diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index b7d977b310..28fdfc24a3 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -10,45 +10,50 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 12/06/2018 +ms.date: 05/15/2019 --- -# What's new in MDM enrollment and management +# What's new in mobile device enrollment and management This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices. -For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). -## In this section +- **What’s new in MDM for Windows 10 versions** + - [What’s new in MDM for Windows 10, version 1903](#whats-new-in-mdm-for-windows-10-version-1903) + - [What’s new in MDM for Windows 10, version 1809](#whats-new-in-mdm-for-windows-10-version-1809) + - [What’s new in MDM for Windows 10, version 1803](#whats-new-in-mdm-for-windows-10-version-1803) + - [What’s new in MDM for Windows 10, version 1709](#whats-new-in-mdm-for-windows-10-version-1709) + - [What’s new in MDM for Windows 10, version 1703](#whats-new-in-mdm-for-windows-10-version-1703) + - [What’s new in MDM for Windows 10, version 1607](#whats-new-in-mdm-for-windows-10-version-1607) + - [What’s new in MDM for Windows 10, version 1511](#whats-new-in-mdm-for-windows-10-version-1511) -- [What's new in MDM enrollment and management](#whats-new-in-mdm-enrollment-and-management) - - [In this section](#in-this-section) - - [What's new in Windows 10, version 1511](#a-href%22%22-id%22whatsnew%22awhats-new-in-windows-10-version-1511) - - [What's new in Windows 10, version 1607](#a-href%22%22-id%22whatsnew1607%22awhats-new-in-windows-10-version-1607) - - [What's new in Windows 10, version 1703](#a-href%22%22-id%22whatsnew10%22awhats-new-in-windows-10-version-1703) - - [What's new in Windows 10, version 1709](#a-href%22%22-id%22whatsnew1709%22awhats-new-in-windows-10-version-1709) - - [What's new in Windows 10, version 1803](#a-href%22%22-id%22whatsnew1803%22awhats-new-in-windows-10-version-1803) - - [What's new in Windows 10, version 1809](#a-href%22%22-id%22whatsnew1809%22awhats-new-in-windows-10-version-1809) - - [Breaking changes and known issues](#breaking-changes-and-known-issues) - - [Get command inside an atomic command is not supported](#a-href%22%22-id%22getcommand%22aget-command-inside-an-atomic-command-is-not-supported) - - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#a-href%22%22-id%22notification%22anotification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) - - [Apps installed using WMI classes are not removed](#a-href%22%22-id%22appsnotremoved%22aapps-installed-using-wmi-classes-are-not-removed) - - [Passing CDATA in SyncML does not work](#a-href%22%22-id%22cdata%22apassing-cdata-in-syncml-does-not-work) - - [SSL settings in IIS server for SCEP must be set to "Ignore"](#a-href%22%22-id%22sslsettings%22assl-settings-in-iis-server-for-scep-must-be-set-to-%22ignore%22) - - [MDM enrollment fails on the mobile device when traffic is going through proxy](#a-href%22%22-id%22enrollmentviaproxy%22amdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) - - [Server-initiated unenrollment failure](#a-href%22%22-id%22unenrollment%22aserver-initiated-unenrollment-failure) - - [Certificates causing issues with Wi-Fi and VPN](#a-href%22%22-id%22certissues%22acertificates-causing-issues-with-wi-fi-and-vpn) - - [Version information for mobile devices](#a-href%22%22-id%22versioninformation%22aversion-information-for-mobile-devices) - - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#a-href%22%22-id%22whitelist%22aupgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) - - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#a-href%22%22-id%22frameworks%22aapps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) - - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#a-href%22%22-id%22wificertissue%22amultiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) - - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#a-href%22%22-id%22remote%22aremote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) - - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#a-href%22%22-id%22renewwns%22amdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) - - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#a-href%22%22-id%22userprovisioning%22auser-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) - - [Requirements to note for VPN certificates also used for Kerberos Authentication](#a-href%22%22-id%22kerberos%22arequirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) - - [Device management agent for the push-button reset is not working](#a-href%22%22-id%22pushbuttonreset%22adevice-management-agent-for-the-push-button-reset-is-not-working) - - [Change