Merge remote-tracking branch 'upstream/surface-2s-update' into surface-2s-update-vjokai

This commit is contained in:
John Kaiser
2019-06-11 09:27:30 -07:00
625 changed files with 1925 additions and 2193 deletions

View File

@ -14983,6 +14983,56 @@
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/windows-autopilot-requirements-network.md",
"redirect_url": "/windows/deployment/windows-autopilot/windows-autopilot-requirements#networking-requirements",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/windows-autopilot-requirements-licensing.md",
"redirect_url": "/windows/deployment/windows-autopilot/windows-autopilot-requirements#licensing-requirements",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/windows-autopilot-requirements-configuration.md",
"redirect_url": "/windows/deployment/windows-autopilot/windows-autopilot-requirements#configuration-requirements",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/user-driven-aad.md",
"redirect_url": "/windows/deployment/windows-autopilot/user-driven#user-driven-mode-for-azure-active-directory-join",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/user-driven-hybrid.md",
"redirect_url": "/windows/deployment/windows-autopilot/user-driven#user-driven-mode-for-hybrid-azure-active-directory-join",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/intune-connector.md",
"redirect_url": "https://docs.microsoft.com/intune/windows-autopilot-hybrid",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/windows-autopilot-reset-remote.md",
"redirect_url": "/windows/deployment/windows-autopilot/windows-autopilot-reset#reset-devices-with-remote-windows-autopilot-reset",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/windows-autopilot-reset-local.md",
"redirect_url": "/windows/deployment/windows-autopilot/windows-autopilot-reset#reset-devices-with-local-windows-autopilot-reset",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/configure-autopilot.md",
"redirect_url": "/windows/deployment/windows-autopilot/add-devices",
"redirect_document_id": true
},
{
"source_path": "windows/deployment/windows-autopilot/administer.md",
"redirect_url": "/windows/deployment/windows-autopilot/add-devices#registering-devices",
"redirect_document_id": true
},
{
"source_path": "windows/hub/release-information.md",
"redirect_url": "/windows/release-information",
"redirect_document_id": true

View File

@ -14,8 +14,11 @@
"resource": [
{
"files": [
"**/images/**"
],
"**/images/**",
"**/*.png",
"**/*.jpg",
"**/*.gif"
],
"exclude": [
"**/obj/**"
]

View File

@ -20,7 +20,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|-----------------------------------------|:---:|:--------:|---------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented. Hide the Address bar drop-down list and disable the *Show search and site suggestions as I type* toggle in Settings. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented. Hide the Address bar drop-down list and disable the *Show search and site suggestions as I type* toggle in Settings. | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured **(default)** | 1 | 1 | Allowed. Show the Address bar drop-down list and make it available. | |
---

View File

@ -20,7 +20,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|------------------------------------------|:---:|:--------:|------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured **(default)** | 0 | 0 | Prevented. Users can configure the *Clear browsing data* option in Settings. | |
| Enabled | 1 | 1 | Allowed. Clear the browsing data upon exit automatically. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Allowed. Clear the browsing data upon exit automatically. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|---------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented. | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed. Microsoft Edge updates the configuration data for the Books Library automatically. | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------|:---:|:--------:|------------------------------------------------------------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented. Users can still search to find items on their device. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented. Users can still search to find items on their device. | ![Most restricted value](/images/check-gn.png) |
| Enabled<br>**(default)** | 1 | 1 | Allowed. | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Allowed | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Show the Books Library only in countries or regions where supported. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | Show the Books Library only in countries or regions where supported. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Show the Books Library, regardless of the devices country or region. | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Gather and send only basic diagnostic data. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | Gather and send only basic diagnostic data. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Gather all diagnostic data. For this policy to work correctly, you must set the diagnostic data in *Settings > Diagnostics & feedback* to **Full**. | |
---

View File

@ -20,7 +20,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -20,7 +20,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:-------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restrictive value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restrictive value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:-------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restrictive value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restrictive value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed | |
---

View File

@ -20,12 +20,12 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Prevented. Microsoft Edge downloads book files to a per-user folder for each user. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | Prevented. Microsoft Edge downloads book files to a per-user folder for each user. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Allowed. Microsoft Edge downloads book files to a shared folder. For this policy to work correctly, you must also enable the **Allow a Windows app to share application data between users** group policy, which you can find:<p>**Computer Configuration\\Administrative Templates\\Windows Components\\App Package Deployment\\**<p>Also, the users must be signed in with a school or work account. | |
---
![Allow a shared books folder](../images/allow-shared-books-folder_sm.png)
![Allow a shared books folder](/images/allow-shared-books-folder_sm.png)
### ADMX info and settings

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|----------------------------|:---:|:--------:|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured | 0 | 0 | Prevented. Disabling does not prevent sideloading of extensions using Add-AppxPackage via PowerShell. To prevent this, you must enable the **Allows development of Windows Store apps and installing them from an integrated development environment (IDE)** group policy, which you can find:<p>**Computer Configuration\\Administrative Templates\\Windows Components\\App Package Deployment\\**<p>For the MDM setting, set the **ApplicationManagement/AllowDeveloperUnlock** policy to 1 (enabled). | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured | 0 | 0 | Prevented. Disabling does not prevent sideloading of extensions using Add-AppxPackage via PowerShell. To prevent this, you must enable the **Allows development of Windows Store apps and installing them from an integrated development environment (IDE)** group policy, which you can find:<p>**Computer Configuration\\Administrative Templates\\Windows Components\\App Package Deployment\\**<p>For the MDM setting, set the **ApplicationManagement/AllowDeveloperUnlock** policy to 1 (enabled). | ![Most restricted value](/images/check-gn.png) |
| Enabled<br>**(default)** | 1 | 1 | Allowed. | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|-------------------------------------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Prevented. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented. | ![Most restricted value](/images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Allowed. Preload Start and New Tab pages. | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Show the Books Library only in countries or regions where supported. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | Show the Books Library only in countries or regions where supported. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Show the Books Library, regardless of the devices country or region. | |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Prevented. Use the search engine specified in App settings.<p><p>If you enabled this policy and now want to disable it, all previously configured search engines get removed. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | Prevented. Use the search engine specified in App settings.<p><p>If you enabled this policy and now want to disable it, all previously configured search engines get removed. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Allowed. Add up to five additional search engines and set any one of them as the default.<p><p>For each search engine added you must specify a link to the OpenSearch XML file that contains, at a minimum, the short name and URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see [Search provider discovery](https://developer.microsoft.com/en-us/microsoft-edge/platform/documentation/dev-guide/browser/search-provider-discovery/). | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------------------------|:---:|:--------:|--------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled | 0 | 0 | Load and run Adobe Flash content automatically. | |
| Enabled or not configured<br>**(default)** | 1 | 1 | Do not load or run Adobe Flash content and require action from the user. | ![Most restricted value](../images/check-gn.png) |
| Enabled or not configured<br>**(default)** | 1 | 1 | Do not load or run Adobe Flash content and require action from the user. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------|:-----:|:--------:|-----------------------------------|:------------------------------------------------:|
| Not configured<br>**(default)** | Blank | Blank | Users can choose to use Autofill. | |
| Disabled | 0 | no | Prevented. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | no | Prevented. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | yes | Allowed. | |
---

View File

@ -29,7 +29,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | No data collected or sent | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | No data collected or sent | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Send intranet history only | |
| Enabled | 2 | 2 | Send Internet history only | |
| Enabled | 3 | 3 | Send both intranet and Internet history | |

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------------|:------------------------------------------------:|
| Enabled | 0 | 0 | Block all cookies from all sites. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 0 | 0 | Block all cookies from all sites. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Block only coddies from third party websites. | |
| Disabled or not configured<br>**(default)** | 2 | 2 | Allow all cookies from all sites. | |

