From 0a66b6f05e91387b42daff9fd96b923f3d8f7edb Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Fri, 11 Dec 2020 23:11:36 +0500
Subject: [PATCH 001/434] Addition to information
As we can also configure credential guard using account protection profile in endpoint security. Added link to that article as well.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/8711
---
.../credential-guard/credential-guard-manage.md | 3 +++
1 file changed, 3 insertions(+)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index 1d0b90717a..ef647da88d 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -59,6 +59,9 @@ To enforce processing of the group policy, you can run ```gpupdate /force```.
3. Click **Profiles** > **Create Profile** > **Endpoint protection** > **Windows Defender Credential Guard**.
+> [!TIP]
+> You can also configure Credential Guard using account protection profile in Endpoint Security. See [https://docs.microsoft.com/mem/intune/protect/endpoint-security-account-protection-profile-settings](account protection policy settings for endpoint security in Intune).
+
> [!NOTE]
> It will enable VBS and Secure Boot and you can do it with or without UEFI Lock. If you will need to disable Credential Guard remotely, enable it without UEFI lock.
From eb8721263bdb89883c1799eee909ac2d8b8cac80 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Mon, 14 Dec 2020 18:10:06 +0500
Subject: [PATCH 002/434] Update
windows/security/identity-protection/credential-guard/credential-guard-manage.md
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../credential-guard/credential-guard-manage.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index ef647da88d..2602ea1fb5 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -60,7 +60,7 @@ To enforce processing of the group policy, you can run ```gpupdate /force```.
3. Click **Profiles** > **Create Profile** > **Endpoint protection** > **Windows Defender Credential Guard**.
> [!TIP]
-> You can also configure Credential Guard using account protection profile in Endpoint Security. See [https://docs.microsoft.com/mem/intune/protect/endpoint-security-account-protection-profile-settings](account protection policy settings for endpoint security in Intune).
+> You can also configure Credential Guard using an account protection profile in endpoint security. See [Account protection policy settings for endpoint security in Intune](https://docs.microsoft.com/mem/intune/protect/endpoint-security-account-protection-profile-settings).
> [!NOTE]
> It will enable VBS and Secure Boot and you can do it with or without UEFI Lock. If you will need to disable Credential Guard remotely, enable it without UEFI lock.
@@ -296,4 +296,3 @@ Set-VMSecurity -VMName -VirtualizationBasedSecurityOptOut $true
```
-
From 0753c70dd3208f7853281987e713b02f8c622ab7 Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Thu, 7 Jan 2021 01:46:40 +0530
Subject: [PATCH 003/434] updated=474959941to61ASCIIimages
---
windows/client-management/mdm/nap-csp.md | 42 ++++++++++++--
.../client-management/mdm/networkproxy-csp.md | 16 ++++--
.../mdm/networkqospolicy-csp.md | 17 ++++--
.../client-management/mdm/nodecache-csp.md | 41 +++++++++++++-
windows/client-management/mdm/office-csp.md | 26 ++++++++-
.../mdm/personalization-csp.md | 13 +++--
.../client-management/mdm/provisioning-csp.md | 21 +++++--
windows/client-management/mdm/proxy-csp.md | 35 ++++++++++--
windows/client-management/mdm/reboot-csp.md | 13 +++--
.../client-management/mdm/remotefind-csp.md | 19 +++++--
.../client-management/mdm/remotelock-csp.md | 10 ++--
.../client-management/mdm/remotering-csp.md | 16 +++++-
.../client-management/mdm/remotewipe-csp.md | 17 ++++--
.../client-management/mdm/reporting-csp.md | 20 +++++--
.../mdm/rootcacertificates-csp.md | 41 ++++++++++++--
.../mdm/secureassessment-csp.md | 11 ++--
windows/client-management/mdm/sharedpc-csp.md | 25 +++++++--
windows/client-management/mdm/storage-csp.md | 10 ++--
windows/client-management/mdm/supl-csp.md | 38 +++++++++++--
.../client-management/mdm/surfacehub-csp.md | 55 +++++++++++++++++--
20 files changed, 411 insertions(+), 75 deletions(-)
diff --git a/windows/client-management/mdm/nap-csp.md b/windows/client-management/mdm/nap-csp.md
index dcaef76767..89d18c8eff 100644
--- a/windows/client-management/mdm/nap-csp.md
+++ b/windows/client-management/mdm/nap-csp.md
@@ -23,10 +23,44 @@ The NAP (Network Access Point) Configuration Service Provider is used to manage
For the NAP CSP, you cannot use the Replace command unless the node already exists.
