mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
CSP Updates for October 2024
This commit is contained in:
parent
ab3b161c10
commit
90d05214e9
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: DeclaredConfiguration CSP
|
title: DeclaredConfiguration CSP
|
||||||
description: Learn more about the DeclaredConfiguration CSP.
|
description: Learn more about the DeclaredConfiguration CSP.
|
||||||
ms.date: 09/12/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -45,6 +45,8 @@ The following list shows the DeclaredConfiguration configuration service provide
|
|||||||
- [Results](#hostinventoryresults)
|
- [Results](#hostinventoryresults)
|
||||||
- [{DocID}](#hostinventoryresultsdocid)
|
- [{DocID}](#hostinventoryresultsdocid)
|
||||||
- [Document](#hostinventoryresultsdociddocument)
|
- [Document](#hostinventoryresultsdociddocument)
|
||||||
|
- [ManagementServiceConfiguration](#managementserviceconfiguration)
|
||||||
|
- [ConflictResolution](#managementserviceconfigurationconflictresolution)
|
||||||
<!-- DeclaredConfiguration-Tree-End -->
|
<!-- DeclaredConfiguration-Tree-End -->
|
||||||
|
|
||||||
<!-- Device-Host-Begin -->
|
<!-- Device-Host-Begin -->
|
||||||
@ -728,6 +730,93 @@ The Document node's value is an XML based document containing a collection of se
|
|||||||
|
|
||||||
<!-- Device-Host-Inventory-Results-{DocID}-Document-End -->
|
<!-- Device-Host-Inventory-Results-{DocID}-Document-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Begin -->
|
||||||
|
## ManagementServiceConfiguration
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/DeclaredConfiguration/ManagementServiceConfiguration
|
||||||
|
```
|
||||||
|
<!-- Device-ManagementServiceConfiguration-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
The ManagementServiceConfiguration node that's used to control certain Windows Declared Configuration behavior.
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Description-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Editable-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `node` |
|
||||||
|
| Access Type | Get |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-Examples-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Begin -->
|
||||||
|
### ManagementServiceConfiguration/ConflictResolution
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/DeclaredConfiguration/ManagementServiceConfiguration/ConflictResolution
|
||||||
|
```
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This node controls to turn on conflict resolution on and off.
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Description-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Editable-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | The conflict resolution is OFF. |
|
||||||
|
| 1 | The conflict resolution is ON. |
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-Examples-End -->
|
||||||
|
|
||||||
|
<!-- Device-ManagementServiceConfiguration-ConflictResolution-End -->
|
||||||
|
|
||||||
<!-- DeclaredConfiguration-CspMoreInfo-Begin -->
|
<!-- DeclaredConfiguration-CspMoreInfo-Begin -->
|
||||||
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
||||||
## DeclaredConfiguration OMA URI
|
## DeclaredConfiguration OMA URI
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: DeclaredConfiguration DDF file
|
title: DeclaredConfiguration DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the DeclaredConfiguration configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the DeclaredConfiguration configuration service provider.
|
||||||
ms.date: 06/28/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -466,6 +466,61 @@ The following XML file contains the device description framework (DDF) for the D
|
|||||||
</Node>
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
|
<Node>
|
||||||
|
<NodeName>ManagementServiceConfiguration</NodeName>
|
||||||
|
<DFProperties>
|
||||||
|
<AccessType>
|
||||||
|
<Get />
|
||||||
|
</AccessType>
|
||||||
|
<Description>The ManagementServiceConfiguration node that is used to control certain Windows Declared Configuration behavior</Description>
|
||||||
|
<DFFormat>
|
||||||
|
<node />
|
||||||
|
</DFFormat>
|
||||||
|
<Occurrence>
|
||||||
|
<One />
|
||||||
|
</Occurrence>
|
||||||
|
<Scope>
|
||||||
|
<Dynamic />
|
||||||
|
</Scope>
|
||||||
|
<DFType>
|
||||||
|
<DDFName />
|
||||||
|
</DFType>
|
||||||
|
</DFProperties>
|
||||||
|
<Node>
|
||||||
|
<NodeName>ConflictResolution</NodeName>
|
||||||
|
<DFProperties>
|
||||||
|
<AccessType>
|
||||||
|
<Add />
|
||||||
|
<Delete />
|
||||||
|
<Get />
|
||||||
|
<Replace />
|
||||||
|
</AccessType>
|
||||||
|
<Description>This node controls to turn on conflict resolution on and off.</Description>
|
||||||
|
<DFFormat>
|
||||||
|
<int />
|
||||||
|
</DFFormat>
|
||||||
|
<Occurrence>
|
||||||
|
<One />
|
||||||
|
</Occurrence>
|
||||||
|
<Scope>
|
||||||
|
<Dynamic />
|
||||||
|
</Scope>
|
||||||
|
<DFType>
|
||||||
|
<MIME />
|
||||||
|
</DFType>
|
||||||
|
<MSFT:AllowedValues ValueType="ENUM">
|
||||||
|
<MSFT:Enum>
|
||||||
|
<MSFT:Value>0</MSFT:Value>
|
||||||
|
<MSFT:ValueDescription>The conflict resolution is OFF.</MSFT:ValueDescription>
|
||||||
|
</MSFT:Enum>
|
||||||
|
<MSFT:Enum>
|
||||||
|
<MSFT:Value>1</MSFT:Value>
|
||||||
|
<MSFT:ValueDescription>The conflict resolution is ON.</MSFT:ValueDescription>
|
||||||
|
</MSFT:Enum>
|
||||||
|
</MSFT:AllowedValues>
|
||||||
|
</DFProperties>
|
||||||
|
</Node>
|
||||||
|
</Node>
|
||||||
</Node>
|
</Node>
|
||||||
</MgmtTree>
|
</MgmtTree>
|
||||||
```
|
```
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LAPS CSP
|
title: LAPS CSP
|
||||||
description: Learn more about the LAPS CSP.