history in MDM documentation](#change-history-in-mdm-documentation) +- **Breaking changes and known issues** + - [Get command inside an atomic command is not supported](#get-command-inside-an-atomic-command-is-not-supported) + - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#notification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) + - [Apps installed using WMI classes are not removed](#apps-installed-using-wmi-classes-are-not-removed) + - [Passing CDATA in SyncML does not work](#passing-cdata-in-syncml-does-not-work) + - [SSL settings in IIS server for SCEP must be set to "Ignore"](#ssl-settings-in-iis-server-for-scep-must-be-set-to-ignore) + - [MDM enrollment fails on the mobile device when traffic is going through proxy](#mdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) + - [Server-initiated unenrollment failure](#server-initiated-unenrollment-failure) + - [Certificates causing issues with Wi-Fi and VPN](#certificates-causing-issues-with-wi-fi-and-vpn) + - [Version information for mobile devices](#version-information-for-mobile-devices) + - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#upgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) + - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#apps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) + - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#multiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) + - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#remote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) + - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#mdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) + - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#user-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) + - [Requirements to note for VPN certificates also used for Kerberos Authentication](#requirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) + - [Device management agent for the push-button reset is not working](#device-management-agent-for-the-push-button-reset-is-not-working) + +- **Frequently Asked Questions** + - [Can there be more than 1 MDM server to enroll and manage devices in Windows 10?](#can-there-be-more-than-1-mdm-server-to-enroll-and-manage-devices-in-windows-10) + - [How do I set the maximum number of Azure Active Directory joined devices per user?](#how-do-i-set-the-maximum-number-of-azure-active-directory-joined-devices-per-user) + - [What is dmwappushsvc?](#what-is-dmwappushsvc) + +- **Change history in MDM documentation** - [February 2019](#february-2019) - [January 2019](#january-2019) - [December 2018](#december-2018) @@ -66,10 +71,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s - [October 2017](#october-2017) - [September 2017](#september-2017) - [August 2017](#august-2017) - - [FAQ](#faq) - -## What's new in Windows 10, version 1511 +## What’s new in MDM for Windows 10, version 1903
Item | +New or updated topic | Description |
---|---|---|
New configuration service providers added in Windows 10, version 1511 |
-
|
-|
New and updated policies in Policy CSP |
-The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md): + | |
[Policy CSP](policy-configuration-service-provider.md) | +Added the following new policies in Windows 10, version 1903:
The following policies have been updated in the Policy CSP: -
The following policies have been deprecated in the Policy CSP: -
|
-|
Management tool for the Micosoft Store for Business |
-New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates. |
-|
Custom header for generic alert |
-The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format: -MDM-GenericAlert: <AlertType1><AlertType2>
-If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526). |
-|
Alert message for slow client response |
-When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending. -To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md). |
-|
New node in DMClient CSP |
-Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs. |
-|
New nodes in EnterpriseModernAppManagement CSP |
-Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md): -
|
-|
New nodes in EnterpriseExt CSP |
-Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md): -
|
-|
New node in EnterpriseExtFileSystem CSP |
-Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md). |
-|
New nodes in PassportForWork CSP |
-Added the following nodes to [PassportForWork CSP](passportforwork-csp.md): -
|
-|
Updated EnterpriseAssignedAccess CSP |
-Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md): -
|
-|
New nodes in the DevDetail CSP |