View File

@ -20,7 +20,7 @@ ms:topic: include
|---------------------------------|:-----:|:--------:|---------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Not configured<br>**(default)** | Blank | Blank | Do not send tracking information but let users choose to send tracking information to sites they visit. | |
| Disabled | 0 | 0 | Never send tracking information. | |
| Enabled | 1 | 1 | Send tracking information. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Send tracking information. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -11,7 +11,7 @@ ms:topic: include
| | |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Single-app**<p><a href="../images/Picture1.png" alt="Full-sized view single-app digital/interactive signage" target="_blank">![thumbnail](../images/Picture1-sm.png)</a><p>**Digital/interactive signage**<p>Displays a specific site in full-screen mode, running Microsoft Edge InPrivate protecting user data.<ul><li>**Digital signage** does not require user interaction.<p>***Example.*** Use digital signage for things like a rotating advertisement or menu.<p></li><li>**Interactive signage**, on the other hand, requires user interaction within the page but doesnt allow for any other uses, such as browsing the internet.<p>***Example.*** Use interactive signage for things like a building business directory or restaurant order/pay station.</li></ul><p>**Policy setting** = Not configured (0 default)<p> | <p>&nbsp;<p><a href="../images/Picture2.png" alt="Full-sized view single-app public browsing" target="_blank">![thumbnail](../images/Picture2-sm.png)</a> <p><strong>Public browsing</strong><p>Runs a limited multi-tab version of Microsoft Edge, protecting user data. Microsoft Edge is the only app users can use on the device, preventing them from customizing Microsoft Edge. Users can only browse publically or end their browsing session.<p>The single-app public browsing mode is the only kiosk mode that has an <strong>End session</strong> button. Microsoft Edge also resets the session after a specified time of user inactivity. Both restart Microsoft Edge and clear the users session.<p><em><strong>Example.</strong></em> A public library or hotel concierge desk are two examples of public browsing that provides access to Microsoft Edge and other apps. <p><strong>Policy setting</strong> = Enabled (1) |
| **Multi-app**<p><a href="../images/Picture5.png" alt="Full-sized view multi-app normal browsing" target="_blank">![thumbnail](../images/Picture5-sm.png)</a><p>**Normal browsing**<p>Runs a full-version of Microsoft Edge with all browsing features and preserves the user data and state between sessions.<p>Some features may not work depending on what other apps you have configured in assigned access. For example, installing extensions or books from the Microsoft store are not allowed if the store is not available. Also, if Internet Explorer 11 is set up in assigned access, you can enable [EnterpriseModeSiteList](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-browser#browser-enterprisemodesitelist) to automatically switch users to Internet Explorer 11 for sites that need backward compatibility support.<p>**Policy setting** = Not configured (0 default) | <p>&nbsp;<p><a href="../images/Picture6.png" alt="Full-sized view multi-app public browsing" target="_blank">![thumbnail](../images/Picture6-sm.png)</a><p><strong>Public browsing</strong><p>Runs a multi-tab version of Microsoft Edge InPrivate with a tailored experience for kiosks that runs in full-screen mode. Users can open and close Microsoft Edge and launch other apps if allowed by assigned access. Instead of an End session button to clear their browsing session, the user closes Microsoft Edge normally.<p>In this configuration, Microsoft Edge can interact with other applications. For example, if Internet Explorer 11 is set up in multi-app assigned access, you can enable [EnterpriseModeSiteList](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-browser#browser-enterprisemodesitelist) to automatically switch users to Internet Explorer 11 for sites that need backward compatibility support. <p><em><strong>Example.</strong></em> A public library or hotel concierge desk are two examples of public browsing that provides access to Microsoft Edge and other apps.<p><strong>Policy setting</strong> = Enabled (1) |
| **Single-app**<p><a href="/images/Picture1.png" alt="Full-sized view single-app digital/interactive signage" target="_blank">![thumbnail](/images/Picture1-sm.png)</a><p>**Digital/interactive signage**<p>Displays a specific site in full-screen mode, running Microsoft Edge InPrivate protecting user data.<ul><li>**Digital signage** does not require user interaction.<p>***Example.*** Use digital signage for things like a rotating advertisement or menu.<p></li><li>**Interactive signage**, on the other hand, requires user interaction within the page but doesnt allow for any other uses, such as browsing the internet.<p>***Example.*** Use interactive signage for things like a building business directory or restaurant order/pay station.</li></ul><p>**Policy setting** = Not configured (0 default)<p> | <p>&nbsp;<p><a href="/images/Picture2.png" alt="Full-sized view single-app public browsing" target="_blank">![thumbnail](/images/Picture2-sm.png)</a> <p><strong>Public browsing</strong><p>Runs a limited multi-tab version of Microsoft Edge, protecting user data. Microsoft Edge is the only app users can use on the device, preventing them from customizing Microsoft Edge. Users can only browse publically or end their browsing session.<p>The single-app public browsing mode is the only kiosk mode that has an <strong>End session</strong> button. Microsoft Edge also resets the session after a specified time of user inactivity. Both restart Microsoft Edge and clear the users session.<p><em><strong>Example.</strong></em> A public library or hotel concierge desk are two examples of public browsing that provides access to Microsoft Edge and other apps. <p><strong>Policy setting</strong> = Enabled (1) |
| **Multi-app**<p><a href="/images/Picture5.png" alt="Full-sized view multi-app normal browsing" target="_blank">![thumbnail](/images/Picture5-sm.png)</a><p>**Normal browsing**<p>Runs a full-version of Microsoft Edge with all browsing features and preserves the user data and state between sessions.<p>Some features may not work depending on what other apps you have configured in assigned access. For example, installing extensions or books from the Microsoft store are not allowed if the store is not available. Also, if Internet Explorer 11 is set up in assigned access, you can enable [EnterpriseModeSiteList](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-browser#browser-enterprisemodesitelist) to automatically switch users to Internet Explorer 11 for sites that need backward compatibility support.<p>**Policy setting** = Not configured (0 default) | <p>&nbsp;<p><a href="/images/Picture6.png" alt="Full-sized view multi-app public browsing" target="_blank">![thumbnail](/images/Picture6-sm.png)</a><p><strong>Public browsing</strong><p>Runs a multi-tab version of Microsoft Edge InPrivate with a tailored experience for kiosks that runs in full-screen mode. Users can open and close Microsoft Edge and launch other apps if allowed by assigned access. Instead of an End session button to clear their browsing session, the user closes Microsoft Edge normally.<p>In this configuration, Microsoft Edge can interact with other applications. For example, if Internet Explorer 11 is set up in multi-app assigned access, you can enable [EnterpriseModeSiteList](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-browser#browser-enterprisemodesitelist) to automatically switch users to Internet Explorer 11 for sites that need backward compatibility support. <p><em><strong>Example.</strong></em> A public library or hotel concierge desk are two examples of public browsing that provides access to Microsoft Edge and other apps.<p><strong>Policy setting</strong> = Enabled (1) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|--------------------------|:-----:|:--------:|--------------------------------------------------------|:------------------------------------------------:|
| Not configured | Blank | Blank | Users can choose to save and manage passwords locally. | |
| Disabled | 0 | no | Not allowed. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | no | Not allowed. | ![Most restricted value](/images/check-gn.png) |
| Enabled<br>**(default)** | 1 | yes | Allowed. | |
---

View File

@ -20,7 +20,7 @@ ms:topic: include
|---------------------------|:-----:|:--------:|-------------------------------------------------|:------------------------------------------------:|
| Not configured | Blank | Blank | Users can choose to use Pop-up Blocker. | |
| Disabled<br>**(default)** | 0 | 0 | Turned off. Allow pop-up windows to open. | |
| Enabled | 1 | 1 | Turned on. Prevent pop-up windows from opening. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Turned on. Prevent pop-up windows from opening. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------|:-----:|:--------:|---------------------------------------------|:------------------------------------------------:|
| Not configured<br>**(default)** | Blank | Blank | Users can choose to see search suggestions. | |
| Disabled | 0 | 0 | Prevented. Hide the search suggestions. | ![Most restricted value](../images/check-gn.png) |
| Disabled | 0 | 0 | Prevented. Hide the search suggestions. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Allowed. Show the search suggestions. | |
---

View File

@ -20,13 +20,13 @@ ms:topic: include
|----------------|:-----:|:--------:|-----------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Not configured | Blank | Blank | Users can choose to use Windows Defender SmartScreen. | |
| Disabled | 0 | 0 | Turned off. Do not protect users from potential threats and prevent users from turning it on. | |
| Enabled | 1 | 1 | Turned on. Protect users from potential threats and prevent users from turning it off. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Turned on. Protect users from potential threats and prevent users from turning it off. | ![Most restricted value](/images/check-gn.png) |
---
To verify Windows Defender SmartScreen is turned off (disabled):
1. Click or tap **More** (…) and select **Settings** > **View Advanced settings**.
2. Verify the setting **Help protect me from malicious sites and download with SmartScreen Filter** is disabled.<p>![Verify that Windows Defender SmartScreen is turned off (disabled)](../images/allow-smart-screen-validation.PNG)
2. Verify the setting **Help protect me from malicious sites and download with SmartScreen Filter** is disabled.<p>![Verify that Windows Defender SmartScreen is turned off (disabled)](/images/allow-smart-screen-validation.PNG)
### ADMX info and settings