|
description: Learn more about the LAPS CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -325,7 +325,7 @@ Note if a custom managed local administrator account name is specified in this s
|
|||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
||||||
|
|
||||||
@ -387,7 +387,7 @@ If not specified, this setting defaults to True.
|
|||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LAPS DDF file
|
title: LAPS DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the LAPS configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the LAPS configuration service provider.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -80,7 +80,7 @@ The following XML file contains the device description framework (DDF) for the L
|
|||||||
The allowable settings are:
|
The allowable settings are:
|
||||||
|
|
||||||
0=Disabled (password will not be backed up)
|
0=Disabled (password will not be backed up)
|
||||||
1=Backup the password to Azure AD only
|
1=Backup the password to Microsoft Entra ID only
|
||||||
2=Backup the password to Active Directory only
|
2=Backup the password to Active Directory only
|
||||||
|
|
||||||
If not specified, this setting will default to 0.</Description>
|
If not specified, this setting will default to 0.</Description>
|
||||||
@ -103,7 +103,7 @@ If not specified, this setting will default to 0.</Description>
|
|||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>1</MSFT:Value>
|
<MSFT:Value>1</MSFT:Value>
|
||||||
<MSFT:ValueDescription>Backup the password to Azure AD only</MSFT:ValueDescription>
|
<MSFT:ValueDescription>Backup the password to Microsoft Entra ID only</MSFT:ValueDescription>
|
||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>2</MSFT:Value>
|
<MSFT:Value>2</MSFT:Value>
|
||||||
@ -126,7 +126,7 @@ If not specified, this setting will default to 0.</Description>
|
|||||||
|
|
||||||
If not specified, this setting will default to 30 days
|
If not specified, this setting will default to 30 days
|
||||||
|
|
||||||
This setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Azure AD.
|
This setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID.
|
||||||
|
|
||||||
This setting has a maximum allowed value of 365 days.</Description>
|
This setting has a maximum allowed value of 365 days.</Description>
|
||||||
<DFFormat>
|
<DFFormat>
|
||||||
@ -154,7 +154,7 @@ This setting has a maximum allowed value of 365 days.</Description>
|
|||||||
<MSFT:DependencyAllowedValue ValueType="ENUM">
|
<MSFT:DependencyAllowedValue ValueType="ENUM">
|
||||||
<MSFT:Enum>
|
<MSFT:Enum>
|
||||||
<MSFT:Value>1</MSFT:Value>
|
<MSFT:Value>1</MSFT:Value>
|
||||||
<MSFT:ValueDescription>BackupDirectory configured to Azure AD</MSFT:ValueDescription>
|
<MSFT:ValueDescription>BackupDirectory configured to Microsoft Entra ID</MSFT:ValueDescription>
|
||||||
</MSFT:Enum>
|
</MSFT:Enum>
|
||||||
</MSFT:DependencyAllowedValue>
|
</MSFT:DependencyAllowedValue>
|
||||||
</MSFT:Dependency>
|
</MSFT:Dependency>
|
||||||
@ -442,7 +442,7 @@ If not specified, this setting defaults to True.</Description>
|
|||||||
<DefaultValue>True</DefaultValue>
|
<DefaultValue>True</DefaultValue>
|
||||||
<Description>Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
<Description>Use this setting to configure whether the password is encrypted before being stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
This setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.
|
||||||
|
|
||||||
@ -499,7 +499,7 @@ If not specified, this setting defaults to True.</Description>
|
|||||||
</AccessType>
|
</AccessType>
|
||||||
<Description>Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
<Description>Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.
|
||||||
|
|
||||||
This setting is ignored if the password is currently being stored in Azure.
|
This setting is ignored if the password is currently being stored in Microsoft Entra ID.
|
||||||
|
|
||||||
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
If not specified, the password will be decryptable by the Domain Admins group in the device's domain.
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: PassportForWork CSP
|
title: PassportForWork CSP
|
||||||
description: Learn more about the PassportForWork CSP.
|
description: Learn more about the PassportForWork CSP.
|
||||||
ms.date: 08/06/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -265,7 +265,7 @@ If the user forgets their PIN, it can be changed to a new PIN using the Windows
|
|||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-Begin -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 22H2 [10.0.22621] and later |
|
||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-End -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-Applicability-End -->
|
||||||
|
|
||||||
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-OmaUri-Begin -->
|
<!-- Device-{TenantId}-Policies-EnableWindowsHelloProvisioningForSecurityKeys-OmaUri-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: PassportForWork DDF file
|
title: PassportForWork DDF file
|
||||||
description: View the XML file containing the device description framework (DDF) for the PassportForWork configuration service provider.
|
description: View the XML file containing the device description framework (DDF) for the PassportForWork configuration service provider.
|
||||||
ms.date: 06/28/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -831,7 +831,7 @@ If you disable or do not configure this policy setting, the PIN recovery secret
|
|||||||
<MIME />
|
<MIME />
|
||||||
</DFType>
|
</DFType>
|
||||||
<MSFT:Applicability>
|
<MSFT:Applicability>
|
||||||
<MSFT:OsBuildVersion>99.9.99999</MSFT:OsBuildVersion>
|
<MSFT:OsBuildVersion>10.0.22621</MSFT:OsBuildVersion>
|
||||||
<MSFT:CspVersion>1.6</MSFT:CspVersion>
|
<MSFT:CspVersion>1.6</MSFT:CspVersion>
|
||||||
</MSFT:Applicability>
|
</MSFT:Applicability>
|
||||||
<MSFT:AllowedValues ValueType="ENUM">
|
<MSFT:AllowedValues ValueType="ENUM">
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Policies supported by Windows 10 Team
|
title: Policies supported by Windows 10 Team
|
||||||
description: Learn about the policies supported by Windows 10 Team.