-The following diagram shows the NAP configuration service provider management object in tree format as used by OMA DM. The OMA Client Provisioning protocol is not supported by this configuration service provider.
-
-
-
+The following shows the NAP configuration service provider management object in tree format as used by OMA DM. The OMA Client Provisioning protocol is not supported by this configuration service provider.
+```
+./Vendor/MSFT
+NAP
+----*
+--------NapId
+--------Name
+--------Addr
+--------AddrType
+--------IPv4
+------------AutoConfig
+------------LocalAddr
+------------NetMask
+------------Gateway
+------------DNS
+----------------*
+--------------------DNSAddr
+--------IPv6
+------------AutoConfig
+------------LocalAddr
+--------Linger
+--------AuthInfo
+------------AuthType
+------------AuthName
+------------AuthSecret
+------------AuthEntities
+----------------*
+--------------------AuthEntity
+------------SPI
+--------Bearer
+------------BearerType
+--------Ext
+------------Microsoft
+----------------Guid
+----------------AlwaysOn
+----------------Secure
+----------------SecureLevel
+```
**./Vendor/MSFT/NAP**
Root node.
diff --git a/windows/client-management/mdm/networkproxy-csp.md b/windows/client-management/mdm/networkproxy-csp.md
index 43aff61d37..4fa1f6289f 100644
--- a/windows/client-management/mdm/networkproxy-csp.md
+++ b/windows/client-management/mdm/networkproxy-csp.md
@@ -28,10 +28,18 @@ How the settings work:
-The following diagram shows the NetworkProxy configuration service provider in tree format.
-
-
-
+The following shows the NetworkProxy configuration service provider in tree format.
+```
+./Vendor/MSFT
+NetworkProxy
+----ProxySettingsPerUser
+----AutoDetect
+----SetupScriptUrl
+----ProxyServer
+--------ProxyAddress
+--------Exceptions
+--------UseProxyForLocalAddresses
+```
**./Vendor/MSFT/NetworkProxy**
The root node for the NetworkProxy configuration service provider..
diff --git a/windows/client-management/mdm/networkqospolicy-csp.md b/windows/client-management/mdm/networkqospolicy-csp.md
index 19a52ed0be..3c523ba304 100644
--- a/windows/client-management/mdm/networkqospolicy-csp.md
+++ b/windows/client-management/mdm/networkqospolicy-csp.md
@@ -27,10 +27,19 @@ The following actions are supported:
> [!NOTE]
> The NetworkQoSPolicy configuration service provider is officially supported for devices that are Intune managed and Azure AD joined. Currently, this CSP is not supported on Azure AD Hybrid joined devices and for devices using GPO and CSP at the same time. The minimum operating system requirement for this CSP is Windows 10, version 2004. This CSP is supported only in Microsoft Surface Hub prior to Window 10, version 2004.
-The following diagram shows the NetworkQoSPolicy configuration service provider in tree format.
-
-
-
+The following shows the NetworkQoSPolicy configuration service provider in tree format.
+```
+./Device/Vendor/MSFT
+NetworkQoSPolicy
+----Version
+----Name
+--------IPProtocolMatchCondition
+--------AppPathNameMatchCondition
+--------SourcePortMatchCondition
+--------DestinationPortMatchCondition
+--------PriorityValue8021Action
+--------DSCPAction
+```
**NetworkQoSPolicy**
The root node for the NetworkQoSPolicy configuration service provider.
diff --git a/windows/client-management/mdm/nodecache-csp.md b/windows/client-management/mdm/nodecache-csp.md
index 045b8152d9..ff47aa238d 100644
--- a/windows/client-management/mdm/nodecache-csp.md
+++ b/windows/client-management/mdm/nodecache-csp.md
@@ -27,10 +27,47 @@ application/x-nodemon-sha256
NodeCache will hash the values and compare with a hash value that was sent down by the server. This supports checking a parent node and its children recursively.
-The following diagram shows the NodeCache configuration service provider in tree format.
+The following shows the NodeCache configuration service provider in tree format.
