From 8806b28bd01b16e346170ee9dfe2480df91c1346 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 16 May 2019 13:32:49 -0700 Subject: [PATCH] Added dev comments --- ...ew-in-windows-mdm-enrollment-management.md | 2047 +++++++++-------- .../mdm/policy-csp-search.md | 2 + 2 files changed, 1043 insertions(+), 1006 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index b7d977b310..28fdfc24a3 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -10,45 +10,50 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 12/06/2018 +ms.date: 05/15/2019 --- -# What's new in MDM enrollment and management +# What's new in mobile device enrollment and management This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices. -For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). -## In this section +- **What’s new in MDM for Windows 10 versions** + - [What’s new in MDM for Windows 10, version 1903](#whats-new-in-mdm-for-windows-10-version-1903) + - [What’s new in MDM for Windows 10, version 1809](#whats-new-in-mdm-for-windows-10-version-1809) + - [What’s new in MDM for Windows 10, version 1803](#whats-new-in-mdm-for-windows-10-version-1803) + - [What’s new in MDM for Windows 10, version 1709](#whats-new-in-mdm-for-windows-10-version-1709) + - [What’s new in MDM for Windows 10, version 1703](#whats-new-in-mdm-for-windows-10-version-1703) + - [What’s new in MDM for Windows 10, version 1607](#whats-new-in-mdm-for-windows-10-version-1607) + - [What’s new in MDM for Windows 10, version 1511](#whats-new-in-mdm-for-windows-10-version-1511) -- [What's new in MDM enrollment and management](#whats-new-in-mdm-enrollment-and-management) - - [In this section](#in-this-section) - - [What's new in Windows 10, version 1511](#a-href%22%22-id%22whatsnew%22awhats-new-in-windows-10-version-1511) - - [What's new in Windows 10, version 1607](#a-href%22%22-id%22whatsnew1607%22awhats-new-in-windows-10-version-1607) - - [What's new in Windows 10, version 1703](#a-href%22%22-id%22whatsnew10%22awhats-new-in-windows-10-version-1703) - - [What's new in Windows 10, version 1709](#a-href%22%22-id%22whatsnew1709%22awhats-new-in-windows-10-version-1709) - - [What's new in Windows 10, version 1803](#a-href%22%22-id%22whatsnew1803%22awhats-new-in-windows-10-version-1803) - - [What's new in Windows 10, version 1809](#a-href%22%22-id%22whatsnew1809%22awhats-new-in-windows-10-version-1809) - - [Breaking changes and known issues](#breaking-changes-and-known-issues) - - [Get command inside an atomic command is not supported](#a-href%22%22-id%22getcommand%22aget-command-inside-an-atomic-command-is-not-supported) - - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#a-href%22%22-id%22notification%22anotification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) - - [Apps installed using WMI classes are not removed](#a-href%22%22-id%22appsnotremoved%22aapps-installed-using-wmi-classes-are-not-removed) - - [Passing CDATA in SyncML does not work](#a-href%22%22-id%22cdata%22apassing-cdata-in-syncml-does-not-work) - - [SSL settings in IIS server for SCEP must be set to "Ignore"](#a-href%22%22-id%22sslsettings%22assl-settings-in-iis-server-for-scep-must-be-set-to-%22ignore%22) - - [MDM enrollment fails on the mobile device when traffic is going through proxy](#a-href%22%22-id%22enrollmentviaproxy%22amdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) - - [Server-initiated unenrollment failure](#a-href%22%22-id%22unenrollment%22aserver-initiated-unenrollment-failure) - - [Certificates causing issues with Wi-Fi and VPN](#a-href%22%22-id%22certissues%22acertificates-causing-issues-with-wi-fi-and-vpn) - - [Version information for mobile devices](#a-href%22%22-id%22versioninformation%22aversion-information-for-mobile-devices) - - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#a-href%22%22-id%22whitelist%22aupgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) - - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#a-href%22%22-id%22frameworks%22aapps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) - - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#a-href%22%22-id%22wificertissue%22amultiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) - - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#a-href%22%22-id%22remote%22aremote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) - - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#a-href%22%22-id%22renewwns%22amdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) - - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#a-href%22%22-id%22userprovisioning%22auser-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) - - [Requirements to note for VPN certificates also used for Kerberos Authentication](#a-href%22%22-id%22kerberos%22arequirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) - - [Device management agent for the push-button reset is not working](#a-href%22%22-id%22pushbuttonreset%22adevice-management-agent-for-the-push-button-reset-is-not-working) - - [Change history in MDM documentation](#change-history-in-mdm-documentation) +- **Breaking changes and known issues** + - [Get command inside an atomic command is not supported](#get-command-inside-an-atomic-command-is-not-supported) + - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#notification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) + - [Apps installed using WMI classes are not removed](#apps-installed-using-wmi-classes-are-not-removed) + - [Passing CDATA in SyncML does not work](#passing-cdata-in-syncml-does-not-work) + - [SSL settings in IIS server for SCEP must be set to "Ignore"](#ssl-settings-in-iis-server-for-scep-must-be-set-to-ignore) + - [MDM enrollment fails on the mobile device when traffic is going through proxy](#mdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) + - [Server-initiated unenrollment failure](#server-initiated-unenrollment-failure) + - [Certificates causing issues with Wi-Fi and VPN](#certificates-causing-issues-with-wi-fi-and-vpn) + - [Version information for mobile devices](#version-information-for-mobile-devices) + - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#upgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) + - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#apps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) + - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#multiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) + - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#remote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) + - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#mdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) + - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#user-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) + - [Requirements to note for VPN certificates also used for Kerberos Authentication](#requirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) + - [Device management agent for the push-button reset is not working](#device-management-agent-for-the-push-button-reset-is-not-working) + +- **Frequently Asked Questions** + - [Can there be more than 1 MDM server to enroll and manage devices in Windows 10?](#can-there-be-more-than-1-mdm-server-to-enroll-and-manage-devices-in-windows-10) + - [How do I set the maximum number of Azure Active Directory joined devices per user?](#how-do-i-set-the-maximum-number-of-azure-active-directory-joined-devices-per-user) + - [What is dmwappushsvc?](#what-is-dmwappushsvc) + +- **Change history in MDM documentation** - [February 2019](#february-2019) - [January 2019](#january-2019) - [December 2018](#december-2018) @@ -66,10 +71,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s - [October 2017](#october-2017) - [September 2017](#september-2017) - [August 2017](#august-2017) - - [FAQ](#faq) - -## What's new in Windows 10, version 1511 +## What’s new in MDM for Windows 10, version 1903 @@ -77,130 +80,44 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +
ItemNew or updated topic Description

New configuration service providers added in Windows 10, version 1511

    -
  • [AllJoynManagement CSP](alljoynmanagement-csp.md)
  • -
  • [Maps CSP](maps-csp.md)
  • -
  • [Reporting CSP](reporting-csp.md)
  • -
  • [SurfaceHub CSP](surfacehub-csp.md)
  • -
  • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
  • -

New and updated policies in Policy CSP

The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

+
[Policy CSP](policy-configuration-service-provider.md)

Added the following new policies in Windows 10, version 1903:

    -
  • Accounts/DomainNamesForEmailSync
  • -
  • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
  • -
  • Bluetooth/ServicesAllowedList
  • -
  • DataProtection/AllowAzureRMSForEDP
  • -
  • DataProtection/RevokeOnUnenroll
  • -
  • DeviceLock/DevicePasswordExpiration
  • -
  • DeviceLock/DevicePasswordHistory
  • -
  • TextInput/AllowInputPanel
  • -
  • Update/PauseDeferrals
  • -
  • Update/RequireDeferUpdate
  • -
  • Update/RequireUpdateApproval
  • +
  • [DeliveryOptimization/DODelayCacheServerFallbackBackground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground)
  • +
  • [DeliveryOptimization/DODelayCacheServerFallbackForeground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackforeground)
  • +
  • [Experience/ShowLockOnUserTile](policy-csp-experience.md#experience-showlockonusertile)
  • +
  • [Power/EnergySaverBatteryThresholdOnBattery](policy-csp-power.md#power-energysaverbatterythresholdonbattery)
  • +
  • [Power/EnergySaverBatteryThresholdPluggedIn](policy-csp-power.md#power-energysaverbatterythresholdpluggedin)
  • +
  • [Power/SelectLidCloseActionOnBattery](policy-csp-power.md#power-selectlidcloseactiononbattery)
  • +
  • [Power/SelectLidCloseActionPluggedIn](policy-csp-power.md#power-selectlidcloseactionpluggedin)
  • +
  • [Power/SelectPowerButtonActionOnBattery](policy-csp-power.md#power-selectpowerbuttonactiononbattery)
  • +
  • [Power/SelectPowerButtonActionPluggedIn](policy-csp-power.md#power-selectpowerbuttonactionpluggedin)
  • +
  • [Power/SelectSleepButtonActionOnBattery](policy-csp-power.md#power-selectsleepbuttonactiononbattery)
  • +
  • [Power/SelectSleepButtonActionPluggedIn](policy-csp-power.md#power-selectsleepbuttonactionpluggedin)
  • +
  • [Power/TurnOffHybridSleepOnBattery](policy-csp-power.md#power-turnoffhybridsleeponbattery)
  • +
  • [Power/TurnOffHybridSleepPluggedIn](policy-csp-power.md#power-turnoffhybridsleeppluggedin)
  • +
  • [Power/UnattendedSleepTimeoutOnBattery](policy-csp-power.md#power-unattendedsleeptimeoutonbattery)
  • +
  • [Power/UnattendedSleepTimeoutPluggedIn](policy-csp-power.md#power-unattendedsleeptimeoutpluggedin)
  • +
  • [Search/AllowFindMyFiles](policy-csp-search.md#allowfindmyfiles)
  • +
  • [Update/AutomaticMaintenanceWakeUp](policy-csp-update.md#update-automaticmaintenancewakeup)
  • +
  • [Update/ConfigureDeadlineForFeatureUpdates](policy-csp-update.md#update-configuredeadlineforfeatureupdates)
  • +
  • [Update/ConfigureDeadlineForQualityUpdates](policy-csp-update.md#update-configuredeadlineforqualityupdates)
  • +
  • [Update/ConfigureDeadlineGracePeriod](policy-csp-update.md#update-configuredeadlinegraceperiod)
  • +
  • [WindowsLogon/AllowAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-allowautomaticrestartsignon)
  • +
  • [WindowsLogon/ConfigAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-configautomaticrestartsignon)
  • +
  • [WindowsLogon/EnableFirstLogonAnimation](policy-csp-windowslogon.md#windowslogon-enablefirstlogonanimation)
-