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|----------------|:---:|:--------:|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Not configured | 0 | 0 | Locked. Start pages configured in either the Configure Open Microsoft Edge With policy and Configure Start Pages policy are not editable. | ![Most restricted value](../images/check-gn.png) |
| Not configured | 0 | 0 | Locked. Start pages configured in either the Configure Open Microsoft Edge With policy and Configure Start Pages policy are not editable. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Unlocked. Users can make changes to all configured start pages.<p><p>When you enable this policy and define a set of URLs in the Configure Start Pages policy, Microsoft Edge uses the URLs defined in the Configure Open Microsoft Edge With policy. | |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed/turned on. Users can choose what to sync to their device. | |
| Enabled | 2 | 2 | Prevented/turned off. Disables the *Sync your Settings* toggle and prevents syncing. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 2 | 2 | Prevented/turned off. Disables the *Sync your Settings* toggle and prevents syncing. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Turned off/not syncing | |
| Enabled | 1 | 1 | Turned on/syncing | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Turned on/syncing | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed | |
| Enabled | 1 | 1 | Prevented | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|---------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed/turned off. Users can ignore the warning and continue to download the unverified file(s). | |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|----------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed/turned off. Users can ignore the warning and continue to the site. | |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -18,7 +18,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|---------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed/turned on. Override the security warning to sites that have SSL errors. | |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented/turned on. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|-----------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed/unlocked. Users can add, import, and make changes to the Favorites list. | |
| Enabled | 1 | 1 | Prevented/locked down. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented/locked down. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed. Load the First Run webpage. | |
| Enabled | 1 | 1 | Prevented. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Collect and send Live Tile metadata. | |
| Enabled | 1 | 1 | Do not collect data. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Do not collect data. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -19,7 +19,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|---------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | Allowed. Show localhost IP addresses. | |
| Enabled | 1 | 1 | Prevented. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Prevented. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -23,7 +23,7 @@ ms:topic: include
| Group Policy | Description | Most restricted |
|---------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | Users can customize the favorites list, such as adding folders, or adding and removing favorites. | |
| Enabled | Define a default list of favorites in Microsoft Edge. In this case, the Save a Favorite, Import settings, and context menu options (such as Create a new folder) are turned off.<p>To define a default list of favorites, do the following:<ol><li>In the upper-right corner of Microsoft Edge, click the ellipses (**...**) and select **Settings**.</li><li>Click **Import from another browser**, click **Export to file** and save the file.</li><li>In the **Options** section of the Group Policy Editor, provide the location that points the file with the list of favorites to provision. Specify the URL as: <ul><li>HTTP location: "SiteList"=<https://localhost:8080/URLs.html></li><li>Local network: "SiteList"="\network\shares\URLs.html"</li><li>Local file: "SiteList"=file:///c:/Users/Documents/URLs.html</li></ul></li></ol> | ![Most restricted value](../images/check-gn.png) |
| Enabled | Define a default list of favorites in Microsoft Edge. In this case, the Save a Favorite, Import settings, and context menu options (such as Create a new folder) are turned off.<p>To define a default list of favorites, do the following:<ol><li>In the upper-right corner of Microsoft Edge, click the ellipses (**...**) and select **Settings**.</li><li>Click **Import from another browser**, click **Export to file** and save the file.</li><li>In the **Options** section of the Group Policy Editor, provide the location that points the file with the list of favorites to provision. Specify the URL as: <ul><li>HTTP location: "SiteList"=<https://localhost:8080/URLs.html></li><li>Local network: "SiteList"="\network\shares\URLs.html"</li><li>Local file: "SiteList"=file:///c:/Users/Documents/URLs.html</li></ul></li></ol> | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -22,7 +22,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | All sites, including intranet sites, open in Microsoft Edge automatically. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | All sites, including intranet sites, open in Microsoft Edge automatically. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Only intranet sites open in Internet Explorer 11 automatically.<p><p>Enabling this policy opens all intranet sites in IE11 automatically, even if the users have Microsoft Edge as their default browser.<ol><li>In Group Policy Editor, navigate to:<p><p>**Computer Configuration\\Administrative Templates\\Windows Components\\File Explorer\\Set a default associations configuration file**</li><li>Click **Enable** and then refresh the policy to view the affected sites in Microsoft Edge.<p><p>A message opens stating that the page needs to open in IE. At the same time, the page opens in IE11 automatically; in a new frame if it is not yet running, or in a new tab.</li></ol> | |
---

View File

@ -20,7 +20,7 @@ ms:topic: include
|---------------------------------|:-----:|:--------:|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Not configured<br>**(default)** | Blank | Blank | Use the search engine specified in App settings. If you don't configure this policy and disable the [Allow search engine customization](../group-policies/search-engine-customization-gp.md#allow-search-engine-customization) policy, users cannot make changes. | |
| Disabled | 0 | 0 | Remove or don't use the policy-set search engine and use the search engine for the market, letting users make changes. | |
| Enabled | 1 | 1 | Use the policy-set search engine specified in the OpenSearch XML file, preventing users from making changes.<p><p>Specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see [Search provider discovery](https://docs.microsoft.com/microsoft-edge/dev-guide/browser/search-provider-discovery). Use this format to specify the link you want to add.<p><p>If you want your users to use the default Microsoft Edge settings for each market, then set the string to **EDGEDEFAULT**.<p><p>If you would like your users to use Microsoft Bing as the default search engine, then set the string to **EDGEBING**. | ![Most restricted value](../images/check-gn.png) |
| Enabled | 1 | 1 | Use the policy-set search engine specified in the OpenSearch XML file, preventing users from making changes.<p><p>Specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see [Search provider discovery](https://docs.microsoft.com/microsoft-edge/dev-guide/browser/search-provider-discovery). Use this format to specify the link you want to add.<p><p>If you want your users to use the default Microsoft Edge settings for each market, then set the string to **EDGEDEFAULT**.<p><p>If you would like your users to use Microsoft Bing as the default search engine, then set the string to **EDGEBING**. | ![Most restricted value](/images/check-gn.png) |
---

View File

@ -21,7 +21,7 @@ ms:topic: include
| Group Policy | MDM | Registry | Description | Most restricted |
|---------------------------------------------|:---:|:--------:|--------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------:|
| Disabled or not configured<br>**(default)** | 0 | 0 | No additional message displays. | ![Most restricted value](../images/check-gn.png) |
| Disabled or not configured<br>**(default)** | 0 | 0 | No additional message displays. | ![Most restricted value](/images/check-gn.png) |
| Enabled | 1 | 1 | Show an additional message stating that a site has opened in IE11. | |
| Enabled | 2 | 2 | Show an additional message with a *Keep going in Microsoft Edge* link to allow users to open the site in Microsoft Edge. | |

View File

@ -10,7 +10,7 @@ ms:topic: include
If you need to replace your entire site list because of errors, or simply because its out of date, you can import your exported Enterprise Mode site list using the Enterprise Mode Site List Manager.
>[!IMPORTANT]
>[!IMPORTANT]
>Importing your file overwrites everything thats currently in the tool, so make sure its what want to do.
1. In the Enterprise Mode Site List Manager, click **File \> Import**.

View File

@ -17,7 +17,7 @@ manager: dansimp
In order to switch to the Chinese or Japanese version of HoloLens, youll need to download the build for the language on a PC and then install it on your HoloLens using the Windows Device Recovery Tool (WDRT).
>[!IMPORTANT]
>[!IMPORTANT]
>Installing the Chinese or Japanese builds of HoloLens using WDRT will delete existing data, like personal files and settings, from your HoloLens.

