be unsigned or even signed apps when you don't want to trust all apps that may share the same signing certificate. - -The basic process is to generate a catalog file for each app using Package Inspector, then sign the catalog files using a custom PKI. To authorize the catalog signing certificate in the supplemental policy, use the **Add-SignerRule** PowerShell cmdlet as shown earlier in step 1 of the [Policy authorization process](#policy-authorization-process). After that, use the [Standard process for deploying apps through Intune](#standard-process-for-deploying-apps-through-intune) outlined earlier. For more information on generating catalogs, see [Deploy catalog files to support WDAC](deploy-catalog-files-to-support-wdac.md). - -> [!NOTE] -> Every time an app updates, you need to deploy an updated catalog. Try to avoid using catalog files for applications that auto-update, and direct users not to update applications on their own. - -## Sample policy - -The following policy is a sample that allows kernel debuggers, PowerShell ISE, and Registry Editor. It also demonstrates how to specify your organization's code signing and policy signing certificates. - -```xml - - - 10.0.0.0 - {2E07F7E4-194C-4D20-B7C9-6F44A6C5A234} - - {5951A96A-E0B5-4D3D-8FB8-3E5B61030784} - - {52671094-ACC6-43CF-AAF1-096DC69C1345} - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 0 - - - - Example Policy Name - - - - - Example-Policy-10.0.0.0 - - - - -``` - -## Policy removal - -In order to revert users to an unmodified S mode policy, remove a user or users from the targeted Intune group that received the policy. This action triggers a removal of both the policy and the authorization token from the device. - -You can also delete a supplemental policy through Intune. - -```xml - - - 10.0.0.1 - {2E07F7E4-194C-4D20-B7C9-6F44A6C5A234} - {5951A96A-E0B5-4D3D-8FB8-3E5B61030784} - {52671094-ACC6-43CF-AAF1-096DC69C1345} - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 0 - - - - Example Policy Name - Empty - - - - - Example-Policy-Empty-10.0.0.1 - - - - -``` - -## Errata - -If a Windows 10 in S mode device with a policy authorization token and supplemental policy is rolled back from the 1909 update to the 1903 build, it will not revert to locked-down S mode until the next policy refresh. To achieve an immediate change to a locked-down S mode state, IT Pros should delete any tokens in %SystemRoot%\System32\CI\Tokens\Active. diff --git a/windows/security/application-security/application-control/windows-defender-application-control/design/applications-that-can-bypass-wdac.md b/windows/security/application-security/application-control/windows-defender-application-control/design/applications-that-can-bypass-wdac.md index 008ae3d8ea..13ff7f41f2 100644 --- a/windows/security/application-security/application-control/windows-defender-application-control/design/applications-that-can-bypass-wdac.md +++ b/windows/security/application-security/application-control/windows-defender-application-control/design/applications-that-can-bypass-wdac.md @@ -169,7 +169,7 @@ The blocklist policy that follows includes "Allow all" rules for both kernel and - + diff --git a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-catalogs.png b/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-catalogs.png deleted file mode 100644 index 754cf041ba..0000000000 Binary files a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-catalogs.png and /dev/null differ diff --git a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-deployment.png b/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-deployment.png deleted file mode 100644 index 91fc4f136b..0000000000 Binary files a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-app-deployment.png and /dev/null differ diff --git a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-policy-authorization.png b/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-policy-authorization.png deleted file mode 100644 index d011fc4408..0000000000 Binary files a/windows/security/application-security/application-control/windows-defender-application-control/images/wdac-intune-policy-authorization.png and /dev/null differ diff --git a/windows/security/application-security/application-control/windows-defender-application-control/index.yml b/windows/security/application-security/application-control/windows-defender-application-control/index.yml index 1b1d46e536..04252abe74 100644 --- a/windows/security/application-security/application-control/windows-defender-application-control/index.yml +++ b/windows/security/application-security/application-control/windows-defender-application-control/index.yml @@ -8,7 +8,7 @@ metadata: author: vinaypamnani-msft ms.author: vinpa manager: aaroncz - ms.date: 04/05/2023 + ms.date: 08/14/2024 # linkListType: overview | how-to-guide | tutorial | video landingContent: # Cards and links should be based on top customer tasks or top subjects @@ -39,8 +39,6 @@ landingContent: url: design/microsoft-recommended-driver-block-rules.md - text: Example WDAC policies url: design/example-wdac-base-policies.md - - text: LOB Win32 apps on S Mode - url: deployment/LOB-win32-apps-on-s.md - text: Managing multiple policies url: design/deploy-multiple-wdac-policies.md - linkListType: how-to-guide @@ -51,7 +49,7 @@ landingContent: url: design/create-wdac-policy-for-fully-managed-devices.md - text: Create a WDAC policy for a fixed-workload url: design/create-wdac-policy-using-reference-computer.md - - text: Create a WDAC deny list policy + - text: Create a WDAC blocklist policy url: design/create-wdac-deny-policy.md - text: Deploying catalog files for WDAC management url: deployment/deploy-catalog-files-to-support-wdac.md @@ -82,7 +80,7 @@ landingContent: url: design/manage-packaged-apps-with-wdac.md - text: Allow com object registration url: design/allow-com-object-registration-in-wdac-policy.md - - text: Manage plug-ins, add-ins and modules + - text: Manage plug-ins, add-ins, and modules url: design/use-wdac-policy-to-control-specific-plug-ins-add-ins-and-modules.md # Card - title: Learn how to deploy WDAC Policies diff --git a/windows/security/docfx.json b/windows/security/docfx.json index d7c7571c0e..1a7808e2b1 100644 --- a/windows/security/docfx.json +++ b/windows/security/docfx.json @@ -54,6 +54,7 @@ } }, "contributors_to_exclude": [ + "aditisrivastava07", "alekyaj", "alexbuckgit", "American-Dipper", @@ -64,17 +65,14 @@ "dstrome2", "garycentric", "jborsecnik", + "padmagit77", "rjagiewich", "rmca14", "shdyas", "Stacyrch140", "tiburd", "traya1", - "v-dihans", - "v-stchambers", - "v-stsavell", - "padmagit77", - "aditisrivastava07" + "v-stsavell" ], "searchScope": [ "Windows 10" diff --git a/windows/security/identity-protection/credential-guard/configure.md b/windows/security/identity-protection/credential-guard/configure.md index fee6dbbc20..b965f14e38 100644 --- a/windows/security/identity-protection/credential-guard/configure.md +++ b/windows/security/identity-protection/credential-guard/configure.md @@ -404,4 +404,4 @@ bcdedit /set vsmlaunchtype off [CSP-1]: /windows/client-management/mdm/policy-csp-deviceguard#enablevirtualizationbasedsecurity -[INT-1]: /mem/intune/configuration/settings-catalog +[INT-1]: /mem/intune/configuration/custom-settings-configure diff --git a/windows/security/identity-protection/credential-guard/considerations-known-issues.md b/windows/security/identity-protection/credential-guard/considerations-known-issues.md index b52bfea7e9..71298d9a5b 100644 --- a/windows/security/identity-protection/credential-guard/considerations-known-issues.md +++ b/windows/security/identity-protection/credential-guard/considerations-known-issues.md @@ -112,7 +112,7 @@ Once the device has connectivity to the domain controllers, DPAPI recovers the u When data protected with user DPAPI is unusable, then the user loses access to all work data protected by Windows Information Protection. The impact includes: Outlook is unable to start and work protected documents can't be opened. If DPAPI is working, then newly created work data is protected and can be accessed. -**Workaround:** Users can resolve the problem by connecting their device to the domain and rebooting or using their Encrypting File System Data Recovery Agent certificate. For more information about Encrypting File System Data Recovery Agent certificate, see [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](/windows/threat-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate). +**Workaround:** Users can resolve the problem by connecting their device to the domain and rebooting or using their Encrypting File System Data Recovery Agent certificate. For more information about Encrypting File System Data Recovery Agent certificate, see [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate). ## Known issues diff --git a/windows/security/identity-protection/hello-for-business/faq.yml b/windows/security/identity-protection/hello-for-business/faq.yml index fb596103e4..c17a99f819 100644 --- a/windows/security/identity-protection/hello-for-business/faq.yml +++ b/windows/security/identity-protection/hello-for-business/faq.yml @@ -16,7 +16,10 @@ sections: questions: - question: What's the difference between Windows Hello and Windows Hello for Business? answer: | - Windows Hello represents the biometric framework provided in Windows. Windows Hello lets users use biometrics to sign in to their devices by securely storing their user name and password and releasing it for authentication when the user successfully identifies themselves using biometrics. Windows Hello for Business uses asymmetric keys protected by the device's security module that requires a user gesture (PIN or biometrics) to authenticate. + *Windows Hello* is an authentication technology that allows users to sign in to their Windows devices using biometric data, or a PIN, instead of a traditional password. + + *Windows Hello for Business* is an extension of Windows Hello that provides enterprise-grade security and management capabilities, including device attestation, certificate-based authentication, and conditional access policies. Policy settings can be deployed to devices to ensure they're secure and compliant with organizational requirements. + - question: Why a PIN is better than an online password answer: | Three main reasons: diff --git a/windows/security/identity-protection/hello-for-business/index.md b/windows/security/identity-protection/hello-for-business/index.md index c9827058be..e838ad5167 100644 --- a/windows/security/identity-protection/hello-for-business/index.md +++ b/windows/security/identity-protection/hello-for-business/index.md @@ -18,7 +18,7 @@ The following table lists the main authentication and security differences betwe ||Windows Hello for Business|Windows Hello| |-|-|-| |**Authentication**|Users can authenticate to:
- A Microsoft Entra ID account
- An Active Directory account
- Identity provider (IdP) or relying party (RP) services that support [Fast ID Online (FIDO) v2.0](https://fidoalliance.org/) authentication.|Users can authenticate to:
- A Microsoft account
- Identity provider (IdP) or relying party (RP) services that support [Fast ID Online (FIDO) v2.0](https://fidoalliance.org/) authentication.| -|**Security**|It uses **key-based** or **certificate-based** authentication. There's no symmetric secret (password) which can be stolen from a server or phished from a user and used remotely.
Enhanced security is available on devices with a Trusted Platform Module (TPM).|Users can create a PIN or biometric gesture on their personal devices for convenient sign-in. This use of Windows Hello is unique to the device on which it's set up, but can use a password hash depending on the account type. This configuration is referred to as *Windows Hello convenience PIN*, and it's not backed by asymmetric (public/private key) or certificate-based authentication.| +|**Security**|It uses **key-based** or **certificate-based** authentication. There's no symmetric secret (password) which can be stolen from a server or phished from a user and used remotely.
Enhanced security is available on devices with a Trusted Platform Module (TPM).|Users can create a PIN or biometric gesture on their personal devices for convenient sign-in. This use of Windows Hello is unique to the device on which it's set up, but can use a password hash depending on the account type. This configuration isn't backed by asymmetric (public/private key) or certificate-based authentication.| > [!NOTE] > FIDO2 (Fast Identity Online) authentication is an open standard for passwordless authentication. It allows users to sign in to their devices and apps using biometric authentication or a physical security key, without the need for a traditional password. FIDO2 support in Windows Hello for Business provides an additional layer of security and convenience for users, while also reducing the risk of password-related attacks. diff --git a/windows/security/identity-protection/passkeys/images/hello-use-confirm.png b/windows/security/identity-protection/passkeys/images/hello-use-confirm.png deleted file mode 100644 index 4139c708c3..0000000000 Binary files a/windows/security/identity-protection/passkeys/images/hello-use-confirm.png and /dev/null differ diff --git a/windows/security/identity-protection/passkeys/index.md b/windows/security/identity-protection/passkeys/index.md index 44f695a852..be6abe05f7 100644 --- a/windows/security/identity-protection/passkeys/index.md +++ b/windows/security/identity-protection/passkeys/index.md @@ -1,11 +1,11 @@ --- title: Support for passkeys in Windows description: Learn about passkeys and how to use them on Windows devices. -ms.collection: +ms.collection: - tier1 ms.topic: overview ms.date: 11/07/2023 -appliesto: +appliesto: - ✅ Windows 11 - ✅ Windows 10 --- @@ -31,7 +31,7 @@ FIDO protocols prioritize user privacy, as they're designed to prevent online se ### Passkeys compared to passwords -Passkeys have several advantages over passwords, including their ease of use and intuitive nature. Unlike passwords, passkeys are easy to create, don't need to be remembered, and don't need to be safeguarded. Additionally, passkeys are unique to each website or application, preventing their reuse. They're highly secure because they're only stored on the user's devices, with the service only storing public keys. Passkeys are designed to prevent attackers to guess or obtain them, which helps to make them resistant to phishing attempts where the attacker may try to trick the user into revealing the private key. Passkeys are enforced by the browsers or operating systems to only be used for the appropriate service, rather than relying on human verification. Finally, passkeys provide cross-device and cross-platform authentication, meaning that a passkey from one device can be used to sign in on another device. +Passkeys have several advantages over passwords, including their ease of use and intuitive nature. Unlike passwords, passkeys are easy to create, don't need to be remembered, and don't need to be safeguarded. Additionally, passkeys are unique to each website or application, preventing their reuse. They're highly secure because they're only stored on the user's devices, with the service only storing public keys. Passkeys are designed to prevent attackers to guess or obtain them, which helps to make them resistant to phishing attempts where the attacker might try to trick the user into revealing the private key. Passkeys are enforced by the browsers or operating systems to only be used for the appropriate service, rather than relying on human verification. Finally, passkeys provide cross-device and cross-platform authentication, meaning that a passkey from one device can be used to sign in on another device. [!INCLUDE [passkey](../../../../includes/licensing/passkeys.md)] @@ -113,7 +113,7 @@ Pick one of the following options to learn how to save a passkey, based on where :::row::: :::column span="4"::: - 4. Select your linked device name (e.g. **Pixel**) > **Next** + 4. Select your linked device name (for example, **Pixel**) > **Next** :::column-end::: :::row-end::: :::row::: @@ -241,7 +241,7 @@ Pick one of the following options to learn how to use a passkey, based on where :::row::: :::column span="4"::: - 4. Select your linked device name (e.g. **Pixel**) > **Next** + 4. Select your linked device name (for example, **Pixel**) > **Next** :::column-end::: :::row-end::: :::row::: @@ -311,12 +311,86 @@ Starting in Windows 11, version 22H2 with [KB5030310][KB-1], you can use the Set > [!NOTE] > Some passkeys for *login.microsoft.com* can't be deleted, as they're used with Microsoft Entra ID and/or Microsoft Account for signing in to the device and Microsoft services. +## Passkeys in Bluetooth-restricted environments + +For passkey cross-device authentication scenarios, both the Windows device and the mobile device must have Bluetooth enabled and connected to the Internet. This allows the user to authorize another device securely over Bluetooth without transferring or copying the passkey itself. + +Some organizations restrict Bluetooth usage, which includes the use of passkeys. In such cases, organizations can allow passkeys by permitting Bluetooth pairing exclusively with passkey-enabled FIDO2 authenticators. + +To limit the use of Bluetooth to only passkey use cases, use the [Bluetooth Policy CSP][CSP-8] and the [DeviceInstallation Policy CSP][CSP-7]. + +### Device configuration + +[!INCLUDE [tab-intro](../../../../includes/configure/tab-intro.md)] + +#### [:::image type="icon" source="../../images/icons/intune.svg" border="false"::: **Intune/CSP**](#tab/intune) + +To configure devices with Microsoft Intune, [you can use a custom policy][INT-2] with these settings: + +| Setting | +|--| +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/Bluetooth/`[AllowAdvertising][CSP-1]
  • Data type: **Integer**
  • Value: `0`

  • When set to `0`, the device doesn't send out advertisements. | +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/Bluetooth/`[AllowDiscoverableMode][CSP-2]
  • Data type: **Integer**
  • Value: `0`

  • When set to `0`, other devices can't detect the device. | +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/Bluetooth/`[AllowPrepairing][CSP-3]
  • Data type: **Integer**
  • Value: `0`

  • Prevents specific bundled Bluetooth peripherals from automatically pairing with the host device. | +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/Bluetooth/`[AllowPromptedProximalConnections][CSP-4]
  • Data type: **Integer**
  • Value: `0`

  • Prevents users from using Swift Pair and other proximity-based scenarios. | +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/Bluetooth/`[ServicesAllowedList][CSP-5]
  • Data type: **String**
  • Value: `{0000FFFD-0000-1000-8000-00805F9B34FB};{0000FFF9-0000-1000-8000-00805F9B34FB}`

    Set a list of allowable Bluetooth services and profiles:
    - FIDO Alliance Universal Second Factor Authenticator service (`0000fffd-0000-1000-8000-00805f9b34fb`)
    - FIDO2 secure client-to-authenticator transport service (`0000FFF9-0000-1000-8000-00805F9B34FB`)

    For more information, see [FIDO CTAP 2.1 standard specification][BT-1] and [Bluetooth Assigned Numbers document][BT-2]. | +|
  • OMA-URI: `./Device/Vendor/MSFT/Policy/Config/DeviceInstallation/`[PreventInstallationOfMatchingDeviceIDs][CSP-6]
  • Data type: **String**
  • Value: ``

  • Disables the existing Bluetooth Personal Area Network (PAN) network adapter, preventing the installation of the Bluetooth Network Adapter that can be used for network connectivity or tethering. | + +#### [:::image type="icon" source="../../images/icons/powershell.svg" border="false"::: **PowerShell**](#tab/powershell) + +[!INCLUDE [powershell-wmi-bridge-1](../../../../includes/configure/powershell-wmi-bridge-1.md)] + +```powershell +# Bluetooth configuration +$namespaceName = "root\cimv2\mdm\dmmap" +$className = "MDM_Policy_Config01_Bluetooth02" +New-CimInstance -Namespace $namespaceName -ClassName $className -Property @{ + ParentID="./Vendor/MSFT/Policy/Config"; + InstanceID="Bluetooth"; + AllowDiscoverableMode=0; + AllowAdvertising=0; + AllowPrepairing=0; + AllowPromptedProximalConnections=0; + ServicesAllowedList="{0000FFF9-0000-1000-8000-00805F9B34FB};{0000FFFD-0000-1000-8000-00805F9B34FB}" +} + + +# Device installation configuration +$namespaceName = "root\cimv2\mdm\dmmap" +$className = "MDM_Policy_Config01_DeviceInstallation02" +New-CimInstance -Namespace $namespaceName -ClassName $className -Property @{ + ParentID="./Vendor/MSFT/Policy/Config"; + InstanceID="DeviceInstallation"; + PreventInstallationOfMatchingDeviceIDs=']]>' +} +``` + +[!INCLUDE [powershell-wmi-bridge-2](../../../../includes/configure/powershell-wmi-bridge-2.md)] + +--- + +>[!NOTE] +>Once the settings are applied, if you try to pair a device via Bluetooth, it will initially pair and immediately disconnect. The Bluetooth device is blocked from loading and not available from Settings nor Device Manager. + ## :::image type="icon" source="../../images/icons/feedback.svg" border="false"::: Provide feedback To provide feedback for passkeys, open [**Feedback Hub**][FHUB] and use the category **Security and Privacy > Passkey**. +[BT-1]: https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-20210615.html#ble-fido-service +[BT-2]: https://www.bluetooth.com/wp-content/uploads/Files/Specification/HTML/Assigned_Numbers/out/en/Assigned_Numbers.pdf?v=1713387868258 [FHUB]: feedback-hub:?tabid=2&newFeedback=true [KB-1]: https://support.microsoft.com/kb/5030310 [MSS-1]: ms-settings:savedpasskeys + +[INT-2]: /mem/intune/configuration/custom-settings-configure + +[CSP-1]: /windows/client-management/mdm/policy-csp-bluetooth#allowadvertising +[CSP-2]: /windows/client-management/mdm/policy-csp-bluetooth#allowdiscoverablemode +[CSP-3]: /windows/client-management/mdm/policy-csp-bluetooth#allowprepairing +[CSP-4]: /windows/client-management/mdm/policy-csp-bluetooth#allowpromptedproximalconnections +[CSP-5]: /windows/client-management/mdm/policy-csp-bluetooth#servicesallowedlist +[CSP-6]: /windows/client-management/mdm/policy-csp-deviceinstallation#preventinstallationofmatchingdeviceids +[CSP-7]: /windows/client-management/mdm/policy-csp-deviceinstallation +[CSP-8]: /windows/client-management/mdm/policy-csp-bluetooth \ No newline at end of file diff --git a/windows/security/identity-protection/passwordless-experience/images/edge-on.png b/windows/security/identity-protection/passwordless-experience/images/edge-on.png deleted file mode 100644 index 06a13b6f1a..0000000000 Binary files a/windows/security/identity-protection/passwordless-experience/images/edge-on.png and /dev/null differ diff --git a/windows/security/images/icons/control-panel.svg b/windows/security/images/icons/control-panel.svg deleted file mode 100644 index 6eebbe9be8..0000000000 --- a/windows/security/images/icons/control-panel.svg +++ /dev/null @@ -1,9 +0,0 @@ - - - - - - - - - diff --git a/windows/security/images/icons/drive.svg b/windows/security/images/icons/drive.svg deleted file mode 100644 index 0293932c8e..0000000000 --- a/windows/security/images/icons/drive.svg +++ /dev/null @@ -1,75 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/windows/security/images/icons/face.svg b/windows/security/images/icons/face.svg deleted file mode 100644 index a4fa1ca0df..0000000000 --- a/windows/security/images/icons/face.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/insider.svg b/windows/security/images/icons/insider.svg deleted file mode 100644 index fa002fa2a1..0000000000 --- a/windows/security/images/icons/insider.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/iris.svg b/windows/security/images/icons/iris.svg deleted file mode 100644 index 465902e0b3..0000000000 --- a/windows/security/images/icons/iris.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/key.svg b/windows/security/images/icons/key.svg deleted file mode 100644 index 62e4755d33..0000000000 --- a/windows/security/images/icons/key.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/kiosk.svg b/windows/security/images/icons/kiosk.svg deleted file mode 100644 index f975677d19..0000000000 --- a/windows/security/images/icons/kiosk.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/lock.svg b/windows/security/images/icons/lock.svg deleted file mode 100644 index ccd1850fbb..0000000000 --- a/windows/security/images/icons/lock.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/pin-code.svg b/windows/security/images/icons/pin-code.svg deleted file mode 100644 index a5bfdc4148..0000000000 --- a/windows/security/images/icons/pin-code.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/sc.svg b/windows/security/images/icons/sc.svg deleted file mode 100644 index d1924ffebb..0000000000 --- a/windows/security/images/icons/sc.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/subscription.svg b/windows/security/images/icons/subscription.svg deleted file mode 100644 index ce4771b082..0000000000 --- a/windows/security/images/icons/subscription.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/images/icons/vsc.svg b/windows/security/images/icons/vsc.svg deleted file mode 100644 index cbf23de89e..0000000000 --- a/windows/security/images/icons/vsc.svg +++ /dev/null @@ -1,3 +0,0 @@ - - - diff --git a/windows/security/information-protection/windows-information-protection/app-behavior-with-wip.md b/windows/security/information-protection/windows-information-protection/app-behavior-with-wip.md deleted file mode 100644 index 3db313bdd3..0000000000 --- a/windows/security/information-protection/windows-information-protection/app-behavior-with-wip.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: Unenlightened and enlightened app behavior while using Windows Information Protection (WIP) -description: Learn how unenlightened and enlightened apps might behave, based on Windows Information Protection (WIP) network policies, app configuration, and other criteria -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 -ms.reviewer: ---- - -# Unenlightened and enlightened app behavior while using Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - -Windows Information Protection (WIP) classifies apps into two categories: enlightened and unenlightened. Enlighted apps can differentiate between corporate and personal data, correctly determining which to protect based on internal policies. Corporate data is encrypted on the managed device and attempts to copy/paste or share this information with non-corporate apps or people will fail. Unenlightened apps, when marked as corporate-managed, consider all data corporate and encrypt everything by default. - -To avoid the automatic encryption of data, developers can enlighten apps by adding and compiling code using the Windows Information Protection application programming interfaces. The most likely candidates for enlightenment are apps that: - -- Don't use common controls for saving files. -- Don't use common controls for text boxes. -- Simultaneously work on personal and corporate data (for example, contact apps that display personal and corporate data in a single view or a browser that displays personal and corporate web pages on tabs within a single instance). - -We strongly suggest that the only unenlightened apps you add to your allowed apps list are Line-of-Business (LOB) apps. - -> [!IMPORTANT] -> After revoking WIP, unenlightened apps will have to be uninstalled and re-installed since their settings files will remain encrypted. For more info about creating enlightened apps, see the [Windows Information Protection (WIP)](/windows/uwp/enterprise/wip-hub) topic in the Windows Dev Center. - -## Unenlightened app behavior -This table includes info about how unenlightened apps might behave, based on your Windows Information Protection (WIP) networking policies, your app configuration, and potentially whether the app connects to network resources directly by using IP addresses or by using hostnames. - -|App rule setting|Networking policy configuration| -|--- |--- | -|**Not required.** App connects to enterprise cloud resources directly, using an IP address.| **Name-based policies, without the `/*AppCompat*/` string:**
  • App is entirely blocked from both personal and enterprise cloud resources.
  • No encryption is applied.
  • App can't access local Work files.