The following policies have been updated in the Policy CSP:

-
    -
  • System/AllowLocation
  • -
  • Update/RequireDeferUpgrade
  • -
-

The following policies have been deprecated in the Policy CSP:

-
    -
  • TextInput/AllowKoreanExtendedHanja
  • -
  • WiFi/AllowWiFiHotSpotReporting
  • -

Management tool for the Micosoft Store for Business

New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

Custom header for generic alert

The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

-MDM-GenericAlert: <AlertType1><AlertType2> -

If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

Alert message for slow client response

When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

-

To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

New node in DMClient CSP

Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

New nodes in EnterpriseModernAppManagement CSP

Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

-
    -
  • AppManagement/GetInventoryQuery
  • -
  • AppManagement/GetInventoryResults
  • -
  • .../PackageFamilyName/AppSettingPolicy/SettingValue
  • -
  • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
  • -
  • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
  • -
  • AppLicenses/StoreLicenses/LicenseID/RequesterID
  • -
  • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
  • -

New nodes in EnterpriseExt CSP

Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

-
    -
  • DeviceCustomData (CustomID, CustomeString)
  • -
  • Brightness (Default, MaxAuto)
  • -
  • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
  • -

New node in EnterpriseExtFileSystem CSP

Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

New nodes in PassportForWork CSP

Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

-
    -
  • TenantId/Policies/PINComplexity/History
  • -
  • TenantId/Policies/PINComplexity/Expiration
  • -
  • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
  • -
  • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
  • -
  • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
  • -

Updated EnterpriseAssignedAccess CSP

Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

-
    -
  • In AssignedAccessXML node, added new page settings and quick action settings.
  • -
  • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
  • -
  • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
  • -

New nodes in the DevDetail CSP

Here are the changes to the [DevDetail CSP](devdetail-csp.md):

-
    -
  • Added TotalStore and TotalRAM settings.
  • -
  • Added support for Replace command for the DeviceName setting.
  • -

Handling large objects

Added support for the client to handle uploading of large objects to the server.

- -## What's new in Windows 10, version 1607 +## What’s new in MDM for Windows 10, version 1809 @@ -209,309 +126,574 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - - - - - - - + - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
ItemNew or updated topic Description

Sideloading of apps

Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

New value for [NodeCache CSP](nodecache-csp.md)

In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

New CSP.

[Policy CSP](policy-configuration-service-provider.md)

Removed the following policies:

+

Added the following new policies in Windows 10, version 1809:

    -
  • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
  • -
  • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
  • -
  • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
  • -
  • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
  • -
  • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
  • -
  • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
  • -
  • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
  • -
  • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
  • -
  • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
  • -
  • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
  • -
  • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
  • +
  • ApplicationManagement/LaunchAppAfterLogOn
  • +
  • ApplicationManagement/ScheduleForceRestartForUpdateFailures
  • +
  • Authentication/EnableFastFirstSignIn (Preview mode only)
  • +
  • Authentication/EnableWebSignIn (Preview mode only)
  • +
  • Authentication/PreferredAadTenantDomainName
  • +
  • Browser/AllowFullScreenMode
  • +
  • Browser/AllowPrelaunch
  • +
  • Browser/AllowPrinting
  • +
  • Browser/AllowSavingHistory
  • +
  • Browser/AllowSideloadingOfExtensions
  • +
  • Browser/AllowTabPreloading
  • +
  • Browser/AllowWebContentOnNewTabPage
  • +
  • Browser/ConfigureFavoritesBar
  • +
  • Browser/ConfigureHomeButton
  • +
  • Browser/ConfigureKioskMode
  • +
  • Browser/ConfigureKioskResetAfterIdleTimeout
  • +
  • Browser/ConfigureOpenMicrosoftEdgeWith
  • +
  • Browser/ConfigureTelemetryForMicrosoft365Analytics
  • +
  • Browser/PreventCertErrorOverrides
  • +
  • Browser/SetHomeButtonURL
  • +
  • Browser/SetNewTabPageURL
  • +
  • Browser/UnlockHomeButton
  • +
  • Defender/CheckForSignaturesBeforeRunningScan
  • +
  • Defender/DisableCatchupFullScan
  • +
  • Defender/DisableCatchupQuickScan
  • +
  • Defender/EnableLowCPUPriority
  • +
  • Defender/SignatureUpdateFallbackOrder
  • +
  • Defender/SignatureUpdateFileSharesSources
  • +
  • DeviceGuard/ConfigureSystemGuardLaunch
  • +
  • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
  • +
  • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
  • +
  • DeviceInstallation/PreventDeviceMetadataFromNetwork
  • +
  • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
  • +
  • DmaGuard/DeviceEnumerationPolicy
  • +
  • Experience/AllowClipboardHistory
  • +
  • Experience/DoNotSyncBrowserSettings
  • +
  • Experience/PreventUsersFromTurningOnBrowserSyncing
  • +
  • Kerberos/UPNNameHints
  • +
  • Privacy/AllowCrossDeviceClipboard
  • +
  • Privacy/DisablePrivacyExperience
  • +
  • Privacy/UploadUserActivities
  • +
  • Security/RecoveryEnvironmentAuthentication
  • +
  • System/AllowDeviceNameInDiagnosticData
  • +
  • System/ConfigureMicrosoft365UploadEndpoint
  • +
  • System/DisableDeviceDelete
  • +
  • System/DisableDiagnosticDataViewer
  • +
  • Storage/RemovableDiskDenyWriteAccess
  • +
  • TaskManager/AllowEndTask
  • +
  • Update/EngagedRestartDeadlineForFeatureUpdates
  • +
  • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
  • +
  • Update/EngagedRestartTransitionScheduleForFeatureUpdates
  • +
  • Update/SetDisablePauseUXAccess
  • +
  • Update/SetDisableUXWUAccess
  • +
  • WindowsDefenderSecurityCenter/DisableClearTpmButton
  • +
  • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
  • +
  • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
  • +
  • WindowsLogon/DontDisplayNetworkSelectionUI
-

Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

-
    -
  • Windows 10 Pro
  • -
  • Windows 10 Enterprise
  • -
  • Windows 10 Education
  • -
-

Added the following new policies:

-
    -
  • AboveLock/AllowCortanaAboveLock
  • -
  • ApplicationManagement/DisableStoreOriginatedApps
  • -
  • Authentication/AllowSecondaryAuthenticationDevice
  • -
  • Bluetooth/AllowPrepairing
  • -
  • Browser/AllowExtensions
  • -
  • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
  • -
  • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
  • -
  • DeliveryOptimization/DOAbsoluteMaxCacheSize
  • -
  • DeliveryOptimization/DOMaxDownloadBandwidth
  • -
  • DeliveryOptimization/DOMinBackgroundQoS
  • -
  • DeliveryOptimization/DOModifyCacheDrive
  • -
  • DeliveryOptimization/DOMonthlyUploadDataCap
  • -
  • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
  • -
  • DeviceLock/EnforceLockScreenAndLogonImage
  • -
  • DeviceLock/EnforceLockScreenProvider
  • -
  • Defender/PUAProtection
  • -
  • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
  • -
  • Experience/AllowWindowsSpotlight
  • -
  • Experience/ConfigureWindowsSpotlightOnLockScreen
  • -
  • Experience/DoNotShowFeedbackNotifications
  • -
  • Licensing/AllowWindowsEntitlementActivation
  • -
  • Licensing/DisallowKMSClientOnlineAVSValidation
  • -
  • LockDown/AllowEdgeSwipe
  • -
  • Maps/EnableOfflineMapsAutoUpdate
  • -
  • Maps/AllowOfflineMapsDownloadOverMeteredConnection
  • -
  • Messaging/AllowMessageSync
  • -
  • NetworkIsolation/EnterpriseCloudResources
  • -
  • NetworkIsolation/EnterpriseInternalProxyServers
  • -
  • NetworkIsolation/EnterpriseIPRange
  • -
  • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
  • -
  • NetworkIsolation/EnterpriseNetworkDomainNames
  • -
  • NetworkIsolation/EnterpriseProxyServers
  • -
  • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
  • -
  • NetworkIsolation/NeutralResources
  • -
  • Notifications/DisallowNotificationMirroring
  • -
  • Privacy/DisableAdvertisingId
  • -
  • Privacy/LetAppsAccessAccountInfo
  • -
  • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessCalendar
  • -
  • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessCallHistory
  • -
  • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessCamera
  • -
  • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessContacts
  • -
  • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessEmail
  • -
  • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessLocation
  • -
  • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessMessaging
  • -
  • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessMicrophone
  • -
  • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessMotion
  • -
  • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessNotifications
  • -
  • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessPhone
  • -
  • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessRadios
  • -
  • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsAccessTrustedDevices
  • -
  • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
  • -
  • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
  • -
  • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
  • -
  • Privacy/LetAppsSyncWithDevices
  • -
  • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
  • -
  • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
  • -
  • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
  • -
  • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
  • -
  • Settings/AllowEditDeviceName
  • -
  • Speech/AllowSpeechModelUpdate
  • -
  • System/TelemetryProxy
  • -
  • Update/ActiveHoursStart
  • -
  • Update/ActiveHoursEnd
  • -
  • Update/AllowMUUpdateService
  • -
  • Update/BranchReadinessLevel
  • -
  • Update/DeferFeatureUpdatesPeriodInDays
  • -
  • Update/DeferQualityUpdatesPeriodInDays
  • -
  • Update/ExcludeWUDriversInQualityUpdate
  • -
  • Update/PauseFeatureUpdates
  • -
  • Update/PauseQualityUpdates
  • -
  • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
  • -
  • WindowsInkWorkspace/AllowWindowsInkWorkspace
  • -
  • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
  • -
  • WirelessDisplay/AllowProjectionToPC
  • -
  • WirelessDisplay/RequirePinForPairing
  • -
-

Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

-

Updated DeliveryOptimization/DODownloadMode to add new values.