+```
+./User/Vendor/MSFT
+NodeCache
+----ProviderID
+--------CacheVersion
+--------ChangedNodes
+--------ChangedNodesData
+--------Nodes
+------------NodeID
+----------------NodeURI
+----------------ExpectedValue
+----------------AutoSetExpectedValue
-
+./Device/Vendor/MSFT
+NodeCache
+----ProviderID
+--------CacheVersion
+--------ChangedNodes
+--------ChangedNodesData
+--------Nodes
+------------NodeID
+----------------NodeURI
+----------------ExpectedValue
+----------------AutoSetExpectedValue
+
+
+./User/Vendor/MSFT
+./Device/Vendor/MSFT
+NodeCache
+----ProviderID
+--------CacheVersion
+--------ChangedNodes
+--------ChangedNodesData
+--------Nodes
+------------NodeID
+----------------NodeURI
+----------------ExpectedValue
+----------------AutoSetExpectedValue
+```
**./Device/Vendor/MSFT and ./User/Vendor/MSFT**
Required. The root node for the NodeCache object. Supported operation is Get. This configuration service provider is used for enterprise device management only. This is a predefined MIME type to identify this managed object in OMA DM syntax.
diff --git a/windows/client-management/mdm/office-csp.md b/windows/client-management/mdm/office-csp.md
index 58e1e0a8e9..3a20d04ce0 100644
--- a/windows/client-management/mdm/office-csp.md
+++ b/windows/client-management/mdm/office-csp.md
@@ -20,10 +20,32 @@ This CSP was added in Windows 10, version 1703.
For additional information, see [Office DDF](office-ddf.md).
-The following diagram shows the Office configuration service provider in tree format.
+The following shows the Office configuration service provider in tree format.
+```
+./Vendor/MSFT
+Office
+----Installation
+--------id
+------------Install
+------------Status
-
+./Device/Vendor/MSFT
+Office
+----Installation
+--------id
+------------Install
+------------Status
+
+
+./Vendor/MSFT
+./Device/Vendor/MSFT
+Office
+----Installation
+--------id
+------------Install
+------------Status
+```
**./Device/Vendor/MSFT/Office/ or ./User/Vendor/MSFT/Office**
The root node for the Office configuration service provider.
diff --git a/windows/client-management/mdm/personalization-csp.md b/windows/client-management/mdm/personalization-csp.md
index 8d4f260502..bf3d84f0f4 100644
--- a/windows/client-management/mdm/personalization-csp.md
+++ b/windows/client-management/mdm/personalization-csp.md
@@ -20,10 +20,15 @@ This CSP was added in Windows 10, version 1703.
> [!Note]
> Personalization CSP is supported in Windows 10 Enterprise and Education SKUs. It works in Windows 10 Pro and Windows 10 Pro in S mode if SetEduPolicies in [SharedPC CSP](sharedpc-csp.md) is set.
-The following diagram shows the Personalization configuration service provider in tree format.
-
-
-
+The following shows the Personalization configuration service provider in tree format.
+```
+./Vendor/MSFT
+Personalization
+----DesktopImageUrl
+----DesktopImageStatus
+----LockScreenImageUrl
+----LockScreenImageStatus
+```
**./Vendor/MSFT/Personalization**
Defines the root node for the Personalization configuration service provider.
diff --git a/windows/client-management/mdm/provisioning-csp.md b/windows/client-management/mdm/provisioning-csp.md
index 9dfabcfba3..1e6a236656 100644
--- a/windows/client-management/mdm/provisioning-csp.md
+++ b/windows/client-management/mdm/provisioning-csp.md
@@ -23,10 +23,23 @@ The Provisioning configuration service provider is used for bulk user enrollment
For bulk enrollment step-by-step guide, see [Bulk enrollment](bulk-enrollment-using-windows-provisioning-tool.md).
-The following diagram shows the Provisioning configuration service provider in tree format.
-
-
-
+The following shows the Provisioning configuration service provider in tree format.