    **Name-based policies, using the `/*AppCompat*/` string or proxy-based policies:**
  • App can access both personal and enterprise cloud resources. However, you might encounter apps using policies that restrict access to enterprise cloud resources.
  • No encryption is applied.
  • App can't access local Work files.| -|**Not required.** App connects to enterprise cloud resources, using a hostname.|
  • App is blocked from accessing enterprise cloud resources, but can access other network resources.
  • No encryption is applied.
  • App can't access local Work files.| -|**Allow.** App connects to enterprise cloud resources, using an IP address or a hostname.|
  • App can access both personal and enterprise cloud resources.
  • Auto-encryption is applied.
  • App can access local Work files.| -|**Exempt.** App connects to enterprise cloud resources, using an IP address or a hostname.|
  • App can access both personal and enterprise cloud resources.
  • No encryption is applied.
  • App can access local Work files.| - -## Enlightened app behavior -This table includes info about how enlightened apps might behave, based on your Windows Information Protection (WIP) networking policies, your app configuration, and potentially whether the app connects to network resources directly by using IP addresses or by using hostnames. - -|App rule setting|Networking policy configuration for name-based policies, possibly using the /*AppCompat*/ string, or proxy-based policies| -|--- |--- | -|**Not required.** App connects to enterprise cloud resources, using an IP address or a hostname.|
  • App is blocked from accessing enterprise cloud resources, but can access other network resources.
  • No encryption is applied.
  • App can't access local Work files.| -|**Allow.** App connects to enterprise cloud resources, using an IP address or a hostname.|
  • App can access both personal and enterprise cloud resources.
  • App protects work data and leaves personal data unprotected.
  • App can access local Work files.| -|**Exempt.** App connects to enterprise cloud resources, using an IP address or a hostname.|
  • App can access both personal and enterprise cloud resources.
  • App protects work data and leaves personal data unprotected.
  • App can access local Work files.| - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md b/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md deleted file mode 100644 index 3d7152aa4c..0000000000 --- a/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md +++ /dev/null @@ -1,205 +0,0 @@ ---- -title: How to collect Windows Information Protection (WIP) audit event logs -description: How to collect & understand Windows Information Protection audit event logs via the Reporting configuration service provider (CSP) or Windows Event Forwarding. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 -ms.reviewer: ---- - -# How to collect Windows Information Protection (WIP) audit event logs - -**Applies to:** - -- Windows 10, version 1607 and later - -Windows Information Protection (WIP) creates audit events in the following situations: - -- If an employee changes the File ownership for a file from **Work** to **Personal**. - -- If data is marked as **Work**, but shared to a personal app or webpage. For example, through copying and pasting, dragging and dropping, sharing a contact, uploading to a personal webpage, or if the user grants a personal app provides temporary access to a work file. - -- If an app has custom audit events. - -## Collect WIP audit logs by using the Reporting configuration service provider (CSP) -Collect the WIP audit logs from your employee's devices by following the guidance provided by the [Reporting configuration service provider (CSP)](/windows/client-management/mdm/reporting-csp) documentation. This topic provides info about the actual audit events. - ->[!Note] ->The **Data** element in the response includes the requested audit logs in an XML-encoded format. - -### User element and attributes -This table includes all available attributes for the **User** element. - -|Attribute |Value type |Description | -|----------|-----------|------------| -|UserID |String |The security identifier (SID) of the user corresponding to this audit report. | -|EnterpriseID |String |The enterprise ID corresponding to this audit report. | - -### Log element and attributes -This table includes all available attributes/elements for the **Log** element. The response can contain zero (0) or more **Log** elements. - -|Attribute/Element |Value type |Description | -|----------|-----------|------------| -|ProviderType |String |This is always **EDPAudit**. | -|LogType |String |Includes:
    • **DataCopied.** Work data is copied or shared to a personal location.
    • **ProtectionRemoved.** Windows Information Protection is removed from a Work-defined file.
    • **ApplicationGenerated.** A custom audit log provided by an app.
    | -|TimeStamp |Int |Uses the [FILETIME structure](/windows/win32/api/minwinbase/ns-minwinbase-filetime) to represent the time that the event happened. | -|Policy |String |How the work data was shared to the personal location:
    • **CopyPaste.** Work data was pasted into a personal location or app.
    • **ProtectionRemoved.** Work data was changed to be unprotected.
    • **DragDrop.** Work data was dropped into a personal location or app.
    • **Share.** Work data was shared with a personal location or app.
    • **NULL.** Any other way work data could be made personal beyond the options above. For example, when a work file is opened using a personal application (also known as, temporary access).
    | -|Justification |String |Not implemented. This will always be either blank or NULL.

    **Note**
    Reserved for future use to collect the user justification for changing from **Work** to **Personal**. | -|Object |String |A description of the shared work data. For example, if an employee opens a work file by using a personal app, this would be the file path. | -|DataInfo |String |Any additional info about how the work file changed:
    • **A file path.** If an employee uploads a work file to a personal website by using Microsoft Edge or Internet Explorer, the file path is included here.
    • **Clipboard data types.** If an employee pastes work data into a personal app, the list of clipboard data types provided by the work app are included here. For more info, see the [Examples](#examples) section of this topic.
    | -|Action |Int |Provides info about what happened when the work data was shared to personal, including:
    • **1.** File decrypt.
    • **2.** Copy to location.
    • **3.** Send to recipient.
    • **4.** Other.
    | -|FilePath |String |The file path to the file specified in the audit event. For example, the location of a file that's been decrypted by an employee or uploaded to a personal website. | -|SourceApplicationName |String |The source app or website. For the source app, this is the AppLocker identity. For the source website, this is the hostname. | -|SourceName |String |A string provided by the app that's logging the event. It's intended to describe the source of the work data. | -|DestinationEnterpriseID |String |The enterprise ID value for the app or website where the employee is sharing the data.

    **NULL**, **Personal**, or **blank** means there's no enterprise ID because the work data was shared to a personal location. Because we don't currently support multiple enrollments, you'll always see one of these values. | -|DestinationApplicationName |String |The destination app or website. For the destination app, this is the AppLocker identity. For the destination website, this is the hostname. | -|DestinationName |String |A string provided by the app that's logging the event. It's intended to describe the destination of the work data. | -|Application |String |The AppLocker identity for the app where the audit event happened. | - -### Examples - -Here are a few examples of responses from the Reporting CSP. - -#### File ownership on a file is changed from work to personal - -```xml -110SyncHdr200212Replace200314Get200414./Vendor/MSFT/Reporting/EnterpriseDataProtection/RetrieveByTimeRange/Logsxml - - - - Protection removed - NULL - C:\Users\TestUser\Desktop\tmp\demo\Work document.docx - - - -``` - -#### A work file is uploaded to a personal webpage in Edge - -```xml -110SyncHdr200212Replace200314Get200414./Vendor/MSFT/Reporting/EnterpriseDataProtection/RetrieveByTimeRange/Logsxml - - - - CopyPaste - NULL - NULL - NULL - mail.contoso.com - C:\Users\TestUser\Desktop\tmp\demo\Work document.docx - - - -``` - -#### Work data is pasted into a personal webpage - -```xml -110SyncHdr200212Replace200314Get200414./Vendor/MSFT/Reporting/EnterpriseDataProtection/RetrieveByTimeRange/Logsxml - - - - CopyPaste - NULL - O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFT OFFICE 2016\WINWORD.EXE\16.0.8027.1000 - NULL - mail.contoso.com - EnterpriseDataProtectionId|Object Descriptor|Rich Text Format|HTML Format|AnsiText|Text|EnhancedMetafile|Embed Source|Link Source|Link Source Descriptor|ObjectLink|Hyperlink - - - -``` - -#### A work file is opened with a personal application - -```xml -110SyncHdr200212Replace200314Get200414./Vendor/MSFT/Reporting/EnterpriseDataProtection/RetrieveByTimeRange/Logsxml - - - - NULL - - C:\Users\TestUser\Desktop\tmp\demo\Work document.docx - 1 - O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFT® WINDOWS® OPERATING SYSTEM\WORDPAD.EXE\10.0.15063.2 - Personal - O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFT® WINDOWS® OPERATING SYSTEM\WORDPAD.EXE\10.0.15063.2 - O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFT® WINDOWS® OPERATING SYSTEM\WORDPAD.EXE\10.0.15063.2 - - - -``` - -#### Work data is pasted into a personal application - -```xml -110SyncHdr200212Replace200314Get200414./Vendor/MSFT/Reporting/EnterpriseDataProtection/RetrieveByTimeRange/Logsxml - - - - CopyPaste - NULL - O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFT OFFICE 2016\WINWORD.EXE\16.0.8027.1000 - NULL - - EnterpriseDataProtectionId|Object Descriptor|Rich Text Format|HTML Format|AnsiText|Text|EnhancedMetafile|Embed Source|Link Source|Link Source Descriptor|ObjectLink|Hyperlink - - - -``` - -## Collect WIP audit logs by using Windows Event Forwarding (for Windows desktop domain-joined devices only) - -Use Windows Event Forwarding to collect and aggregate your Windows Information Protection audit events. You can view your audit events in the Event Viewer. - -**To view the WIP events in the Event Viewer** - -1. Open Event Viewer. - -2. In the console tree under **Application and Services Logs\Microsoft\Windows**, click **EDP-Audit-Regular** and **EDP-Audit-TCB**. - -## Collect WIP audit logs using Azure Monitor - -You can collect audit logs using Azure Monitor. See [Windows event log data sources in Azure Monitor.]() - -**To view the WIP events in Azure Monitor** - -1. Use an existing or create a new Log Analytics workspace. - -2. In **Log Analytics** > **Advanced Settings**, select **Data**. In Windows Event Logs, add logs to receive: - - ```console - Microsoft-Windows-EDP-Application-Learning/Admin - Microsoft-Windows-EDP-Audit-TCB/Admin - ``` - >[!NOTE] - >If using Windows Events Logs, the event log names can be found under Properties of the event in the Events folder (Application and Services Logs\Microsoft\Windows, click EDP-Audit-Regular and EDP-Audit-TCB). - -3. Download Microsoft [Monitoring Agent](/azure/azure-monitor/platform/agent-windows#install-the-agent-using-dsc-in-azure-automation). - -4. To get MSI for Intune installation as stated in the Azure Monitor article, extract: `MMASetup-.exe /c /t:` - - Install Microsoft Monitoring Agent to WIP devices using Workspace ID and Primary key. More information on Workspace ID and Primary key can be found in **Log Analytics** > **Advanced Settings**. - -5. To deploy MSI via Intune, in installation parameters add: `/q /norestart NOAPM=1 ADD_OPINSIGHTS_WORKSPACE=1 OPINSIGHTS_WORKSPACE_AZURE_CLOUD_TYPE=0 OPINSIGHTS_WORKSPACE_ID= OPINSIGHTS_WORKSPACE_KEY= AcceptEndUserLicenseAgreement=1` - - >[!NOTE] - >Replace & received from step 5. In installation parameters, don't place & in quotes ("" or ''). - -6. After the agent is deployed, data will be received within approximately 10 minutes. - -7. To search for logs, go to **Log Analytics workspace** > **Logs**, and type **Event** in search. - - ***Example*** - - ```console - Event | where EventLog == "Microsoft-Windows-EDP-Audit-TCB/Admin" - ``` - -## Additional resources -- [How to deploy app via Intune](/intune/apps-add) -- [How to create Log workspace](/azure/azure-monitor/learn/quick-create-workspace) -- [How to use Microsoft Monitoring Agents for Windows](/azure/azure-monitor/platform/agents-overview) diff --git a/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md b/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md deleted file mode 100644 index d730747292..0000000000 --- a/windows/security/information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md +++ /dev/null @@ -1,162 +0,0 @@ ---- -title: Create an EFS Data Recovery Agent certificate -description: Follow these steps to create, verify, and perform a quick recovery by using an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.reviewer: rafals -ms.topic: how-to -ms.date: 07/15/2022 ---- - -# Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate - -[!INCLUDE [Deprecate Windows Information Protection](includes/wip-deprecation.md)] - - -_Applies to:_ - -- Windows 10 -- Windows 11 - -If you don't already have an EFS DRA certificate, you'll need to create and extract one from your system before you can use Windows Information Protection (WIP), formerly known as enterprise data protection (EDP), in your organization. For the purposes of this section, we'll use the file name EFSDRA; however, this name can be replaced with anything that makes sense to you. - ->[!IMPORTANT] ->If you already have an EFS DRA certificate for your organization, you can skip creating a new one. Just use your current EFS DRA certificate in your policy. For more info about when to use a PKI and the general strategy you should use to deploy DRA certificates, see the [Security Watch Deploying EFS: Part 1](/previous-versions/technet-magazine/cc162507(v=msdn.10)) article on TechNet. For more general info about EFS protection, see [Protecting Data by Using EFS to Encrypt Hard Drives](/previous-versions/tn-archive/cc875821(v=technet.10)).

    If your DRA certificate has expired, you won't be able to encrypt your files with it. To fix this, you'll need to create a new certificate, using the steps in this topic, and then deploy it through policy. - -## Manually create an EFS DRA certificate - -1. On a computer without an EFS DRA certificate installed, open a command prompt with elevated rights, and then navigate to where you want to store the certificate. - -2. Run this command: - - ```cmd - cipher /r:EFSRA - ``` - - Where *EFSRA* is the name of the `.cer` and `.pfx` files that you want to create. - -3. When prompted, type and confirm a password to help protect your new Personal Information Exchange (.pfx) file. - - The EFSDRA.cer and EFSDRA.pfx files are created in the location you specified in Step 1. - - >[!Important] - >Because the private keys in your DRA .pfx files can be used to decrypt any WIP file, you must protect them accordingly. We highly recommend storing these files offline, keeping copies on a smart card with strong protection for normal use and master copies in a secured physical location. - -4. Add your EFS DRA certificate to your WIP policy using a deployment tool, such as [Microsoft Intune](create-wip-policy-using-intune-azure.md) or [Microsoft Configuration Manager](create-wip-policy-using-configmgr.md). - - > [!NOTE] - > This certificate can be used in Intune for policies both _with_ device enrollment (MDM) and _without_ device enrollment (MAM). - -## Verify your data recovery certificate is correctly set up on a WIP client computer - -1. Find or create a file that's encrypted using Windows Information Protection. For example, you could open an app on your allowed app list, and then create and save a file so it's encrypted by WIP. - -2. Open an app on your protected app list, and then create and save a file so that it's encrypted by WIP. - -3. Open a command prompt with elevated rights, navigate to where you stored the file you just created, and then run this command: - - ```cmd - cipher /c filename - ``` - - Where *filename* is the name of the file you created in Step 1. - -4. Make sure that your data recovery certificate is listed in the **Recovery Certificates** list. - -## Recover your data using the EFS DRA certificate in a test environment - -1. Copy your WIP-encrypted file to a location where you have admin access. - -2. Install the EFSDRA.pfx file, using its password. - -3. Open a command prompt with elevated rights, navigate to the encrypted file, and then run this command: - - ```cmd - cipher /d encryptedfile.extension - ``` - - Where *encryptedfile.extension* is the name of your encrypted file. For example, `corporatedata.docx`. - -## Recover WIP-protected after unenrollment - -It's possible that you might revoke data from an unenrolled device only to later want to restore it all. This can happen in the case of a missing device being returned or if an unenrolled employee enrolls again. If the employee enrolls again using the original user profile, and the revoked key store is still on the device, all of the revoked data can be restored at once. - ->[!IMPORTANT] ->To maintain control over your enterprise data, and to be able to revoke again in the future, you must only perform this process after the employee has re-enrolled the device. - -1. Have the employee sign in to the unenrolled device, open an elevated command prompt, and type: - - ```cmd - Robocopy "%localappdata%\Microsoft\EDP\Recovery" "new_location" * /EFSRAW - ``` - - Where "*new_location*" is in a different directory. This can be on the employee's device or on a shared folder on a computer that runs Windows 8 or Windows Server 2012 or newer and can be accessed while you're logged in as a data recovery agent. - - To start Robocopy in S mode, open Task Manager. Click **File** > **Run new task**, type the command, and click **Create this task with administrative privileges**. - - ![Robocopy in S mode.](images/robocopy-s-mode.png) - - If the employee performed a clean installation and there is no user profile, you need to recover the keys from the System Volume folder in each drive. Type: - - ```cmd - Robocopy "drive_letter:\System Volume Information\EDP\Recovery\" "new_location" * /EFSRAW - ``` - -2. Sign in to a different device with administrator credentials that have access to your organization's DRA certificate, and perform the file decryption and recovery by typing: - - ```cmd - cipher.exe /D "new_location" - ``` - -3. Have your employee sign in to the unenrolled device, and type: - - ```cmd - Robocopy "new_location" "%localappdata%\Microsoft\EDP\Recovery\Input" - ``` - -4. Ask the employee to lock and unlock the device. - - The Windows Credential service automatically recovers the employee's previously revoked keys from the `Recovery\Input` location. - -## Auto-recovery of encryption keys -Starting with Windows 10, version 1709, WIP includes a data recovery feature that lets your employees auto-recover access to work files if the encryption key is lost and the files are no longer accessible. This typically happens if an employee reimages the operating system partition, removing the WIP key info, or if a device is reported as lost and you mistakenly target the wrong device for unenrollment. - -To help make sure employees can always access files, WIP creates an auto-recovery key that's backed up to their Microsoft Entra identity. - -The employee experience is based on signing in with a Microsoft Entra ID work account. The employee can either: - -- Add a work account through the **Windows Settings > Accounts > Access work or school > Connect** menu. - - -OR- - -- Open **Windows Settings > Accounts > Access work or school > Connect** and choose the **Join this device to Microsoft Entra ID** link, under **Alternate actions**. - - >[!Note] - >To perform a Microsoft Entra Domain Join from the Settings page, the employee must have administrator privileges to the device. - -After signing in, the necessary WIP key info is automatically downloaded and employees are able to access the files again. - -### To test what the employee sees during the WIP key recovery process - -1. Attempt to open a work file on an unenrolled device. - - The **Connect to Work to access work files** box appears. - -2. Click **Connect**. - - The **Access work or school settings** page appears. - -3. Sign-in to Microsoft Entra ID as the employee and verify that the files now open - -## Related topics - -- [Security Watch Deploying EFS: Part 1](/previous-versions/technet-magazine/cc162507(v=msdn.10)) - -- [Protecting Data by Using EFS to Encrypt Hard Drives](/previous-versions/tn-archive/cc875821(v=technet.10)) - -- [Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune-azure.md) - -- [Create a Windows Information Protection (WIP) policy using Microsoft Configuration Manager](create-wip-policy-using-configmgr.md) - -- [Creating a Domain-Based Recovery Agent](/previous-versions/tn-archive/cc875821(v=technet.10)#EJAA) diff --git a/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md b/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md deleted file mode 100644 index c3badb03b9..0000000000 --- a/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: Associate and deploy a VPN policy for Windows Information Protection (WIP) using the Azure portal for Microsoft Intune -description: After you've created and deployed your Windows Information Protection (WIP) policy, use Microsoft Intune to link it to your Virtual Private Network (VPN) policy -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 -ms.reviewer: ---- - -# Associate and deploy a VPN policy for Windows Information Protection (WIP) using Microsoft Intune - -**Applies to:** - -- Windows 10, version 1607 and later - -After you've created and deployed your Windows Information Protection (WIP) policy, you can use Microsoft Intune to associate and deploy your Virtual Private Network (VPN) policy, linking it to your WIP policy. - -## Associate your WIP policy to your VPN policy using Intune - -To associate your WIP policy with your organization's existing VPN policy, use the following steps: - -1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). -2. Select **Devices** > **Configuration profiles** > **Create profile**. -3. Enter the following properties: - - - **Platform**: Select **Windows 10 and later** - - **Profile**: Select **Templates** > **Custom**. - -4. Select **Create**. -5. In **Basics**, enter the following properties: - - - **Name**: Enter a descriptive name for the profile. Name your profiles so you can easily identify them later. - - **Description**: Enter a description for the profile. This setting is optional, but recommended. - -6. Select **Next**. -7. In **Configuration settings**, enter the following properties: - - - **Name**: Enter a name for your setting. For example, enter `EDPModeID`. - - **OMA-URI**: Enter `./Vendor/MSFT/VPNv2/YourVPNProfileName/EDPModeId`. - - **Data type**: Select `String`. - - **Value**: Type your fully qualified domain that should be used by the OMA-URI setting. For example, enter `corp.contoso.com`. - - For more information on these settings, see [Use custom settings for Windows devices in Intune](/mem/intune/configuration/custom-settings-windows-10). - -8. Select **Next**, and continue configuring the policy. For the specific steps and recommendations, see [Create a profile with custom settings in Intune](/mem/intune/configuration/custom-settings-configure). - -## Deploy your VPN policy using Microsoft Intune - -After you've created your VPN policy, you'll need to deploy it to the same group you deployed your Windows Information Protection (WIP) policy. - -1. On the **App policy** blade, select your newly created policy, select **User groups** from the menu that appears, and then select **Add user group**. - - A list of user groups, made up of all of the security groups in your Microsoft Entra ID, appear in the **Add user group** blade. - -2. Choose the group you want your policy to apply to, and then select **Select** to deploy the policy. - - The policy is deployed to the selected users' devices. - - ![Microsoft Intune: Pick your user groups that should get the policy when it's deployed.](images/wip-azure-add-user-groups.png) - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr.md b/windows/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr.md deleted file mode 100644 index 01f7c3b238..0000000000 --- a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr.md +++ /dev/null @@ -1,480 +0,0 @@ ---- -title: Create and deploy a WIP policy in Configuration Manager -description: Use Microsoft Configuration Manager to create and deploy a Windows Information Protection (WIP) policy. Choose protected apps, WIP-protection level, and find enterprise data. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.reviewer: rafals -ms.topic: how-to -ms.date: 07/15/2022 ---- - -# Create and deploy a Windows Information Protection policy in Configuration Manager - -[!INCLUDE [Deprecate Windows Information Protection](includes/wip-deprecation.md)] - - -_Applies to:_ - -- Windows 10 -- Windows 11 - -Microsoft Configuration Manager helps you create and deploy your Windows Information Protection (WIP) policy. You can choose your protected apps, your WIP-protection mode, and how to find enterprise data on the network. - -## Add a WIP policy -After you've installed and set up Configuration Manager for your organization, you must create a configuration item for WIP, which in turn becomes your WIP policy. - ->[!TIP] -> Review the [Limitations while using Windows Information Protection (WIP)](limitations-with-wip.md) article before creating a new configuration item to avoid common issues. - -**To create a configuration item for WIP** - -1. Open the Configuration Manager console, select the **Assets and Compliance** node, expand the **Overview** node, expand the **Compliance Settings** node, and then expand the **Configuration Items** node. - - ![Configuration Manager, Configuration Items screen.](images/wip-configmgr-addpolicy.png) - -2. Select the **Create Configuration Item** button.