-

Updated Experience/AllowCortana description to clarify what each supported value does.

-

Updated Security/AntiTheftMode description to clarify what each supported value does.

[PassportForWork CSP](passportforwork-csp.md)

Added new settings in Windows 10, version 1809.

+
[EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

+
[Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

Added new configuration service provider in Windows 10, version 1809.

+
[WindowsLicensing CSP](windowslicensing-csp.md)

Added S mode settings and SyncML examples in Windows 10, version 1809.

+
[SUPL CSP](supl-csp.md)

Added 3 new certificate nodes in Windows 10, version 1809.

+
[Defender CSP](defender-csp.md)

Added a new node Health/ProductStatus in Windows 10, version 1809.

+
[BitLocker CSP](bitlocker-csp.md)

Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

+
[DevDetail CSP](devdetail-csp.md)

Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

+
[Wifi CSP](wifi-csp.md)

Added a new node WifiCost in Windows 10, version 1809.

+
[WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

Added new settings in Windows 10, version 1809.

+
[RemoteWipe CSP](remotewipe-csp.md)

Added new settings in Windows 10, version 1809.

+
[TenantLockdown CSP](tenantlockdown-csp.md)

Added new CSP in Windows 10, version 1809.

+
[Office CSP](office-csp.md)

Added FinalStatus setting in Windows 10, version 1809.

+
+ +## What’s new in MDM for Windows 10, version 1803 + + ++++ + + + + + + + + + + + + - - + - - - - - - + + + + + + + - +
  • Rollback
  • +
  • Rollback/FeatureUpdate
  • +
  • Rollback/QualityUpdateStatus
  • +
  • Rollback/FeatureUpdateStatus
  • + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

    Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

    + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    New or updated topicDescription
    [Policy CSP](policy-configuration-service-provider.md)

    Added the following new policies for Windows 10, version 1803:

    +
      +
    • ApplicationDefaults/EnableAppUriHandlers
    • +
    • ApplicationManagement/MSIAllowUserControlOverInstall
    • +
    • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
    • +
    • Bluetooth/AllowPromptedProximalConnections
    • +
    • Browser/AllowConfigurationUpdateForBooksLibrary
    • +
    • Browser/AlwaysEnableBooksLibrary
    • +
    • Browser/EnableExtendedBooksTelemetry
    • +
    • Browser/UseSharedFolderForBooks
    • +
    • Connectivity/AllowPhonePCLinking
    • +
    • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
    • +
    • DeliveryOptimization/DODelayForegroundDownloadFromHttp
    • +
    • DeliveryOptimization/DOGroupIdSource
    • +
    • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
    • +
    • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
    • +
    • DeliveryOptimization/DORestrictPeerSelectionBy
    • +
    • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
    • +
    • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
    • +
    • Display/DisablePerProcessDpiForApps
    • +
    • Display/EnablePerProcessDpi
    • +
    • Display/EnablePerProcessDpiForApps
    • +
    • Experience/AllowWindowsSpotlightOnSettings
    • +
    • KioskBrowser/BlockedUrlExceptions
    • +
    • KioskBrowser/BlockedUrls
    • +
    • KioskBrowser/DefaultURL
    • +
    • KioskBrowser/EnableEndSessionButton
    • +
    • KioskBrowser/EnableHomeButton
    • +
    • KioskBrowser/EnableNavigationButtons
    • +
    • KioskBrowser/RestartOnIdleTime
    • +
    • LanmanWorkstation/EnableInsecureGuestLogons
    • +
    • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
    • +
    • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
    • +
    • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
    • +
    • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
    • +
    • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
    • +
    • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
    • +
    • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
    • +
    • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
    • +
    • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
    • +
    • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
    • +
    • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
    • +
    • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
    • +
    • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
    • +
    • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
    • +
    • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
    • +
    • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
    • +
    • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
    • +
    • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
    • +
    • Notifications/DisallowCloudNotification
    • +
    • RestrictedGroups/ConfigureGroupMembership
    • +
    • Search/AllowCortanaInAAD
    • +
    • Search/DoNotUseWebResults
    • +
    • Security/ConfigureWindowsPasswords
    • +
    • Start/DisableContextMenus
    • +
    • System/FeedbackHubAlwaysSaveDiagnosticsLocally
    • +
    • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
    • +
    • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
    • +
    • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
    • +
    • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
    • +
    • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
    • +
    • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
    • +
    • TaskScheduler/EnableXboxGameSaveTask
    • +
    • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
    • +
    • TextInput/ForceTouchKeyboardDockedState
    • +
    • TextInput/TouchKeyboardDictationButtonAvailability
    • +
    • TextInput/TouchKeyboardEmojiButtonAvailability
    • +
    • TextInput/TouchKeyboardFullModeAvailability
    • +
    • TextInput/TouchKeyboardHandwritingModeAvailability
    • +
    • TextInput/TouchKeyboardNarrowModeAvailability
    • +
    • TextInput/TouchKeyboardSplitModeAvailability
    • +
    • TextInput/TouchKeyboardWideModeAvailability
    • +
    • Update/ConfigureFeatureUpdateUninstallPeriod
    • +
    • UserRights/AccessCredentialManagerAsTrustedCaller
    • +
    • UserRights/AccessFromNetwork
    • +
    • UserRights/ActAsPartOfTheOperatingSystem
    • +
    • UserRights/AllowLocalLogOn
    • +
    • UserRights/BackupFilesAndDirectories
    • +
    • UserRights/ChangeSystemTime
    • +
    • UserRights/CreateGlobalObjects
    • +
    • UserRights/CreatePageFile
    • +
    • UserRights/CreatePermanentSharedObjects
    • +
    • UserRights/CreateSymbolicLinks
    • +
    • UserRights/CreateToken
    • +
    • UserRights/DebugPrograms
    • +
    • UserRights/DenyAccessFromNetwork
    • +
    • UserRights/DenyLocalLogOn
    • +
    • UserRights/DenyRemoteDesktopServicesLogOn
    • +
    • UserRights/EnableDelegation
    • +
    • UserRights/GenerateSecurityAudits
    • +
    • UserRights/ImpersonateClient
    • +
    • UserRights/IncreaseSchedulingPriority
    • +
    • UserRights/LoadUnloadDeviceDrivers
    • +
    • UserRights/LockMemory
    • +
    • UserRights/ManageAuditingAndSecurityLog
    • +
    • UserRights/ManageVolume
    • +
    • UserRights/ModifyFirmwareEnvironment
    • +
    • UserRights/ModifyObjectLabel
    • +
    • UserRights/ProfileSingleProcess
    • +
    • UserRights/RemoteShutdown
    • +
    • UserRights/RestoreFilesAndDirectories
    • +
    • UserRights/TakeOwnership
    • +
    • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
    • +
    • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
    • +
    • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
    • +
    • WindowsDefenderSecurityCenter/HideSecureBoot
    • +
    • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
    • +
    +

    Security/RequireDeviceEncryption - updated to show it is supported in desktop.

    +
    [BitLocker CSP](bitlocker-csp.md)

    Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

    +
    [DMClient CSP](dmclient-csp.md)

    Added the following settings:

    +

    Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

      -
    • ManagementServerAddressList
    • -
    • AADDeviceID
    • -
    • EnrollmentType
    • -
    • HWDevID
    • -
    • CommercialID
    • +
    • AADSendDeviceToken
    • +
    • BlockInStatusPage
    • +
    • AllowCollectLogsButton
    • +
    • CustomErrorText
    • +
    • SkipDeviceStatusPage
    • +
    • SkipUserStatusPage
    -

    Removed the EnrollmentID setting.

    [DeviceManageability CSP](devicemanageability-csp.md)

    New CSP.

    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following new settings:

    +
    [Defender CSP](defender-csp.md)

    Added new node (OfflineScan) in Windows 10, version 1803.

    +
    [UEFI CSP](uefi-csp.md)

    Added a new CSP in Windows 10, version 1803.

    +
    [Update CSP](update-csp.md)

    Added the following nodes in Windows 10, version 1803:

      -
    • DeviceStatus/TPM/SpecificationVersion
    • -
    • DeviceStatus/OS/Edition
    • -
    • DeviceStatus/Antivirus/SignatureStatus
    • -
    • DeviceStatus/Antivirus/Status
    • -
    • DeviceStatus/Antispyware/SignatureStatus
    • -
    • DeviceStatus/Antispyware/Status
    • -
    • DeviceStatus/Firewall/Status
    • -
    • DeviceStatus/UAC/Status
    • -
    • DeviceStatus/Battery/Status
    • -
    • DeviceStatus/Battery/EstimatedChargeRemaining
    • -
    • DeviceStatus/Battery/EstimatedRuntime
    • -
    [AssignedAccess CSP](assignedaccess-csp.md)

    Added SyncML examples.