-Here are the changes to the [DevDetail CSP](devdetail-csp.md): -
|
-|
Handling large objects |
-Added support for the client to handle uploading of large objects to the server. |
-
Item | +New or updated topic | Description |
---|---|---|
Sideloading of apps |
-Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices. |
-|
New value for [NodeCache CSP](nodecache-csp.md) |
-In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache. |
-|
[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md) | -New CSP. |
-|
[Policy CSP](policy-configuration-service-provider.md) | -Removed the following policies: + | Added the following new policies in Windows 10, version 1809:
Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607: -
Added the following new policies: -
Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information. -Updated DeliveryOptimization/DODownloadMode to add new values. -Updated Experience/AllowCortana description to clarify what each supported value does. -Updated Security/AntiTheftMode description to clarify what each supported value does. |
+
[PassportForWork CSP](passportforwork-csp.md) | +Added new settings in Windows 10, version 1809. + | |
[EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md) | +Added NonRemovable setting under AppManagement node in Windows 10, version 1809. + | |
[Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md) | +Added new configuration service provider in Windows 10, version 1809. + | |
[WindowsLicensing CSP](windowslicensing-csp.md) | +Added S mode settings and SyncML examples in Windows 10, version 1809. + | |
[SUPL CSP](supl-csp.md) | +Added 3 new certificate nodes in Windows 10, version 1809. + | |
[Defender CSP](defender-csp.md) | +Added a new node Health/ProductStatus in Windows 10, version 1809. + | |
[BitLocker CSP](bitlocker-csp.md) | +Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro. + | |
[DevDetail CSP](devdetail-csp.md) | +Added a new node SMBIOSSerialNumber in Windows 10, version 1809. + | |
[Wifi CSP](wifi-csp.md) | +Added a new node WifiCost in Windows 10, version 1809. + | |
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | +Added new settings in Windows 10, version 1809. + | |
[RemoteWipe CSP](remotewipe-csp.md) | +Added new settings in Windows 10, version 1809. + | |
[TenantLockdown CSP](tenantlockdown-csp.md) | +Added new CSP in Windows 10, version 1809. + | |
[Office CSP](office-csp.md) | +Added FinalStatus setting in Windows 10, version 1809. + |
New or updated topic | +Description | ||
---|---|---|---|
[Policy CSP](policy-configuration-service-provider.md) | +Added the following new policies for Windows 10, version 1803: +
Security/RequireDeviceEncryption - updated to show it is supported in desktop. + | ||
[BitLocker CSP](bitlocker-csp.md) | +Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803. + | ||
[DMClient CSP](dmclient-csp.md) | -Added the following settings: + | Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:
Removed the EnrollmentID setting. |
-|
[DeviceManageability CSP](devicemanageability-csp.md) | -New CSP. |
-||
[DeviceStatus CSP](devicestatus-csp.md) | -Added the following new settings: + | [Defender CSP](defender-csp.md) | +Added new node (OfflineScan) in Windows 10, version 1803. + |
[UEFI CSP](uefi-csp.md) | +Added a new CSP in Windows 10, version 1803. + | ||
[Update CSP](update-csp.md) | +Added the following nodes in Windows 10, version 1803:
|
-||
[AssignedAccess CSP](assignedaccess-csp.md) | -Added SyncML examples. |
-||
[EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md) | -
|
-||
[SecureAssessment CSP](secureassessment-csp.md) | -New CSP for Windows 10, version 1607 |
-||
[DiagnosticLog CSP](diagnosticlog-csp.md)
- [DiagnosticLog DDF](diagnosticlog-ddf.md) |
-Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607. + | Added the following nodes in Windows 10, version 1803:
|
-|
[Reboot CSP](reboot-csp.md) | -New CSP for Windows 10, version 1607 |
-||
[CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md) | -New CSP for Windows 10, version 1607 |
-||
[VPNv2 CSP](vpnv2-csp.md) | -Added the following settings for Windows 10, version 1607 -
|
-||
[Win32AppInventory CSP](win32appinventory-csp.md)
- [Win32AppInventory DDF](win32appinventory-ddf-file.md) |
-New CSP for Windows 10, version 1607. |
-||
[SharedPC CSP](sharedpc-csp.md) | -New CSP for Windows 10, version 1607. |
-||
[WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md) | -New CSP for Windows 10, version 1607. |
-||
[MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224) | -Added new classes for Windows 10, version 1607. |
-||
[MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md) | -Topic renamed from "Enrollment UI". -Completely updated enrollment procedures and screenshots. |
-||
[UnifiedWriteFilter CSP](unifiedwritefilter-csp.md)
- [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md) |
-Added the following new setting for Windows 10, version 1607: -
|
-||
[CertificateStore CSP](certificatestore-csp.md)
- [CertificateStore DDF file](certificatestore-ddf-file.md) |
-Added the following new settings in Windows 10, version 1607: -
|
-||
[WindowsLicensing CSP](windowslicensing-csp.md) |
-Added the following new node and settings in Windows 10, version 1607, but not documented: -
|
-||
[MultiSIM CSP](multisim-csp.md) | +Added a new CSP in Windows 10, version 1803. + | ||
[EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md) | +Added the following node in Windows 10, version 1803: +
| ||
[eUICCs CSP](euiccs-csp.md) | +Added the following node in Windows 10, version 1803: +
| ||
[DeviceStatus CSP](devicestatus-csp.md) | +Added the following node in Windows 10, version 1803: +
| ||
[AccountManagement CSP](accountmanagement-csp.md) | +Added a new CSP in Windows 10, version 1803. + | ||
[RootCATrustedCertificates CSP](rootcacertificates-csp.md) | +Added the following node in Windows 10, version 1803: +
| ||
[NetworkProxy CSP](\networkproxy--csp.md) | +Added the following node in Windows 10, version 1803: +
| ||
[Accounts CSP](accounts-csp.md) | +Added a new CSP in Windows 10, version 1803. + | ||
[MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat) | +Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies. + | ||
[CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download) | +Added the DDF download of Windows 10, version 1803 configuration service providers. + |
Item | +Description | +
---|---|
The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx) | +The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message: +
For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation. + |
[Firewall CSP](firewall-csp.md) | +Added new CSP in Windows 10, version 1709. + |
[eUICCs CSP](euiccs-csp.md) | +Added new CSP in Windows 10, version 1709. + |
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | +New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md). | +
[CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md) | +In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated. | +
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | +New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md). | +
[VPNv2 CSP](vpnv2-csp.md) | +Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709. + |
[DeviceStatus CSP](devicestatus-csp.md) | +Added the following settings in Windows 10, version 1709: +
|
[AssignedAccess CSP](assignedaccess-csp.md) | +Added the following setting in Windows 10, version 1709. +
Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro. + |
[DeviceManageability CSP](devicemanageability-csp.md) | +Added the following settings in Windows 10, version 1709: +
|
[Office CSP](office-csp.md) | +Added the following setting in Windows 10, version 1709: +
|
[DMClient CSP](dmclient-csp.md) | +Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics. + |
[Bitlocker CSP](bitlocker-csp.md) | +Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709. + |
[ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies) | +Added new policies. + |
Microsoft Store for Business and Microsoft Store | +Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store. + | [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md) | +New features in the Settings app: +
For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs) + |
+
[Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md) | +Added new topic to introduce a new Group Policy for automatic MDM enrollment. + |
[Policy CSP](policy-configuration-service-provider.md) | +Added the following new policies for Windows 10, version 1709: +
|
The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx) | -The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message: -
For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation. - | ||
[Firewall CSP](firewall-csp.md) | -Added new CSP in Windows 10, version 1709. - | ||
[eUICCs CSP](euiccs-csp.md) | -Added new CSP in Windows 10, version 1709. - | ||
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | -New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md). | +Sideloading of apps |
+Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices. |
[CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md) | -In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated. | +New value for [NodeCache CSP](nodecache-csp.md) |