    -The **Create Configuration Item Wizard** starts. - - ![Create Configuration Item wizard, define the configuration item and choose the configuration type.](images/wip-configmgr-generalscreen.png) - -3. On the **General Information screen**, type a name (required) and an optional description for your policy into the **Name** and **Description** boxes. - -4. In the **Specify the type of configuration item you want to create** area, pick the option that represents whether you use Configuration Manager for device management, and then select **Next**. - - - **Settings for devices managed with the Configuration Manager client:** Windows 10 - - -OR- - - - **Settings for devices managed without the Configuration Manager client:** Windows 8.1 and Windows 10 - -5. On the **Supported Platforms** screen, select the **Windows 10** box, and then select **Next**. - - ![Create Configuration Item wizard, choose the supported platforms for the policy.](images/wip-configmgr-supportedplat.png) - -6. On the **Device Settings** screen, select **Windows Information Protection**, and then select **Next**. - - ![Create Configuration Item wizard, choose the Windows Information Protection settings.](images/wip-configmgr-devicesettings.png) - -The **Configure Windows Information Protection settings** page appears, where you'll configure your policy for your organization. - -## Add app rules to your policy - -During the policy-creation process in Configuration Manager, you can choose the apps you want to give access to your enterprise data through Windows Information Protection. Apps included in this list can protect data on behalf of the enterprise and are restricted from copying or moving enterprise data to unprotected apps. - -The steps to add your app rules are based on the type of rule template being applied. You can add a store app (also known as a Universal Windows Platform (UWP) app), a signed Windows desktop app, or an AppLocker policy file. - ->[!IMPORTANT] ->Enlightened apps are expected to prevent enterprise data from going to unprotected network locations and to avoid encrypting personal data. On the other hand, WIP-unaware apps might not respect the corporate network boundary, and WIP-unaware apps will encrypt all files they create or modify. This means that they could encrypt personal data and cause data loss during the revocation process.

    Care must be taken to get a support statement from the software provider that their app is safe with Windows Information Protection before adding it to your **App rules** list. If you don't get this statement, it's possible that you could experience app compat issues due to an app losing the ability to access a necessary file after revocation. - -### Add a store app rule to your policy -For this example, we're going to add Microsoft OneNote, a store app, to the **App Rules** list. - -**To add a store app** - -1. From the **App rules** area, select **Add**. - - The **Add app rule** box appears. - - ![Create Configuration Item wizard, add a universal store app.](images/wip-configmgr-adduniversalapp.png) - -2. Add a friendly name for your app into the **Title** box. In this example, it's *Microsoft OneNote*. - -3. Select **Allow** from the **Windows Information Protection mode** drop-down list. - - Allow turns on WIP, helping to protect that app's corporate data through the enforcement of WIP restrictions. If you want to exempt an app, you can follow the steps in the [Exempt apps from WIP restrictions](#exempt-apps-from-wip-restrictions) section. - -4. Pick **Store App** from the **Rule template** drop-down list. - - The box changes to show the store app rule options. - -5. Type the name of the app and the name of its publisher, and then select **OK**. For this UWP app example, the **Publisher** is `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US` and the **Product name** is `Microsoft.Office.OneNote`. - -If you don't know the publisher or product name, you can find them for both desktop devices by following these steps. - -**To find the Publisher and Product Name values for Store apps without installing them** - -1. Go to the [Microsoft Store](https://apps.microsoft.com/) website, and find your app. For example, Microsoft OneNote. - - > [!NOTE] - > If your app is already installed on desktop devices, you can use the AppLocker local security policy MMC snap-in to gather the info for adding the app to the protected apps list. For info about how to do this, see the steps in [Add an AppLocker policy file](#add-an-applocker-policy-file) in this article. - -2. Copy the ID value from the app URL. For example, Microsoft OneNote's ID URL is `https://www.microsoft.com/store/apps/onenote/9wzdncrfhvjl`, and you'd copy the ID value, `9wzdncrfhvjl`. - -3. In a browser, run the Store for Business portal web API, to return a JavaScript Object Notation (JSON) file that includes the publisher and product name values. For example, run `https://bspmts.mp.microsoft.com/v1/public/catalog/Retail/Products/9wzdncrfhvjl/applockerdata`, where `9wzdncrfhvjl` is replaced with your ID value. - - The API runs and opens a text editor with the app details. - - ```json - { - "packageIdentityName": "Microsoft.Office.OneNote", - "publisherCertificateName": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" - } - ``` - -4. Copy the `publisherCertificateName` value and paste them into the **Publisher Name** box, copy the `packageIdentityName` value into the **Product Name** box of Intune. - - > [!IMPORTANT] - > The JSON file might also return a `windowsPhoneLegacyId` value for both the **Publisher Name** and **Product Name** boxes. This means that you have an app that's using a XAP package and that you must set the **Product Name** as `windowsPhoneLegacyId`, and set the **Publisher Name** as "CN=" followed by the `windowsPhoneLegacyId`. - > - > For example: - > - > ```json - > { - > "windowsPhoneLegacyId": "ca05b3ab-f157-450c-8c49-a1f127f5e71d", - > } - > ``` - -### Add a desktop app rule to your policy - -For this example, we're going to add Internet Explorer, a desktop app, to the **App Rules** list. - -**To add a desktop app to your policy** - -1. From the **App rules** area, select **Add**. - - The **Add app rule** box appears. - - ![Create Configuration Item wizard, add a classic desktop app.](images/wip-configmgr-adddesktopapp.png) - -2. Add a friendly name for your app into the **Title** box. In this example, it's *Internet Explorer*. - -3. Select **Allow** from the **Windows Information Protection mode** drop-down list. - - Allow turns on WIP, helping to protect that app's corporate data through the enforcement of WIP restrictions. If you want to exempt an app, you can follow the steps in the [Exempt apps from WIP restrictions](#exempt-apps-from-wip-restrictions) section. - -4. Pick **Desktop App** from the **Rule template** drop-down list. - - The box changes to show the desktop app rule options. - -5. Pick the options you want to include for the app rule (see table), and then select **OK**. - - |Option|Manages| - |--- |--- | - |All fields left as "*"|All files signed by any publisher. (Not recommended.)| - |**Publisher** selected|All files signed by the named publisher. This might be useful if your company is the publisher and signer of internal line-of-business apps.| - |**Publisher** and **Product Name** selected|All files for the specified product, signed by the named publisher.| - |**Publisher**, **Product Name**, and **Binary name** selected|Any version of the named file or package for the specified product, signed by the named publisher.| - |**Publisher**, **Product Name**, **Binary name**, and **File Version, and above**, selected|Specified version or newer releases of the named file or package for the specified product, signed by the named publisher. This option is recommended for enlightened apps that weren't previously enlightened.| - |**Publisher**, **Product Name**, **Binary name**, and **File Version, And below** selected|Specified version or older releases of the named file or package for the specified product, signed by the named publisher.| - |**Publisher**, **Product Name**, **Binary name**, and **File Version, Exactly** selected|Specified version of the named file or package for the specified product, signed by the named publisher.| - -If you're unsure about what to include for the publisher, you can run this PowerShell command: - -```powershell -Get-AppLockerFileInformation -Path "" -``` - -Where `""` goes to the location of the app on the device. For example, `Get-AppLockerFileInformation -Path "C:\Program Files\Internet Explorer\iexplore.exe"`. - -In this example, you'd get the following info: - -```console -Path Publisher ----- --------- -%PROGRAMFILES%\INTERNET EXPLORER\IEXPLORE.EXE O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\INTERNET EXPLOR... -``` - -Where the text, `O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US` is the publisher name to enter in the **Publisher Name** box. - -### Add an AppLocker policy file - -For this example, we're going to add an AppLocker XML file to the **App Rules** list. You'll use this option if you want to add multiple apps at the same time. For more info about AppLocker, see the [AppLocker](../../application-security/application-control/windows-defender-application-control/applocker/applocker-overview.md) content. - -**To create an app rule and xml file using the AppLocker tool** - -1. Open the Local Security Policy snap-in (SecPol.msc). - -2. In the left pane, expand **Application Control Policies**, expand **AppLocker**, and then select **Packaged App Rules**. - - ![Local security snap-in, showing the Packaged app Rules.](images/intune-local-security-snapin.png) - -3. Right-click in the right-hand pane, and then select **Create New Rule**. - - The **Create Packaged app Rules** wizard appears. - -4. On the **Before You Begin** page, select **Next**. - - ![Create a Packaged app Rules wizard and showing the Before You Begin page.](images/intune-applocker-before-begin.png) - -5. On the **Permissions** page, make sure the **Action** is set to **Allow** and the **User or group** is set to **Everyone**, and then select **Next**. - - ![Create Packaged app Rules wizard, set action to Allow.](images/intune-applocker-permissions.png) - -6. On the **Publisher** page, select **Select** from the **Use an installed packaged app as a reference** area. - - ![Create Packaged app Rules wizard, select use an installed packaged app.](images/intune-applocker-publisher.png) - -7. In the **Select applications** box, pick the app that you want to use as the reference for your rule, and then select **OK**. For this example, we're using Microsoft Photos. - - ![Create Packaged app Rules wizard, select application and click ok.](images/intune-applocker-select-apps.png) - -8. On the updated **Publisher** page, select **Create**. - - ![Create Packaged app Rules wizard, showing the Microsoft Photos on the Publisher page.](images/intune-applocker-publisher-with-app.png) - -9. Review the Local Security Policy snap-in to make sure your rule is correct. - - ![Local security snap-in, showing the new rule.](images/intune-local-security-snapin-updated.png) - -10. In the left pane, right-click on **AppLocker**, and then select **Export policy**. - - The **Export policy** box opens, letting you export and save your new policy as XML. - - ![Local security snap-in, showing the Export Policy option.](images/intune-local-security-export.png) - -11. In the **Export policy** box, browse to where the policy should be stored, give the policy a name, and then select **Save**. - - The policy is saved and you'll see a message that says one rule was exported from the policy. - - **Example XML file**
    - This is the XML file that AppLocker creates for Microsoft Photos. - - ```xml - - - - - - - - - - - - - - - - ``` -12. After you've created your XML file, you need to import it by using Configuration Manager. - -**To import your Applocker policy file app rule using Configuration Manager** - -1. From the **App rules** area, select **Add**. - - The **Add app rule** box appears. - - ![Create Configuration Item wizard, add an AppLocker policy.](images/wip-configmgr-addapplockerfile.png) - -2. Add a friendly name for your app into the **Title** box. In this example, it's *Allowed app list*. - -3. Select **Allow** from the **Windows Information Protection mode** drop-down list. - - Allow turns on WIP, helping to protect that app's corporate data through the enforcement of WIP restrictions. If you want to exempt an app, you can follow the steps in the [Exempt apps from WIP restrictions](#exempt-apps-from-wip-restrictions) section. - -4. Pick the **AppLocker policy file** from the **Rule template** drop-down list. - - The box changes to let you import your AppLocker XML policy file. - -5. Select the ellipsis (...) to browse for your AppLocker XML file, select **Open**, and then select **OK** to close the **Add app rule** box. - - The file is imported and the apps are added to your **App Rules** list. - -### Exempt apps from WIP restrictions -If you're running into compatibility issues where your app is incompatible with Windows Information Protection (WIP), but still needs to be used with enterprise data, you can exempt the app from the WIP restrictions. This means that your apps won't include auto-encryption or tagging and won't honor your network restrictions. It also means that your exempted apps might leak. - -**To exempt a store app, a desktop app, or an AppLocker policy file app rule** - -1. From the **App rules** area, select **Add**. - - The **Add app rule** box appears. - -2. Add a friendly name for your app into the **Title** box. In this example, it's *Exempt apps list*. - -3. Select **Exempt** from the **Windows Information Protection mode** drop-down list. - - When you exempt apps, they're allowed to bypass the WIP restrictions and access your corporate data. To allow apps, see [Add app rules to your policy](#add-app-rules-to-your-policy) in this article. - -4. Fill out the rest of the app rule info, based on the type of rule you're adding: - - - **Store app.** Follow the **Publisher** and **Product name** instructions in the [Add a store app rule to your policy](#add-a-store-app-rule-to-your-policy) section of this article. - - - **Desktop app.** Follow the **Publisher**, **Product name**, **Binary name**, and **Version** instructions in the [Add a desktop app rule to your policy](#add-a-desktop-app-rule-to-your-policy) section of this article. - - - **AppLocker policy file.** Follow the **Import** instructions in the [Add an AppLocker policy file](#add-an-applocker-policy-file) section of this article, using a list of exempted apps. - -5. Select **OK**. - -## Manage the WIP-protection level for your enterprise data -After you've added the apps you want to protect with WIP, you'll need to apply a management and protection mode. - -We recommend that you start with **Silent** or **Override** while verifying with a small group that you have the right apps on your protected apps list. After you're done, you can change to your final enforcement policy, either **Override** or **Block**. - ->[!NOTE] ->For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md). - -|Mode |Description | -|-----|------------| -|Block |WIP looks for inappropriate data sharing practices and stops the employee from completing the action. This can include sharing info across non-enterprise-protected apps in addition to sharing enterprise data between other people and devices outside of your enterprise.| -|Override |WIP looks for inappropriate data sharing, warning employees if they do something deemed potentially unsafe. However, this management mode lets the employee override the policy and share the data, logging the action to your audit log. | -|Silent |WIP runs silently, logging inappropriate data sharing, without blocking anything that would have been prompted for employee interaction while in Override mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still blocked.| -|Off |WIP is turned off and doesn't help to protect or audit your data.

