diff --git a/windows/manage/device-guard-signing-portal.md b/windows/manage/device-guard-signing-portal.md index e9dabd0581..dbdf376f92 100644 --- a/windows/manage/device-guard-signing-portal.md +++ b/windows/manage/device-guard-signing-portal.md @@ -1,6 +1,6 @@ --- title: Device Guard signing (Windows 10) -description: Device Guard signing is a Device Guard feature that is available in the Windows Store for Business. +description: Device Guard signing is a Device Guard feature that is available in the Microsoft Store for Business. ms.assetid: 8D9CD2B9-5FC6-4C3D-AA96-F135AFEEBB78 ms.prod: w10 ms.mktglfcycl: manage @@ -18,37 +18,16 @@ localizationpriority: high - Windows 10 - Windows 10 Mobile -Device Guard signing is a Device Guard feature that is available in the Windows Store for Business. It gives admins a single place to sign catalog files and code integrity policies. After admins have created catalog files for unsigned apps and signed the catalog files, they can add the signers to a code integrity policy. You can merge the code integrity policy with your existing policy to include your custom signing certificate. This allows you to trust the catalog files. +Device Guard signing is a Device Guard feature that is available in Microsoft Store for Business. It gives admins a single place to sign catalog files and code integrity policies. After admins have created catalog files for unsigned apps and signed the catalog files, they can add the signers to a code integrity policy. You can merge the code integrity policy with your existing policy to include your custom signing certificate. This allows you to trust the catalog files. Device Guard is a feature set that consists of both hardware and software system integrity hardening features. These features use new virtualization-based security options and the trust-nothing mobile device operating system model. A key feature in this model is called configurable code integrity, which allows your organization to choose exactly which software or trusted software publishers are allowed to run code on your client machines. Also, Device Guard offers organizations a way to sign existing line-of-business (LOB) applications so that they can trust their own code, without the requirement that the application be repackaged. Also, this same method of signing allows organizations to trust individual third-party applications. For more information, see [Device Guard deployment guide](https://technet.microsoft.com/library/mt463091.aspx). ## In this section - -
Topic | -Description | -
---|---|
[Add unsigned app to code integrity policy](add-unsigned-app-to-code-integrity-policy.md) |
-When you want to add an unsigned app to a code integrity policy, you need to start with a code integrity policy created from a reference device. Then, create the catalog files for your unsigned app, sign the catalog files, and then merge the default policy that includes your signing certificate with existing code integrity policies. |
-
[Sign code integrity policy with Device Guard signing](sign-code-integrity-policy-with-device-guard-signing.md) |
-Signing code integrity policies prevents policies from being tampered with after they're deployed. You can sign code integrity policies with the Device Guard signing portal. |
-
Topic | -Description | -
---|---|
[Distribute apps using your private store](distribute-apps-from-your-private-store.md) |
-The private store is a feature in Store for Business that organizations receive during the sign up process. When admins add apps to the private store, all employees in the organization can view and download the apps. Your private store is available as a tab in the Windows Store, and is usually named for your company or organization. Only apps with online licenses can be added to the private store. |
-
[Assign apps to employees](assign-apps-to-employees.md) |
-Administrators can assign online-licensed apps to employees in their organization. |
-
[Distribute apps with a management tool](distribute-apps-with-management-tool.md) |
-You can configure a mobile device management (MDM) tool to synchronize your Store for Business inventory. Store for Business management tool services work with MDM tools to manage content. |
-
[Distribute offline apps](distribute-offline-apps.md) |
-Offline licensing is a new licensing option for Windows 10. With offline licenses, organizations can download apps and their licenses to deploy within their network, or on devices that are not connected to the Internet. ISVs or devs can opt-in their apps for offline licensing when they submit them to the Windows Dev Center. Only apps that are opted in to offline licensing will show that they are available for offline licensing in the Store for Business. This model means organizations can deploy apps when users or devices do not have connectivity to the Store. |
-
Topic | -Description | -
---|---|
[Apps in the Windows Store for Business](apps-in-windows-store-for-business.md) |
-Store for Business has thousands of apps from many different categories. |