|
description: Learn about the policies supported by Windows 10 Team.
|
||||||
ms.date: 08/06/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -417,6 +417,7 @@ This article lists the policies that are applicable for the Surface Hub operatin
|
|||||||
- [ExcludeJapaneseIMEExceptJIS0208andEUDC](policy-csp-textinput.md#excludejapaneseimeexceptjis0208andeudc)
|
- [ExcludeJapaneseIMEExceptJIS0208andEUDC](policy-csp-textinput.md#excludejapaneseimeexceptjis0208andeudc)
|
||||||
- [ExcludeJapaneseIMEExceptShiftJIS](policy-csp-textinput.md#excludejapaneseimeexceptshiftjis)
|
- [ExcludeJapaneseIMEExceptShiftJIS](policy-csp-textinput.md#excludejapaneseimeexceptshiftjis)
|
||||||
- [ForceTouchKeyboardDockedState](policy-csp-textinput.md#forcetouchkeyboarddockedstate)
|
- [ForceTouchKeyboardDockedState](policy-csp-textinput.md#forcetouchkeyboarddockedstate)
|
||||||
|
- [TouchKeyboardControllerModeAvailability](policy-csp-textinput.md#touchkeyboardcontrollermodeavailability)
|
||||||
- [TouchKeyboardDictationButtonAvailability](policy-csp-textinput.md#touchkeyboarddictationbuttonavailability)
|
- [TouchKeyboardDictationButtonAvailability](policy-csp-textinput.md#touchkeyboarddictationbuttonavailability)
|
||||||
- [TouchKeyboardEmojiButtonAvailability](policy-csp-textinput.md#touchkeyboardemojibuttonavailability)
|
- [TouchKeyboardEmojiButtonAvailability](policy-csp-textinput.md#touchkeyboardemojibuttonavailability)
|
||||||
- [TouchKeyboardFullModeAvailability](policy-csp-textinput.md#touchkeyboardfullmodeavailability)
|
- [TouchKeyboardFullModeAvailability](policy-csp-textinput.md#touchkeyboardfullmodeavailability)
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Configuration service provider preview policies
|
title: Configuration service provider preview policies
|
||||||
description: Learn more about configuration service provider (CSP) policies that are available for Windows Insider Preview.
|
description: Learn more about configuration service provider (CSP) policies that are available for Windows Insider Preview.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -29,10 +29,17 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
- [EnablePhysicalDeviceAccessOnErrorScreens](clouddesktop-csp.md#userenablephysicaldeviceaccessonerrorscreens)
|
- [EnablePhysicalDeviceAccessOnErrorScreens](clouddesktop-csp.md#userenablephysicaldeviceaccessonerrorscreens)
|
||||||
- [EnableBootToCloudSharedPCMode](clouddesktop-csp.md#deviceenableboottocloudsharedpcmode)
|
- [EnableBootToCloudSharedPCMode](clouddesktop-csp.md#deviceenableboottocloudsharedpcmode)
|
||||||
|
|
||||||
|
## Connectivity
|
||||||
|
|
||||||
|
- [UseCellularWhenWiFiPoor](policy-csp-connectivity.md#usecellularwhenwifipoor)
|
||||||
|
- [DisableCellularSettingsPage](policy-csp-connectivity.md#disablecellularsettingspage)
|
||||||
|
- [DisableCellularOperatorSettingsPage](policy-csp-connectivity.md#disablecellularoperatorsettingspage)
|
||||||
|
|
||||||
## DeclaredConfiguration CSP
|
## DeclaredConfiguration CSP
|
||||||
|
|
||||||
- [Document](declaredconfiguration-csp.md#hostcompletedocumentsdociddocument)
|
- [Document](declaredconfiguration-csp.md#hostcompletedocumentsdociddocument)
|
||||||
- [Abandoned](declaredconfiguration-csp.md#hostcompletedocumentsdocidpropertiesabandoned)
|
- [Abandoned](declaredconfiguration-csp.md#hostcompletedocumentsdocidpropertiesabandoned)
|
||||||
|
- [ConflictResolution](declaredconfiguration-csp.md#managementserviceconfigurationconflictresolution)
|
||||||
|
|
||||||
## DeliveryOptimization
|
## DeliveryOptimization
|
||||||
|
|
||||||
@ -52,6 +59,10 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
- [MdmAgentInstalled](devicepreparation-csp.md#mdmprovidermdmagentinstalled)
|
- [MdmAgentInstalled](devicepreparation-csp.md#mdmprovidermdmagentinstalled)
|
||||||
- [RebootRequired](devicepreparation-csp.md#mdmproviderrebootrequired)
|
- [RebootRequired](devicepreparation-csp.md#mdmproviderrebootrequired)
|
||||||
|
|
||||||
|
## Display
|
||||||
|
|
||||||
|
- [ConfigureMultipleDisplayMode](policy-csp-display.md#configuremultipledisplaymode)
|
||||||
|
|
||||||
## DMClient CSP
|
## DMClient CSP
|
||||||
|
|
||||||
- [DiscoveryEndpoint](dmclient-csp.md#deviceproviderprovideridlinkedenrollmentdiscoveryendpoint)
|
- [DiscoveryEndpoint](dmclient-csp.md#deviceproviderprovideridlinkedenrollmentdiscoveryendpoint)
|
||||||
@ -97,7 +108,6 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
|
|
||||||
## PassportForWork CSP
|
## PassportForWork CSP
|
||||||
|
|
||||||
- [EnableWindowsHelloProvisioningForSecurityKeys](passportforwork-csp.md#devicetenantidpoliciesenablewindowshelloprovisioningforsecuritykeys)
|
|
||||||
- [DisablePostLogonProvisioning](passportforwork-csp.md#devicetenantidpoliciesdisablepostlogonprovisioning)
|
- [DisablePostLogonProvisioning](passportforwork-csp.md#devicetenantidpoliciesdisablepostlogonprovisioning)
|
||||||
|
|
||||||
## Reboot CSP
|
## Reboot CSP
|
||||||
@ -112,6 +122,10 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
|
|
||||||
- [ExchangeModernAuthEnabled](surfacehub-csp.md#deviceaccountexchangemodernauthenabled)
|