+```
+./Vendor/MSFT/ProvisioningCommands
+ProvisioningCommands
+----DeviceContext
+--------CommandSet
+------------Default
+----------------CommandLine
+----PrimaryContext
+--------CommandSet
+------------CommandName
+----------------CommandLine
+----------------ReturnCodeSuccess
+----------------ReturnCodeRestart
+----------------RestartRequired
+----------------ContinueInstall
+```
**./Vendor/MSFT**
Root node for Provisioning CSP.
diff --git a/windows/client-management/mdm/proxy-csp.md b/windows/client-management/mdm/proxy-csp.md
index c1d9034fe8..540a52a931 100644
--- a/windows/client-management/mdm/proxy-csp.md
+++ b/windows/client-management/mdm/proxy-csp.md
@@ -25,10 +25,37 @@ This configuration service provider requires the ID\_CAP\_CSP\_FOUNDATION and ID
For the PROXY CSP, you cannot use the Replace command unless the node already exists.
-The following diagram shows the PROXY configuration service provider management object in tree format as used by OMA DM. The OMA Client Provisioning protocol is not supported by this configuration service provider.
-
-
-
+The following shows the PROXY configuration service provider management object in tree format as used by OMA DM. The OMA Client Provisioning protocol is not supported by this configuration service provider.
+```
+./Vendor/MSFT
+Proxy
+----*
+--------ProxyId
+--------Name
+--------AddrType
+--------Addr
+--------AddrFQDN
+--------ConRefs
+------------*
+----------------ConRef
+--------Domains
+------------*
+----------------DomainName
+--------Ports
+------------*
+----------------PortNbr
+----------------Services
+--------------------*
+------------------------ServiceName
+--------ProxyType
+--------ProxyParams
+------------WAP
+----------------Trust
+----------------PushEnabled
+--------Ext
+------------Microsoft
+----------------Guid
+```
**./Vendor/MSFT/Proxy**
Root node for the proxy connection.
diff --git a/windows/client-management/mdm/reboot-csp.md b/windows/client-management/mdm/reboot-csp.md
index d906bca3da..cda7004487 100644
--- a/windows/client-management/mdm/reboot-csp.md
+++ b/windows/client-management/mdm/reboot-csp.md
@@ -17,10 +17,15 @@ ms.date: 06/26/2017
The Reboot configuration service provider is used to configure reboot settings.
-The following diagram shows the Reboot configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
-
-
-
+The following shows the Reboot configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
+```
+./Device/Vendor/MSFT
+Reboot
+----RebootNow
+----Schedule
+--------Single
+--------DailyRecurrent
+```
**./Vendor/MSFT/Reboot**
The root node for the Reboot configuration service provider.
diff --git a/windows/client-management/mdm/remotefind-csp.md b/windows/client-management/mdm/remotefind-csp.md
index 554e07f2d4..0dc50af800 100644
--- a/windows/client-management/mdm/remotefind-csp.md
+++ b/windows/client-management/mdm/remotefind-csp.md
@@ -17,10 +17,21 @@ ms.date: 06/26/2017
The RemoteFind configuration service provider retrieves the location information for a particular device.
-The following diagram shows the RemoteFind configuration service provider management object in tree format as used by OMA Client Provisioning.
-
-
-
+The following shows the RemoteFind configuration service provider management object in tree format as used by OMA Client Provisioning.
+```
+./Vendor/MSFT
+RemoteFind
+----DesiredAccuracy
+----MaximumAge
+----Timeout
+----Location
+--------Latitude
+--------Longitude
+--------Altitude
+--------Accuracy
+--------AltitudeAccuracy
+--------Age
+```
**DesiredAccuracy**
Optional. The node accepts the requested radius value in meters. Valid values for accuracy are any value between 1 and 1000 meters.
diff --git a/windows/client-management/mdm/remotelock-csp.md b/windows/client-management/mdm/remotelock-csp.md
index 57368cb103..c23205597b 100644
--- a/windows/client-management/mdm/remotelock-csp.md
+++ b/windows/client-management/mdm/remotelock-csp.md
@@ -21,10 +21,12 @@ The RemoteLock CSP supports the ability to lock a device that has a PIN set on t
> The RemoteLock CSP is only supported in Windows 10 Mobile.
-The following diagram shows the RemoteLock configuration service provider in a tree format.
-
-
-
+The following shows the RemoteLock configuration service provider in a tree format.
+```
+./Vendor/MSFT
+RemoteLock
+----Lock
+```
**./Vendor/MSFT/RemoteLock**
Defines the root node for the RemoteLock configuration service provider.
diff --git a/windows/client-management/mdm/remotering-csp.md b/windows/client-management/mdm/remotering-csp.md
index 999d8b629e..d1db2f57e8 100644
--- a/windows/client-management/mdm/remotering-csp.md
+++ b/windows/client-management/mdm/remotering-csp.md
@@ -17,10 +17,22 @@ ms.date: 06/26/2017
The RemoteRing configuration service provider can be used to remotely trigger a device to produce an audible ringing sound regardless of the volume that is set on the device.