    [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
      -
    • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
    • -
    • Updated the DDF and XSD file sections.
    • -
    [SecureAssessment CSP](secureassessment-csp.md)

    New CSP for Windows 10, version 1607

    [DiagnosticLog CSP](diagnosticlog-csp.md) -

    [DiagnosticLog DDF](diagnosticlog-ddf.md)

    Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

    +

    Added the following nodes in Windows 10, version 1803:

      -
    • DeviceStateData
    • -
    • DeviceStateData/MdmConfiguration
    • -
    [Reboot CSP](reboot-csp.md)

    New CSP for Windows 10, version 1607

    [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

    New CSP for Windows 10, version 1607

    [VPNv2 CSP](vpnv2-csp.md)

    Added the following settings for Windows 10, version 1607

    -
      -
    • ProfileName/RouteList/routeRowId/ExclusionRoute
    • -
    • ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
    • -
    • ProfileName/DomainNameInformationList/dniRowId/Persistent
    • -
    • ProfileName/ProfileXML
    • -
    • ProfileName/DeviceCompliance/Enabled
    • -
    • ProfileName/DeviceCompliance/Sso
    • -
    • ProfileName/DeviceCompliance/Sso/Enabled
    • -
    • ProfileName/DeviceCompliance/Sso/IssuerHash
    • -
    • ProfileName/DeviceCompliance/Sso/Eku
    • -
    • ProfileName/NativeProfile/CryptographySuite
    • -
    • ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
    • -
    • ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
    • -
    • ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
    • -
    • ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
    • -
    • ProfileName/NativeProfile/CryptographySuite/DHGroup
    • -
    • ProfileName/NativeProfile/CryptographySuite/PfsGroup
    • -
    • ProfileName/NativeProfile/L2tpPsk
    • -
    [Win32AppInventory CSP](win32appinventory-csp.md) -

    [Win32AppInventory DDF](win32appinventory-ddf-file.md)

    New CSP for Windows 10, version 1607.

    [SharedPC CSP](sharedpc-csp.md)

    New CSP for Windows 10, version 1607.

    [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

    New CSP for Windows 10, version 1607.

    [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

    Added new classes for Windows 10, version 1607.

    [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

    Topic renamed from "Enrollment UI".

    -

    Completely updated enrollment procedures and screenshots.

    [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) -

    [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

    Added the following new setting for Windows 10, version 1607:

    -
      -
    • NextSession/HORMEnabled
    • -
    [CertificateStore CSP](certificatestore-csp.md) -

    [CertificateStore DDF file](certificatestore-ddf-file.md)

    Added the following new settings in Windows 10, version 1607:

    -
      -
    • My/WSTEP/Renew/LastRenewalAttemptTime
    • -
    • My/WSTEP/Renew/RenewNow
    • -

    [WindowsLicensing CSP](windowslicensing-csp.md)

    Added the following new node and settings in Windows 10, version 1607, but not documented:

    -
      -
    • Subscriptions
    • -
    • Subscriptions/SubscriptionId
    • -
    • Subscriptions/SubscriptionId/Status
    • -
    • Subscriptions/SubscriptionId/Name
    • +
    • Status
    • +
    • ShellLauncher
    • +
    • StatusConfiguration
    -
    [MultiSIM CSP](multisim-csp.md)

    Added a new CSP in Windows 10, version 1803.

    +
    [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

    Added the following node in Windows 10, version 1803:

    +
      +
    • MaintainProcessorArchitectureOnUpdate
    • +
    +
    [eUICCs CSP](euiccs-csp.md)

    Added the following node in Windows 10, version 1803:

    +
      +
    • IsEnabled
    • +
    +
    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following node in Windows 10, version 1803:

    +
      +
    • OS/Mode
    • +
    +
    [AccountManagement CSP](accountmanagement-csp.md)

    Added a new CSP in Windows 10, version 1803.

    +
    [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

    Added the following node in Windows 10, version 1803:

    +
      +
    • UntrustedCertificates
    • +
    +
    [NetworkProxy CSP](\networkproxy--csp.md)

    Added the following node in Windows 10, version 1803:

    +
      +
    • ProxySettingsPerUser
    • +
    +
    [Accounts CSP](accounts-csp.md)

    Added a new CSP in Windows 10, version 1803.

    +
    [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

    Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

    +
    [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

    Added the DDF download of Windows 10, version 1803 configuration service providers.

    +
    -## What's new in Windows 10, version 1703 +## What’s new in MDM for Windows 10, version 1709 + + ++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    ItemDescription
    The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

    The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

    +
      +
    • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
    • +
    • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
    • +
    • DomainName - fully qualified domain name if the device is domain-joined.
    • +
    +

    For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

    +
    [Firewall CSP](firewall-csp.md)

    Added new CSP in Windows 10, version 1709.

    +
    [eUICCs CSP](euiccs-csp.md)

    Added new CSP in Windows 10, version 1709.

    +
    [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
    [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.
    [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
    [VPNv2 CSP](vpnv2-csp.md)

    Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

    +
    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following settings in Windows 10, version 1709:

    +
      +
    • DeviceStatus/DomainName
    • +
    • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
    • +
    • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
    • +
    • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
    • +
    +
    [AssignedAccess CSP](assignedaccess-csp.md)

    Added the following setting in Windows 10, version 1709.

    +
      +
    • Configuration
    • +
    +

    Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

    +
    [DeviceManageability CSP](devicemanageability-csp.md)

    Added the following settings in Windows 10, version 1709:

    +
      +
    • Provider/_ProviderID_/ConfigInfo
    • +
    • Provider/_ProviderID_/EnrollmentInfo
    • +
    +
    [Office CSP](office-csp.md)

    Added the following setting in Windows 10, version 1709:

    +
      +
    • Installation/CurrentStatus
    • +
    +
    [DMClient CSP](dmclient-csp.md)

    Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

    +
    [Bitlocker CSP](bitlocker-csp.md)

    Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

    +
    [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

    Added new policies.

    +
    Microsoft Store for Business and Microsoft Store

    Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

    +
    [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

    New features in the Settings app:

    +
      +
    • User sees installation progress of critical policies during MDM enrollment.
    • +
    • User knows what policies, profiles, apps MDM has configured
    • +
    • IT helpdesk can get detailed MDM diagnostic information using client tools
    • +
    +

    For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

    +
    [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

    Added new topic to introduce a new Group Policy for automatic MDM enrollment.

    +
    [Policy CSP](policy-configuration-service-provider.md)

    Added the following new policies for Windows 10, version 1709:

    +
      +
    • Authentication/AllowAadPasswordReset
    • +
    • Authentication/AllowFidoDeviceSignon
    • +
    • Browser/LockdownFavorites
    • +
    • Browser/ProvisionFavorites
    • +
    • Cellular/LetAppsAccessCellularData
    • +
    • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
    • +
    • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
    • +
    • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
    • +
    • CredentialProviders/DisableAutomaticReDeploymentCredentials
    • +
    • DeviceGuard/EnableVirtualizationBasedSecurity
    • +
    • DeviceGuard/RequirePlatformSecurityFeatures
    • +
    • DeviceGuard/LsaCfgFlags
    • +
    • DeviceLock/MinimumPasswordAge
    • +
    • ExploitGuard/ExploitProtectionSettings
    • +
    • Games/AllowAdvancedGamingServices
    • +
    • Handwriting/PanelDefaultModeDocked
    • +
    • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
    • +
    • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
    • +
    • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
    • +
    • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
    • +
    • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
    • +
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
    • +
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
    • +
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
    • +
    • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
    • +
    • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
    • +
    • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
    • +
    • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
    • +
    • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
    • +
    • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
    • +
    • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
    • +
    • Power/DisplayOffTimeoutOnBattery
    • +
    • Power/DisplayOffTimeoutPluggedIn
    • +
    • Power/HibernateTimeoutOnBattery
    • +
    • Power/HibernateTimeoutPluggedIn
    • +
    • Power/StandbyTimeoutOnBattery
    • +
    • Power/StandbyTimeoutPluggedIn
    • +
    • Privacy/EnableActivityFeed
    • +
    • Privacy/PublishUserActivities
    • +
    • Defender/AttackSurfaceReductionOnlyExclusions
    • +
    • Defender/AttackSurfaceReductionRules
    • +
    • Defender/CloudBlockLevel
    • +
    • Defender/CloudExtendedTimeout
    • +
    • Defender/ControlledFolderAccessAllowedApplications
    • +
    • Defender/ControlledFolderAccessProtectedFolders
    • +
    • Defender/EnableControlledFolderAccess
    • +
    • Defender/EnableNetworkProtection
    • +
    • Education/DefaultPrinterName
    • +
    • Education/PreventAddingNewPrinters
    • +
    • Education/PrinterNames
    • +
    • Search/AllowCloudSearch
    • +
    • Security/ClearTPMIfNotReady
    • +
    • Settings/AllowOnlineTips
    • +
    • Start/HidePeopleBar
    • +
    • Storage/AllowDiskHealthModelUpdates
    • +
    • System/DisableEnterpriseAuthProxy
    • +
    • System/LimitEnhancedDiagnosticDataWindowsAnalytics
    • +
    • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
    • +
    • Update/DisableDualScan
    • +
    • Update/ManagePreviewBuilds
    • +
    • Update/ScheduledInstallEveryWeek
    • +
    • Update/ScheduledInstallFirstWeek
    • +
    • Update/ScheduledInstallFourthWeek
    • +
    • Update/ScheduledInstallSecondWeek
    • +
    • Update/ScheduledInstallThirdWeek
    • +
    • WindowsDefenderSecurityCenter/CompanyName
    • +
    • WindowsDefenderSecurityCenter/DisableAppBrowserUI
    • +
    • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
    • +
    • WindowsDefenderSecurityCenter/DisableFamilyUI
    • +
    • WindowsDefenderSecurityCenter/DisableHealthUI
    • +
    • WindowsDefenderSecurityCenter/DisableNetworkUI
    • +
    • WindowsDefenderSecurityCenter/DisableNotifications
    • +
    • WindowsDefenderSecurityCenter/DisableVirusUI
    • +
    • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
    • +
    • WindowsDefenderSecurityCenter/Email
    • +
    • WindowsDefenderSecurityCenter/EnableCustomizedToasts
    • +
    • WindowsDefenderSecurityCenter/EnableInAppCustomization
    • +
    • WindowsDefenderSecurityCenter/Phone
    • +
    • WindowsDefenderSecurityCenter/URL
    • +
    • WirelessDisplay/AllowMdnsAdvertisement
    • +
    • WirelessDisplay/AllowMdnsDiscovery
    • +
    +
    + +## What’s new in MDM for Windows 10, version 1703 @@ -932,7 +1114,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s
      -## What's new in Windows 10, version 1709 + +## What’s new in MDM for Windows 10, version 1607 @@ -946,439 +1129,304 @@ For details about Microsoft mobile device management protocols for Windows 10 s - - - - - - - - - - - + + - - + + - - + + - - + + + - - + - - - +

    Removed the EnrollmentID setting.