View File

@ -37,7 +37,7 @@ Note that the local admin account information is not backed by any directory ser
### Domain join the device to Active Directory (AD)
You can domain join the Surface Hub to your AD domain to allow users from a specified security group to configure settings. During first run, choose to use [Active Directory Domain Services](first-run-program-surface-hub.md#a-href-iduse-active-directoryause-active-directory-domain-services). You'll need to provide credentials that are capable of joining the domain of your choice, and the name of an existing security group. Anyone who is a member of that security group can enter their credentials and unlock Settings.
You can domain join the Surface Hub to your AD domain to allow users from a specified security group to configure settings. During first run, choose to use [Active Directory Domain Services](first-run-program-surface-hub.md#use-active-directory-domain-services). You'll need to provide credentials that are capable of joining the domain of your choice, and the name of an existing security group. Anyone who is a member of that security group can enter their credentials and unlock Settings.
#### What happens when you domain join your Surface Hub?
Surface Hubs use domain join to:
@ -53,7 +53,7 @@ Surface Hub does not support applying group policies or certificates from the do
### Azure Active Directory (Azure AD) join the device
You can Azure AD join the Surface Hub to allow IT pros from your Azure AD tenant to configure settings. During first run, choose to use [Microsoft Azure Active Directory](first-run-program-surface-hub.md#a-href-iduse-microsoft-azureause-microsoft-azure-active-directory). You will need to provide credentials that are capable of joining the Azure AD tenant of your choice. After you successfully Azure AD join, the appropriate people will be granted admin rights on the device.
You can Azure AD join the Surface Hub to allow IT pros from your Azure AD tenant to configure settings. During first run, choose to use [Microsoft Azure Active Directory](first-run-program-surface-hub.md#use-microsoft-azure-active-directory). You will need to provide credentials that are capable of joining the Azure AD tenant of your choice. After you successfully Azure AD join, the appropriate people will be granted admin rights on the device.
By default, all **global administrators** will be given admin rights on an Azure AD joined Surface Hub. With **Azure AD Premium** or **Enterprise Mobility Suite (EMS)**, you can add additional administrators:
1. In the [Azure classic portal](https://manage.windowsazure.com/), click **Active Directory**, and then click the name of your organization's directory.

View File

@ -13,7 +13,7 @@ ms.localizationpriority: Normal
# Create Surface Hub 2S device account
Creating a Surface Hub device account (also known as a Room mailbox) allows Surface Hub 2S to receive, approve or decline meeting requests as well as join meetings using Microsoft Teams or Skype for Business. Configure the device account during OOBE setup. If needed you can changed it later (without going through OOBE setup).
Creating a Surface Hub device account (also known as a Room mailbox) allows Surface Hub 2S to receive, approve, or decline meeting requests as well as join meetings using Microsoft Teams or Skype for Business. Configure the device account during OOBE setup. If needed you can changed it later (without going through OOBE setup).
Unlike standard Room mailboxes that remain disabled by default, youll need to enable the Surface Hub 2S device account to sign on to Microsoft Teams and Skype for Business. Surface Hub 2S relies on Exchange ActiveSync, which requires an ActiveSync mailbox policy on the device account. Apply the default ActiveSync mailbox policy that comes with Exchange Online.
@ -30,17 +30,22 @@ For more information, see [Configure Surface Hub 2S accounts via PowerShell].
1. In the Office 365 Admin portal, go to Resources and choose Rooms & Equipment.
2. Provide a name and email address for the device account. Leave remaining settings unchanged in the default state.
![Provide a name and email address](images/sh2-account2.png)
![Leave remaining settings unchanged in the default state](images/sh2-account3.png)
3. Set the password for the device account. Ensure you **do not** select the option **Make this user change their password when they first sign in.**
![Set the password for the device account](images/sh2-account4.png)
4. Assign the room with an Office 365 license. Its recommended to assign the Office 365 **Meeting Room** license, a new option that automatically enables the account for Skype for Business Online and Microsoft Teams.
![Assign Office 365 license](images/sh2-account5.png)
## Finalize setup via PowerShell
- **Skype for Business.** If you did not choose an Office 365 Meeting Room license, you can enable the Skype for Business object by running Enable-CsMeetingRoom.
- **Calling features.** Regardless of your Office 365 licensing configuration, run Enable-CsMeetingRoom to enable features such as **Meeting room prompt for audio** and **Lobby hold**.
- **Calendar.** Set **Calendar Auto processing** for this account.<br><br>
For more information, see [Configure Surface Hub 2S accounts via PowerShell.](devices\surface-hub\surface-hub-2s-configure-using-o365.md)
- **Skype for Business:** If you did not choose an Office 365 Meeting Room license, you can enable the Skype for Business object by running *Enable-CsMeetingRoom*.
- **Calling features:** Regardless of your Office 365 licensing configuration, run *Enable-CsMeetingRoom* to enable features such as **Meeting room prompt for audio** and **Lobby hold**.
- **Calendar:** Set **Calendar Auto processing** for this account.
For more information, see [Configure Surface Hub 2S accounts via PowerShell.](devices\surface-hub\surface-hub-2s-configure-using-o365.md)