- [ExchangeModernAuthEnabled](surfacehub-csp.md#deviceaccountexchangemodernauthenabled)
|
||||||
|
|
||||||
|
## TextInput
|
||||||
|
|
||||||
|
- [TouchKeyboardControllerModeAvailability](policy-csp-textinput.md#touchkeyboardcontrollermodeavailability)
|
||||||
|
|
||||||
## Update
|
## Update
|
||||||
|
|
||||||
- [AllowTemporaryEnterpriseFeatureControl](policy-csp-update.md#allowtemporaryenterprisefeaturecontrol)
|
- [AllowTemporaryEnterpriseFeatureControl](policy-csp-update.md#allowtemporaryenterprisefeaturecontrol)
|
||||||
@ -123,9 +137,14 @@ This article lists the policies that are applicable for Windows Insider Preview
|
|||||||
|
|
||||||
## WindowsAI
|
## WindowsAI
|
||||||
|
|
||||||
- [SetCopilotHardwareKey](policy-csp-windowsai.md#setcopilothardwarekey)
|
- [SetDenyAppListForRecall](policy-csp-windowsai.md#setdenyapplistforrecall)
|
||||||
|
- [SetDenyUriListForRecall](policy-csp-windowsai.md#setdenyurilistforrecall)
|
||||||
|
- [SetMaximumStorageSpaceForRecallSnapshots](policy-csp-windowsai.md#setmaximumstoragespaceforrecallsnapshots)
|
||||||
|
- [SetMaximumStorageDurationForRecallSnapshots](policy-csp-windowsai.md#setmaximumstoragedurationforrecallsnapshots)
|
||||||
|
- [AllowRecallExport](policy-csp-windowsai.md#allowrecallexport)
|
||||||
- [DisableImageCreator](policy-csp-windowsai.md#disableimagecreator)
|
- [DisableImageCreator](policy-csp-windowsai.md#disableimagecreator)
|
||||||
- [DisableCocreator](policy-csp-windowsai.md#disablecocreator)
|
- [DisableCocreator](policy-csp-windowsai.md#disablecocreator)
|
||||||
|
- [AllowRecallEnablement](policy-csp-windowsai.md#allowrecallenablement)
|
||||||
|
|
||||||
## WindowsLicensing CSP
|
## WindowsLicensing CSP
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Connectivity Policy CSP
|
title: Connectivity Policy CSP
|
||||||
description: Learn more about the Connectivity Area in Policy CSP.
|
description: Learn more about the Connectivity Area in Policy CSP.
|
||||||
ms.date: 04/10/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -11,6 +11,8 @@ ms.date: 04/10/2024
|
|||||||
|
|
||||||
[!INCLUDE [ADMX-backed CSP tip](includes/mdm-admx-csp-note.md)]
|
[!INCLUDE [ADMX-backed CSP tip](includes/mdm-admx-csp-note.md)]
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- Connectivity-Editable-Begin -->
|
<!-- Connectivity-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Connectivity-Editable-End -->
|
<!-- Connectivity-Editable-End -->
|
||||||
@ -584,6 +586,104 @@ Also, see the "Web-based printing" policy setting in Computer Configuration/Admi
|
|||||||
|
|
||||||
<!-- DiablePrintingOverHTTP-End -->
|
<!-- DiablePrintingOverHTTP-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Begin -->
|
||||||
|
## DisableCellularOperatorSettingsPage
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/DisableCellularOperatorSettingsPage
|
||||||
|
```
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy makes all configurable settings in the 'Cellular' > 'Mobile operator settings' page read-only.
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Description-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Editable-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Disabled. |
|
||||||
|
| 1 | Enabled. |
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-Examples-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularOperatorSettingsPage-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Begin -->
|
||||||
|
## DisableCellularSettingsPage
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- DisableCellularSettingsPage-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/DisableCellularSettingsPage
|
||||||
|
```
|
||||||
|
<!-- DisableCellularSettingsPage-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy makes all configurable settings in the 'Cellular' Settings page read-only.
|
||||||
|
<!-- DisableCellularSettingsPage-Description-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularSettingsPage-Editable-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- DisableCellularSettingsPage-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Disabled. |
|
||||||
|
| 1 | Enabled. |
|
||||||
|
<!-- DisableCellularSettingsPage-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- DisableCellularSettingsPage-Examples-End -->
|
||||||
|
|
||||||
|
<!-- DisableCellularSettingsPage-End -->
|
||||||
|
|
||||||
<!-- DisableDownloadingOfPrintDriversOverHTTP-Begin -->
|
<!-- DisableDownloadingOfPrintDriversOverHTTP-Begin -->
|
||||||
## DisableDownloadingOfPrintDriversOverHTTP
|
## DisableDownloadingOfPrintDriversOverHTTP
|
||||||
|
|
||||||
@ -899,6 +999,55 @@ If you disable this setting or don't configure it, the user will be able to crea
|
|||||||
|
|
||||||
<!-- ProhibitInstallationAndConfigurationOfNetworkBridge-End -->
|
<!-- ProhibitInstallationAndConfigurationOfNetworkBridge-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Begin -->
|
||||||
|
## UseCellularWhenWiFiPoor
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Connectivity/UseCellularWhenWiFiPoor
|
||||||
|
```
|
||||||
|
<!-- UseCellularWhenWiFiPoor-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows the use of a cellular connection when Wi-Fi connectivity is limited.