    After you turn off WIP, an attempt is made to decrypt any WIP-tagged files on the locally attached drives. Your previous decryption and policy info isn't automatically reapplied if you turn WIP protection back on. For more information, see [How to disable Windows Information Protection](how-to-disable-wip.md).| - -:::image type="content" alt-text="Create Configuration Item wizard, choose your WIP-protection level" source="images/wip-configmgr-appmgmt.png"::: - -## Define your enterprise-managed identity domains -Corporate identity, usually expressed as your primary internet domain (for example, contoso.com), helps to identify and tag your corporate data from apps you've marked as protected by WIP. For example, emails using contoso.com are identified as being corporate and are restricted by your Windows Information Protection policies. - -You can specify multiple domains owned by your enterprise by separating them with the `|` character. For example, `contoso.com|newcontoso.com`. With multiple domains, the first one is designated as your corporate identity and all of the additional ones as being owned by the first one. We strongly recommend that you include all of your email address domains in this list. - -**To add your corporate identity** - -- Type the name of your corporate identity into the **Corporate identity** field. For example, `contoso.com` or `contoso.com|newcontoso.com`. - - ![Create Configuration Item wizard, Add the primary Internet domain for your enterprise identity.](images/wip-configmgr-corp-identity.png) - -## Choose where apps can access enterprise data -After you've added a protection mode to your apps, you'll need to decide where those apps can access enterprise data on your network. - -There are no default locations included with WIP, you must add each of your network locations. This area applies to any network endpoint device that gets an IP address in your enterprise's range and is also bound to one of your enterprise domains, including SMB shares. Local file system locations should just maintain encryption (for example, on local NTFS, FAT, ExFAT). - ->[!IMPORTANT] ->Every WIP policy should include policy that defines your enterprise network locations.
    ->Classless Inter-Domain Routing (CIDR) notation isn't supported for WIP configurations. - -**To define where your protected apps can find and send enterprise data on your network** - -1. Add additional network locations your apps can access by clicking **Add**. - - The **Add or edit corporate network definition** box appears. - -2. Type a name for your corporate network element into the **Name** box, and then pick what type of network element it is, from the **Network element** drop-down box. This can include any of the options in the following table. - - ![Add or edit corporate network definition box, Add your enterprise network locations.](images/wip-configmgr-add-network-domain.png) - - - **Enterprise Cloud Resources**: Specify the cloud resources to be treated as corporate and protected by WIP. - - For each cloud resource, you may also optionally specify a proxy server from your internal proxy servers list to route traffic for this cloud resource. All traffic routed through your internal proxy servers is considered enterprise. - - If you have multiple resources, you must separate them using the `|` delimiter. If you don't use proxy servers, you must also include the `,` delimiter just before the `|`. For example: URL `<,proxy>|URL <,proxy>`. - - **Format examples**: - - - **With proxy**: `contoso.sharepoint.com,contoso.internalproxy1.com|contoso.visualstudio.com,contoso.internalproxy2.com` - - - **Without proxy**: `contoso.sharepoint.com|contoso.visualstudio.com` - - >[!Important] - > In some cases, such as when an app connects directly to a cloud resource through an IP address, Windows can't tell whether it's attempting to connect to an enterprise cloud resource or to a personal site. In this case, Windows blocks the connection by default. To stop Windows from automatically blocking these connections, you can add the /*AppCompat*/ string to the setting. For example: URL <,proxy>|URL <,proxy>|/*AppCompat*/. - - - **Enterprise Network Domain Names (Required)**: Specify the DNS suffixes used in your environment. All traffic to the fully qualified domains appearing in this list will be protected. - - This setting works with the IP ranges settings to detect whether a network endpoint is enterprise or personal on private networks. - - If you have multiple resources, you must separate them using the "," delimiter. - - **Format examples**: `corp.contoso.com,region.contoso.com` - - - **Proxy servers**: Specify the proxy servers your devices will go through to reach your cloud resources. Using this server type indicates that the cloud resources you're connecting to are enterprise resources. - - This list shouldn't include any servers listed in your Internal proxy servers list. Internal proxy servers must be used only for WIP-protected (enterprise) traffic. - - If you have multiple resources, you must separate them using the ";" delimiter. - - **Format examples**: `proxy.contoso.com:80;proxy2.contoso.com:443` - - - **Internal proxy servers**: Specify the internal proxy servers your devices will go through to reach your cloud resources. Using this server type indicates that the cloud resources you're connecting to are enterprise resources. - - This list shouldn't include any servers listed in your Proxy servers list. Proxy servers must be used only for non-WIP-protected (non-enterprise) traffic. - - If you have multiple resources, you must separate them using the ";" delimiter. - - **Format examples**: `contoso.internalproxy1.com;contoso.internalproxy2.com` - - - **Enterprise IPv4 Range (Required)**: Specify the addresses for a valid IPv4 value range within your intranet. These addresses, used with your Enterprise Network Domain Names, define your corporate network boundaries. - - If you have multiple ranges, you must separate them using the "," delimiter. - - **Format examples**: - - - **Starting IPv4 Address:** `3.4.0.1` - - **Ending IPv4 Address:** `3.4.255.254` - - **Custom URI:** `3.4.0.1-3.4.255.254, 10.0.0.1-10.255.255.254` - - - **Enterprise IPv6 Range**: Specify the addresses for a valid IPv6 value range within your intranet. These addresses, used with your Enterprise Network Domain Names, define your corporate network boundaries. - - If you have multiple ranges, you must separate them using the "," delimiter. - - **Format examples**: - - - **Starting IPv6 Address:** `2a01:110::` - - **Ending IPv6 Address:** `2a01:110:7fff:ffff:ffff:ffff:ffff:ffff` - - **Custom URI:** `2a01:110:7fff:ffff:ffff:ffff:ffff:ffff,fd00::-fdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff` - - - **Neutral Resources**: Specify your authentication redirection endpoints for your company. These locations are considered enterprise or personal, based on the context of the connection before the redirection. - - If you have multiple resources, you must separate them using the "," delimiter. - - **Format examples**: `sts.contoso.com,sts.contoso2.com` - -3. Add as many locations as you need, and then select **OK**. - - The **Add or edit corporate network definition** box closes. - -4. Decide if you want to Windows to look for additional network settings and if you want to show the WIP icon on your corporate files while in File Explorer. - - :::image type="content" alt-text="Create Configuration Item wizard, Add whether to search for additional network settings" source="images/wip-configmgr-optsettings.png"::: - - - **Enterprise Proxy Servers list is authoritative (do not auto-detect).** Select this box if you want Windows to treat the proxy servers you specified in the network boundary definition as the complete list of proxy servers available on your network. If you clear this box, Windows will search for additional proxy servers in your immediate network. Not configured is the default option. - - - **Enterprise IP Ranges list is authoritative (do not auto-detect).** Select this box if you want Windows to treat the IP ranges you specified in the network boundary definition as the complete list of IP ranges available on your network. If you clear this box, Windows will search for additional IP ranges on any domain-joined devices connected to your network. Not configured is the default option. - - - **Show the Windows Information Protection icon overlay on your allowed apps that are WIP-unaware on corporate files in the File Explorer.** Select this box if you want the Windows Information Protection icon overlay to appear on corporate files in the Save As and File Explorer views. Additionally, for unenlightened but allowed apps, the icon overlay also appears on the app tile and with *Managed* text on the app name in the **Start** menu. Not configured is the default option. - -5. In the required **Upload a Data Recovery Agent (DRA) certificate to allow recovery of encrypted data** box, select **Browse** to add a data recovery certificate for your policy. - - ![Create Configuration Item wizard, Add a data recovery agent (DRA) certificate.](images/wip-configmgr-dra.png) - - After you create and deploy your WIP policy to your employees, Windows will begin to encrypt your corporate data on the employees' local device drive. If somehow the employees' local encryption keys get lost or revoked, the encrypted data can become unrecoverable. To help avoid this possibility, the DRA certificate lets Windows use an included public key to encrypt the local data, while you maintain the private key that can unencrypt the data. - - For more info about how to find and export your data recovery certificate, see [Data Recovery and Encrypting File System (EFS)](/previous-versions/tn-archive/cc512680(v=technet.10)). For more info about creating and verifying your EFS DRA certificate, see [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](create-and-verify-an-efs-dra-certificate.md). - -## Choose your optional WIP-related settings -After you've decided where your protected apps can access enterprise data on your network, you'll be asked to decide if you want to add any optional WIP settings. - -![Create Configuration Item wizard, Choose any additional, optional settings.](images/wip-configmgr-additionalsettings.png) - -**To set your optional settings** -1. Choose to set any or all of the optional settings: - - - **Allow Windows Search to search encrypted corporate data and Store apps.** Determines whether Windows Search can search and index encrypted corporate data and Store apps. The options are: - - - **Yes.** Allows Windows Search to search and index encrypted corporate data and Store apps. - - - **No, or not configured (recommended).** Stops Windows Search from searching and indexing encrypted corporate data and Store apps. - - - **Revoke local encryption keys during the unenrollment process.** Determines whether to revoke a user's local encryption keys from a device when it's unenrolled from Windows Information Protection. If the encryption keys are revoked, a user no longer has access to encrypted corporate data. The options are: - - - **Yes, or not configured (recommended).** Revokes local encryption keys from a device during unenrollment. - - - **No.** Stop local encryption keys from being revoked from a device during unenrollment. For example, if you're migrating between Mobile Device Management (MDM) solutions. - - - **Allow Azure RMS.** Enables secure sharing of files by using removable media such as USB drives. For more information about how RMS works with WIP, see [Create a WIP policy using Intune](create-wip-policy-using-intune-azure.md). To confirm what templates your tenant has, run [Get-AadrmTemplate](/powershell/module/aadrm/get-aadrmtemplate) from the [AADRM PowerShell module](/azure/information-protection/administer-powershell). If you don't specify a template, WIP uses a key from a default RMS template that everyone in the tenant will have access to. - -2. After you pick all of the settings you want to include, select **Summary**. - -## Review your configuration choices in the Summary screen -After you've finished configuring your policy, you can review all of your info on the **Summary** screen. - -**To view the Summary screen** -- Select the **Summary** button to review your policy choices, and then select **Next** to finish and to save your policy. - - ![Create Configuration Item wizard, Summary screen for all of your policy choices.](images/wip-configmgr-summaryscreen.png) - - A progress bar appears, showing you progress for your policy. After it's done, select **Close** to return to the **Configuration Items** page. - -## Deploy the WIP policy -After you've created your WIP policy, you'll need to deploy it to your organization's devices. For more information about your deployment options, see the following articles: - -- [Create configuration baselines in Configuration Manager](/mem/configmgr/compliance/deploy-use/create-configuration-baselines) - -- [How to deploy configuration baselines in Configuration Manager](/mem/configmgr/compliance/deploy-use/deploy-configuration-baselines) - -## Related articles - -- [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md) - -- [General guidance and best practices for Windows Information Protection (WIP)](guidance-and-best-practices-wip.md) - -- [Limitations while using Windows Information Protection (WIP)](limitations-with-wip.md) diff --git a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md b/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md deleted file mode 100644 index c73eda005f..0000000000 --- a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md +++ /dev/null @@ -1,605 +0,0 @@ ---- -title: Create a WIP policy in Intune -description: Learn how to use the Microsoft Intune admin center to create and deploy your Windows Information Protection (WIP) policy to protect data on your network. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.reviewer: rafals -ms.topic: how-to -ms.date: 07/15/2022 ---- - -# Create a Windows Information Protection policy in Microsoft Intune - -[!INCLUDE [Deprecate Windows Information Protection](includes/wip-deprecation.md)] - - -_Applies to:_ - -- Windows 10 -- Windows 11 - -Microsoft Intune has an easy way to create and deploy a Windows Information Protection (WIP) policy. You can choose which apps to protect, the level of protection, and how to find enterprise data on the network. The devices can be fully managed by Mobile Device Management (MDM), or managed by Mobile Application Management (MAM), where Intune manages only the apps on a user's personal device. - -## Differences between MDM and MAM for WIP - -You can create an app protection policy in Intune either with device enrollment for MDM or without device enrollment for MAM. The process to create either policy is similar, but there are important differences: - -- MAM has more **Access** settings for Windows Hello for Business. -- MAM can [selectively wipe company data](/intune/apps-selective-wipe) from a user's personal device. -- MAM requires an [Microsoft Entra ID P1 or P2 license](/azure/active-directory/fundamentals/active-directory-whatis#what-are-the-azure-ad-licenses). -- A Microsoft Entra ID P1 or P2 license is also required for WIP auto-recovery, where a device can re-enroll and regain access to protected data. WIP auto-recovery depends on Microsoft Entra registration to back up the encryption keys, which requires device auto-enrollment with MDM. -- MAM supports only one user per device. -- MAM can only manage [enlightened apps](enlightened-microsoft-apps-and-wip.md). -- Only MDM can use [BitLocker CSP](/windows/client-management/mdm/bitlocker-csp) policies. -- If the same user and device are targeted for both MDM and MAM, the MDM policy will be applied to devices joined to Microsoft Entra ID. For personal devices that are workplace-joined (that is, added by using **Settings** > **Email & accounts** > **Add a work or school account**), the MAM-only policy will be preferred but it's possible to upgrade the device management to MDM in **Settings**. Windows Home edition only supports WIP for MAM-only; upgrading to MDM policy on Home edition will revoke WIP-protected data access. - - -## Prerequisites - -Before you can create a WIP policy using Intune, you need to configure an MDM or MAM provider in Microsoft Entra ID. MAM requires an [Microsoft Entra ID P1 or P2 license](/azure/active-directory/fundamentals/active-directory-whatis#what-are-the-azure-ad-licenses). A Microsoft Entra ID P1 or P2 license is also required for WIP auto-recovery, where a device can re-enroll and regain access to protected data. WIP auto-recovery relies on Microsoft Entra registration to back up the encryption keys, which requires device auto-enrollment with MDM. - -## Configure the MDM or MAM provider - -1. Sign in to the Azure portal. - -2. Select **Microsoft Entra ID** > **Mobility (MDM and MAM)** > **Microsoft Intune**. - -3. Select **Restore Default URLs** or enter the settings for MDM or MAM user scope and select **Save**: - - ![Configure MDM or MAM provider.](images/mobility-provider.png) - -## Create a WIP policy - -1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). - -2. Open Microsoft Intune and select **Apps** > **App protection policies** > **Create policy**. - - ![Open Client apps.](images/create-app-protection-policy.png) - -3. In the **App policy** screen, select **Add a policy**, and then fill out the fields: - - - **Name.** Type a name (required) for your new policy. - - - **Description.** Type an optional description. - - - **Platform.** Choose **Windows 10**. - - - **Enrollment state.** Choose **Without enrollment** for MAM or **With enrollment** for MDM. - - ![Add a mobile app policy.](images/add-a-mobile-app-policy.png) - -4. Select **Protected apps** and then select **Add apps**. - - ![Add protected apps.](images/add-protected-apps.png) - - You can add these types of apps: - - - [Recommended apps](#add-recommended-apps) - - [Store apps](#add-store-apps) - - [Desktop apps](#add-desktop-apps) - ->[!NOTE] ->An application might return access denied errors after removing it from the list of protected apps. Rather than remove it from the list, uninstall and reinstall the application or exempt it from WIP policy. - -### Add recommended apps - -Select **Recommended apps** and select each app you want to access your enterprise data or select them all, and select **OK**. - -![Microsoft Intune management console: Recommended apps.](images/recommended-apps.png) - -### Add Store apps - -Select **Store apps**, type the app product name and publisher, and select **OK**. For example, to add the Power BI Mobile App from the Store, type the following: - -- **Name**: Microsoft Power BI -- **Publisher**: `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US` -- **Product Name**: `Microsoft.MicrosoftPowerBIForWindows` - -![Add Store app.](images/add-a-protected-store-app.png) - -To add multiple Store apps, select the ellipsis `…`. - -If you don't know the Store app publisher or product name, you can find them by following these steps. - -1. Go to the [Microsoft Store for Business](https://go.microsoft.com/fwlink/p/?LinkID=722910) website, and find your app. For example, *Power BI Mobile App*. - -2. Copy the ID value from the app URL. For example, the Power BI Mobile App ID URL is `https://www.microsoft.com/store/p/microsoft-power-bi/9nblgggzlxn1`, and you'd copy the ID value, `9nblgggzlxn1`. - -3. In a browser, run the Store for Business portal web API, to return a JavaScript Object Notation (JSON) file that includes the publisher and product name values. For example, run `https://bspmts.mp.microsoft.com/v1/public/catalog/Retail/Products/9nblgggzlxn1/applockerdata`, where `9nblgggzlxn1` is replaced with your ID value. - - The API runs and opens a text editor with the app details. - - ```json - { - "packageIdentityName": "Microsoft.MicrosoftPowerBIForWindows", - "publisherCertificateName": "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" - } - ``` - -4. Copy the `publisherCertificateName` value into the **Publisher** box and copy the `packageIdentityName` value into the **Name** box of Intune. - - >[!Important] - >The JSON file might also return a `windowsPhoneLegacyId` value for both the **Publisher Name** and **Product Name** boxes. This means that you have an app that's using a XAP package and that you must set the **Product Name** as `windowsPhoneLegacyId`, and set the **Publisher Name** as `CN=` followed by the `windowsPhoneLegacyId`. - > - > For example: - > - > ```json - > { - > "windowsPhoneLegacyId": "ca05b3ab-f157-450c-8c49-a1f127f5e71d", - > } - - - -### Add Desktop apps - -To add **Desktop apps**, complete the following fields, based on what results you want returned. - -|Field|Manages| -|--- |--- | -|All fields marked as `*`|All files signed by any publisher. (Not recommended and may not work)| -|Publisher only|If you only fill out this field, you'll get all files signed by the named publisher. This might be useful if your company is the publisher and signer of internal line-of-business apps.| -|Publisher and Name only|If you only fill out these fields, you'll get all files for the specified product, signed by the named publisher.| -|Publisher, Name, and File only|If you only fill out these fields, you'll get any version of the named file or package for the specified product, signed by the named publisher.| -|Publisher, Name, File, and Min version only|If you only fill out these fields, you'll get the specified version or newer releases of the named file or package for the specified product, signed by the named publisher. This option is recommended for enlightened apps that weren't previously enlightened.| -|Publisher, Name, File, and Max version only|If you only fill out these fields, you'll get the specified version or older releases of the named file or package for the specified product, signed by the named publisher.| -|All fields completed|If you fill out all fields, you'll get the specified version of the named file or package for the specified product, signed by the named publisher.| - -To add another Desktop app, select the ellipsis `…`. After you've entered the info into the fields, select **OK**. - -![Microsoft Intune management console: Adding Desktop app info.](images/wip-azure-add-desktop-apps.png) - -If you're unsure about what to include for the publisher, you can run this PowerShell command: - -```powershell -Get-AppLockerFileInformation -Path "" -``` - -Where `""` goes to the location of the app on the device. For example: - -```powershell -Get-AppLockerFileInformation -Path "C:\Program Files\Windows NT\Accessories\wordpad.exe" -``` - -In this example, you'd get the following info: - -```console -Path Publisher ----- --------- -%PROGRAMFILES%\WINDOWS NT\ACCESSORIES\WORDPAD.EXE O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US -``` - -Where `O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US` is the **Publisher** name and `WORDPAD.EXE` is the **File** name. - -Regarding to how to get the Product Name for the Apps you wish to Add, contact the Windows Support Team to request the guidelines - -### Import a list of apps - -This section covers two examples of using an AppLocker XML file to the **Protected apps** list. You'll use this option if you want to add multiple apps at the same time. - -- [Create a Packaged App rule for Store apps](#create-a-packaged-app-rule-for-store-apps) -- [Create an Executable rule for unsigned apps](#create-an-executable-rule-for-unsigned-apps) - -For more info about AppLocker, see the [AppLocker](../../application-security/application-control/windows-defender-application-control/applocker/applocker-overview.md) content. - -#### Create a Packaged App rule for Store apps - -1. Open the Local Security Policy snap-in (SecPol.msc). - -2. Expand **Application Control Policies**, expand **AppLocker**, and then select **Packaged App Rules**. - - ![Local security snap-in, showing the Packaged app Rules.](images/wip-applocker-secpol-1.png) - -3. Right-click in the right side, and then select **Create New Rule**. - - The **Create Packaged app Rules** wizard appears. - -4. On the **Before You Begin** page, select **Next**. - - ![Screenshot of the Before You Begin tab.](images/wip-applocker-secpol-wizard-1.png) - -5. On the **Permissions** page, make sure the **Action** is set to **Allow** and the **User or group** is set to **Everyone**, and then select **Next**. - - ![Screenshot of the Permissions tab with "Allow" and "Everyone" selected](images/wip-applocker-secpol-wizard-2.png) - -6. On the **Publisher** page, choose **Select** from the **Use an installed packaged app as a reference** area. - - ![Screenshot of the "Use an installed package app as a reference" radio button selected and the Select button highlighted](images/wip-applocker-secpol-wizard-3.png) - -7. In the **Select applications** box, pick the app that you want to use as the reference for your rule, and then select **OK**. For this example, we're using Microsoft Dynamics 365. - - ![Screenshot of the Select applications list.](images/wip-applocker-secpol-wizard-4.png) - -8. On the updated **Publisher** page, select **Create**. - - ![Screenshot of the Publisher tab.](images/wip-applocker-secpol-wizard-5.png) - -9. Select **No** in the dialog box that appears, asking if you want to create the default rules. Don't create default rules for your WIP policy. - - ![Screenshot of AppLocker warning.](images/wip-applocker-default-rule-warning.png) - -9. Review the Local Security Policy snap-in to make sure your rule is correct. - - ![Local security snap-in, showing the new rule.](images/wip-applocker-secpol-create.png) - -10. On the left, right-click on **AppLocker**, and then select **Export policy**. - - The **Export policy** box opens, letting you export and save your new policy as XML. - - ![Local security snap-in, showing the Export Policy option.](images/wip-applocker-secpol-export.png) - -11. In the **Export policy** box, browse to where the policy should be stored, give the policy a name, and then select **Save**. - - The policy is saved and you'll see a message that says one rule was exported from the policy. - - **Example XML file**
    - This is the XML file that AppLocker creates for Microsoft Dynamics 365. - - ```xml - - - - - - - - - - - - - - - - - ``` - -12. After you've created your XML file, you need to import it by using Microsoft Intune. - -## Create an Executable rule for unsigned apps - -The executable rule helps to create an AppLocker rule to sign any unsigned apps. It enables adding the file path or the app publisher contained in the file's digital signature needed for the WIP policy to be applied. - -1. Open the Local Security Policy snap-in (SecPol.msc). - -2. In the left pane, select **Application Control Policies** > **AppLocker** > **Executable Rules**. - -3. Right-click **Executable Rules** > **Create New Rule**. - - ![Local security snap-in, showing the Executable Rules.](images/create-new-path-rule.png) - -4. On the **Before You Begin** page, select **Next**. - -5. On the **Permissions** page, make sure the **Action** is set to **Allow** and the **User or group** is set to **Everyone**, and then select **Next**. - -6. On the **Conditions** page, select **Path** and then select **Next**. - - ![Screenshot with Path conditions selected in the Create Executable Rules wizard.](images/path-condition.png) - -7. Select **Browse Folders...** and select the path for the unsigned apps. For this example, we're using "C:\Program Files". - - ![Screenshot of the Path field of the Create Executable Rules wizard.](images/select-path.png) - -8. On the **Exceptions** page, add any exceptions and then select **Next**. - -9. On the **Name** page, type a name and description for the rule and then select **Create**. - -10. In the left pane, right-click **AppLocker** > **Export policy**. - -11. In the **Export policy** box, browse to where the policy should be stored, give the policy a name, and then select **Save**. - - The policy is saved and you'll see a message that says one rule was exported from the policy. - -12. After you've created your XML file, you need to import it by using Microsoft Intune. - - -**To import a list of protected apps using Microsoft Intune** - -1. In **Protected apps**, select **Import apps**. - - ![Import protected apps.](images/import-protected-apps.png) - - Then import your file. - - ![Microsoft Intune, Importing your AppLocker policy file using Intune.](images/wip-azure-import-apps.png) - -2. Browse to your exported AppLocker policy file, and then select **Open**. - - The file imports and the apps are added to your **Protected apps** list. - -### Exempt apps from a WIP policy -If your app is incompatible with WIP, but still needs to be used with enterprise data, then you can exempt the app from the WIP restrictions. This means that your apps won't include auto-encryption or tagging and won't honor your network restrictions. It also means that your exempted apps might leak. - -1. In **Client apps - App protection policies**, select **Exempt apps**. - - ![Exempt apps.](images/exempt-apps.png) - -2. In **Exempt apps**, select **Add apps**. - - When you exempt apps, they're allowed to bypass the WIP restrictions and access your corporate data. - -3. Fill out the rest of the app info, based on the type of app you're adding: - - - [Add Recommended apps](#add-recommended-apps) - - - [Add Store apps](#add-store-apps) - - - [Add Desktop apps](#add-desktop-apps) - - - [Import apps](#import-a-list-of-apps) - -4. Select **OK**. - -## Manage the WIP protection mode for your enterprise data -After you've added the apps you want to protect with WIP, you'll need to apply a management and protection mode. - -We recommend that you start with **Silent** or **Allow Overrides** while verifying with a small group that you have the right apps on your protected apps list. After you're done, you can change to your final enforcement policy, **Block**. - -1. From **App protection policy**, select the name of your policy, and then select **Required settings**. - - ![Microsoft Intune, Required settings shows Windows Information Protection mode.](images/wip-azure-required-settings-protection-mode.png) - - |Mode |Description | - |-----|------------| - |Block |WIP looks for inappropriate data sharing practices and stops the employee from completing the action. This can include sharing info across non-enterprise-protected apps in addition to sharing enterprise data between other people and devices outside of your enterprise.| - |Allow Overrides |WIP looks for inappropriate data sharing, warning employees if they do something deemed potentially unsafe. However, this management mode lets the employee override the policy and share the data, logging the action to your audit log. For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md).| - |Silent |WIP runs silently, logging inappropriate data sharing, without blocking anything that would have been prompted for employee interaction while in Allow Override mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped.| - |Off |WIP is turned off and doesn't help to protect or audit your data.