-The following diagram shows the RemoteRing configuration service provider in tree format.
+The following shows the RemoteRing configuration service provider in tree format.
+```
+./User/Vendor/MSFT
+RemoteRing
+----Ring
-
+./Device/Vendor/MSFT
+Root
+
+
+./User/Vendor/MSFT
+./Device/Vendor/MSFT
+RemoteRing
+----Ring
+```
**Ring**
Required. The node accepts requests to ring the device.
diff --git a/windows/client-management/mdm/remotewipe-csp.md b/windows/client-management/mdm/remotewipe-csp.md
index efd8cdac2b..67772b648f 100644
--- a/windows/client-management/mdm/remotewipe-csp.md
+++ b/windows/client-management/mdm/remotewipe-csp.md
@@ -17,10 +17,19 @@ ms.date: 08/13/2018
The RemoteWipe configuration service provider can be used by mobile operators DM server or enterprise management server to remotely wipe a device. The RemoteWipe configuration service provider can make the data stored in memory and hard disks difficult to recover if the device is remotely wiped after being lost or stolen.
-The following diagram shows the RemoteWipe configuration service provider management object in tree format as used by both OMA DM and OMA Client Provisioning. Enterprise IT Professionals can update these settings by using the Exchange Server.
-
-
-
+The following shows the RemoteWipe configuration service provider management object in tree format as used by both OMA DM and OMA Client Provisioning. Enterprise IT Professionals can update these settings by using the Exchange Server.
+```
+./Vendor/MSFT
+RemoteWipe
+----doWipe
+----doWipePersistProvisionedData
+----doWipeProtected
+----doWipePersistUserData
+----AutomaticRedeployment
+--------doAutomaticRedeployment
+--------LastError
+--------Status
+```
**doWipe**
Specifies that a remote wipe of the device should be performed. The return status code indicates whether the device accepted the Exec command.
diff --git a/windows/client-management/mdm/reporting-csp.md b/windows/client-management/mdm/reporting-csp.md
index 1f1391ff33..efa527ae2d 100644
--- a/windows/client-management/mdm/reporting-csp.md
+++ b/windows/client-management/mdm/reporting-csp.md
@@ -17,10 +17,22 @@ ms.date: 06/26/2017
The Reporting configuration service provider is used to retrieve Windows Information Protection (formerly known as Enterprise Data Protection) and security auditing logs. This CSP was added in Windows 10, version 1511.
-The following diagram shows the Reporting configuration service provider in tree format.
-
-
-
+The following shows the Reporting configuration service provider in tree format.
+```
+./Vendor/MSFT
+Reporting
+----EnterpriseDataProtection
+--------RetrieveByTimeRange
+------------Logs
+------------StartTime
+------------StopTime
+------------Type
+--------RetrieveByCount
+------------Logs
+------------LogCount
+------------StartTime
+------------Type
+```
**Reporting**
Root node.
diff --git a/windows/client-management/mdm/rootcacertificates-csp.md b/windows/client-management/mdm/rootcacertificates-csp.md
index 1c5b7912aa..c1e940ef69 100644
--- a/windows/client-management/mdm/rootcacertificates-csp.md
+++ b/windows/client-management/mdm/rootcacertificates-csp.md
@@ -21,12 +21,45 @@ The RootCATrustedCertificates configuration service provider enables the enterpr
> The **./User/** configuration is not supported for **RootCATrustedCertificates/Root/**.
-The following image shows the RootCATrustedCertificates configuration service provider in tree format.
+The following shows the RootCATrustedCertificates configuration service provider in tree format.
Detailed specification of the principal root nodes:
-
-
-
+```
+./Vendor/MSFT
+RootCATrustedCertificates
+----Root
+--------CertHash
+------------EncodedCertificate
+------------IssuedBy
+------------IssuedTo
+------------ValidFrom
+------------ValidTo
+------------TemplateName
+----CA
+--------CertHash
+------------EncodedCertificate
+------------IssuedBy
+------------IssuedTo
+------------ValidFrom
+------------ValidTo
+------------TemplateName
+----TrustedPublisher
+--------CertHash
+------------EncodedCertificate
+------------IssuedBy
+------------IssuedTo
+------------ValidFrom
+------------ValidTo
+------------TemplateName
+----TrustedPeople
+--------CertHash
+------------EncodedCertificate
+------------IssuedBy
+------------IssuedTo
+------------ValidFrom
+------------ValidTo
+------------TemplateName
+```
**Device or User**
For device certificates, use **./Device/Vendor/MSFT** path and for user certificates use **./User/Vendor/MSFT** path.
diff --git a/windows/client-management/mdm/secureassessment-csp.md b/windows/client-management/mdm/secureassessment-csp.md
index 6585261229..1bd4c71692 100644
--- a/windows/client-management/mdm/secureassessment-csp.md
+++ b/windows/client-management/mdm/secureassessment-csp.md
@@ -16,10 +16,13 @@ ms.date: 06/26/2017
The SecureAssessment configuration service provider is used to provide configuration information for the secure assessment browser.
-The following diagram shows the SecureAssessment configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
-
-
-
+The following shows the SecureAssessment configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
+```
+./Vendor/MSFT
+SecureAssessment
+----LaunchURI
+----TesterAccount
+```
**./Vendor/MSFT/SecureAssessment**
The root node for the SecureAssessment configuration service provider.
diff --git a/windows/client-management/mdm/sharedpc-csp.md b/windows/client-management/mdm/sharedpc-csp.md
index cf00680823..82731ed689 100644
--- a/windows/client-management/mdm/sharedpc-csp.md
+++ b/windows/client-management/mdm/sharedpc-csp.md
@@ -17,10 +17,27 @@ ms.date: 01/16/2019
The SharedPC configuration service provider is used to configure settings for Shared PC usage.
-The following diagram shows the SharedPC configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
-
-
-
+The following shows the SharedPC configuration service provider management objects in tree format as used by Open Mobile Alliance Device Management (OMA DM), OMA Client Provisioning, and Enterprise DM.
+```
+./Vendor/MSFT
+SharedPC
+----EnableSharedPCMode
+----SetEduPolicies
+----SetPowerPolicies
+----MaintenanceStartTime
+----SignInOnResume
+----SleepTimeout
+----EnableAccountManager
+----AccountModel
+----DeletionPolicy
+----DiskLevelDeletion
+----DiskLevelCaching
+----RestrictLocalStorage
+----KioskModeAUMID
+----KioskModeUserTileDisplayText
+----InactiveThreshold
+----MaxPageFileSizeMB
+```
**./Vendor/MSFT/SharedPC**
The root node for the SharedPC configuration service provider.
diff --git a/windows/client-management/mdm/storage-csp.md b/windows/client-management/mdm/storage-csp.md
index 3cb5d8920c..ea5aad60ca 100644
--- a/windows/client-management/mdm/storage-csp.md
+++ b/windows/client-management/mdm/storage-csp.md
@@ -21,10 +21,12 @@ The Storage enterprise configuration service provider is used to configure the s
-The following diagram shows the Storage configuration service provider in tree format.
-
-
-
+The following shows the Storage configuration service provider in tree format.
+```
+./Vendor/MSFT
+Storage
+----Disable
+```
**Disable**
Required. A Boolean value that specifies whether to enable or disable a storage card. A value of **True** disables the storage card. A value of **False** enables the storage card. The default value is **False**. The value is case sensitive.
diff --git a/windows/client-management/mdm/supl-csp.md b/windows/client-management/mdm/supl-csp.md
index 45e335fdf9..e41a8c2374 100644
--- a/windows/client-management/mdm/supl-csp.md
+++ b/windows/client-management/mdm/supl-csp.md
@@ -59,16 +59,44 @@ The SUPL configuration service provider is used to configure the location client
The SUPL or V2 UPL connection will be reconfigured every time the device is rebooted, a new UICC is inserted, or new settings are provisioned by using OMA Client Provisioning, OMA DM, or test tools. When the device is in roaming mode, it reverts to Mobile Station Standalone mode, in which only the built–in Microsoft location components are used.
-The following diagram shows the SUPL configuration service provider management object in tree format as used by OMA DM and OMA Client Provisioning.
+The following shows the SUPL configuration service provider management object in tree format as used by OMA DM and OMA Client Provisioning.