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Description-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Editable-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 1 |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | Disabled. |
|
||||||
|
| 1 (Default) | Enabled. |
|
||||||
|
<!-- UseCellularWhenWiFiPoor-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- UseCellularWhenWiFiPoor-Examples-End -->
|
||||||
|
|
||||||
|
<!-- UseCellularWhenWiFiPoor-End -->
|
||||||
|
|
||||||
<!-- Connectivity-CspMoreInfo-Begin -->
|
<!-- Connectivity-CspMoreInfo-Begin -->
|
||||||
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Connectivity-CspMoreInfo-End -->
|
<!-- Connectivity-CspMoreInfo-End -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Display Policy CSP
|
title: Display Policy CSP
|
||||||
description: Learn more about the Display Area in Policy CSP.
|
description: Learn more about the Display Area in Policy CSP.
|
||||||
ms.date: 01/18/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -9,10 +9,72 @@ ms.date: 01/18/2024
|
|||||||
<!-- Display-Begin -->
|
<!-- Display-Begin -->
|
||||||
# Policy CSP - Display
|
# Policy CSP - Display
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- Display-Editable-Begin -->
|
<!-- Display-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- Display-Editable-End -->
|
<!-- Display-Editable-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Begin -->
|
||||||
|
## ConfigureMultipleDisplayMode
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/Display/ConfigureMultipleDisplayMode
|
||||||
|
```
|
||||||
|
<!-- ConfigureMultipleDisplayMode-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy set the default display to set the arrangement between cloning or extending.
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Description-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Editable-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 1 |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | Default. |
|
||||||
|
| 1 (Default) | Clone. |
|
||||||
|
| 2 | Extend. |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | ConfigureMultipleDisplayMode |
|
||||||
|
| Path | Display > AT > System > DisplayCat |
|
||||||
|
| Element Name | ConfigureMultipleDisplayModePrompt |
|
||||||
|
<!-- ConfigureMultipleDisplayMode-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- ConfigureMultipleDisplayMode-Examples-End -->
|
||||||
|
|
||||||
|
<!-- ConfigureMultipleDisplayMode-End -->
|
||||||
|
|
||||||
<!-- DisablePerProcessDpiForApps-Begin -->
|
<!-- DisablePerProcessDpiForApps-Begin -->
|
||||||
## DisablePerProcessDpiForApps
|
## DisablePerProcessDpiForApps
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: LocalPoliciesSecurityOptions Policy CSP
|
title: LocalPoliciesSecurityOptions Policy CSP
|
||||||
description: Learn more about the LocalPoliciesSecurityOptions Area in Policy CSP.
|
description: Learn more about the LocalPoliciesSecurityOptions Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -388,10 +388,27 @@ Audit: Audit the use of Backup and Restore privilege This security setting deter
|
|||||||
|:--|:--|
|
|:--|:--|
|
||||||
| Format | `b64` |
|
| Format | `b64` |
|
||||||
| Access Type | Add, Delete, Get, Replace |
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
| Allowed Values | List (Delimiter: ``) |
|
| Default Value | AA== |
|
||||||
| Default Value | 00 |
|
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-DFProperties-End -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| AQ== | Enable. |
|
||||||
|
| AA== (Default) | Disable. |
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | Audit: Audit the use of Backup and Restore privilege |
|
||||||
|
| Path | Windows Settings > Security Settings > Local Policies > Security Options |
|
||||||
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-GpMapping-End -->
|
||||||
|
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-Begin -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-Begin -->
|
||||||
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-End -->
|
<!-- Audit_AuditTheUseOfBackupAndRestoreprivilege-Examples-End -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: RemoteDesktopServices Policy CSP
|
title: RemoteDesktopServices Policy CSP
|
||||||
description: Learn more about the RemoteDesktopServices Area in Policy CSP.
|
description: Learn more about the RemoteDesktopServices Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -156,7 +156,7 @@ FIPS compliance can be configured through the System cryptography. Use FIPS comp
|
|||||||
<!-- DisconnectOnLockLegacyAuthn-Applicability-Begin -->
|
<!-- DisconnectOnLockLegacyAuthn-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ [10.0.20348.2461] and later <br> ✅ [10.0.25398.887] and later <br> ✅ Windows 10, version 2004 [10.0.19041.4474] and later <br> ✅ Windows 11, version 21H2 with [KB5037770](https://support.microsoft.com/help/5037770) [10.0.22000.2960] and later <br> ✅ Windows 11, version 22H2 with [KB5037771](https://support.microsoft.com/help/5037771) [10.0.22621.3593] and later <br> ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
||||||
<!-- DisconnectOnLockLegacyAuthn-Applicability-End -->
|
<!-- DisconnectOnLockLegacyAuthn-Applicability-End -->
|
||||||
|
|
||||||
<!-- DisconnectOnLockLegacyAuthn-OmaUri-Begin -->
|
<!-- DisconnectOnLockLegacyAuthn-OmaUri-Begin -->
|
||||||
@ -217,7 +217,7 @@ This policy applies only when using legacy authentication to authenticate to the
|
|||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-Begin -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ [10.0.20348.2461] and later <br> ✅ [10.0.25398.887] and later <br> ✅ Windows 10, version 2004 [10.0.19041.4474] and later <br> ✅ Windows 11, version 21H2 with [KB5037770](https://support.microsoft.com/help/5037770) [10.0.22000.2960] and later <br> ✅ Windows 11, version 22H2 with [KB5037771](https://support.microsoft.com/help/5037771) [10.0.22621.3593] and later <br> ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-End -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-Applicability-End -->
|
||||||
|
|
||||||
<!-- DisconnectOnLockMicrosoftIdentityAuthn-OmaUri-Begin -->
|
<!-- DisconnectOnLockMicrosoftIdentityAuthn-OmaUri-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: TextInput Policy CSP
|
title: TextInput Policy CSP
|
||||||
description: Learn more about the TextInput Area in Policy CSP.