    + - - - - - - - - - - - - - - - - - - - - - - - - - -
    The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

    The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

    -
      -
    • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
    • -
    • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
    • -
    • DomainName - fully qualified domain name if the device is domain-joined.
    • -
    -

    For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

    -
    [Firewall CSP](firewall-csp.md)

    Added new CSP in Windows 10, version 1709.

    -
    [eUICCs CSP](euiccs-csp.md)

    Added new CSP in Windows 10, version 1709.

    -
    [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).

    Sideloading of apps

    Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

    [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.

    New value for [NodeCache CSP](nodecache-csp.md)

    In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

    [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

    New CSP.

    [VPNv2 CSP](vpnv2-csp.md)

    Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

    -
    [Policy CSP](policy-configuration-service-provider.md)

    Removed the following policies:

    +
      +
    • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
    • +
    • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
    • +
    • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
    • +
    • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
    • +
    • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
    • +
    • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
    • +
    • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
    • +
    • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
    • +
    • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
    • +
    • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
    • +
    • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
    • +
    +

    Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

    +
      +
    • Windows 10 Pro
    • +
    • Windows 10 Enterprise
    • +
    • Windows 10 Education
    • +
    +

    Added the following new policies:

    +
      +
    • AboveLock/AllowCortanaAboveLock
    • +
    • ApplicationManagement/DisableStoreOriginatedApps
    • +
    • Authentication/AllowSecondaryAuthenticationDevice
    • +
    • Bluetooth/AllowPrepairing
    • +
    • Browser/AllowExtensions
    • +
    • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
    • +
    • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
    • +
    • DeliveryOptimization/DOAbsoluteMaxCacheSize
    • +
    • DeliveryOptimization/DOMaxDownloadBandwidth
    • +
    • DeliveryOptimization/DOMinBackgroundQoS
    • +
    • DeliveryOptimization/DOModifyCacheDrive
    • +
    • DeliveryOptimization/DOMonthlyUploadDataCap
    • +
    • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
    • +
    • DeviceLock/EnforceLockScreenAndLogonImage
    • +
    • DeviceLock/EnforceLockScreenProvider
    • +
    • Defender/PUAProtection
    • +
    • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
    • +
    • Experience/AllowWindowsSpotlight
    • +
    • Experience/ConfigureWindowsSpotlightOnLockScreen
    • +
    • Experience/DoNotShowFeedbackNotifications
    • +
    • Licensing/AllowWindowsEntitlementActivation
    • +
    • Licensing/DisallowKMSClientOnlineAVSValidation
    • +
    • LockDown/AllowEdgeSwipe
    • +
    • Maps/EnableOfflineMapsAutoUpdate
    • +
    • Maps/AllowOfflineMapsDownloadOverMeteredConnection
    • +
    • Messaging/AllowMessageSync
    • +
    • NetworkIsolation/EnterpriseCloudResources
    • +
    • NetworkIsolation/EnterpriseInternalProxyServers
    • +
    • NetworkIsolation/EnterpriseIPRange
    • +
    • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
    • +
    • NetworkIsolation/EnterpriseNetworkDomainNames
    • +
    • NetworkIsolation/EnterpriseProxyServers
    • +
    • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
    • +
    • NetworkIsolation/NeutralResources
    • +
    • Notifications/DisallowNotificationMirroring
    • +
    • Privacy/DisableAdvertisingId
    • +
    • Privacy/LetAppsAccessAccountInfo
    • +
    • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessCalendar
    • +
    • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessCallHistory
    • +
    • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessCamera
    • +
    • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessContacts
    • +
    • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessEmail
    • +
    • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessLocation
    • +
    • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessMessaging
    • +
    • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessMicrophone
    • +
    • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessMotion
    • +
    • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessNotifications
    • +
    • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessPhone
    • +
    • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessRadios
    • +
    • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsAccessTrustedDevices
    • +
    • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
    • +
    • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
    • +
    • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
    • +
    • Privacy/LetAppsSyncWithDevices
    • +
    • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
    • +
    • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
    • +
    • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
    • +
    • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
    • +
    • Settings/AllowEditDeviceName
    • +
    • Speech/AllowSpeechModelUpdate
    • +
    • System/TelemetryProxy
    • +
    • Update/ActiveHoursStart
    • +
    • Update/ActiveHoursEnd
    • +
    • Update/AllowMUUpdateService
    • +
    • Update/BranchReadinessLevel
    • +
    • Update/DeferFeatureUpdatesPeriodInDays
    • +
    • Update/DeferQualityUpdatesPeriodInDays
    • +
    • Update/ExcludeWUDriversInQualityUpdate
    • +
    • Update/PauseFeatureUpdates
    • +
    • Update/PauseQualityUpdates
    • +
    • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
    • +
    • WindowsInkWorkspace/AllowWindowsInkWorkspace
    • +
    • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
    • +
    • WirelessDisplay/AllowProjectionToPC
    • +
    • WirelessDisplay/RequirePinForPairing
    • +
    +

    Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

    +

    Updated DeliveryOptimization/DODownloadMode to add new values.

    +

    Updated Experience/AllowCortana description to clarify what each supported value does.

    +

    Updated Security/AntiTheftMode description to clarify what each supported value does.

    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following settings in Windows 10, version 1709:

    +
    [DMClient CSP](dmclient-csp.md)

    Added the following settings:

      -
    • DeviceStatus/DomainName
    • -
    • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
    • -
    • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
    • -
    • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
    • +
    • ManagementServerAddressList
    • +
    • AADDeviceID
    • +
    • EnrollmentType
    • +
    • HWDevID
    • +
    • CommercialID
    -
    [AssignedAccess CSP](assignedaccess-csp.md)

    Added the following setting in Windows 10, version 1709.

    -
      -
    • Configuration
    • -
    -

    Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

    -
    [DeviceManageability CSP](devicemanageability-csp.md)

    Added the following settings in Windows 10, version 1709:

    -
      -
    • Provider/_ProviderID_/ConfigInfo
    • -
    • Provider/_ProviderID_/EnrollmentInfo
    • -
    -
    [Office CSP](office-csp.md)

    Added the following setting in Windows 10, version 1709:

    -
      -
    • Installation/CurrentStatus
    • -
    -
    [DMClient CSP](dmclient-csp.md)

    Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

    -
    [Bitlocker CSP](bitlocker-csp.md)

    Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

    -
    [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

    Added new policies.

    -
    Microsoft Store for Business and Microsoft Store

    Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

    -
    [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

    New features in the Settings app:

    -
      -
    • User sees installation progress of critical policies during MDM enrollment.
    • -
    • User knows what policies, profiles, apps MDM has configured
    • -
    • IT helpdesk can get detailed MDM diagnostic information using client tools
    • -
    -

    For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

    -
    [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

    Added new topic to introduce a new Group Policy for automatic MDM enrollment.

    -
    [Policy CSP](policy-configuration-service-provider.md)

    Added the following new policies for Windows 10, version 1709:

