mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-27 08:13:39 +00:00
Merge branch 'main' into tfosmark-patch-2
This commit is contained in:
@ -32,6 +32,14 @@ manager: dansimp
|
||||
<!--Policy-->
|
||||
<a href="" id="controlpolicyconflict-mdmwinsovergp"></a>**ControlPolicyConflict/MDMWinsOverGP**
|
||||
|
||||
> [!NOTE]
|
||||
> This setting doesn't apply to the following types of group policies:
|
||||
>
|
||||
> - If they don't map to an MDM policy. For example, firewall policies and account lockout policies.
|
||||
> - If they aren't defined by an ADMX. For example, Password policy - minimum password age.
|
||||
> - If they're in the Windows Update category.
|
||||
> - If they have list entries. For example, the Microsoft Edge CookiesAllowedForUrls policy.
|
||||
|
||||
<!--SupportedSKUs-->
|
||||
|
||||
|Edition|Windows 10|Windows 11|
|
||||
@ -58,9 +66,6 @@ manager: dansimp
|
||||
<!--Description-->
|
||||
This policy allows the IT admin to control which policy will be used whenever both the MDM policy and its equivalent Group Policy (GP) are set on the device.
|
||||
|
||||
> [!NOTE]
|
||||
> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable; not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.
|
||||
|
||||
This policy is used to ensure that MDM policy wins over GP when policy is configured on MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set 1.
|
||||
|
||||
> [!NOTE]
|
||||
|
@ -13,7 +13,7 @@ manager: dansimp
|
||||
audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 03/05/2019
|
||||
ms.date: 05/25/2022
|
||||
ms.reviewer:
|
||||
---
|
||||
|
||||
@ -26,7 +26,7 @@ This list provides all of the tasks and settings that are required for the opera
|
||||
|
||||
|Task|Description|
|
||||
|----|-----------|
|
||||
|Add at least one app to the **Protected apps** list in your WIP policy.|You must have at least one app added to your **Protected apps** list. For more info about where this area is and how to add apps, see the **Add apps to your Protected apps list** section of the policy creation topics.|
|
||||
|Add at least one app of each type (Store and Desktop) to the **Protected apps** list in your WIP policy.|You must have at least one Store app and one Desktop app added to your **Protected apps** list. For more info about where this area is and how to add apps, see the **Add apps to your Protected apps list** section of the policy creation topics. |
|
||||
|Choose your WIP protection level.|You must choose the level of protection you want to apply to your WIP-protected content, including **Allow Overrides**, **Silent**, or **Block**. For more info about where this area is and how to decide on your protection level, see the [Manage the WIP protection mode for your enterprise data](./create-wip-policy-using-configmgr.md#manage-the-wip-protection-level-for-your-enterprise-data) section of the policy creation topics. For info about how to collect your audit log files, see [How to collect Windows Information Protection (WIP) audit event logs](collect-wip-audit-event-logs.md).|
|
||||
|Specify your corporate identity.|This field is automatically filled out for you by Microsoft Intune. However, you must manually correct it if it’s incorrect or if you need to add additional domains. For more info about where this area is and what it means, see the **Define your enterprise-managed corporate identity** section of the policy creation topics.
|
||||
|Specify your network domain names.|Starting with Windows 10, version 1703, this field is optional.<br><br>Specify the DNS suffixes used in your environment. All traffic to the fully-qualified domains appearing in this list will be protected. For more info about where this area is and how to add your suffixes, see the table that appears in the **Choose where apps can access enterprise data** section of the policy creation topics.|
|
||||
|
@ -12,6 +12,7 @@ ms.localizationpriority: high
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.technology: windows-sec
|
||||
adobe-target: true
|
||||
---
|
||||
|
||||
# Microsoft Defender SmartScreen
|
||||
|
Reference in New Issue
Block a user