BitLocker | |
---|---|
Description: | Checks if BitLocker is enabled on the system drive. |
Value: | Protection On |
Condition: | Optimal |
Guidance: | It is highly recommended to enable BitLocker to protect your data. |
Secure Boot | |
---|---|
Description: | Checks if Secure Boot is enabled. |
Value: | True |
Condition: | Optimal |
Guidance: | It is highly recommended to enable Secure Boot to protect your PC. |
Trusted Platform Module | |
---|---|
Description: | Ensures that the TPM is functional. |
Value: | True |
Condition: | Optimal |
Guidance: | Without a functional TPM, security-based functions such as BitLocker may not work properly. |
Connected Standby | |
---|---|
Description: | Checks if Connected Standby is enabled. |
Value: | True |
Condition: | Optimal |
Guidance: | Connected Standby allows a Surface device to receive updates and notifications while not being used. For best experience, Connected Standby should be enabled. |
Bluetooth | |
---|---|
Description: | Checks if Bluetooth is enabled. |
Value: | Enabled |
Condition: | Optimal |
Guidance: |
Debug Mode | |
---|---|
Description: | Checks if the operating system is in Debug mode. |
Value: | Normal |
Condition: | Optimal |
Guidance: | The debug boot option enables or disables kernel debugging of the Windows operating system. Enabling this option can cause system instability and can prevent DRM (digital rights managemend) protected media from playing. |
Test Signing | |
---|---|
Description: | Checks if Test Signing is enabled. |
Value: | Normal |
Condition: | Optimal |
Guidance: | Test Signing is a Windows startup setting that should only be used to test pre-release drivers. |
Active Power Plan | |
---|---|
Description: | Checks that the correct power plan is active. |
Value: | Balanced |
Condition: | Optimal |
Guidance: | It is highly recommended to use the "Balanced" power plan to maximize productivity and battery life. |
Windows Update | |
---|---|
Description: | Checks if the device is up to date with Windows updates. |
Value: | Microsoft Silverlight (KB4023307), Definition Update for Windows Defender Antivirus - KB2267602 (Definition 1.279.1433.0) |
Condition: | Not Optimal |
Guidance: | Updating to the latest windows makes sure you are on the latest firmware and drivers. It is recommended to always keep your device up to date |
Free Hard Drive Space | |
---|---|
Description: | Checks for low free hard drive space. |
Value: | 66% |
Condition: | Optimal |
Guidance: | For best performance, your hard drive should have at least 10% of its capacity as free space. |
Non-Functioning Devices | |
---|---|
Description: | List of non-functioning devices in Device Manager. |
Value: | |
Condition: | Optimal |
Guidance: | Non-functioning devices in Device Manager may cause unpredictable problems with Surface devices such as, but not limited to, no power savings for the respective hardware component. |
External Monitor | |
---|---|
Description: | Checks for an external monitor that may have compatibility issues. |
Value: | |
Condition: | Optimal |
Guidance: | Check with the original equipment manufacturer for compatibility with your Surface device. |
Security/RequireDeviceEncrption - updated to show it is supported in desktop.
+Security/RequireDeviceEncryption - updated to show it is supported in desktop.
Security/RequireDeviceEncrption - updated to show it is supported in desktop.
+Security/RequireDeviceEncryption - updated to show it is supported in desktop.
Version 1511 GPO keys | Version 1607 GPO keys | -
---|---|
**DeferUpgrade**: *enable/disable*Enabling allows user to set deferral periods for upgrades and updates. It also puts the device on CBB (no ability to defer updates while on the CB branch).**DeferUpgradePeriod**: *0 - 8 months***DeferUpdatePeriod**: *1 – 4 weeks***Pause**: *enable/disable*Enabling will pause both upgrades and updates for a max of 35 days | **DeferFeatureUpdates**: *enable/disable***BranchReadinessLevel**Set device on CB or CBB**DeferFeatureUpdatesPeriodinDays**: *1 - 180 days***PauseFeatureUpdates**: *enable/disable*Enabling will pause Feature updates for a max of 60 days**DeferQualityUpdates**: *Enable/disable***DeferQualityUpdatesPeriodinDays**: *0 - 35 days***PauseQualityUpdates**: *enable/disable*Enabling will pause Quality updates for a max of 35 days**ExcludeWUDrivers**: *enable/disable* |
Version 1511 MDM keys | Version 1607 MDM keys | -
---|---|
**RequireDeferUpgade**: *bool*Puts the device on CBB (no ability to defer updates while on the CB branch).**DeferUpgradePeriod**: *0 - 8 months***DeferUpdatePeriod**: *1 – 4 weeks***PauseDeferrals**: *bool*Enabling will pause both upgrades and updates for a max of 35 days | **BranchReadinessLevel**Set system on CB or CBB**DeferFeatureUpdatesPeriodinDays**: *1 - 180 days***PauseFeatureUpdates**: *enable/disable*Enabling will pause Feature updates for a max of 60 days**DeferQualityUpdatesPeriodinDays**: *0 - 35 days***PauseQualityUpdates**: *enable/disable*Enabling will pause Quality updates for a max of 35 days**ExcludeWUDriversInQualityUpdate**: *enable/disable* |
Capability | Windows 10, version 1511 | Windows 10, version 1607 | -
---|---|---|
Select servicing options: CB or CBB | Not available. To defer updates, all systems must be on the Current Branch for Business (CBB) | Ability to set systems on the Current Branch (CB) or Current Branch for Business (CBB). |
Quality Updates | Able to defer receiving Quality Updates:
| Able to defer receiving Quality Updates:
|
Feature Updates | Able to defer receiving Feature Updates:
| Able to defer receiving Feature Updates:
|
Pause updates |
| Features and Quality Updates can be paused separately.
|
Drivers | No driver-specific controls | Drivers can be selectively excluded from Windows Update for Business. |