diff --git a/windows/client-management/mdm/bitlocker-csp.md b/windows/client-management/mdm/bitlocker-csp.md
index 456fbbd28c..c0d680c371 100644
--- a/windows/client-management/mdm/bitlocker-csp.md
+++ b/windows/client-management/mdm/bitlocker-csp.md
@@ -68,24 +68,16 @@ Defines the root node for the BitLocker configuration service provider.
Allows the administrator to require storage card encryption on the device. This policy is valid only for a mobile SKU.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|No|No|
+|Business|No|No|
+|Enterprise|No|No|
+|Education|No|No|
+|Mobile|Yes|Yes|
+
Data type is integer. Sample value for this node to enable this policy: 1. Disabling this policy will not turn off the encryption on the storage card, but the user will no longer be prompted to turn it on.
@@ -124,24 +116,16 @@ Data type is integer. Supported operations are Add, Get, Replace, and Delete.
Allows the administrator to require encryption to be turned on by using BitLocker\Device Encryption.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|Yes|Yes|
+
Data type is integer. Sample value for this node to enable this policy: 1.
Supported operations are Add, Get, Replace, and Delete.
@@ -193,24 +177,16 @@ If you want to disable this policy, use the following SyncML:
Allows you to set the default encryption method for each of the different drive types: operating system drives, fixed data drives, and removable data drives. Hidden, system, and recovery partitions are skipped from encryption. This setting is a direct mapping to the BitLocker Group Policy "Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)".
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -276,26 +252,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
Allows you to associate unique organizational identifiers to a new drive that is enabled with BitLocker.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -347,26 +313,16 @@ If you disable or do not configure this setting, the identification field is not
Allows users on devices that are compliant with InstantGo or the Microsoft Hardware Security Test Interface (HSTI) to not have a PIN for preboot authentication.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -400,26 +356,16 @@ If this policy is disabled, the options of "Require additional authentication at
Allows users to configure whether or not enhanced startup PINs are used with BitLocker.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -456,26 +402,16 @@ If you disable or do not configure this policy setting, enhanced PINs will not b
Allows you to configure whether standard users are allowed to change BitLocker PIN or password that is used to protect the operating system drive.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -512,26 +448,16 @@ Sample value for this node to disable this policy is:
Allows users to enable authentication options that require user input from the preboot environment, even if the platform indicates a lack of preboot input capability.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -574,26 +500,16 @@ When the Windows Recovery Environment is not enabled and this policy is not enab
Allows you to configure the encryption type that is used by BitLocker.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -633,26 +549,16 @@ For more information about the tool to manage BitLocker, see [Manage-bde](/windo
This setting is a direct mapping to the BitLocker Group Policy "Require additional authentication at startup".
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -741,26 +647,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
This setting is a direct mapping to the BitLocker Group Policy "Configure minimum PIN length for startup".
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -818,26 +714,16 @@ This setting is a direct mapping to the BitLocker Group Policy "Configure pre-bo
(PrebootRecoveryInfo_Name).
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -907,26 +793,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
This setting is a direct mapping to the BitLocker Group Policy "Choose how BitLocker-protected operating system drives can be recovered" (OSRecoveryUsage_Name).
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1004,26 +880,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
This setting is a direct mapping to the BitLocker Group Policy "Choose how BitLocker-protected fixed drives can be recovered" ().
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1110,26 +976,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
This setting is a direct mapping to the BitLocker Group Policy "Deny write access to fixed drives not protected by BitLocker" (FDVDenyWriteAccess_Name).
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1179,26 +1035,16 @@ Data type is string. Supported operations are Add, Get, Replace, and Delete.
Allows you to configure the encryption type on fixed data drives that is used by BitLocker.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1240,26 +1086,16 @@ For more information about the tool to manage BitLocker, see [Manage-bde](/windo
This setting is a direct mapping to the BitLocker Group Policy "Deny write access to removable drives not protected by BitLocker" (RDVDenyWriteAccess_Name).