View File

@ -38,9 +38,9 @@ Set-Msoluser -UserPrincipalName account@YourDomain.com -UsageLocation IE
Set-MsolUserLicense -UserPrincipalName "account@YourDomain.com" -AddLicenses "contoso:MEETING_ROOM"
```
# Connect to Skype for Business Online using PowerShell
## Connect to Skype for Business Online using PowerShell
**Install prerequisites**
### Install prerequisites
- [Visual C++ 2017 Redistributable](https://aka.ms/vs/15/release/vc_redist.x64.exe)
- [Skype for Business Online PowerShell Module](https://www.microsoft.com/en-us/download/confirmation.aspx?id=39366)

View File

@ -10,25 +10,23 @@ audience: Admin
ms.topic: article
ms.localizationpriority: Normal
---
# Deploy apps to Surface Hub 2S using Intune
You can deploy Universal Windows Platform (UWP) apps to Surface Hub 2S using Intune, easing app deployment to devices.
1. To deploy apps, enable MDM for your organization. In the Intune portal, select **Intune** as your MDM Authority (recommended).
![Choose MDM authority](images/sh2-set-intune5.png)<br>
![Choose MDM authority](images/sh2-set-intune5.png)
2. Enable the Microsoft Store for Business in Intune.
![Enable Store for Business](images/sh2-set-intune6.png)<br>
![Enable Store for Business](images/sh2-set-intune6.png)
3. Open the store from the Intune portal and click **Settings** > **Distribute** > **Management tools**. Choose **Microsoft Intune** as your management tool.
![Add Intune as your management tool](images/sh2-set-intune8.png)<br>
![Add Intune as your management tool](images/sh2-set-intune8.png)
4. In **Settings** > **Shop** > **Shopping Experience**, turn on **Show offline apps**.
Offline apps refer to apps that can be synced to Intune and centrally deployed to a device.
4. In **Settings** > **Shop** > **Shopping Experience**, turn on **Show offline apps**. Offline apps refer to apps that can be synced to Intune and centrally deployed to a device.
5. After enabling Offline shopping, acquire offline licenses for apps, which you can sync to Intune and deploy as Device licensing.

View File

@ -13,61 +13,51 @@ ms.localizationpriority: Normal
# Surface Hub 2S deployment checklist
#
##Pre-deployment checklist
| **Item** | **Response** | **Learn more** |
| ----------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Device account name** | | |
| **Device account UPN** | | |
| **ActiveSync Policy** | | |
| **Calendar processing configuration completed** | - Yes<br>- No | |
| **Device friendly name** | | |
| **Device host name** | | |
| **Affiliation** | - None<br>- Active Directory affiliation<br>- Azure Active Directory | |
| **Microsoft Teams Mode** | - Mode 0<br>- Mode 1<br>- Mode 2 | |
| **Device Management** | - Yes, Microsoft Intune<br>- Yes, other mobile device manager [MDM]<br>- None | |
| **Proxy** | - Automatic configuration<br>- Proxy server<br>- Proxy auto-config (PAC) file | |
| **Proxy authentication** | - Device account credentials<br>- Prompt for credentials | |
| **Password rotation** | - On<br>- Off | |
| **Skype for Business additional domain names (on-premises only)** | | |
| **Session timeout time** | | |
| **Session timeout action** | - End session<br>- Allow resume | |
| **My meetings and files** | - Enabled<br>- Disabled | |
| **Lock screen timeout** | | |
| **Sleep idle timeout** | | |
| **Bluetooth** | - On<br>- Off | |
| **Use only BitLocker USB drives** | - On<br>- Off | |
| **Install additional certificates (on-premises only)** | | [Using certificates for AADJ on-premises single-sign on](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert) |
| **Windows update** | - Windows Update for Business<br>- Windows Server Update Services [WSUS] | [Deploy updates using Windows Update for Business](https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb)<br> <br> <br> <br>[Get Started with Windows Server Update Services (WSUS)](https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) |
| **Surface app speaker setting** | - Rolling stand<br>- Wall-mounted | |
| **IP Address** | - Wired - DHCP<br>- Wired - DHCP reservation<br>- Wireless DHCP<br>- Wireless DHCP reservation | |
## Surface Hub 2S pre-deployment checklist
|**Item**|**Response**| **Learn more**|
|:------ |:----- |:------ |
|**Device account name**| | |
|**Device account UPN**| | |
|**ActiveSync Policy**| | |
|**Calendar processing configuration completed**| - Yes <br> - No | |
|**Device friendly name**| | |
|**Device host name**| | |
|**Affiliation**| - None <br> - Active Directory affiliation <br> - Azure Active Directory | |
|**Microsoft Teams Mode**| - Mode 0 <br> - Mode 1 <br> - Mode 2 | |
|**Device Management**| - Yes, Microsoft Intune <br> - Yes, other mobile device manager [MDM] <br> - None | |
|**Proxy**| - Automatic configuration <br> - Proxy server <br> - Proxy auto-config (PAC) file | |
|**Proxy authentication**| - Device account credentials <br> - Prompt for credentials | |
|**Password rotation**| - On <br> - Off | |
|**Skype for Business additional domain names (on-premises only)**| | |
|**Session timeout time**| | |
|**Session timeout action**| - End session <br> - Allow resume | |
|**My meetings and files**| - Enabled <br> - Disabled | |
|**Lock screen timeout**| | |
|**Sleep idle timeout**| | |
|**Bluetooth**| - On <br> - Off | |
|**Use only BitLocker USB drives**| - On <br> - Off | |
|**Install additional certificates (on-premises only)**| | [Using certificates for AADJ on-premises single-sign on](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert) |
|**Windows update**| - Windows Update for Business <br> - Windows Server Update Services [WSUS] | [Deploy updates using Windows Update for Business](https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb) <br> [Get Started with Windows Server Update Services (WSUS)](https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) |
|**Surface app speaker setting**| - Rolling stand <br> - Wall-mounted | |
|**IP Address**| - Wired - DHCP <br> - Wired - DHCP reservation <br> - Wireless DHCP <br> - Wireless DHCP reservation | |
## Surface Hub 2S post-deployment checklist
| **Item** | **Response** | **Learn more** |
| ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------- |
| **Device account syncing** | - Yes<br>- No | |
| **Bitlocker key** | - Saved to file (no affiliation)<br>- Saved in Active Directory (AD affiliation)<br>- Saved in Azure AD ( Azure AD affiliation) | |
| **Device OS updates** | - Completed | |
| **Windows Store updates** | - Automatic<br>- Manual | |
| **Microsoft Teams scheduled meeting** | - Confirmation email received<br>- Meeting appears on start screen<br>- One-touch join functions<br>- Able to join audio<br>- Able to join video<br>- Able to share screen | |
| **Skype for Business scheduled meeting** | - Confirmation email received<br>- Meeting appears on start screen<br>- One-touch join functions correctly<br>- Able to join audio<br>- Able to join video<br>- Able to share screen<br>- Able to send/receive IM | |
| **Scheduled meeting when already invited** | - Meeting declined | |
| **Microsoft Teams ad-hoc meeting** | - Invite other users work<br>- Able to join audio<br>- Able to join Video<br>- Able to share screen | |
| **Skype for Business scheduled meeting** | - Invite other users work<br>- Able to join audio<br>- Able to join video<br>- Able to share screen<br>- Able to send/receive IM | |
| **Microsoft Whiteboard** | - Launch from start / welcome screen<br>- Launch from Microsoft Teams | [Microsoft Whiteboard](https://whiteboard.microsoft.com/) |
| **Incoming Skype/Teams call** | - Able to join audio<br>- Able to join video<br>- Able to share screen<br>- Able to send/receive IM (Skype for Business only) | |
| **Incoming live video streams** | - Maximum 2 (Skype for Business)<br>- Maximum 4 (Microsoft Teams) | |
| **Microsoft Teams Mode 0 behavior** | - Skype for Business tile on Welcome/Start screen<br>- Can join scheduled Skype for Business meetings (Skype UI)<br>- Can join scheduled Teams meetings (Teams UI) | |
| **Microsoft Teams Mode 1 behavior** | - Teams tile on Welcome/Start screen<br>- Can join scheduled Skype for Business meetings (Skype UI)<br>- Can join scheduled Teams meetings (Teams UI) | |
| **Microsoft Teams Mode 2 behavior** | - Teams tile on welcome / start screen<br>- Can join scheduled Teams meetings<br>- Fail to join Skype for Business meetings | |
|**Item**|**Response**|**Learn more**|
|:-------|:---------|:----------|
|**Device account syncing**| - Yes <br> - No | |
|**Bitlocker key**| - Saved to file (no affiliation) <br> - Saved in Active Directory (AD affiliation) <br>- Saved in Azure AD ( Azure AD affiliation) | |
|**Device OS updates**| - Completed | |
|**Windows Store updates**| - Automatic <br> - Manual | |
|**Microsoft Teams scheduled meeting**| - Confirmation email received <br> - Meeting appears on start screen <br> - One-touch join functions <br> - Able to join audio <br> - Able to join video <br> - Able to share screen | |
|**Skype for Business scheduled meeting**| - Confirmation email received <br> - Meeting appears on start screen <br> - One-touch join functions correctly <br> - Able to join audio <br> - Able to join video <br> - Able to share screen <br> - Able to send/receive IM | |
|**Scheduled meeting when already invited**| - Meeting declined | |
|**Microsoft Teams ad-hoc meeting**| - Invite other users work <br> - Able to join audio <br> - Able to join Video <br> - Able to share screen | |
|**Skype for Business scheduled meeting**| - Invite other users work <br> - Able to join audio <br> - Able to join video <br> - Able to share screen <br> - Able to send/receive IM | |
|**Microsoft Whiteboard**| - Launch from start / welcome screen <br> - Launch from Microsoft Teams | [Microsoft Whiteboard](https://whiteboard.microsoft.com/) |
|**Incoming Skype/Teams call**| - Able to join audio<br>- Able to join video <br> - Able to share screen <br> - Able to send/receive IM (Skype for Business only) | |
|**Incoming live video streams**| - Maximum 2 (Skype for Business) <br> - Maximum 4 (Microsoft Teams) | |
|**Microsoft Teams Mode 0 behavior**| - Skype for Business tile on Welcome/Start screen <br> - Can join scheduled Skype for Business meetings (Skype UI) <br> - Can join scheduled Teams meetings (Teams UI) | |
|**Microsoft Teams Mode 1 behavior**| - Teams tile on Welcome/Start screen <br> - Can join scheduled Skype for Business meetings (Skype UI) <br> - Can join scheduled Teams meetings (Teams UI) | |
|**Microsoft Teams Mode 2 behavior**| - Teams tile on welcome / start screen <br> - Can join scheduled Teams meetings <br> - Fail to join Skype for Business meetings | |

View File

@ -39,22 +39,29 @@ In Windows Configuration Designer, go to the Configure proxy settings tab and en
> When configuring proxy settings, turn off **Automatically detect settings** if you intend to use a setup script or a proxy server. You can use a setup script *or* a proxy server, not both.
### Affiliate Surface Hub 2S with Azure Active Directory
You can affiliate Surface Hub 2S with Azure Active Directory using a provisioning package:
As an Azure Active Directory Global Administrator, you can join large numbers of new Windows devices to Azure Active Directory and Intune using a bulk token.
To create a bulk token, give it a friendly name, configure the expiration date (maximum of 30 days) and use your Admin credentials to acquire the token as shown below:
![Set up device admins](images/sh2-token.png) <br>
![Set up device admins](images/sh2-token2.png)<br>
![Set up device admins](images/sh2-token3.png) <br>
![Set up device admins](images/sh2-token.png) <br><br>
![Set up device admins](images/sh2-token2.png) <br><br>
![Set up device admins](images/sh2-token3.png) <br><br>
### Provisioning multiple devices (.csv file)
In addition to the provisioning package, you can use a Surface Hub configuration file to make it even easier to set up your devices. A Surface Hub configuration file contains a list of device accounts and friendly names for wireless projection. During first run, youll get an option to choose a device account and friendly name from a configuration file.
### To create a Surface Hub configuration file
1. Using Microsoft Excel or another CSV editor, create a CSV file named: **SurfaceHubConfiguration.csv**
2. Enter a list of device accounts and friendly names in this format: **<DeviceAccountName>,<DeviceAccountPassword>,<FriendlyName>**
2. Enter a list of device accounts and friendly names in this format:
```
<DeviceAccountName>,<DeviceAccountPassword>,<FriendlyName>
```
3. Save the file to the root of the USB thumb drive where you copied the PPKG file.
![Configuration file example](images/sh2-config-file.png)
![Configuration file example](images/sh2-config-file.png)

View File

@ -14,45 +14,48 @@ ms.localizationpriority: Normal
# Manage Surface Hub 2S with Intune
## Register Surface Hub 2S with Intune
Surface Hub 2S allows IT administrators to manage settings and policies using a mobile device management (MDM) provider. Surface Hub 2S has a built-in management component to communicate with the management server, so there is no need to install additional clients on the device.
**Manual registration**
### Manual registration
1. Sign in as a local administrator on Surface Hub 2S and open the **Settings** app. Click **Surface Hub** > **Device management** and then click **+** to add.
2. After authenticating, the device will automatically register with Intune.
![Register Surface Hub 2S with Intune](images/sh2-set-intune1.png)<br>
*Figure 1. Register Surface Hub 2S with Intune*<br> <br>
**Auto registration — Azure Active Directory Affiliated**
### Auto registration — Azure Active Directory Affiliated
When affiliating Surface Hub 2S with a tenant that has Intune auto enrollment enabled, the device will automatically enroll with Intune.
## Windows 10 Team Edition settings
Select Windows 10 Team for preset device restriction settings for Surface Hub and Surface Hub 2S.
![Set device restrictions for Surface Hub 2S.](images/sh2-set-intune3.png) <br>
*Figure 2. Set device restrictions for Surface Hub 2S* <br> <br>
These settings include user experience and app behavior, Azure Log Analytics registration, Maintenance windows configuration, Session settings and Miracast settings.
## Additional supported configuration service providers
For a list of all available configuration service providers (CSPs), see [SurfaceHub CSP](https://docs.microsoft.com/en-us/windows/client-management/mdm/surfacehub-csp).
**Quality of Service (QoS) settings**
### Quality of Service (QoS) settings
To ensure optimal video and audio quality on Surface Hub 2S, add the following QoS settings to the device. The settings are identical for Skype for Business and Teams.
| Name | Description | OMA-URI | Type | Value |
| ----------- | ------------------- | ----------------------------------------------------------------------- | ------- | ----------- |
|:----------- |:------------------- |:----------------------------------------------------------------------- |:------- |:----------- |
| Audio Ports | Audio Port range | ./Device/Vendor/MSFT/NetworkQoSPolicy/HubAudio/SourcePortMatchCondition | String | 50000-50019 |
| Audio DSCP | Audio ports marking | ./Device/Vendor/MSFT/NetworkQoSPolicy/HubAudio/DSCPAction | Integer | 46 |
| Video Ports | Video Port range | ./Device/Vendor/MSFT/NetworkQoSPolicy/HubVideo/SourcePortMatchCondition | String | 50020-50039 |
| Video DSCP | Video ports marking | ./Device/Vendor/MSFT/NetworkQoSPolicy/HubVideo/DSCPAction | Integer | 34 |
> [!NOTE]
> These are the default port ranges. Administrators may change the port ranges in the Skype for Business and Teams control panel.
**Microsoft Teams Mode settings**
### Microsoft Teams Mode settings
You can set the Microsoft Teams app mode using Intune. Surface Hub 2S comes installed with Microsoft Teams in mode 0, which supports both Microsoft Teams and Skype for Business. You can adjust the modes as shown below.
Modes:
@ -64,9 +67,6 @@ Modes:
To set modes, add the following settings to a custom Device Configuration Profile.
| Name | Description | OMA-URI | Type | Value |
| -------------- | ----------- | --------------------------------------------------------- | ------- | ----------------------------------------------------------- |
|:-------------- |:----------- |:--------------------------------------------------------- |:------- |:----------------------------------------------------------- |
| Teams App ID | App name | ./Vendor/MSFT/SurfaceHub/Properties/VtcAppPackageId | String | Microsoft.MicrosoftTeamsforSurfaceHub_8wekyb3d8bbwe!Teams­­ |
| Teams App Mode | Teams mode | ./Vendor/MSFT/SurfaceHub/Properties/SurfaceHubMeetingMode | Integer | 0 or 1 or 2 |
#

View File

@ -10,6 +10,7 @@ audience: Admin
ms.topic: article
ms.localizationpriority: Normal
---
# Configure Surface Hub 2S on-premises accounts with PowerShell
## Connect to Exchange Server PowerShell
@ -22,7 +23,6 @@ ms.localizationpriority: Normal
$ExchSession = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri http://$ExchServer/PowerShell/ -Authentication Kerberos -Credential (Get-Credential)
Import-PSSession $ExchSession
```
```PowerShell
$ExchServer = Read-Host "Please Enter the FQDN of your Exchange Server"
@ -51,7 +51,7 @@ Set-CalendarProcessing -Identity "HUB01@contoso.com" -AutomateProcessing AutoAcc
Enable-CsMeetingRoom -Identity Contoso\HUB01 -SipAddressType emailaddress -RegistrarPool SfbIEFE01.contoso.local
```
# Mobile Device Mailbox Policy
## Mobile Device Mailbox Policy
You may need to create a new Mobile Device Mailbox Policy (also known as ActiveSync Policy) to allow your Surface Hub to connect to your online or on-premises environment.