-
[Acquire apps in the Windows Store for Business](acquire-apps-windows-store-for-business.md) |
-You can acquire apps from the Windows Store for Business for your employees. |
-
[Working with line-of-business apps](working-with-line-of-business-apps.md) |
-Your company can make line-of-business (LOB) applications available through Store for Business. These apps are custom to your company – they might be internal business apps, or apps specific to your business or industry. |
-
Topic | -Description | -
---|---|
[Manage access to private store](manage-access-to-private-store.md) |
-You can manage access to your private store in Store for Business. |
-
[App inventory managemement for Windows Store for Business](app-inventory-managemement-windows-store-for-business.md) |
-You can manage all apps that you've acquired on your Inventory page. |
-
[Manage private store settings](manage-private-store-settings.md) |
-The private store is a feature in the Store for Business that organizations receive during the sign up process. When admins add apps to the private store, all employees in the organization can view and download the apps. Only online-licensed apps can be distributed from your private store. |
-
[Configure MDM provider](configure-mdm-provider-windows-store-for-business.md) |
-For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content. |
-
Topic | -Description | -
---|---|
[Update Windows Store for Business account settings](update-windows-store-for-business-account-settings.md) |
-The Account information page in Windows Store for Business shows information about your organization that you can update, including: organization information, payment options, and offline licensing settings. |
-
[Manage user accounts in Windows Store for Business](manage-users-and-groups-windows-store-for-business.md) |
-Store for Business manages permissions with a set of roles. Currently, you can [assign these roles to individuals in your organization](roles-and-permissions-windows-store-for-business.md), but not to groups. |
-
Topic | -Description | -
---|---|
[Windows Store for Business overview](windows-store-for-business-overview.md) |
-Learn about Windows Store for Business. |
-
[Prerequisites for Windows Store for Business](prerequisites-windows-store-for-business.md) |
-There are a few prerequisites for using Store for Business. |
-
[Sign up for Windows Store for Business](sign-up-windows-store-for-business.md) |
-Before you sign up for Store for Business, at a minimum, you'll need an Azure Active Directory (AD) account for your organization, and you'll need to be the global administrator for your organization. If your organization is already using Azure AD, you can go ahead and sign up for Store for Business. If not, we'll help you create an Azure AD account and directory as part of the sign up process. |
-
[Roles and permissions in the Windows Store for Business](roles-and-permissions-windows-store-for-business.md) |
-The first person to sign in to Store for Business must be a Global Admin of the Azure Active Directory (AD) tenant. Once the Global Admin has signed in, they can give permissions to others employees. |
-
[Settings reference: Windows Store for Business](settings-reference-windows-store-for-business.md) |
-The Store for Business has a group of settings that admins use to manage the store. |
-
Topic | -Description | -
---|---|
[Sign up and get started](sign-up-windows-store-for-business-overview.md) |
-IT admins can sign up for the Store for Business, and get started working with apps. |
-
[Find and acquire apps](find-and-acquire-apps-overview.md) |
-Use the Store for Business to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization. |
-
[Distribute apps to your employees from the Windows Store for Business](distribute-apps-to-your-employees-windows-store-for-business.md) |
-Distribute apps to your employees from Store for Business. You can assign apps to employees, or let employees install them from your private store. |
-
[Manage apps](manage-apps-windows-store-for-business-overview.md) |
-Manage settings and access to apps in Store for Business. |
-
[Device Guard signing portal](device-guard-signing-portal.md) |
-Device Guard signing is a Device Guard feature that is available in the Store for Business. It gives admins a single place to sign catalog files and code integrity policies. After admins have created catalog files for unsigned apps and signed the catalog files, they can add the signers to a code integrity policy. You can merge the code integrity policy with your existing policy to include your custom signing certificate. This allows you to trust the catalog files. |
-
[Manage settings in the Windows Store for Business](manage-settings-windows-store-for-business.md) |
-You can add users and groups, as well as update some of the settings associated with the Azure Active Directory (AD) tenant |
-
[Troubleshoot Windows Store for Business](troubleshoot-windows-store-for-business.md) |
-Troubleshooting topics for Store for Business. |
-