    -
      -
    • Authentication/AllowAadPasswordReset
    • -
    • Authentication/AllowFidoDeviceSignon
    • -
    • Browser/LockdownFavorites
    • -
    • Browser/ProvisionFavorites
    • -
    • Cellular/LetAppsAccessCellularData
    • -
    • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
    • -
    • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
    • -
    • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
    • -
    • CredentialProviders/DisableAutomaticReDeploymentCredentials
    • -
    • DeviceGuard/EnableVirtualizationBasedSecurity
    • -
    • DeviceGuard/RequirePlatformSecurityFeatures
    • -
    • DeviceGuard/LsaCfgFlags
    • -
    • DeviceLock/MinimumPasswordAge
    • -
    • ExploitGuard/ExploitProtectionSettings
    • -
    • Games/AllowAdvancedGamingServices
    • -
    • Handwriting/PanelDefaultModeDocked
    • -
    • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
    • -
    • LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus
    • -
    • LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus
    • -
    • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
    • -
    • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
    • -
    • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
    • -
    • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
    • -
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
    • -
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
    • -
    • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
    • -
    • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
    • -
    • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
    • -
    • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
    • -
    • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
    • -
    • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
    • -
    • Power/DisplayOffTimeoutOnBattery
    • -
    • Power/DisplayOffTimeoutPluggedIn
    • -
    • Power/HibernateTimeoutOnBattery
    • -
    • Power/HibernateTimeoutPluggedIn
    • -
    • Power/StandbyTimeoutOnBattery
    • -
    • Power/StandbyTimeoutPluggedIn
    • -
    • Privacy/EnableActivityFeed
    • -
    • Privacy/PublishUserActivities
    • -
    • Defender/AttackSurfaceReductionOnlyExclusions
    • -
    • Defender/AttackSurfaceReductionRules
    • -
    • Defender/CloudBlockLevel
    • -
    • Defender/CloudExtendedTimeout
    • -
    • Defender/ControlledFolderAccessAllowedApplications
    • -
    • Defender/ControlledFolderAccessProtectedFolders
    • -
    • Defender/EnableControlledFolderAccess
    • -
    • Defender/EnableNetworkProtection
    • -
    • Education/DefaultPrinterName
    • -
    • Education/PreventAddingNewPrinters
    • -
    • Education/PrinterNames
    • -
    • Search/AllowCloudSearch
    • -
    • Security/ClearTPMIfNotReady
    • -
    • Settings/AllowOnlineTips
    • -
    • Start/HidePeopleBar
    • -
    • Storage/AllowDiskHealthModelUpdates
    • -
    • System/DisableEnterpriseAuthProxy
    • -
    • System/LimitEnhancedDiagnosticDataWindowsAnalytics
    • -
    • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
    • -
    • Update/DisableDualScan
    • -
    • Update/ManagePreviewBuilds
    • -
    • Update/ScheduledInstallEveryWeek
    • -
    • Update/ScheduledInstallFirstWeek
    • -
    • Update/ScheduledInstallFourthWeek
    • -
    • Update/ScheduledInstallSecondWeek
    • -
    • Update/ScheduledInstallThirdWeek
    • -
    • WindowsDefenderSecurityCenter/CompanyName
    • -
    • WindowsDefenderSecurityCenter/DisableAppBrowserUI
    • -
    • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
    • -
    • WindowsDefenderSecurityCenter/DisableFamilyUI
    • -
    • WindowsDefenderSecurityCenter/DisableHealthUI
    • -
    • WindowsDefenderSecurityCenter/DisableNetworkUI
    • -
    • WindowsDefenderSecurityCenter/DisableNotifications
    • -
    • WindowsDefenderSecurityCenter/DisableVirusUI
    • -
    • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
    • -
    • WindowsDefenderSecurityCenter/Email
    • -
    • WindowsDefenderSecurityCenter/EnableCustomizedToasts
    • -
    • WindowsDefenderSecurityCenter/EnableInAppCustomization
    • -
    • WindowsDefenderSecurityCenter/Phone
    • -
    • WindowsDefenderSecurityCenter/URL
    • -
    • WirelessDisplay/AllowMdnsAdvertisement
    • -
    • WirelessDisplay/AllowMdnsDiscovery
    • -
    -
    - -## What's new in Windows 10, version 1803 - - ---- - - - - + - - - - - + + - - - - - - - - - - - - - - - - + + + + + + - - + + + + + + + - - + + + + + + + + + - - - + + + + + + + + + + + + + + + + + + + + + + + + - - - + + + + - - - - - - + + + + - - - - - - - - - - - - + +
    New or updated topicDescription

    New CSP.

    [Policy CSP](policy-configuration-service-provider.md)

    Added the following new policies for Windows 10, version 1803:

    +
    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following new settings:

      -
    • ApplicationDefaults/EnableAppUriHandlers
    • -
    • ApplicationManagement/MSIAllowUserControlOverInstall
    • -
    • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
    • -
    • Bluetooth/AllowPromptedProximalConnections
    • -
    • Browser/AllowConfigurationUpdateForBooksLibrary
    • -
    • Browser/AlwaysEnableBooksLibrary
    • -
    • Browser/EnableExtendedBooksTelemetry
    • -
    • Browser/UseSharedFolderForBooks
    • -
    • Connectivity/AllowPhonePCLinking
    • -
    • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
    • -
    • DeliveryOptimization/DODelayForegroundDownloadFromHttp
    • -
    • DeliveryOptimization/DOGroupIdSource
    • -
    • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
    • -
    • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
    • -
    • DeliveryOptimization/DORestrictPeerSelectionBy
    • -
    • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
    • -
    • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
    • -
    • Display/DisablePerProcessDpiForApps
    • -
    • Display/EnablePerProcessDpi
    • -
    • Display/EnablePerProcessDpiForApps
    • -
    • Experience/AllowWindowsSpotlightOnSettings
    • -
    • KioskBrowser/BlockedUrlExceptions
    • -
    • KioskBrowser/BlockedUrls
    • -
    • KioskBrowser/DefaultURL
    • -
    • KioskBrowser/EnableEndSessionButton
    • -
    • KioskBrowser/EnableHomeButton
    • -
    • KioskBrowser/EnableNavigationButtons
    • -
    • KioskBrowser/RestartOnIdleTime
    • -
    • LanmanWorkstation/EnableInsecureGuestLogons
    • -
    • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
    • -
    • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
    • -
    • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
    • -
    • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
    • -
    • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
    • -
    • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
    • -
    • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
    • -
    • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
    • -
    • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
    • -
    • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
    • -
    • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
    • -
    • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
    • -
    • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
    • -
    • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
    • -
    • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
    • -
    • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
    • -
    • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
    • -
    • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
    • -
    • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
    • -
    • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
    • -
    • Notifications/DisallowCloudNotification
    • -
    • RestrictedGroups/ConfigureGroupMembership
    • -
    • Search/AllowCortanaInAAD
    • -
    • Search/DoNotUseWebResults
    • -
    • Security/ConfigureWindowsPasswords
    • -
    • Start/DisableContextMenus
    • -
    • System/FeedbackHubAlwaysSaveDiagnosticsLocally
    • -
    • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
    • -
    • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
    • -
    • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
    • -
    • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
    • -
    • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
    • -
    • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
    • -
    • TaskScheduler/EnableXboxGameSaveTask
    • -
    • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
    • -
    • TextInput/ForceTouchKeyboardDockedState
    • -
    • TextInput/TouchKeyboardDictationButtonAvailability
    • -
    • TextInput/TouchKeyboardEmojiButtonAvailability
    • -
    • TextInput/TouchKeyboardFullModeAvailability
    • -
    • TextInput/TouchKeyboardHandwritingModeAvailability
    • -
    • TextInput/TouchKeyboardNarrowModeAvailability
    • -
    • TextInput/TouchKeyboardSplitModeAvailability
    • -
    • TextInput/TouchKeyboardWideModeAvailability
    • -
    • Update/ConfigureFeatureUpdateUninstallPeriod
    • -
    • UserRights/AccessCredentialManagerAsTrustedCaller
    • -
    • UserRights/AccessFromNetwork
    • -
    • UserRights/ActAsPartOfTheOperatingSystem
    • -
    • UserRights/AllowLocalLogOn
    • -
    • UserRights/BackupFilesAndDirectories
    • -
    • UserRights/ChangeSystemTime
    • -
    • UserRights/CreateGlobalObjects
    • -
    • UserRights/CreatePageFile
    • -
    • UserRights/CreatePermanentSharedObjects
    • -
    • UserRights/CreateSymbolicLinks
    • -
    • UserRights/CreateToken
    • -
    • UserRights/DebugPrograms
    • -
    • UserRights/DenyAccessFromNetwork
    • -
    • UserRights/DenyLocalLogOn
    • -
    • UserRights/DenyRemoteDesktopServicesLogOn
    • -
    • UserRights/EnableDelegation
    • -
    • UserRights/GenerateSecurityAudits
    • -
    • UserRights/ImpersonateClient
    • -
    • UserRights/IncreaseSchedulingPriority
    • -
    • UserRights/LoadUnloadDeviceDrivers
    • -
    • UserRights/LockMemory
    • -
    • UserRights/ManageAuditingAndSecurityLog
    • -
    • UserRights/ManageVolume
    • -
    • UserRights/ModifyFirmwareEnvironment
    • -
    • UserRights/ModifyObjectLabel
    • -
    • UserRights/ProfileSingleProcess
    • -
    • UserRights/RemoteShutdown
    • -
    • UserRights/RestoreFilesAndDirectories
    • -
    • UserRights/TakeOwnership
    • -
    • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
    • -
    • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
    • -
    • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
    • -
    • WindowsDefenderSecurityCenter/HideSecureBoot
    • -
    • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
    • -
    -

    Security/RequireDeviceEncryption - updated to show it is supported in desktop.

    +
  • DeviceStatus/TPM/SpecificationVersion
  • +
  • DeviceStatus/OS/Edition
  • +
  • DeviceStatus/Antivirus/SignatureStatus
  • +
  • DeviceStatus/Antivirus/Status
  • +
  • DeviceStatus/Antispyware/SignatureStatus
  • +
  • DeviceStatus/Antispyware/Status
  • +
  • DeviceStatus/Firewall/Status
  • +
  • DeviceStatus/UAC/Status
  • +
  • DeviceStatus/Battery/Status
  • +
  • DeviceStatus/Battery/EstimatedChargeRemaining
  • +
  • DeviceStatus/Battery/EstimatedRuntime
  • +
    [BitLocker CSP](bitlocker-csp.md)

    Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

    -
    [DMClient CSP](dmclient-csp.md)

    Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

    -
      -
    • AADSendDeviceToken
    • -
    • BlockInStatusPage
    • -
    • AllowCollectLogsButton
    • -
    • CustomErrorText
    • -
    • SkipDeviceStatusPage
    • -
    • SkipUserStatusPage
    • -
    -
    [Defender CSP](defender-csp.md)

    Added new node (OfflineScan) in Windows 10, version 1803.

    -
    [UEFI CSP](uefi-csp.md)

    Added a new CSP in Windows 10, version 1803.