    After you turn off WIP, an attempt is made to decrypt any WIP-tagged files on the locally attached drives. Your previous decryption and policy info isn't automatically reapplied if you turn WIP protection back on. For more information, see [How to disable Windows Information Protection](how-to-disable-wip.md).| - -2. Select **Save**. - -## Define your enterprise-managed corporate identity -Corporate identity, typically expressed as your primary Internet domain (for example, contoso.com), helps to identify and tag your corporate data from apps you've marked as protected by WIP. For example, emails using contoso.com are identified as being corporate and are restricted by your Windows Information Protection policies. - -Starting with Windows 10, version 1703, Intune automatically determines your corporate identity and adds it to the **Corporate identity** field. - -**To change your corporate identity** - -1. From **App policy**, select the name of your policy, and then select **Required settings**. - -2. If the auto-defined identity isn't correct, you can change the info in the **Corporate identity** field. - - ![Microsoft Intune, Set your corporate identity for your organization.](images/wip-azure-required-settings-corp-identity.png) - -3. To add domains, such your email domain names, select **Configure Advanced settings** > **Add network boundary** and select **Protected domains**. - - ![Add protected domains.](images/add-protected-domains.png) - -## Choose where apps can access enterprise data -After you've added a protection mode to your apps, you'll need to decide where those apps can access enterprise data on your network. Every WIP policy should include your enterprise network locations. - -There are no default locations included with WIP, you must add each of your network locations. This area applies to any network endpoint device that gets an IP address in your enterprise's range and is also bound to one of your enterprise domains, including SMB shares. Local file system locations should just maintain encryption (for example, on local NTFS, FAT, ExFAT). - -To define the network boundaries, select **App policy** > the name of your policy > **Advanced settings** > **Add network boundary**. - -![Microsoft Intune, Set where your apps can access enterprise data on your network.](images/wip-azure-advanced-settings-network.png) - -Select the type of network boundary to add from the **Boundary type** box. Type a name for your boundary into the **Name** box, add your values to the **Value** box, based on the options covered in the following subsections, and then select **OK**. - -### Cloud resources - -Specify the cloud resources to be treated as corporate and protected by WIP. -For each cloud resource, you may also optionally specify a proxy server from your Internal proxy servers list to route traffic for this cloud resource. -All traffic routed through your Internal proxy servers is considered enterprise. - -Separate multiple resources with the "|" delimiter. -For example: - -```console -URL <,proxy>|URL <,proxy> -``` - -Personal applications can access a cloud resource that has a blank space or an invalid character, such as a trailing dot in the URL. - -To add a subdomain for a cloud resource, use a period (.) instead of an asterisk (*). For example, to add all subdomains within Office.com, use ".office.com" (without the quotation marks). - -In some cases, such as when an app connects directly to a cloud resource through an IP address, Windows can't tell whether it's attempting to connect to an enterprise cloud resource or to a personal site. -In this case, Windows blocks the connection by default. -To stop Windows from automatically blocking these connections, you can add the `/*AppCompat*/` string to the setting. -For example: - -```console -URL <,proxy>|URL <,proxy>|/*AppCompat*/ -``` - -When you use this string, we recommend that you also turn on [Microsoft Entra Conditional Access](/azure/active-directory/active-directory-conditional-access), using the **Domain joined or marked as compliant** option, which blocks apps from accessing any enterprise cloud resources that are protected by conditional access. - -Value format with proxy: - -```console -contoso.sharepoint.com,contoso.internalproxy1.com|contoso.visualstudio.com,contoso.internalproxy2.com -``` - -Value format without proxy: - -```console -contoso.sharepoint.com|contoso.visualstudio.com|contoso.onedrive.com, -``` - -### Protected domains - -Specify the domains used for identities in your environment. -All traffic to the fully qualified domains appearing in this list will be protected. -Separate multiple domains with the "|" delimiter. - -```console -exchange.contoso.com|contoso.com|region.contoso.com -``` - -### Network domains - -Specify the DNS suffixes used in your environment. -All traffic to the fully qualified domains appearing in this list will be protected. -Separate multiple resources with the "," delimiter. - -```console -corp.contoso.com,region.contoso.com -``` - -### Proxy servers - -Specify the proxy servers your devices will go through to reach your cloud resources. -Using this server type indicates that the cloud resources you're connecting to are enterprise resources. - -This list shouldn't include any servers listed in your Internal proxy servers list. -Proxy servers must be used only for non-WIP-protected (non-enterprise) traffic. -Separate multiple resources with the ";" delimiter. - -```console -proxy.contoso.com:80;proxy2.contoso.com:443 -``` - -### Internal proxy servers - -Specify the internal proxy servers your devices will go through to reach your cloud resources. Using this server type indicates that the cloud resources you're connecting to are enterprise resources. - -This list shouldn't include any servers listed in your Proxy servers list. -Internal proxy servers must be used only for WIP-protected (enterprise) traffic. -Separate multiple resources with the ";" delimiter. - -```console -contoso.internalproxy1.com;contoso.internalproxy2.com -``` - -### IPv4 ranges - -Specify the addresses for a valid IPv4 value range within your intranet. -These addresses, used with your Network domain names, define your corporate network boundaries. -Classless Inter-Domain Routing (CIDR) notation isn't supported. - -Separate multiple ranges with the "," delimiter. - -**Starting IPv4 Address:** 3.4.0.1
    -**Ending IPv4 Address:** 3.4.255.254
    -**Custom URI:** 3.4.0.1-3.4.255.254,
    -10.0.0.1-10.255.255.254 - -### IPv6 ranges - -Starting with Windows 10, version 1703, this field is optional. - -Specify the addresses for a valid IPv6 value range within your intranet. -These addresses, used with your network domain names, define your corporate network boundaries. -Classless Inter-Domain Routing (CIDR) notation isn't supported. - -Separate multiple ranges with the "," delimiter. - -**Starting IPv6 Address:** `2a01:110::`
    -**Ending IPv6 Address:** `2a01:110:7fff:ffff:ffff:ffff:ffff:ffff`
    -**Custom URI:** `2a01:110:7fff:ffff:ffff:ffff:ffff:ffff,'
    'fd00::-fdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff` - -### Neutral resources - -Specify your authentication redirection endpoints for your company. -These locations are considered enterprise or personal, based on the context of the connection before the redirection. -Separate multiple resources with the "," delimiter. - -```console -sts.contoso.com,sts.contoso2.com -``` - -Decide if you want Windows to look for more network settings: - -- **Enterprise Proxy Servers list is authoritative (do not auto-detect).** Turn on if you want Windows to treat the proxy servers you specified in the network boundary definition as the complete list of proxy servers available on your network. If you turn this off, Windows will search for more proxy servers in your immediate network. - -- **Enterprise IP Ranges list is authoritative (do not auto-detect).** Turn on if you want Windows to treat the IP ranges you specified in the network boundary definition as the complete list of IP ranges available on your network. If you turn this off, Windows will search for more IP ranges on any domain-joined devices connected to your network. - -![Microsoft Intune, Choose if you want Windows to search for more proxy servers or IP ranges in your enterprise.](images/wip-azure-advanced-settings-network-autodetect.png) - -## Upload your Data Recovery Agent (DRA) certificate -After you create and deploy your WIP policy to your employees, Windows begins to encrypt your corporate data on the employees' local device drive. If somehow the employees' local encryption keys get lost or revoked, the encrypted data can become unrecoverable. To help avoid this possibility, the Data Recovery Agent (DRA) certificate lets Windows use an included public key to encrypt the local data while you maintain the private key that can unencrypt the data. - ->[!Important] ->Using a DRA certificate isn't mandatory. However, we strongly recommend it. For more info about how to find and export your data recovery certificate, see [Data Recovery and Encrypting File System (EFS)](/previous-versions/tn-archive/cc512680(v=technet.10)). For more info about creating and verifying your EFS DRA certificate, see [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](/windows/threat-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate). - -**To upload your DRA certificate** -1. From **App policy**, select the name of your policy, and then select **Advanced settings** from the menu that appears. - - **Advanced settings** shows. - -2. In the **Upload a Data Recovery Agent (DRA) certificate to allow recovery of encrypted data** box, select **Browse** to add a data recovery certificate for your policy. - - ![Microsoft Intune, Upload your Data Recovery Agent (DRA) certificate.](images/wip-azure-advanced-settings-efsdra.png) - -## Choose your optional WIP-related settings -After you've decided where your protected apps can access enterprise data on your network, you can choose optional settings. - -![Advanced optional settings.](images/wip-azure-advanced-settings-optional.png) - -**Revoke encryption keys on unenroll.** Determines whether to revoke a user's local encryption keys from a device when it's unenrolled from Windows Information Protection. If the encryption keys are revoked, a user no longer has access to encrypted corporate data. The options are: - -- **On, or not configured (recommended).** Revokes local encryption keys from a device during unenrollment. - -- **Off.** Stop local encryption keys from being revoked from a device during unenrollment. For example, if you're migrating between Mobile Device Management (MDM) solutions. - -**Show the enterprise data protection icon.** Determines whether the Windows Information Protection icon overlay appears on corporate files in the Save As and File Explorer views. The options are: - -- **On.** Allows the Windows Information Protection icon overlay to appear on corporate files in the Save As and File Explorer views. Also, for unenlightened but protected apps, the icon overlay also appears on the app tile and with Managed text on the app name in the **Start** menu. - -- **Off, or not configured (recommended).** Stops the Windows Information Protection icon overlay from appearing on corporate files or unenlightened, but protected apps. Not configured is the default option. - -**Use Azure RMS for WIP.** Determines whether WIP uses [Microsoft Azure Rights Management](/azure/information-protection/what-is-azure-rms) to apply EFS encryption to files that are copied from Windows 10 to USB or other removable drives so they can be securely shared with employees. In other words, WIP uses Azure Rights Management "machinery" to apply EFS encryption to files when they're copied to removable drives. You must already have Azure Rights Management set up. The EFS file encryption key is protected by the RMS template's license. Only users with permission to that template can read it from the removable drive. WIP can also integrate with Azure RMS by using the **AllowAzureRMSForEDP** and the **RMSTemplateIDForEDP** MDM settings in the [EnterpriseDataProtection CSP](/windows/client-management/mdm/enterprisedataprotection-csp). - -- **On.** Protects files that are copied to a removable drive. You can enter a TemplateID GUID to specify who can access the Azure Rights Management protected files, and for how long. The RMS template is only applied to the files on removable media, and is only used for access control—it doesn't actually apply Azure Information Protection to the files. - - If you don't specify an [RMS template](/information-protection/deploy-use/configure-custom-templates), it's a regular EFS file using a default RMS template that all users can access. - -- **Off, or not configured.** Stops WIP from encrypting Azure Rights Management files that are copied to a removable drive. - - > [!NOTE] - > Regardless of this setting, all files in OneDrive for Business will be encrypted, including moved Known Folders. - -**Allow Windows Search Indexer to search encrypted files.** Determines whether to allow the Windows Search Indexer to index items that are encrypted, such as WIP protected files. - -- **On.** Starts Windows Search Indexer to index encrypted files. - -- **Off, or not configured.** Stops Windows Search Indexer from indexing encrypted files. - -## Encrypted file extensions - -You can restrict which files are protected by WIP when they're downloaded from an SMB share within your enterprise network locations. If this setting is configured, only files with the extensions in the list will be encrypted. If this setting is not specified, the existing auto-encryption behavior is applied. - -![WIP encrypted file extensions.](images/wip-encrypted-file-extensions.png) - -## Related articles - -- [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md) - -- [General guidance and best practices for Windows Information Protection (WIP)](guidance-and-best-practices-wip.md) - -- [What is Azure Rights Management?](/information-protection/understand-explore/what-is-azure-rms) - -- [Create a Windows Information Protection (WIP) protection policy using Microsoft Intune](overview-create-wip-policy.md) - -- [Intune MAM Without Enrollment](/archive/blogs/configmgrdogs/intune-mam-without-enrollment) - -- [Azure RMS Documentation Update for May 2016](https://blogs.technet.microsoft.com/enterprisemobility/2016/05/31/azure-rms-documentation-update-for-may-2016/) diff --git a/windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md b/windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md deleted file mode 100644 index 0269f73fe5..0000000000 --- a/windows/security/information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: Deploy your Windows Information Protection (WIP) policy using the Azure portal for Microsoft Intune -description: After you've created your Windows Information Protection (WIP) policy, you'll need to deploy it to your organization's enrolled devices. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 03/05/2019 -ms.reviewer: ---- - -# Deploy your Windows Information Protection (WIP) policy using the Azure portal for Microsoft Intune - -**Applies to:** - -- Windows 10, version 1607 and later - -After you've created your Windows Information Protection (WIP) policy, you'll need to deploy it to your organization's enrolled devices. Enrollment can be done for business or personal devices, allowing the devices to use your managed apps and to sync with your managed content and information. - -## To deploy your WIP policy - -1. On the **App protection policies** pane, click your newly created policy, click **Assignments**, and then select groups to include or exclude from the policy. - -2. Choose the group you want your policy to apply to, and then click **Select** to deploy the policy. - - The policy is deployed to the selected users' devices. - - ![Microsoft Intune: Pick your user groups that should get the policy when it's deployed.](images/wip-azure-add-user-groups.png) - - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). - -## Related topics - -- [General guidance and best practices for Windows Information Protection (WIP)](guidance-and-best-practices-wip.md) diff --git a/windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md b/windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md deleted file mode 100644 index 1660b49f10..0000000000 --- a/windows/security/information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: List of enlightened Microsoft apps for use with Windows Information Protection (WIP) -description: Learn the difference between enlightened and unenlightened apps. Find out which enlightened apps are provided by Microsoft. Learn how to allow-list them. -ms.reviewer: -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 05/02/2019 ---- - -# List of enlightened Microsoft apps for use with Windows Information Protection (WIP) - -**Applies to:** - -- Windows 10, version 1607 and later - -Learn the difference between enlightened and unenlightened apps, and then review the list of enlightened apps provided by Microsoft along with the text you will need to use to add them to your allowed apps list. - -## Enlightened versus unenlightened apps -Apps can be enlightened or unenlightened: - -- **Enlightened apps** can differentiate between corporate and personal data, correctly determining which to protect, based on your policies. - -- **Unenlightened apps** consider all data corporate and encrypt everything. Typically, you can tell an unenlightened app because: - - - Windows Desktop shows it as always running in enterprise mode. - - - Windows **Save As** experiences only allow you to save your files as enterprise. - -- **Windows Information Protection-work only apps** are unenlightened line-of-business apps that have been tested and deemed safe for use in an enterprise with WIP and Mobile App Management (MAM) solutions without device enrollment. Unenlightened apps that are targeted by WIP without enrollment run under personal mode. - -## List of enlightened Microsoft apps -Microsoft has made a concerted effort to enlighten several of our more popular apps, including the following: - -- Microsoft 3D Viewer - -- Microsoft Edge - -- Internet Explorer 11 - -- Microsoft People - -- Mobile Office apps, including Word, Excel, PowerPoint, OneNote, and Outlook Mail and Calendar - -- Microsoft 365 Apps for enterprise apps, including Word, Excel, PowerPoint, OneNote, and Outlook - -- OneDrive app - -- OneDrive sync client (OneDrive.exe, the next generation sync client) - -- Microsoft Photos - -- Groove Music - -- Notepad - -- Microsoft Paint - -- Microsoft Movies & TV - -- Microsoft Messaging - -- Microsoft Remote Desktop - -- Microsoft To Do - -> [!NOTE] -> Microsoft Visio, Microsoft Office Access, Microsoft Project, and Microsoft Publisher are not enlightened apps and need to be exempted from Windows Information Protection policy. If they are allowed, there is a risk of data loss. For example, if a device is workplace-joined and managed and the user leaves the company, metadata files that the apps rely on remain encrypted and the apps stop functioning. - -## List of WIP-work only apps from Microsoft -Microsoft still has apps that are unenlightened, but which have been tested and deemed safe for use in an enterprise with Windows Information Protection and MAM solutions. - -- Skype for Business - -- Microsoft Teams (build 1.3.00.12058 and later) - -## Adding enlightened Microsoft apps to the allowed apps list - -> [!NOTE] -> As of January 2019 it is no longer necessary to add Intune Company Portal as an exempt app since it is now included in the default list of protected apps. - -You can add any or all of the enlightened Microsoft apps to your allowed apps list. Included here is the **Publisher name**, **Product or File name**, and **App Type** info for both Microsoft Intune and Microsoft Configuration Manager. - - -| Product name | App info | -|------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| -| Microsoft 3D Viewer | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Microsoft3DViewer
    **App Type:** Universal app | -| Microsoft Edge | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.MicrosoftEdge
    **App Type:** Universal app | -| Microsoft People | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.People
    **App Type:** Universal app | -| Word Mobile | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Office.Word
    **App Type:** Universal app | -| Excel Mobile | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Office.Excel
    **App Type:** Universal app | -| PowerPoint Mobile | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Office.PowerPoint
    **App Type:** Universal app | -| OneNote | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Office.OneNote
    **App Type:** Universal app | -| Outlook Mail and Calendar | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** microsoft.windowscommunicationsapps
    **App Type:** Universal app | -| Microsoft 365 Apps for enterprise and Office 2019 Professional Plus | Microsoft 365 Apps for enterprise and Office 2019 Professional Plus apps are set up as a suite. You must use the [O365 ProPlus - Allow and Exempt AppLocker policy files (.zip files)](https://download.microsoft.com/download/7/0/D/70D72459-D72D-4673-B309-F480E3BEBCC9/O365%20ProPlus%20-%20WIP%20Enterprise%20AppLocker%20Policy%20Files.zip) to turn the suite on for Windows Information Protection.
    We don't recommend setting up Office by using individual paths or publisher rules. | -| Microsoft Photos | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Windows.Photos
    **App Type:** Universal app | -| Groove Music | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.ZuneMusic
    **App Type:** Universal app | -| Microsoft Movies & TV | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.ZuneVideo
    **App Type:** Universal app | -| Microsoft Messaging | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Messaging
    **App Type:** Universal app | -| IE11 | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** iexplore.exe
    **App Type:** Desktop app | -| OneDrive Sync Client | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** onedrive.exe
    **App Type:** Desktop app | -| OneDrive app | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Microsoftskydrive
    Product Version:Product version: 17.21.0.0 (and later)
    **App Type:** Universal app | -| Notepad | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** notepad.exe
    **App Type:** Desktop app | -| Microsoft Paint | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** mspaint.exe
    **App Type:** Desktop app | -| Microsoft Remote Desktop | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** mstsc.exe
    **App Type:** Desktop app | -| Microsoft MAPI Repair Tool | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Binary Name:** fixmapi.exe
    **App Type:** Desktop app | -| Microsoft To Do | **Publisher:** `O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
    **Product Name:** Microsoft.Todos
    **App Type:** Store app | - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip.md b/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip.md deleted file mode 100644 index f98f1a7125..0000000000 --- a/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: General guidance and best practices for Windows Information Protection (WIP) -description: Find resources about apps that can work with Windows Information Protection (WIP) to protect data. Enlightened apps can tell corporate and personal data apart. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 ---- - -# General guidance and best practices for Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - -This section includes info about the enlightened Microsoft apps, including how to add them to your allowed apps list in Microsoft Intune. It also includes some testing scenarios that we recommend running through with Windows Information Protection (WIP). - -## In this section - -|Topic |Description | -|------|------------| -|[Enlightened apps for use with Windows Information Protection (WIP)](enlightened-microsoft-apps-and-wip.md) |Learn the difference between enlightened and unenlightened apps, and then review the list of enlightened apps provided by Microsoft along with the text you will need to use to add them to your allowed apps list. | -|[Unenlightened and enlightened app behavior while using Windows Information Protection (WIP)](app-behavior-with-wip.md) |Learn the difference between enlightened and unenlightened app behaviors. | -|[Recommended Enterprise Cloud Resources and Neutral Resources network settings with Windows Information Protection (WIP)](recommended-network-definitions-for-wip.md) |Recommended additions for the Enterprise Cloud Resources and Neutral Resources network settings, when used with Windows Information Protection (WIP). | -|[Using Outlook on the web with Windows Information Protection (WIP)](using-owa-with-wip.md) |Options for using Outlook on the web with Windows Information Protection (WIP). | - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/how-to-disable-wip.md b/windows/security/information-protection/windows-information-protection/how-to-disable-wip.md deleted file mode 100644 index f30aaac954..0000000000 --- a/windows/security/information-protection/windows-information-protection/how-to-disable-wip.md +++ /dev/null @@ -1,124 +0,0 @@ ---- -title: How to disable Windows Information Protection (WIP) -description: How to disable Windows Information Protection (WIP) in Microsoft Intune or Microsoft Configuration Manager. -ms.date: 07/21/2022 -ms.topic: how-to -author: lizgt2000 -ms.author: lizlong -ms.reviewer: aaroncz -manager: aaroncz ---- - -# How to disable Windows Information Protection (WIP) - -[!INCLUDE [wip-deprecation](includes/wip-deprecation.md)] - - -_Applies to:_ - -- Windows 10 -- Windows 11 - -## Use Intune to disable WIP - -To disable Windows Information Protection (WIP) using Intune, you have the following options: - -### Option 1 - Unassign the WIP policy (preferred) - -When you unassign an existing policy, it removes the intent to deploy WIP from those devices. When that intent is removed, the device removes protection for files and the configuration for WIP. For more information, see [Assign user and device profiles in Microsoft Intune](/mem/intune/configuration/device-profile-assign). - -### Option 2 - Change current WIP policy to off - -If you're currently deploying a WIP policy for enrolled or unenrolled devices, you switch the WIP policy to Off. When devices check in after this change, the devices will proceed to unprotect files previously protected by WIP. - -1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). -1. Open Microsoft Intune and select **Apps** > **App protection policies**. -1. Select the existing policy to turn off, and then select the **Properties**. -1. Edit **Required settings**. - :::image type="content" alt-text="Intune App Protection policy properties, required settings, with WIP mode Off." source="images/intune-edit-app-protection-policy-mode-off.png"::: -1. Set **Windows Information Protection mode** to off. -1. After making this change, select **Review and Save**. -1. Select **Save**. - -> [!NOTE] -> **Another option is to create a disable policy that sets WIP to Off.** -> -> You can create a separate disable policy for WIP (both enrolled and unenrolled) and deploy that to a new group. You then can stage the transition to this disabled state. Move devices from the existing group to the new group. This process slowly migrates devices instead of all at once. - -### Revoke local encryption keys during the unenrollment process - -Determine whether to revoke a user's local encryption keys from a device when it's unenrolled from Windows Information Protection. If the encryption keys are revoked, a user no longer has access to encrypted corporate data. The options are: - -- Yes, or not configured. Revokes local encryption keys from a device during unenrollment. -- No (recommended). Stop local encryption keys from being revoked from a device during unenrollment. - -## Use Configuration Manager to disable WIP - -To disable Windows Information Protection (WIP) using Configuration Manager, create a new configuration item that turns off WIP. Configure that new object for your environment to match the existing policy, except for disabling WIP. Then deploy the new policy, and move devices into the new collection. - -> [!WARNING] -> Don't just delete your existing WIP policy. If you delete the old policy, Configuration Manager stops sending further WIP policy updates, but also leaves WIP enforced on the devices. To remove WIP from your managed devices, follow the steps in this section to create a new policy to turn off WIP. - -### Create a WIP policy - -To disable WIP for your organization, first create a configuration item. - -1. Open the Configuration Manager console, select the **Assets and Compliance** node, expand the **Overview** node, expand the **Compliance Settings** node, and then expand the **Configuration Items** node. - -2. Select the **Create Configuration Item** button. - The **Create Configuration Item Wizard** starts. - - ![Create Configuration Item wizard, define the configuration item and choose the configuration type.](images/wip-configmgr-generalscreen-off.png) - -3. On the **General Information screen**, type a name (required) and an optional description for your policy into the **Name** and **Description** boxes. - -4. In the **Specify the type of configuration item you want to create** area, select **Windows 10 or later** for devices managed with the Configuration Manager client, and then select **Next**. - -5. On the **Supported Platforms** screen, select the **Windows 10** box, and then select **Next**. - -6. On the **Device Settings** screen, select **Windows Information Protection**, and then select **Next**. - -The **Configure Windows Information Protection settings** page appears, where you'll configure your policy for your organization. The following sections provide details on the required settings on this page. - -> [!TIP] -> For more information on filling out the required fields, see [Create and deploy a Windows Information Protection (WIP) policy using Microsoft Configuration Manager](/windows/security/information-protection/windows-information-protection/create-wip-policy-using-configmgr). - -#### Turn off WIP - -Of the four options to specify the restriction mode, select **Off** to turn off Windows Information Protection. - -:::image type="content" alt-text="Create Configuration Item wizard, choose your WIP-protection level." source="images/wip-configmgr-disable-wip.png"::: - -#### Specify the corporate identity - -Paste the value of your corporate identity into the **Corporate identity** field. For example, `contoso.com` or `contoso.com|newcontoso.com`. - -![Create Configuration Item wizard, Add the primary Internet domain for your enterprise identity.](images/wip-configmgr-corp-identity.png) - -> [!IMPORTANT] -> This corporate identity value must match the string in the original policy. Copy and paste the string from your original policy that enables WIP. - -#### Specify the corporate network definition - -For the **Corporate network definition**, select **Add** to specify the necessary network locations. The **Add or edit corporate network definition** box appears. Add the required fields. - -> [!IMPORTANT] -> These corporate network definitions must match the original policy. Copy and paste the strings from your original policy that enables WIP. - -#### Specify the data recovery agent certificate - -In the required **Upload a Data Recovery Agent (DRA) certificate to allow recovery of encrypted data** box, select **Browse** to add a data recovery certificate for your policy. This certificate should be the same as the original policy that enables WIP. - -![Create Configuration Item wizard, Add a data recovery agent (DRA) certificate.](images/wip-configmgr-dra.png) - -### Deploy the WIP policy - -After you've created the new policy to turn off WIP, deploy it to your organization's devices. For more information about deployment options, see the following articles: - -- [Create a configuration baseline that includes the new configuration item](/mem/configmgr/compliance/deploy-use/create-configuration-baselines). - -- [Create a new collection](/mem/configmgr/core/clients/manage/collections/create-collections). - -- [Deploy the baseline to the collection](/mem/configmgr/compliance/deploy-use/deploy-configuration-baselines). - -- Move devices from the old collection to new collection. diff --git a/windows/security/information-protection/windows-information-protection/images/access-wip-learning-report.png b/windows/security/information-protection/windows-information-protection/images/access-wip-learning-report.png deleted file mode 100644 index 12d4f6eefd..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/access-wip-learning-report.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/add-a-mobile-app-policy.png b/windows/security/information-protection/windows-information-protection/images/add-a-mobile-app-policy.png deleted file mode 100644 index 31f979f9f1..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/add-a-mobile-app-policy.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/add-a-protected-store-app.png b/windows/security/information-protection/windows-information-protection/images/add-a-protected-store-app.png deleted file mode 100644 index 8522b463a7..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/add-a-protected-store-app.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/add-protected-apps.png b/windows/security/information-protection/windows-information-protection/images/add-protected-apps.png deleted file mode 100644 index c702a0acff..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/add-protected-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/add-protected-domains.png b/windows/security/information-protection/windows-information-protection/images/add-protected-domains.png deleted file mode 100644 index 848ff120a2..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/add-protected-domains.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/create-app-protection-policy.png b/windows/security/information-protection/windows-information-protection/images/create-app-protection-policy.png deleted file mode 100644 index 345093afc8..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/create-app-protection-policy.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/create-new-path-rule.png b/windows/security/information-protection/windows-information-protection/images/create-new-path-rule.png deleted file mode 100644 index b33322202c..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/create-new-path-rule.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/exempt-apps.png b/windows/security/information-protection/windows-information-protection/images/exempt-apps.png deleted file mode 100644 index 59b0ebd268..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/exempt-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/import-protected-apps.png b/windows/security/information-protection/windows-information-protection/images/import-protected-apps.png deleted file mode 100644 index eefe2c57d4..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/import-protected-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-applocker-before-begin.png b/windows/security/information-protection/windows-information-protection/images/intune-applocker-before-begin.png deleted file mode 100644 index 3f6a79c8d6..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-applocker-before-begin.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-applocker-permissions.png b/windows/security/information-protection/windows-information-protection/images/intune-applocker-permissions.png deleted file mode 100644 index 901c861793..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-applocker-permissions.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher-with-app.png b/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher-with-app.png deleted file mode 100644 index 29f08e03f0..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher-with-app.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher.png b/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher.png deleted file mode 100644 index 42da98610a..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-applocker-publisher.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-applocker-select-apps.png b/windows/security/information-protection/windows-information-protection/images/intune-applocker-select-apps.png deleted file mode 100644 index 38ba06d474..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-applocker-select-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-edit-app-protection-policy-mode-off.png b/windows/security/information-protection/windows-information-protection/images/intune-edit-app-protection-policy-mode-off.png deleted file mode 100644 index e5cb84a44e..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-edit-app-protection-policy-mode-off.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-local-security-export.png b/windows/security/information-protection/windows-information-protection/images/intune-local-security-export.png deleted file mode 100644 index 56b27c2387..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-local-security-export.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin-updated.png b/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin-updated.png deleted file mode 100644 index d794b8976c..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin-updated.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin.png b/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin.png deleted file mode 100644 index 492f3fc50a..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/intune-local-security-snapin.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/mobility-provider.png b/windows/security/information-protection/windows-information-protection/images/mobility-provider.png deleted file mode 100644 index 280a0531dc..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/mobility-provider.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/path-condition.png b/windows/security/information-protection/windows-information-protection/images/path-condition.png deleted file mode 100644 index 6aaf295bcc..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/path-condition.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/recommended-apps.png b/windows/security/information-protection/windows-information-protection/images/recommended-apps.png deleted file mode 100644 index 658cbb343b..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/recommended-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/robocopy-s-mode.png b/windows/security/information-protection/windows-information-protection/images/robocopy-s-mode.png deleted file mode 100644 index 141e7a1819..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/robocopy-s-mode.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/select-path.png b/windows/security/information-protection/windows-information-protection/images/select-path.png deleted file mode 100644 index 0fd5274d45..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/select-path.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-default-rule-warning.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-default-rule-warning.png deleted file mode 100644 index 50440a4fc8..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-default-rule-warning.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-1.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-1.png deleted file mode 100644 index 709ff73d25..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-1.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-create.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-create.png deleted file mode 100644 index 74497fd6ab..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-create.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-export.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-export.png deleted file mode 100644 index 1f5d20dffa..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-export.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-1.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-1.png deleted file mode 100644 index 0ced278421..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-1.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-2.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-2.png deleted file mode 100644 index e399d8aa66..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-2.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-3.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-3.png deleted file mode 100644 index 0ac48ca032..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-3.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-4.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-4.png deleted file mode 100644 index c924430a97..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-4.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-5.png b/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-5.png deleted file mode 100644 index 4b5e707aec..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-applocker-secpol-wizard-5.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-add-desktop-apps.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-add-desktop-apps.png deleted file mode 100644 index 1d1aff1a0c..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-add-desktop-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-add-user-groups.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-add-user-groups.png deleted file mode 100644 index 34c89b37a9..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-add-user-groups.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-efsdra.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-efsdra.png deleted file mode 100644 index 59e2071bd8..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-efsdra.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network-autodetect.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network-autodetect.png deleted file mode 100644 index 7fff387ab2..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network-autodetect.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network.png deleted file mode 100644 index 9fbe37d56d..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-network.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-optional.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-optional.png deleted file mode 100644 index 785925efdf..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-advanced-settings-optional.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-import-apps.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-import-apps.png deleted file mode 100644 index 01489c8059..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-import-apps.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-corp-identity.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-corp-identity.png deleted file mode 100644 index 752ea852ce..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-corp-identity.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-protection-mode.png b/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-protection-mode.png deleted file mode 100644 index 734f23b46c..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-azure-required-settings-protection-mode.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-add-network-domain.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-add-network-domain.png deleted file mode 100644 index 6f5e80d670..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-add-network-domain.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addapplockerfile.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addapplockerfile.png deleted file mode 100644 index 6cd571b404..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addapplockerfile.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adddesktopapp.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adddesktopapp.png deleted file mode 100644 index 5da4686e3f..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adddesktopapp.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-additionalsettings.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-additionalsettings.png deleted file mode 100644 index 89c1eae2a8..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-additionalsettings.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addpolicy.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addpolicy.png deleted file mode 100644 index 49613b5587..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-addpolicy.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adduniversalapp.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adduniversalapp.png deleted file mode 100644 index b2fc9ee966..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-adduniversalapp.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-appmgmt.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-appmgmt.png deleted file mode 100644 index 8af8967001..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-appmgmt.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-corp-identity.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-corp-identity.png deleted file mode 100644 index 940d60acf1..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-corp-identity.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-devicesettings.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-devicesettings.png deleted file mode 100644 index bee8ddfb1a..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-devicesettings.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-disable-wip.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-disable-wip.png deleted file mode 100644 index f1cf7c107d..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-disable-wip.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-dra.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-dra.png deleted file mode 100644 index cc58cdb34a..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-dra.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen-off.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen-off.png deleted file mode 100644 index ab05d9607a..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen-off.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen.png deleted file mode 100644 index 2d6cadb5c6..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-generalscreen.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-optsettings.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-optsettings.png deleted file mode 100644 index f3d12e7f2f..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-optsettings.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-summaryscreen.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-summaryscreen.png deleted file mode 100644 index 5cae0416bd..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-summaryscreen.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-supportedplat.png b/windows/security/information-protection/windows-information-protection/images/wip-configmgr-supportedplat.png deleted file mode 100644 index c09ff3cfc3..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-configmgr-supportedplat.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-encrypted-file-extensions.png b/windows/security/information-protection/windows-information-protection/images/wip-encrypted-file-extensions.png deleted file mode 100644 index 8ec000d2a7..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-encrypted-file-extensions.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-learning-app-info.png b/windows/security/information-protection/windows-information-protection/images/wip-learning-app-info.png deleted file mode 100644 index 09539d6773..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-learning-app-info.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-learning-choose-store-or-desktop-app.png b/windows/security/information-protection/windows-information-protection/images/wip-learning-choose-store-or-desktop-app.png deleted file mode 100644 index 2393cc7eca..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-learning-choose-store-or-desktop-app.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-learning-select-report.png b/windows/security/information-protection/windows-information-protection/images/wip-learning-select-report.png deleted file mode 100644 index 926a3c4473..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-learning-select-report.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-select-column.png b/windows/security/information-protection/windows-information-protection/images/wip-select-column.png deleted file mode 100644 index d4e8a9e7a0..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-select-column.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/images/wip-taskmgr.png b/windows/security/information-protection/windows-information-protection/images/wip-taskmgr.png deleted file mode 100644 index d69e829d65..0000000000 Binary files a/windows/security/information-protection/windows-information-protection/images/wip-taskmgr.png and /dev/null differ diff --git a/windows/security/information-protection/windows-information-protection/limitations-with-wip.md b/windows/security/information-protection/windows-information-protection/limitations-with-wip.md deleted file mode 100644 index 783f627a5c..0000000000 --- a/windows/security/information-protection/windows-information-protection/limitations-with-wip.md +++ /dev/null @@ -1,152 +0,0 @@ ---- -title: Limitations while using Windows Information Protection (WIP) -description: This section includes info about the common problems you might encounter while using Windows Information Protection (WIP). -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.reviewer: rafals -ms.topic: conceptual -ms.date: 04/05/2019 ---- - -# Limitations while using Windows Information Protection (WIP) - -_Applies to:_ - -- Windows 10 -- Windows 11 - -This following list provides info about the most common problems you might encounter while running Windows Information Protection in your organization. - -- **Limitation**: Your enterprise data on USB drives might be tied to the device it was protected on, based on your Azure RMS configuration. - - **How it appears**: - - If you're using Azure RMS: Authenticated users can open enterprise data on USB drives, on computers running Windows 10, version 1703. - - If you're not using Azure RMS: Data in the new location remains encrypted, but becomes inaccessible on other devices and for other users. For example, the file won't open or the file opens, but doesn't contain readable text. - - - **Workaround**: Share files with fellow employees through enterprise file servers or enterprise cloud locations. If data must be shared via USB, employees can decrypt protected files, but it will be audited. - - We strongly recommend educating employees about how to limit or eliminate the need for this decryption. - -- **Limitation**: Direct Access is incompatible with Windows Information Protection. - - **How it appears**: Direct Access might experience problems with how Windows Information Protection enforces app behavior and data movement because of how WIP determines what is and isn't a corporate network resource. - - **Workaround**: We recommend that you use VPN for client access to your intranet resources. - - > [!NOTE] - > VPN is optional and isn't required by Windows Information Protection. - -- **Limitation**: **NetworkIsolation** Group Policy setting takes precedence over MDM Policy settings. - - **How it appears**: The **NetworkIsolation** Group Policy setting can configure network settings that can also be configured by using MDM. WIP relies on these policies being correctly configured. - - **Workaround**: If you use both Group Policy and MDM to configure your **NetworkIsolation** settings, you must make sure that those same settings are deployed to your organization using both Group Policy and MDM. - -- **Limitation**: Cortana can potentially allow data leakage if it's on the allowed apps list. - - **How it appears**: If Cortana is on the allowed list, some files might become unexpectedly encrypted after an employee performs a search using Cortana. Your employees will still be able to use Cortana to search and provide results on enterprise documents and locations, but results might be sent to Microsoft. - - **Workaround**: We don't recommend adding Cortana to your allowed apps list. However, if you wish to use Cortana and don't mind whether the results potentially go to Microsoft, you can make Cortana an Exempt app. - - - -- **Limitation**: Windows Information Protection is designed for use by a single user per device. - - **How it appears**: A secondary user on a device might experience app compatibility issues when unenlightened apps start to automatically encrypt for all users. Additionally, only the initial, enrolled user's content can be revoked during the unenrollment process. - - **Workaround**: Have only one user per managed device. - - If this scenario occurs, it may be possible to mitigate. Once protection is disabled, a second user can remove protection by changing the file ownership. Although the protection is in place, the file remains accessible to the user. - -- **Limitation**: Installers copied from an enterprise network file share might not work properly. - - **How it appears**: An app might fail to properly install because it can't read a necessary configuration or data file, such as a .cab or .xml file needed for installation, which was protected by the copy action. - - **Workaround**: To fix this, you can: - - Start the installer directly from the file share. - - OR - - - Decrypt the locally copied files needed by the installer. - - OR - - - Mark the file share with the installation media as "personal". To do this, you'll need to set the Enterprise IP ranges as **Authoritative** and then exclude the IP address of the file server, or you'll need to put the file server on the Enterprise Proxy Server list. - -- **Limitation**: Changing your primary Corporate Identity isn't supported. - - **How it appears**: You might experience various instabilities, including but not limited to network and file access failures, and potentially granting incorrect access. - - **Workaround**: Turn off Windows Information Protection for all devices before changing the primary Corporate Identity (first entry in the list), restarting, and finally redeploying. - -- **Limitation**: Redirected folders with Client-Side Caching are not compatible with Windows Information Protection. - - **How it appears**: Apps might encounter access errors while attempting to read a cached, offline file. - - **Workaround**: Migrate to use another file synchronization method, such as Work Folders or OneDrive for Business. - - > [!NOTE] - > For more info about Work Folders and Offline Files, see the [Work Folders and Offline Files support for Windows Information Protection blog](https://blogs.technet.microsoft.com/filecab/2016/08/29/work-folders-and-offline-files-support-for-windows-information-protection/). If you're having trouble opening files offline while using Offline Files and Windows Information Protection, see [Can't open files offline when you use Offline Files and Windows Information Protection](/troubleshoot/windows-client/networking/error-open-files-offline-offline-files-wip). - -- **Limitation**: An unmanaged device can use Remote Desktop Protocol (RDP) to connect to a WIP-managed device. - - **How it appears**: - - Data copied from the WIP-managed device is marked as **Work**. - - Data copied to the WIP-managed device is not marked as **Work**. - - Local **Work** data copied to the WIP-managed device remains **Work** data. - - **Work** data that is copied between two apps in the same session remains ** data. - - - **Workaround**: Disable RDP to prevent access because there is no way to restrict access to only devices managed by Windows Information Protection. RDP is disabled by default. - -- **Limitation**: You can't upload an enterprise file to a personal location using Microsoft Edge or Internet Explorer. - - **How it appears**: A message appears stating that the content is marked as **Work** and the user isn't given an option to override to **Personal**. - - **Workaround**: Open File Explorer and change the file ownership to **Personal** before you upload. - -- **Limitation**: ActiveX controls should be used with caution. - - **How it appears**: Webpages that use ActiveX controls can potentially communicate with other outside processes that aren't protected by using Windows Information Protection. - - **Workaround**: We recommend that you switch to using Microsoft Edge, the more secure and safer browser that prevents the use of ActiveX controls. We also recommend that you limit the usage of Internet Explorer 11 to only those line-of-business apps that require legacy technology. - - For more info, see [Out-of-date ActiveX control blocking](/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking). - -- **Limitation**: Resilient File System (ReFS) isn't currently supported with Windows Information Protection. - - **How it appears**:Trying to save or transfer Windows Information Protection files to ReFS will fail. - - **Workaround**: Format drive for NTFS, or use a different drive. - -- **Limitation**: Windows Information Protection isn't turned on if any of the following folders have the **MakeFolderAvailableOfflineDisabled** option set to **False**: - - AppDataRoaming - - Desktop - - StartMenu - - Documents - - Pictures - - Music - - Videos - - Favorites - - Contacts - - Downloads - - Links - - Searches - - SavedGames - -
    - - - **How it appears**: Windows Information Protection isn't turned on for employees in your organization. Error code 0x807c0008 will result if Windows Information Protection is deployed by using Microsoft Configuration Manager. - - **Workaround**: Don't set the **MakeFolderAvailableOfflineDisabled** option to **False** for any of the specified folders. You can configure this parameter, as described [Disable Offline Files on individual redirected folders](/windows-server/storage/folder-redirection/disable-offline-files-on-folders). - - If you currently use redirected folders, we recommend that you migrate to a file synchronization solution that supports Windows Information Protection, such as Work Folders or OneDrive for Business. Additionally, if you apply redirected folders after Windows Information Protection is already in place, you might be unable to open your files offline. - - For more info about these potential access errors, see [Can't open files offline when you use Offline Files and Windows Information Protection](/troubleshoot/windows-client/networking/error-open-files-offline-offline-files-wip). - -- **Limitation**: Only enlightened apps can be managed without device enrollment - - **How it appears**: If a user enrolls a device for Mobile Application Management (MAM) without device enrollment, only enlightened apps will be managed. This is by design to prevent personal files from being unintentionally encrypted by unenlighted apps. - - Unenlighted apps that need to access work using MAM need to be re-compiled as LOB apps or managed by using MDM with device enrollment. - - - **Workaround**: If all apps need to be managed, enroll the device for MDM. - -- **Limitation**: By design, files in the Windows directory (%windir% or C:/Windows) cannot be encrypted because they need to be accessed by any user. If a file in the Windows directory gets encrypted by one user, other users can't access it. - - **How it appears**: Any attempt to encrypt a file in the Windows directory will return a file access denied error. But if you copy or drag and drop an encrypted file to the Windows directory, it will retain encryption to honor the intent of the owner. - - **Workaround**: If you need to save an encrypted file in the Windows directory, create and encrypt the file in a different directory and copy it. - -- **Limitation**: OneNote notebooks on OneDrive for Business must be properly configured to work with Windows Information Protection. - - **How it appears**: OneNote might encounter errors syncing a OneDrive for Business notebook and suggest changing the file ownership to Personal. Attempting to view the notebook in OneNote Online in the browser will show an error and unable to view it. - - **Workaround**: OneNote notebooks that are newly copied into the OneDrive for Business folder from File Explorer should get fixed automatically. To do this, follow these steps: - - 1. Close the notebook in OneNote. - 2. Move the notebook folder via File Explorer out of the OneDrive for Business folder to another location, such as the Desktop. - 3. Copy the notebook folder and Paste it back into the OneDrive for Business folder. - - Wait a few minutes to allow OneDrive to finish syncing & upgrading the notebook, and the folder should automatically convert to an Internet Shortcut. Opening the shortcut will open the notebook in the browser, which can then be opened in the OneNote client by using the "Open in app" button. - -- **Limitation**: Microsoft Office Outlook offline data files (PST and OST files) are not marked as **Work** files, and are therefore not protected. - - **How it appears**: If Microsoft Office Outlook is set to work in cached mode (default setting), or if some emails are stored in a local PST file, the data is unprotected. - - **Workaround**: It is recommended to use Microsoft Office Outlook in Online mode, or to use encryption to protect OST and PST files manually. - -> [!NOTE] -> -> - When corporate data is written to disk, Windows Information Protection uses the Windows-provided Encrypting File System (EFS) to protect it and associate it with your enterprise identity. One caveat to keep in mind is that the Preview Pane in File Explorer will not work for encrypted files. -> -> - Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Contributing to our content](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/mandatory-settings-for-wip.md b/windows/security/information-protection/windows-information-protection/mandatory-settings-for-wip.md deleted file mode 100644 index c849026e4b..0000000000 --- a/windows/security/information-protection/windows-information-protection/mandatory-settings-for-wip.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: Mandatory tasks and settings required to turn on Windows Information Protection (WIP) -description: Review all of the tasks required for Windows to turn on Windows Information Protection (WIP), formerly enterprise data protection (EDP), in your enterprise. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 05/25/2022 ---- - -# Mandatory tasks and settings required to turn on Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - -This list provides all of the tasks and settings that are required for the operating system to turn on Windows Information Protection (WIP), formerly known as enterprise data protection (EDP), in your enterprise. - -|Task|Description| -|----|-----------| -|Add at least one app of each type (Store and Desktop) to the **Protected apps** list in your WIP policy.|You must have at least one Store app and one Desktop app added to your **Protected apps** list. For more info about where this area is and how to add apps, see the **Add apps to your Protected apps list** section of the policy creation topics. | -|Choose your Windows Information Protection protection level.|You must choose the level of protection you want to apply to your WIP-protected content, including **Allow Overrides**, **Silent**, or **Block**. For more info about where this area is and how to decide on your protection level, see the [Manage Windows Information Protection mode for your enterprise data](create-wip-policy-using-configmgr.md#manage-the-wip-protection-level-for-your-enterprise-data) section of the policy creation topics. For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md).| -|Specify your corporate identity.|This field is automatically filled out for you by Microsoft Intune. However, you must manually correct it if it's incorrect or if you need to add additional domains. For more info about where this area is and what it means, see the **Define your enterprise-managed corporate identity** section of the policy creation topics. -|Specify your network domain names.|Starting with Windows 10, version 1703, this field is optional.

