mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 10:53:43 +00:00
Merge branch 'master' of https://cpubwin.visualstudio.com/_git/it-client into vsts15845892
This commit is contained in:
@ -2,9 +2,10 @@
|
||||
## [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md)
|
||||
## [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md)
|
||||
## [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md)
|
||||
## [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)
|
||||
## [Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)
|
||||
## [Windows 10 diagnostic data for the Full diagnostic data level](windows-diagnostic-data-1703.md)
|
||||
## [Windows 10, version 1709 enhanced telemetry events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)
|
||||
## [Windows 10, version 1709 diagnostic data for the Full telemetry level](windows-diagnostic-data.md)
|
||||
## [Windows 10, version 1703 diagnostic data for the Full telemetry level](windows-diagnostic-data-1703.md)
|
||||
## [Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](gdpr-win10-whitepaper.md)
|
||||
## [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md)
|
||||
## [Manage Windows 10 connection endpoints](manage-windows-endpoints-version-1709.md)
|
||||
|
@ -1,5 +1,5 @@
|
||||
---
|
||||
description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level.
|
||||
description: Learn more about the Windows diagnostic data that is gathered at the basic level.
|
||||
title: Windows 10, version 1709 basic diagnostic events and fields (Windows 10)
|
||||
keywords: privacy, diagnostic data
|
||||
ms.prod: w10
|
||||
@ -9,7 +9,7 @@ ms.pagetype: security
|
||||
localizationpriority: high
|
||||
author: eross-msft
|
||||
ms.author: lizross
|
||||
ms.date: 10/26/2017
|
||||
ms.date: 02/12/2018
|
||||
---
|
||||
|
||||
|
||||
@ -101,7 +101,7 @@ The following fields are available:
|
||||
- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server.
|
||||
- **seqNum** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server.
|
||||
- **iKey** Represents an ID for applications or other logical groupings of events.
|
||||
- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency.
|
||||
- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experiences and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency.
|
||||
- **os** Represents the operating system name.
|
||||
- **osVer** Represents the OS version, and its format is OS dependent.
|
||||
- **appId** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application.
|
||||
@ -255,7 +255,7 @@ The following fields are available:
|
||||
|
||||
### Microsoft.Windows.Appraiser.General.RunContext
|
||||
|
||||
"This event indicates what should be expected in the data payload. "
|
||||
This event indicates what should be expected in the data payload.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
@ -1604,6 +1604,39 @@ The following fields are available:
|
||||
- **SocketCount** Number of physical CPU sockets of the machine.
|
||||
|
||||
|
||||
### Census.Security
|
||||
|
||||
This event provides information on about security settings used to help keep Windows up-to-date and secure.
|
||||
|
||||
- **AvailableSecurityProperties** Enumerates and reports state on the relevant security properties for Device Guard.
|
||||
- **CGRunning** Is Credential Guard running?
|
||||
- **DGState** A summary of the Device Guard state.
|
||||
- **HVCIRunning** Is HVCI running?
|
||||
- **IsSawGuest** Describes whether the device is running as a Secure Admin Workstation Guest.
|
||||
- **IsSawHost** Describes whether the device is running as a Secure Admin Workstation Host.
|
||||
- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security.
|
||||
- **SecureBootCapable** Is this device capable of running Secure Boot?
|
||||
- **VBSState** Is virtualization-based security enabled, disabled, or running?
|
||||
|
||||
|
||||
### Census.Speech
|
||||
|
||||
This event is used to gather basic speech settings on the device.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked.
|
||||
- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities.
|
||||
- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user.
|
||||
- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices.
|
||||
- **KWSEnabled** "Cortana setting that represents if a user has enabled the ""Hey Cortana"" keyword spotter (KWS)."
|
||||
- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities.
|
||||
- **RemotelyManaged** Indicates if the device is being controlled by a remote admininistrator (MDM or Group Policy) in the context of speech functionalities.
|
||||
- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice.
|
||||
- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device.
|
||||
|
||||
|
||||
|
||||
### Census.Storage
|
||||
|
||||
This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date.
|
||||
@ -1614,34 +1647,6 @@ The following fields are available:
|
||||
- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any).
|
||||
- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB.
|
||||
|
||||
|
||||
### Census.VM
|
||||
|
||||
This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within.
|
||||
- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor.
|
||||
- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present.
|
||||
- **isVDI** Is the device using Virtual Desktop Infrastructure?
|
||||
- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#HASH#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#HASH#1 Hypervisors.
|
||||
- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware.
|
||||
- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware.
|
||||
|
||||
|
||||
### Census.Xbox
|
||||
|
||||
This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console.
|
||||
- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console.
|
||||
- **XboxLiveDeviceId** Retrieves the unique device id of the console.
|
||||
- **XboxLiveSandboxId** Retrieves the developer sandbox id if the device is internal to MS.
|
||||
|
||||
|
||||
### Census.Userdefault
|
||||
|
||||
This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date.
|
||||
@ -1664,6 +1669,25 @@ The following fields are available:
|
||||
- **KeyboardInputLanguages** The Keyboard input languages installed on the device.
|
||||
- **SpeechInputLanguages** The Speech Input languages installed on the device.
|
||||
|
||||
### Census.VM
|
||||
|
||||
This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within.
|
||||
- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor.
|
||||
- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present.
|
||||
- **isVDI** Is the device using Virtual Desktop Infrastructure?
|
||||
- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#HASH#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#HASH#1 Hypervisors.
|
||||
- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware.
|
||||
- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
### Census.WU
|
||||
|
||||
@ -1695,34 +1719,18 @@ The following fields are available:
|
||||
- **WUPauseState** Retrieves WU setting to determine if updates are paused
|
||||
- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default).
|
||||
|
||||
### Census.Xbox
|
||||
|
||||
### Census.Speech
|
||||
|
||||
This event is used to gather basic speech settings on the device.
|
||||
This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked.
|
||||
- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities.
|
||||
- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user.
|
||||
- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices.
|
||||
- **KWSEnabled** "Cortana setting that represents if a user has enabled the ""Hey Cortana"" keyword spotter (KWS)."
|
||||
- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities.
|
||||
- **RemotelyManaged** Indicates if the device is being controlled by a remote admininistrator (MDM or Group Policy) in the context of speech functionalities.
|
||||
- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice.
|
||||
- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device.
|
||||
- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console.
|
||||
- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console.
|
||||
- **XboxLiveDeviceId** Retrieves the unique device id of the console.
|
||||
- **XboxLiveSandboxId** Retrieves the developer sandbox id if the device is internal to MS.
|
||||
|
||||
### Census.Security
|
||||
|
||||
This event provides information on about security settings used to help keep Windows up-to-date and secure.
|
||||
|
||||
- **AvailableSecurityProperties** Enumerates and reports state on the relevant security properties for Device Guard.
|
||||
- **CGRunning** Is Credential Guard running?
|
||||
- **DGState** A summary of the Device Guard state.
|
||||
- **HVCIRunning** Is HVCI running?
|
||||
- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security.
|
||||
- **SecureBootCapable** Is this device capable of running Secure Boot?
|
||||
- **VBSState** Is virtualization-based security enabled, disabled, or running?
|
||||
|
||||
|
||||
## Diagnostic data events
|
||||
@ -1812,7 +1820,7 @@ The following fields are available:
|
||||
- **LastEventSizeOffender** The name of the last event that exceeded the maximum event size.
|
||||
- **LastInvalidHttpCode** The last invalid HTTP code received from Vortex.
|
||||
- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe.
|
||||
- **MaxInUseScenarioCounter** The soft maximum number of scenarios loaded by the Connected User Experience and Telemetry component.
|
||||
- **MaxInUseScenarioCounter** The soft maximum number of scenarios loaded by the Connected User Experiences and Telemetry component.
|
||||
- **PreviousHeartBeatTime** The time of last heartbeat event. This allows chaining of events.
|
||||
- **SettingsHttpAttempts** The number of attempts to contact the OneSettings service.
|
||||
- **SettingsHttpFailures** The number of failures from contacting the OneSettings service.
|
||||
@ -1990,8 +1998,9 @@ The following fields are available:
|
||||
|
||||
This event provides data on the installed Office Add-ins.
|
||||
|
||||
- **AddInCLSID** The CLSID key office the Office addin.
|
||||
- **AddInId** The ID of the Office addin.
|
||||
- **AddInCLSID** The CLSID key office for the Office addin.
|
||||
- **AddInId** The identifier of the Office addin.
|
||||
- **AddinType** The type of the Office addin.
|
||||
- **BinFileTimestamp** The timestamp of the Office addin.
|
||||
- **BinFileVersion** The version of the Office addin.
|
||||
- **Description** The description of the Office addin.
|
||||
@ -2004,8 +2013,58 @@ This event provides data on the installed Office Add-ins.
|
||||
- **OfficeArchitecture** The architecture of the addin.
|
||||
- **OfficeVersion** The Office version for this addin.
|
||||
- **OutlookCrashingAddin** A boolean value that indicates if crashes have been found for this addin.
|
||||
- **ProductCompany** The name of the company associated with the Office addin.
|
||||
- **ProductName** The product name associated with the Office addin.
|
||||
- **ProductVersion** The version associated with the Office addin.
|
||||
- **ProgramId** The unique program identifier of the Office addin.
|
||||
- **Provider** The provider name for this addin.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove
|
||||
|
||||
This event indicates that the particular data object represented by the objectInstanceId is no longer present.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd
|
||||
|
||||
This event provides insight data on the installed Office products.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **OfficeApplication** The name of the Office application.
|
||||
- **OfficeArchitecture** The bitness of the Office application.
|
||||
- **OfficeVersion** The version of the Office application.
|
||||
- **Value** The insights collected about this entity.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove
|
||||
|
||||
This event indicates that the particular data object represented by the objectInstanceId is no longer present.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync
|
||||
|
||||
This diagnostic event indicates that a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd
|
||||
|
||||
This event describes various Office settings.
|
||||
|
||||
The following fields are available:
|
||||
|
||||
- **BrowserFlags** Browser flags for Office-related products.
|
||||
- **ExchangeProviderFlags** Provider policies for Office Exchange.
|
||||
- **SharedComputerLicensing** Office shared computer licensing policies.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync
|
||||
|
||||
Diagnostic event to indicate a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd
|
||||
|
||||
@ -2036,6 +2095,18 @@ The following fields are available:
|
||||
- **Validation_x64** Count of files that require additional manual validation for 64-bit issues
|
||||
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove
|
||||
|
||||
This event indicates that the particular data object represented by the objectInstanceId is no longer present.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove
|
||||
|
||||
This event indicates that the particular data object represented by the objectInstanceId is no longer present.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync
|
||||
|
||||
This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent
|
||||
@ -2412,6 +2483,66 @@ This event indicates that a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd
|
||||
|
||||
This event provides data on the installed Office identifiers.
|
||||
|
||||
- **OAudienceData** The Office Audience descriptor.
|
||||
- **OAudienceId** The Office Audience ID.
|
||||
- **OMID** The Office machine ID.
|
||||
- **OPlatform** The Office architecture.
|
||||
- **OVersion** The Office version
|
||||
- **OTenantId** The Office 365 Tenant GUID.
|
||||
- **OWowMID** The Office machine ID.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync
|
||||
|
||||
This event indicates that a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd
|
||||
|
||||
This event provides data on the installed Office-related Internet Explorer features.
|
||||
|
||||
- **OIeFeatureAddon** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeMachineLockdown** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeMimeHandling** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeMimeSniffing** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeNoAxInstall** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeNoDownload** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeObjectCaching** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIePasswordDisable** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeSafeBind** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeSecurityBand** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeUncSaveCheck** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeValidateUrl** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeWebOcPopup** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeWinRestrict** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
- **OIeZoneElevate** For more information, see the Office-related [Internet Feature Control Keys](https://msdn.microsoft.com/en-us/library/ee330720.aspx).
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync
|
||||
|
||||
This event indicates that a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd
|
||||
|
||||
This event describes the Office products that are installed.
|
||||
|
||||
- **OC2rApps** The Office Click-to-Run apps.
|
||||
- **OC2rSkus** The Office Click-to-Run products.
|
||||
- **OMsiApps** The Office MSI apps.
|
||||
- **OProductCodes** The Office MSI product code.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync
|
||||
|
||||
This event indicates that a new sync is being generated for this object type.
|
||||
|
||||
There are no fields in this event.
|
||||
|
||||
### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync
|
||||
|
||||
This event indicates that a new sync is being generated for this object type.
|
||||
|
@ -8,13 +8,21 @@ ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: high
|
||||
author: jdeckerms
|
||||
ms.date: 01/31/2018
|
||||
ms.date: 02/12/2018
|
||||
---
|
||||
|
||||
# Change history for Configure Windows 10
|
||||
|
||||
This topic lists new and updated topics in the [Configure Windows 10](index.md) documentation for Windows 10 and Windows 10 Mobile.
|
||||
|
||||
## February 2018
|
||||
|
||||
New or changed topic | Description
|
||||
--- | ---
|
||||
[Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md) | Added events and fields that were added in the February update.
|
||||
[Create a Windows 10 kiosk that runs multiple apps](lock-down-windows-10-to-specific-apps.md) | Added steps for configuring a kiosk in Microsoft Intune.
|
||||
[Customize Windows 10 Start and taskbar with mobile device management (MDM)](customize-windows-10-start-screens-by-using-mobile-device-management.md) | Updated the instructions for applying a customized Start layout using Microsoft Intune.
|
||||
|
||||
## January 2018
|
||||
|
||||
New or changed topic | Description
|
||||
|
@ -43,7 +43,7 @@ The following example shows how apps will be pinned: Windows default apps to the
|
||||
3. Apply the layout modification XML file to devices using [Group Policy](customize-windows-10-start-screens-by-using-group-policy.md) or a [provisioning package created in Windows Imaging and Configuration Designer (Windows ICD)](customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md).
|
||||
|
||||
>[!IMPORTANT]
|
||||
>If you use a provisioning package to configure the taskbar, your configuration will be reapplied each time the explorer.exe process restarts. If your configuration pins an app and the user then unpins that app, the user's change will be overwritten the next time the configuration is applied. To apply a taskbar configuration that allows users to make changes that will persist, apply your configuration by using Group Policy.
|
||||
>If you use a provisioning package or import-startlayout to configure the taskbar, your configuration will be reapplied each time the explorer.exe process restarts. If your configuration pins an app and the user then unpins that app, the user's change will be overwritten the next time the configuration is applied. To apply a taskbar configuration that allows users to make changes that will persist, apply your configuration by using Group Policy.
|
||||
>
|
||||
>If you use Group Policy and your configuration only contains a taskbar layout, the default Windows tile layout will be applied and cannot be changed by users. If you use Group Policy and your configuration includes taskbar and a full Start layout, users can only make changes to the taskbar. If you use Group Policy and your configuration includes taskbar and a [partial Start layout](https://technet.microsoft.com/itpro/windows/manage/customize-and-export-start-layout#configure-a-partial-start-layout), users can make changes to the taskbar and to tile groups not defined in the partial Start layout.
|
||||
|
||||
|
@ -8,7 +8,7 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
author: jdeckerms
|
||||
ms.localizationpriority: medium
|
||||
ms.date: 11/15/2017
|
||||
ms.date: 02/08/2018
|
||||
---
|
||||
|
||||
# Customize Windows 10 Start and taskbar with mobile device management (MDM)
|
||||
@ -45,86 +45,37 @@ Two features enable Start layout control:
|
||||
|
||||
|
||||
|
||||
- In MDM, you set the path to the .xml file that defines the Start layout using an OMA-URI setting, which is based on the [Policy configuration service provider (CSP)](https://go.microsoft.com/fwlink/p/?LinkID=623244).
|
||||
- In Microsoft Intune, you select the Start layout XML file and add it to a device configuration profile.
|
||||
|
||||
## <a href="" id="bkmk-domaingpodeployment"></a>Create a policy for your customized Start layout
|
||||
|
||||
|
||||
This example uses Microsoft Intune to configure an MDM policy that applies a customized Start layout. See the documentation for your MDM solution for help in applying the policy.
|
||||
|
||||
1. In the Start layout file created when you ran **Export-StartLayout**, replace markup characters with escape characters, and save the file. (You can replace the characters manually or use an online tool.)
|
||||
1. In the Microsoft Azure portal, search for **Intune** or go to **More services** > **Intune**.
|
||||
|
||||
Example of a layout file produced by Export-StartLayout:
|
||||
2. Select **Device configuration**.
|
||||
|
||||
<span codelanguage="XML"></span>
|
||||
<table>
|
||||
<colgroup>
|
||||
<col width="100%" />
|
||||
</colgroup>
|
||||
<thead>
|
||||
<tr class="header">
|
||||
<th align="left">XML</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr class="odd">
|
||||
<td align="left"><pre><code><LayoutModificationTemplate Version="1" xmlns="http://schemas.microsoft.com/Start/2014/LayoutModification">
|
||||
<DefaultLayoutOverride>
|
||||
<StartLayoutCollection>
|
||||
<defaultlayout:StartLayout GroupCellWidth="6" xmlns:defaultlayout="http://schemas.microsoft.com/Start/2014/FullDefaultLayout">
|
||||
<start:Group Name="Life at a glance" xmlns:start="http://schemas.microsoft.com/Start/2014/StartLayout">
|
||||
<start:Tile Size="2x2" Column="0" Row="0" AppUserModelID="Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge" />
|
||||
<start:Tile Size="2x2" Column="4" Row="0" AppUserModelID="Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI" />
|
||||
<start:Tile Size="2x2" Column="2" Row="0" AppUserModelID="Microsoft.BingWeather_8wekyb3d8bbwe!App" />
|
||||
</start:Group>
|
||||
</defaultlayout:StartLayout>
|
||||
</StartLayoutCollection>
|
||||
</DefaultLayoutOverride>
|
||||
</LayoutModificationTemplate></code></pre></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
3. Select **Profiles**.
|
||||
|
||||
Example of the same layout file with escape characters replacing the markup characters:
|
||||
4. Select **Create profile**.
|
||||
|
||||
```
|
||||
&lt;wdcml:p xmlns:wdcml=&quot;http://microsoft.com/wdcml&quot;&gt;Example of a layout file produced by Export-StartLayout:&lt;/wdcml:p&gt;&lt;wdcml:snippet xmlns:wdcml=&quot;http://microsoft.com/wdcml&quot;&gt;&lt;![CDATA[&lt;LayoutModificationTemplate Version=&quot;1&quot; xmlns=&quot;http://schemas.microsoft.com/Start/2014/LayoutModification&quot;&gt;
|
||||
&lt;DefaultLayoutOverride&gt;
|
||||
&lt;StartLayoutCollection&gt;
|
||||
&lt;defaultlayout:StartLayout GroupCellWidth=&quot;6&quot; xmlns:defaultlayout=&quot;http://schemas.microsoft.com/Start/2014/FullDefaultLayout&quot;&gt;
|
||||
&lt;start:Group Name=&quot;Life at a glance&quot; xmlns:start=&quot;http://schemas.microsoft.com/Start/2014/StartLayout&quot;&gt;
|
||||
&lt;start:Tile Size=&quot;2x2&quot; Column=&quot;0&quot; Row=&quot;0&quot; AppUserModelID=&quot;Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge&quot; /&gt;
|
||||
&lt;start:Tile Size=&quot;2x2&quot; Column=&quot;4&quot; Row=&quot;0&quot; AppUserModelID=&quot;Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI&quot; /&gt;
|
||||
&lt;start:Tile Size=&quot;2x2&quot; Column=&quot;2&quot; Row=&quot;0&quot; AppUserModelID=&quot;Microsoft.BingWeather_8wekyb3d8bbwe!App&quot; /&gt;
|
||||
&lt;/start:Group&gt;
|
||||
&lt;/defaultlayout:StartLayout&gt;
|
||||
&lt;/StartLayoutCollection&gt;
|
||||
&lt;/DefaultLayoutOverride&gt;
|
||||
&lt;/LayoutModificationTemplate&gt;]]&gt;&lt;/wdcml:snippet&gt;
|
||||
```
|
||||
5. Enter a friendly name for the profile.
|
||||
|
||||
2. In the Microsoft Intune administration console, click **Policy** > **Add Policy**.
|
||||
6. Select **Windows 10 and later** for the platform.
|
||||
|
||||
3. Under **Windows**, choose a **Custom Configuration (Windows 10 Desktop and Mobile and later)** policy.
|
||||
7. Select **Device restrictions for the profile type.
|
||||
|
||||
4. Enter a name (mandatory) and description (optional) for the policy.
|
||||
8. Select **Start**.
|
||||
|
||||
5. In the **OMA-URI Settings** section, click **Add.**
|
||||
9. In **Start menu layout**, browse to and select your Start layout XML File.
|
||||
|
||||
6. In **Add or Edit OMA-URI Setting**, enter the following information.
|
||||
10. Select **OK** twice, and then select **Create**.
|
||||
|
||||
| Item | Information |
|
||||
|----|----|
|
||||
| **Setting name** | Enter a unique name for the OMA-URI setting to help you identify it in the list of settings. |
|
||||
| **Setting description** | Provide a description that gives an overview of the setting and other relevant information to help you locate it. |
|
||||
| **Data type** | **String** |
|
||||
| **OMA-URI (case sensitive)** | **./User/Vendor/MSFT/Policy/Config/Start/StartLayout** |
|
||||
| **Value** | Paste the contents of the Start layout .xml file that you created. |
|
||||
11. Assign the profile to a device group.
|
||||
|
||||
|
||||
7. Click **OK** to save the setting and return to the **Create Policy** page.
|
||||
For other MDM solutions, you may need to use an OMA-URI setting for Start layout, based on the [Policy configuration service provider (CSP)](https://go.microsoft.com/fwlink/p/?LinkID=623244). The OMA-URI setting is `./User/Vendor/MSFT/Policy/Config/Start/StartLayout`.
|
||||
|
||||
8. Click **Save Policy**.
|
||||
|
||||
## Related topics
|
||||
|
||||
|
@ -22,9 +22,10 @@ Enterprises often need to apply custom configurations to devices for their users
|
||||
| [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) | Use this article to make informed decisions about how you can configure Windows diagnostic data in your organization. |
|
||||
|[Diagnostic Data Viewer overview](diagnostic-data-viewer-overview.md) |Learn about the categories of diagnostic data your device is sending to Microsoft, along with how it's being used.|
|
||||
| [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md) | Learn about diagnostic data that is collected at the basic level in Windows 10, version 1709. |
|
||||
|[Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)|Learn about diagnostic data that is collected by Windows Analytics.|
|
||||
| [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) | Learn about diagnostic data that is collected at the basic level in Windows 10, version 1703. |
|
||||
| [Windows 10 diagnostic data for the Full diagnostic data level](windows-diagnostic-data-1703.md) | Learn about the types of data that is collected at the full level in Windows 10, version 1703 and later. |
|
||||
| [Windows 10, version 1703 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md)| Learn about diagnostic data that is collected at the basic level in Windows 10, version 1703.|
|
||||
| [Windows 10, version 1709 enhanced telemetry events and fields used by Windows Analytics](enhanced-diagnostic-data-windows-analytics-events-and-fields.md)|Learn about diagnostic data that is collected by Windows Analytics.|
|
||||
| [Windows 10, version 1709 diagnostic data for the Full telemetry level](windows-diagnostic-data.md) | Learn about diagnostic data that is collected at the full level in Windows 10, version 1709. |
|
||||
| [Windows 10, version 1703 diagnostic data for the Full telemetry level](windows-diagnostic-data-1703.md) | Learn about diagnostic data that is collected at the full level in Windows 10, version 1703. |
|
||||
|[Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](gdpr-win10-whitepaper.md)|Learn about Windows 10 and the upcoming GDPR-compliance requirements.|
|
||||
| [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) | Learn about the network connections that Windows components make to Microsoft and also the privacy settings that affect data that is shared with either Microsoft or apps and how they can be managed by an IT Pro. |
|
||||
| [Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Wi-Fi Sense automatically connects you to Wi-Fi, so you can get online quickly in more places. It can connect you to open Wi-Fi hotspots it knows about through crowdsourcing, or to Wi-Fi networks your contacts have shared with you by using Wi-Fi Sense. The initial settings for Wi-Fi Sense are determined by the options you chose when you first set up your PC with Windows 10. |
|
||||
|
@ -9,7 +9,7 @@ ms.sitesec: library
|
||||
ms.pagetype: edu, security
|
||||
author: jdeckerms
|
||||
ms.localizationpriority: high
|
||||
ms.date: 01/31/2018
|
||||
ms.date: 02/08/2018
|
||||
ms.author: jdecker
|
||||
---
|
||||
|
||||
@ -20,21 +20,49 @@ ms.author: jdecker
|
||||
|
||||
- Windows 10
|
||||
|
||||
A [kiosk device](set-up-a-kiosk-for-windows-10-for-desktop-editions.md) typically runs a single app, and users are prevented from accessing any features or functions on the device outside of the kiosk app. In Windows 10, version 1709, the [AssignedAccess configuration service provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/assignedaccess-csp) has been expanded to make it easy for administrators to create kiosks that run more than one app. You can configure multi-app kiosks using Microsoft Intune or a provisioning package.
|
||||
A [kiosk device](set-up-a-kiosk-for-windows-10-for-desktop-editions.md) typically runs a single app, and users are prevented from accessing any features or functions on the device outside of the kiosk app. In Windows 10, version 1709, the [AssignedAccess configuration service provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/assignedaccess-csp) has been expanded to make it easy for administrators to create kiosks that run more than one app.
|
||||
|
||||
The benefit of a multi-app kiosk, or fixed-purpose device, is to provide an easy-to-understand experience for individuals by putting in front of them only the things they need to use, and removing from their view the things they don’t need to access.
|
||||
|
||||
>[!WARNING]
|
||||
>The assigned access feature is intended for corporate-owned fixed-purpose devices, like kiosks. When the multi-app assigned access configuration is applied on the device, [certain policies](#policies-set-by-multi-app-kiosk-configuration) are enforced system-wide, and will impact other users on the device. Deleting the multi-app configuration will remove the assigned access lockdown profiles associated with the users, but it cannot revert all the enforced policies (such as Start layout). A factory reset is needed to clear all the policies enforced via assigned access.
|
||||
|
||||
You can configure multi-app kiosks using [Microsoft Intune](#intune) or a [provisioning package](#provision).
|
||||
|
||||
<span id="intune"/>
|
||||
## Configure a kiosk in Microsoft Intune
|
||||
|
||||
Watch how to use Intune to configure a multi-app kiosk.
|
||||
|
||||
>[!VIDEO https://www.microsoft.com/videoplayer/embed/ce9992ab-9fea-465d-b773-ee960b990c4a?autoplay=false]
|
||||
|
||||
>[!NOTE]
|
||||
>For devices running versions of Windows 10 earlier than version 1709, you can [create AppLocker rules](lock-down-windows-10-applocker.md) to configure a multi-app kiosk.
|
||||
1. [Generate the Start layout for the kiosk device.](#startlayout)
|
||||
2. In the Microsoft Azure portal, search for **Intune** or go to **More services** > **Intune**.
|
||||
3. Select **Device configuration**.
|
||||
4. Select **Profiles**.
|
||||
5. Select **Create profile**.
|
||||
6. Enter a friendly name for the profile.
|
||||
7. Select **Windows 10 and later** for the platform.
|
||||
8. Select **Device restrictions** for the profile type.
|
||||
9. Select **Kiosk**.
|
||||
10. In **Kiosk Mode**, select **Multi app kiosk**.
|
||||
11. Select **Add** to define a configuration, which specifies the apps that will run and the layout for the Start menu.
|
||||
12. Enter a friendly name for the configuration.
|
||||
13. Select an app type, either **Win32 App** for a classic desktop application or **UWP App** for a Universal Windows Platform app.
|
||||
- For **Win32 App**, enter the fully qualified pathname of the executable, with respect to the device.
|
||||
- For **UWP App**, enter the Application User Model ID for an installed app.
|
||||
14. Select whether to enable the taskbar.
|
||||
15. Browse to and select the Start layout XML file that you generated in step 1.
|
||||
16. Add one or more accounts. When the account signs in, only the apps defined in the configuration will be available.
|
||||
17. Select **OK**. You can add additional configurations or finish.
|
||||
18. Assign the profile to a device group to configure the devices in that group as kiosks.
|
||||
|
||||
The benefit of a multi-app kiosk, or fixed-purpose device, is to provide an easy-to-understand experience for individuals by putting in front of them only the things they need to use, and removing from their view the things they don’t need to access.
|
||||
|
||||
>[!WARNING]
|
||||
>The assigned access feature is intended for corporate-owned fixed-purpose devices, like kiosks. When the multi-app assigned access configuration is applied on the device, certain policies are enforced system-wide, and will impact other users on the device. Deleting the multi-app configuration will remove the assigned access lockdown profiles associated with the users, but it cannot revert all the enforced policies (such as Start layout). A factory reset is needed to clear all the policies enforced via assigned access.
|
||||
|
||||
|
||||
|
||||
## Configure a kiosk using a provisioning package
|
||||
|
||||
Process:
|
||||
1. [Create XML file](#create-xml-file)
|
||||
2. [Add XML file to provisioning package](#add-xml)
|
||||
@ -46,14 +74,15 @@ Watch how to use a provisioning package to configure a multi-app kiosk.
|
||||
|
||||
If you don't want to use a provisioning package, you can deploy the configuration XML file using [mobile device management (MDM)](#alternate-methods) or you can configure assigned access using the [MDM Bridge WMI Provider](#bridge).
|
||||
|
||||
## Prerequisites
|
||||
### Prerequisites
|
||||
|
||||
- Windows Configuration Designer (Windows 10, version 1709)
|
||||
- The kiosk device must be running Windows 10 (S, Pro, Enterprise, or Education), version 1709
|
||||
|
||||
>[!NOTE]
|
||||
>For devices running versions of Windows 10 earlier than version 1709, you can [create AppLocker rules](lock-down-windows-10-applocker.md) to configure a multi-app kiosk.
|
||||
|
||||
|
||||
## Create XML file
|
||||
### Create XML file
|
||||
|
||||
Let's start by looking at the basic structure of the XML file.
|
||||
|
||||
@ -90,7 +119,7 @@ You can start your file by pasting the following XML (or any other examples in t
|
||||
</AssignedAccessConfiguration>
|
||||
```
|
||||
|
||||
### Profile
|
||||
#### Profile
|
||||
|
||||
A profile section in the XML has the following entries:
|
||||
|
||||
@ -103,7 +132,7 @@ A profile section in the XML has the following entries:
|
||||
- [**Taskbar**](#taskbar)
|
||||
|
||||
|
||||
#### Id
|
||||
##### Id
|
||||
|
||||
The profile **Id** is a GUID attribute to uniquely identify the profile. You can create a GUID using a GUID generator. The GUID just needs to be unique within this XML file.
|
||||
|
||||
@ -113,7 +142,7 @@ The profile **Id** is a GUID attribute to uniquely identify the profile. You can
|
||||
</Profiles>
|
||||
```
|
||||
|
||||
#### AllowedApps
|
||||
##### AllowedApps
|
||||
|
||||
**AllowedApps** is a list of applications that are allowed to run. Apps can be Universal Windows Platform (UWP) apps or Classic Windows desktop apps.
|
||||
|
||||
@ -155,7 +184,7 @@ The following example allows Groove Music, Movies & TV, Photos, Weather, Calcula
|
||||
</AllAppsList>
|
||||
```
|
||||
|
||||
#### StartLayout
|
||||
##### StartLayout
|
||||
|
||||
After you define the list of allowed applications, you can customize the Start layout for your kiosk experience. You can choose to pin all the allowed apps on the Start screen or just a subset, depending on whether you want the end user to directly access them on the Start screen.
|
||||
|
||||
@ -202,7 +231,7 @@ This example pins Groove Music, Movies & TV, Photos, Weather, Calculator, Paint,
|
||||
|
||||

|
||||
|
||||
#### Taskbar
|
||||
##### Taskbar
|
||||
|
||||
Define whether you want to have the taskbar present in the kiosk device. For tablet-based or touch-enabled all-in-one kiosks, when you don’t attach a keyboard and mouse, you can hide the taskbar as part of the multi-app experience if you want.
|
||||
|
||||
@ -221,7 +250,7 @@ The following example hides the taskbar:
|
||||
>[!NOTE]
|
||||
>This is different from the **Automatically hide the taskbar** option in tablet mode, which shows the taskbar when swiping up from or moving the mouse pointer down to the bottom of the screen. Setting **ShowTaskbar** as **false** will always keep the taskbar hidden.
|
||||
|
||||
### Configs
|
||||
#### Configs
|
||||
|
||||
Under **Configs**, define which user account will be associated with the profile. When this user account signs in on the device, the associated assigned access profile will be enforced, including the allowed apps, Start layout, and taskbar configuration, as well as other local group policies or mobile device management (MDM) policies set as part of the multi-app experience.
|
||||
|
||||
@ -256,7 +285,7 @@ Before applying the multi-app configuration, make sure the specified user accoun
|
||||
|
||||
|
||||
<span id="add-xml" />
|
||||
## Add XML file to provisioning package
|
||||
### Add XML file to provisioning package
|
||||
|
||||
Before you add the XML file to a provisioning package, you can [validate your configuration XML against the XSD](multi-app-kiosk-xml.md#xsd-for-assignedaccess-configuration-xml).
|
||||
|
||||
@ -317,12 +346,12 @@ Use the Windows Configuration Designer tool to create a provisioning package. [L
|
||||
15. Copy the provisioning package to the root directory of a USB drive.
|
||||
|
||||
<span id="apply-ppkg" />
|
||||
## Apply provisioning package to device
|
||||
### Apply provisioning package to device
|
||||
|
||||
Provisioning packages can be applied to a device during the first-run experience (out-of-box experience or "OOBE") and after ("runtime").
|
||||
|
||||
|
||||
### During initial setup, from a USB drive
|
||||
#### During initial setup, from a USB drive
|
||||
|
||||
1. Start with a computer on the first-run setup screen. If the PC has gone past this screen, reset the PC to start over. To reset the PC, go to **Settings** > **Update & security** > **Recovery** > **Reset this PC**.
|
||||
|
||||
@ -346,7 +375,7 @@ Provisioning packages can be applied to a device during the first-run experience
|
||||
|
||||
|
||||
|
||||
### After setup, from a USB drive, network folder, or SharePoint site
|
||||
#### After setup, from a USB drive, network folder, or SharePoint site
|
||||
|
||||
1. Sign in with an admin account.
|
||||
2. Insert the USB drive to a desktop computer, navigate to **Settings** > **Accounts** > **Access work or school** > **Add or remove a provisioning package** > **Add a package**, and select the package to install.
|
||||
@ -365,7 +394,7 @@ Provisioning packages can be applied to a device during the first-run experience
|
||||
|
||||
|
||||
<span id="alternate-methods" />
|
||||
## Use MDM to deploy the multi-app configuration
|
||||
### Use MDM to deploy the multi-app configuration
|
||||
|
||||
|
||||
Multi-app kiosk mode is enabled by the [AssignedAccess configuration service provider (CSP)](https://docs.microsoft.com/windows/client-management/mdm/assignedaccess-csp). Your MDM policy can contain the assigned access configuration XML.
|
||||
|
@ -32,7 +32,8 @@ A single-use or *kiosk* device is easy to set up in Windows 10 for desktop edit
|
||||
|
||||
- For a kiosk device to run a Classic Windows application, use [Shell Launcher](#shell-launcher) to set a custom user interface as the shell (Windows 10 Enterprise or Education only).
|
||||
|
||||
To return the device to the regular shell, see [Sign out of assigned access](#sign-out-of-assigned-access).
|
||||
>[!TIP]
|
||||
>To return the device to the regular shell, see [Sign out of assigned access](#sign-out-of-assigned-access).
|
||||
|
||||
>[!NOTE]
|
||||
>A Universal Windows app is built on the Universal Windows Platform (UWP), which was first introduced in Windows 8 as the Windows Runtime. A Classic Windows application uses the Classic Windows Platform (CWP) (e.g., COM, Win32, WPF, WinForms, etc.) and is typically launched using an .EXE or .DLL file.
|
||||
|
@ -51,7 +51,7 @@ The following policy settings can be configured for UE-V.
|
||||
<td align="left"><p>The default is enabled.</p></td>
|
||||
</tr>
|
||||
<tr class="odd">
|
||||
<td align="left"><p>Roam Windows settings</p></td>
|
||||
<td align="left"><p>Synchronize Windows settings</p></td>
|
||||
<td align="left"><p>Computers and Users</p></td>
|
||||
<td align="left"><p>This Group Policy setting configures the synchronization of Windows settings.</p></td>
|
||||
<td align="left"><p>Select which Windows settings synchronize between computers.</p>
|
||||
|
@ -425,6 +425,7 @@ The following table shows the scenarios supported by this customization:
|
||||
|
||||
|
||||
Multivariant setting set?|SPN provisioned?|MSISDN (last 4 digits: 1234, for example) provisioned?|Default SIM name
|
||||
--- | --- | --- | ---
|
||||
Yes|Yes|Yes|*MultivariantProvisionedSPN*1234 or *MultivariantProvisionedSPN*" "1234
|
||||
Yes|No|No|*MultivariantProvisionedSPN* (up to 16 characters)
|
||||
Yes|Yes|No|*MultivariantProvisionedSPN* (up to 16 characters)
|
||||
|
@ -8,13 +8,13 @@ ms.sitesec: library
|
||||
ms.localizationpriority: high
|
||||
author: eross-msft
|
||||
ms.author: lizross
|
||||
ms.date: 04/05/2017
|
||||
ms.date: 11/28/2017
|
||||
---
|
||||
|
||||
# Windows 10 diagnostic data for the Full diagnostic data level
|
||||
|
||||
**Applies to:**
|
||||
- Windows 10, version 1703 and later
|
||||
- Windows 10, version 1703
|
||||
|
||||
Microsoft collects Windows diagnostic data to keep Windows up-to-date, secure, and operating properly. It also helps us improve Windows and, for users who have turned on “tailored experiences”, can be used to provide more relevant tips and recommendations to tailor Microsoft products to the user’s needs. This article describes all types diagnostic data collected by Windows at the Full diagnostic data level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1709 Basic level diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md) and [Windows 10, version 1703 Basic level diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md).
|
||||
|
||||
|
262
windows/configuration/windows-diagnostic-data.md
Normal file
262
windows/configuration/windows-diagnostic-data.md
Normal file
@ -0,0 +1,262 @@
|
||||
---
|
||||
title: Windows 10, version 1709 diagnostic data for the Full level (Windows 10)
|
||||
description: Use this article to learn about the types of diagnostic data that is collected at the Full level.
|
||||
keywords: privacy,Windows 10
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: high
|
||||
author: brianlic-msft
|
||||
ms.author: brianlic
|
||||
ms.date: 01/30/2018
|
||||
---
|
||||
|
||||
# Windows 10, version 1709 diagnostic data for the Full level
|
||||
|
||||
Applies to:
|
||||
- Windows 10, version 1709
|
||||
|
||||
Microsoft uses Windows diagnostic data to keep Windows secure and up-to-date, troubleshoot problems, and make product improvements. For users who have turned on "Tailored experiences", it can also be used to offer you personalized tips, ads, and recommendations to enhance Microsoft products and services for your needs. This article describes all types of diagnostic data collected by Windows at the Full level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1709 Basic level diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields.md).
|
||||
|
||||
In addition, this article provides references to equivalent definitions for the data types and examples from [ISO/IEC 19944:2017 Information technology -- Cloud computing -- Cloud services and devices: Data flow, data categories and data use](https://www.iso.org/standard/66674.html). Each data type also has a Data Use statement, for diagnostics and for Tailored experiences on the device, using the terms as defined by the standard. These Data Use statements define the purposes for which Microsoft processes each type of Windows diagnostic data, using a uniform set of definitions referenced at the end of this document and based on the ISO standard. Reference to the ISO standard provides additional clarity about the information collected, and allows easy comparison with other services or guidance that also references the standard.
|
||||
|
||||
The data covered in this article is grouped into the following types:
|
||||
|
||||
- Common data (diagnostic header information)
|
||||
|
||||
- Device, Connectivity, and Configuration data
|
||||
|
||||
- Product and Service Usage data
|
||||
|
||||
- Product and Service Performance data
|
||||
|
||||
- Software Setup and Inventory data
|
||||
|
||||
- Browsing History data
|
||||
|
||||
- Inking, Typing, and Speech Utterance data
|
||||
|
||||
## Common data
|
||||
Most diagnostic events contain a header of common data. In each example, the info in parentheses provides the equivalent definition for ISO/IEC 19944:2017.
|
||||
|
||||
**Data Use for Common data**
|
||||
Header data supports the use of data associated with all diagnostic events. Therefore, Common data is used to [provide](#provide) Windows 10, and may be used to [improve](#improve), [personalize](#personalize), [recommend](#recommend), [offer](#offer), or [promote](#promote) Microsoft and third-party products and services, depending on the uses described in the **Data Use** statements for each data category.
|
||||
|
||||
### Data Description for Common data type
|
||||
|Sub-type|Description and examples|
|
||||
|- |- |
|
||||
|Common Data|Information that is added to most diagnostic events, if relevant and available:<ul><li>Diagnostic level -- Basic or Full, Sample level -- for sampled data, what sample level is this device opted into (8.2.3.2.4 Observed Usage of the Service Capability)</li><li>Operating system name, version, build, and locale (8.2.3.2.2 Telemetry data)</li><li>Event collection time (8.2.3.2.2 Telemetry data)</li><li>User ID -- a unique identifier associated with the user's Microsoft Account (if one is used) or local account. The user's Microsoft Account identifier is not collected from devices configured to send Basic diagnostic data (8.2.5 Account data)</li><li>Xbox UserID (8.2.5 Account data)</li><li>Device ID -- This is not the user provided device name, but an ID that is unique for that device. (8.2.3.2.3 Connectivity data)</li><li>Device class -- Desktop, Server, or Mobile (8.2.3.2.3 Connectivity data)</li><li>Environment from which the event was logged -- Application ID of app or component that logged the event, Session GUID. Used to track events over a given period of time, such as the amount of time an app is running or between boots of the operating system (8.2.4 Cloud service provider data)</li><li>Diagnostic event name, Event ID, ETW opcode, version, schema signature, keywords, and flags (8.2.4 Cloud service provider data)</li><li>HTTP header information, including the IP address. This IP address is the source address that’s provided by the network packet header and received by the diagnostics ingestion service (8.2.4 Cloud service provider data)</li><li>Various IDs that are used to correlate and sequence related events together (8.2.4 Cloud service provider data)</li></ul>|
|
||||
|
||||
## Device, Connectivity, and Configuration data
|
||||
This type of data includes details about the device, its configuration and connectivity capabilities, and status. Device, Connectivity, and Configuration Data is equivalent to ISO/IEC 19944:2017, 8.2.3.2.3 Connectivity data.
|
||||
|
||||
### Data Use for Device, Connectivity, and Configuration data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft products and services. For example:
|
||||
|
||||
- Device, Connectivity, and Configuration data is used to understand the unique device characteristics that can contribute to an error experienced on the device, to identify patterns, and to more quickly resolve problems that impact devices with unique hardware, capabilities, or settings. For example:
|
||||
|
||||
- Data about the use of cellular modems and their configuration on your devices is used to troubleshoot cellular modem issues.
|
||||
|
||||
- Data about the use of USB hubs use and their configuration on your devices is used to troubleshoot USB hub issues.
|
||||
|
||||
- Data about the use of connected Bluetooth devices is used to troubleshoot compatibility issues with Bluetooth devices.
|
||||
|
||||
- Data about device properties, such as the operating system version and available memory, is used to determine whether the device is due to, and able to, receive a Windows update.
|
||||
|
||||
- Data about device peripherals is used to determine whether a device has installed drivers that might be negatively impacted by a Windows update.
|
||||
|
||||
- Data about which devices, peripherals, and settings are most-used by customers, is used to prioritize Windows 10 improvements to determine the greatest positive impact to the most Windows 10 users.
|
||||
|
||||
**With (optional) Tailored experiences:**<br>
|
||||
If a user has enabled Tailored experiences on the device, [Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
|
||||
|
||||
- Data about device properties and capabilities is used to provide tips about how to use or configure the device to get the best performance and user experience.
|
||||
|
||||
- Data about device capabilities, such as whether the device is pen-enabled, is used to recommend (Microsoft and third-party) apps that are appropriate for the device. These may be free or paid apps.
|
||||
|
||||
### Data Description for Device, Connectivity, and Configuration data type
|
||||
|Sub-type|Description and examples|
|
||||
|- |- |
|
||||
|Device properties |Information about the operating system and device hardware, such as:<br><ul><li>Operating system - version name, edition</li><li>Installation type, subscription status, and genuine operating system status</li><li>Processor architecture, speed, number of cores, manufacturer, and model</li><li>OEM details --manufacturer, model, and serial number</li><li>Device identifier and Xbox serial number</li><li>Firmware/BIOS operating system -- type, manufacturer, model, and version</li><li>Memory -- total memory, video memory, speed, and how much memory is available after the device has reserved memory</li><li>Storage -- total capacity and disk type</li><li>Battery -- charge capacity and InstantOn support</li><li>Hardware chassis type, color, and form factor</li><li>Is this a virtual machine?</li></ul>|
|
||||
|Device capabilities|Information about the specific device capabilities, such as:<br/><ul><li>Camera -- whether the device has a front facing camera, a rear facing camera, or both.</li><li>Touch screen -- Whether the device has a touch screen? If yes, how many hardware touch points are supported?</li><li>Processor capabilities -- CompareExchange128, LahfSahf, NX, PrefetchW, and SSE2</li><li>Trusted Platform Module (TPM) -- whether a TPM exists and if yes, what version</li><li>Virtualization hardware -- whether an IOMMU exists, whether it includes SLAT support, and whether virtualization is enabled in the firmware</li><li>Voice -- whether voice interaction is supported and the number of active microphones</li><li>Number of displays, resolutions, and DPI</li><li>Wireless capabilities</li><li>OEM or platform face detection</li><li>OEM or platform video stabilization and quality-level set</li><li>Advanced Camera Capture mode (HDR versus Low Light), OEM versus platform implementation, HDR probability, and Low Light probability</li></ul>|
|
||||
|Device preferences and settings |Information about the device settings and user preferences, such as:<br><ul><li>User Settings -- System, Device, Network & Internet, Personalization, Cortana, Apps, Accounts, Time & Language, Gaming, Ease of Access, Privacy, Update & Security</li><li>User-provided device name</li><li>Whether device is domain-joined, or cloud-domain joined (for example, part of a company-managed network)</li><li>Hashed representation of the domain name</li><li>MDM (mobile device management) enrollment settings and status</li><li>BitLocker, Secure Boot, encryption settings, and status</li><li>Windows Update settings and status</li><li>Developer Unlock settings and status</li><li>Default app choices</li><li>Default browser choice</li><li>Default language settings for app, input, keyboard, speech, and display</li><li>App store update settings</li><li>Enterprise OrganizationID, Commercial ID</li></ul>|
|
||||
|Device peripherals |Information about the device peripherals, such as:<br><ul><li>Peripheral name, device model, class, manufacturer, and description</li><li>Peripheral device state, install state, and checksum</li><li>Driver name, package name, version, and manufacturer</li><li>HWID - A hardware vendor-defined ID to match a device to a driver [INF file](https://msdn.microsoft.com/windows/hardware/drivers/install/hardware-ids)</li><li>Driver state, problem code, and checksum</li><li>Whether driver is kernel mode, signed, and image size</li></ul>|
|
||||
|Device network info |Information about the device network configuration, such as:<br><ul><li>Network system capabilities</li><li>Local or Internet connectivity status</li><li>Proxy, gateway, DHCP, DNS details, and addresses</li><li>Whether it's a paid or free network</li><li>Whether the wireless driver is emulated</li><li>Whether it's access point mode-capable</li><li>Access point manufacturer, model, and MAC address</li><li>WDI Version</li><li>Name of networking driver service</li><li>Wi-Fi Direct details</li><li>Wi-Fi device hardware ID and manufacturer</li><li>Wi-Fi scan attempt and item counts</li><li>Whether MAC randomization is supported and enabled</li><li>Number of supported spatial streams and channel frequencies</li><li>Whether Manual or Auto-connect is enabled</li><li>Time and result of each connection attempt</li><li>Airplane mode status and attempts</li><li>Interface description provided by the manufacturer</li><li>Data transfer rates</li><li>Cipher algorithm</li><li>Mobile Equipment ID (IMEI) and Mobile Country Code (MCCO)</li><li>Mobile operator and service provider name</li><li>Available SSIDs and BSSIDs</li><li>IP Address type -- IPv4 or IPv6</li><li>Signal Quality percentage and changes</li><li>Hotspot presence detection and success rate</li><li>TCP connection performance</li><li>Miracast device names</li><li>Hashed IP address</li></ul>
|
||||
|
||||
## Product and Service Usage data
|
||||
This type of data includes details about the usage of the device, operating system, applications and services. Product and Service Usage data is equivalent to ISO/IEC 19944:2017, 8.2.3.2.4 Observed Usage of the Service Capability.
|
||||
|
||||
### Data Use for Product and Service Usage data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
|
||||
|
||||
- Data about the specific apps that are in-use when an error occurs is used to troubleshoot and repair issues with Windows features and Microsoft apps.
|
||||
|
||||
- Data about the specific apps that are most-used by customers, is used to prioritize Windows 10 improvements to determine the greatest positive impact to the most Windows 10 users.
|
||||
|
||||
- Data about whether devices have Suggestions turned off from the **Settings Phone** screen is to improve the Suggestions feature.
|
||||
|
||||
- Data about whether a user canceled the authentication process in their browser is used to help troubleshoot issues with and improve the authentication process.
|
||||
|
||||
- Data about when and what feature invoked Cortana is used to prioritize efforts for improvement and innovation in Cortana.
|
||||
|
||||
- Data about when a context menu in the photo app is closed is used to troubleshoot and improve the photo app.
|
||||
|
||||
**With (optional) Tailored experiences:**<br>
|
||||
If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
|
||||
|
||||
- If data shows that a user has not used a particular feature of Windows, we may recommend that the user try that feature.
|
||||
|
||||
- Data about which apps are most-used on a device is used to provide recommendations for similar or complementary (Microsoft or third-party) apps. These may be free or paid apps.
|
||||
|
||||
|
||||
### Data Description for Product and Service Usage data type
|
||||
|Sub-type|Description and examples |
|
||||
|- |- |
|
||||
|App usage|Information about Windows and application usage, such as:<ul><li>Operating system component and app feature usage</li><li>User navigation and interaction with app and Windows features. This could potentially include user input, such as name of a new alarm set, user menu choices, or user favorites</li><li>Time of and count of app and component launches, duration of use, session GUID, and process ID</li><li>App time in various states –- running in the foreground or background, sleeping, or receiving active user interaction</li><li>User interaction method and duration –- whether the user used a keyboard, mouse, pen, touch, speech, or game controller, and for how long</li><li>Cortana launch entry point and reason</li><li>Notification delivery requests and status</li><li>Apps used to edit images and videos</li><li>SMS, MMS, VCard, and broadcast message usage statistics on primary or secondary lines</li><li>Incoming and outgoing calls and voicemail usage statistics on primary or secondary lines</li><li>Emergency alerts are received or displayed statistics</li><li>Content searches within an app</li><li>Reading activity -- bookmarked, printed, or had the layout changed</li></ul>|
|
||||
|App or product state|Information about Windows and application state, such as:<ul><li>Start Menu and Taskbar pins</li><li>Online and offline status</li><li>App launch state –- with deep-links, such as Groove launching with an audio track to play or MMS launching to share a picture</li><li>Personalization impressions delivered</li><li>Whether the user clicked on, or hovered over, UI controls or hotspots</li><li>User provided feedback, such as Like, Dislike or a rating</li><li>Caret location or position within documents and media files -- how much has been read in a book in a single session, or how much of a song has been listened to.</li></ul>|
|
||||
|Purchasing|Information about purchases made on the device, such as:<br><ul><li>Product ID, edition ID and product URI</li><li>Offer details -- price</li><li>Date and time an order was requested</li><li>Microsoft Store client type -- web or native client</li><li>Purchase quantity and price</li><li>Payment type -- credit card type and PayPal</li></ul> |
|
||||
|Login properties|Information about logins on the device, such as:<ul><li>Login success or failure</li><li>Login sessions and state</li></ul>|
|
||||
|
||||
## Product and Service Performance data
|
||||
This type of data includes details about the health of the device, operating system, apps, and drivers. Product and Service Performance data is equivalent to ISO/IEC 19944:2017 8.2.3.2.2 EUII Telemetry data.
|
||||
|
||||
### Data Use for Product and Service Performance data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
|
||||
|
||||
- Data about the reliability of content that appears in the [Windows Spotlight](https://docs.microsoft.com/en-us/windows/configuration/windows-spotlight) (rotating lock screen images) is used for Windows Spotlight reliability investigations.
|
||||
|
||||
- Timing data about how quickly Cortana responds to voice commands is used to improve Cortana listening peformance.
|
||||
|
||||
- Timing data about how quickly the facial recognition feature starts up and finishes is used to improve facial recognition performance.
|
||||
|
||||
- Data about when an Application Window fails to appear is used to investigate issues with Application Window reliability and performance.
|
||||
|
||||
**With (optional) Tailored experiences:**<br>
|
||||
If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users.
|
||||
|
||||
- Data about battery performance on a device may be used to recommend settings changes that can improve battery performance.
|
||||
|
||||
- If data shows a device is running low on file storage, we may recommend Windows-compatible cloud storage solutions to free up space.
|
||||
|
||||
- If data shows the device is experiencing performance issues, we may provide recommendations for Windows apps that can help diagnose or resolve these issues. These may be free or paid apps.
|
||||
|
||||
**Microsoft doesn't use crash and hang dump data to [personalize](#personalize), [recommend](#recommend), [offer](#offer), or [promote](#promote) any product or service.**
|
||||
|
||||
### Data Description for Product and Service Performance data type
|
||||
|Sub-type|Description and examples |
|
||||
|- |- |
|
||||
|Device health and crash data|Information about the device and software health, such as:<br><ul><li>Error codes and error messages, name and ID of the app, and process reporting the error</li><li>DLL library predicted to be the source of the error -- for example, xyz.dll</li><li>System generated files -- app or product logs and trace files to help diagnose a crash or hang</li><li>System settings, such as registry keys</li><li>User generated files -- files that are indicated as a potential cause for a crash or hang. For example, .doc, .ppt, .csv files</li><li>Details and counts of abnormal shutdowns, hangs, and crashes</li><li>Crash failure data -- operating system, operating system component, driver, device, and 1st and 3rd-party app data</li><li>Crash and hang dumps, including:<ul><li>The recorded state of the working memory at the point of the crash</li><li>Memory in-use by the kernel at the point of the crash.</li><li>Memory in-use by the application at the point of the crash</li><li>All the physical memory used by Windows at the point of the crash</li><li>Class and function name within the module that failed.</li></li></ul>|
|
||||
|Device performance and reliability data|Information about the device and software performance, such as:<br><ul><li>User interface interaction durations -- Start menu display times, browser tab switch times, app launch and switch times, and Cortana and Search performance and reliability</li><li>Device on and off performance -- Device boot, shutdown, power on and off, lock and unlock times, and user authentication times (fingerprint and face recognition durations)</li><li>In-app responsiveness -- time to set alarm, time to fully render in-app navigation menus, time to sync reading list, time to start GPS navigation, time to attach picture MMS, and time to complete a Microsoft Store transaction</li><li>User input responsiveness -- onscreen keyboard invocation times for different languages, time to show auto-complete words, pen or touch latencies, latency for handwriting recognition to words, Narrator screen reader responsiveness, and CPU score</li><li>UI and media performance and glitches versus smoothness -- video playback frame rate, audio glitches, animation glitches (stutter when bringing up Start), graphics score, time to first frame, play/pause/stop/seek responsiveness, time to render PDF, dynamic streaming of video from OneDrive performance</li><li>Disk footprint -- Free disk space, out of memory conditions, and disk score</li><li>Excessive resource utilization -- components impacting performance or battery life through high CPU usage during different screen and power states</li><li>Background task performance -- download times, Windows Update scan duration, Windows Defender Antivirus scan times, disk defrag times, mail fetch times, service startup and state transition times, and time to index on-device files for search results</li><li>Peripheral and devices -- USB device connection times, time to connect to a wireless display, printing times, network availability and connection times (time to connect to Wi-Fi, time to get an IP address from DHCP etc.), smart card authentication times, automatic brightness, and environmental response times</li><li>Device setup -- first setup experience times (time to install updates, install apps, connect to network, and so on), time to recognize connected devices (printer and monitor), and time to set up a Microsoft Account</li><li>Power and Battery life -- power draw by component (Process/CPU/GPU/Display), hours of time the screen is off, sleep state transition details, temperature and thermal throttling, battery drain in a power state (screen off or screen on), processes and components requesting power use while the screen is off, auto-brightness details, time device is plugged into AC versus battery, and battery state transitions</li><li>Service responsiveness -- Service URI, operation, latency, service success and error codes, and protocol</li><li>Diagnostic heartbeat -- regular signal used to validate the health of the diagnostics system</li></ul>|
|
||||
|Movies|Information about movie consumption functionality on the device. This isn't intended to capture user viewing, listening, or habits.<ul><li>Video Width, height, color palette, encoding (compression) type, and encryption type</li><li>Instructions about how to stream content for the user -- the smooth streaming manifest of content file chunks that must be pieced together to stream the content based on screen resolution and bandwidth</li><li>URL for a specific two-second chunk of content if there is an error</li><li>Full-screen viewing mode details</li></ul>|
|
||||
|Music & TV|Information about music and TV consumption on the device. This isn't intended to capture user viewing, listening, or habits.<ul><li>Service URL for song being downloaded from the music service -- collected when an error occurs to facilitate restoration of service</li><li>Content type (video, audio, or surround audio)</li><li>Local media library collection statistics -- number of purchased tracks and number of playlists</li><li>Region mismatch -- User's operating system region and Xbox Live region</li></ul>|
|
||||
|Reading|Information about reading consumption functionality on the device. This isn't intended to capture user viewing, listening, or habits.<ul><li>App accessing content and status and options used to open a Microsoft Store book</li><li>Language of the book</li><li>Time spent reading content</li><li>Content type and size details</li></ul>|
|
||||
|Photos App|Information about photos usage on the device. This isn't intended to capture user viewing, listening, or habits.<ul><li>File source data -- local, SD card, network device, and OneDrive</li><li>Image and video resolution, video length, file sizes types, and encoding</li><li>Collection view or full screen viewer use and duration of view</li></ul>|
|
||||
|On-device file query |Information about local search activity on the device, such as: <ul><li>Kind of query issued and index type (ConstraintIndex or SystemIndex)</li><li>Number of items requested and retrieved</li><li>File extension of search result with which the user interacted</li><li>Launched item type, file extension, index of origin, and the App ID of the opening app</li><li>Name of process calling the indexer and the amount of time to service the query</li><li>A hash of the search scope (file, Outlook, OneNote, or IE history). The state of the indices (fully optimized, partially optimized, or being built)</li></ul> |
|
||||
|Entitlements |Information about entitlements on the device, such as:<ul><li>Service subscription status and errors</li><li>DRM and license rights details -- Groove subscription or operating system volume license</li><li>Entitlement ID, lease ID, and package ID of the install package</li><li>Entitlement revocation</li><li>License type (trial, offline versus online) and duration</li><li>License usage session</li></ul>|
|
||||
|
||||
## Software Setup and Inventory data
|
||||
This type of data includes software installation and update information on the device. Software Setup and Inventory Data is a sub-type of ISO/IEC 19944:2017 8.2.3.2.4 Observed Usage of the Service Capability.
|
||||
|
||||
### Data Use for Software Setup and Inventory data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
|
||||
|
||||
- Data about the specific drivers that are installed on a device is used to understand whether there are any hardware or driver compatibility issues which should block or delay a Windows update.
|
||||
|
||||
- Data about when a download starts and finishes on a device is used to understand and address download problems.
|
||||
|
||||
- Data about the specific Microsoft Store apps that are installed on a device is used to determine which app updates to provide to the device.
|
||||
|
||||
- Data about the antimalware installed on a device is used to understand malware transmissions vectors.
|
||||
|
||||
**With (optional) Tailored experiences:**<br>
|
||||
If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
|
||||
|
||||
- Data about the specific apps that are installed on a device is used to provide recommendations for similar or complementary apps in the Microsoft Store.
|
||||
|
||||
### Data Description for Software Setup and Inventory data type
|
||||
|Sub-type|Description and examples |
|
||||
|- |- |
|
||||
|Installed Applications and Install History|Information about apps, drivers, update packages, or operating system components installed on the device, such as:<ul><li>App, driver, update package, or component’s Name, ID, or Package Family Name</li><li>Product, SKU, availability, catalog, content, and Bundle IDs</li><li>Operating system component, app or driver publisher, language, version and type (Win32 or UWP)</li><li>Install date, method, install directory, and count of install attempts</li><li>MSI package and product code</li><li>Original operating system version at install time</li><li>User, administrator, or mandatory installation or update</li><li>Installation type -- clean install, repair, restore, OEM, retail, upgrade, or update</li></ul>|
|
||||
|Device update information |Information about Windows Update, such as:<ul><li>Update Readiness analysis of device hardware, operating system components, apps, and drivers (progress, status, and results)</li><li>Number of applicable updates, importance, and type</li><li>Update download size and source -- CDN or LAN peers</li><li>Delay upgrade status and configuration</li><li>Operating system uninstall and rollback status and count</li><li>Windows Update server and service URL</li><li>Windows Update machine ID</li><li>Windows Insider build details</li></ul>|
|
||||
|
||||
## Browsing History data
|
||||
This type of data includes details about web browsing in the Microsoft browsers. Browsing History data is equivalent to ISO/IEC 19944:2017 8.2.3.2.8 Client side browsing history.
|
||||
|
||||
### Data Use for Browsing History data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
|
||||
|
||||
- Data about when the **Block Content** dialog box has been shown is used for investigations of blocked content.
|
||||
|
||||
- Data about potentially abusive or malicious domains is used to make updates to Microsoft Edge and Windows Defender SmartScreen to warn users about the domain.
|
||||
|
||||
- Data about when the **Address** bar is used for navigation purposes is used to improve the Suggested Sites feature and to understand and address problems arising from navigation.
|
||||
|
||||
- Data about when a Web Notes session starts is used to measure popular domains and URLs for the Web Notes feature.
|
||||
|
||||
- Data about when a default **Home** page is changed by a user is used to measure which default **Home** pages are the most popular and how often users change the default **Home** page.
|
||||
|
||||
**With (optional) Tailored experiences:**<br>
|
||||
If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
|
||||
|
||||
- We may recommend that a user download a compatible app from the Microsoft Store if they have browsed to the related website. For example, if a user uses the Facebook website, we may recommend the Facebook app.
|
||||
|
||||
### Data Description for Browsing History data type
|
||||
|Sub-type|Description and examples |
|
||||
|- |- |
|
||||
|Microsoft browser data|Information about **Address** bar and **Search** box performance on the device, such as:<ul><li>Text typed in **Address** bar and **Search** box</li><li>Text selected for an **Ask Cortana** search</li><li>Service response time</li><li>Auto-completed text, if there was an auto-complete</li><li>Navigation suggestions provided based on local history and favorites</li><li>Browser ID</li><li>URLs (may include search terms)</li><li>Page title</li></ul>|
|
||||
|
||||
## Inking Typing and Speech Utterance data
|
||||
This type of data gathers details about the voice, inking, and typing input features on the device. Inking, Typing and Speech Utterance data is a sub-type of ISO/IEC 19944:2017 8.2.3.2.1 End User Identifiable information.
|
||||
|
||||
### Data Use for Inking, Typing, and Speech Utterance data
|
||||
|
||||
**For Diagnostics:**<br>
|
||||
[Anonymized](#anon) Inking, Typing, and Speech Utterance data from Windows 10 is used by Microsoft to [improve](#improve) natural language capabilities in Microsoft products and services. For example:
|
||||
|
||||
- Data about words marked as spelling mistakes and replaced with another word from the context menu is used to improve the spelling feature.
|
||||
|
||||
- Data about alternate words shown and selected by the user after right-clicking is used to improve the word recommendation feature.
|
||||
|
||||
- Data about auto-corrected words that were restored back to the original word by the user is used to improve the auto-correct feature.
|
||||
|
||||
- Data about whether Narrator detected and recognized a touch gesture is used to improve touch gesture recognition.
|
||||
|
||||
- Data about handwriting samples sent from the Handwriting Panel is used to help Microsoft improve handwriting recognition.
|
||||
|
||||
**With (optional) Tailored experiences:**
|
||||
|
||||
**Microsoft doesn't use Windows Inking, Typing, and Speech Utterance data for Tailored experiences.**
|
||||
|
||||
### Data Description for Inking, Typing, and Speech Utterance data type
|
||||
|Sub-type|Description and examples |
|
||||
|- |- |
|
||||
|Voice, inking, and typing|Information about voice, inking and typing features, such as:<ul><li>Type of pen used (highlighter, ball point, or pencil), pen color, stroke height and width, and how long it is used</li><li>Pen gestures (click, double click, pan, zoom, or rotate)</li><li>Palm Touch x,y coordinates</li><li>Input latency, missed pen signals, number of frames, strokes, first frame commit time, and sample rate</li><li>Ink strokes written, text before and after the ink insertion point, recognized text entered, input language -- processed to remove identifiers, sequencing information, and other data (such as email addresses and numeric values), which could be used to reconstruct the original content or associate the input to the user</li><li>Text input from Windows 10 Mobile on-screen keyboards, except from password fields and private sessions -- processed to remove identifiers, sequencing information, and other data (such as email addresses and numeric values), which could be used to reconstruct the original content or associate the input to the user</li><li>Text of speech recognition results -- result codes and recognized text</li><li>Language and model of the recognizer and the System Speech language</li><li>App ID using speech features</li><li>Whether user is known to be a child</li><li>Confidence and success or failure of speech recognition</li></ul>|
|
||||
|
||||
## ISO/IEC 19944:2017-specific terminology
|
||||
This table provides the ISO/IEC 19944:2017-specific definitions for use and de-identification qualifiers used in this article.
|
||||
|
||||
|Term |ISO/IEC 19944:2017 Reference |Microsoft usage notes |
|
||||
|-|-|-|
|
||||
|<a name="#provide">Provide</a> |9.3.2 Provide |Use of a specified data category by a Microsoft product or service to protect and provide the described service, including, (i) troubleshoot and fix issues with the product or service or (ii) provide product or service updates.|
|
||||
|<a name="#improve">Improve</a> |9.3.3 Improve |Use of a specified data category to improve or increase the quality of a Microsoft product or service. Those improvements may be available to end users.|
|
||||
|<a name="#personalize">Personalize</a> |9.3.4 Personalize |Use of the specified data categories to create a customized experience for the end user in any Microsoft product or service.|
|
||||
|<a name="#recommend">Recommend</a> |9.3.4 Personalize |“Recommend” means use of the specified data categories to Personalize (9.3.4) the end user’s experience by recommending Microsoft products or services that can be accessed without the need to make a purchase or pay money.<br><br>Use of the specified data categories give recommendations about Microsoft products or services the end user may act on where the recommendation is (i) contextually relevant to the product or service in which it appears, (ii) that can be accessed without the need to make a purchase or pay money, and (iii) Microsoft receives no compensation for the placement.|
|
||||
|<a name="#offer">Offer</a> |9.3.5 Offer upgrades or upsell |Implies the source of the data is Microsoft products and services, and the upgrades offered come from Microsoft products and services that are relevant to the context of the current capability. The target audience for the offer is Microsoft customers.<br><br>Specifically, use of the specified data categories to make an offer or upsell new capability or capacity of a Microsoft product or service which is (i) contextually relevant to the product or service in which it appears; (ii) likely to result in additional future revenue for Microsoft from end user; and (iii) Microsoft receives no consideration for placement.|
|
||||
|<a name="#promote">Promote</a>|9.3.6 Market/advertise/promote|Use of the specified data categories to promote a product or service in or on a first-party Microsoft product or service.|
|
||||
|
||||
<br><br>
|
||||
|Data identification qualifiers |ISO/IEC 19944:2017 Reference |Microsoft usage notes |
|
||||
|-|-|-|
|
||||
|<a name="#pseudo">Pseudonymized Data</a> |8.3.3 Pseudonymized data|As defined|
|
||||
|<a name="#anon">Anonymized Data</a> |8.3.5 Anonymized data|As defined|
|
||||
|<a name="#aggregate">Aggregated Data</a> |8.3.6 Aggregated data|As defined|
|
Reference in New Issue
Block a user