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1320,26 +1156,16 @@ Disabling the policy will let the system choose the default behaviors. If you wa
Allows you to configure the encryption type that is used by BitLocker.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1375,26 +1201,16 @@ If this policy is disabled or not configured, the BitLocker Setup Wizard asks th
Allows you to control the use of BitLocker on removable data drives.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
ADMX Info:
@@ -1445,26 +1261,16 @@ Allows the admin to disable the warning prompt for other disk encryption on the
> [!Warning]
> When you enable BitLocker on a device with third-party encryption, it may render the device unusable and require you to reinstall Windows.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
The following list shows the supported values:
@@ -1509,26 +1315,16 @@ Allows Admin to enforce "RequireDeviceEncryption" policy for scenarios where pol
If "AllowWarningForOtherDiskEncryption" is not set, or is set to "1", "RequireDeviceEncryption" policy will not try to encrypt drive(s) if a standard user is the current logged on user in the system.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
The expected values for this policy are:
@@ -1564,26 +1360,16 @@ This setting initiates a client-driven recovery password refresh after an OS dri
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
Value type is int. Supported operations are Add, Delete, Get, and Replace.
@@ -1619,26 +1405,16 @@ Each server-side recovery key rotation is represented by a request ID. The serve
- RotateRecoveryPasswordsRequestID: Returns request ID of last request processed.
- RotateRecoveryPasswordsRotationStatus: Returns status of last request processed.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
Value type is string. Supported operation is Execute. Request ID is expected as a parameter.
@@ -1664,26 +1440,16 @@ Interior node. Supported operation is Get.
This node reports compliance state of device encryption on the system.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
@@ -1732,26 +1498,16 @@ Status code can be one of the following:
- 0 - Pass
- Any other code - Failure HRESULT
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
Value type is int. Supported operation is Get.
@@ -1767,26 +1523,16 @@ This node reports the RequestID corresponding to RotateRecoveryPasswordsStatus.
This node needs to be queried in synchronization with RotateRecoveryPasswordsStatus to ensure the status is correctly matched to the request ID.
-
-
- Home |
- Pro |
- Business |
- Enterprise |
- Education |
- Mobile |
-
-
-
-  |
-  |
-  |
-  |
-  |
-  |
-
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
+|Mobile|No|No|
+
diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md
index a2120ee9fb..e3bcc31993 100644
--- a/windows/client-management/mdm/policy-csp-update.md
+++ b/windows/client-management/mdm/policy-csp-update.md
@@ -2422,38 +2422,14 @@ This policy is deprecated. Use [Update/RequireUpdateApproval](#update-requireupd
**Update/ProductVersion**
-
-
- Edition |
- Windows 10 |
- Windows 11 |
-
-
- Home |
- No |
- No |
-
-
- Pro |
- Yes |
- Yes |
-
-
- Business |
- Yes |
- Yes |
-
-
- Enterprise |
- Yes |
- Yes |
-
-
- Education |
- Yes |
- Yes |
-
-
+
+|Edition|Windows 10|Windows 11|
+|--- |--- |--- |
+|Home|No|No|
+|Pro|Yes|Yes|
+|Business|Yes|Yes|
+|Enterprise|Yes|Yes|
+|Education|Yes|Yes|
diff --git a/windows/configuration/provisioning-packages/provisioning-packages.md b/windows/configuration/provisioning-packages/provisioning-packages.md
index 8f3f00962f..6c9e724c17 100644
--- a/windows/configuration/provisioning-packages/provisioning-packages.md
+++ b/windows/configuration/provisioning-packages/provisioning-packages.md
@@ -86,18 +86,6 @@ The following table describes settings that you can configure using the wizards
| Configure kiosk common settings | Set tablet mode, configure welcome and shutdown screens, turn off timeout settings | ❌ | ✔️ | ❌ |
| Developer Setup | Enable Developer Mode | ❌ | ❌ | ✔️ |
-
-
-
-
-
-
-
-
-
-
-
-
- [Instructions for the desktop wizard](provision-pcs-for-initial-deployment.md)
- [Instructions for the kiosk wizard](../kiosk-single-app.md#wizard)
- [Instructions for the HoloLens wizard](/hololens/hololens-provisioning#wizard)