+In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache. |
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | -New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md). | +[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md) | +New CSP. |
[VPNv2 CSP](vpnv2-csp.md) | -Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709. - | [Policy CSP](policy-configuration-service-provider.md) | +Removed the following policies: +
Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607: +
Added the following new policies: +
Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information. +Updated DeliveryOptimization/DODownloadMode to add new values. +Updated Experience/AllowCortana description to clarify what each supported value does. +Updated Security/AntiTheftMode description to clarify what each supported value does. |
+
[DeviceStatus CSP](devicestatus-csp.md) | -Added the following settings in Windows 10, version 1709: + | [DMClient CSP](dmclient-csp.md) | +Added the following settings:
|
[AssignedAccess CSP](assignedaccess-csp.md) | -Added the following setting in Windows 10, version 1709. -
Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro. - | ||
[DeviceManageability CSP](devicemanageability-csp.md) | -Added the following settings in Windows 10, version 1709: -
| ||
[Office CSP](office-csp.md) | -Added the following setting in Windows 10, version 1709: -
| ||
[DMClient CSP](dmclient-csp.md) | -Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics. - | ||
[Bitlocker CSP](bitlocker-csp.md) | -Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709. - | ||
[ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies) | -Added new policies. - | ||
Microsoft Store for Business and Microsoft Store | -Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store. - | [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md) | -New features in the Settings app: -
For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs) - |
-
[Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md) | -Added new topic to introduce a new Group Policy for automatic MDM enrollment. - | ||
[Policy CSP](policy-configuration-service-provider.md) | -Added the following new policies for Windows 10, version 1709: -
|
New or updated topic | -Description | +New CSP. |
|
---|---|---|---|
[Policy CSP](policy-configuration-service-provider.md) | -Added the following new policies for Windows 10, version 1803: + | ||
[DeviceStatus CSP](devicestatus-csp.md) | +Added the following new settings:
Security/RequireDeviceEncryption - updated to show it is supported in desktop. + |
||
[BitLocker CSP](bitlocker-csp.md) | -Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803. - | ||
[DMClient CSP](dmclient-csp.md) | -Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803: -
| ||
[Defender CSP](defender-csp.md) | -Added new node (OfflineScan) in Windows 10, version 1803. - | ||
[UEFI CSP](uefi-csp.md) | -Added a new CSP in Windows 10, version 1803. - | ||
[Update CSP](update-csp.md) | -Added the following nodes in Windows 10, version 1803: -
| ||
[AssignedAccess CSP](assignedaccess-csp.md) | -Added the following nodes in Windows 10, version 1803: -
Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition. - | Added SyncML examples. |
+
+|
[EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md) | +
|
+||
[MultiSIM CSP](multisim-csp.md) | -Added a new CSP in Windows 10, version 1803. - | [SecureAssessment CSP](secureassessment-csp.md) | +New CSP for Windows 10, version 1607 |
+
+
[DiagnosticLog CSP](diagnosticlog-csp.md)
+ [DiagnosticLog DDF](diagnosticlog-ddf.md) |
+Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607. +
|
+||
[EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md) | -Added the following node in Windows 10, version 1803: + | [Reboot CSP](reboot-csp.md) | +New CSP for Windows 10, version 1607 |
+
[CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md) | +New CSP for Windows 10, version 1607 |
+||
[VPNv2 CSP](vpnv2-csp.md) | +Added the following settings for Windows 10, version 1607
| ||
[eUICCs CSP](euiccs-csp.md) | -Added the following node in Windows 10, version 1803: + |
+||
[Win32AppInventory CSP](win32appinventory-csp.md)
+ [Win32AppInventory DDF](win32appinventory-ddf-file.md) |
+New CSP for Windows 10, version 1607. |
+||
[SharedPC CSP](sharedpc-csp.md) | +New CSP for Windows 10, version 1607. |
+||
[WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md) | +New CSP for Windows 10, version 1607. |
+||
[MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224) | +Added new classes for Windows 10, version 1607. |