|
description: Learn more about the TextInput Area in Policy CSP.
|
||||||
ms.date: 01/18/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -9,6 +9,8 @@ ms.date: 01/18/2024
|
|||||||
<!-- TextInput-Begin -->
|
<!-- TextInput-Begin -->
|
||||||
# Policy CSP - TextInput
|
# Policy CSP - TextInput
|
||||||
|
|
||||||
|
[!INCLUDE [Windows Insider tip](includes/mdm-insider-csp-note.md)]
|
||||||
|
|
||||||
<!-- TextInput-Editable-Begin -->
|
<!-- TextInput-Editable-Begin -->
|
||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- TextInput-Editable-End -->
|
<!-- TextInput-Editable-End -->
|
||||||
@ -1172,6 +1174,56 @@ Specifies the touch keyboard is always docked. When this policy is set to enable
|
|||||||
|
|
||||||
<!-- ForceTouchKeyboardDockedState-End -->
|
<!-- ForceTouchKeyboardDockedState-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Begin -->
|
||||||
|
## TouchKeyboardControllerModeAvailability
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/TextInput/TouchKeyboardControllerModeAvailability
|
||||||
|
```
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
Specifies whether the controller keyboard mode is enabled or disabled for the touch keyboard. When this policy is set to disabled, the controller keyboard mode for touch keyboard is disabled.
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Description-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Editable-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | The OS determines when it's most appropriate to be available. |
|
||||||
|
| 1 | Controller keyboard is always available. |
|
||||||
|
| 2 | Controller keyboard is always disabled. |
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-Examples-End -->
|
||||||
|
|
||||||
|
<!-- TouchKeyboardControllerModeAvailability-End -->
|
||||||
|
|
||||||
<!-- TouchKeyboardDictationButtonAvailability-Begin -->
|
<!-- TouchKeyboardDictationButtonAvailability-Begin -->
|
||||||
## TouchKeyboardDictationButtonAvailability
|
## TouchKeyboardDictationButtonAvailability
|
||||||
|
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Wifi Policy CSP
|
title: Wifi Policy CSP
|
||||||
description: Learn more about the Wifi Area in Policy CSP.
|
description: Learn more about the Wifi Area in Policy CSP.
|
||||||
ms.date: 01/31/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -188,10 +188,7 @@ By default, ICS is disabled when you create a remote access connection, but admi
|
|||||||
|
|
||||||
<!-- AllowManualWiFiConfiguration-Description-Begin -->
|
<!-- AllowManualWiFiConfiguration-Description-Begin -->
|
||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Allow or disallow connecting to Wi-Fi outside of MDM server-installed networks. Most restricted value is 0.
|
Allow or block connections to Wi-Fi outside of MDM server-installed networks. If you change this setting to Block, you must deploy enterprise Wi-Fi profiles to the device using the Wi-Fi CSP before you apply this setting. Otherwise, the device will go offline since it won't be able to connect to Wi-Fi. Note that choosing to block Wi-Fi connections will delete any previously installed user-configured Wi-Fi profiles from the device, though not all non-MDM profiles will be deleted.
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> Setting this policy deletes any previously installed user-configured and Wi-Fi sense Wi-Fi profiles from the device. Certain Wi-Fi profiles that aren't user configured nor Wi-Fi sense might not be deleted. In addition, not all non-MDM profiles are completely deleted.
|
|
||||||
<!-- AllowManualWiFiConfiguration-Description-End -->
|
<!-- AllowManualWiFiConfiguration-Description-End -->
|
||||||
|
|
||||||
<!-- AllowManualWiFiConfiguration-Editable-Begin -->
|
<!-- AllowManualWiFiConfiguration-Editable-Begin -->
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: WindowsAI Policy CSP
|
title: WindowsAI Policy CSP
|
||||||
description: Learn more about the WindowsAI Area in Policy CSP.
|
description: Learn more about the WindowsAI Area in Policy CSP.
|
||||||
ms.date: 09/27/2024
|
ms.date: 11/05/2024
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- Auto-Generated CSP Document -->
|
<!-- Auto-Generated CSP Document -->
|
||||||
@ -15,19 +15,143 @@ ms.date: 09/27/2024
|
|||||||
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
<!-- WindowsAI-Editable-End -->
|
<!-- WindowsAI-Editable-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-Begin -->
|
||||||
|
## AllowRecallEnablement
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ❌ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- AllowRecallEnablement-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-OmaUri-Begin -->
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/AllowRecallEnablement
|
||||||
|
```
|
||||||
|
<!-- AllowRecallEnablement-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows you to determine whether Recall optional component allowed on a device. When this policy enabled, Recall bits are allowed on a device. If the police set to disabled or not configured, it's a signal to disable Recall and remove Recall component bits from device (all users snapshot data will be deleted).