View File

@ -15,20 +15,20 @@ ms.localizationpriority: Normal
Phone authentication for Surface Hub simplifies signing-in to your meetings and files on Surface Hub.
**To set up phone authentication:**
## To set up phone authentication
1. Download the [Microsoft Authenticator](https://www.microsoft.com/en-us/account/authenticator) app for iPhone or Android to your phone.
2. From your PC, go to [https://aka.ms/MFASetup](https://aka.ms/MFASetup) , sign in with your account, and click **Next.**
3. In the Additional security verification screen, select Mobile App and Use verification code, and then click Setup.
**To configure mobile app:**
## To configure mobile app
1. In the Microsoft authenticator app on your phone, add an account, choose **Work or School Account**, and then scan the QR code displayed on your PC
2. Send a notification to your phone and then approve the sign-in request.
3. In the Authenticator app on your phone, use the drop-down menu next to your account and select **Enable phone sign-in**.
4. If required, register your device with your organization and follow the on-screen instructions.
**To sign into Surface Hub:**
## To sign into Surface Hub
1. On Surface Hub, sign into **My meetings and files** and click **Send notification** when prompted.
2. Match the number displayed on your phone with the number displayed on Surface Hub to approve your sign-in request.

View File

@ -22,7 +22,7 @@ The figure below shows the location of ports and physical buttons located on a k
## Port and keypad component reference
| Key | Component | Description | Key parameters |
| --- | --------- | ----------- | -------------- |
|:--- |:--------- |:----------- |:-------------- |
| 1 | **USB C** | **USB 3.1 Gen 1** <br> Use as a walk-up port for plugging in peripherals such as thumb-drives. Guest ports are located on each side of the device (4).<br> <br> *NOTE: This is the recommended port for connecting an external camera. Additional camera mount features are incorporated into the design to help support retention of attached cameras.*<br> <br> NOTE: TouchBack and video ingest are not supported on these ports. | Type C <br> <br> 15 W Port (5V/3A) |
| 2 | **AC power** | **100-240V input** <br> Connect to standard AC power and Surface Hub 2S will auto switch to the local power standard such as110 volts in the US and Canada or 220 volts in the UK. <br> <br> *NOTE: When the AC cord is plugged in, the system remains in an off state in which only the system management controller (SMC), real time clock (RTC), and keypad are running.* | IEC 60320 C14 |
| 3 | **DC power** | **24V DC input port** <br> Use for connecting to mobile battery. | Xbox1 Dual barrel to Anderson connector |
@ -42,6 +42,6 @@ The figure below shows the location of ports and physical buttons located on a k
Surface Hub 2S consists of two primary system components:
| Component | Functionality |
| --------- | ------------- |
|:--------- |:------------- |
| **Video board** | - Produces the image on the LCD display. <br> - Provides an audio/video connection path to/from the compute module. <br> - Provides video scaling to support external video sources. <br> - Performs color correction and calibration. <br> - Responsible for power management, including occupancy sensors and device power states. <br> - Monitors and manages all thermal sensors throughout the device. <br> - Performs internal diagnostics. <br> - Captures diagnostics, error logs and telemetry for all components not connected to the compute module. <br> - Controls the behavior of keypad buttons. <br> - Provides an on-screen display for control of video source, brightness, and volume. |
| **Compute module** | Connects to and controls all USB devices. <br> - Provides video board interconnections for USB, DisplayPort, HDMI, PCIe. <br> - Provides Ethernet access via wired and wireless interfaces. <br> Provides the on-screen audio/video content. <br> - Ingests audio/video provided by external sources. <br> - Allows video to be passed directly to the video board (bypassing the ingest process) for scenarios in which an external source is HDCP encrypted or is beyond the capability of the ingest subsystem. <br> - Provides digital audio output for accessibility and room audio systems respectively (USB dongle support only). |