    -
    [Update CSP](update-csp.md)

    Added the following nodes in Windows 10, version 1803:

    -
      -
    • Rollback
    • -
    • Rollback/FeatureUpdate
    • -
    • Rollback/QualityUpdateStatus
    • -
    • Rollback/FeatureUpdateStatus
    • -
    -
    [AssignedAccess CSP](assignedaccess-csp.md)

    Added the following nodes in Windows 10, version 1803:

    -
      -
    • Status
    • -
    • ShellLauncher
    • -
    • StatusConfiguration
    • -
    -

    Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

    -

    Added SyncML examples.

    [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
      +
    • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
    • +
    • Updated the DDF and XSD file sections.
    • +
    [MultiSIM CSP](multisim-csp.md)

    Added a new CSP in Windows 10, version 1803.

    -
    [SecureAssessment CSP](secureassessment-csp.md)

    New CSP for Windows 10, version 1607

    [DiagnosticLog CSP](diagnosticlog-csp.md) +

    [DiagnosticLog DDF](diagnosticlog-ddf.md)

    Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

    +
      +
    • DeviceStateData
    • +
    • DeviceStateData/MdmConfiguration
    • +
    [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

    Added the following node in Windows 10, version 1803:

    +
    [Reboot CSP](reboot-csp.md)

    New CSP for Windows 10, version 1607

    [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

    New CSP for Windows 10, version 1607

    [VPNv2 CSP](vpnv2-csp.md)

    Added the following settings for Windows 10, version 1607

      -
    • MaintainProcessorArchitectureOnUpdate
    • -
    -
    [eUICCs CSP](euiccs-csp.md)

    Added the following node in Windows 10, version 1803:

    +
  • ProfileName/RouteList/routeRowId/ExclusionRoute
  • +
  • ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
  • +
  • ProfileName/DomainNameInformationList/dniRowId/Persistent
  • +
  • ProfileName/ProfileXML
  • +
  • ProfileName/DeviceCompliance/Enabled
  • +
  • ProfileName/DeviceCompliance/Sso
  • +
  • ProfileName/DeviceCompliance/Sso/Enabled
  • +
  • ProfileName/DeviceCompliance/Sso/IssuerHash
  • +
  • ProfileName/DeviceCompliance/Sso/Eku
  • +
  • ProfileName/NativeProfile/CryptographySuite
  • +
  • ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
  • +
  • ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
  • +
  • ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
  • +
  • ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
  • +
  • ProfileName/NativeProfile/CryptographySuite/DHGroup
  • +
  • ProfileName/NativeProfile/CryptographySuite/PfsGroup
  • +
  • ProfileName/NativeProfile/L2tpPsk
  • +
    [Win32AppInventory CSP](win32appinventory-csp.md) +

    [Win32AppInventory DDF](win32appinventory-ddf-file.md)

    New CSP for Windows 10, version 1607.

    [SharedPC CSP](sharedpc-csp.md)

    New CSP for Windows 10, version 1607.

    [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

    New CSP for Windows 10, version 1607.

    [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

    Added new classes for Windows 10, version 1607.

    [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

    Topic renamed from "Enrollment UI".

    +

    Completely updated enrollment procedures and screenshots.

    [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) +

    [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

    Added the following new setting for Windows 10, version 1607:

      -
    • IsEnabled
    • -
    -
    [DeviceStatus CSP](devicestatus-csp.md)

    Added the following node in Windows 10, version 1803:

    +
  • NextSession/HORMEnabled
  • +
    [CertificateStore CSP](certificatestore-csp.md) +

    [CertificateStore DDF file](certificatestore-ddf-file.md)

    Added the following new settings in Windows 10, version 1607:

      -
    • OS/Mode
    • -
    -
    [AccountManagement CSP](accountmanagement-csp.md)

    Added a new CSP in Windows 10, version 1803.

    -
    [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

    Added the following node in Windows 10, version 1803:

    +
  • My/WSTEP/Renew/LastRenewalAttemptTime
  • +
  • My/WSTEP/Renew/RenewNow
  • +

    [WindowsLicensing CSP](windowslicensing-csp.md)

    Added the following new node and settings in Windows 10, version 1607, but not documented:

      -
    • UntrustedCertificates
    • +
    • Subscriptions
    • +
    • Subscriptions/SubscriptionId
    • +
    • Subscriptions/SubscriptionId/Status
    • +
    • Subscriptions/SubscriptionId/Name
    -
    [NetworkProxy CSP](\networkproxy--csp.md)

    Added the following node in Windows 10, version 1803:

    -
      -
    • ProxySettingsPerUser
    • -
    -
    [Accounts CSP](accounts-csp.md)

    Added a new CSP in Windows 10, version 1803.

    -
    [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

    Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

    -
    [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

    Added the DDF download of Windows 10, version 1803 configuration service providers.

    -
    -## What's new in Windows 10, version 1809 +## What’s new in MDM for Windows 10, version 1511 @@ -1387,175 +1435,173 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

    The following policies have been updated in the Policy CSP:

    + +

    The following policies have been deprecated in the Policy CSP:

    + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    New or updated topicItem Description
    [Policy CSP](policy-configuration-service-provider.md)

    Added the following new policies in Windows 10, version 1809:

    +

    New configuration service providers added in Windows 10, version 1511

      +
    • [AllJoynManagement CSP](alljoynmanagement-csp.md)
    • +
    • [Maps CSP](maps-csp.md)
    • +
    • [Reporting CSP](reporting-csp.md)
    • +
    • [SurfaceHub CSP](surfacehub-csp.md)
    • +
    • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
    • +

    New and updated policies in Policy CSP

    The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

      -
    • ApplicationManagement/LaunchAppAfterLogOn
    • -
    • ApplicationManagement/ScheduleForceRestartForUpdateFailures
    • -
    • Authentication/EnableFastFirstSignIn
    • -
    • Authentication/EnableWebSignIn
    • -
    • Authentication/PreferredAadTenantDomainName
    • -
    • Browser/AllowFullScreenMode
    • -
    • Browser/AllowPrelaunch
    • -
    • Browser/AllowPrinting
    • -
    • Browser/AllowSavingHistory
    • -
    • Browser/AllowSideloadingOfExtensions
    • -
    • Browser/AllowTabPreloading
    • -
    • Browser/AllowWebContentOnNewTabPage
    • -
    • Browser/ConfigureFavoritesBar
    • -
    • Browser/ConfigureHomeButton
    • -
    • Browser/ConfigureKioskMode
    • -
    • Browser/ConfigureKioskResetAfterIdleTimeout
    • -
    • Browser/ConfigureOpenMicrosoftEdgeWith
    • -
    • Browser/ConfigureTelemetryForMicrosoft365Analytics
    • -
    • Browser/PreventCertErrorOverrides
    • -
    • Browser/SetHomeButtonURL
    • -
    • Browser/SetNewTabPageURL
    • -
    • Browser/UnlockHomeButton
    • -
    • Defender/CheckForSignaturesBeforeRunningScan
    • -
    • Defender/DisableCatchupFullScan
    • -
    • Defender/DisableCatchupQuickScan
    • -
    • Defender/EnableLowCPUPriority
    • -
    • Defender/SignatureUpdateFallbackOrder
    • -
    • Defender/SignatureUpdateFileSharesSources
    • -
    • DeviceGuard/ConfigureSystemGuardLaunch
    • -
    • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
    • -
    • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
    • -
    • DeviceInstallation/PreventDeviceMetadataFromNetwork
    • -
    • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
    • -
    • DmaGuard/DeviceEnumerationPolicy
    • -
    • Experience/AllowClipboardHistory
    • -
    • Experience/DoNotSyncBrowserSettings
    • -
    • Experience/PreventUsersFromTurningOnBrowserSyncing
    • -
    • Kerberos/UPNNameHints
    • -
    • Privacy/AllowCrossDeviceClipboard
    • -
    • Privacy/DisablePrivacyExperience
    • -
    • Privacy/UploadUserActivities
    • -
    • Security/RecoveryEnvironmentAuthentication
    • -
    • System/AllowDeviceNameInDiagnosticData
    • -
    • System/ConfigureMicrosoft365UploadEndpoint
    • -
    • System/DisableDeviceDelete
    • -
    • System/DisableDiagnosticDataViewer
    • -
    • Storage/RemovableDiskDenyWriteAccess
    • -
    • TaskManager/AllowEndTask
    • -
    • Update/EngagedRestartDeadlineForFeatureUpdates
    • -
    • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
    • -
    • Update/EngagedRestartTransitionScheduleForFeatureUpdates
    • -
    • Update/SetDisablePauseUXAccess
    • -
    • Update/SetDisableUXWUAccess
    • -
    • WindowsDefenderSecurityCenter/DisableClearTpmButton
    • -
    • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
    • -
    • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
    • -
    • WindowsLogon/DontDisplayNetworkSelectionUI
    • +
    • Accounts/DomainNamesForEmailSync
    • +
    • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
    • +
    • Bluetooth/ServicesAllowedList
    • +
    • DataProtection/AllowAzureRMSForEDP
    • +
    • DataProtection/RevokeOnUnenroll
    • +
    • DeviceLock/DevicePasswordExpiration
    • +
    • DeviceLock/DevicePasswordHistory
    • +
    • TextInput/AllowInputPanel
    • +
    • Update/PauseDeferrals
    • +
    • Update/RequireDeferUpdate
    • +
    • Update/RequireUpdateApproval
    -
    [PassportForWork CSP](passportforwork-csp.md)

    Added new settings in Windows 10, version 1809.

    -
    [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

    Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

    -
    [Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

    Added new configuration service provider in Windows 10, version 1809.

    -
    [WindowsLicensing CSP](windowslicensing-csp.md)

    Added S mode settings and SyncML examples in Windows 10, version 1809.

    -
    [SUPL CSP](supl-csp.md)

    Added 3 new certificate nodes in Windows 10, version 1809.

    -
    [Defender CSP](defender-csp.md)

    Added a new node Health/ProductStatus in Windows 10, version 1809.