|
||||||
|
<!-- AllowRecallEnablement-Description-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- AllowRecallEnablement-Editable-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 1 |
|
||||||
|
<!-- AllowRecallEnablement-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 | Recall isn't available. |
|
||||||
|
| 1 (Default) | Recall is available. |
|
||||||
|
<!-- AllowRecallEnablement-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | AllowRecallEnablement |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- AllowRecallEnablement-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- AllowRecallEnablement-Examples-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallEnablement-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-Begin -->
|
||||||
|
## AllowRecallExport
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- AllowRecallExport-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-OmaUri-Begin -->
|
||||||
|
```User
|
||||||
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/AllowRecallExport
|
||||||
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/AllowRecallExport
|
||||||
|
```
|
||||||
|
<!-- AllowRecallExport-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows you to determine whether Recall and snapshot information can be exported. Recall and snapshot information may be sensitive, and the files that are exported are unencrypted. Users can export from Settings > Privacy & Security > Recall & Snapshots > Advanced Settings > Export your Recall and snapshot info. Users are warned that the files are unencrypted before exporting. When you set this policy to enabled, users will be able to export Recall and snapshot information. If the policy is set to disabled or not configured, users won't be able to export their Recall and snapshot information.
|
||||||
|
<!-- AllowRecallExport-Description-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- AllowRecallExport-Editable-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- AllowRecallExport-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Deny export of Recall and snapshots information. |
|
||||||
|
| 1 | Allow export of Recall and snapshot information. |
|
||||||
|
<!-- AllowRecallExport-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | AllowRecallExport |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- AllowRecallExport-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- AllowRecallExport-Examples-End -->
|
||||||
|
|
||||||
|
<!-- AllowRecallExport-End -->
|
||||||
|
|
||||||
<!-- DisableAIDataAnalysis-Begin -->
|
<!-- DisableAIDataAnalysis-Begin -->
|
||||||
## DisableAIDataAnalysis
|
## DisableAIDataAnalysis
|
||||||
|
|
||||||
<!-- DisableAIDataAnalysis-Applicability-Begin -->
|
<!-- DisableAIDataAnalysis-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ❌ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 24H2 [10.0.26100] and later |
|
||||||
<!-- DisableAIDataAnalysis-Applicability-End -->
|
<!-- DisableAIDataAnalysis-Applicability-End -->
|
||||||
|
|
||||||
<!-- DisableAIDataAnalysis-OmaUri-Begin -->
|
<!-- DisableAIDataAnalysis-OmaUri-Begin -->
|
||||||
```User
|
```User
|
||||||
./User/Vendor/MSFT/Policy/Config/WindowsAI/DisableAIDataAnalysis
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/DisableAIDataAnalysis
|
||||||
```
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/DisableAIDataAnalysis
|
||||||
|
```
|
||||||
<!-- DisableAIDataAnalysis-OmaUri-End -->
|
<!-- DisableAIDataAnalysis-OmaUri-End -->
|
||||||
|
|
||||||
<!-- DisableAIDataAnalysis-Description-Begin -->
|
<!-- DisableAIDataAnalysis-Description-Begin -->
|
||||||
@ -212,7 +336,7 @@ This policy setting allows you to control whether Image Creator functionality is
|
|||||||
<!-- SetCopilotHardwareKey-Applicability-Begin -->
|
<!-- SetCopilotHardwareKey-Applicability-Begin -->
|
||||||
| Scope | Editions | Applicable OS |
|
| Scope | Editions | Applicable OS |
|
||||||
|:--|:--|:--|
|
|:--|:--|:--|
|
||||||
| ❌ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
| ❌ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows 11, version 22H2 with [KB5044380](https://support.microsoft.com/help/5044380) [10.0.22621.4391] and later |
|
||||||
<!-- SetCopilotHardwareKey-Applicability-End -->
|
<!-- SetCopilotHardwareKey-Applicability-End -->
|
||||||
|
|
||||||
<!-- SetCopilotHardwareKey-OmaUri-Begin -->
|
<!-- SetCopilotHardwareKey-OmaUri-Begin -->
|
||||||
@ -258,6 +382,244 @@ This policy setting determines which app opens when the user presses the Copilot
|
|||||||
|
|
||||||
<!-- SetCopilotHardwareKey-End -->
|
<!-- SetCopilotHardwareKey-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-Begin -->
|
||||||
|
## SetDenyAppListForRecall
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- SetDenyAppListForRecall-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-OmaUri-Begin -->
|
||||||
|
```User
|
||||||
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/SetDenyAppListForRecall
|
||||||
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/SetDenyAppListForRecall
|
||||||
|
```
|
||||||
|
<!-- SetDenyAppListForRecall-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows you to define a list of apps that Windows won't include in snapshots for Recall. Users will be able to add additional applications to exclude from snapshots using Recall settings. The list can include Application User Model IDs (AUMID) or the name of the executable file. Use a semicolon-separated list of apps to define the deny app list for Recall. For example: code.exe;Microsoft. WindowsNotepad_8wekyb3d8bbwe!App;ms-teams.exe.