    Specify the DNS suffixes used in your environment. All traffic to the fully qualified domains appearing in this list will be protected. For more info about where this area is and how to add your suffixes, see the table that appears in the **Choose where apps can access enterprise data** section of the policy creation topics.| -|Specify your enterprise IPv4 or IPv6 ranges.|Starting with Windows 10, version 1703, this field is optional.

    Specify the addresses for a valid IPv4 or IPv6 value range within your intranet. These addresses, used with your Network domain names, define your corporate network boundaries. For more info about where this area is and what it means, see the table that appears in the **Define your enterprise-managed corporate identity** section of the policy creation topics.| -|Include your Data Recovery Agent (DRA) certificate.|Starting with Windows 10, version 1703, this field is optional. But we strongly recommend that you add a certificate.

    This certificate makes sure that any of your WIP-encrypted data can be decrypted, even if the security keys are lost. For more info about where this area is and what it means, see the [Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](create-and-verify-an-efs-dra-certificate.md) topic.| - - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr.md b/windows/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr.md deleted file mode 100644 index 25099e224a..0000000000 --- a/windows/security/information-protection/windows-information-protection/overview-create-wip-policy-configmgr.md +++ /dev/null @@ -1,24 +0,0 @@ ---- -title: Create a Windows Information Protection (WIP) policy using Microsoft Configuration Manager -description: Microsoft Configuration Manager helps you create and deploy your enterprise data protection (WIP) policy, including letting you choose your protected apps, your WIP-protection level, and how to find enterprise data on the network. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 ---- - -# Create a Windows Information Protection (WIP) policy using Microsoft Configuration Manager -**Applies to:** - -- Windows 10, version 1607 and later - -Microsoft Configuration Manager helps you create and deploy your enterprise data protection (WIP) policy. It lets you choose your protected apps, your WIP-protection level, and how to find enterprise data on the network. - -## In this section - -|Article |Description | -|------|------------| -|[Create and deploy a Windows Information Protection (WIP) policy using Microsoft Configuration Manager](create-wip-policy-using-configmgr.md) |Microsoft Configuration Manager helps you create and deploy your WIP policy. And, lets you choose your protected apps, your WIP-protection level, and how to find enterprise data on the network. | -|[Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](create-and-verify-an-efs-dra-certificate.md) |Steps to create, verify, and perform a quick recovery using an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate. | -|[Determine the Enterprise Context of an app running in Windows Information Protection (WIP)](wip-app-enterprise-context.md) |Use the Task Manager to determine whether an app is considered work, personal or exempt by Windows Information Protection (WIP). | diff --git a/windows/security/information-protection/windows-information-protection/overview-create-wip-policy.md b/windows/security/information-protection/windows-information-protection/overview-create-wip-policy.md deleted file mode 100644 index 794a46361f..0000000000 --- a/windows/security/information-protection/windows-information-protection/overview-create-wip-policy.md +++ /dev/null @@ -1,24 +0,0 @@ ---- -title: Create a Windows Information Protection (WIP) policy using Microsoft Intune -description: Microsoft Intune helps you create and deploy your enterprise data protection (WIP) policy. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 03/11/2019 ---- - -# Create a Windows Information Protection (WIP) policy using Microsoft Intune -**Applies to:** - -- Windows 10, version 1607 and later - -Microsoft Intune helps you create and deploy your enterprise data protection (WIP) policy. It also lets you choose your protected apps, your WIP-protection level, and how to find enterprise data on the network. - -## In this section - -|Article |Description | -|------|------------| -|[Create a Windows Information Protection (WIP) policy using the Azure portal for Microsoft Intune](create-wip-policy-using-intune-azure.md)|Details about how to use Microsoft Intune to create and deploy your WIP policy with MDM (Mobile Device Management), including letting you choose your protected apps, your WIP-protection level, and how to find enterprise data on the network. | -|[Create and verify an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate](create-and-verify-an-efs-dra-certificate.md) |Steps to create, verify, and perform a quick recovery using an Encrypting File System (EFS) Data Recovery Agent (DRA) certificate. | -|[Determine the Enterprise Context of an app running in Windows Information Protection (WIP)](wip-app-enterprise-context.md) |Use the Task Manager to determine whether an app is considered work, personal or exempt by Windows Information Protection (WIP). | diff --git a/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip.md b/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip.md deleted file mode 100644 index 4135a203b8..0000000000 --- a/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip.md +++ /dev/null @@ -1,151 +0,0 @@ ---- -title: Protect your enterprise data using Windows Information Protection -description: Learn how to prevent accidental enterprise data leaks through apps and services, such as email, social media, and the public cloud. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.reviewer: rafals -ms.topic: overview -ms.date: 07/15/2022 ---- - -# Protect your enterprise data using Windows Information Protection (WIP) - -[!INCLUDE [Deprecate Windows Information Protection](includes/wip-deprecation.md)] - - -_Applies to:_ - -- Windows 10 -- Windows 11 - -With the increase of employee-owned devices in the enterprise, there's also an increasing risk of accidental data leak through apps and services, like email, social media, and the public cloud, which are outside of the enterprise's control. For example, when an employee sends the latest engineering pictures from their personal email account, copies and pastes product info into a tweet, or saves an in-progress sales report to their public cloud storage. - -Windows Information Protection (WIP), previously known as enterprise data protection (EDP), helps to protect against this potential data leakage without otherwise interfering with the employee experience. WIP also helps to protect enterprise apps and data against accidental data leak on enterprise-owned devices and personal devices that employees bring to work without requiring changes to your environment or other apps. Azure Rights Management, another data protection technology, also works alongside WIP. It extend data protection for data that leaves the device, such as when email attachments are sent from an enterprise aware version of a rights management mail client. - ->[!IMPORTANT] ->While Windows Information Protection can stop accidental data leaks from honest employees, it is not intended to stop malicious insiders from removing enterprise data. For more information about the benefits WIP provides, see [Why use WIP?](#why-use-wip) later in this topic. - -## Video: Protect enterprise data from being accidentally copied to the wrong place - -> [!Video https://www.microsoft.com/videoplayer/embed/RE2IGhh] - -## Prerequisites -You'll need this software to run Windows Information Protection in your enterprise: - -|Operating system | Management solution | -|-----------------|---------------------| -|Windows 10, version 1607 or later | Microsoft Intune

    -OR-

    Microsoft Configuration Manager

    -OR-

    Your current company-wide third party mobile device management (MDM) solution. For info about third party MDM solutions, see the documentation that came with your product. If your third party MDM doesn't have UI support for the policies, refer to the [EnterpriseDataProtection CSP](/windows/client-management/mdm/enterprisedataprotection-csp) documentation.| - -## What is enterprise data control? -Effective collaboration means that you need to share data with others in your enterprise. This sharing can be from one extreme where everyone has access to everything without any security. Another extreme is when people can't share anything and it's all highly secured. Most enterprises fall somewhere in between the two extremes, where success is balanced between providing the necessary access with the potential for improper data disclosure. - -As an admin, you can address the question of who gets access to your data by using access controls, such as employee credentials. However, just because someone has the right to access your data doesn't guarantee that the data will remain within the secured locations of the enterprise. So, access controls are a great start, they're not enough. - -In the end, all of these security measures have one thing in common: employees will tolerate only so much inconvenience before looking for ways around the security restrictions. For example, if you don't allow employees to share files through a protected system, employees will turn to an outside app that more than likely lacks security controls. - -### Using data loss prevention systems -To help address this security insufficiency, companies developed data loss prevention (also known as DLP) systems. Data loss prevention systems require: -- **A set of rules about how the system can identify and categorize the data that needs to be protected.** For example, a rule set might contain a rule that identifies credit card numbers and another rule that identifies Social Security numbers. - -- **A way to scan company data to see whether it matches any of your defined rules.** Currently, Microsoft Exchange Server and Exchange Online provide this service for email in transit, while Microsoft SharePoint and SharePoint Online provide this service for content stored in document libraries. - -- **The ability to specify what happens when data matches a rule, including whether employees can bypass enforcement.** For example, in Microsoft SharePoint and SharePoint Online, the Microsoft Purview Data Loss Prevention system lets you warn your employees that shared data includes sensitive info, and to share it anyway (with an optional audit log entry). - -Unfortunately, data loss prevention systems have their own problems. For example, the less detailed the rule set, the more false positives are created. This behavior can lead employees to believe that the rules slow down their work and need to be bypassed in order to remain productive, potentially leading to data being incorrectly blocked or improperly released. Another major problem is that data loss prevention systems must be widely implemented to be effective. For example, if your company uses a data loss prevention system for email, but not for file shares or document storage, you might find that your data leaks through the unprotected channels. Perhaps the biggest problem with data loss prevention systems is that it provides a jarring experience that interrupts the employees' natural workflow. It can stop some operations (such as sending a message with an attachment that the system tags as sensitive) while allowing others, often according to subtle rules that the employee doesn't see and can't understand. - -### Using information rights management systems -To help address the potential data loss prevention system problems, companies developed information rights management (also known as IRM) systems. Information rights management systems embed protection directly into documents, so that when an employee creates a document, he or she determines what kind of protection to apply. For example, an employee can choose to stop the document from being forwarded, printed, shared outside of the organization, and so on. - -After the type of protection is set, the creating app encrypts the document so that only authorized people can open it, and even then, only in compatible apps. After an employee opens the document, the app becomes responsible for enforcing the specified protections. Because protection travels with the document, if an authorized person sends it to an unauthorized person, the unauthorized person won't be able to read or change it. However, for this to work effectively information rights management systems require you to deploy and set up both a server and client environment. And, because only compatible clients can work with protected documents, an employees' work might be unexpectedly interrupted if he or she attempts to use a non-compatible app. - -### And what about when an employee leaves the company or unenrolls a device? -Finally, there's the risk of data leaking from your company when an employee leaves or unenrolls a device. Previously, you would erase all of the corporate data from the device, along with any other personal data on the device. - -## Benefits of WIP -Windows Information Protection provides: -- Obvious separation between personal and corporate data, without requiring employees to switch environments or apps. - -- Additional data protection for existing line-of-business apps without a need to update the apps. - -- Ability to wipe corporate data from Intune MDM enrolled devices while leaving personal data alone. - -- Use of audit reports for tracking issues and remedial actions. - -- Integration with your existing management system (Microsoft Intune, Microsoft Configuration Manager, or your current mobile device management (MDM) system) to configure, deploy, and manage Windows Information Protection for your company. - -## Why use WIP? -Windows Information Protection is the mobile application management (MAM) mechanism on Windows 10. WIP gives you a new way to manage data policy enforcement for apps and documents on Windows 10 desktop operating systems, along with the ability to remove access to enterprise data from both enterprise and personal devices (after enrollment in an enterprise management solution, like Intune). - -- **Change the way you think about data policy enforcement.** As an enterprise admin, you need to maintain compliance in your data policy and data access. Windows Information Protection helps protect enterprise on both corporate and employee-owned devices, even when the employee isn't using the device. When employees create content on an enterprise-protected device, they can choose to save it as a work document. If it's a work document, it becomes locally maintained as enterprise data. - -- **Manage your enterprise documents, apps, and encryption modes.** - - - **Copying or downloading enterprise data.** When an employee or an app downloads content from a location like SharePoint, a network share, or an enterprise web location, while using a WIP-protected device, WIP encrypts the data on the device. - - - **Using protected apps.** Managed apps (apps that you've included on the **Protected apps** list in your WIP policy) are allowed to access your enterprise data and will interact differently when used with unallowed, non-enterprise aware, or personal-only apps. For example, if WIP management is set to **Block**, your employees can copy and paste from one protected app to another protected app, but not to personal apps. Imagine an HR person wants to copy a job description from a protected app to the internal career website, an enterprise-protected location, but makes a mistake and tries to paste into a personal app instead. The paste action fails and a notification pops up, saying that the app couldn't paste because of a policy restriction. The HR person then correctly pastes to the career website without a problem. - - - **Managed apps and restrictions.** With WIP you can control which apps can access and use your enterprise data. After adding an app to your protected apps list, the app is trusted with enterprise data. All apps not on this list are stopped from accessing your enterprise data, depending on your WIP management-mode. - - You don't have to modify line-of-business apps that never touch personal data to list them as protected apps; just include them in the protected apps list. - - - **Deciding your level of data access.** WIP lets you block, allow overrides, or audit employees' data sharing actions. Hiding overrides stops the action immediately. Allowing overrides lets the employee know there's a risk, but lets him or her continue to share the data while recording and auditing the action. Silent just logs the action without stopping anything that the employee could have overridden while using that setting; collecting info that can help you to see patterns of inappropriate sharing so you can take educative action or find apps that should be added to your protected apps list. For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md). - - - - **Data encryption at rest.** Windows Information Protection helps protect enterprise data on local files and on removable media. - - Apps such as Microsoft Word work with WIP to help continue your data protection across local files and removable media. These apps are being referred to as, enterprise aware. For example, if an employee opens WIP-encrypted content from Word, edits the content, and then tries to save the edited version with a different name, Word automatically applies Windows Information Protection to the new document. - - - **Helping prevent accidental data disclosure to public spaces.** Windows Information Protection helps protect your enterprise data from being accidentally shared to public spaces, such as public cloud storage. For example, if Dropbox™ isn't on your protected apps list, employees won't be able to sync encrypted files to their personal cloud storage. Instead, if the employee stores the content to an app on your protected apps list, like Microsoft OneDrive for Business, the encrypted files can sync freely to the business cloud, while maintaining the encryption locally. - - - **Helping prevent accidental data disclosure to removable media.** Windows Information Protection helps prevent enterprise data from leaking when it's copied or transferred to removable media. For example, if an employee puts enterprise data on a Universal Serial Bus (USB) drive that also has personal data, the enterprise data remains encrypted while the personal data doesn't. - -- **Remove access to enterprise data from enterprise-protected devices.** Windows Information Protection gives admins the ability to revoke enterprise data from one or many MDM-enrolled devices, while leaving personal data alone. This is a benefit when an employee leaves your company, or if a device is stolen. After determining that the data access needs to be removed, you can use Microsoft Intune to unenroll the device so when it connects to the network, the user's encryption key for the device is revoked and the enterprise data becomes unreadable. - - >[!NOTE] - >For management of Surface devices it is recommended that you use the Current Branch of Microsoft Configuration Manager.
    Configuration Manager also allows you to revoke enterprise data. However, it does it by performing a factory reset of the device. - -## How WIP works -Windows Information Protection helps address your everyday challenges in the enterprise. Including: - -- Helping to prevent enterprise data leaks, even on employee-owned devices that can't be locked down. - -- Reducing employee frustrations because of restrictive data management policies on enterprise-owned devices. - -- Helping to maintain the ownership and control of your enterprise data. - -- Helping control the network and data access and data sharing for apps that aren't enterprise aware - -### Enterprise scenarios -Windows Information Protection currently addresses these enterprise scenarios: -- You can encrypt enterprise data on employee-owned and corporate-owned devices. - -- You can remotely wipe enterprise data off managed computers, including employee-owned computers, without affecting the personal data. - -- You can protect specific apps that can access enterprise data that are clearly recognizable to employees. You can also stop non-protected apps from accessing enterprise data. - -- Your employees won't have their work otherwise interrupted while switching between personal and enterprise apps while the enterprise policies are in place. Switching environments or signing in multiple times isn't required. - -### WIP-protection modes -Enterprise data is automatically encrypted after it's loaded on a device from an enterprise source or if an employee marks the data as corporate. Then, when the enterprise data is written to disk, Windows Information Protection uses the Windows-provided Encrypting File System (EFS) to protect it and associate it with your enterprise identity. - -Your Windows Information Protection policy includes a list of trusted apps that are protected to access and process corporate data. This list of apps is implemented through the [AppLocker](/windows/device-security/applocker/applocker-overview) functionality, controlling what apps are allowed to run and letting the Windows operating system know that the apps can edit corporate data. Apps included on this list don't have to be modified to open corporate data because their presence on the list allows Windows to determine whether to grant them access. However, new for Windows 10, app developers can use a new set of application programming interfaces (APIs) to create *enlightened* apps that can use and edit both enterprise and personal data. A huge benefit to working with enlightened apps is that dual-use apps, like Microsoft Word, can be used with less concern about encrypting personal data by mistake because the APIs allow the app to determine whether data is owned by the enterprise or if it's personally owned. - ->[!NOTE] ->For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md). - -You can set your Windows Information Protection policy to use 1 of 4 protection and management modes: - -|Mode|Description| -|----|-----------| -|Block |Windows Information Protection looks for inappropriate data sharing practices and stops the employee from completing the action. This can include sharing enterprise data to non-enterprise-protected apps in addition to sharing enterprise data between apps or attempting to share outside of your organization's network.| -|Allow overrides |Windows Information Protection looks for inappropriate data sharing, warning employees if they do something deemed potentially unsafe. However, this management mode lets the employee override the policy and share the data, logging the action to your audit log.| -|Silent |Windows Information Protection runs silently, logging inappropriate data sharing, without stopping anything that would have been prompted for employee interaction while in Allow overrides mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped.| -|Off |Windows Information Protection is turned off and doesn't help to protect or audit your data.

    After you turn off WIP, an attempt is made to decrypt any WIP-tagged files on the locally attached drives. Your previous decryption and policy info isn't automatically reapplied if you turn Windows Information Protection back on. | - -## Turn off WIP -You can turn off all Windows Information Protection and restrictions, decrypting all devices managed by WIP and reverting to where you were pre-WIP, with no data loss. However, this isn't recommended. If you choose to turn off WIP, you can always turn it back on, but your decryption and policy info won't be automatically reapplied. - -## Next steps - -After you decide to use WIP in your environment, [create a Windows Information Protection (WIP) policy](overview-create-wip-policy.md). diff --git a/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md b/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md deleted file mode 100644 index fc9dfc237c..0000000000 --- a/windows/security/information-protection/windows-information-protection/recommended-network-definitions-for-wip.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: Recommended URLs for Windows Information Protection -description: Recommended URLs to add to your Enterprise Cloud Resources and Neutral Resources network settings, when used with Windows Information Protection (WIP). -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 03/25/2019 ---- - -# Recommended Enterprise Cloud Resources and Neutral Resources network settings with Windows Information Protection (WIP) - -**Applies to:** - -- Windows 10, version 1607 and later - ->Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare). - -We recommend that you add the following URLs to the Enterprise Cloud Resources and Neutral Resources network settings when you create a Windows Information Protection policy. If you are using Intune, the SharePoint entries may be added automatically. - -## Recommended Enterprise Cloud Resources - -This table includes the recommended URLs to add to your Enterprise Cloud Resources network setting, based on the apps you use in your organization. - -|If your organization uses... |Add these entries to your Enterprise Cloud Resources network setting
    (Replace "contoso" with your domain name(s)| -|-----------------------------|---------------------------------------------------------------------| -|Sharepoint Online |- `contoso.sharepoint.com`
    - `contoso-my.sharepoint.com`
    - `contoso-files.sharepoint.com` | -|Viva Engage |- `www.yammer.com`
    - `yammer.com`
    - `persona.yammer.com` | -|Outlook Web Access (OWA) |- `outlook.office.com`
    - `outlook.office365.com`
    - `attachments.office.net` | -|Microsoft Dynamics |`contoso.crm.dynamics.com` | -|Visual Studio Online |`contoso.visualstudio.com` | -|Power BI |`contoso.powerbi.com` | -|Microsoft Teams |`teams.microsoft.com` | -|Other Office 365 services |- `tasks.office.com`
    - `protection.office.com`
    - `meet.lync.com`
    - `project.microsoft.com` | - -You can add other work-only apps to the Cloud Resource list, or you can create a packaged app rule for the .exe file to protect every file the app creates or modifies. Depending on how the app is accessed, you might want to add both. - -For Office 365 endpoints, see [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges). -Office 365 endpoints are updated monthly. -Allow the domains listed in section number 46 "Allow Required" and add also add the apps. -Note that apps from officeapps.live.com can also store personal data. - -When multiple files are selected from SharePoint Online or OneDrive, the files are aggregated and the URL can change. In this case, add an entry for a second-level domain and use a wildcard such as .svc.ms. - - -## Recommended Neutral Resources -We recommended adding these URLs if you use the Neutral Resources network setting with Windows Information Protection (WIP). - -- `login.microsoftonline.com` -- `login.windows.net` diff --git a/windows/security/information-protection/windows-information-protection/testing-scenarios-for-wip.md b/windows/security/information-protection/windows-information-protection/testing-scenarios-for-wip.md deleted file mode 100644 index 30c94d76be..0000000000 --- a/windows/security/information-protection/windows-information-protection/testing-scenarios-for-wip.md +++ /dev/null @@ -1,149 +0,0 @@ ---- -title: Testing scenarios for Windows Information Protection (WIP) -description: A list of suggested testing scenarios that you can use to test Windows Information Protection (WIP) in your company. -ms.reviewer: -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 03/05/2019 ---- - -# Testing scenarios for Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - -We've come up with a list of suggested testing scenarios that you can use to test Windows Information Protection (WIP) in your company. - -## Testing scenarios -You can try any of the processes included in these scenarios, but you should focus on the ones that you might encounter in your organization. - ->[!IMPORTANT] ->If any of these scenarios does not work, first take note of whether WIP has been revoked. If it has, unenlightened apps will have to be uninstalled and re-installed since their settings files will remain encrypted. - -- **Encrypt and decrypt files using File Explorer**: - - 1. Open File Explorer, right-click a work document, and then click **Work** from the **File Ownership** menu. - - Make sure the file is encrypted by right-clicking the file again, clicking **Advanced** from the **General** tab, and then clicking **Details** from the **Compress or Encrypt attributes** area. The file should show up under the heading, **This enterprise domain can remove or revoke access:** `**`. For example, `contoso.com`. - - 2. In File Explorer, right-click the same document, and then click **Personal** from the **File Ownership** menu. - - Make sure the file is decrypted by right-clicking the file again, clicking **Advanced** from the **General** tab, and then verifying that the **Details** button is unavailable. - -- **Create work documents in enterprise-allowed apps**: Start an unenlightened but allowed app, such as a line-of-business app, and then create a new document, saving your changes. - - Make sure the document is encrypted to your Enterprise Identity. This might take a few minutes and require you to close and re-open the file. - - > [!IMPORTANT] - > Certain file types like `.exe` and `.dll`, along with certain file paths, such as `%windir%` and `%programfiles%` are excluded from automatic encryption. - - For more info about your Enterprise Identity and adding apps to your allowed apps list, see either [Create a Windows Information Protection (WIP) policy using Microsoft Intune](create-wip-policy-using-intune-azure.md) or [Create a Windows Information Protection (WIP) policy using Microsoft Configuration Manager](create-wip-policy-using-configmgr.md), based on your deployment system. - -- **Block enterprise data from non-enterprise apps**: - - 1. Start an app that doesn't appear on your allowed apps list, and then try to open a work-encrypted file. - - The app shouldn't be able to access the file. - - 2. Try double-clicking or tapping on the work-encrypted file. If your default app association is an app not on your allowed apps list, you should get an **Access Denied** error message. - -- **Copy and paste from enterprise apps to non-enterprise apps**: - - 1. Copy (CTRL+C) content from an app on your allowed apps list, and then try to paste (CTRL+V) the content into an app that doesn't appear on your allowed apps list. - - You should see a WIP-related warning box, asking you to click either **Change to personal** or **Keep at work**. - - 2. Click **Keep at work**. The content isn't pasted into the non-enterprise app. - 3. Repeat Step 1, but this time select **Change to personal** and try to paste the content again. - - The content is pasted into the non-enterprise app. - - 4. Try copying and pasting content between apps on your allowed apps list. The content should copy and paste between apps without any warning messages. - -- **Drag and drop from enterprise apps to non-enterprise apps**: - - 1. Drag content from an app on your allowed apps list, and then try to drop the content into an app that doesn't appear on your allowed apps list. - - You should see a WIP-related warning box, asking you to click either **Keep at work** or **Change to personal**. - - 2. Click **Keep at work**. The content isn't dropped into the non-enterprise app. - 3. Repeat Step 1, but this time select **Change to personal** and try to drop the content again. - - The content is dropped into the non-enterprise app. - - 4. Try dragging and dropping content between apps on your allowed apps list. The content should move between the apps without any warning messages. - -- **Share between enterprise apps and non-enterprise apps**: - - 1. Open an app on your allowed apps list, like Microsoft Photos, and try to share content with an app that doesn't appear on your allowed apps list, like Facebook. - - You should see a WIP-related warning box, asking you to click either **Keep at work** or **Change to personal**. - - 2. Click **Keep at work**. The content isn't shared into Facebook. - 3. Repeat Step 1, but this time select **Change to personal** and try to share the content again. - - The content is shared into Facebook. - - 4. Try sharing content between apps on your allowed apps list. The content should share between the apps without any warning messages. - -- **Verify that Windows system components can use WIP**: - - 1. Start Windows Journal and Internet Explorer 11, creating, editing, and saving files in both apps. - - Make sure that all of the files you worked with are encrypted to your configured Enterprise Identity. In some cases, you might need to close the file and wait a few moments for it to be automatically encrypted. - - 2. Open File Explorer and make sure your modified files are appearing with a **Lock** icon. - 3. Try copying and pasting, dragging and dropping, and sharing using these apps with other apps that appear both on and off the allowed apps list. - - > [!NOTE] - > Most Windows-signed components like File Explorer (when running in the user's context), should have access to enterprise data. - > - > A few notable exceptions include some of the user-facing in-box apps, like Wordpad, Notepad, and Microsoft Paint. These apps don't have access by default, but can be added to your allowed apps list. - -- **Use WIP on NTFS, FAT, and exFAT systems**: - - 1. Start an app that uses the FAT or exFAT file system (for example an SD card or USB flash drive), and appears on your allowed apps list. - 2. Create, edit, write, save, copy, and move files. Basic file and folder operations like copy, move, rename, delete, and so on, should work properly on encrypted files. - -- **Verify your shared files can use WIP**: - - 1. Download a file from a protected file share, making sure the file is encrypted by locating the **Briefcase** icon next to the file name. - 2. Open the same file, make a change, save it and then try to upload it back to the file share. Again, this should work without any warnings. - 3. Open an app that doesn't appear on your allowed apps list and attempt to access a file on the WIP-enabled file share. - - The app shouldn't be able to access the file share. - -- **Verify your cloud resources can use WIP**: - - 1. Add both Internet Explorer 11 and Microsoft Edge to your allowed apps list. - 2. Open SharePoint (or another cloud resource that's part of your policy) and access a WIP-enabled resource by using both IE11 and Microsoft Edge. - - Both browsers should respect the enterprise and personal boundary. - - 3. Remove Internet Explorer 11 from your allowed app list and then try to access an intranet site or enterprise-related cloud resource. - - IE11 shouldn't be able to access the sites. - - > [!NOTE] - > Any file downloaded from your work SharePoint site, or any other WIP-enabled cloud resource, is automatically marked as **Work**. - -- **Verify your Virtual Private Network (VPN) can be auto-triggered**: - - 1. Set up your VPN network to start based on the **WIPModeID** setting. For specific info, see [Create and deploy a VPN policy for Windows Information Protection (WIP) using Microsoft Intune](create-vpn-and-wip-policy-using-intune-azure.md). - 2. Start an app from your allowed apps list. The VPN network should automatically start. - 3. Disconnect from your network and then start an app that isn't on your allowed apps list. - - The VPN shouldn't start and the app shouldn't be able to access your enterprise network. - -- **Unenroll client devices from WIP**: Unenroll a device from WIP by going to **Settings**, click **Accounts**, click **Work**, click the name of the device you want to unenroll, and then click **Remove**. - - The device should be removed and all of the enterprise content for that managed account should be gone. - - > [!IMPORTANT] - > On client devices, the data isn't removed and can be recovered. So, you must make sure the content is marked as **Revoked** and that access is denied for the employee. - - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/information-protection/windows-information-protection/using-owa-with-wip.md b/windows/security/information-protection/windows-information-protection/using-owa-with-wip.md deleted file mode 100644 index 43f6497a22..0000000000 --- a/windows/security/information-protection/windows-information-protection/using-owa-with-wip.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: Using Outlook on the web with WIP -description: Options for using Outlook on the web with Windows Information Protection (WIP). -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 ---- - -# Using Outlook on the web with Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - ->Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare). - -Because Outlook on the web can be used both personally and as part of your organization, you have the following options to configure it with Windows Information Protection (WIP): - -|Option |Outlook on the web behavior | -|-------|-------------| -|Disable Outlook on the web. Employees can only use Microsoft Outlook 2016 or the Mail for Windows 10 app. | Disabled. | -|Don't configure outlook.office.com in any of your networking settings. |All mailboxes are automatically marked as personal. This means employees attempting to copy work content into Outlook on the web receive prompts and that files downloaded from Outlook on the web aren't automatically protected as corporate data. | -|Add outlook.office.com and outlook.office365.com to the Cloud resources network element in your WIP policy. |All mailboxes are automatically marked as corporate. This means any personal inboxes hosted on Office 365 are also automatically marked as corporate data. | - ->[!NOTE] ->These limitations don't apply to Outlook 2016, the Mail for Windows 10 app, or the Calendar for Windows 10 app. These apps will work properly, marking an employee's mailbox as corporate data, regardless of how you've configured outlook.office.com in your network settings. diff --git a/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context.md b/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context.md deleted file mode 100644 index 02730fbed2..0000000000 --- a/windows/security/information-protection/windows-information-protection/wip-app-enterprise-context.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: Determine the Enterprise Context of an app running in Windows Information Protection (WIP) -description: Use the Task Manager to determine whether an app is considered work, personal or exempt by Windows Information Protection (WIP). -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 ---- - -# Determine the Enterprise Context of an app running in Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 and later - ->Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare). - -Use Task Manager to check the context of your apps while running in Windows Information Protection (WIP) to make sure that your organization's policies are applied and running correctly. - -## Viewing the Enterprise Context column in Task Manager -You need to add the Enterprise Context column to the **Details** tab of the Task Manager. - -1. Make sure that you have an active Windows Information Protection policy deployed and turned on in your organization. - -2. Open the Task Manager (taskmgr.exe), click the **Details** tab, right-click in the column heading area, and click **Select columns**. - - The **Select columns** box appears. - - ![Task Manager, Select column box with Enterprise Context option selected.](images/wip-select-column.png) - -3. Scroll down and check the **Enterprise Context** option, and then click **OK** to close the box. - - The **Enterprise Context** column should now be available in Task Manager. - - ![Task Manager, Enterprise Context column highlighted.](images/wip-taskmgr.png) - -## Review the Enterprise Context -The **Enterprise Context** column shows you what each app can do with your enterprise data: - -- **Domain.** Shows the employee's work domain (such as, corp.contoso.com). This app is considered work-related and can freely touch and open work data and resources. - -- **Personal.** Shows the text, *Personal*. This app is considered non-work-related and can't touch any work data or resources. - -- **Exempt.** Shows the text, *Exempt*. Windows Information Protection policies don't apply to these apps (such as, system components). - - > [!Important] - > Enlightened apps can change between Work and Personal, depending on the data being touched. For example, Microsoft Word 2016 shows as **Personal** when an employee opens a personal letter, but changes to **Work** when that same employee opens the company financials. diff --git a/windows/security/information-protection/windows-information-protection/wip-learning.md b/windows/security/information-protection/windows-information-protection/wip-learning.md deleted file mode 100644 index 08963510aa..0000000000 --- a/windows/security/information-protection/windows-information-protection/wip-learning.md +++ /dev/null @@ -1,104 +0,0 @@ ---- -title: Fine-tune Windows Information Policy (WIP) with WIP Learning -description: How to access the WIP Learning report to monitor and apply Windows Information Protection in your company. -author: aczechowski -ms.author: aaroncz -manager: aaroncz -ms.topic: conceptual -ms.date: 02/26/2019 ---- - -# Fine-tune Windows Information Protection (WIP) with WIP Learning -**Applies to:** - -- Windows 10, version 1703 and later - -With WIP Learning, you can intelligently tune which apps and websites are included in your WIP policy to help reduce disruptive prompts and keep it accurate and relevant. WIP Learning generates two reports: The **App learning report** and the **Website learning report**. Both reports can be accessed from Microsoft Azure Intune. - -The **App learning report** monitors your apps, not in policy, that attempt to access work data. You can identify these apps using the report and add them to your WIP policies to avoid productivity disruption before fully enforcing WIP with ["Block"](protect-enterprise-data-using-wip.md#bkmk-modes) mode. Frequent monitoring of the report will help you continuously identify access attempts so you can update your policy accordingly. - -In the **Website learning report**, you can view a summary of the devices that have shared work data with websites. You can use this information to determine which websites should be added to group and user WIP policies. The summary shows which website URLs are accessed by WIP-enabled apps so you can decide which ones are cloud or personal, and add them to the resource list. - -## Access the WIP Learning reports - -1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431). - -1. Select **Apps** > **Monitor** > **App protection status** > **Reports**. - - ![Image showing the UI path to the WIP report.](images/access-wip-learning-report.png) - -1. Select either **App learning report for Windows Information Protection** or **Website learning report for Windows Information Protection**. - - ![Image showing the UI with for app and website learning reports.](images/wip-learning-select-report.png) - -Once you have the apps and websites showing up in the WIP Learning logging reports, you can decide whether to add them to your app protection policies. - -## Use the WIP section of Device Health - -You can use Device Health to adjust your WIP protection policy. See [Using Device Health](/windows/deployment/update/device-health-using#windows-information-protection) to learn more. - -If you want to configure your environment for Windows Analytics: Device Health, see [Get Started with Device Health](/windows/deployment/update/device-health-get-started) for more information. - -Once you have WIP policies in place, by using the WIP section of Device Health, you can: - -- Reduce disruptive prompts by adding rules to allow data sharing from approved apps. -- Tune WIP rules by confirming that certain apps are allowed or denied by current policy. - -## Use Device Health and Intune to adjust WIP protection policy - -The information needed for the following steps can be found using Device Health, which you will first have to set up. Learn more about how you can [Monitor the health of devices with Device Health](/windows/deployment/update/device-health-monitor). - -1. In **Device Health** click the app you want to add to your policy and copy the **WipAppId**. - - For example, if the app is Google Chrome, the WipAppId is: - - `O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US\GOOGLE CHROME\CHROME.EXE\74.0.3729.108` - - In the steps below, you separate the WipAppId by back slashes into the **PUBLISHER**, **PRODUCT NAME**, and **FILE** fields. - -2. In Intune, click **App protection policies** and then choose the app policy you want to add an application to. - -3. Click **Protected apps**, and then click **Add Apps**. - -4. In the **Recommended apps** drop down menu, choose either **Store apps** or **Desktop apps**, depending on the app you've chosen (for example, an executable (EXE) is a desktop app). - - ![View of drop down menu for Store or desktop apps.](images/wip-learning-choose-store-or-desktop-app.png) - -5. In **NAME** (optional), type the name of the app, and then in **PUBLISHER** (required), paste the publisher information that you copied in step 1 above. - - For example, if the WipAppId is - - `O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US\GOOGLE CHROME\CHROME.EXE\74.0.3729.108` - - the text before the first back slash is the publisher: - - `O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US` - - ![View of Add Apps app info entry boxes.](images/wip-learning-app-info.png) - -6. Type the name of the product in **PRODUCT NAME** (required) (this will probably be the same as what you typed for **NAME**). - - For example, if the WipAppId is - - `O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US\GOOGLE CHROME\CHROME.EXE\74.0.3729.108` - - the text between the first and second back slashes is the product name: - - `GOOGLE CHROME` - -7. Copy the name of the executable (for example, snippingtool.exe) and paste it in **FILE** (required). - - For example, if the WipAppId is - - `O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US\GOOGLE CHROME\CHROME.EXE\74.0.3729.108` - - the text between the second and third back slashes is the file: - - `CHROME.EXE` - -8. Type the version number of the app into **MIN VERSION** in Intune (alternately, you can specify the max version, but one or the other is required), and then select the **ACTION**: **Allow** or **Deny** - -When working with WIP-enabled apps and WIP-unknown apps, it is recommended that you start with **Silent** or **Allow overrides** while verifying with a small group that you have the right apps on your allowed apps list. After you're done, you can change to your final enforcement policy, **Block**. For more information about WIP modes, see: [Protect enterprise data using WIP: WIP-modes](protect-enterprise-data-using-wip.md#bkmk-modes) - ->[!NOTE] ->Help to make this topic better by providing us with edits, additions, and feedback. For info about how to contribute to this topic, see [Editing Windows IT professional documentation](https://github.com/Microsoft/windows-itpro-docs/blob/master/CONTRIBUTING.md). diff --git a/windows/security/operating-system-security/data-protection/toc.yml b/windows/security/operating-system-security/data-protection/toc.yml index decdd162a6..81f918fba2 100644 --- a/windows/security/operating-system-security/data-protection/toc.yml +++ b/windows/security/operating-system-security/data-protection/toc.yml @@ -8,51 +8,4 @@ items: - name: Email Encryption (S/MIME) href: configure-s-mime.md - name: Windows Information Protection (WIP) - href: ../../information-protection/windows-information-protection/protect-enterprise-data-using-wip.md - items: - - name: Create a WIP policy using Microsoft Intune - href: ../../information-protection/windows-information-protection/overview-create-wip-policy.md - items: - - name: Create a WIP policy in Microsoft Intune - href: ../../information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md - items: - - name: Deploy your WIP policy in Microsoft Intune - href: ../../information-protection/windows-information-protection/deploy-wip-policy-using-intune-azure.md - - name: Associate and deploy a VPN policy for WIP in Microsoft Intune - href: ../../information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure.md - - name: Create and verify an EFS Data Recovery Agent (DRA) certificate - href: ../../information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md - - name: Determine the enterprise context of an app running in WIP - href: ../../information-protection/windows-information-protection/wip-app-enterprise-context.md - - name: Create a WIP policy using Microsoft Configuration Manager - href: ../../information-protection/windows-information-protection/overview-create-wip-policy-configmgr.md - items: - - name: Create and deploy a WIP policy in Configuration Manager - href: ../../information-protection/windows-information-protection/create-wip-policy-using-configmgr.md - - name: Create and verify an EFS Data Recovery Agent (DRA) certificate - href: ../../information-protection/windows-information-protection/create-and-verify-an-efs-dra-certificate.md - - name: Determine the enterprise context of an app running in WIP - href: ../../information-protection/windows-information-protection/wip-app-enterprise-context.md - - name: Mandatory tasks and settings required to turn on WIP - href: ../../information-protection/windows-information-protection/mandatory-settings-for-wip.md - - name: Testing scenarios for WIP - href: ../../information-protection/windows-information-protection/testing-scenarios-for-wip.md - - name: Limitations while using WIP - href: ../../information-protection/windows-information-protection/limitations-with-wip.md - - name: How to collect WIP audit event logs - href: ../../information-protection/windows-information-protection/collect-wip-audit-event-logs.md - - name: General guidance and best practices for WIP - href: ../../information-protection/windows-information-protection/guidance-and-best-practices-wip.md - items: - - name: Enlightened apps for use with WIP - href: ../../information-protection/windows-information-protection/enlightened-microsoft-apps-and-wip.md - - name: Unenlightened and enlightened app behavior while using WIP - href: ../../information-protection/windows-information-protection/app-behavior-with-wip.md - - name: Recommended Enterprise Cloud Resources and Neutral Resources network settings with WIP - href: ../../information-protection/windows-information-protection/recommended-network-definitions-for-wip.md - - name: Using Outlook Web Access with WIP - href: ../../information-protection/windows-information-protection/using-owa-with-wip.md - - name: Fine-tune WIP Learning - href: ../../information-protection/windows-information-protection/wip-learning.md - - name: Disable WIP - href: ../../information-protection/windows-information-protection/how-to-disable-wip.md \ No newline at end of file + href: /previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip diff --git a/windows/security/security-foundations/images/simplified-sdl.png b/windows/security/security-foundations/images/simplified-sdl.png deleted file mode 100644 index 97c7448b8c..0000000000 Binary files a/windows/security/security-foundations/images/simplified-sdl.png and /dev/null differ diff --git a/windows/whats-new/deprecated-features.md b/windows/whats-new/deprecated-features.md index fa2925d159..99a107408b 100644 --- a/windows/whats-new/deprecated-features.md +++ b/windows/whats-new/deprecated-features.md @@ -6,7 +6,7 @@ ms.service: windows-client ms.subservice: itpro-fundamentals ms.localizationpriority: medium author: mestew -ms.author: mstewart +ms.author: mstewart manager: aaroncz ms.topic: reference ms.collection: @@ -49,9 +49,9 @@ The features in this article are no longer being actively developed, and might b |---|---|---| | Paint 3D | Paint 3D is deprecated and will be removed from the Microsoft Store on November 4, 2024. To view and edit 2D images, you can use [Paint](https://apps.microsoft.com/detail/9pcfs5b6t72h) or [Photos](https://apps.microsoft.com/detail/9wzdncrfjbh4). For viewing 3D content, you can use [3D Viewer](https://apps.microsoft.com/detail/9nblggh42ths). For more information, see [Resources for deprecated features](deprecated-features-resources.md#paint-3d). | August 2024 | | Adobe Type1 fonts | Adobe PostScript Type1 fonts are deprecated and support will be removed in a future release of Windows.

    In January 2023, Adobe announced the [end of support for PostScript Type1 fonts](https://helpx.adobe.com/fonts/kb/postscript-type-1-fonts-end-of-support.html) for their latest software offerings. Remove any dependencies on this font type by selecting a supported font type. To display currently installed fonts, go to **Settings** > **Personalization** > **Fonts**. Application developers and content owners should test their apps and data files with the Adobe Type1 fonts removed. For more information, contact the application vendor or Adobe. | August 2024 | -| DirectAccess | DirectAccess is deprecated and will be removed in a future release of Windows. We recommend [migrating from DirectAccess to Always On VPN](/windows-server/remote/remote-access/da-always-on-vpn-migration/da-always-on-migration-overview). | June 2024 | +| DirectAccess | DirectAccess is deprecated and will be removed in a future release of Windows. We recommend [migrating from DirectAccess to Always On VPN](/windows-server/remote/remote-access/da-always-on-vpn-migration/da-always-on-migration-overview). | June 2024 | | NTLM | All versions of [NTLM](/windows/win32/secauthn/microsoft-ntlm), including LANMAN, NTLMv1, and NTLMv2, are no longer under active feature development and are deprecated. Use of NTLM will continue to work in the next release of Windows Server and the next annual release of Windows. Calls to NTLM should be replaced by calls to Negotiate, which will try to authenticate with Kerberos and only fall back to NTLM when necessary. For more information, see [Resources for deprecated features](deprecated-features-resources.md). | June 2024 | -| Driver Verifier GUI (verifiergui.exe) | Driver Verifier GUI, verifiergui.exe, is deprecated and will be removed in a future version of Windows. You can use the [Verifier Command Line](/windows-hardware/drivers/devtest/verifier-command-line) (verifier.exe) instead of the Driver Verifier GUI.| May 2024 | +| Driver Verifier GUI (verifiergui.exe) | Driver Verifier GUI, verifiergui.exe, is deprecated and will be removed in a future version of Windows. You can use the [Verifier Command Line](/windows-hardware/drivers/devtest/verifier-command-line) (verifier.exe) instead of the Driver Verifier GUI.| May 2024 | | NPLogonNotify and NPPasswordChangeNotify APIs | Starting in Windows 11, version 24H2, the inclusion of password payload in MPR notifications is set to disabled by default through group policy in [NPLogonNotify](/windows/win32/api/npapi/nf-npapi-nplogonnotify) and [NPPasswordChangeNotify](/windows/win32/api/npapi/nf-npapi-nppasswordchangenotify) APIs. The APIs may be removed in a future release. The primary reason for disabling this feature is to enhance security. When enabled, these APIs allow the caller to retrieve a user's password, presenting potential risks for password exposure and harvesting by malicious users. To include password payload in MPR notifications, set the [EnableMPRNotifications](/windows/client-management/mdm/policy-csp-windowslogon#enablemprnotifications) policy to `enabled`.| March 2024 | | TLS server authentication certificates using RSA keys with key lengths shorter than 2048 bits | Support for certificates using RSA keys with key lengths shorter than 2048 bits will be deprecated. Internet standards and regulatory bodies disallowed the use of 1024-bit keys in 2013, recommending specifically that RSA keys should have a key length of 2048 bits or longer. For more information, see [Transitioning of Cryptographic Algorithms and Key Sizes - Discussion Paper (nist.gov)](https://csrc.nist.gov/CSRC/media/Projects/Key-Management/documents/transitions/Transitioning_CryptoAlgos_070209.pdf). This deprecation focuses on ensuring that all RSA certificates used for TLS server authentication must have key lengths greater than or equal to 2048 bits to be considered valid by Windows.

    TLS certificates issued by enterprise or test certification authorities (CA) aren't impacted with this change. However, we recommend that they be updated to RSA keys greater than or equal to 2048 bits as a security best practice. This change is necessary to preserve security of Windows customers using certificates for authentication and cryptographic purposes.| March 2024| | Test Base | [Test Base for Microsoft 365](/microsoft-365/test-base/overview), an Azure cloud service for application testing, is deprecated. The service will be retired in the future and will be no longer available for use after retirement. | March 2024 | @@ -74,7 +74,7 @@ The features in this article are no longer being actively developed, and might b | Microsoft Support Diagnostic Tool (MSDT) | [MSDT](/windows-server/administration/windows-commands/msdt) is deprecated and will be removed in a future release of Windows. MSDT is used to gather diagnostic data for analysis by support professionals. For more information, see [Resources for deprecated features](deprecated-features-resources.md) | January 2023 | | Universal Windows Platform (UWP) Applications for 32-bit Arm | This change is applicable only to devices with an Arm processor, for example Snapdragon processors from Qualcomm. If you have a PC built with a processor from Intel or AMD, this content isn't applicable. If you aren't sure which type of processor you have, check **Settings** > **System** > **About**.

    Support for 32-bit Arm versions of applications will be removed in a future release of Windows 11. After this change, for the small number of applications affected, app features might be different and you might notice a difference in performance. For more technical details about this change, see [Update app architecture from Arm32 to Arm64](/windows/arm/arm32-to-arm64). | January 2023 | | Update Compliance | [Update Compliance](/windows/deployment/update/update-compliance-monitor), a cloud-based service for the Windows client, is no longer being developed. This service was replaced with [Windows Update for Business reports](/windows/deployment/update/wufb-reports-overview), which provides reporting on client compliance with Microsoft updates from the Azure portal. | November 2022| -| Windows Information Protection | [Windows Information Protection](/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) will no longer be developed in future versions of Windows. For more information, see [Announcing sunset of Windows Information Protection (WIP)](https://go.microsoft.com/fwlink/?linkid=2202124).

    For your data protection needs, Microsoft recommends that you use [Microsoft Purview Information Protection](/microsoft-365/compliance/information-protection) and [Microsoft Purview Data Loss Prevention](/microsoft-365/compliance/dlp-learn-about-dlp). | July 2022 | +| Windows Information Protection | [Windows Information Protection](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) will no longer be developed in future versions of Windows. For more information, see [Announcing sunset of Windows Information Protection (WIP)](https://go.microsoft.com/fwlink/?linkid=2202124).

    For your data protection needs, Microsoft recommends that you use [Microsoft Purview Information Protection](/microsoft-365/compliance/information-protection) and [Microsoft Purview Data Loss Prevention](/microsoft-365/compliance/dlp-learn-about-dlp). | July 2022 | | BitLocker To Go Reader | **Note: BitLocker to Go as a feature is still supported.**
    Reading of BitLocker-protected removable drives ([BitLocker To Go](/windows/security/information-protection/bitlocker/bitlocker-to-go-faq)) from Windows XP or Windows Vista in later operating systems is deprecated and might be removed in a future release of Windows client.
    The following items might not be available in a future release of Windows client:
    - ADMX policy: **Allow access to BitLocker-protected removable data drives from earlier versions of Windows**
    - Command line parameter: [`manage-bde -DiscoveryVolumeType`](/windows-server/administration/windows-commands/manage-bde-on) (-dv)
    - Catalog file: **c:\windows\BitLockerDiscoveryVolumeContents**
    - BitLocker 2 Go Reader app: **bitlockertogo.exe** and associated files | 21H1 | | Personalization roaming | Roaming of Personalization settings (including wallpaper, slideshow, accent colors, and lock screen images) is no longer being developed and might be removed in a future release. | 21H1 | | Windows Management Instrumentation command-line (WMIC) utility. | The WMIC utility is deprecated in Windows 10, version 21H1 and the 21H1 General Availability Channel release of Windows Server. This utility is superseded by [Windows PowerShell for WMI](/powershell/scripting/learn/ps101/07-working-with-wmi). Note: This deprecation applies to only the [command-line management utility](/windows/win32/wmisdk/wmic). WMI itself isn't affected.

    **[Update - January 2024]**: Currently, WMIC is a Feature on Demand (FoD) that's [preinstalled by default](/windows-hardware/manufacture/desktop/features-on-demand-non-language-fod#wmic) in Windows 11, versions 23H2 and 22H2. In the next release of Windows, the WMIC FoD will be disabled by default. | 21H1 | diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2016.md b/windows/whats-new/ltsc/whats-new-windows-10-2016.md index 315ac95603..9c94a7e808 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2016.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2016.md @@ -82,10 +82,7 @@ With the increase of employee-owned devices in the enterprise, there's also an i Windows Information Protection (WIP) helps to protect against this potential data leakage without otherwise interfering with the employee experience. WIP also helps to protect enterprise apps and data against accidental data leak on enterprise-owned devices and personal devices that employees bring to work without requiring changes to your environment or other apps. -- [Create a Windows Information Protection (WIP) policy](/windows/security/information-protection/windows-information-protection/overview-create-wip-policy) -- [General guidance and best practices for Windows Information Protection (WIP)](/windows/security/information-protection/windows-information-protection/guidance-and-best-practices-wip) - -[Learn more about Windows Information Protection (WIP)](/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip) +[Learn more about Windows Information Protection (WIP)](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip). ### Windows Defender @@ -107,7 +104,7 @@ With the growing threat from more sophisticated targeted attacks, a new security ### VPN security - The VPN client can integrate with the Conditional Access Framework, a cloud-based policy engine built into Microsoft Entra ID, to provide a device compliance option for remote clients. -- The VPN client can integrate with Windows Information Protection (WIP) policy to provide extra security. [Learn more about Windows Information Protection](/windows/threat-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. +- The VPN client can integrate with Windows Information Protection (WIP) policy to provide extra security. [Learn more about Windows Information Protection](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip), previously known as Enterprise Data Protection. - New VPNv2 configuration service provider (CSP) adds configuration settings. For details, see [VPNv2 CSP](/windows/client-management/mdm/vpnv2-csp) - Microsoft Intune: *VPN* profile template includes support for native VPN plug-ins. For more information, see [Create VPN profiles to connect to VPN servers in Intune](/mem/intune/configuration/vpn-settings-configure). diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2019.md b/windows/whats-new/ltsc/whats-new-windows-10-2019.md index 6e5084a543..9f16b31604 100644 --- a/windows/whats-new/ltsc/whats-new-windows-10-2019.md +++ b/windows/whats-new/ltsc/whats-new-windows-10-2019.md @@ -158,9 +158,9 @@ Improvements have been added to Windows Information Protection and BitLocker. Windows Information Protection is now designed to work with Microsoft Office and Azure Information Protection. -Microsoft Intune helps you create and deploy your Windows Information Protection (WIP) policy, including letting you choose your allowed apps, your WIP-protection level, and how to find enterprise data on the network. For more info, see [Create a Windows Information Protection (WIP) policy using Microsoft Intune](/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure) and [Associate and deploy your Windows Information Protection (WIP) and VPN policies by using Microsoft Intune](/windows/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure). +Microsoft Intune helps you create and deploy your Windows Information Protection (WIP) policy, including letting you choose your allowed apps, your WIP-protection level, and how to find enterprise data on the network. For more info, see [Create a Windows Information Protection (WIP) policy using Microsoft Intune](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure) and [Associate and deploy your Windows Information Protection (WIP) and VPN policies by using Microsoft Intune](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/create-vpn-and-wip-policy-using-intune-azure). -You can also now collect your audit event logs by using the Reporting configuration service provider (CSP) or the Windows Event Forwarding (for Windows desktop domain-joined devices). For more information, see [How to collect Windows Information Protection (WIP) audit event logs](/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs). +You can also now collect your audit event logs by using the Reporting configuration service provider (CSP) or the Windows Event Forwarding (for Windows desktop domain-joined devices). For more information, see [How to collect Windows Information Protection (WIP) audit event logs](/previous-versions/windows/it-pro/windows-10/security/information-protection/windows-information-protection/collect-wip-audit-event-logs). This release enables support for WIP with Files on Demand, allows file encryption while the file is open in another app, and improves performance. For more information, see [OneDrive files on-demand for the enterprise](https://techcommunity.microsoft.com/t5/microsoft-onedrive-blog/onedrive-files-on-demand-for-the-enterprise/ba-p/117234). diff --git a/windows/whats-new/windows-11-requirements.md b/windows/whats-new/windows-11-requirements.md index 62733bd8d1..a348f85ad3 100644 --- a/windows/whats-new/windows-11-requirements.md +++ b/windows/whats-new/windows-11-requirements.md @@ -60,7 +60,7 @@ To upgrade directly to Windows 11, eligible Windows 10 devices must meet both of > [!NOTE] > > - S mode is only supported on the Home edition of Windows 11. -> - If you're running a different edition of Windows in S mode, before upgrading to Windows 11, first [switch out of S mode](/windows/deployment/windows-10-pro-in-s-mode). +> - If you're running a different edition of Windows in S mode, before upgrading to Windows 11, first [switch out of S mode](/previous-versions/windows/it-pro/windows-10/deployment/s-mode/switch-edition-from-s-mode). > - To switch a device out of Windows 10 in S mode also requires internet connectivity. If you switch out of S mode, you can't switch back to S mode later. ## Feature-specific requirements