    -
    [BitLocker CSP](bitlocker-csp.md)

    Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

    -
    [DevDetail CSP](devdetail-csp.md)

    Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

    -
    [Wifi CSP](wifi-csp.md)

    Added a new node WifiCost in Windows 10, version 1809.

    -
    [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

    Added new settings in Windows 10, version 1809.

    -
    [RemoteWipe CSP](remotewipe-csp.md)

    Added new settings in Windows 10, version 1809.

    -
    [TenantLockdown CSP](tenantlockdown-csp.md)

    Added new CSP in Windows 10, version 1809.

    -
    [Office CSP](office-csp.md)

    Added FinalStatus setting in Windows 10, version 1809.

    -

    Management tool for the Micosoft Store for Business

    New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

    Custom header for generic alert

    The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

    +MDM-GenericAlert: <AlertType1><AlertType2> +

    If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

    Alert message for slow client response

    When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

    +

    To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

    New node in DMClient CSP

    Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

    New nodes in EnterpriseModernAppManagement CSP

    Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

    +
      +
    • AppManagement/GetInventoryQuery
    • +
    • AppManagement/GetInventoryResults
    • +
    • .../PackageFamilyName/AppSettingPolicy/SettingValue
    • +
    • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
    • +
    • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
    • +
    • AppLicenses/StoreLicenses/LicenseID/RequesterID
    • +
    • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
    • +

    New nodes in EnterpriseExt CSP

    Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

    +
      +
    • DeviceCustomData (CustomID, CustomeString)
    • +
    • Brightness (Default, MaxAuto)
    • +
    • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
    • +

    New node in EnterpriseExtFileSystem CSP

    Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

    New nodes in PassportForWork CSP

    Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

    +
      +
    • TenantId/Policies/PINComplexity/History
    • +
    • TenantId/Policies/PINComplexity/Expiration
    • +
    • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
    • +
    • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
    • +
    • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
    • +

    Updated EnterpriseAssignedAccess CSP

    Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

    +
      +
    • In AssignedAccessXML node, added new page settings and quick action settings.
    • +
    • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
    • +
    • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
    • +

    New nodes in the DevDetail CSP

    Here are the changes to the [DevDetail CSP](devdetail-csp.md):

    +
      +
    • Added TotalStore and TotalRAM settings.
    • +
    • Added support for Replace command for the DeviceName setting.
    • +

    Handling large objects

    Added support for the client to handle uploading of large objects to the server.

    - ## Breaking changes and known issues -### Get command inside an atomic command is not supported +### Get command inside an atomic command is not supported In Windows 10, a Get command inside an atomic command is not supported. This was allowed in Windows Phone 8 and Windows Phone 8.1. -### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 +### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 During an upgrade from Windows 8.1 to Windows 10, the notification channel URI information is not preserved. In addition, the MDM client loses the PFN, AppID, and client secret. After upgrading to Windows 10, you should call MDM\_WNSConfiguration class to recreate the notification channel URI. -### Apps installed using WMI classes are not removed +### Apps installed using WMI classes are not removed Applications installed using WMI classes are not removed when the MDM account is removed from device. -### Passing CDATA in SyncML does not work +### Passing CDATA in SyncML does not work Passing CDATA in data in SyncML to ConfigManager and CSPs does not work in Windows 10. It worked in Windows Phone 8. -### SSL settings in IIS server for SCEP must be set to "Ignore" +### SSL settings in IIS server for SCEP must be set to "Ignore" The certificate setting under "SSL Settings" in the IIS server for SCEP must be set to "Ignore" in Windows 10. In Windows Phone 8.1, when you set the client certificate to "Accept," it works fine. ![ssl settings](images/ssl-settings.png) -### MDM enrollment fails on the mobile device when traffic is going through proxy +### MDM enrollment fails on the mobile device when traffic is going through proxy When the mobile device is configured to use a proxy that requires authentication, the enrollment will fail. To work around this issue, the user can use a proxy that does not require authentication or remove the proxy setting from the connected network. -### Server-initiated unenrollment failure +### Server-initiated unenrollment failure Server-initiated unenrollment for a device enrolled by adding a work account silently fails leaving the MDM account active. MDM policies and resources are still in place and the client can continue to sync with the server. Remote server unenrollment is disabled for mobile devices enrolled via Azure Active Directory Join. It returns an error message to the server. The only way to remove enrollment for a mobile device that is Azure AD joined is by remotely wiping the device. -### Certificates causing issues with Wi-Fi and VPN +### Certificates causing issues with Wi-Fi and VPN Currently in Windows 10, version 1511, when using the ClientCertificateInstall to install certificates to the device store and the user store and both certificates are sent to the device in the same MDM payload, the certificate intended for the device store will also get installed in the user store. This may cause issues with Wi-Fi or VPN when choosing the correct certificate to establish a connection. We are working to fix this issue. -### Version information for mobile devices +### Version information for mobile devices The software version information from **DevDetail/SwV** does not match the version in **Settings** under **System/About**. -### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues +### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues - When you upgrade Windows Phone 8.1 devices to Windows 10 Mobile using ApplicationRestrictions with a list of allowed apps, some Windows inbox apps get blocked causing unexpected behavior. To work around this issue, you must include the [inbox apps](applocker-csp.md#inboxappsandcomponents) that you need to your list of allowed apps. @@ -1575,7 +1621,7 @@ The software version information from **DevDetail/SwV** does not match the versi No workaround is available at this time. An OS update to fix this issue is coming soon. -### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 +### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 Applies only to phone prior to build 10586.218: When ApplicationManagement/ApplicationRestrictions policy is deployed to Windows 10 Mobile, installation and update of apps dependent on Microsoft Frameworks may get blocked with error 0x80073CF9. To work around this issue, you must include the Microsoft Framework Id to your list of allowed apps. @@ -1583,7 +1629,7 @@ Applies only to phone prior to build 10586.218: When ApplicationManagement/Appli ``` -### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile +### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile In your deployment, if you have multiple certificates provisioned on the device and the Wi-Fi profile provisioned does not have a strict filtering criteria, you may see connection failures when connecting to Wi-Fi. The solution is to ensure that the Wi-Fi profile provisioned has strict filtering criteria such that it matches only one certificate. @@ -1756,26 +1802,49 @@ Alternatively you can use the following procedure to create an EAP Configuration >You can also set all the other applicable EAP Properties through this UI as well. A guide for what these properties mean can be found in the [Extensible Authentication Protocol (EAP) Settings for Network Access](https://technet.microsoft.com/library/hh945104.aspx) topic. -### Remote PIN reset not supported in Azure Active Directory joined mobile devices +### Remote PIN reset not supported in Azure Active Directory joined mobile devices In Windows 10 Mobile, remote PIN reset in Azure AD joined devices are not supported. Devices are wiped when you issue a remote PIN reset command using the RemoteLock CSP. -### MDM client will immediately check-in with the MDM server after client renews WNS channel URI +### MDM client will immediately check-in with the MDM server after client renews WNS channel URI Starting in Windows 10, after the MDM client automatically renews the WNS channel URI, the MDM client will immediately check-in with the MDM server. Henceforth, for every MDM client check-in, the MDM server should send a GET request for "ProviderID/Push/ChannelURI" to retrieve the latest channel URI and compare it with the existing channel URI; then update the channel URI if necessary. -### User provisioning failure in Azure Active Directory joined Windows 10 PC +### User provisioning failure in Azure Active Directory joined Windows 10 PC In Azure AD joined Windows 10 PC, provisioning /.User resources fails when the user is not logged in as an Azure AD user. If you attempt to join Azure AD from **Settings** > **System** > **About** user interface, make sure to log off and log on with Azure AD credentials to get your organizational configuration from your MDM server. This behavior is by design. -### Requirements to note for VPN certificates also used for Kerberos Authentication +### Requirements to note for VPN certificates also used for Kerberos Authentication If you want to use the certificate used for VPN authentication also for Kerberos authentication (required if you need access to on-premises resources using NTLM or Kerberos), the user's certificate must meet the requirements for smart card certificate, the Subject field should contain the DNS domain name in the DN or the SAN should contain a fully qualified UPN so that the DC can be located from the DNS registrations. If certificates that do not meet these requirements are used for VPN, users may fail to access resources that require Kerberos authentication. This issue primarily impacts Windows Phone. -### Device management agent for the push-button reset is not working +### Device management agent for the push-button reset is not working The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware/commercialize/manufacture/desktop/push-button-reset-overview) keeps the registry settings for OMA DM sessions, but deletes the task schedules. The client enrollment is retained, but it never syncs with the MDM service. +## Frequently Asked Questions + + +###**Can there be more than 1 MDM server to enroll and manage devices in Windows 10?** +No. Only one MDM is allowed. + +###**How do I set the maximum number of Azure Active Directory joined devices per user?** +1. Login to the portal as tenant admin: https://manage.windowsazure.com. +2. Click Active Directory on the left pane. +3. Choose your tenant. +4. Click **Configure**. +5. Set quota to unlimited. + + ![aad maximum joined devices](images/faq-max-devices.png) +  + +###**What is dmwappushsvc?** + +Entry | Description +--------------- | -------------------- +What is dmwappushsvc? | It is a Windows service that ships in Windows 10 operating system as a part of the windows management platform. It is used internally by the operating system as a queue for categorizing and processing all WAP messages, which include Windows management messages, MMS, NabSync, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server. | +What data is handled by dmwappushsvc? | It is a component handling the internal workings of the management platform and involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further: MMS, NabSync, SI/SL. | +How do I turn if off? | The service can be stopped from the "Services" console on the device (Start > Run > services.msc). However, since this is a component part of the OS and required for the proper functioning of the device, we strongly recommend not to do this. | ## Change history in MDM documentation @@ -1943,8 +2012,8 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware