mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
Merge branch 'master' into indicators-update
This commit is contained in:
commit
9d9c09aee8
@ -45,7 +45,7 @@ Some of the components might also need additional system resources. Check the co
|
||||
|
||||
## Supported languages
|
||||
|
||||
Microsoft Edge supports all of the same languages as Windows 10 and you can use the [Microsoft Translator extension](https://www.microsoft.com/en-us/p/translator-for-microsoft-edge/9nblggh4n4n3) to translate foreign language web pages and text selections for 60+ languages.
|
||||
Microsoft Edge supports all of the same languages as Windows 10 and you can use the [Microsoft Translator extension](https://www.microsoft.com/p/translator-for-microsoft-edge/9nblggh4n4n3) to translate foreign language web pages and text selections for 60+ languages.
|
||||
|
||||
If the extension does not work after install, restart Microsoft Edge. If the extension still does not work, provide feedback through the Feedback Hub.
|
||||
|
||||
|
@ -41,7 +41,7 @@ If you're having trouble deciding whether Microsoft Edge is right for your organ
|
||||
|
||||
|Microsoft Edge |IE11 |
|
||||
|---------|---------|
|
||||
|Microsoft Edge takes you beyond just browsing to actively engaging with the web through features like Web Note, Reading View, and Cortana.<ul><li>**Web Note.** Microsoft Edge lets you annotate, highlight, and call things out directly on web pages.</li><li>**Reading view.** Microsoft Edge lets you enjoy and print online articles in a distraction-free layout optimized for your screen size. While in reading view, you can also save web pages or PDF files to your reading list, for later viewing.</li><li>**Cortana.** Enabled by default in Microsoft Edge, Cortana lets you highlight words for more info and gives you one-click access to things like restaurant reservations and reviews, without leaving the webpage.</li><li>**Compatibility and security.** Microsoft Edge lets you continue to use IE11 for sites that are on your corporate intranet or that are included on your Enterprise Mode Site List. You must use IE11 to run older, less secure technology, such as ActiveX controls.</li></ul> |IE11 offers enterprises additional security, manageability, performance, backward compatibility, and modern standards support.<ul><li>**Backward compatibility.** IE11 supports 9 document modes that include high-fidelity emulations for older versions of IE.</li><li>**Modern web standards.** IE11 supports modern web technologies like HTML5, CSS3, and WebGL, which help to ensure today's modern websites and apps work just as well as your old, legacy websites and apps.</li><li>**More secure.** IE11 was designed with security in mind and is more secure than older versions. Using security features like SmartScreen and Enhanced Protected Mode can help IE11 reduce your risk.</li><li>**Faster.** IE11 is significantly faster than previous versions of Internet Explorer, taking advantage of network optimization and hardware-accelerated text, graphics, and JavaScript rendering.</li><li>**Easier migration to Windows 10.** IE11 is the only version of IE that runs on Windows 7, Windows 8.1, and Windows 10. Upgrading to IE11 on Windows 7 can also help your organization support the next generation of software, services, and devices.</li><li>**Administration.** IE11 can use the Internet Explorer Administration Kit (IEAK) 11 or MSIs for deployment and includes more than 1,600 Group Policies and preferences for granular control.</li></ul> |
|
||||
|Microsoft Edge takes you beyond just browsing to actively engaging with the web through features like Web Note, Reading View, and Cortana.<ul><li>**Web Note.** Microsoft Edge lets you annotate, highlight, and call things out directly on web pages.</li><li>**Reading view.** Microsoft Edge lets you enjoy and print online articles in a distraction-free layout optimized for your screen size. While in reading view, you can also save web pages or PDF files to your reading list, for later viewing.</li><li>**Cortana.** Enabled by default in Microsoft Edge, Cortana lets you highlight words for more info and gives you one-click access to things like restaurant reservations and reviews, without leaving the webpage.</li><li>**Compatibility and security.** Microsoft Edge lets you continue to use IE11 for sites that are on your corporate intranet or that are included on your Enterprise Mode Site List. You must use IE11 to run older, less secure technology, such as ActiveX controls.</li></ul> |IE11 offers enterprises additional security, manageability, performance, backward compatibility, and modern standards support.<ul><li>**Backward compatibility.** IE11 supports 9 document modes that include high-fidelity emulations for older versions of IE.</li><li>**Modern web standards.** IE11 supports modern web technologies like HTML5, CSS3, and WebGL, which help to ensure today's modern websites and apps work just as well as your old, legacy websites and apps. **IE11 does not support some modern CSS properties, JavaScript modules and certain APIs.**</li><li>**More secure.** IE11 was designed with security in mind and is more secure than older versions. Using security features like SmartScreen and Enhanced Protected Mode can help IE11 reduce your risk.</li><li>**Faster.** IE11 is significantly faster than previous versions of Internet Explorer, taking advantage of network optimization and hardware-accelerated text, graphics, and JavaScript rendering.</li><li>**Easier migration to Windows 10.** IE11 is the only version of IE that runs on Windows 7, Windows 8.1, and Windows 10. Upgrading to IE11 on Windows 7 can also help your organization support the next generation of software, services, and devices.</li><li>**Administration.** IE11 can use the Internet Explorer Administration Kit (IEAK) 11 or MSIs for deployment and includes more than 1,600 Group Policies and preferences for granular control.</li></ul> |
|
||||
|
||||
|
||||
## Configure the Enterprise Mode Site List
|
||||
|
@ -9,7 +9,7 @@ author: eavena
|
||||
---
|
||||
|
||||
Return to: [Browser: Microsoft Edge and Internet Explorer 11](enterprise-guidance-using-microsoft-edge-and-ie11.md)<br>
|
||||
Download image: [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/en-us/download/details.aspx?id=53892)
|
||||
Download image: [Total Economic Impact of Microsoft Edge: Infographic](https://www.microsoft.com/download/details.aspx?id=53892)
|
||||
|
||||

|
||||
|
||||
|
@ -16,7 +16,7 @@ Forrester Research measures the return on investment (ROI) of Microsoft Edge in
|
||||
## Forrester report video summary
|
||||
View a brief overview of the Forrester TEI case study that Microsoft commissioned to examine the value your organization can achieve by utilizing Microsoft Edge:
|
||||
|
||||
> ![VIDEO <https://www.microsoft.com/en-us/videoplayer/embed/RE26zQm>]
|
||||
> ![VIDEO <https://www.microsoft.com/videoplayer/embed/RE26zQm>]
|
||||
|
||||
## Forrester Study report
|
||||
|
||||
|
@ -34,4 +34,4 @@ If you want to deliver applications to users via Citrix through Microsoft Edge,
|
||||
|
||||
## Missing SettingSync.admx and SettingSync.adml files
|
||||
|
||||
Make sure to [download](https://www.microsoft.com/en-us/download/windows.aspx) the latest templates to C:\windows\policydefinitions\.
|
||||
Make sure to [download](https://www.microsoft.com/download/windows.aspx) the latest templates to C:\windows\policydefinitions\.
|
||||
|
@ -24,7 +24,7 @@ ms.topic: include
|
||||
|
||||
- [Web Application Compatibility Lab Kit](https://technet.microsoft.com/microsoft-edge/mt612809.aspx)
|
||||
|
||||
- [Microsoft Services Support](https://www.microsoft.com/en-us/microsoftservices/support.aspx)
|
||||
- [Microsoft Services Support](https://www.microsoft.com/microsoftservices/support.aspx)
|
||||
|
||||
- [Find a Microsoft partner on Pinpoint](https://partnercenter.microsoft.com/pcv/search)
|
||||
|
||||
|
@ -25,7 +25,7 @@ Before you install Internet Explorer 11, you should:
|
||||
|
||||
- **Choose how you'll deploy your installation package.** Your deployment method should be based on whether you're installing to computers already running Windows, or if you're deploying IE11 as part of a Windows installation.
|
||||
|
||||
- **Existing computers running Windows.** Use System Center R2 2012 System Center 2012 R2 Configuration Manager, System Center Essentials 2010, Windows Server Updates Services (WSUS), or Microsoft Intune to deploy IE11. For more information about how to use these systems, see [System Center 2012 R2 Configuration Manager](https://go.microsoft.com/fwlink/p/?LinkID=276664), [System Center Essentials 2010](https://go.microsoft.com/fwlink/p/?LinkId=395200), [Windows Server Update Services](https://go.microsoft.com/fwlink/p/?LinkID=276790), and [Microsoft Intune Overview](https://www.microsoft.com/en-us/cloud-platform/microsoft-intune).
|
||||
- **Existing computers running Windows.** Use System Center R2 2012 System Center 2012 R2 Configuration Manager, System Center Essentials 2010, Windows Server Updates Services (WSUS), or Microsoft Intune to deploy IE11. For more information about how to use these systems, see [System Center 2012 R2 Configuration Manager](https://go.microsoft.com/fwlink/p/?LinkID=276664), [System Center Essentials 2010](https://go.microsoft.com/fwlink/p/?LinkId=395200), [Windows Server Update Services](https://go.microsoft.com/fwlink/p/?LinkID=276790), and [Microsoft Intune Overview](https://www.microsoft.com/cloud-platform/microsoft-intune).
|
||||
|
||||
- **As part of a Windows deployment.** Update your Windows images to include IE11, and then add the update to your MDT deployment share or to your Windows image. For instructions about how to create and use Windows images, see [Create and Manage a Windows Image Using DISM](https://go.microsoft.com/fwlink/p/?LinkId=299408). For general information about deploying IE, see [Microsoft Deployment Toolkit (MDT)](https://go.microsoft.com/fwlink/p/?LinkId=331148), [Windows ADK Overview](https://go.microsoft.com/fwlink/p/?LinkId=276669).
|
||||
|
||||
|
@ -33,7 +33,7 @@ From AGPM you can:
|
||||
- **Manage your GPO lifecycle with change control features.** You can use the available version-control, history, and auditing features to help you manage your GPOs while moving through your archive, to your editing process, and finally to your GPO deployment.
|
||||
|
||||
**Note**<br>
|
||||
For more information about AGPM, and to get the license, see [Advanced Group Policy Management 4.0 Documents](https://www.microsoft.com/en-us/download/details.aspx?id=13975).
|
||||
For more information about AGPM, and to get the license, see [Advanced Group Policy Management 4.0 Documents](https://www.microsoft.com/download/details.aspx?id=13975).
|
||||
|
||||
|
||||
|
||||
|
@ -127,7 +127,7 @@ We recommend that enterprise customers focus their new development on establishe
|
||||
- [Document modes](https://msdn.microsoft.com/library/dn384051(v=vs.85).aspx)
|
||||
- [What is Enterprise Mode?](what-is-enterprise-mode.md)
|
||||
- [Turn on Enterprise Mode and use a site list](turn-on-enterprise-mode-and-use-a-site-list.md)
|
||||
- [Enterprise Site Discovery Toolkit](https://www.microsoft.com/en-us/download/details.aspx?id=44570)
|
||||
- [Enterprise Site Discovery Toolkit](https://www.microsoft.com/download/details.aspx?id=44570)
|
||||
- [Collect data using Enterprise Site Discovery](collect-data-using-enterprise-site-discovery.md)
|
||||
- [Download the Enterprise Mode Site List Manager (schema v.2)](https://go.microsoft.com/fwlink/p/?LinkId=716853)
|
||||
- [Download the Enterprise Mode Site List Manager (schema v.1)](https://go.microsoft.com/fwlink/p/?LinkID=394378)
|
||||
|
@ -163,6 +163,6 @@ Because the tool is open-source, the source code is readily available for examin
|
||||
|
||||
- [Web Application Compatibility Lab Kit](https://technet.microsoft.com/microsoft-edge/mt612809.aspx)
|
||||
|
||||
- [Microsoft Services Support](https://www.microsoft.com/en-us/microsoftservices/support.aspx)
|
||||
- [Microsoft Services Support](https://www.microsoft.com/microsoftservices/support.aspx)
|
||||
|
||||
- [Find a Microsoft partner on Pinpoint](https://partnercenter.microsoft.com/pcv/search)
|
||||
|
@ -35,7 +35,7 @@ Critical cloud services include:
|
||||
- Azure active directory (AAD)
|
||||
- Windows Update (WU)
|
||||
|
||||
Commercial customers will need enterprise mobility management (EMM) or mobile device management (MDM) infrastructure in order to manage HoloLens devices at scale. This guide uses [Microsoft Intune](https://www.microsoft.com/en-us/enterprise-mobility-security/microsoft-intune) as an example though any provider with full support for Microsoft Policy can support HoloLens. Ask your mobile device management provider if they support HoloLens 2.
|
||||
Commercial customers will need enterprise mobility management (EMM) or mobile device management (MDM) infrastructure in order to manage HoloLens devices at scale. This guide uses [Microsoft Intune](https://www.microsoft.com/enterprise-mobility-security/microsoft-intune) as an example though any provider with full support for Microsoft Policy can support HoloLens. Ask your mobile device management provider if they support HoloLens 2.
|
||||
|
||||
HoloLens does support a limited set of cloud disconnected experiences.
|
||||
|
||||
|
@ -21,8 +21,8 @@ ms.sitesec: library
|
||||
Area|HoloLens (1st gen)|HoloLens 2
|
||||
----|:----:|:----:
|
||||
[Azure services](https://status.azure.com/en-us/status)|✔️|✔️
|
||||
[Store app](https://www.microsoft.com/en-us/store/collections/hlgettingstarted/hololens)|✔️|✔️
|
||||
[Apps](https://www.microsoft.com/en-us/hololens/apps)|✔️|✔️
|
||||
[Store app](https://www.microsoft.com/store/collections/hlgettingstarted/hololens)|✔️|✔️
|
||||
[Apps](https://www.microsoft.com/hololens/apps)|✔️|✔️
|
||||
[MDM](https://docs.microsoft.com/en-us/hololens/hololens-enroll-mdm)|✔️|✔️
|
||||
|
||||
## Notes and related topics
|
||||
|
@ -77,7 +77,7 @@ From here on, you'll need to finish the account creation process using PowerShel
|
||||
|
||||
In order to run cmdlets used by these PowerShell scripts, the following must be installed for the admin PowerShell console:
|
||||
|
||||
- [Microsoft Online Services Sign-In Assistant for IT Professionals RTW](https://www.microsoft.com/en-us/download/details.aspx?id=41950)
|
||||
- [Microsoft Online Services Sign-In Assistant for IT Professionals RTW](https://www.microsoft.com/download/details.aspx?id=41950)
|
||||
- [Windows Azure Active Directory Module for Windows PowerShell](https://www.microsoft.com/web/handlers/webpi.ashx/getinstaller/WindowsAzurePowershellGet.3f.3f.3fnew.appids)
|
||||
- [Skype for Business Online, Windows PowerShell Module](https://www.microsoft.com/download/details.aspx?id=39366)
|
||||
|
||||
|
@ -63,10 +63,12 @@ If you have a single-forest on-premises deployment with Microsoft Exchange 2013
|
||||
Once you have a compatible policy, then you will need to apply the policy to the device account. However, policies can only be applied to user accounts and not resource mailboxes. You need to convert the mailbox into a user type, apply the policy, and then convert it back into a mailbox—you may need to re-enable it and set the password again too.
|
||||
|
||||
```PowerShell
|
||||
$acctUpn = Get-Mailbox -Identity "<mailbox identity>"
|
||||
$credNewAccount.Password = ConvertTo-SecureString -String <room mailbox password> -AsPlainText -Force
|
||||
Set-Mailbox $acctUpn -Type Regular
|
||||
Set-CASMailbox $acctUpn -ActiveSyncMailboxPolicy $easPolicy
|
||||
Set-Mailbox $acctUpn -Type Room
|
||||
Set-Mailbox $credNewAccount.UserName -RoomMailboxPassword $credNewAccount.Password -EnableRoomMailboxAccount $true
|
||||
Set-Mailbox $acctUpn -RoomMailboxPassword $credNewAccount.Password -EnableRoomMailboxAccount $true
|
||||
```
|
||||
|
||||
4. Various Exchange properties can be set on the device account to improve the meeting experience for people. You can see which properties need to be set in the [Exchange properties](exchange-properties-for-surface-hub-device-accounts.md) section.
|
||||
|
@ -83,7 +83,7 @@ Set-MsolUserLicense -UserPrincipalName "account@YourDomain.com" -AddLicenses "co
|
||||
### Install prerequisites
|
||||
|
||||
- [Visual C++ 2017 Redistributable](https://aka.ms/vs/15/release/vc_redist.x64.exe)
|
||||
- [Skype for Business Online PowerShell Module](https://www.microsoft.com/en-us/download/confirmation.aspx?id=39366)
|
||||
- [Skype for Business Online PowerShell Module](https://www.microsoft.com/download/confirmation.aspx?id=39366)
|
||||
|
||||
```
|
||||
Import-Module LyncOnlineConnector
|
||||
|
@ -22,7 +22,7 @@ Password-less phone sign-in simplifies signing-in to your meetings and files on
|
||||
|
||||
## To set up password-less phone sign-in
|
||||
|
||||
1. Download the [Microsoft Authenticator](https://www.microsoft.com/en-us/account/authenticator) app for iPhone or Android to your phone.
|
||||
1. Download the [Microsoft Authenticator](https://www.microsoft.com/account/authenticator) app for iPhone or Android to your phone.
|
||||
2. From your PC, go to [https://aka.ms/MFASetup](https://aka.ms/MFASetup) , sign in with your account, and select **Next.**
|
||||
3. In the Additional security verification screen, select Mobile App and Use verification code, and then select **Setup**.
|
||||
|
||||
|
@ -24,6 +24,17 @@ Please refer to the “[Surface Hub Important Information](https://support.micro
|
||||
|
||||
## Windows 10 Team Creators Update 1703
|
||||
|
||||
<details>
|
||||
<summary>August 17, 2019—update for Team edition based on KB4512474* (OS Build 15063.2021)</summary>
|
||||
|
||||
This update to the Surface Hub includes quality improvements and security fixes. Key updates to Surface Hub, not already outlined in [Windows 10 Update History](https://support.microsoft.com/help/4018124/windows-10-update-history), include:
|
||||
|
||||
* Ensures that Video Out on Hub 2S defaults to "Duplicate" mode.
|
||||
|
||||
Please refer to the [Surface Hub Admin guide](https://docs.microsoft.com/surface-hub/) for enabling/disabling device features and services.
|
||||
*[KB4503289](https://support.microsoft.com/help/4503289)
|
||||
</details>
|
||||
|
||||
<details>
|
||||
<summary>June 18, 2019—update for Team edition based on KB4503289* (OS Build 15063.1897)</summary>
|
||||
|
||||
@ -31,6 +42,9 @@ This update to the Surface Hub includes quality improvements and security fixes.
|
||||
|
||||
* Addresses an issue with log collection for Microsoft Surface Hub 2S.
|
||||
* Addresses an issue preventing a user from signing in to a Microsoft Surface Hub device with an Azure Active Directory account. This issue occurs because a previous session did not end successfully.
|
||||
* Adds support for TLS 1.2 connections to identity providers and Exchange in device account setup scenarios.
|
||||
* Fixes to improve reliability of Hardware Diagnostic App on Hub 2S.
|
||||
* Fix to improve consistency of first-run setup experience on Hub 2S.
|
||||
|
||||
Please refer to the [Surface Hub Admin guide](https://docs.microsoft.com/surface-hub/) for enabling/disabling device features and services.
|
||||
*[KB4503289](https://support.microsoft.com/help/4503289)
|
||||
|
@ -29,7 +29,7 @@ for Surface devices. It works on Surface Pro 3 and all newer Surface devices.
|
||||
To run Surface Asset Tag:
|
||||
|
||||
1. On the Surface device, download **Surface Asset Tag.zip** from the [Microsoft Download
|
||||
Center](https://www.microsoft.com/en-us/download/details.aspx?id=46703),
|
||||
Center](https://www.microsoft.com/download/details.aspx?id=46703),
|
||||
extract the zip file, and save AssetTag.exe in desired folder (in
|
||||
this example, C:\\assets).
|
||||
|
||||
|
@ -55,7 +55,7 @@ Before you can perform a deployment with MDT, you must first supply a set of ope
|
||||
|
||||
|
||||
>[!NOTE]
|
||||
>The installation media generated from the [Get Windows 10](https://www.microsoft.com/en-us/software-download/windows10/) page differs from physical media or media downloaded from the VLSC, in that it contains an image file in Electronic Software Download (ESD) format rather than in the Windows Imaging (WIM) format. Installation media with an image file in WIM format is required for use with MDT. Installation media from the Get Windows 10 page cannot be used for Windows deployment with MDT.
|
||||
>The installation media generated from the [Get Windows 10](https://www.microsoft.com/software-download/windows10/) page differs from physical media or media downloaded from the VLSC, in that it contains an image file in Electronic Software Download (ESD) format rather than in the Windows Imaging (WIM) format. Installation media with an image file in WIM format is required for use with MDT. Installation media from the Get Windows 10 page cannot be used for Windows deployment with MDT.
|
||||
|
||||
|
||||
#### Windows Server
|
||||
@ -64,7 +64,7 @@ Although MDT can be installed on a Windows client, to take full advantage of Win
|
||||
|
||||
|
||||
>[!NOTE]
|
||||
>To evaluate the deployment process for Surface devices or to test the deployment process described in this article with the upcoming release of Windows Server 2016, you can download evaluation and preview versions from the [TechNet Evaluation Center](https://www.microsoft.com/en-us/evalcenter).
|
||||
>To evaluate the deployment process for Surface devices or to test the deployment process described in this article with the upcoming release of Windows Server 2016, you can download evaluation and preview versions from the [TechNet Evaluation Center](https://www.microsoft.com/evalcenter).
|
||||
|
||||
|
||||
#### Windows Deployment Services
|
||||
@ -82,7 +82,7 @@ Because customizations are performed by MDT at the time of deployment, the goal
|
||||
|
||||
|
||||
>[!NOTE]
|
||||
>Hyper-V is available not only on Windows Server, but also on Windows clients, including Professional and Enterprise editions of Windows 8, Windows 8.1, and Windows 10. Find out more at [Client Hyper-V on Windows 10](https://msdn.microsoft.com/virtualization/hyperv_on_windows/windows_welcome) and [Client Hyper-V on Windows 8 and Windows 8.1](https://technet.microsoft.com/library/hh857623) in the TechNet Library. Hyper-V is also available as a standalone product, Microsoft Hyper-V Server, at no cost. You can download [Microsoft Hyper-V Server 2012 R2](https://www.microsoft.com/en-us/evalcenter/evaluate-hyper-v-server-2012-r2) or [Microsoft Hyper-V Server 2016 Technical Preview](https://www.microsoft.com/en-us/evalcenter/evaluate-hyper-v-server-technical-preview) from the TechNet Evaluation Center.
|
||||
>Hyper-V is available not only on Windows Server, but also on Windows clients, including Professional and Enterprise editions of Windows 8, Windows 8.1, and Windows 10. Find out more at [Client Hyper-V on Windows 10](https://msdn.microsoft.com/virtualization/hyperv_on_windows/windows_welcome) and [Client Hyper-V on Windows 8 and Windows 8.1](https://technet.microsoft.com/library/hh857623) in the TechNet Library. Hyper-V is also available as a standalone product, Microsoft Hyper-V Server, at no cost. You can download [Microsoft Hyper-V Server 2012 R2](https://www.microsoft.com/evalcenter/evaluate-hyper-v-server-2012-r2) or [Microsoft Hyper-V Server 2016 Technical Preview](https://www.microsoft.com/evalcenter/evaluate-hyper-v-server-technical-preview) from the TechNet Evaluation Center.
|
||||
|
||||
|
||||
#### Surface firmware and drivers
|
||||
|
@ -68,7 +68,7 @@ Some scenarios where Microsoft Surface Data Eraser can be helpful include:
|
||||
|
||||
To create a Microsoft Surface Data Eraser USB stick, first install the Microsoft Surface Data Eraser setup tool from the Microsoft Download Center using the link provided at the beginning of this article. You do not need a Surface device to *create* the USB stick. After you have downloaded the installation file to your computer, follow these steps to install the Microsoft Surface Data Eraser creation tool:
|
||||
|
||||
1. Run the DataEraserSetup.msi installation file that you downloaded from the [Microsoft Download Center](https://www.microsoft.com/en-us/download/details.aspx?id=46703).
|
||||
1. Run the DataEraserSetup.msi installation file that you downloaded from the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=46703).
|
||||
|
||||
2. Select the check box to accept the terms of the license agreement, and then click **Install**.
|
||||
|
||||
|
@ -36,6 +36,6 @@ The diagnosis and repair time averages 15 minutes but could take an hour or long
|
||||
|
||||
If the Surface Diagnostic Toolkit for Business didn’t fix the problem, you can also:
|
||||
|
||||
- Make an in-store appointment: We might be able to fix the problem or provide a replacement Surface at your local Microsoft Store. [Locate a Microsoft Store near you](https://www.microsoft.com/en-us/store/locations/find-a-store?WT.mc_id=MSC_Solutions_en_us_scheduleappt).
|
||||
- Make an in-store appointment: We might be able to fix the problem or provide a replacement Surface at your local Microsoft Store. [Locate a Microsoft Store near you](https://www.microsoft.com/store/locations/find-a-store?WT.mc_id=MSC_Solutions_en_us_scheduleappt).
|
||||
- Contact customer support: If you want to talk to someone about how to fix your problem, [contact us](https://support.microsoft.com/en-us/help/4037645/contact-surface-warranty-and-software-support-for-business).
|
||||
- Get your Surface serviced: If your Surface product needs service, [request it online](https://mybusinessservice.surface.com/).
|
||||
|
@ -226,7 +226,9 @@ create a reset package using PowerShell to reset SEMM.
|
||||
|
||||
## Version History
|
||||
|
||||
|
||||
### Version 2.54.139.0
|
||||
* Support to Surface Hub 2S
|
||||
* Bug fixes
|
||||
|
||||
### Version 2.43.136.0
|
||||
* Support to enable/disable simulatenous multithreating
|
||||
|
@ -52,7 +52,7 @@ You will also need to have available the following resources:
|
||||
* Windows 10 installation files, such as the installation media downloaded from the [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx)
|
||||
|
||||
>[!NOTE]
|
||||
>Installation media for use with MDT must contain a Windows image in Windows Imaging Format (.wim). Installation media produced by the [Get Windows 10](https://www.microsoft.com/en-us/software-download/windows10/) page does not use a .wim file, instead using an Electronic Software Download (.esd) file, which is not compatible with MDT.
|
||||
>Installation media for use with MDT must contain a Windows image in Windows Imaging Format (.wim). Installation media produced by the [Get Windows 10](https://www.microsoft.com/software-download/windows10/) page does not use a .wim file, instead using an Electronic Software Download (.esd) file, which is not compatible with MDT.
|
||||
* [Surface firmware and drivers](https://technet.microsoft.com/itpro/surface/deploy-the-latest-firmware-and-drivers-for-surface-devices) for Windows 10
|
||||
|
||||
* Application installation files for any applications you want to install, such as the Surface app
|
||||
|
@ -44,7 +44,7 @@ Management of SEMM with Configuration Manager requires the installation of Micro
|
||||
|
||||
#### Download SEMM scripts for Configuration Manager
|
||||
|
||||
After Microsoft Surface UEFI Manager is installed on the client Surface device, SEMM is deployed and managed with PowerShell scripts. You can download samples of the [SEMM management scripts](https://www.microsoft.com/en-us/download/details.aspx?id=46703) from the Download Center.
|
||||
After Microsoft Surface UEFI Manager is installed on the client Surface device, SEMM is deployed and managed with PowerShell scripts. You can download samples of the [SEMM management scripts](https://www.microsoft.com/download/details.aspx?id=46703) from the Download Center.
|
||||
|
||||
## Deploy Microsoft Surface UEFI Manager
|
||||
|
||||
@ -378,7 +378,7 @@ The following code fragment, found on lines 380-477, is used to write these regi
|
||||
|
||||
### Settings names and IDs
|
||||
|
||||
To configure Surface UEFI settings or permissions for Surface UEFI settings, you must refer to each setting by either its setting name or setting ID. With each new update for Surface UEFI, new settings may be added. The best way to get a complete list of the settings available on a Surface device, along with the settings name and settings IDs, is to use the ShowSettingsOptions.ps1 script from SEMM_Powershell.zip in [Surface Tools for IT Downloads](https://www.microsoft.com/en-us/download/details.aspx?id=46703)
|
||||
To configure Surface UEFI settings or permissions for Surface UEFI settings, you must refer to each setting by either its setting name or setting ID. With each new update for Surface UEFI, new settings may be added. The best way to get a complete list of the settings available on a Surface device, along with the settings name and settings IDs, is to use the ShowSettingsOptions.ps1 script from SEMM_Powershell.zip in [Surface Tools for IT Downloads](https://www.microsoft.com/download/details.aspx?id=46703)
|
||||
|
||||
The computer where ShowSettingsOptions.ps1 is run must have Microsoft Surface UEFI Manager installed, but the script does not require a Surface device.
|
||||
|
||||
|
@ -19,39 +19,10 @@ Windows Autopilot is a cloud-based deployment technology available in Windows 10
|
||||
|
||||
With Surface devices, you can choose to register your devices at the time of purchase when purchasing from a Surface partner enabled for Windows Autopilot. New devices can be shipped directly to your end-users and will be automatically enrolled and configured when the units are unboxed and turned on for the first time. This process can eliminate need to reimage your devices as part of your deployment process, reducing the work required of your deployment staff and opening up new, agile methods for device management and distribution.
|
||||
|
||||
In this article learn how to enroll your Surface devices in Windows Autopilot with a Surface partner and the options and considerations you will need to know along the way. This article focuses specifically on Surface devices, for more information about using Windows Autopilot with other devices, or to read more about Windows Autopilot and its capabilities, see [Overview of Windows Autopilot](https://docs.microsoft.com/windows/deployment/windows-autopilot/windows-10-autopilot) in the Windows Docs Library.
|
||||
|
||||
## Prerequisites
|
||||
Enrollment of Surface devices in Windows Autopilot with a Surface partner enabled for Windows Autopilot has the following licensing requirements for each enrolled Surface device:
|
||||
* **Azure Active Directory Premium** – Required to enroll your devices in your organization and to automatically enroll devices in your organization’s mobile management solution.
|
||||
* **Mobile Device Management (such as Microsoft Intune)** – Required to remotely deploy applications, configure, and manage your enrolled devices.
|
||||
* **Office 365 ProPlus** – Required to deploy Microsoft Office to your enrolled devices.
|
||||
|
||||
These requirements are also met by the following solutions:
|
||||
* Microsoft 365 E3 or E5 (includes Azure Active Directory Premium, Microsoft Intune, and Office 365 ProPlus)
|
||||
|
||||
Or
|
||||
* Enterprise Mobility + Security E3 or E5 (includes Azure Active Directory Premium and Microsoft Intune)
|
||||
* Office 365 ProPlus, E3, or E5 (includes Office 365 ProPlus)
|
||||
|
||||
>[!NOTE]
|
||||
>Deployment of devices using Windows Autopilot to complete the Out-of-Box Experience (OOBE) is supported without these prerequisites, however will yield deployed devices without applications, configuration, or enrollment in a management solution and is highly discouraged.
|
||||
In this article learn how to enroll your Surface devices in Windows Autopilot with a Surface partner and the options and considerations you will need to know along the way. This article focuses specifically on Surface devices, for more information about using Windows Autopilot with other devices, or to read more about Windows Autopilot and its capabilities, see [Overview of Windows Autopilot](https://docs.microsoft.com/windows/deployment/windows-autopilot/windows-10-autopilot) in the Windows Docs Library. For information about licensing and other prerequisites, see [Windows Autopilot requirements](https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-autopilot-requirements).
|
||||
|
||||
### Windows version considerations
|
||||
Support for broad deployments of Surface devices using Windows Autopilot, including enrollment performed by Surface partners at the time of purchase, requires devices manufactured with or otherwise installed with Windows 10 Version 1709 (Fall Creators Update). Windows 10 Version 1709 uses a secure 4096-bit (4k) hash value to uniquely identify devices for Windows Autopilot that is necessary for deployments at scale.
|
||||
|
||||
### Surface device support
|
||||
Surface devices with support for out-of-box deployment with Windows Autopilot, enrolled during the purchase process with a Surface partner, include the following devices, where the devices ship from the factory with Windows 10 Version 1709:
|
||||
|
||||
* Surface Pro (5th gen)
|
||||
* Surface Laptop(1st gen)
|
||||
* Surface Studio (1st gen)
|
||||
* Surface Pro 6
|
||||
* Surface Book 2
|
||||
* Surface Laptop 2
|
||||
* Surface Studio 2
|
||||
* Surface Go
|
||||
* Surface Go with LTE Advanced
|
||||
Support for broad deployments of Surface devices using Windows Autopilot, including enrollment performed by Surface partners at the time of purchase, requires devices manufactured with or otherwise installed with Windows 10 Version 1709 (Fall Creators Update) or later. These versions support a 4000-byte (4k) hash value to uniquely identify devices for Windows Autopilot that is necessary for deployments at scale. All new Surface devices ship with Windows 10 Version 1709 or above.
|
||||
|
||||
## Surface partners enabled for Windows Autopilot
|
||||
Enrolling Surface devices in Windows Autopilot at the time of purchase is a capability provided by select Surface partners that are enabled with the capability to identify individual Surface devices during the purchase process and perform enrollment on an organization’s behalf. Devices enrolled by a Surface partner at time of purchase can be shipped directly to users and configured entirely through the zero-touch process of Windows Autopilot, Azure Active Directory, and Mobile Device Management.
|
||||
@ -63,4 +34,3 @@ When you purchase Surface devices from a Surface partner enabled for Windows Aut
|
||||
- [Insight](https://www.insight.com/en_US/buy/partner/microsoft/surface/windows-autopilot.html)
|
||||
- [SHI](https://www.shi.com/Surface)
|
||||
|
||||
|
||||
|
@ -26,7 +26,7 @@ ms.prod: w10
|
||||
</div>
|
||||
</li>
|
||||
<li>
|
||||
<a href="https://www.microsoft.com/en-us/education/itdm/default.aspx" target="_blank">
|
||||
<a href="https://www.microsoft.com/education/itdm/default.aspx" target="_blank">
|
||||
<div class="cardSize">
|
||||
<div class="cardPadding">
|
||||
<div class="card">
|
||||
|
@ -339,7 +339,7 @@ For more information about checking for updates, and how to optionally turn on a
|
||||
## Get more info
|
||||
* Learn more at <a href="https://www.microsoft.com/education" target="_blank">microsoft.com/education</a>
|
||||
* Find out if your school is eligible for a device trial at <a href="https://aka.ms/EDUTrialInABox" target="_blank">aka.ms/EDUTrialInABox</a>
|
||||
* <a href="https://www.microsoft.com/en-us/education/devices/default.aspx" target="_blank">Buy Windows 10 devices</a>
|
||||
* <a href="https://www.microsoft.com/education/devices/default.aspx" target="_blank">Buy Windows 10 devices</a>
|
||||
|
||||
<br/>
|
||||
<br/>
|
||||
|
@ -278,4 +278,4 @@ For more information about checking for updates, and how to optionally turn on a
|
||||
## Get more info
|
||||
* Learn more at <a href="https://www.microsoft.com/education" target="_blank">microsoft.com/education</a>
|
||||
* Find out if your school is eligible for a device trial at <a href="https://aka.ms/EDUTrialInABox" target="_blank">aka.ms/EDUTrialInABox</a>
|
||||
* <a href="https://www.microsoft.com/en-us/education/devices/default.aspx" target="_blank">Buy Windows 10 devices</a>
|
||||
* <a href="https://www.microsoft.com/education/devices/default.aspx" target="_blank">Buy Windows 10 devices</a>
|
||||
|
@ -37,7 +37,7 @@ Before you change to Windows 10 Pro Education, make sure you meet these requirem
|
||||
- The user making the changes must be a member of the Azure AD global administrator group.
|
||||
|
||||
## Compare Windows 10 Pro and Pro Education editions
|
||||
You can [compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare) to find out more about the features we support in other editions of Windows 10.
|
||||
You can [compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare) to find out more about the features we support in other editions of Windows 10.
|
||||
|
||||
For more info about Windows 10 default settings and recommendations for education customers, see [Windows 10 configuration recommendations for education customers](configure-windows-for-education.md).
|
||||
|
||||
@ -314,6 +314,6 @@ For more information about integrating on-premises AD DS domains with Azure AD,
|
||||
|
||||
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)
|
||||
[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md)
|
||||
[Compare Windows 10 editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare)
|
||||
[Compare Windows 10 editions](https://www.microsoft.com/WindowsForBusiness/Compare)
|
||||
[Windows 10 subscription activation](https://docs.microsoft.com/windows/deployment/windows-10-subscription-activation)
|
||||
|
||||
|
@ -26,7 +26,7 @@ This guide shows you how to deploy the Windows 10 operating system in a school d
|
||||
|
||||
Proper preparation is essential for a successful district deployment. To avoid common mistakes, your first step is to plan a typical district configuration. Just as with building a house, you need a blueprint for what your district and individual schools should look like when it’s finished. The second step in preparation is to learn how you will manage the users, apps, and devices in your district. Just as a builder needs to have the right tools to build a house, you need the right set of tools to deploy your district.
|
||||
|
||||
>**Note** This guide focuses on Windows 10 deployment and management in a district. For management of other devices and operating systems in education environments, see [Manage BYOD and corporate-owned devices with MDM solutions](https://www.microsoft.com/en-us/cloud-platform/mobile-device-management).
|
||||
>**Note** This guide focuses on Windows 10 deployment and management in a district. For management of other devices and operating systems in education environments, see [Manage BYOD and corporate-owned devices with MDM solutions](https://www.microsoft.com/cloud-platform/mobile-device-management).
|
||||
|
||||
### Plan a typical district configuration
|
||||
|
||||
@ -115,7 +115,7 @@ The configuration process requires the following devices:
|
||||
|
||||
* **Admin device.** This is the device you use for your day-to-day job functions. It’s also the one you use to create and manage the Windows 10 and app deployment process. You install the Windows ADK, MDT, and the System Center Configuration Manager Console on this device.
|
||||
* **Reference devices.** These are the devices that you will use as a template for the faculty and student devices. You install Windows 10 and Windows desktop apps on these devices, and then capture an image (.wim file) of the devices.
|
||||
You will have a reference device for each type of device in your district. For example, if your district has Surface, HP Stream, Dell Inspiron, and Lenovo Yoga devices, then you would have a reference device for each model. For more information about approved Windows 10 devices, see [Explore devices](https://www.microsoft.com/en-us/windows/view-all).
|
||||
You will have a reference device for each type of device in your district. For example, if your district has Surface, HP Stream, Dell Inspiron, and Lenovo Yoga devices, then you would have a reference device for each model. For more information about approved Windows 10 devices, see [Explore devices](https://www.microsoft.com/windows/view-all).
|
||||
* **Faculty and staff devices.** These are the devices that the teachers, faculty, and staff use for their day-to-day job functions. You use the admin device to deploy (or upgrade) Windows 10 and apps to these devices.
|
||||
* **Student devices.** The students will use these devices. You will use the admin device deploy (or upgrade) Windows 10 and apps to them.
|
||||
|
||||
@ -550,7 +550,7 @@ In this section, you installed the Windows ADK and MDT on the admin device. You
|
||||
|
||||
Office 365 is one of the core components of your classroom environment. You create and manage student identities in Office 365, and students and teachers use the suite as their email, contacts, and calendar system. They also use Office 365 collaboration features such as SharePoint, OneNote, and OneDrive for Business.
|
||||
|
||||
As a first step in deploying your classroom, create an Office 365 Education subscription, and then configure Office 365 for the classroom. For more information about Office 365 Education deployment, see [School deployment of Office 365 Education](https://www.microsoft.com/en-us/education/products/office-365-deployment-resources/default.aspx).
|
||||
As a first step in deploying your classroom, create an Office 365 Education subscription, and then configure Office 365 for the classroom. For more information about Office 365 Education deployment, see [School deployment of Office 365 Education](https://www.microsoft.com/education/products/office-365-deployment-resources/default.aspx).
|
||||
|
||||
### Select the appropriate Office 365 Education license plan
|
||||
|
||||
@ -991,7 +991,7 @@ Depending on your school’s requirements, you may need any combination of the f
|
||||
|
||||
>**Note** Although you can use Windows 10 Home on institution-owned devices, Microsoft recommends that you use Windows 10 Pro or Windows 10 Education, instead. Windows 10 Pro and Windows 10 Education provide support for MDM, policy-based management, and Microsoft Store for Business—features not available in Windows 10 Home. For more information about how to upgrade Windows 10 Home to Windows 10 Pro or Windows 10 Education, see [Windows 10 edition upgrade](https://technet.microsoft.com/itpro/windows/deploy/windows-10-edition-upgrades).
|
||||
|
||||
For more information about the Windows 10 editions, see [Compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare).
|
||||
For more information about the Windows 10 editions, see [Compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare).
|
||||
|
||||
One other consideration is the mix of processor architectures you will support. If you can, support only 64-bit versions of Windows 10. If you have devices that can run only 32-bit versions of Windows 10, you will need to import both 64-bit and 32-bit versions of the Windows 10 editions listed above.
|
||||
|
||||
|
@ -164,7 +164,7 @@ In this section, you installed the Windows ADK and MDT on the admin device. You
|
||||
|
||||
Office 365 is one of the core components of your classroom environment. You create and manage student identities in Office 365, and students and teachers use the suite as their email, contacts, and calendar system. Teachers and students use Office 365 collaboration features such as SharePoint, OneNote, and OneDrive for Business.
|
||||
|
||||
As a first step in deploying your classroom, create an Office 365 Education subscription, and then configure Office 365 for the classroom. For more information about Office 365 Education deployment, see [School deployment of Office 365 Education](https://www.microsoft.com/en-us/education/products/office-365-deployment-resources/default.aspx).
|
||||
As a first step in deploying your classroom, create an Office 365 Education subscription, and then configure Office 365 for the classroom. For more information about Office 365 Education deployment, see [School deployment of Office 365 Education](https://www.microsoft.com/education/products/office-365-deployment-resources/default.aspx).
|
||||
|
||||
### Select the appropriate Office 365 Education license plan
|
||||
|
||||
|
@ -19,8 +19,8 @@ ms.date: 10/13/2017
|
||||
##  Learn
|
||||
|
||||
<p><b><a href="windows-editions-for-education-customers.md" data-raw-source="[Windows 10 editions for education customers](windows-editions-for-education-customers.md)">Windows 10 editions for education customers</a></b><br />Windows 10, version 1607 introduces two editions designed for the unique needs of K-12 institutions: Windows 10 Pro Education and Windows 10 Education. These editions provide education-specific default settings for the evolving landscape in K-12 education IT environments.</p>
|
||||
<p><b><a href="https://www.microsoft.com/en-us/WindowsForBusiness/Compare" data-raw-source="[Compare each Windows edition](https://www.microsoft.com/en-us/WindowsForBusiness/Compare)">Compare each Windows edition</a></b><br />Find out more about the features and functionality we support in each edition of Windows.</p>
|
||||
<p><b><a href="https://www.microsoft.com/en-us/education/buy-license/overview-of-how-to-buy/default.aspx?tabshow=schools" data-raw-source="[Get Windows 10 Education or Windows 10 Pro Education](https://www.microsoft.com/en-us/education/buy-license/overview-of-how-to-buy/default.aspx?tabshow=schools)">Get Windows 10 Education or Windows 10 Pro Education</a></b><br />When you've made your decision, find out how to buy Windows for your school.</p>
|
||||
<p><b><a href="https://www.microsoft.com/WindowsForBusiness/Compare" data-raw-source="[Compare each Windows edition](https://www.microsoft.com/WindowsForBusiness/Compare)">Compare each Windows edition</a></b><br />Find out more about the features and functionality we support in each edition of Windows.</p>
|
||||
<p><b><a href="https://www.microsoft.com/education/buy-license/overview-of-how-to-buy/default.aspx?tabshow=schools" data-raw-source="[Get Windows 10 Education or Windows 10 Pro Education](https://www.microsoft.com/education/buy-license/overview-of-how-to-buy/default.aspx?tabshow=schools)">Get Windows 10 Education or Windows 10 Pro Education</a></b><br />When you've made your decision, find out how to buy Windows for your school.</p>
|
||||
|
||||
##  Plan
|
||||
|
||||
|
@ -71,4 +71,4 @@ Tenant-wide Windows 10 Pro > Pro Education
|
||||
[FAQs](https://support.microsoft.com/help/4020089/windows-10-in-s-mode-faq)<br>
|
||||
[Deploy Windows 10 in a school](deploy-windows-10-in-a-school.md)<BR>
|
||||
[Deploy Windows 10 in a school district](deploy-windows-10-in-a-school-district.md) <BR>
|
||||
[Compare Windows 10 editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare)
|
||||
[Compare Windows 10 editions](https://www.microsoft.com/WindowsForBusiness/Compare)
|
||||
|
@ -51,7 +51,7 @@ Due to these reasons, we recommend that you use the installation tool and avoid
|
||||
Before you install Windows 10 in S mode on your existing Windows 10 Pro, Windows 10 Pro Education, Windows 10 Education, or Windows 10 Enterprise device:
|
||||
* Make sure that you updated your existing device to Windows 10, version 1703 (Creators Update).
|
||||
|
||||
See [Download Windows 10](https://www.microsoft.com/en-us/software-download/windows10) and follow the instructions to update your device to Windows 10, version 1703. You can verify your current version in **Settings > System > About**.
|
||||
See [Download Windows 10](https://www.microsoft.com/software-download/windows10) and follow the instructions to update your device to Windows 10, version 1703. You can verify your current version in **Settings > System > About**.
|
||||
|
||||
* Install the latest Windows Update.
|
||||
|
||||
@ -184,7 +184,7 @@ If you see this message, follow these steps to stop receiving the message:
|
||||
|
||||
To use an installation media to reinstall Windows 10, follow these steps.
|
||||
|
||||
1. On a working PC, go to the [Microsoft software download website](https://www.microsoft.com/en-us/software-download/windows10).
|
||||
1. On a working PC, go to the [Microsoft software download website](https://www.microsoft.com/software-download/windows10).
|
||||
2. Download the Media Creation Tool and then run it.
|
||||
3. Select **Create installation media for another PC**.
|
||||
4. Choose a language, edition, and architecture (64-bit or 32-bit).
|
||||
|
@ -30,7 +30,7 @@ AGPM 4.0 SP3 adds support for the Windows 10 and Windows Server 2016 operating
|
||||
|
||||
### Support for PowerShell
|
||||
|
||||
AGPM 4.0 SP3 adds support for PowerShell cmdlets. For a list of the cmdlets available in AGPM 4.0 SP3, including descriptions and syntax, see [Microsoft Desktop Optimization Pack Automation with Windows PowerShell](https://technet.microsoft.com/library/dn520245.aspx).
|
||||
AGPM 4.0 SP3 adds support for PowerShell cmdlets. For a list of the cmdlets available in AGPM 4.0 SP3, including descriptions and syntax, see [Microsoft Desktop Optimization Pack Automation with Windows PowerShell](https://docs.microsoft.com/powershell/mdop/get-started?view=win-mdop2-ps).
|
||||
|
||||
### Customer feedback and hotfix rollup
|
||||
|
||||
|
@ -19,7 +19,7 @@ author: shortpatti
|
||||
This topic describes the process for applying the hotfixes for Microsoft BitLocker Administration and Monitoring (MBAM) Server 2.5 SP1
|
||||
|
||||
### Before you begin, download the latest hotfix of Microsoft BitLocker Administration and Monitoring (MBAM) Server 2.5 SP1
|
||||
[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=58345)
|
||||
[Desktop Optimization Pack](https://www.microsoft.com/download/details.aspx?id=58345)
|
||||
|
||||
#### Steps to update the MBAM Server for existing MBAM environment
|
||||
1. Remove MBAM server feature (do this by opening the MBAM Server Configuration Tool, then selecting Remove Features).
|
||||
|
@ -26,7 +26,7 @@ MDOP Group Policy templates are available for download in a self-extracting, com
|
||||
|
||||
**How to download and deploy the MDOP Group Policy templates**
|
||||
|
||||
1. Download the MDOP Group Policy templates from [Microsoft Desktop Optimization Pack Group Policy Administrative Templates](https://www.microsoft.com/en-us/download/details.aspx?id=55531).
|
||||
1. Download the MDOP Group Policy templates from [Microsoft Desktop Optimization Pack Group Policy Administrative Templates](https://www.microsoft.com/download/details.aspx?id=55531).
|
||||
|
||||
2. Run the downloaded file to extract the template folders.
|
||||
|
||||
|
@ -352,7 +352,7 @@ You must install SQL Server with the **SQL\_Latin1\_General\_CP1\_CI\_AS** colla
|
||||
<td align="left"><p>Microsoft SQL Server 2016</p></td>
|
||||
<td align="left"><p>Standard, Enterprise, or Datacenter</p></td>
|
||||
<td align="left"><p>SP1</p></td>
|
||||
<a href="https://www.microsoft.com/en-us/download/details.aspx?id=54967" data-raw-source="https://www.microsoft.com/en-us/download/details.aspx?id=54967">https://www.microsoft.com/en-us/download/details.aspx?id=54967</a><td align="left"><p>64-bit</p></td>
|
||||
<a href="https://www.microsoft.com/download/details.aspx?id=54967" data-raw-source="https://www.microsoft.com/download/details.aspx?id=54967">https://www.microsoft.com/download/details.aspx?id=54967</a><td align="left"><p>64-bit</p></td>
|
||||
<tr class="odd">
|
||||
<td align="left"><p>Microsoft SQL Server 2014</p></td>
|
||||
<td align="left"><p>Standard, Enterprise, or Datacenter</p></td>
|
||||
@ -373,7 +373,7 @@ You must install SQL Server with the **SQL\_Latin1\_General\_CP1\_CI\_AS** colla
|
||||
</table>
|
||||
|
||||
**Note**
|
||||
In order to support SQL 2016 you must install the March 2017 Servicing Release for MDOP https://www.microsoft.com/en-us/download/details.aspx?id=54967 and to support SQL 2017 you must install the July 2018 Servicing Release for MDOP https://www.microsoft.com/en-us/download/details.aspx?id=57157. In general stay current by always using the most recent servicing update as it also includes all bugfixes and new features.
|
||||
In order to support SQL 2016 you must install the March 2017 Servicing Release for MDOP https://www.microsoft.com/download/details.aspx?id=54967 and to support SQL 2017 you must install the July 2018 Servicing Release for MDOP https://www.microsoft.com/download/details.aspx?id=57157. In general stay current by always using the most recent servicing update as it also includes all bugfixes and new features.
|
||||
|
||||
|
||||
### <a href="" id="bkmk-sql-stand-alone-ramreqs"></a>SQL Server processor, RAM, and disk space requirements – Stand-alone topology
|
||||
|
49
mdop/mbam-v25/upgrade-mbam2.5-sp1.md
Normal file
49
mdop/mbam-v25/upgrade-mbam2.5-sp1.md
Normal file
@ -0,0 +1,49 @@
|
||||
---
|
||||
title: Upgrading from MBAM 2.5 to MBAM 2.5 SP1 Servicing Release Update
|
||||
author: TobyTu
|
||||
ms.author: ksharma
|
||||
manager: dcscontentpm
|
||||
audience: ITPro
|
||||
ms.topic: article
|
||||
ms.prod: mbam
|
||||
localization_priority: Normal
|
||||
---
|
||||
|
||||
# Upgrading from MBAM 2.5 to MBAM 2.5 SP1 Servicing Release Update
|
||||
|
||||
This article provides step-by-step instructions for upgrading Microsoft BitLocker Administration and Monitoring (MBAM) 2.5 to MBAM 2.5 SP1 along with Microsoft Desktop Optimization Pack (MDOP) July 2018 Servicing update in a stand-alone configuration. In this guide we will use a two-server configuration. One of the two servers will be a database server that's running Microsoft SQL Server 2016. This server will host the MBAM databases and reports. The additional server will be a Windows Server 2012 R2 web server and will host "Administration and Monitoring Server" and "Self-Service Portal."
|
||||
|
||||
## Preparation steps before you upgrade MBAM 2.5 SP1 server
|
||||
|
||||
### Know the MBAM Servers in your environment
|
||||
|
||||
1. SQL Server Database Engine: Server Hosting the MBAM Databases.
|
||||
2. SQL Server Reporting Services: Server Hosting the MBAM Reports.
|
||||
3. Internet Information Services (IIS) Web Servers: Server Hosting MBAM Web Applications and Services.
|
||||
4. (Optional) Microsoft System Center Configuration Manager (SCCM) Primary Site Server: MBAM Configuration Application is run on this server to integrate MBAM Repots with SCCM which are then merged with existing SCCM reports on the SCCM’s SQL Server Reporting Services (SSRS) instance.
|
||||
|
||||
### Identify Service Accounts, Groups, Server Name and Reports URL
|
||||
|
||||
1. Identify the MBAM App Pool Svc Account used by IIS web servers to Read and Write Data to MBAM Databases.
|
||||
2. Identify the Groups used during MBAM Web Features Configuration and the Reports Web Service URL.
|
||||
3. Identify the SQL Server Name and Instance Name.
|
||||
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RE3ANP1]
|
||||
4. Identify the SQL Server Reporting Services Account used for reading compliance data from Compliance and Audit Database.
|
||||
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RE3ALdZ]
|
||||
|
||||
## Upgrade the MBAM Infrastructure to the latest version available
|
||||
|
||||
> [!NOTE]
|
||||
> We recommend that you take a full database backup of the MBAM Databases before performing upgrades.
|
||||
|
||||
### Upgrade the MBAM SQL Server
|
||||
|
||||
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RE3ALew]
|
||||
|
||||
### Upgrade MBAM Web Server
|
||||
|
||||
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RE3ALex]
|
||||
|
||||
## More information
|
||||
|
||||
For more about MBAM 2.5 SP1 known issues, please refer [Release Notes for MBAM 2.5 SP1](https://docs.microsoft.com/microsoft-desktop-optimization-pack/mbam-v25/release-notes-for-mbam-25-sp1).
|
@ -23,7 +23,7 @@ You can manage the feature settings of certain Microsoft Desktop Optimization Pa
|
||||
|
||||
**How to download and deploy the MDOP Group Policy templates**
|
||||
|
||||
1. Download the latest [MDOP Group Policy templates](https://www.microsoft.com/en-us/download/details.aspx?id=55531)
|
||||
1. Download the latest [MDOP Group Policy templates](https://www.microsoft.com/download/details.aspx?id=55531)
|
||||
|
||||
2. Expand the downloaded .cab file by running `expand <download_folder>\MDOP_ADMX_Templates.cab -F:* <destination_folder>`
|
||||
|
||||
|
@ -31,7 +31,7 @@ ADMX files can be installed and tested locally on any computer that runs the Win
|
||||
|
||||
**To download the UE-V ADMX templates**
|
||||
|
||||
1. Download the UE-V ADMX template files: <https://www.microsoft.com/en-us/download/details.aspx?id=55531>.
|
||||
1. Download the UE-V ADMX template files: <https://www.microsoft.com/download/details.aspx?id=55531>.
|
||||
|
||||
2. For more information about how to deploy the Group Policy templates, see <https://go.microsoft.com/fwlink/p/?LinkId=393944>.
|
||||
|
||||
|
@ -114,7 +114,7 @@ Before you proceed, make sure your environment includes these requirements for r
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
**Note:** Starting with Windows 10, version 1607, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/en-us/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack
|
||||
**Note:** Starting with Windows 10, version 1607, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack
|
||||
|
||||
Also…
|
||||
|
||||
|
@ -710,7 +710,7 @@ Also…
|
||||
|
||||
**Note**
|
||||
|
||||
- Starting with WIndows 10, version 1607, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/en-us/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
- Starting with WIndows 10, version 1607, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
|
||||
- The UE-V Windows PowerShell feature of the UE-V Agent requires .NET Framework 4 or higher and Windows PowerShell 3.0 or higher to be enabled. Download Windows PowerShell 3.0 [here](https://go.microsoft.com/fwlink/?LinkId=309609).
|
||||
|
||||
|
@ -23,7 +23,7 @@ Windows Autopilot simplifies device set up for IT Admins. For an overview of ben
|
||||
|
||||
Watch this video to learn more about Windows Autopilot in Microsoft Store for Business. </br>
|
||||
|
||||
> [!video https://www.microsoft.com/en-us/videoplayer/embed/3b30f2c2-a3e2-4778-aa92-f65dbc3ecf54?autoplay=false]
|
||||
> [!video https://www.microsoft.com/videoplayer/embed/3b30f2c2-a3e2-4778-aa92-f65dbc3ecf54?autoplay=false]
|
||||
|
||||
## What is Windows Autopilot?
|
||||
In Microsoft Store for Business, you can manage devices for your organization and apply an *Autopilot deployment profile* to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows based on the Autopilot deployment profile you applied to the device.
|
||||
|
@ -42,7 +42,7 @@ Previous versions of App-V have required you to manually remove your unpublished
|
||||
|
||||
### App-V is now a feature in Windows 10
|
||||
|
||||
With Windows 10, version 1607 and later releases, App-V is now included with [Windows 10 for Enterprise and Windows 10 for Education](https://www.microsoft.com/en-us/WindowsForBusiness/windows-product-home) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
With Windows 10, version 1607 and later releases, App-V is now included with [Windows 10 for Enterprise and Windows 10 for Education](https://www.microsoft.com/WindowsForBusiness/windows-product-home) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
|
||||
To learn more about earlier versions of App-V, see [MDOP Information Experience](https://docs.microsoft.com/microsoft-desktop-optimization-pack/index).
|
||||
|
||||
|
@ -346,7 +346,7 @@ This process will recreate both the local and network locations for AppData and
|
||||
|
||||
In an App-V Full Infrastructure, after applications are sequenced they are managed and published to users or computers through the App-V Management and Publishing servers. This section details the operations that occur during the common App-V application lifecycle operations (Add, publishing, launch, upgrade, and removal) and the file and registry locations that are changed and modified from the App-V Client perspective. The App-V Client operations are input as PowerShell commands on the computer running the App-V Client.
|
||||
|
||||
This document focuses on App-V Full Infrastructure solutions. For specific information on App-V Integration with Configuration Manager 2012, see [Integrating Virtual Application Management with App-V 5 and Configuration Manager 2012 SP1](https://www.microsoft.com/en-us/download/details.aspx?id=38177).
|
||||
This document focuses on App-V Full Infrastructure solutions. For specific information on App-V Integration with Configuration Manager 2012, see [Integrating Virtual Application Management with App-V 5 and Configuration Manager 2012 SP1](https://www.microsoft.com/download/details.aspx?id=38177).
|
||||
|
||||
The App-V application lifecycle tasks are triggered at user sign in (default), machine startup, or as background timed operations. The settings for the App-V Client operations, including Publishing Servers, refresh intervals, package script enablement, and others, are configured (after the client is enabled) with Windows PowerShell commands. See [App-V Client Configuration Settings: Windows PowerShell](appv-client-configuration-settings.md#app-v-client-configuration-settings-windows-powershell).
|
||||
|
||||
@ -799,7 +799,7 @@ App-V packages contain the Manifest file inside of the App-V Package file, which
|
||||
|
||||
### Examples of dynamic configuration files
|
||||
|
||||
The following example shows the combination of the Manifest, Deployment Configuration, and User Configuration files after publishing and during normal operation. These examples are abbreviated examples of each of the files. The purpose is show the combination of the files only, not to be a complete description of the specific categories available in each file. For more information, download the [App-V Sequencing Guide](https://www.microsoft.com/en-us/download/details.aspx?id=27760).
|
||||
The following example shows the combination of the Manifest, Deployment Configuration, and User Configuration files after publishing and during normal operation. These examples are abbreviated examples of each of the files. The purpose is show the combination of the files only, not to be a complete description of the specific categories available in each file. For more information, download the [App-V Sequencing Guide](https://www.microsoft.com/download/details.aspx?id=27760).
|
||||
|
||||
#### Manifest
|
||||
|
||||
|
@ -62,5 +62,5 @@ Using Group Policy, you can turn on the **Enable automatic cleanup of unused App
|
||||
## Related topics
|
||||
|
||||
- [Download the Windows ADK](https://developer.microsoft.com/windows/hardware/windows-assessment-deployment-kit)
|
||||
- [Download the Microsoft Application Virtualization 5.0 Client UI Application](https://www.microsoft.com/en-us/download/details.aspx?id=41186)
|
||||
- [Download the Microsoft Application Virtualization 5.0 Client UI Application](https://www.microsoft.com/download/details.aspx?id=41186)
|
||||
- [Using the App-V Client Management Console](appv-using-the-client-management-console.md)
|
||||
|
@ -32,7 +32,7 @@ ms.topic: article
|
||||
1. Download the App-V server components. All five App-V server components are included in the Microsoft Desktop Optimization Pack (MDOP) 2015 ISO package, which can be downloaded from either of the following locations:
|
||||
|
||||
* The [MSDN (Microsoft Developer Network) subscriptions site](https://msdn.microsoft.com/subscriptions/downloads/default.aspx#FileId=65215). You must have a MSDN subscription to download the MDOP ISO package from this site.
|
||||
* The [Volume Licensing Service Center](https://www.microsoft.com/en-us/licensing/default.aspx) if you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/en-us/WindowsForBusiness/windows-product-home).
|
||||
* The [Volume Licensing Service Center](https://www.microsoft.com/licensing/default.aspx) if you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/WindowsForBusiness/windows-product-home).
|
||||
2. Copy the App-V server installation files to the computer on which you want to install it.
|
||||
3. Start the App-V server installation by right-clicking and running **appv\_server\_setup.exe** as an administrator, and then click **Install**.
|
||||
4. Review and accept the license terms, and choose whether to enable Microsoft updates.
|
||||
|
@ -86,7 +86,7 @@ The following table provides a full list of supported integration points for Off
|
||||
|
||||
### Office 2010 App-V Packages
|
||||
|
||||
* [Microsoft Office 2010 Sequencing Kit for Microsoft Application Virtualization 5.0](https://www.microsoft.com/en-us/download/details.aspx?id=38399)
|
||||
* [Microsoft Office 2010 Sequencing Kit for Microsoft Application Virtualization 5.0](https://www.microsoft.com/download/details.aspx?id=38399)
|
||||
* [Known issues when you create or use an App-V 5.0 Office 2010 package](https://support.microsoft.com/kb/2828619)
|
||||
* [How To Sequence Microsoft Office 2010 in Microsoft Application Virtualization 5.0](https://support.microsoft.com/kb/2830069)
|
||||
|
||||
|
@ -30,7 +30,7 @@ To learn how to configure the App-V client to enable only administrators to publ
|
||||
|
||||
## Related topics
|
||||
|
||||
- [App-V and Citrix integration](https://www.microsoft.com/en-us/download/details.aspx?id=40885)
|
||||
- [App-V and Citrix integration](https://www.microsoft.com/download/details.aspx?id=40885)
|
||||
- [Operations for App-V](appv-operations.md)
|
||||
|
||||
|
||||
|
@ -45,7 +45,7 @@ App-V offers the following five server components, each of which serves a specif
|
||||
All five App-V server components are included in the Microsoft Desktop Optimization Pack (MDOP) 2015 ISO package, which can be downloaded from either of the following locations:
|
||||
|
||||
* The [MSDN (Microsoft Developer Network) subscriptions site](https://msdn.microsoft.com/subscriptions/downloads/default.aspx#FileId=65215). You must have a MSDN subscription to download the MDOP ISO package from this site.
|
||||
* The [Volume Licensing Service Center](https://www.microsoft.com/en-us/licensing/default.aspx) if you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/en-us/WindowsForBusiness/windows-product-home).
|
||||
* The [Volume Licensing Service Center](https://www.microsoft.com/licensing/default.aspx) if you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/WindowsForBusiness/windows-product-home).
|
||||
|
||||
In large organizations, you might want to install more than one instance of the server components to get the following benefits.
|
||||
|
||||
|
@ -18,7 +18,7 @@ ms.topic: article
|
||||
|
||||
Microsoft Application Virtualization (App-V) for Windows 10 delivers Win32 applications to users as virtual applications. Virtual applications are installed on centrally managed servers and delivered to users as a service in real time and on an as-needed basis. Users launch virtual applications from familiar access points and interact with them as if they were installed locally.
|
||||
|
||||
With the release of Windows 10, version 1607, App-V is included with the [Windows 10 for Enterprise edition](https://www.microsoft.com/en-us/WindowsForBusiness/windows-for-enterprise). If you're new to Windows 10 and App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. To learn what you need to know before getting started with App-V, see the [Application Virtualization (App-V) overview](appv-for-windows.md).
|
||||
With the release of Windows 10, version 1607, App-V is included with the [Windows 10 for Enterprise edition](https://www.microsoft.com/WindowsForBusiness/windows-for-enterprise). If you're new to Windows 10 and App-V, you’ll need to download, activate, and install server- and client-side components to start delivering virtual applications to users. To learn what you need to know before getting started with App-V, see the [Application Virtualization (App-V) overview](appv-for-windows.md).
|
||||
|
||||
If you’re already using App-V, performing an in-place upgrade to Windows 10 on user devices automatically installs the App-V client and migrates users’ App-V applications and settings. For more information about how to configure an existing App-V installation after upgrading user devices to Windows 10, see [Upgrading to App-V for Windows 10 from an existing installation](appv-upgrading-to-app-v-for-windows-10-from-an-existing-installation.md).
|
||||
|
||||
@ -35,13 +35,13 @@ To start using App-V to deliver virtual applications to users, you’ll need to
|
||||
|
||||
| Component | What it does | Where to find it |
|
||||
|------------|--|------|
|
||||
| App-V server components | App-V offers five server components that work together to allow you to host and publish virtual applications, generate usage reports, and manage your App-V environment. For more details, see [Deploying the App-V Server](appv-deploying-the-appv-server.md).<br><br>If you're already using App-V 5.x, you don't need to redeploy the App-V server components, as they haven't changed since App-V 5.0's release. | The App-V server components are included in the Microsoft Desktop Optimization Pack (MDOP) 2015 ISO package that can be downloaded from the following locations:<br><br> If you have a Microsoft Developer Network (MSDN) subscription, use the [MSDN (Microsoft Developer Network) subscriptions site](https://msdn.microsoft.com/subscriptions/downloads/default.aspx#FileId=65215) to download the MDOP ISO package.<br><br> If you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/en-us/WindowsForBusiness/windows-product-home), download it from the [Volume Licensing Service Center](https://www.microsoft.com/en-us/licensing/default.aspx).<br><br>See [Deploying the App-V Server](appv-deploying-the-appv-server.md) for more information about installing and using the server components.|
|
||||
| App-V server components | App-V offers five server components that work together to allow you to host and publish virtual applications, generate usage reports, and manage your App-V environment. For more details, see [Deploying the App-V Server](appv-deploying-the-appv-server.md).<br><br>If you're already using App-V 5.x, you don't need to redeploy the App-V server components, as they haven't changed since App-V 5.0's release. | The App-V server components are included in the Microsoft Desktop Optimization Pack (MDOP) 2015 ISO package that can be downloaded from the following locations:<br><br> If you have a Microsoft Developer Network (MSDN) subscription, use the [MSDN (Microsoft Developer Network) subscriptions site](https://msdn.microsoft.com/subscriptions/downloads/default.aspx#FileId=65215) to download the MDOP ISO package.<br><br> If you're using [Windows 10 for Enterprise or Education](https://www.microsoft.com/WindowsForBusiness/windows-product-home), download it from the [Volume Licensing Service Center](https://www.microsoft.com/licensing/default.aspx).<br><br>See [Deploying the App-V Server](appv-deploying-the-appv-server.md) for more information about installing and using the server components.|
|
||||
| App-V client and App-V Remote Desktop Services (RDS) client | The App-V client is the component that runs virtualized applications on user devices, allowing users to interact with icons and file names to start virtualized applications. | The App-V client is automatically installed with Windows 10, version 1607. <br><br>To learn how to enable the client, see [Enable the App-V desktop client](appv-enable-the-app-v-desktop-client.md). |
|
||||
| App-V sequencer | Use the App-V sequencer to convert Win32 applications into virtual packages for deployment to user devices. Devices must run the App-V client to allow users to interact with virtual applications. | Installed with the [Windows Assessment and Deployment kit (ADK) for Windows 10, version 1607](https://developer.microsoft.com/windows/hardware/windows-assessment-deployment-kit). |
|
||||
|
||||
For more information about these components, see [High Level Architecture for App-V](appv-high-level-architecture.md).
|
||||
|
||||
If you're new to App-V, it's a good idea to read the documentation thoroughly. Before deploying App-V in a production environment, you can ensure installation goes smoothly by validating your deployment plan in a test network environment. You might also consider taking a class about relevant technologies. To get started, see the [Microsoft Training Overview](https://www.microsoft.com/en-us/learning/default.aspx).
|
||||
If you're new to App-V, it's a good idea to read the documentation thoroughly. Before deploying App-V in a production environment, you can ensure installation goes smoothly by validating your deployment plan in a test network environment. You might also consider taking a class about relevant technologies. To get started, see the [Microsoft Training Overview](https://www.microsoft.com/learning/default.aspx).
|
||||
|
||||
## Getting started with App-V
|
||||
|
||||
|
@ -31,7 +31,7 @@ You should read and understand the following information before reading this doc
|
||||
|
||||
- [Application Publishing and Client Interaction](appv-application-publishing-and-client-interaction.md)
|
||||
|
||||
- [App-V Sequencing Guide](https://www.microsoft.com/en-us/download/details.aspx?id=27760)
|
||||
- [App-V Sequencing Guide](https://www.microsoft.com/download/details.aspx?id=27760)
|
||||
|
||||
**Note**
|
||||
Some terms used in this document may have different meanings depending on external source and context. For more information about terms used in this document followed by an asterisk <strong>*</strong> review the [Application Virtualization Performance Guidance Terminology](#bkmk-terms1) section of this document.
|
||||
|
@ -30,7 +30,7 @@ The following list displays the end–to-end high-level workflow for reporting i
|
||||
|
||||
To confirm SQL Server Reporting Services is running, enter <https://localhost/Reports> in a web browser as administrator on the server that will host App-V Reporting. The SQL Server Reporting Services Home page should appear.
|
||||
2. Install the App-V reporting server and associated database. For more information about installing the reporting server see [How to install the Reporting Server on a standalone computer and connect it to the database](appv-install-the-reporting-server-on-a-standalone-computer.md). Configure the time when the computer running the App-V client should send data to the reporting server.
|
||||
3. If you are not using an electronic software distribution system such as Configuration Manager to view reports then you can define reports in SQL Server Reporting Service. Download predefined appvshort Reports from the Download Center at [Application Virtualization SSRS Reports](https://www.microsoft.com/en-us/download/details.aspx?id=42630).
|
||||
3. If you are not using an electronic software distribution system such as Configuration Manager to view reports then you can define reports in SQL Server Reporting Service. Download predefined appvshort Reports from the Download Center at [Application Virtualization SSRS Reports](https://www.microsoft.com/download/details.aspx?id=42630).
|
||||
|
||||
> [!NOTE]
|
||||
>If you are using the Configuration Manager integration with App-V, most reports are generated from Configuration Manager rather than from App-V.
|
||||
|
@ -22,7 +22,7 @@ This topic provides information about using the Application Virtualization (App-
|
||||
|
||||
## Obtain the client management console
|
||||
|
||||
The client management console is separate from the App-V client itself. You can download the client management console from the [Microsoft Download Center](https://www.microsoft.com/en-us/download/details.aspx?id=41186).
|
||||
The client management console is separate from the App-V client itself. You can download the client management console from the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=41186).
|
||||
|
||||
> [!NOTE]
|
||||
> To perform all of the actions available using the client management console, you must have administrative access on the computer running the App-V client.
|
||||
|
@ -92,7 +92,7 @@ Revision=1
|
||||
|
||||
If a per-user service can't be disabled using a the security template, you can disable it by using Group Policy preferences.
|
||||
|
||||
1. On a Windows Server domain controller or Windows 10 PC that has the [Remote Server Administration Tools (RSAT)](https://www.microsoft.com/en-us/download/details.aspx?id=45520) installed, click **Start**, type GPMC.MSC, and then press **Enter** to open the **Group Policy Management Console**.
|
||||
1. On a Windows Server domain controller or Windows 10 PC that has the [Remote Server Administration Tools (RSAT)](https://www.microsoft.com/download/details.aspx?id=45520) installed, click **Start**, type GPMC.MSC, and then press **Enter** to open the **Group Policy Management Console**.
|
||||
|
||||
2. Create a new Group Policy Object (GPO) or use an existing GPO.
|
||||
|
||||
|
@ -14,8 +14,8 @@ ms.topic: troubleshooting
|
||||
|
||||
# Advanced troubleshooting for Windows boot problems
|
||||
|
||||
>[!NOTE]
|
||||
>This article is intended for use by support agents and IT professionals. If you're looking for more general information about recovery options, see [Recovery options in Windows 10](https://support.microsoft.com/help/12415).
|
||||
> [!NOTE]
|
||||
> This article is intended for use by support agents and IT professionals. If you're looking for more general information about recovery options, see [Recovery options in Windows 10](https://support.microsoft.com/help/12415).
|
||||
|
||||
## Summary
|
||||
|
||||
@ -58,14 +58,14 @@ Here is a summary of the boot sequence, what will be seen on the display, and ty
|
||||
|
||||
Each phase has a different approach to troubleshooting. This article provides troubleshooting techniques for problems that occur during the first three phases.
|
||||
|
||||
>[!NOTE]
|
||||
>If the computer repeatedly boots to the recovery options, run the following command at a command prompt to break the cycle:
|
||||
> [!NOTE]
|
||||
> If the computer repeatedly boots to the recovery options, run the following command at a command prompt to break the cycle:
|
||||
>
|
||||
>`Bcdedit /set {default} recoveryenabled no`
|
||||
> `Bcdedit /set {default} recoveryenabled no`
|
||||
>
|
||||
>If the F8 options don't work, run the following command:
|
||||
> If the F8 options don't work, run the following command:
|
||||
>
|
||||
>`Bcdedit /set {default} bootmenupolicy legacy`
|
||||
> `Bcdedit /set {default} bootmenupolicy legacy`
|
||||
|
||||
|
||||
## BIOS phase
|
||||
@ -98,11 +98,10 @@ The Startup Repair tool automatically fixes many common problems. The tool also
|
||||
|
||||
To do this, follow these steps.
|
||||
|
||||
>[!NOTE]
|
||||
>For additional methods to start WinRE, see [Entry points into WinRE](https://docs.microsoft.com/windows-hardware/manufacture/desktop/windows-recovery-environment--windows-re--technical-reference#span-identrypointsintowinrespanspan-identrypointsintowinrespanspan-identrypointsintowinrespanentry-points-into-winre).
|
||||
> [!NOTE]
|
||||
> For additional methods to start WinRE, see [Windows Recovery Environment (Windows RE)](https://docs.microsoft.com/windows-hardware/manufacture/desktop/windows-recovery-environment--windows-re--technical-reference#span-identrypointsintowinrespanspan-identrypointsintowinrespanspan-identrypointsintowinrespanentry-points-into-winre).
|
||||
|
||||
1. Start the system to the installation media for the installed version of Windows.
|
||||
**Note** For more information, see [Create installation media for Windows](https://support.microsoft.com/help/15088).
|
||||
1. Start the system to the installation media for the installed version of Windows. For more information, see [Create installation media for Windows](https://support.microsoft.com/help/15088).
|
||||
|
||||
2. On the **Install Windows** screen, select **Next** > **Repair your computer**.
|
||||
|
||||
@ -132,8 +131,8 @@ To repair the boot sector, run the following command:
|
||||
BOOTREC /FIXBOOT
|
||||
```
|
||||
|
||||
>[!NOTE]
|
||||
>Running **BOOTREC** together with **Fixmbr** overwrites only the master boot code. If the corruption in the MBR affects the partition table, running **Fixmbr** may not fix the problem.
|
||||
> [!NOTE]
|
||||
> Running **BOOTREC** together with **Fixmbr** overwrites only the master boot code. If the corruption in the MBR affects the partition table, running **Fixmbr** may not fix the problem.
|
||||
|
||||
### Method 3: Fix BCD errors
|
||||
|
||||
@ -152,20 +151,25 @@ If you receive BCD-related errors, follow these steps:
|
||||
```
|
||||
|
||||
4. You might receive one of the following outputs:
|
||||
|
||||
- Scanning all disks for Windows installations. Please wait, since this may take a while...Successfully scanned Windows installations. Total identified Windows installations: 0
|
||||
```dos
|
||||
Scanning all disks for Windows installations. Please wait, since this may take a while ...
|
||||
Successfully scanned Windows installations. Total identified Windows installations: 0
|
||||
The operation completed successfully.
|
||||
```
|
||||
|
||||
- Scanning all disks for Windows installations. Please wait, since this may take a while... Successfully scanned Windows installations. Total identified Windows installations: 1
|
||||
```dos
|
||||
Scanning all disks for Windows installations. Please wait, since this may take a while ...
|
||||
Successfully scanned Windows installations. Total identified Windows installations: 1
|
||||
D:\Windows
|
||||
Add installation to boot list? Yes/No/All:
|
||||
```
|
||||
|
||||
If the output shows **windows installation: 0**, run the following commands:
|
||||
|
||||
```dos
|
||||
bcdedit /export c:\bcdbackup
|
||||
|
||||
attrib c:\\boot\\bcd -h -r –s
|
||||
attrib c:\\boot\\bcd -r –s -h
|
||||
|
||||
ren c:\\boot\\bcd bcd.old
|
||||
|
||||
@ -174,39 +178,41 @@ bootrec /rebuildbcd
|
||||
|
||||
After you run the command, you receive the following output:
|
||||
|
||||
Scanning all disks for Windows installations. Please wait, since this may take a while...Successfully scanned Windows installations. Total identified Windows installations: 1{D}:\Windows
|
||||
```dos
|
||||
Scanning all disks for Windows installations. Please wait, since this may take a while ...
|
||||
Successfully scanned Windows installations. Total identified Windows installations: 1
|
||||
{D}:\Windows
|
||||
Add installation to boot list? Yes/No/All: Y
|
||||
```
|
||||
|
||||
5. Try again to start the system.
|
||||
5. Try restarting the system.
|
||||
|
||||
### Method 4: Replace Bootmgr
|
||||
|
||||
If methods 1 and 2 do not fix the problem, replace the Bootmgr file from drive C to the System Reserved partition. To do this, follow these steps:
|
||||
If methods 1, 2 and 3 do not fix the problem, replace the Bootmgr file from drive C to the System Reserved partition. To do this, follow these steps:
|
||||
|
||||
1. At a command prompt, change the directory to the System Reserved partition.
|
||||
|
||||
2. Run the **attrib** command to unhide the file:
|
||||
```dos
|
||||
attrib-s -h -r
|
||||
attrib -r -s -h
|
||||
```
|
||||
|
||||
3. Run the same **attrib** command on the Windows (system drive):
|
||||
```dos
|
||||
attrib-s -h –r
|
||||
attrib -r -s -h
|
||||
```
|
||||
|
||||
4. Rename the Bootmgr file as Bootmgr.old:
|
||||
```dos
|
||||
ren c:\\bootmgr bootmgr.old
|
||||
ren c:\bootmgr bootmgr.old
|
||||
```
|
||||
|
||||
5. Start a text editor, such as Notepad.
|
||||
5. Navigate to the system drive.
|
||||
|
||||
6. Navigate to the system drive.
|
||||
6. Copy the Bootmgr file, and then paste it to the System Reserved partition.
|
||||
|
||||
7. Copy the Bootmgr file, and then paste it to the System Reserved partition.
|
||||
|
||||
8. Restart the computer.
|
||||
7. Restart the computer.
|
||||
|
||||
### Method 5: Restore System Hive
|
||||
|
||||
@ -267,16 +273,16 @@ For detailed instructions, see [How to perform a clean boot in Windows](https://
|
||||
If the computer starts in Disable Driver Signature mode, start the computer in Disable Driver Signature Enforcement mode, and then follow the steps that are documented in the following article to determine which drivers or files require driver signature enforcement:
|
||||
[Troubleshooting boot problem caused by missing driver signature (x64)](https://blogs.technet.microsoft.com/askcore/2012/04/15/troubleshooting-boot-issues-due-to-missing-driver-signature-x64/)
|
||||
|
||||
>[!NOTE]
|
||||
>If the computer is a domain controller, try Directory Services Restore mode (DSRM).
|
||||
> [!NOTE]
|
||||
> If the computer is a domain controller, try Directory Services Restore mode (DSRM).
|
||||
>
|
||||
>This method is an important step if you encounter Stop error "0xC00002E1" or "0xC00002E2"
|
||||
> This method is an important step if you encounter Stop error "0xC00002E1" or "0xC00002E2"
|
||||
|
||||
|
||||
**Examples**
|
||||
|
||||
>[!WARNING]
|
||||
>Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these
|
||||
> [!WARNING]
|
||||
> Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these
|
||||
problems can be solved. Modify the registry at your own risk.
|
||||
|
||||
*Error code INACCESSIBLE_BOOT_DEVICE (STOP 0x7B)*
|
||||
@ -307,11 +313,11 @@ For additional troubleshooting steps, see the following articles:
|
||||
|
||||
To fix problems that occur after you install Windows updates, check for pending updates by using these steps:
|
||||
|
||||
1. Open a Command Prompt winodw in WinRE.
|
||||
1. Open a Command Prompt window in WinRE.
|
||||
|
||||
2. Run the command:
|
||||
```dos
|
||||
dism /image:C:\ /get-packages
|
||||
DISM /image:C:\ /get-packages
|
||||
```
|
||||
|
||||
3. If there are any pending updates, uninstall them by running the following commands:
|
||||
@ -319,7 +325,7 @@ To fix problems that occur after you install Windows updates, check for pending
|
||||
DISM /image:C:\ /remove-package /packagename: name of the package
|
||||
```
|
||||
```dos
|
||||
Dism /Image:C:\ /Cleanup-Image /RevertPendingActions
|
||||
DISM /Image:C:\ /Cleanup-Image /RevertPendingActions
|
||||
```
|
||||
|
||||
Try to start the computer.
|
||||
|
@ -98,7 +98,7 @@ As you review the roles in your organization, you can use the following generali
|
||||
|
||||
Your configuration requirements are defined by multiple factors, including the level of management needed, the devices and data managed, and your industry requirements. Meanwhile, employees are frequently concerned about IT applying strict policies to their personal devices, but they still want access to corporate email and documents. With Windows 10, you can create a consistent set of configurations across PCs, tablets, and phones through the common MDM layer.
|
||||
|
||||
**MDM**: [MDM](https://www.microsoft.com/en-us/cloud-platform/mobile-device-management) gives you a way to configure settings that achieve your administrative intent without exposing every possible setting. (In contrast, Group Policy exposes fine-grained settings that you control individually.) One benefit of MDM is that it enables you to apply broader privacy, security, and application management settings through lighter and more efficient tools. MDM also allows you to target Internet-connected devices to manage policies without using GP that requires on-premises domain-joined devices. This makes MDM the best choice for devices that are constantly on the go.
|
||||
**MDM**: [MDM](https://www.microsoft.com/cloud-platform/mobile-device-management) gives you a way to configure settings that achieve your administrative intent without exposing every possible setting. (In contrast, Group Policy exposes fine-grained settings that you control individually.) One benefit of MDM is that it enables you to apply broader privacy, security, and application management settings through lighter and more efficient tools. MDM also allows you to target Internet-connected devices to manage policies without using GP that requires on-premises domain-joined devices. This makes MDM the best choice for devices that are constantly on the go.
|
||||
|
||||
**Group Policy** and **System Center Configuration Manager**: Your organization might still need to manage domain joined computers at a granular level such as Internet Explorer’s 1,500 configurable Group Policy settings. If so, Group Policy and System Center Configuration Manager continue to be excellent management choices:
|
||||
|
||||
|
@ -114,7 +114,7 @@ Example: Export the Debug logs
|
||||
|
||||
## Collect logs from Windows 10 Mobile devices
|
||||
|
||||
Since there is no Event Viewer in Windows 10 Mobile, you can use the [Field Medic](https://www.microsoft.com/en-us/p/field-medic/9wzdncrfjb82?activetab=pivot%3aoverviewtab) app to collect logs.
|
||||
Since there is no Event Viewer in Windows 10 Mobile, you can use the [Field Medic](https://www.microsoft.com/p/field-medic/9wzdncrfjb82?activetab=pivot%3aoverviewtab) app to collect logs.
|
||||
|
||||
**To collect logs manually**
|
||||
|
||||
|
@ -156,8 +156,8 @@ Requirements:
|
||||
>[!IMPORTANT]
|
||||
>If you do not see the policy, it may be because you don’t have the ADMX installed for Windows 10, version 1803 or version 1809. To fix the issue, follow these steps:
|
||||
> 1. Download:
|
||||
> 1803 -->[Administrative Templates (.admx) for Windows 10 April 2018 Update (1803)](https://www.microsoft.com/en-us/download/details.aspx?id=56880) or
|
||||
> 1809 --> [Administrative Templates for Windows 10 October 2018 Update (1809)](https://www.microsoft.com/en-us/download/details.aspx?id=57576).
|
||||
> 1803 -->[Administrative Templates (.admx) for Windows 10 April 2018 Update (1803)](https://www.microsoft.com/download/details.aspx?id=56880) or
|
||||
> 1809 --> [Administrative Templates for Windows 10 October 2018 Update (1809)](https://www.microsoft.com/download/details.aspx?id=57576).
|
||||
> 2. Install the package on the Primary Domain Controller (PDC).
|
||||
> 3. Navigate, depending on the version to the folder:
|
||||
> 1803 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 April 2018 Update (1803) v2**, or
|
||||
|
@ -167,6 +167,9 @@ AuthenticationServiceUrl?appru=<appid>&login_hint=<User Principal Name>
|
||||
|
||||
After authentication is complete, the auth server should return an HTML form document with a POST method action of appid identified in the query string parameter.
|
||||
|
||||
> [!NOTE]
|
||||
> To make an application compatible with strict Content Security Policy, it is usually necessary to make some changes to HTML templates and client-side code, add the policy header, and test that everything works properly once the policy is deployed.
|
||||
|
||||
```
|
||||
HTTP/1.1 200 OK
|
||||
Content-Type: text/html; charset=UTF-8
|
||||
|
@ -81,43 +81,7 @@ For code samples, see [Microsoft Azure Active Directory Samples and Documentatio
|
||||
|
||||
## Configure your Azure AD application
|
||||
|
||||
Here are the steps to configure your Azure AD app. For additional information, see [Integrating Applications with Azure Active Directory](https://go.microsoft.com/fwlink/p/?LinkId=623021):
|
||||
|
||||
1. Log into Microsoft Azure Management Portal (https:manage.windowsazure.com)
|
||||
2. Go to the Active Directory module.
|
||||
3. Select your directory.
|
||||
4. Click the **Applications** tab.
|
||||
|
||||

|
||||
|
||||
5. Click **Add**.
|
||||
|
||||

|
||||
|
||||
6. Select **Add an application that my organization is developing**.
|
||||
|
||||

|
||||
|
||||
7. Specify a name and then select **WEB APPLICATION AND/OR WEB API**.
|
||||
|
||||

|
||||
|
||||
8. Specify the **SIGN-ON URL** to your application.
|
||||
|
||||

|
||||
|
||||
9. Specify whether your app is multi-tenant or single tenant. For more information, see [Integrating Applications with Azure Active Directory](https://go.microsoft.com/fwlink/p/?LinkId=623021).
|
||||
|
||||

|
||||
|
||||
10. Create a client key.
|
||||
|
||||

|
||||
|
||||
> **Note** In the prior version of the tool, an update to the app manifest was required to authorize the application. This is no longer necessary.
|
||||
|
||||
11. Login to Store for Business and enable your application. For step-by-step guide, see [Configure an MDM provider](https://technet.microsoft.com/library/mt606939.aspx).
|
||||
|
||||
See [Quickstart: Register an application with the Microsoft identity platform](https://docs.microsoft.com/azure/active-directory/develop/quickstart-register-app) for the steps to configure your Azure AD app.
|
||||
|
||||
## Azure AD Authentication for MTS
|
||||
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: manikadhiman
|
||||
ms.date: 01/26/2019
|
||||
ms.date: 08/26/2019
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
---
|
||||
@ -205,8 +205,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off scanning on archived files.
|
||||
- 1 (default) – Allowed. Scans the archive files.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -267,8 +267,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off behavior monitoring.
|
||||
- 1 (default) – Allowed. Turns on real-time behavior monitoring.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -330,8 +330,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off the Microsoft Active Protection Service.
|
||||
- 1 (default) – Allowed. Turns on the Microsoft Active Protection Service.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -392,8 +392,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 (default) – Not allowed.
|
||||
- 1 – Allowed.
|
||||
- 0 (default) – Not allowed. Turns off email scanning.
|
||||
- 1 – Allowed. Turns on email scanning.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -454,8 +454,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 (default) – Not allowed.
|
||||
- 1 – Allowed.
|
||||
- 0 (default) – Not allowed. Disables scanning on mapped network drives.
|
||||
- 1 – Allowed. Scans mapped network drives.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -502,7 +502,7 @@ The following list shows the supported values:
|
||||
> This policy is only enforced in Windows 10 for desktop.
|
||||
|
||||
|
||||
Allows or disallows a full scan of removable drives.
|
||||
Allows or disallows a full scan of removable drives. During a quick scan, removable drives may still be scanned.
|
||||
|
||||
<!--/Description-->
|
||||
<!--ADMXMapped-->
|
||||
@ -516,8 +516,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off scanning on removable drives.
|
||||
- 1 (default) – Allowed. Scans removable drives.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -756,8 +756,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off the real-time monitoring service.
|
||||
- 1 (default) – Allowed. Turns on and runs the real-time monitoring service.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -818,8 +818,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Turns off scanning of network files.
|
||||
- 1 (default) – Allowed. Scans network files.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
@ -934,8 +934,8 @@ ADMX Info:
|
||||
<!--SupportedValues-->
|
||||
The following list shows the supported values:
|
||||
|
||||
- 0 – Not allowed.
|
||||
- 1 (default) – Allowed.
|
||||
- 0 – Not allowed. Prevents users from accessing UI.
|
||||
- 1 (default) – Allowed. Lets users access UI.
|
||||
|
||||
<!--/SupportedValues-->
|
||||
<!--/Policy-->
|
||||
|
@ -23,7 +23,7 @@ Here's the XSD for the ProfileXML node in VPNv2 CSP for Windows 10 and some pro
|
||||
```xml
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
|
||||
<xs:import namespace="http://www.microsoft.com/provisioning/EapHostConfig" />
|
||||
<xs:import namespace="http://www.microsoft.com/provisioning/EapHostConfig" schemaLocation="EapHostConfig.xsd" />
|
||||
<xs:element name="VPNProfile">
|
||||
<xs:complexType>
|
||||
<xs:sequence>
|
||||
|
@ -108,7 +108,7 @@ MDM enrollment can also be initiated with a provisioning package. This option en
|
||||
|
||||
Employees can use only one account to initialize a device so it’s imperative that your organization controls which account is enabled first. The account chosen will determine who controls the device and influence your management capabilities.
|
||||
|
||||
>**Note:** Why must the user add an account to the device in OOBE? Windows 10 Mobile are single user devices and the user accounts give access to a number of default cloud services that enhance the productivity and entertainment value of the phone for the user. Such services are: Store for downloading apps, Groove for music and entertainment, Xbox for gaming, etc. Both an [MSA](https://www.microsoft.com/en-us/account/) and an [Azure AD account](https://www.microsoft.com/en-us/server-cloud/products/azure-active-directory/?WT.srch=1&WT.mc_id=SEM_%5B_uniqid%5D&utm_source=Bing&utm_medium=CPC&utm_term=azure%20ad&utm_campaign=Enterprise_Mobility_Suite) give access to these services.
|
||||
>**Note:** Why must the user add an account to the device in OOBE? Windows 10 Mobile are single user devices and the user accounts give access to a number of default cloud services that enhance the productivity and entertainment value of the phone for the user. Such services are: Store for downloading apps, Groove for music and entertainment, Xbox for gaming, etc. Both an [MSA](https://www.microsoft.com/account/) and an [Azure AD account](https://www.microsoft.com/server-cloud/products/azure-active-directory/?WT.srch=1&WT.mc_id=SEM_%5B_uniqid%5D&utm_source=Bing&utm_medium=CPC&utm_term=azure%20ad&utm_campaign=Enterprise_Mobility_Suite) give access to these services.
|
||||
|
||||
The following table describes the impact of identity choice on device management characteristics of the personal and corporate device scenarios.
|
||||
|
||||
@ -186,7 +186,7 @@ For both personal and corporate deployment scenarios, an MDM system is the essen
|
||||
Azure AD is a cloud-based directory service that provides identity and access management. You can integrate it with existing on-premises directories to create a hybrid identity solution. Organizations that use Microsoft Office 365 or Intune are already using Azure AD, which has three editions: Free Basic, and Premium (see [Azure Active Directory editions](https://azure.microsoft.com/documentation/articles/active-directory-editions/)). All editions support Azure AD device registration, but the Premium edition is required to enable MDM auto-enrollment and conditional access based on device state.
|
||||
|
||||
**Mobile Device Management**
|
||||
Microsoft [Intune](https://www.microsoft.com/en-us/server-cloud/products/microsoft-intune/overview.aspx), part of the Enterprise Mobility + Security, is a cloud-based MDM system that manages devices off premises. Like Office 365, Intune uses Azure AD for identity management so employees use the same credentials to enroll devices in Intune that they use to sign into Office 365. Intune supports devices that run other operating systems, such as iOS and Android, to provide a complete MDM solution.
|
||||
Microsoft [Intune](https://www.microsoft.com/server-cloud/products/microsoft-intune/overview.aspx), part of the Enterprise Mobility + Security, is a cloud-based MDM system that manages devices off premises. Like Office 365, Intune uses Azure AD for identity management so employees use the same credentials to enroll devices in Intune that they use to sign into Office 365. Intune supports devices that run other operating systems, such as iOS and Android, to provide a complete MDM solution.
|
||||
You can also integrate Intune with Configuration Manager to gain a single console for managing all devices in the cloud and on premises, mobile or PC. For more information, see [Manage Mobile Devices with Configuration Manager and Microsoft Intune](https://technet.microsoft.com/library/jj884158.aspx). For guidance on choosing between a stand-alone Intune installation and Intune integrated with System Center Configuration Manager, see Choose between Intune by itself or integrating Intune with System Center Configuration Manager.
|
||||
Multiple MDM systems support Windows 10 and most support personal and corporate device deployment scenarios. MDM providers that support Windows 10 Mobile currently include: AirWatch, Citrix, MobileIron, SOTI, Blackberry and others. Most industry-leading MDM vendors already support integration with Azure AD. You can find the MDM vendors that support Azure AD in [Azure Marketplace](https://azure.microsoft.com/marketplace/). If your organization doesn’t use Azure AD, the user must use an MSA during OOBE before enrolling the device in your MDM using a corporate account.
|
||||
|
||||
|
@ -53,7 +53,7 @@ Your organization must have an Azure AD tenant and your employees’ devices mus
|
||||
## Cortana and privacy
|
||||
We understand that there are some questions about Cortana and your organization’s privacy, including concerns about what info is collected by Cortana, where the info is saved, how to manage what data is collected, how to turn Cortana off, how to opt completely out of data collection, and what info is shared with other Microsoft apps and services. For more details about these concerns, see the [Cortana, Search, and privacy: FAQ](https://windows.microsoft.com/windows-10/cortana-privacy-faq) topic.
|
||||
|
||||
Cortana is covered under the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and [Microsoft Services Agreement](https://www.microsoft.com/en-us/servicesagreement).
|
||||
Cortana is covered under the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
||||
|
||||
## See also
|
||||
- [What is Cortana?](https://go.microsoft.com/fwlink/p/?LinkId=746818)
|
||||
|
@ -18,7 +18,7 @@ manager: dansimp
|
||||
- Windows 10 Mobile, version 1703
|
||||
|
||||
>[!IMPORTANT]
|
||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering. For more info, see the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and the [Microsoft Services Agreement](https://www.microsoft.com/en-us/servicesagreement).
|
||||
>The data created as part of these scenarios will be uploaded to Microsoft’s Cloud to help Cortana learn and help your employees. This is the same info that Cortana uses in the consumer offering. For more info, see the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) and the [Microsoft Services Agreement](https://www.microsoft.com/servicesagreement).
|
||||
|
||||
Cortana automatically finds patterns in your email, suggesting reminders based things that you said you would do so you don’t forget about them. For example, Cortana recognizes that if you include the text, _I’ll get this to you by the end of the week_ in an email, you're making a commitment to provide something by a specific date. Cortana can now suggest that you be reminded about this event, letting you decide whether to keep it or to cancel it.
|
||||
|
||||
|
@ -21,15 +21,15 @@ ms.topic: article
|
||||
|
||||
- Windows 10 Pro, Enterprise, and Education
|
||||
|
||||
>[!WARNING]
|
||||
>For kiosks in public-facing environments with auto sign-in enabled, you should use a user account with least privilege, such as a local standard user account.
|
||||
> [!WARNING]
|
||||
> For kiosks in public-facing environments with auto sign-in enabled, you should use a user account with the least privileges, such as a local standard user account.
|
||||
>
|
||||
>Assigned access can be configured via Windows Management Instrumentation (WMI) or configuration service provider (CSP) to run its applications under a domain user or service account, rather than a local account. However, use of domain user or service accounts introduces risks that an attacker subverting the assigned access application might gain access to sensitive domain resources that have been inadvertently left accessible to any domain account. We recommend that customers proceed with caution when using domain accounts with assigned access, and consider the domain resources potentially exposed by the decision to do so.
|
||||
> Assigned access can be configured via Windows Management Instrumentation (WMI) or configuration service provider (CSP) to run its applications under a domain user or service account, rather than a local account. However, use of domain user or service accounts introduces risks that might allow an attacker subverting the assigned access application to gain access to sensitive domain resources that have been inadvertently left accessible to any domain account. We recommend that customers proceed with caution when using domain accounts with assigned access, and consider the domain resources potentially exposed by the decision to do so.
|
||||
|
||||
>[!IMPORTANT]
|
||||
>[User account control (UAC)](https://docs.microsoft.com/windows/security/identity-protection/user-account-control/user-account-control-overview) must be turned on to enable kiosk mode.
|
||||
> [!IMPORTANT]
|
||||
> [User account control (UAC)](https://docs.microsoft.com/windows/security/identity-protection/user-account-control/user-account-control-overview) must be turned on to enable kiosk mode.
|
||||
>
|
||||
>Kiosk mode is not supported over a remote desktop connection. Your kiosk users must sign in on the physical device that is set up as a kiosk.
|
||||
> Kiosk mode is not supported over a remote desktop connection. Your kiosk users must sign in on the physical device that is set up as a kiosk.
|
||||
|
||||
## Configuration recommendations
|
||||
|
||||
@ -60,19 +60,19 @@ Logs can help you [troubleshoot issues](multi-app-kiosk-troubleshoot.md) kiosk i
|
||||
|
||||
In addition to the settings in the table, you may want to set up **automatic logon** for your kiosk device. When your kiosk device restarts, whether from an update or power outage, you can sign in the assigned access account manually or you can configure the device to sign in to the assigned access account automatically. Make sure that Group Policy settings applied to the device do not prevent automatic sign in.
|
||||
|
||||
>[!NOTE]
|
||||
>If you are using a Windows 10 and later device restriction CSP to set "Preferred Azure AD tenant domain", this will break the "User logon type" auto-login feature of the Kiosk profile.
|
||||
> [!NOTE]
|
||||
> If you are using a Windows 10 and later device restriction CSP to set "Preferred Azure AD tenant domain", this will break the "User logon type" auto-login feature of the Kiosk profile.
|
||||
|
||||
>[!TIP]
|
||||
>If you use the [kiosk wizard in Windows Configuration Designer](kiosk-single-app.md#wizard) or [XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) to configure your kiosk, you can set an account to sign in automatically in the wizard or XML.
|
||||
> [!TIP]
|
||||
> If you use the [kiosk wizard in Windows Configuration Designer](kiosk-single-app.md#wizard) or [XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) to configure your kiosk, you can set an account to sign in automatically in the wizard or XML.
|
||||
|
||||
|
||||
**How to edit the registry to have an account sign in automatically**
|
||||
|
||||
1. Open Registry Editor (regedit.exe).
|
||||
|
||||
>[!NOTE]
|
||||
>If you are not familiar with Registry Editor, [learn how to modify the Windows registry](https://go.microsoft.com/fwlink/p/?LinkId=615002).
|
||||
> [!NOTE]
|
||||
> If you are not familiar with Registry Editor, [learn how to modify the Windows registry](https://go.microsoft.com/fwlink/p/?LinkId=615002).
|
||||
|
||||
|
||||
2. Go to
|
||||
@ -94,8 +94,8 @@ In addition to the settings in the table, you may want to set up **automatic log
|
||||
|
||||
4. Close Registry Editor. The next time the computer restarts, the account will sign in automatically.
|
||||
|
||||
>[!TIP]
|
||||
>You can also configure automatic sign-in [using the Autologon tool from Sysinternals](https://docs.microsoft.com/sysinternals/downloads/autologon).
|
||||
> [!TIP]
|
||||
> You can also configure automatic sign-in [using the Autologon tool from Sysinternals](https://docs.microsoft.com/sysinternals/downloads/autologon).
|
||||
|
||||
|
||||
## Interactions and interoperability
|
||||
@ -245,13 +245,13 @@ The following table describes some features that have interoperability issues we
|
||||
</table>
|
||||
|
||||
|
||||
<span id="test-vm"/>
|
||||
|
||||
<span id="test-vm" />
|
||||
## Testing your kiosk in a virtual machine (VM)
|
||||
|
||||
Customers sometimes use virtual machines (VMs) to test configurations before deploying those configurations to physical devices. If you use a VM to test your single-app kiosk configuration, you need to know how to connect to the VM properly.
|
||||
|
||||
A single-app kiosk configuration runs an app above the lockscreen. It doesn't work when it's accessed remotely, which includes *enhanced* sessions in Hyper-V.
|
||||
A single-app kiosk configuration runs an app above the lock screen. It doesn't work when it's accessed remotely, which includes *enhanced* sessions in Hyper-V.
|
||||
|
||||
When you connect to a VM configured as a single-app kiosk, you need a *basic* session rather than an enhanced session. In the following image, notice that **Enhanced session** is not selected in the **View** menu; that means it's a basic session.
|
||||
|
||||
@ -259,4 +259,4 @@ When you connect to a VM configured as a single-app kiosk, you need a *basic* se
|
||||
|
||||
To connect to a VM in a basic session, do not select **Connect** in the connection dialog, as shown in the following image, but instead, select the **X** button in the upper-right corner to cancel the dialog.
|
||||
|
||||

|
||||

|
||||
|
@ -51,6 +51,7 @@ Method | Description
|
||||
|
||||
|
||||
<span id="local"/>
|
||||
|
||||
## Set up a kiosk in local Settings
|
||||
|
||||
>App type: UWP
|
||||
@ -122,6 +123,7 @@ To remove assigned access, choose **Turn off assigned access and sign out of the
|
||||
|
||||
|
||||
<span id="powershell"/>
|
||||
|
||||
## Set up a kiosk using Windows PowerShell
|
||||
|
||||
|
||||
@ -182,6 +184,7 @@ Clear-AssignedAccess
|
||||
|
||||
|
||||
<span id="wizard" />
|
||||
|
||||
## Set up a kiosk using the kiosk wizard in Windows Configuration Designer
|
||||
|
||||
>App type: UWP or Windows desktop application
|
||||
@ -234,6 +237,7 @@ When you use the **Provision kiosk devices** wizard in Windows Configuration Des
|
||||
|
||||
|
||||
<span id="mdm" />
|
||||
|
||||
## Set up a kiosk or digital sign using Microsoft Intune or other MDM service
|
||||
|
||||
>App type: UWP
|
||||
|
@ -591,6 +591,7 @@ To create a multi-app kiosk that can run mixed reality apps, you must include th
|
||||
<App AppUserModelId="MixedRealityLearning_cw5n1h2txyewy!MixedRealityLearning" />
|
||||
<App AppUserModelId="HoloShell_cw5n1h2txyewy!HoloShell" />
|
||||
<App AppUserModelId="Microsoft.Windows.HolographicFirstRun_cw5n1h2txyewy!App" />
|
||||
<App AppUserModelId="Microsoft.MixedReality.Portal_8wekyb3d8bbwe!App" />
|
||||
```
|
||||
|
||||
These are in addition to any mixed reality apps that you allow.
|
||||
|
@ -26,7 +26,7 @@ Windows 10, version 1703, ships with Windows Provisioning PowerShell cmdlets. Th
|
||||
|
||||
|
||||
<table><tr><th>Cmdlet</th><th>Use this cmdlet to</th><th>Syntax</th></tr>
|
||||
<tr><td>Add-ProvisioningPackage</td><td> Apply a provisioning package</td><td><code>Add-ProvisioningPackage [-Path] <string> [-ForceInstall] [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code></td></tr>
|
||||
<tr><td>Add-ProvisioningPackage</td><td> Apply a provisioning package</td><td><code>Add-ProvisioningPackage [-Path] <string> [-ForceInstall] [-LogsFolder <string>] [-QuietInstall] [-WprpFile <string>] [<CommonParameters>]</code></td></tr>
|
||||
<tr><td rowspan="3">Remove-ProvisioningPackage</td><td rowspan="3">Remove a provisioning package</td><td> <code>Remove-ProvisioningPackage -PackageId <string> [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr><tr><td> <code>Remove-ProvisioningPackage -Path <string> [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr><tr><td> <code>Remove-ProvisioningPackage -AllInstalledPackages [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr>
|
||||
<tr><td rowspan="3">Get-ProvisioningPackage </td><td rowspan="3"> Get information about an installed provisioning package </td><td> <code>Get-ProvisioningPackage -PackageId <string> [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr><tr><td><code>Get-ProvisioningPackage -Path <string> [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr><tr><td> <code>Get-ProvisioningPackage -AllInstalledPackages [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr>
|
||||
<tr><td rowspan="2"> Export-ProvisioningPackage</td><td rowspan="2"> Extract the contents of a provisioning package</td><td> <code>Export-ProvisioningPackage -PackageId <string> -OutputFolder <string> [-Overwrite] [-AnswerFileOnly] [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr><tr><td> <code>Export-ProvisioningPackage -Path <string> -OutputFolder <string> [-Overwrite] [-AnswerFileOnly] [-LogsFolder <string>] [-WprpFile <string>] [<CommonParameters>]</code> </td></tr>
|
||||
|
@ -78,9 +78,6 @@ In Windows 10, version 1703, by using the PowerShell cmdlet `export-StartLayoutE
|
||||
- For example, your layout.xml contains `Square150x150LogoUri="ms-appdata:///local/PinnedTiles/21581260870/hires.png" Wide310x150LogoUri="ms-appx:///"`
|
||||
- Open `C:\Users\<username>\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\21581260870\` and replace those images with your customized images.
|
||||
|
||||
>[!TIP]
|
||||
>A quick method for getting appropriately sized images for each tile size is to upload your image at [BuildMyPinnedSite](http://www.buildmypinnedsite.com/) and then download the resized tile images.
|
||||
|
||||
4. In Windows PowerShell, enter the following command:
|
||||
|
||||
```
|
||||
@ -112,11 +109,8 @@ In Microsoft Intune, you create a device restrictions policy to apply to device
|
||||
>[!NOTE]
|
||||
>The device restrictions in Microsoft Intune include [other Start settings](https://docs.microsoft.com/intune/device-restrictions-windows-10#start) that you can also configure in your profile.
|
||||
|
||||
|
||||
|
||||
### Using a provisioning package
|
||||
|
||||
<span id="escape" />
|
||||
#### Prepare the Start layout and Edge assets XML files
|
||||
|
||||
The **export-StartLayout** and **export-StartLayoutEdgeAssets** cmdlets produce XML files. Because Windows Configuration Designer produces a customizations.xml file that contains the configuration settings, adding the Start layout and Edge assets sections to the customizations.xml file directly would result in an XML file embedded in an XML file. Before you add the Start layout and Edge assets sections to the customizations.xml file, you must replace the markup characters in your layout.xml with escape characters.
|
||||
@ -128,7 +122,7 @@ The **export-StartLayout** and **export-StartLayoutEdgeAssets** cmdlets produce
|
||||
|
||||
3. During the procedure to create a provisioning package, you will copy the text with the escape characters and paste it in the customizations.xml file for your project.
|
||||
|
||||
#### <a href="" id="bkmk-domaingpodeployment"></a>Create a provisioning package that contains a customized Start layout
|
||||
#### Create a provisioning package that contains a customized Start layout
|
||||
|
||||
|
||||
Use the Windows Configuration Designer tool to create a provisioning package. [Learn how to install Windows Configuration Designer.](provisioning-packages/provisioning-install-icd.md)
|
||||
|
@ -23,7 +23,7 @@ ms.date: 4/16/2018
|
||||
- Windows 10
|
||||
- Windows 10 Mobile
|
||||
|
||||
>For more info about the features and functionality that are supported in each edition of Windows, see [Compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare).
|
||||
>For more info about the features and functionality that are supported in each edition of Windows, see [Compare Windows 10 Editions](https://www.microsoft.com/WindowsForBusiness/Compare).
|
||||
|
||||
IT pros can configure access to Microsoft Store for client computers in their organization. For some organizations, business policies require blocking access to Microsoft Store.
|
||||
|
||||
|
@ -228,7 +228,7 @@ To distribute a new Notepad template, you would perform these steps:
|
||||
|
||||
## Get the UE-V Configuration Pack
|
||||
|
||||
You can download the [System Center 2012 Configuration Pack for Microsoft User Experience Virtualization 2.0](https://www.microsoft.com/en-us/download/details.aspx?id=40913) from the Microsoft Download Center.
|
||||
You can download the [System Center 2012 Configuration Pack for Microsoft User Experience Virtualization 2.0](https://www.microsoft.com/download/details.aspx?id=40913) from the Microsoft Download Center.
|
||||
|
||||
|
||||
|
||||
|
@ -139,7 +139,7 @@ You can deploy UE-V settings location template with the following methods:
|
||||
|
||||
- **Registering template with Template Catalog Path**. If you use the Settings Template Catalog Path to manage templates on users’ computers, copy the Office template into the folder defined in the UE-V service. The next time the Template Auto Update (ApplySettingsCatalog.exe) scheduled task runs, the settings location template will be registered on the device. For more information, see [Deploy a settings template catalog](uev-deploy-uev-for-custom-applications.md).
|
||||
|
||||
- **Registering template with Configuration Manager**. If you use Configuration Manager to manage your UE-V settings storage templates, recreate the Template Baseline CAB, import it into Configuration Manager, and then deploy the baseline to user devices. For more information, see the guidance provided in the documentation for the [System Center 2012 Configuration Pack for Microsoft User Experience Virtualization 2.0](https://www.microsoft.com/en-us/download/details.aspx?id=40913).
|
||||
- **Registering template with Configuration Manager**. If you use Configuration Manager to manage your UE-V settings storage templates, recreate the Template Baseline CAB, import it into Configuration Manager, and then deploy the baseline to user devices. For more information, see the guidance provided in the documentation for the [System Center 2012 Configuration Pack for Microsoft User Experience Virtualization 2.0](https://www.microsoft.com/download/details.aspx?id=40913).
|
||||
|
||||
|
||||
|
||||
|
@ -22,7 +22,7 @@ User Experience Virtualization (UE-V) for Windows 10, version 1607, includes the
|
||||
|
||||
## UE-V is now a feature in Windows 10
|
||||
|
||||
With Windows 10, version 1607 and later releases, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/en-us/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
With Windows 10, version 1607 and later releases, UE-V is included with [Windows 10 for Enterprise](https://www.microsoft.com/WindowsForBusiness/windows-for-enterprise) and is no longer part of the Microsoft Desktop Optimization Pack.
|
||||
|
||||
The changes in UE-V for Windows 10, version 1607 impact already existing implementations of UE-V in the following ways:
|
||||
|
||||
|
@ -63,7 +63,7 @@ You probably have on-premises Active Directory Domain Services (AD DS) domains.
|
||||
|
||||
You might ask why you need to synchronize these identities. The answer is so that users will have a *single identity* that they can use to access their on-premises apps and cloud services that use Azure AD (such as Windows 10 Enterprise E3 or E5). This means that users can use their existing credentials to sign in to Azure AD and access the cloud services that you provide and manage for them.
|
||||
|
||||
**Figure 1** illustrates the integration between the on-premises AD DS domain with Azure AD. [Microsoft Azure Active Directory Connect](https://www.microsoft.com/en-us/download/details.aspx?id=47594) (Azure AD Connect) is responsible for synchronization of identities between the on-premises AD DS domain and Azure AD. Azure AD Connect is a service that you can install on-premises or in a virtual machine in Azure.
|
||||
**Figure 1** illustrates the integration between the on-premises AD DS domain with Azure AD. [Microsoft Azure Active Directory Connect](https://www.microsoft.com/download/details.aspx?id=47594) (Azure AD Connect) is responsible for synchronization of identities between the on-premises AD DS domain and Azure AD. Azure AD Connect is a service that you can install on-premises or in a virtual machine in Azure.
|
||||
|
||||

|
||||
|
||||
@ -194,7 +194,7 @@ If there are any problems with the Windows 10 Enterprise E3 or E5 license or th
|
||||
|
||||
## Virtual Desktop Access (VDA)
|
||||
|
||||
Subscriptions to Windows 10 Enterprise are also available for virtualized clients. Windows 10 Enterprise E3 and E5 are available for Virtual Desktop Access (VDA) in Windows Azure or in another [qualified multitenant hoster](https://www.microsoft.com/en-us/CloudandHosting/licensing_sca.aspx).
|
||||
Subscriptions to Windows 10 Enterprise are also available for virtualized clients. Windows 10 Enterprise E3 and E5 are available for Virtual Desktop Access (VDA) in Windows Azure or in another [qualified multitenant hoster](https://www.microsoft.com/CloudandHosting/licensing_sca.aspx).
|
||||
|
||||
Virtual machines (VMs) must be configured to enable Windows 10 Enterprise subscriptions for VDA. Active Directory-joined and Azure Active Directory-joined clients are supported. See [Enable VDA for Enterprise Subscription Activation](vda-subscription-activation.md).
|
||||
|
||||
|
@ -180,6 +180,6 @@ The following topics provide a change history for Windows 10 ITPro TechNet libra
|
||||
[Overview of Windows as a service](update/waas-overview.md)
|
||||
<BR>[Windows 10 deployment considerations](planning/windows-10-deployment-considerations.md)
|
||||
<BR>[Windows 10 release information](https://docs.microsoft.com/windows/windows-10/release-information)
|
||||
<BR>[Windows 10 Specifications & Systems Requirements](https://www.microsoft.com/en-us/windows/windows-10-specifications)
|
||||
<BR>[Windows 10 Specifications & Systems Requirements](https://www.microsoft.com/windows/windows-10-specifications)
|
||||
<BR>[Windows 10 upgrade paths](upgrade/windows-10-upgrade-paths.md)
|
||||
<BR>[Windows 10 deployment tools](windows-deployment-scenarios-and-tools.md)
|
||||
|
@ -452,5 +452,5 @@ To fix this issue, mount the Windows PE image (WIM), copy the missing file from
|
||||
## Related topics
|
||||
|
||||
[Windows 10 Enterprise system requirements](https://technet.microsoft.com/windows/dn798752.aspx)
|
||||
<BR>[Windows 10 Specifications](https://www.microsoft.com/en-us/windows/Windows-10-specifications)
|
||||
<BR>[Windows 10 Specifications](https://www.microsoft.com/windows/Windows-10-specifications)
|
||||
<BR>[Windows 10 IT pro forums](https://social.technet.microsoft.com/Forums/en-US/home?category=Windows10ITPro)
|
||||
|
@ -9,8 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -38,14 +38,11 @@ The following flowchart shows the steps for using the Compatibility Administrato
|
||||
|
||||

|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create and work with custom databases for 32-bit applications, and the 64-bit version to create and work with custom databases for 64-bit applications.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create and work with custom databases for 32-bit applications, and the 64-bit version to create and work with custom databases for 64-bit applications.
|
||||
|
||||
## In this section
|
||||
|
||||
|
||||
<table>
|
||||
<colgroup>
|
||||
<col width="50%" />
|
||||
@ -72,14 +69,3 @@ Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version o
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -102,8 +102,8 @@ If you decide to use the centralized compatibility-fix database deployment strat
|
||||
|
||||
5. The team that manages the centralized database opens Custom DB1 and uses the Compatibility Administrator to include the new compatibility fixes that were included in Custom DB2.
|
||||
|
||||
**Note**
|
||||
Custom DB1 contains a unique GUID that makes updating the database easier. For example, if you install a new version of the custom compatibility-fix database that uses the same GUID as the previous version, the computer will automatically uninstall the old version.
|
||||
> [!NOTE]
|
||||
> Custom DB1 contains a unique GUID that makes updating the database easier. For example, if you install a new version of the custom compatibility-fix database that uses the same GUID as the previous version, the computer will automatically uninstall the old version.
|
||||
|
||||
|
||||
|
||||
@ -123,23 +123,17 @@ In order to meet the two requirements above, we recommend that you use one of th
|
||||
|
||||
You can package your .sdb file and a custom deployment script into an .msi file, and then deploy the .msi file into your organization.
|
||||
|
||||
**Important**
|
||||
You must ensure that you mark your custom script so that it does not impersonate the calling user. For example, if you use Microsoft® Visual Basic® Scripting Edition (VBScript), the custom action type would be:
|
||||
> [!IMPORTANT]
|
||||
> You must ensure that you mark your custom script so that it does not impersonate the calling user. For example, if you use Microsoft® Visual Basic® Scripting Edition (VBScript), the custom action type would be:
|
||||
>`msidbCustomActionTypeVBScript + msidbCustomActionTypeInScript + msidbCustomActionTypeNoImpersonate = 0x0006 + 0x0400 + 0x0800 = 0x0C06 = 3078 decimal)`
|
||||
|
||||
|
||||
|
||||
~~~
|
||||
```
|
||||
msidbCustomActionTypeVBScript + msidbCustomActionTypeInScript + msidbCustomActionTypeNoImpersonate = 0x0006 + 0x0400 + 0x0800 = 0x0C06 = 3078 decimal)
|
||||
```
|
||||
~~~
|
||||
|
||||
- **Using a network share and a custom script**
|
||||
|
||||
You can store your .sdb file on your network share and then call to a script that resides on your specified computers.
|
||||
|
||||
**Important**
|
||||
You must ensure that you call the script at a time when it will receive elevated rights. For example, you should call the script by using computer startup scripts instead of a user logon script. You must also ensure that the installation of the custom compatibility-fix database occurs with Administrator rights.
|
||||
> [!IMPORTANT]
|
||||
> You must ensure that you call the script at a time when it will receive elevated rights. For example, you should call the script by using computer startup scripts instead of a user logon script. You must also ensure that the installation of the custom compatibility-fix database occurs with Administrator rights.
|
||||
|
||||
|
||||
|
||||
|
@ -9,7 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
ms.topic: article
|
||||
---
|
||||
@ -28,8 +29,8 @@ ms.topic: article
|
||||
|
||||
You can fix some compatibility issues that are due to the changes made between Windows operating system versions. These issues can include User Account Control (UAC) restrictions.
|
||||
|
||||
**Important**
|
||||
The Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator. You must use the 32-bit version for 32-bit applications and the 64-bit version to work for 64-bit applications. You will receive an error message if you try to use the wrong version.
|
||||
> [!IMPORTANT]
|
||||
> The Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator. You must use the 32-bit version for 32-bit applications and the 64-bit version to work for 64-bit applications. You will receive an error message if you try to use the wrong version.
|
||||
|
||||
If you start the Compatibility Administrator as an Administrator (with elevated privileges), all repaired applications can run successfully; however, virtualization and redirection might not occur as expected. To verify that a compatibility fix addresses an issue, you must test the repaired application by running it under the destination user account.
|
||||
|
||||
|
@ -9,8 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -19,39 +19,32 @@ ms.topic: article
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
|
||||
The Compatibility Administrator tool uses the term *fix* to describe the combination of compatibility information added to a customized database for a specific application. This combination can include single application fixes, groups of fixes that work together as a compatibility mode, and blocking and non-blocking AppHelp messages.
|
||||
|
||||
**Important**
|
||||
Fixes apply to a single application only; therefore, you must create multiple fixes if you need to fix the same issue in multiple applications.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Fixes apply to a single application only; therefore, you must create multiple fixes if you need to fix the same issue in multiple applications.
|
||||
|
||||
## What is a Compatibility Fix?
|
||||
|
||||
|
||||
A compatibility fix, previously known as a shim, is a small piece of code that intercepts API calls from applications. The fix transforms the API calls so that the current version of the operating system supports the application in the same way as previous versions of the operating system. This can mean anything from disabling a new feature in the current version of the operating system to emulating a particular behavior of an older version of the Windows API.
|
||||
|
||||
## Searching for Existing Compatibility Fixes
|
||||
|
||||
|
||||
The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new compatibility fix, you can search for an existing application and then copy and paste the known fixes into your customized database.
|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
|
||||
**To search for an existing application**
|
||||
|
||||
1. In the left-side pane of Compatibility Administrator, expand the **Applications** folder and search for your application name.
|
||||
|
||||
2. Click the application name to view the preloaded compatibility fixes, compatibility modes, or AppHelp messages.
|
||||
|
||||
## Creating a New Compatibility Fix
|
||||
@ -62,25 +55,13 @@ If you are unable to find a preloaded compatibility fix for your application, yo
|
||||
**To create a new compatibility fix**
|
||||
|
||||
1. In the left-side pane of Compatibility Administrator underneath the **Custom Databases** heading, right-click the name of the database to which you want to apply the compatibility fix, click **Create New**, and then click **Application Fix**.
|
||||
|
||||
2. Type the name of the application to which the compatibility fix applies, type the name of the application vendor, browse to the location of the application file (.exe) on your computer, and then click **Next**.
|
||||
|
||||
3. Select the operating system for which your compatibility fix applies, click any applicable compatibility modes to apply to your compatibility fix, and then click **Next**.
|
||||
|
||||
4. Select any additional compatibility fixes to apply to your compatibility fix, and then click **Next**.
|
||||
|
||||
5. Select any additional criteria to use to match your applications to the AppHelp message, and then click **Finish**.
|
||||
|
||||
By default, Compatibility Administrator selects the basic matching criteria for your application. As a best practice, use a limited set of matching information to represent your application, because it reduces the size of the database. However, make sure you have enough information to correctly identify your application.
|
||||
|
||||
## Related topics
|
||||
|
||||
[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -39,8 +39,8 @@ A compatibility mode is a group of compatibility fixes. A compatibility fix, pre
|
||||
|
||||
The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new compatibility mode, you can search for an existing application and then copy and paste the known fixes into your custom database.
|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
> [!IMPORTANT]
|
||||
> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
|
||||
|
||||
|
||||
@ -55,8 +55,8 @@ Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version o
|
||||
|
||||
If you are unable to find a preloaded compatibility mode for your application, you can create a new one for use by your custom database.
|
||||
|
||||
**Important**
|
||||
A compatibility mode includes a set of compatibility fixes and must be deployed as a group. Therefore, you should include only fixes that you intend to deploy together to the database.
|
||||
> [!IMPORTANT]
|
||||
> A compatibility mode includes a set of compatibility fixes and must be deployed as a group. Therefore, you should include only fixes that you intend to deploy together to the database.
|
||||
|
||||
|
||||
|
||||
|
@ -9,7 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
ms.topic: article
|
||||
---
|
||||
@ -40,8 +41,8 @@ A non-blocking AppHelp message does not prevent the application from starting, b
|
||||
|
||||
The Compatibility Administrator tool has preloaded fixes for many common applications, including known compatibility fixes, compatibility modes, and AppHelp messages. Before you create a new AppHelp message, you can search for an existing application and then copy and paste the known fixes into your custom database.
|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
> [!IMPORTANT]
|
||||
> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to create custom databases for 32-bit applications and the 64-bit version to create custom databases for 64-bit applications.
|
||||
|
||||
|
||||
|
||||
|
@ -10,7 +10,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: mobility
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -19,39 +20,29 @@ ms.topic: article
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 10
|
||||
|
||||
>[!IMPORTANT]
|
||||
>Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEMs.
|
||||
> [!IMPORTANT]
|
||||
> Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEMs.
|
||||
|
||||
From the start, Windows To Go was designed to minimize differences between the user experience of working on a laptop and Windows To Go booted from a USB drive. Given that Windows To Go was designed as an enterprise solution, extra consideration was given to the deployment workflows that enterprises already have in place. Additionally, there has been a focus on minimizing the number of differences in deployment between Windows To Go workspaces and laptop PCs.
|
||||
|
||||
**Note**
|
||||
Windows To Go does not support operating system upgrades. Windows To Go is designed as a feature that is managed centrally. IT departments that plan to transition from one operating system version to a later version will need to incorporate re-imaging their existing Windows To Go drives as part of their upgrade deployment process.
|
||||
|
||||
|
||||
> [!NOTE]
|
||||
> Windows To Go does not support operating system upgrades. Windows To Go is designed as a feature that is managed centrally. IT departments that plan to transition from one operating system version to a later version will need to incorporate re-imaging their existing Windows To Go drives as part of their upgrade deployment process.
|
||||
|
||||
The following sections discuss the boot experience, deployment methods, and tools that you can use with Windows To Go.
|
||||
|
||||
- [Initial boot experiences](#wtg-initboot)
|
||||
|
||||
- [Image deployment and drive provisioning considerations](#wtg-imagedep)
|
||||
|
||||
- [Application installation and domain join](#wtg-appinstall)
|
||||
|
||||
- [Management of Windows To Go using Group Policy](#bkmk-wtggp)
|
||||
|
||||
- [Supporting booting from USB](#wtg-bootusb)
|
||||
|
||||
- [Updating firmware](#stg-firmware)
|
||||
|
||||
- [Configure Windows To Go startup options](#wtg-startup)
|
||||
|
||||
- [Change firmware settings](#wtg-changefirmware)
|
||||
|
||||
## <a href="" id="wtg-initboot"></a>Initial boot experiences
|
||||
|
||||
|
||||
The following diagrams illustrate the two different methods you could use to provide Windows To Go drives to your users. The experiences differ depending on whether the user will be booting the device initially on-premises or off-premises:
|
||||
|
||||

|
||||
@ -62,33 +53,29 @@ When a Windows To Go workspace is first used at the workplace, the Windows To Go
|
||||
|
||||
When the Windows To Go workspace is going to be used first on an off-premises computer, such as one at the employee’s home, then the IT professional preparing the Windows To Go drives should configure the drive to be able to connect to organizational resources and to maintain the security of the workspace. In this situation, the Windows To Go workspace needs to be configured for offline domain join and BitLocker needs to be enabled before the workspace has been initialized.
|
||||
|
||||
**Tip**
|
||||
Applying BitLocker Drive Encryption to the drives before provisioning is a much faster process than encrypting the drives after data has already been stored on them due to a new feature called used-disk space only encryption. For more information, see [What's New in BitLocker](https://go.microsoft.com/fwlink/p/?LinkId=619076).
|
||||
|
||||
|
||||
> [!TIP]
|
||||
> Applying BitLocker Drive Encryption to the drives before provisioning is a much faster process than encrypting the drives after data has already been stored on them due to a new feature called used-disk space only encryption. For more information, see [What's New in BitLocker](https://go.microsoft.com/fwlink/p/?LinkId=619076).
|
||||
|
||||
DirectAccess can be used to ensure that the user can login with their domain credentials without needing a local account. For instructions on setting up a DirectAccess solution, for a small pilot deployment see [Deploy a Single Remote Access Server using the Getting Started Wizard](https://go.microsoft.com/fwlink/p/?LinkId=619077) for a larger scale deployment, see [Deploy Remote Access in an Enterprise](https://go.microsoft.com/fwlink/p/?LinkId=619078). If you do not want to use DirectAccess as an alternative users could log on using a local user account on the Windows To Go workspace and then use a virtual private network for remote access to your organizational network.
|
||||
|
||||
### <a href="" id="wtg-imagedep"></a>Image deployment and drive provisioning considerations
|
||||
|
||||
The Image Deployment process can be accomplished either by a centralized IT process for your organization or by individual users creating their own Windows To Go workspaces. You must have local Administrator access and access to a Windows 10 Enterprise or Windows 10 Education image to create a Windows To Go workspace, or you must be using System Center Configuration Manager 2012 Service Pack 1 or later to distribute Windows To Go workspaces to users. The image deployment process takes a blank USB drive and a Windows 10 Enterprise image (WIM) and turns it into a Windows To Go drive.
|
||||
The Image Deployment process can be accomplished either by a centralized IT process for your organization or by individual users creating their own Windows To Go workspaces. You must have local Administrator access and access to a Windows 10 Enterprise or Windows 10 Education image to create a Windows To Go workspace, or you must be using System Center Configuration Manager 2012 Service Pack 1 or later to distribute Windows To Go workspaces to users. The image deployment process takes a blank USB drive and a Windows 10 Enterprise image (WIM) and turns it into a Windows To Go drive.
|
||||
|
||||

|
||||
|
||||
The simplest way to provision a Windows To Go drive is to use the Windows To Go Creator. After a single Windows To Go workspace has been created, it can be duplicated as many times as necessary using widely available USB duplicator products as long as the device has not been booted. After the Windows To Go drive is initialized, it should not be duplicated. Alternatively, Windows To Go Workspace Creator can be run multiple times to create multiple Windows To Go drives.
|
||||
|
||||
**Tip**
|
||||
When you create your Windows To Go image use sysprep /generalize, just as you do when you deploy Windows 10 to a standard PC. In fact, if appropriate, use the same image for both deployments.
|
||||
|
||||
|
||||
> [!TIP]
|
||||
> When you create your Windows To Go image use sysprep /generalize, just as you do when you deploy Windows 10 to a standard PC. In fact, if appropriate, use the same image for both deployments.
|
||||
|
||||
**Driver considerations**
|
||||
|
||||
Windows includes most of the drivers that you will need to support a wide variety of host computers. However, you will occasionally need to download drivers from Windows Update to take advantage of the full functionality of a device. If you are using Windows To Go on a set of known host computers, you can add any additional drivers to the image used on Windows To Go to make Windows To Go drives more quickly usable by your employees. Especially ensure that network drivers are available so that the user can connect to Windows Update to get additional drivers if necessary.
|
||||
|
||||
Wi-Fi network adapter drivers are one of the most important drivers to make sure that you include in your standard image so that users can easily connect to the internet for any additional updates. IT administrators that are attempting to build Windows 10 images for use with Windows To Go should consider adding additional Wi-Fi drivers to their image to ensure that their users have the best chance of still having basic network connectivity when roaming between systems.
|
||||
Wi-Fi network adapter drivers are one of the most important drivers to make sure that you include in your standard image so that users can easily connect to the internet for any additional updates. IT administrators that are attempting to build Windows 10 images for use with Windows To Go should consider adding additional Wi-Fi drivers to their image to ensure that their users have the best chance of still having basic network connectivity when roaming between systems.
|
||||
|
||||
The following list of commonly used Wi-Fi network adapters that are not supported by the default drivers provided with Windows 10 is provided to help you ascertain whether or not you need to add drivers to your image.
|
||||
The following list of commonly used Wi-Fi network adapters that are not supported by the default drivers provided with Windows 10 is provided to help you ascertain whether or not you need to add drivers to your image.
|
||||
|
||||
<table>
|
||||
<colgroup>
|
||||
@ -230,8 +217,6 @@ The following list of commonly used Wi-Fi network adapters that are not supporte
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
IT administrators that want to target Windows To Go images for specific systems should test their images to ensure that the necessary system drivers are in the image, especially for critical functionality like Wi-Fi that is not supported by class drivers. Some consumer devices require OEM specific driver packages, which may not be available on Windows Update. For more information on how to add a driver to a Windows Image, please refer to the [Basic Windows Deployment Step-by-Step Guide](https://go.microsoft.com/fwlink/p/?LinkId=619079).
|
||||
|
||||
### <a href="" id="wtg-appinstall"></a>Application installation and domain join
|
||||
@ -242,7 +227,7 @@ Unless you are using a customized Windows image that includes unattended install
|
||||
|
||||
In general, management of Windows To Go workspaces is same as that for desktop and laptop computers. There are Windows To Go specific Group Policy settings that should be considered as part of Windows To Go deployment. Windows To Go Group Policy settings are located at `\\Computer Configuration\Administrative Templates\Windows Components\Portable Operating System\` in the Local Group Policy Editor.
|
||||
|
||||
The use of the Store on Windows To Go workspaces that are running Windows 8 can also be controlled by Group Policy. This policy setting is located at `\\Computer Configuration\Administrative Templates\Windows Components\Store\` in the Local Group Policy Editor. The policy settings have specific implications for Windows To Go that you should be aware of when planning your deployment:
|
||||
The use of the Store on Windows To Go workspaces that are running Windows 8 can also be controlled by Group Policy. This policy setting is located at `\\Computer Configuration\Administrative Templates\Windows Components\Store\` in the Local Group Policy Editor. The policy settings have specific implications for Windows To Go that you should be aware of when planning your deployment:
|
||||
|
||||
**Settings for workspaces**
|
||||
|
||||
@ -250,10 +235,8 @@ The use of the Store on Windows To Go workspaces that are running Windows 8 can
|
||||
|
||||
This policy setting specifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace. By default, hibernation is disabled when using Windows To Go workspace, so enabling this setting explicitly turns this ability back on. When a computer enters hibernation, the contents of memory are written to disk. When the disk is resumed, it is important that the hardware attached to the system, as well as the disk itself, are unchanged. This is inherently incompatible with roaming between PC hosts. Hibernation should only be used when the Windows To Go workspace is not being used to roam between host PCs.
|
||||
|
||||
**Important**
|
||||
For the host-PC to resume correctly when hibernation is enabled the Windows To Go workspace must continue to use the same USB port.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> For the host-PC to resume correctly when hibernation is enabled the Windows To Go workspace must continue to use the same USB port.
|
||||
|
||||
- **Disallow standby sleep states (S1-S3) when starting from a Windows To Go workspace**
|
||||
|
||||
@ -265,32 +248,27 @@ The use of the Store on Windows To Go workspaces that are running Windows 8 can
|
||||
|
||||
This policy setting controls whether the host computer will boot to Windows To Go if a USB device containing a Windows To Go workspace is connected, and controls whether users can make changes using the **Windows To Go Startup Options** settings dialog. If you enable this policy setting, booting to Windows To Go when a USB device is connected will be enabled and users will not be able to make changes using the **Windows To Go Startup Options** settings dialog. If you disable this policy setting, booting to Windows To Go when a USB device is connected will not be enabled unless a user configures the option manually in the firmware. If you do not configure this policy setting, users who are members of the local Administrators group can enable or disable booting from USB using the **Windows To Go Startup Options** settings dialog.
|
||||
|
||||
**Important**
|
||||
Enabling this policy setting will cause PCs running Windows to attempt to boot from any USB device that is inserted into the PC before it is started.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Enabling this policy setting will cause PCs running Windows to attempt to boot from any USB device that is inserted into the PC before it is started.
|
||||
|
||||
## <a href="" id="wtg-bootusb"></a>Supporting booting from USB
|
||||
|
||||
|
||||
The biggest hurdle for a user wanting to use Windows To Go is configuring their computer to boot from USB. This is traditionally done by entering the firmware and configuring the appropriate boot order options. To ease the process of making the firmware modifications required for Windows To Go, Windows includes a feature named **Windows To Go Startup Options** that allows a user to configure their computer to boot from USB from within Windows—without ever entering their firmware, as long as their firmware supports booting from USB.
|
||||
|
||||
**Note**
|
||||
Enabling a system to always boot from USB first has implications that you should consider. For example, a USB device that includes malware could be booted inadvertently to compromise the system, or multiple USB drives could be plugged in to cause a boot conflict. For this reason, the Windows To Go startup options are disabled by default. In addition, administrator privileges are required to configure Windows To Go startup options.
|
||||
> [!NOTE]
|
||||
> Enabling a system to always boot from USB first has implications that you should consider. For example, a USB device that includes malware could be booted inadvertently to compromise the system, or multiple USB drives could be plugged in to cause a boot conflict. For this reason, the Windows To Go startup options are disabled by default. In addition, administrator privileges are required to configure Windows To Go startup options.
|
||||
|
||||
|
||||
|
||||
If you are going to be using a Windows 7 computer as a host-PC, see the wiki article [Tips for configuring your BIOS settings to work with Windows To Go](https://go.microsoft.com/fwlink/p/?LinkID=618951).
|
||||
If you are going to be using a Windows 7 computer as a host-PC, see the wiki article [Tips for configuring your BIOS settings to work with Windows To Go](https://go.microsoft.com/fwlink/p/?LinkID=618951).
|
||||
|
||||
### <a href="" id="stg-firmware"></a>Roaming between different firmware types
|
||||
|
||||
Windows supports two types of PC firmware: Unified Extensible Firmware Interface (UEFI), which is the new standard, and legacy BIOS firmware, which was used in most PCs shipping with Windows 7 or earlier version of Windows. Each firmware type has completely different Windows boot components that are incompatible with each other. Beyond the different boot components, Windows supports different partition styles and layout requirements for each type of firmware as shown in the following diagrams.
|
||||
Windows supports two types of PC firmware: Unified Extensible Firmware Interface (UEFI), which is the new standard, and legacy BIOS firmware, which was used in most PCs shipping with Windows 7 or earlier version of Windows. Each firmware type has completely different Windows boot components that are incompatible with each other. Beyond the different boot components, Windows supports different partition styles and layout requirements for each type of firmware as shown in the following diagrams.
|
||||
|
||||

|
||||
|
||||
This presented a unique challenge for Windows To Go because the firmware type is not easily determined by end-users—a UEFI computer looks just like a legacy BIOS computer and Windows To Go must boot on both types of firmware.
|
||||
|
||||
To enable booting Windows To Go on both types of firmware, a new disk layout is provided for Windows 8 or later that contains both sets of boot components on a FAT32 system partition and a new command-line option was added to bcdboot.exe to support this configuration. The **/f** option is used with the **bcdboot /s** command to specify the firmware type of the target system partition by appending either **UEFI**, **BIOS** or **ALL**. When creating Windows To Go drives manually you must use the **ALL** parameter to provide the Windows To Go drive the ability to boot on both types of firmware. For example, on volume H: (your Windows To Go USB drive letter), you would use the command **bcdboot C:\\windows /s H: /f ALL**. The following diagram illustrates the disk layout that results from that command:
|
||||
To enable booting Windows To Go on both types of firmware, a new disk layout is provided for Windows 8 or later that contains both sets of boot components on a FAT32 system partition and a new command-line option was added to bcdboot.exe to support this configuration. The **/f** option is used with the **bcdboot /s** command to specify the firmware type of the target system partition by appending either **UEFI**, **BIOS** or **ALL**. When creating Windows To Go drives manually you must use the **ALL** parameter to provide the Windows To Go drive the ability to boot on both types of firmware. For example, on volume H: (your Windows To Go USB drive letter), you would use the command **bcdboot C:\\windows /s H: /f ALL**. The following diagram illustrates the disk layout that results from that command:
|
||||
|
||||

|
||||
|
||||
@ -298,7 +276,7 @@ This is the only supported disk configuration for Windows To Go. With this disk
|
||||
|
||||
### <a href="" id="wtg-startup"></a>Configure Windows To Go startup options
|
||||
|
||||
Windows To Go Startup Options is a setting available on Windows 10-based PCs that enables the computer to be booted from a USB without manually changing the firmware settings of the PC. To configure Windows To Go Startup Options you must have administrative rights on the computer and the **Windows To Go Default Startup Options** Group Policy setting must not be configured.
|
||||
Windows To Go Startup Options is a setting available on Windows 10-based PCs that enables the computer to be booted from a USB without manually changing the firmware settings of the PC. To configure Windows To Go Startup Options you must have administrative rights on the computer and the **Windows To Go Default Startup Options** Group Policy setting must not be configured.
|
||||
|
||||
**To configure Windows To Go startup options**
|
||||
|
||||
@ -308,33 +286,19 @@ Windows To Go Startup Options is a setting available on Windows 10-based PCs th
|
||||
|
||||
2. Select **Yes** to enable the startup options.
|
||||
|
||||
**Tip**
|
||||
If your computer is part of a domain, the Group Policy setting can be used to enable the startup options instead of the dialog.
|
||||
|
||||
> [!TIP]
|
||||
> If your computer is part of a domain, the Group Policy setting can be used to enable the startup options instead of the dialog.
|
||||
|
||||
|
||||
3. Click **Save Changes**. If the User Account Control dialog box is displayed, confirm that the action it displays is what you want, and then click **Yes**.
|
||||
|
||||
### <a href="" id="wtg-changefirmware"></a>Change firmware settings
|
||||
|
||||
If you choose to not use the Windows To Go startup options or are using a PC running Windows 7 as your host computer you will need to manually configure the firmware settings. The process used to accomplish this will depend on the firmware type and manufacturer. If your host computer is protected by BitLocker and running Windows 7 you should suspend BitLocker before making the change to the firmware settings. After the firmware settings have been successfully reconfigured, resume BitLocker protection. If you do not suspend BitLocker first, BitLocker will assume that the computer has been tampered with and will boot into BitLocker recovery mode.
|
||||
If you choose to not use the Windows To Go startup options or are using a PC running Windows 7 as your host computer you will need to manually configure the firmware settings. The process used to accomplish this will depend on the firmware type and manufacturer. If your host computer is protected by BitLocker and running Windows 7 you should suspend BitLocker before making the change to the firmware settings. After the firmware settings have been successfully reconfigured, resume BitLocker protection. If you do not suspend BitLocker first, BitLocker will assume that the computer has been tampered with and will boot into BitLocker recovery mode.
|
||||
|
||||
## Related topics
|
||||
|
||||
|
||||
[Windows To Go: feature overview](windows-to-go-overview.md)
|
||||
|
||||
[Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md)
|
||||
|
||||
[Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md)
|
||||
|
||||
[Windows To Go: feature overview](windows-to-go-overview.md)<br>
|
||||
[Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md)<br>
|
||||
[Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md)<br>
|
||||
[Windows To Go: frequently asked questions](windows-to-go-frequently-asked-questions.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -9,8 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -30,11 +30,10 @@ You can disable and enable individual compatibility fixes in your customized dat
|
||||
|
||||
## Disabling Compatibility Fixes
|
||||
|
||||
|
||||
Customized compatibility databases can become quite complex as you add your fixes for the multiple applications found in your organization. Over time, you may find you need to disable a particular fix in your customized database. For example, if a software vendor releases a fix for an issue addressed in one of your compatibility fixes, you must validate that the vendor's fix is correct and that it resolves your issue. To do this, you must temporarily disable the compatibility fix and then test your application.
|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications.
|
||||
>[!IMPORTANT]
|
||||
>Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications.
|
||||
|
||||
|
||||
|
||||
@ -65,4 +64,5 @@ You can enable your disabled compatibility fixes at any time.
|
||||
2. On the **Database** menu, click **Enable Entry**.
|
||||
|
||||
## Related topics
|
||||
|
||||
[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md)
|
||||
|
@ -9,7 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
ms.topic: article
|
||||
---
|
||||
@ -30,8 +31,8 @@ The Compatibility Administrator tool enables the creation and the use of custom-
|
||||
|
||||
By default, the Windows® operating system installs a System Application Fix database for use with the Compatibility Administrator. This database can be updated through Windows Update, and is stored in the %WINDIR% \\AppPatch directory. Your custom databases are automatically stored in the %WINDIR% \\AppPatch\\Custom directory and are installed by using the Sdbinst.exe tool provided with the Compatibility Administrator.
|
||||
|
||||
**Important**
|
||||
Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications.
|
||||
> [!IMPORTANT]
|
||||
> Application Compatibility Toolkit (ACT) installs a 32-bit and a 64-bit version of the Compatibility Administrator tool. You must use the 32-bit version to work with custom databases for 32-bit applications and the 64-bit version to work with custom databases for 64-bit applications.
|
||||
|
||||
In addition, you must deploy your databases to your organization’s computers before the included fixes will have any effect on the application issue. For more information about deploying your database, see [Using the Sdbinst.exe Command-Line Tool](using-the-sdbinstexe-command-line-tool.md).
|
||||
|
||||
|
@ -10,7 +10,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: mobility
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -58,8 +59,8 @@ The following scenarios are examples of situations in which Windows To Go worksp
|
||||
|
||||
- **Travel lightly.** In this situation you have employees who are moving from site to site, but who always will have access to a compatible host computer on site. Using Windows To Go workspaces allows them to travel without the need to pack their PC.
|
||||
|
||||
**Note**
|
||||
If the employee wants to work offline for the majority of the time, but still maintain the ability to use the drive on the enterprise network, they should be informed of how often the Windows To Go workspace needs to be connected to the enterprise network. Doing so will ensure that the drive retains its access privileges and the workspace’s computer object is not potentially deleted from Active Directory Domain Services (AD DS).
|
||||
> [!NOTE]
|
||||
> If the employee wants to work offline for the majority of the time, but still maintain the ability to use the drive on the enterprise network, they should be informed of how often the Windows To Go workspace needs to be connected to the enterprise network. Doing so will ensure that the drive retains its access privileges and the workspace’s computer object is not potentially deleted from Active Directory Domain Services (AD DS).
|
||||
|
||||
|
||||
|
||||
@ -77,8 +78,8 @@ Microsoft software, such as Microsoft Office, distributed to a Windows To Go wor
|
||||
|
||||
You should investigate other software manufacturer’s licensing requirements to ensure they are compatible with roaming usage before deploying them to a Windows To Go workspace.
|
||||
|
||||
**Note**
|
||||
Using Multiple Activation Key (MAK) activation is not a supported activation method for Windows To Go as each different PC-host would require separate activation. MAK activation should not be used for activating Windows, Office, or any other application on a Windows To Go drive.
|
||||
> [!NOTE]
|
||||
> Using Multiple Activation Key (MAK) activation is not a supported activation method for Windows To Go as each different PC-host would require separate activation. MAK activation should not be used for activating Windows, Office, or any other application on a Windows To Go drive.
|
||||
|
||||
|
||||
|
||||
|
@ -9,7 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
ms.topic: article
|
||||
---
|
||||
@ -32,9 +33,8 @@ The **Query Compatibility Databases** tool provides additional search options. F
|
||||
|
||||
## Searching for Previously Applied Compatibility Fixes
|
||||
|
||||
|
||||
**Important**
|
||||
You must perform your search with the correct version of the Compatibility Administrator tool. If you are searching for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. If you are searching for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator.
|
||||
> [!IMPORTANT]
|
||||
> You must perform your search with the correct version of the Compatibility Administrator tool. If you are searching for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. If you are searching for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator.
|
||||
|
||||
|
||||
|
||||
|
@ -9,8 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -19,33 +19,33 @@ ms.topic: article
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
|
||||
You can access the Query tool from within Compatibility Administrator. The Query tool provides the same functionality as using the Search feature.
|
||||
|
||||
For information about the Search feature, see [Searching for Fixed Applications in Compatibility Administrator](searching-for-fixed-applications-in-compatibility-administrator.md). However, the Query tool provides more detailed search criteria, including tabs that enable you to search the program properties, the compatibility fix properties, and the fix description. You can perform a search by using SQL SELECT and WHERE clauses, in addition to searching specific types of databases.
|
||||
|
||||
**Important**
|
||||
You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator.
|
||||
|
||||
|
||||
<<<<<<< HEAD
|
||||
> [!IMPORTANT]
|
||||
> You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator.
|
||||
=======
|
||||
>[!IMPORTANT]
|
||||
>You must perform your search with the correct version of the Compatibility Administrator tool. To use the Query tool to search for a 32-bit custom database, you must use the 32-bit version of Compatibility Administrator. To use the Query tool to search for a 64-bit custom database, you must use the 64-bit version of Compatibility Administrator.
|
||||
>>>>>>> bfaab3359a63dde24e6d0dca11b841e045c481f6
|
||||
|
||||
## Querying by Using the Program Properties Tab
|
||||
|
||||
|
||||
You can use the **Program Properties** tab of the Query tool to search for any compatibility fix, compatibility mode, or AppHelp for a specific application.
|
||||
|
||||
**To query by using the Program Properties tab**
|
||||
|
||||
1. On the Compatibility Administrator toolbar, click **Query**.
|
||||
|
||||
2. In the **Look in** drop-down list, select the appropriate database type to search.
|
||||
|
||||
3. Type the location of the application you are searching for into the **Search for the Application** field.
|
||||
|
||||
This name should be the same as the name in the **Applications** area (left pane) of Compatibility Administrator.
|
||||
@ -57,15 +57,11 @@ You can use the **Program Properties** tab of the Query tool to search for any c
|
||||
5. Optionally, select the check box for one of the following types of compatibility fix:
|
||||
|
||||
- **Compatibility Modes**
|
||||
|
||||
- **Compatibility Fixes**
|
||||
|
||||
- **Application Helps**
|
||||
|
||||
**Important**
|
||||
If you do not select any of the check boxes, the search will look for all types of compatibility fixes. Do not select multiple check boxes because only applications that match all of the requirements will appear.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you do not select any of the check boxes, the search will look for all types of compatibility fixes. Do not select multiple check boxes because only applications that match all of the requirements will appear.
|
||||
|
||||
6. Click **Find Now**.
|
||||
|
||||
@ -79,24 +75,17 @@ You can use the **Fix Properties** tab of the Query tool to search for any appli
|
||||
**To query by using the Fix Properties tab**
|
||||
|
||||
1. On the Compatibility Administrator toolbar, click **Query**.
|
||||
|
||||
2. Click the **Fix Properties** tab.
|
||||
|
||||
3. In the **Look in** drop-down list, select the appropriate database type to search.
|
||||
|
||||
4. Type the name of the compatibility fix or compatibility mode into the **Search for programs fixed using** field.
|
||||
|
||||
**Note**
|
||||
You can use the percent (%) symbol as a wildcard in your fix-properties query, as a substitute for any string of zero or more characters.
|
||||
|
||||
|
||||
>[!NOTE]
|
||||
>You can use the percent (%) symbol as a wildcard in your fix-properties query, as a substitute for any string of zero or more characters
|
||||
|
||||
5. Select the check box for either **Search in Compatibility Fixes** or **Search in Compatibility Modes**.
|
||||
|
||||
**Important**
|
||||
Your text must match the type of compatibility fix or mode for which you are performing the query. For example, entering the name of a compatibility fix and selecting the compatibility mode check box will not return any results. Additionally, if you select both check boxes, the query will search for the fix by compatibility mode and compatibility fix. Only applications that match both requirements appear.
|
||||
|
||||
|
||||
>[!IMPORTANT]
|
||||
>Your text must match the type of compatibility fix or mode for which you are performing the query. For example, entering the name of a compatibility fix and selecting the compatibility mode check box will not return any results. Additionally, if you select both check boxes, the query will search for the fix by compatibility mode and compatibility fix. Only applications that match both requirements appear.
|
||||
|
||||
6. Click **Find Now**.
|
||||
|
||||
@ -104,26 +93,19 @@ You can use the **Fix Properties** tab of the Query tool to search for any appli
|
||||
|
||||
## Querying by Using the Fix Description Tab
|
||||
|
||||
|
||||
You can use the **Fix Description** tab of the Query tool to add parameters that enable you to search your compatibility databases by application title or solution description text.
|
||||
|
||||
**To query by using the Fix Description tab**
|
||||
|
||||
1. On the Compatibility Administrator toolbar, click **Query**.
|
||||
|
||||
2. Click the **Fix Description** tab.
|
||||
|
||||
3. In the **Look in** drop-down list, select the appropriate database type to search.
|
||||
|
||||
4. Type your search keywords into the box **Words to look for**. Use commas to separate multiple keywords.
|
||||
|
||||
**Important**
|
||||
You cannot use wildcards as part of the Fix Description search query because the default behavior is to search for any entry that meets your search criteria.
|
||||
|
||||
|
||||
>[!IMPORTANT]
|
||||
>You cannot use wildcards as part of the Fix Description search query because the default behavior is to search for any entry that meets your search criteria.
|
||||
|
||||
5. Refine your search by selecting **Match any word** or **Match all words** from the drop-down list.
|
||||
|
||||
6. Click **Find Now**.
|
||||
|
||||
The query runs and the results of the query are displayed in the lower pane.
|
||||
@ -136,11 +118,8 @@ You can use the **Fix Description** tab of the Query tool to add additional SQL
|
||||
**To query by using the Advanced tab**
|
||||
|
||||
1. On the Compatibility Administrator toolbar, click **Query**.
|
||||
|
||||
2. Click the **Advanced** tab.
|
||||
|
||||
3. In the **Look in** drop-down list, select the appropriate database type to search.
|
||||
|
||||
4. Select the appropriate SELECT clause for your search from the **Select clauses** box. For example, **APP\_NAME**.
|
||||
|
||||
The **APP\_NAME** clause appears in the **SELECT** field. You can add as many additional clauses as you require. They will appear as columns in your search results.
|
||||
@ -171,13 +150,5 @@ You can export any of your search results into a tab-delimited text (.txt) file
|
||||
2. Browse to the location where you intend to store the search results file, and then click **Save**.
|
||||
|
||||
## Related topics
|
||||
|
||||
[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -9,7 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
ms.topic: article
|
||||
---
|
||||
@ -71,8 +72,8 @@ At this point, you probably cannot resolve any unresolved application compatibil
|
||||
|
||||
- Apply specific compatibility modes, or run the program as an Administrator, by using the Compatibility Administrator tool.
|
||||
|
||||
**Note**
|
||||
For more information about using Compatibility Administrator to apply compatibility fixes and compatibility modes, see [Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md).
|
||||
> [!NOTE]
|
||||
> For more information about using Compatibility Administrator to apply compatibility fixes and compatibility modes, see [Using the Compatibility Administrator Tool](using-the-compatibility-administrator-tool.md).
|
||||
|
||||
|
||||
|
||||
|
@ -9,28 +9,26 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Understanding and Using Compatibility Fixes
|
||||
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
- Windows 10
|
||||
- Windows 8.1
|
||||
- Windows 8
|
||||
- Windows 7
|
||||
- Windows Server 2012
|
||||
- Windows Server 2008 R2
|
||||
|
||||
As the Windows operating system evolves to support new technology and functionality, the implementations of some functions may change. This can cause problems for applications that relied upon the original implementation. You can avoid compatibility issues by using the Microsoft Windows Application Compatibility (Compatibility Fix) infrastructure to create a specific application fix for a particular version of an application.
|
||||
|
||||
## How the Compatibility Fix Infrastructure Works
|
||||
|
||||
|
||||
The Compatibility Fix infrastructure uses the linking ability of APIs to redirect an application from Windows code directly to alternative code that implements the compatibility fix.
|
||||
|
||||
The Windows Portable Executable File Format includes headers that contain the data directories that are used to provide a layer of indirection between the application and the linked file. API calls to the external binary files take place through the Import Address Table (IAT), which then directly calls the Windows operating system, as shown in the following figure.
|
||||
@ -41,14 +39,13 @@ Specifically, the process modifies the address of the affected Windows function
|
||||
|
||||

|
||||
|
||||
**Note**
|
||||
For statically linked DLLs, the code redirection occurs as the application loads. You can also fix dynamically linked DLLs by hooking into the GetProcAddress API.
|
||||
>[!NOTE]
|
||||
>For statically linked DLLs, the code redirection occurs as the application loads. You can also fix dynamically linked DLLs by hooking into the GetProcAddress API.
|
||||
|
||||
|
||||
|
||||
## Design Implications of the Compatibility Fix Infrastructure
|
||||
|
||||
|
||||
There are important considerations to keep in mind when determining your application fix strategy, due to certain characteristics of the Compatibility Fix infrastructure.
|
||||
|
||||
- The compatibility fix is not part of the Windows operating system (as shown in the previous figure). Therefore, the same security restrictions apply to the compatibility fix as apply to the application code, which means that you cannot use compatibility fixes to bypass any of the security mechanisms of the operating system. Therefore, compatibility fixes do not increase your security exposure, nor do you need to lower your security settings to accommodate compatibility fixes.
|
||||
@ -57,14 +54,11 @@ There are important considerations to keep in mind when determining your applica
|
||||
|
||||
- The compatibility fixes run as user-mode code inside of a user-mode application process. This means that you cannot use a compatibility fix to fix kernel-mode code issues. For example, you cannot use a compatibility fix to resolve device-driver issues.
|
||||
|
||||
**Note**
|
||||
Some antivirus, firewall, and anti-spyware code runs in kernel mode.
|
||||
|
||||
|
||||
> [!NOTE]
|
||||
> Some antivirus, firewall, and anti-spyware code runs in kernel mode.
|
||||
|
||||
## Determining When to Use a Compatibility Fix
|
||||
|
||||
|
||||
The decision to use compatibility fixes to remedy your compatibility issues may involve more than just technical issues. The following scenarios reflect other common reasons for using a compatibility fix.
|
||||
|
||||
### Scenario 1
|
||||
@ -87,15 +81,14 @@ In the situation where an application is either unimportant to your organization
|
||||
|
||||
## Determining Which Version of an Application to Fix
|
||||
|
||||
|
||||
You can apply a compatibility fix to a particular version of an application, either by using the "up to or including" clause or by selecting that specific version. This means that the next version of the application will not have the compatibility fix automatically applied. This is important, because it allows you to continue to use your application, but it also encourages the vendor to fix the application.
|
||||
|
||||
## Support for Compatibility Fixes
|
||||
|
||||
|
||||
Compatibility fixes are shipped as part of the Windows operating system and are updated by using Windows Update. Therefore, they receive the same level of support as Windows itself.
|
||||
|
||||
You can apply the compatibility fixes to any of your applications. However, Microsoft does not provide the tools to use the Compatibility Fix infrastructure to create your own custom fixes.
|
||||
|
||||
## Related topics
|
||||
|
||||
[Managing Application-Compatibility Fixes and Custom Fix Databases](managing-application-compatibility-fixes-and-custom-fix-databases.md)
|
||||
|
@ -9,8 +9,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.pagetype: appcompat
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
ms.date: 04/19/2017
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -28,8 +28,8 @@ ms.topic: article
|
||||
|
||||
The **Events** screen enables you to record and to view your activities in the Compatibility Administrator tool, provided that the screen is open while you perform the activities.
|
||||
|
||||
**Important**
|
||||
The **Events** screen only records your activities when the screen is open. If you perform an action before opening the **Events** screen, the action will not appear in the list.
|
||||
>[!IMPORTANT]
|
||||
>The **Events** screen only records your activities when the screen is open. If you perform an action before opening the **Events** screen, the action will not appear in the list.
|
||||
|
||||
|
||||
|
||||
@ -45,15 +45,5 @@ Compatibility Administrator enables you to copy your compatibility fixes from on
|
||||
If you open the **Events** screen and then perform the copy operation, you can see a description of the action, along with the time stamp, which enables you to view your fix information without confusion.
|
||||
|
||||
## Related topics
|
||||
[Creating a Custom Compatibility Mode in Compatibility Administrator](creating-a-custom-compatibility-mode-in-compatibility-administrator.md)
|
||||
|
||||
[Creating a Custom Compatibility Mode in Compatibility Administrator](creating-a-custom-compatibility-mode-in-compatibility-administrator.md)<br>
|
||||
[Compatibility Administrator User's Guide](compatibility-administrator-users-guide.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
@ -5,7 +5,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.localizationpriority: medium
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
manager: laurawi
|
||||
ms.author: greglin
|
||||
ms.topic: article
|
||||
@ -16,7 +17,8 @@ ms.topic: article
|
||||
|
||||
Each version of Windows 10 adds new features and functionality; occasionally we also remove features and functionality, often because we've added a better option. Below are the details about the features and functionalities that we removed in Windows 10, version 1903. **The list below is subject to change and might not include every affected feature or functionality.**
|
||||
|
||||
**Note**: Join the [Windows Insider program](https://insider.windows.com) to get early access to new Windows 10 builds and test these changes yourself.
|
||||
> [!NOTE]
|
||||
> Join the [Windows Insider program](https://insider.windows.com) to get early access to new Windows 10 builds and test these changes yourself.
|
||||
|
||||
## Features we removed or will remove soon
|
||||
|
||||
|
@ -23,7 +23,7 @@ Get answers to common questions around compatibility, installation, and support
|
||||
|
||||
### Where can I download Windows 10 Enterprise?
|
||||
|
||||
If you have Windows volume licenses with Software Assurance, or if you have purchased licenses for Windows 10 Enterprise volume licenses, you can download 32-bit and 64-bit versions of Windows 10 Enterprise from the [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx). If you do not have current Software Assurance for Windows and would like to purchase volume licenses for Windows 10 Enterprise, contact your preferred Microsoft Reseller or see [How to purchase through Volume Licensing](https://www.microsoft.com/en-us/Licensing/how-to-buy/how-to-buy.aspx).
|
||||
If you have Windows volume licenses with Software Assurance, or if you have purchased licenses for Windows 10 Enterprise volume licenses, you can download 32-bit and 64-bit versions of Windows 10 Enterprise from the [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx). If you do not have current Software Assurance for Windows and would like to purchase volume licenses for Windows 10 Enterprise, contact your preferred Microsoft Reseller or see [How to purchase through Volume Licensing](https://www.microsoft.com/Licensing/how-to-buy/how-to-buy.aspx).
|
||||
|
||||
### What are the system requirements?
|
||||
|
||||
@ -35,7 +35,7 @@ Most computers that are compatible with Windows 8.1 will be compatible with Wind
|
||||
|
||||
### Can I evaluate Windows 10 Enterprise?
|
||||
|
||||
Yes, a 90-day evaluation of Windows 10 Enterprise is available through the [TechNet Evaluation Center](https://www.microsoft.com/en-us/evalcenter/evaluate-windows-10-enterprise). The evaluation is available in Chinese (Simplified), Chinese (Traditional), French, German, Italian, Japanese, Korean, Portuguese (Brazil), and Spanish (Spain, International Sort). We highly recommend that organizations make use of the Windows 10 Enterprise 90-day Evaluation to try out deployment and management scenarios, test compatibility with hardware and applications, and to get hands on experience with Windows 10 Enterprise features.
|
||||
Yes, a 90-day evaluation of Windows 10 Enterprise is available through the [TechNet Evaluation Center](https://www.microsoft.com/evalcenter/evaluate-windows-10-enterprise). The evaluation is available in Chinese (Simplified), Chinese (Traditional), French, German, Italian, Japanese, Korean, Portuguese (Brazil), and Spanish (Spain, International Sort). We highly recommend that organizations make use of the Windows 10 Enterprise 90-day Evaluation to try out deployment and management scenarios, test compatibility with hardware and applications, and to get hands on experience with Windows 10 Enterprise features.
|
||||
|
||||
## Drivers and compatibility
|
||||
|
||||
@ -56,7 +56,7 @@ Many existing Win32 and Win64 applications already run reliably on Windows 10 wi
|
||||
|
||||
### Is there an easy way to assess if my organization’s devices are ready to upgrade to Windows 10?
|
||||
|
||||
[Windows Analytics Upgrade Readiness](https://technet.microsoft.com/itpro/windows/deploy/manage-windows-upgrades-with-upgrade-analytics) (formerly known as Upgrade Analytics) provides powerful insights and recommendations about the computers, applications, and drivers in your organization, at no extra cost and without additional infrastructure requirements. This new service guides you through your upgrade and feature update projects using a workflow based on Microsoft recommended practices. Up-to-date inventory data allows you to balance cost and risk in your upgrade projects. You can find additional product information at [Windows Analytics](https://www.microsoft.com/en-us/WindowsForBusiness/Windows-Analytics).
|
||||
[Windows Analytics Upgrade Readiness](https://technet.microsoft.com/itpro/windows/deploy/manage-windows-upgrades-with-upgrade-analytics) (formerly known as Upgrade Analytics) provides powerful insights and recommendations about the computers, applications, and drivers in your organization, at no extra cost and without additional infrastructure requirements. This new service guides you through your upgrade and feature update projects using a workflow based on Microsoft recommended practices. Up-to-date inventory data allows you to balance cost and risk in your upgrade projects. You can find additional product information at [Windows Analytics](https://www.microsoft.com/WindowsForBusiness/Windows-Analytics).
|
||||
|
||||
## Administration and deployment
|
||||
|
||||
|
@ -10,7 +10,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: plan
|
||||
ms.localizationpriority: medium
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -48,7 +49,8 @@ For System Center Configuration Manager, Windows 10 support is offered with var
|
||||
| System Center Configuration Manager 2012 R2 | Yes, with SP1 and CU1 | Yes, with SP1, CU1, and the ADK for Windows 10 |
|
||||
|
||||
|
||||
>Note: Configuration Manager 2012 supports Windows 10 version 1507 (build 10.0.10240) and 1511 (build 10.0.10586) for the lifecycle of these builds. Future releases of Windows 10 CB/CBB are not supported With Configuration Manager 2012, and will require System Center Configuration Manager current branch for supported management.
|
||||
> [!NOTE]
|
||||
> Configuration Manager 2012 supports Windows 10 version 1507 (build 10.0.10240) and 1511 (build 10.0.10586) for the lifecycle of these builds. Future releases of Windows 10 CB/CBB are not supported With Configuration Manager 2012, and will require System Center Configuration Manager current branch for supported management.
|
||||
|
||||
|
||||
For more details about System Center Configuration Manager support for Windows 10, see [Deploy Windows 10 with System Center 2012 R2 Configuration Manager](../deploy-windows-sccm/deploy-windows-10-with-system-center-2012-r2-configuration-manager.md).
|
||||
|
@ -10,7 +10,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.pagetype: mobility
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -180,8 +181,8 @@ Press **Windows logo key+W** and then search for **Windows To Go startup options
|
||||
|
||||
In the **Windows To Go Startup Options** dialog box select **Yes** and then click **Save Changes** to configure the computer to boot from USB.
|
||||
|
||||
**Note**
|
||||
Your IT department can use Group Policy to configure Windows To Go Startup Options in your organization.
|
||||
> [!NOTE]
|
||||
> Your IT department can use Group Policy to configure Windows To Go Startup Options in your organization.
|
||||
|
||||
|
||||
|
||||
@ -400,8 +401,8 @@ You can reset the BitLocker system measurements to incorporate the new boot orde
|
||||
|
||||
The host computer will now be able to be booted from a USB drive without triggering recovery mode.
|
||||
|
||||
**Note**
|
||||
The default BitLocker protection profile in Windows 8 or later does not monitor the boot order.
|
||||
> [!NOTE]
|
||||
> The default BitLocker protection profile in Windows 8 or later does not monitor the boot order.
|
||||
|
||||
|
||||
|
||||
@ -412,8 +413,8 @@ Reformatting the drive erases the data on the drive, but doesn’t reconfigure t
|
||||
|
||||
1. Open a command prompt with full administrator permissions.
|
||||
|
||||
**Note**
|
||||
If your user account is a member of the Administrators group, but is not the Administrator account itself, then, by default, the programs that you run only have standard user permissions unless you explicitly choose to elevate them.
|
||||
> [!NOTE]
|
||||
> If your user account is a member of the Administrators group, but is not the Administrator account itself, then, by default, the programs that you run only have standard user permissions unless you explicitly choose to elevate them.
|
||||
|
||||
|
||||
|
||||
|
@ -10,7 +10,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.pagetype: mobility, edu
|
||||
ms.sitesec: library
|
||||
audience: itpro
author: greg-lindsay
|
||||
audience: itpro
|
||||
author: greg-lindsay
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
@ -19,60 +20,48 @@ ms.topic: article
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 10
|
||||
|
||||
>[!IMPORTANT]
|
||||
>Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEMs.
|
||||
> [!IMPORTANT]
|
||||
> Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEMs.
|
||||
|
||||
Windows To Go is a feature in Windows 10 Enterprise and Windows 10 Education that enables the creation of a Windows To Go workspace that can be booted from a USB-connected external drive on PCs.
|
||||
Windows To Go is a feature in Windows 10 Enterprise and Windows 10 Education that enables the creation of a Windows To Go workspace that can be booted from a USB-connected external drive on PCs.
|
||||
|
||||
PCs that meet the Windows 7 or later [certification requirements](https://go.microsoft.com/fwlink/p/?LinkId=618711) can run Windows 10 in a Windows To Go workspace, regardless of the operating system running on the PC. Windows To Go workspaces can use the same image enterprises use for their desktops and laptops and can be managed the same way. Windows To Go is not intended to replace desktops, laptops or supplant other mobility offerings. Rather, it provides support for efficient use of resources for alternative workplace scenarios. There are some additional considerations that you should keep in mind before you start to use Windows To Go:
|
||||
PCs that meet the Windows 7 or later [certification requirements](https://go.microsoft.com/fwlink/p/?LinkId=618711) can run Windows 10 in a Windows To Go workspace, regardless of the operating system running on the PC. Windows To Go workspaces can use the same image enterprises use for their desktops and laptops and can be managed the same way. Windows To Go is not intended to replace desktops, laptops or supplant other mobility offerings. Rather, it provides support for efficient use of resources for alternative workplace scenarios. There are some additional considerations that you should keep in mind before you start to use Windows To Go:
|
||||
|
||||
- [Differences between Windows To Go and a typical installation of Windows](#bkmk-wtgdif)
|
||||
- [Roaming with Windows To Go](#bkmk-wtgroam)
|
||||
- [Prepare for Windows To Go](#wtg-prep-intro)
|
||||
- [Hardware considerations for Windows To Go](#wtg-hardware)
|
||||
|
||||
**Note**
|
||||
Windows To Go is not supported on Windows RT.
|
||||
|
||||
|
||||
> [!NOTE]
|
||||
> Windows To Go is not supported on Windows RT.
|
||||
|
||||
## <a href="" id="bkmk-wtgdif"></a>Differences between Windows To Go and a typical installation of Windows
|
||||
|
||||
|
||||
Windows To Go workspace operates just like any other installation of Windows with a few exceptions. These exceptions are:
|
||||
|
||||
- **Internal disks are offline.** To ensure data isn’t accidentally disclosed, internal hard disks on the host computer are offline by default when booted into a Windows To Go workspace. Similarly if a Windows To Go drive is inserted into a running system, the Windows To Go drive will not be listed in Windows Explorer.
|
||||
|
||||
- **Trusted Platform Module (TPM) is not used.** When using BitLocker Drive Encryption a pre-operating system boot password will be used for security rather than the TPM since the TPM is tied to a specific computer and Windows To Go drives will move between computers.
|
||||
|
||||
- **Hibernate is disabled by default.** To ensure that the Windows To Go workspace is able to move between computers easily, hibernation is disabled by default. Hibernation can be re-enabled by using Group Policy settings.
|
||||
|
||||
- **Windows Recovery Environment is not available.** In the rare case that you need to recover your Windows To Go drive, you should re-image it with a fresh image of Windows.
|
||||
|
||||
- **Refreshing or resetting a Windows To Go workspace is not supported.** Resetting to the manufacturer’s standard for the computer doesn’t apply when running a Windows To Go workspace, so the feature was disabled.
|
||||
|
||||
- **Upgrading a Windows To Go workspace is not supported.** Older Windows 8 or Windows 8.1 Windows To Go workspaces cannot be upgraded to Windows 10 workspaces, nor can Windows 10 Windows To Go workspaces be upgraded to future versions of Windows 10. For new versions, the workspace needs to be re-imaged with a fresh image of Windows.
|
||||
|
||||
## <a href="" id="bkmk-wtgroam"></a>Roaming with Windows To Go
|
||||
|
||||
|
||||
Windows To Go drives can be booted on multiple computers. When a Windows To Go workspace is first booted on a host computer it will detect all hardware on the computer and install any needed drivers. When the Windows To Go workspace is subsequently booted on that host computer it will be able to identify the host computer and load the correct set of drivers automatically.
|
||||
|
||||
The applications that you want to use from the Windows To Go workspace should be tested to make sure they also support roaming. Some applications bind to the computer hardware which will cause difficulties if the workspace is being used with multiple host computers.
|
||||
|
||||
## <a href="" id="wtg-prep-intro"></a>Prepare for Windows To Go
|
||||
|
||||
|
||||
Enterprises install Windows on a large group of computers either by using configuration management software (such as System Center Configuration Manager), or by using standard Windows deployment tools such as DiskPart and the Deployment Image Servicing and Management (DISM) tool.
|
||||
|
||||
These same tools can be used to provision Windows To Go drive, just as you would if you were planning for provisioning a new class of mobile PCs. You can use the [Windows Assessment and Deployment Kit](https://go.microsoft.com/fwlink/p/?LinkId=526803) to review deployment tools available.
|
||||
|
||||
**Important**
|
||||
Make sure you use the versions of the deployment tools provided for the version of Windows you are deploying. There have been many enhancements made to support Windows To Go. Using versions of the deployment tools released for earlier versions of Windows to provision a Windows To Go drive is not supported.
|
||||
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Make sure you use the versions of the deployment tools provided for the version of Windows you are deploying. There have been many enhancements made to support Windows To Go. Using versions of the deployment tools released for earlier versions of Windows to provision a Windows To Go drive is not supported.
|
||||
|
||||
As you decide what to include in your Windows To Go image, be sure to consider the following questions:
|
||||
|
||||
@ -90,47 +79,37 @@ For more information about designing and planning your Windows To Go deployment,
|
||||
|
||||
## <a href="" id="wtg-hardware"></a>Hardware considerations for Windows To Go
|
||||
|
||||
|
||||
**For USB drives**
|
||||
|
||||
The devices listed in this section have been specially optimized and certified for Windows To Go and meet the necessary requirements for booting and running a full version of Windows 10 from a USB drive. The optimizations for Windows To Go include the following:
|
||||
The devices listed in this section have been specially optimized and certified for Windows To Go and meet the necessary requirements for booting and running a full version of Windows 10 from a USB drive. The optimizations for Windows To Go include the following:
|
||||
|
||||
- Windows To Go certified USB drives are built for high random read/write speeds and support the thousands of random access I/O operations per second required for running normal Windows workloads smoothly.
|
||||
|
||||
- Windows To Go certified USB drives have been tuned to ensure they boot and run on hardware certified for use with Windows 7 and later.
|
||||
|
||||
- Windows To Go certified USB drives have been tuned to ensure they boot and run on hardware certified for use with Windows 7 and later.
|
||||
- Windows To Go certified USB drives are built to last. Certified USB drives are backed with manufacturer warranties and should continue operating under normal usage. Refer to the manufacturer websites for warranty details.
|
||||
|
||||
As of the date of publication, the following are the USB drives currently certified for use as Windows To Go drives:
|
||||
|
||||
**Warning**
|
||||
Using a USB drive that has not been certified is not supported
|
||||
|
||||
|
||||
> [!WARNING]
|
||||
> Using a USB drive that has not been certified is not supported.
|
||||
|
||||
- IronKey Workspace W700 ([http://www.ironkey.com/windows-to-go-drives/ironkey-workspace-w700.html](https://go.microsoft.com/fwlink/p/?LinkId=618714))
|
||||
|
||||
- IronKey Workspace W500 ([http://www.ironkey.com/windows-to-go-drives/ironkey-workspace-w500.html](https://go.microsoft.com/fwlink/p/?LinkId=618717))
|
||||
|
||||
- IronKey Workspace W300 ([http://www.ironkey.com/windows-to-go-drives/ironkey-workspace-w300.html](https://go.microsoft.com/fwlink/p/?LinkId=618718))
|
||||
|
||||
- Kingston DataTraveler Workspace for Windows To Go ([http://www.kingston.com/wtg/](https://go.microsoft.com/fwlink/p/?LinkId=618719))
|
||||
|
||||
- Spyrus Portable Workplace ([http://www.spyruswtg.com/](https://go.microsoft.com/fwlink/p/?LinkId=618720))
|
||||
|
||||
We recommend that you run the Spyrus Deployment Suite for Windows To Go to provision the Spyrus Portable Workplace.
|
||||
|
||||
- Spyrus Secure Portable Workplace ([http://www.spyruswtg.com/](https://go.microsoft.com/fwlink/p/?LinkId=618720))
|
||||
|
||||
**Important**
|
||||
You must use the Spyrus Deployment Suite for Windows To Go to provision the Spyrus Secure Portable Workplace. For more information about the Spyrus Deployment Suite for Windows To Go please refer to [http://www.spyruswtg.com/](https://go.microsoft.com/fwlink/p/?LinkId=618720).
|
||||
|
||||
> [!IMPORTANT]
|
||||
> You must use the Spyrus Deployment Suite for Windows To Go to provision the Spyrus Secure Portable Workplace. For more information about the Spyrus Deployment Suite for Windows To Go please refer to [http://www.spyruswtg.com/](https://go.microsoft.com/fwlink/p/?LinkId=618720).
|
||||
|
||||
|
||||
- Spyrus Worksafe ([http://www.spyruswtg.com/](https://go.microsoft.com/fwlink/p/?LinkId=618720))
|
||||
|
||||
**Tip**
|
||||
This device contains an embedded smart card.
|
||||
> [!TIP]
|
||||
> This device contains an embedded smart card.
|
||||
|
||||
|
||||
|
||||
@ -150,10 +129,8 @@ Using a USB drive that has not been certified is not supported
|
||||
|
||||
When assessing the use of a PC as a host for a Windows To Go workspace you should consider the following criteria:
|
||||
|
||||
- Hardware that has been certified for use with Windows 7or later operating systems will work well with Windows To Go.
|
||||
|
||||
- Running a Windows To Go workspace from a computer that is running Windows RT is not a supported scenario.
|
||||
|
||||
- Hardware that has been certified for use with Windows 7 or later operating systems will work well with Windows To Go.
|
||||
- Running a Windows To Go workspace from a computer that is running Windows RT is not a supported scenario.
|
||||
- Running a Windows To Go workspace on a Mac computer is not a supported scenario.
|
||||
|
||||
The following table details the characteristics that the host computer must have to be used with Windows To Go:
|
||||
@ -176,7 +153,7 @@ The following table details the characteristics that the host computer must have
|
||||
</tr>
|
||||
<tr class="even">
|
||||
<td align="left"><p>Firmware</p></td>
|
||||
<td align="left"><p>USB boot enabled. (PCs certified for use with Windows 7 or later can be configured to boot directly from USB, check with the hardware manufacturer if you are unsure of the ability of your PC to boot from USB)</p></td>
|
||||
<td align="left"><p>USB boot enabled. (PCs certified for use with Windows 7 or later can be configured to boot directly from USB, check with the hardware manufacturer if you are unsure of the ability of your PC to boot from USB)</p></td>
|
||||
</tr>
|
||||
<tr class="odd">
|
||||
<td align="left"><p>Processor architecture</p></td>
|
||||
@ -205,11 +182,9 @@ The following table details the characteristics that the host computer must have
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
**Checking for architectural compatibility between the host PC and the Windows To Go drive**
|
||||
|
||||
In addition to the USB boot support in the BIOS, the Windows 10 image on your Windows To Go drive must be compatible with the processor architecture and the firmware of the host PC as shown in the table below.
|
||||
In addition to the USB boot support in the BIOS, the Windows 10 image on your Windows To Go drive must be compatible with the processor architecture and the firmware of the host PC as shown in the table below.
|
||||
|
||||
<table>
|
||||
<colgroup>
|
||||
@ -248,37 +223,17 @@ In addition to the USB boot support in the BIOS, the Windows 10 image on your W
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## Additional resources
|
||||
|
||||
|
||||
- [Windows 10 forums](https://go.microsoft.com/fwlink/p/?LinkId=618949)
|
||||
|
||||
- [Windows To Go Step by Step Wiki](https://go.microsoft.com/fwlink/p/?LinkId=618950)
|
||||
|
||||
- [Tips for configuring your BIOS settings to work with Windows To Go](https://go.microsoft.com/fwlink/p/?LinkId=618951)
|
||||
|
||||
## Related topics
|
||||
|
||||
|
||||
- [Deploy Windows To Go in your organization](https://go.microsoft.com/fwlink/p/?LinkId=619975)
|
||||
|
||||
- [Windows To Go: frequently asked questions](windows-to-go-frequently-asked-questions.md)
|
||||
|
||||
- [Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md)
|
||||
|
||||
- [Deployment considerations for Windows To Go](deployment-considerations-for-windows-to-go.md)
|
||||
|
||||
- [Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md)
|
||||
|
||||
- [Best practice recommendations for Windows To Go](best-practice-recommendations-for-windows-to-go.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
[Deploy Windows To Go in your organization](https://go.microsoft.com/fwlink/p/?LinkId=619975)<br>
|
||||
[Windows To Go: frequently asked questions](windows-to-go-frequently-asked-questions.md)<br>
|
||||
[Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md)<br>
|
||||
[Deployment considerations for Windows To Go](deployment-considerations-for-windows-to-go.md)<br>
|
||||
[Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md)<br>
|
||||
[Best practice recommendations for Windows To Go](best-practice-recommendations-for-windows-to-go.md)
|
||||
|
@ -51,7 +51,7 @@ The [MSIX Packaging Tool](https://docs.microsoft.com/windows/application-managem
|
||||
|
||||
## Related links
|
||||
|
||||
- [Consumer applications for S mode](https://www.microsoft.com/en-us/windows/s-mode)
|
||||
- [S mode devices](https://www.microsoft.com/en-us/windows/view-all-devices)
|
||||
- [Consumer applications for S mode](https://www.microsoft.com/windows/s-mode)
|
||||
- [S mode devices](https://www.microsoft.com/windows/view-all-devices)
|
||||
- [Windows Defender Application Control deployment guide](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide)
|
||||
- [Windows Defender Advanced Threat Protection](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp)
|
||||
- [Windows Defender Advanced Threat Protection](https://www.microsoft.com/WindowsForBusiness/windows-atp)
|
||||
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
x
Reference in New Issue
Block a user