> **Note** This configuration service provider requires the ID\_CAP\_CSP\_FOUNDATION capability to be accessed from a network configuration application.
-
-
-
-
+```
+./Vendor/MSFT/
+SUPL
+----SUPL1
+--------AppID
+--------Addr
+--------Ext
+------------Microsoft
+----------------Version
+----------------MCCMNPairs
+----------------HighAccPositioningMethod
+----------------LocMasterSwitchDependencyNII
+----------------NIDefaultTimeout
+----------------ServerAccessInterval
+----------------RootCertificate
+--------------------Name
+--------------------Data
+----------------RootCertificate2
+--------------------Name
+--------------------Data
+----------------RootCertificate3
+--------------------Name
+--------------------Data
+----V2UPL1
+--------MPC
+--------PDE
+--------PositioningMethod_MR
+--------LocMasterSwitchDependencyNII
+--------ApplicationTypeIndicator_MR
+--------NIDefaultTimeout
+--------ServerAccessInterval
+```
**SUPL1**
Required for SUPL. Defines the account for the SUPL Enabled Terminal (SET) node. Only one SUPL account is supported at a given time.
diff --git a/windows/client-management/mdm/surfacehub-csp.md b/windows/client-management/mdm/surfacehub-csp.md
index 2b8f5d0334..dc5ea81f2a 100644
--- a/windows/client-management/mdm/surfacehub-csp.md
+++ b/windows/client-management/mdm/surfacehub-csp.md
@@ -16,10 +16,57 @@ ms.date: 07/28/2017
The SurfaceHub configuration service provider (CSP) is used to configure Microsoft Surface Hub settings. This CSP was added in Windows 10, version 1511.
-The following diagram shows the SurfaceHub CSP management objects in tree format.
-
-
-
+The following shows the SurfaceHub CSP management objects in tree format.
+```
+./Vendor/MSFT
+SurfaceHub
+----DeviceAccount
+--------DomainName
+--------UserName
+--------UserPrincipalName
+--------Password
+--------ValidateAndCommit
+--------ExchangeServer
+--------SipAddress
+--------Email
+--------CalendarSyncEnabled
+--------ErrorContext
+--------PasswordRotationPeriod
+----MaintenanceHoursSimple
+--------Hours
+------------StartTime
+------------Duration
+----InBoxApps
+--------SkypeForBusiness
+------------DomainName
+--------Welcome
+------------AutoWakeScreen
+------------CurrentBackgroundPath
+------------MeetingInfoOption
+--------WirelessProjection
+------------PINRequired
+------------Enabled
+------------Channel
+--------Connect
+------------AutoLaunch
+----Properties
+--------FriendlyName
+--------DefaultVolume
+--------ScreenTimeout
+--------SessionTimeout
+--------SleepTimeout
+--------AllowSessionResume
+--------AllowAutoProxyAuth
+--------DisableSigninSuggestions
+--------DoNotShowMyMeetingsAndFiles
+----ProxyServers
+----Management
+--------GroupName
+--------GroupSid
+----MOMAgent
+--------WorkspaceID
+--------WorkspaceKey
+```
**./Vendor/MSFT/SurfaceHub**
The root node for the Surface Hub configuration service provider.
From 2889b7d39ddb0ab321bb3126f5fed3571b1785dd Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Sun, 10 Jan 2021 18:06:34 +0500
Subject: [PATCH 004/434] Update demonstrate-deployment-on-vm.md
---
.../windows-autopilot/demonstrate-deployment-on-vm.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm.md b/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm.md
index 4753557b61..17d87f0e10 100644
--- a/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm.md
+++ b/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm.md
@@ -47,7 +47,7 @@ These are the things you'll need to complete this lab:
Windows 10 installation media | Windows 10 Professional or Enterprise (ISO file) for a supported version of Windows 10, semi-annual channel. If you do not already have an ISO to use, a link is provided to download an evaluation version of Windows 10 Enterprise. |
Internet access | If you are behind a firewall, see the detailed networking requirements. Otherwise, just ensure that you have a connection to the Internet. |
Hyper-V or a physical device running Windows 10 | The guide assumes that you will use a Hyper-V VM, and provides instructions to install and configure Hyper-V if needed. To use a physical device, skip the steps to install and configure Hyper-V. |
-A Premium Intune account | This guide will describe how to obtain a free 30-day trial premium account that can be used to complete the lab. |
+An account with Azure AD Premium license | This guide will describe how to obtain a free 30-day trial Azure AD Premium subscription that can be used to complete the lab. |
## Procedures
From 6df567d30766537d2fad246c284da9af7bdc9f84 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Thu, 14 Jan 2021 22:32:22 +0500
Subject: [PATCH 005/434] Removal of Note
As Gen 2 VMs are now available in Azure, the Credential guard feature is made available. So removing this note.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/8938
---
.../credential-guard/credential-guard-manage.md | 4 ----
1 file changed, 4 deletions(-)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index 1d0b90717a..d09a59f416 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -262,10 +262,6 @@ To disable Windows Defender Credential Guard, you can use the following set of p
>bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,DISABLE-VBS
>bcdedit /set vsmlaunchtype off
>```
-
-> [!NOTE]
-> Credential Guard and Device Guard are not currently supported when using Azure IaaS VMs. These options will be made available with future Gen 2 VMs.