|
||||||
|
<!-- SetDenyAppListForRecall-Description-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- SetDenyAppListForRecall-Editable-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `chr` (string) |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Allowed Values | List (Delimiter: `;`) |
|
||||||
|
<!-- SetDenyAppListForRecall-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | DenyAppListForRecall |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- SetDenyAppListForRecall-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- SetDenyAppListForRecall-Examples-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyAppListForRecall-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-Begin -->
|
||||||
|
## SetDenyUriListForRecall
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- SetDenyUriListForRecall-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-OmaUri-Begin -->
|
||||||
|
```User
|
||||||
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/SetDenyUriListForRecall
|
||||||
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/SetDenyUriListForRecall
|
||||||
|
```
|
||||||
|
<!-- SetDenyUriListForRecall-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy allows you to define a list of URIs that Windows won't include in snapshots for Recall when a supported browser is used. Users will be able to add additional websites to exclude from snapshots using Recall settings. Adding WoodgroveBank.com to the list would also filter Account. WoodgroveBank.com and WoodgroveBank.com/Account. Use a semicolon-separated list of URIs to define the deny URI list for Recall. For example: Contoso.com;WoodgroveBank.com;Adatum.com.
|
||||||
|
<!-- SetDenyUriListForRecall-Description-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- SetDenyUriListForRecall-Editable-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `chr` (string) |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Allowed Values | List (Delimiter: `;`) |
|
||||||
|
<!-- SetDenyUriListForRecall-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | DenyUriListForRecall |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- SetDenyUriListForRecall-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- SetDenyUriListForRecall-Examples-End -->
|
||||||
|
|
||||||
|
<!-- SetDenyUriListForRecall-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Begin -->
|
||||||
|
## SetMaximumStorageDurationForRecallSnapshots
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-OmaUri-Begin -->
|
||||||
|
```User
|
||||||
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/SetMaximumStorageDurationForRecallSnapshots
|
||||||
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/SetMaximumStorageDurationForRecallSnapshots
|
||||||
|
```
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. When the policy is enabled, you can configure the maximum storage duration to be 30, 60, 90, or 180 days. When this policy isn't configured, a time frame isn't set for deleting snapshots. Snapshots aren't deleted until the maximum storage allocation for Recall is reached, and then the oldest snapshots are deleted first.
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Description-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Editable-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Let the OS define the maximum amount of time the snapshots will be saved. |
|
||||||
|
| 30 | 30 days. |
|
||||||
|
| 60 | 60 days. |
|
||||||
|
| 90 | 90 days. |
|
||||||
|
| 180 | 180 days. |
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | SetMaximumStorageDurationForRecallSnapshots |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-Examples-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageDurationForRecallSnapshots-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Begin -->
|
||||||
|
## SetMaximumStorageSpaceForRecallSnapshots
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Applicability-Begin -->
|
||||||
|
| Scope | Editions | Applicable OS |
|
||||||
|
|:--|:--|:--|
|
||||||
|
| ✅ Device <br> ✅ User | ✅ Pro <br> ✅ Enterprise <br> ✅ Education <br> ✅ Windows SE <br> ✅ IoT Enterprise / IoT Enterprise LTSC | ✅ Windows Insider Preview |
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Applicability-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-OmaUri-Begin -->
|
||||||
|
```User
|
||||||
|
./User/Vendor/MSFT/Policy/Config/WindowsAI/SetMaximumStorageSpaceForRecallSnapshots
|
||||||
|
```
|
||||||
|
|
||||||
|
```Device
|
||||||
|
./Device/Vendor/MSFT/Policy/Config/WindowsAI/SetMaximumStorageSpaceForRecallSnapshots
|
||||||
|
```
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-OmaUri-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Description-Begin -->
|
||||||
|
<!-- Description-Source-DDF -->
|
||||||
|
This policy setting allows you to control the maximum amount of disk space that can be used by Windows to save snapshots for Recall. You can set the maximum amount of disk space for snapshots to be 10, 25, 50, 75, 100, or 150 GB. When this setting isn't configured, the OS configures the storage allocation for snapshots based on the device storage capacity. 25 GB is allocated when the device storage capacity is 256 GB. 75 GB is allocated when the device storage capacity is 512 GB. 150 GB is allocated when the device storage capacity is 1 TB or higher.
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Description-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Editable-Begin -->
|
||||||
|
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Editable-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-DFProperties-Begin -->
|
||||||
|
**Description framework properties**:
|
||||||
|
|
||||||
|
| Property name | Property value |
|
||||||
|
|:--|:--|
|
||||||
|
| Format | `int` |
|
||||||
|
| Access Type | Add, Delete, Get, Replace |
|
||||||
|
| Default Value | 0 |
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-DFProperties-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-AllowedValues-Begin -->
|
||||||
|
**Allowed values**:
|
||||||
|
|
||||||
|
| Value | Description |
|
||||||
|
|:--|:--|
|
||||||
|
| 0 (Default) | Let the OS define the maximum storage amount based on hard drive storage size. |
|
||||||
|
| 10000 | 10GB. |
|
||||||
|
| 25000 | 25GB. |
|
||||||
|
| 50000 | 50GB. |
|
||||||
|
| 75000 | 75GB. |
|
||||||
|
| 100000 | 100GB. |
|
||||||
|
| 150000 | 150GB. |
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-AllowedValues-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-GpMapping-Begin -->
|
||||||
|
**Group policy mapping**:
|
||||||
|
|
||||||
|
| Name | Value |
|
||||||
|
|:--|:--|
|
||||||
|
| Name | SetMaximumStorageSpaceForRecallSnapshots |
|
||||||
|
| Path | WindowsAI > AT > WindowsComponents > WindowsAI |
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-GpMapping-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Examples-Begin -->
|
||||||
|
<!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-Examples-End -->
|
||||||
|
|
||||||
|
<!-- SetMaximumStorageSpaceForRecallSnapshots-End -->
|
||||||
|
|
||||||
<!-- TurnOffWindowsCopilot-Begin -->
|
<!-- TurnOffWindowsCopilot-Begin -->
|
||||||
## TurnOffWindowsCopilot
|
## TurnOffWindowsCopilot
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user