+||
[MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md) | +Topic renamed from "Enrollment UI". +Completely updated enrollment procedures and screenshots. |
+||
[UnifiedWriteFilter CSP](unifiedwritefilter-csp.md)
+ [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md) |
+Added the following new setting for Windows 10, version 1607:
| ||
[DeviceStatus CSP](devicestatus-csp.md) | -Added the following node in Windows 10, version 1803: + |
+||
[CertificateStore CSP](certificatestore-csp.md)
+ [CertificateStore DDF file](certificatestore-ddf-file.md) |
+Added the following new settings in Windows 10, version 1607:
| ||
[AccountManagement CSP](accountmanagement-csp.md) | -Added a new CSP in Windows 10, version 1803. - | ||
[RootCATrustedCertificates CSP](rootcacertificates-csp.md) | -Added the following node in Windows 10, version 1803: + |
+||
[WindowsLicensing CSP](windowslicensing-csp.md) |
+Added the following new node and settings in Windows 10, version 1607, but not documented:
| ||
[NetworkProxy CSP](\networkproxy--csp.md) | -Added the following node in Windows 10, version 1803: -
| ||
[Accounts CSP](accounts-csp.md) | -Added a new CSP in Windows 10, version 1803. - | ||
[MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat) | -Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies. - | ||
[CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download) | -Added the DDF download of Windows 10, version 1803 configuration service providers. - |
New or updated topic | +Item | Description |
---|---|---|
[Policy CSP](policy-configuration-service-provider.md) | -Added the following new policies in Windows 10, version 1809: + | |
New configuration service providers added in Windows 10, version 1511 |
+
|
+|
New and updated policies in Policy CSP |
+The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):
| |
[PassportForWork CSP](passportforwork-csp.md) | -Added new settings in Windows 10, version 1809. - | |
[EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md) | -Added NonRemovable setting under AppManagement node in Windows 10, version 1809. - | |
[Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md) | -Added new configuration service provider in Windows 10, version 1809. - | |
[WindowsLicensing CSP](windowslicensing-csp.md) | -Added S mode settings and SyncML examples in Windows 10, version 1809. - | |
[SUPL CSP](supl-csp.md) | -Added 3 new certificate nodes in Windows 10, version 1809. - | |
[Defender CSP](defender-csp.md) | -Added a new node Health/ProductStatus in Windows 10, version 1809. - | |
[BitLocker CSP](bitlocker-csp.md) | -Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro. - | |
[DevDetail CSP](devdetail-csp.md) | -Added a new node SMBIOSSerialNumber in Windows 10, version 1809. - | |
[Wifi CSP](wifi-csp.md) | -Added a new node WifiCost in Windows 10, version 1809. - | |
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md) | -Added new settings in Windows 10, version 1809. - | |
[RemoteWipe CSP](remotewipe-csp.md) | -Added new settings in Windows 10, version 1809. - | |
[TenantLockdown CSP](tenantlockdown-csp.md) | -Added new CSP in Windows 10, version 1809. - | |
[Office CSP](office-csp.md) | -Added FinalStatus setting in Windows 10, version 1809. - | |
Management tool for the Micosoft Store for Business |
+New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates. |
+|
Custom header for generic alert |
+The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format: +MDM-GenericAlert: <AlertType1><AlertType2>
+If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526). |
+|
Alert message for slow client response |
+When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending. +To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md). |
+|
New node in DMClient CSP |
+Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs. |
+|
New nodes in EnterpriseModernAppManagement CSP |
+Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md): +
|
+|
New nodes in EnterpriseExt CSP |
+Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md): +
|
+|
New node in EnterpriseExtFileSystem CSP |
+Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md). |
+|
New nodes in PassportForWork CSP |
+Added the following nodes to [PassportForWork CSP](passportforwork-csp.md): +
|
+|
Updated EnterpriseAssignedAccess CSP |
+Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md): +
|
+|
New nodes in the DevDetail CSP |
+Here are the changes to the [DevDetail CSP](devdetail-csp.md): +
|
+|
Handling large objects |
+Added support for the client to handle uploading of large objects to the server. |
+