View File

@ -16,7 +16,7 @@ ms.localizationpriority: Normal
## General specs
| Item | Details |
| ---- | ------- |
|:---- |:------- |
| **Size** | 29.2" x 43.2" x 3.0” (741 mm x 1097 mm x 76 mm) |
| **Weight** | 61.6 lbs. (28 kg) |
| **Resolution** | 3840 x 2560 |
@ -37,7 +37,7 @@ ms.localizationpriority: Normal
## Pen tech specs
| Item | Details |
| ---- | ------- |
|:---- |:------- |
| **Dimensions** | 5.94" x 0.64" x 0.56” (151 mm x 16.3 mm x 14.3 mm) |
| **Weight** | 0.09 lbs. (41g) |
| **Buttons** | Barrel button and tail eraser |
@ -49,7 +49,7 @@ ms.localizationpriority: Normal
## Camera tech specs
| Item | Specification Details |
| ---- | --------------------- |
|:---- |:--------------------- |
|**Dimensions** | 2.26" x 2.18" x 1.65” (57.5 mm x 55.3 mm x 42 mm) |
|**Weight** | 0.19 lbs. (88.01 g) |
| **Connection** | USB-C (with magnetic attach) |
@ -63,7 +63,7 @@ ms.localizationpriority: Normal
> The optional mobile battery is sold separately. For more information, see [APC Charge Mobile Battery](https://www.apc.com/us/en/campaign/apc-charge-mobile-battery-for-microsoft-surface-hub-2.jsp).
| Item | Details |
| ---- | ------- |
|:---- |:------- |
| **Dimensions** | 11 x 17 x 5 inches (282 x 432 x 127 mm) |
| **Weight** | ~30 lbs. (13.6 kg) |
| **Connection** | AC input/DC output & USB-A |

View File

@ -29,7 +29,7 @@ There are two administrative options you can use to manage SEMM and enrolled Sur
The primary workspace of SEMM is Microsoft Surface UEFI Configurator, as shown in Figure 1. Microsoft Surface UEFI Configurator is a tool that is used to create Windows Installer (.msi) packages or WinPE images that are used to enroll, configure, and unenroll SEMM on a Surface device. These packages contain a configuration file where the settings for UEFI are specified. SEMM packages also contain a certificate that is installed and stored in firmware and used to verify the signature of configuration files before UEFI settings are applied.
![Microsoft Surface UEFI Configurator](images\surface-ent-mgmt-fig1-uefi-configurator.png "Microsoft Surface UEFI Configurator")
![Microsoft Surface UEFI Configurator](images/surface-ent-mgmt-fig1-uefi-configurator.png "Microsoft Surface UEFI Configurator")
*Figure 1. Microsoft Surface UEFI Configurator*
@ -51,7 +51,7 @@ You can download Microsoft Surface UEFI Configurator from the [Surface Tools for
Surface UEFI configuration packages are the primary mechanism to implement and manage SEMM on Surface devices. These packages contain a configuration file of UEFI settings specified during creation of the package in Microsoft Surface UEFI Configurator and a certificate file, as shown in Figure 2. When a configuration package is run for the first time on a Surface device that is not already enrolled in SEMM, it provisions the certificate file in the devices firmware and enrolls the device in SEMM. When enrolling a device in SEMM, you will be prompted to confirm the operation by providing the last two digits of the SEMM certificate thumbprint before the certificate file is stored and the enrollment can complete. This confirmation requires that a user be present at the device at the time of enrollment to perform the confirmation.
![Secure a SEMM configuration package with a certificate](images\surface-ent-mgmt-fig2-securepackage.png "Secure a SEMM configuration package with a certificate")
![Secure a SEMM configuration package with a certificate](images/surface-ent-mgmt-fig2-securepackage.png "Secure a SEMM configuration package with a certificate")
*Figure 2. Secure a SEMM configuration package with a certificate*
@ -64,11 +64,11 @@ After a device is enrolled in SEMM, the configuration file is read and the setti
You can use Surface UEFI settings to enable or disable the operation of individual components, such as cameras, wireless communication, or docking USB port (as shown in Figure 3), and configure advanced settings (as shown in Figure 4).
![Enable or disable devices in Surface UEFI with SEMM](images\surface-ent-mgmt-fig3-enabledisable.png "Enable or disable devices in Surface UEFI with SEMM")
![Enable or disable devices in Surface UEFI with SEMM](images/surface-ent-mgmt-fig3-enabledisable.png "Enable or disable devices in Surface UEFI with SEMM")
*Figure 3. Enable or disable devices in Surface UEFI with SEMM*
![Configure advanced settings in SEMM](images\surface-ent-mgmt-fig4-advancedsettings.png "Configure advanced settings in SEMM")
![Configure advanced settings in SEMM](images/surface-ent-mgmt-fig4-advancedsettings.png "Configure advanced settings in SEMM")
*Figure 4. Configure advanced settings with SEMM*
@ -102,13 +102,13 @@ You can configure the following advanced settings with SEMM:
>[!NOTE]
>When you create a SEMM configuration package, two characters are shown on the **Successful** page, as shown in Figure 5.
![Certificate thumbprint display](images\surface-ent-mgmt-fig5-success.png "Certificate thumbprint display")
![Certificate thumbprint display](images/surface-ent-mgmt-fig5-success.png "Certificate thumbprint display")
*Figure 5. Display of the last two characters of the certificate thumbprint on the Successful page*
These characters are the last two characters of the certificate thumbprint and should be written down or recorded. The characters are required to confirm enrollment in SEMM on a Surface device, as shown in Figure 6.
![Enrollment confirmation in SEMM](images\surface-ent-mgmt-fig6-enrollconfirm.png "Enrollment confirmation in SEMM")
![Enrollment confirmation in SEMM](images/surface-ent-mgmt-fig6-enrollconfirm.png "Enrollment confirmation in SEMM")
*Figure 6. Enrollment confirmation in SEMM with the SEMM certificate thumbprint*
@ -134,7 +134,7 @@ A Surface UEFI reset package is used to perform only one task — to unenroll a
In some scenarios, it may be impossible to use a Surface UEFI reset package. (For example, if Windows becomes unusable on the Surface device.) In these scenarios you can unenroll the Surface device from SEMM through the **Enterprise Management** page of Surface UEFI (shown in Figure 7) with a Recovery Request operation.
![Initiate a SEMM recovery request](images\surface-ent-mgmt-fig7-semmrecovery.png "Initiate a SEMM recovery request")
![Initiate a SEMM recovery request](images/surface-ent-mgmt-fig7-semmrecovery.png "Initiate a SEMM recovery request")
*Figure 7. Initiate a SEMM recovery request on the Enterprise Management page*

View File

@ -77,7 +77,7 @@ Autopilot Reset is a two-step process: trigger it and then authenticate. Once yo
2. Sign in with the admin account credentials. If you created a provisioning package, plug in the USB drive and trigger Autopilot Reset.
>[!IMPORTANT]
>[!IMPORTANT]
>To reestablish Wi-Fi connectivity after reset, make sure the **Connect automatically** box is checked for the device's wireless network connection.
Once Autopilot Reset is triggered, the reset process starts.

View File

@ -1055,6 +1055,7 @@ Prior to deployment of Windows 10, ensure that you complete the tasks listed in
| | Notify the students and faculty about the deployment. |
<p>
### Perform the deployment
Use the Deployment Wizard to deploy Windows 10. The LTI deployment process is almost fully automated: You provide only minimal information to the Deployment Wizard at the beginning of the process. After the wizard collects the necessary information, the remainder of the process is fully automated.

View File

@ -28,7 +28,7 @@ Follow the steps in [Provision PCs with common settings for initial deployment (
1. In the **Account Management** step:
> [!WARNING]
> [!WARNING]
> If you don't create a local administrator account and the device fails to enroll in Active Directory for any reason, you will have to reimage the device and start over. As a best practice, we recommend:
> - Use a least-privileged domain account to join the device to the domain.
> - Create a temporary administrator account to use for debugging or reprovisioning if the device fails to enroll successfully.

View File

@ -1,11 +1,11 @@
---
title: About App-V Package Accelerators (App-V 4.6 SP1)
description: About App-V Package Accelerators (App-V 4.6 SP1)
author: dansimp
author: manikadhiman
ms.assetid: fc2d2375-8f17-4a6d-b374-771cb947cb8c
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.author: manikadhiman
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

0
mdop/appv-v4/g Normal file
View File

0
mdop/appv-v4/i Normal file
View File

View File

@ -1,11 +1,11 @@
---
title: SFTMIME Command Reference
description: SFTMIME Command Reference
author: v-madhi
author: manikadhiman
ms.assetid: a4a69228-9dd3-4623-b773-899d03c0cf10
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: SFTTRAY Command Reference
description: SFTTRAY Command Reference
author: v-madhi
author: manikadhiman
ms.assetid: 6fa3a939-b047-4d6c-bd1d-dfb93e065eb2
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Side-by-side Privatization Failed Dialog Box (App-V 4.6 SP1)
description: Side-by-side Privatization Failed Dialog Box (App-V 4.6 SP1)
author: v-madhi
author: manikadhiman
ms.assetid: bcdb9b82-b53d-4a36-9f5d-71c021d4be28
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Software Audit Report
description: Software Audit Report
author: v-madhi
author: manikadhiman
ms.assetid: 55a49ed2-f331-40d3-add6-8e5fcd6816fd
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Stand-Alone Delivery Scenario for Application Virtualization Clients
description: Stand-Alone Delivery Scenario for Application Virtualization Clients
author: v-madhi
author: manikadhiman
ms.assetid: 7545b468-f58a-4504-a6d5-3c2d303731c4
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Stand-Alone Delivery Scenario Overview
description: Stand-Alone Delivery Scenario Overview
author: v-madhi
author: manikadhiman
ms.assetid: b109f309-f3c1-43af-996f-2a9b138dd171
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Streaming Page
description: Streaming Page
author: v-madhi
author: manikadhiman
ms.assetid: a69a57a0-1bbe-4604-840d-bfa87ec463e1
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Support for Client Reporting over HTTP
description: Support for Client Reporting over HTTP
author: v-madhi
author: manikadhiman
ms.assetid: 4a26ac80-1fb5-4c05-83de-4d06793f7bf2
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: SXS Conflict Detected Dialog Box (App-V 4.6 SP1)
description: SXS Conflict Detected Dialog Box (App-V 4.6 SP1)
author: v-madhi
author: manikadhiman
ms.assetid: 7cbb67ba-cc11-4f10-b903-4a6af233eacb
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: System Error Report
description: System Error Report
author: v-madhi
author: manikadhiman
ms.assetid: 4081db2f-92a6-4928-a26b-757048159094
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: System Utilization Report
description: System Utilization Report
author: v-madhi
author: manikadhiman
ms.assetid: 4d490d15-2d1f-4f2c-99bb-0685447c0672
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Target OS Page
description: Target OS Page
author: v-madhi
author: manikadhiman
ms.assetid: 003fd992-0a7e-494e-9e75-4dd5e0927e15
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Tasks for the Application Virtualization Sequencer (App-V 4.6 SP1)
description: Tasks for the Application Virtualization Sequencer (App-V 4.6 SP1)
author: v-madhi
author: manikadhiman
ms.assetid: 58597af9-6a62-4588-ab41-dbf6b7026267
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Tasks for the Application Virtualization Sequencer
description: Tasks for the Application Virtualization Sequencer
author: v-madhi
author: manikadhiman
ms.assetid: 398018f4-297a-440d-b614-23f0ab03e7bd
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Troubleshooting Application Virtualization Sequencer Issues
description: Troubleshooting Application Virtualization Sequencer Issues
author: v-madhi
author: manikadhiman
ms.assetid: 2712094b-a0bc-4643-aced-5415535f3fec
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Troubleshooting Certificate Permission Issues
description: Troubleshooting Certificate Permission Issues
author: v-madhi
author: manikadhiman
ms.assetid: 06b8cbbc-93fd-44aa-af39-2d780792d3c3
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Troubleshooting Information for the Application Virtualization Client
description: Troubleshooting Information for the Application Virtualization Client
author: v-madhi
author: manikadhiman
ms.assetid: 260a8dad-847f-4ec0-b7dd-6e6bc52017ed
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Troubleshooting Information for the Application Virtualization Server
description: Troubleshooting Information for the Application Virtualization Server
author: v-madhi
author: manikadhiman
ms.assetid: e9d43d9b-84f2-4d1b-bb90-a13740151e0c
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Troubleshooting the Application Virtualization Sequencer
description: Troubleshooting the Application Virtualization Sequencer
author: v-madhi
author: manikadhiman
ms.assetid: 12ea8367-0b84-44e1-a885-e0539486556b
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Type of Application Page (Learn More)
description: Type of Application Page (Learn More)
author: v-madhi
author: manikadhiman
ms.assetid: d1262d16-7b14-441e-8500-7974bf68d196
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: UNLOAD APP
description: UNLOAD APP
author: v-madhi
author: manikadhiman
ms.assetid: f0d729ae-8772-498b-be11-1a4b35499c53
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: UNLOAD PACKAGE
description: UNLOAD PACKAGE
author: v-madhi
author: manikadhiman
ms.assetid: a076eb5a-ce3d-49e4-ac7a-4d4df10e3477
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: UNLOCK APP
description: UNLOCK APP
author: v-madhi
author: manikadhiman
ms.assetid: 91fc8ceb-b4f5-4a06-8193-05189f830943
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: UNPUBLISH PACKAGE
description: UNPUBLISH PACKAGE
author: v-madhi
author: manikadhiman
ms.assetid: 1651427c-72a5-4701-bb57-71e14a7a3803
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: User Access Permissions in Application Virtualization Client
description: User Access Permissions in Application Virtualization Client
author: v-madhi
author: manikadhiman
ms.assetid: 7459374c-810c-45e3-b205-fdd1f8514f80
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Using Application Virtualization Servers as a Package Management Solution
description: Using Application Virtualization Servers as a Package Management Solution
author: v-madhi
author: manikadhiman
ms.assetid: 41597355-e7bb-45e2-b300-7b1724419975
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Using Electronic Software Distribution as a Package Management Solution
description: Using Electronic Software Distribution as a Package Management Solution
author: v-madhi
author: manikadhiman
ms.assetid: 7d96ea70-3e7e-49fa-89cc-586804a10657
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Verify Applications Page (Package Accelerators)
description: Verify Applications Page (Package Accelerators)
author: v-madhi
author: manikadhiman
ms.assetid: e58a37db-d042-453f-aa0d-2f324600a35b
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Virtual Application Package Additional Components
description: Virtual Application Package Additional Components
author: v-madhi
author: manikadhiman
ms.assetid: 476b0f40-ebd6-4296-92fa-61fa9495c03c
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Virtual File System Tab
description: Virtual File System Tab
author: v-madhi
author: manikadhiman
ms.assetid: 9d084e2a-720d-4a25-9cd5-d0d70868b413
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Virtual Registry Tab
description: Virtual Registry Tab
author: v-madhi
author: manikadhiman
ms.assetid: 25833383-24c4-40a1-b34c-73b2bd3f11e1
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Virtual Services Tab
description: Virtual Services Tab
author: v-madhi
author: manikadhiman
ms.assetid: 9fc4679d-ccb5-4df7-99de-dd7d3a367ecc
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: Wizard Pages (AppV 4.6 SP1)
description: Wizard Pages (AppV 4.6 SP1)
author: v-madhi
author: manikadhiman
ms.assetid: dadab8cf-fe6d-4cff-8f6c-e9676f244872
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

View File

@ -1,11 +1,11 @@
---
title: About App-V 5.0 Dynamic Configuration
description: About App-V 5.0 Dynamic Configuration
author: v-madhi
author: manikadhiman
ms.assetid: 88afaca1-68c5-45c4-a074-9371c56b5804
ms.reviewer:
manager: dansimp
ms.author: v-madhi
ms.author: dansimp
ms.pagetype: mdop, appcompat, virtualization
ms.mktglfcycl: deploy
ms.sitesec: library

Some files were not shown because too many files have changed in this diff Show More