-
For more info on virtualization-based security and HVCI, see [Enable virtualization-based protection of code integrity](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity
).
From 832863f12564b92d279f679d8869eb8e72a83369 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Fri, 15 Jan 2021 10:53:57 +0500
Subject: [PATCH 006/434] Update
windows/security/identity-protection/credential-guard/credential-guard-manage.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../credential-guard/credential-guard-manage.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index d09a59f416..0a55fcfb87 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -262,6 +262,7 @@ To disable Windows Defender Credential Guard, you can use the following set of p
>bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,DISABLE-VBS
>bcdedit /set vsmlaunchtype off
>```
+
For more info on virtualization-based security and HVCI, see [Enable virtualization-based protection of code integrity](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity
).
@@ -289,4 +290,3 @@ Set-VMSecurity -VMName -VirtualizationBasedSecurityOptOut $true
```
-
From 7b35767f69fd74cab0a59944c9cb5226fd429ea2 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Fri, 15 Jan 2021 10:58:32 +0500
Subject: [PATCH 007/434] Update in note section
As suggested, I have updated the note section to reflect the correct information.
---
.../credential-guard/credential-guard-manage.md | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index 0a55fcfb87..a517440ce8 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -263,8 +263,10 @@ To disable Windows Defender Credential Guard, you can use the following set of p
>bcdedit /set vsmlaunchtype off
>```
-For more info on virtualization-based security and HVCI, see [Enable virtualization-based protection of code integrity](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity
-).
+For more info on virtualization-based security and HVCI, see [Enable virtualization-based protection of code integrity](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity).
+
+> [!Note]
+> Credential Guard and Device Guard are not supported when using Azure Gen 1 VMs. These options are available with Gen 2 VMs only.
From edaa9bb008562633f237ecc061efdb9af7d723c6 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Fri, 15 Jan 2021 12:15:18 +0500
Subject: [PATCH 008/434] Update
windows/security/identity-protection/credential-guard/credential-guard-manage.md
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../credential-guard/credential-guard-manage.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/security/identity-protection/credential-guard/credential-guard-manage.md b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
index a517440ce8..4b7317b63f 100644
--- a/windows/security/identity-protection/credential-guard/credential-guard-manage.md
+++ b/windows/security/identity-protection/credential-guard/credential-guard-manage.md
@@ -265,7 +265,7 @@ To disable Windows Defender Credential Guard, you can use the following set of p
For more info on virtualization-based security and HVCI, see [Enable virtualization-based protection of code integrity](/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity).
-> [!Note]
+> [!NOTE]
> Credential Guard and Device Guard are not supported when using Azure Gen 1 VMs. These options are available with Gen 2 VMs only.
@@ -291,4 +291,3 @@ From the host, you can disable Windows Defender Credential Guard for a virtual m
Set-VMSecurity -VMName -VirtualizationBasedSecurityOptOut $true
```
-
From 10c0e7510626d50bea29e309d14f9978e03ca1c7 Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Mon, 1 Feb 2021 15:48:51 +0530
Subject: [PATCH 009/434] 4797298_updates_4formattingerrors
---
.../policy-csp-admx-microsoftdefenderantivirus.md | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md b/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md
index 5862dadff7..94b2dbcc6d 100644
--- a/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md
+++ b/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md
@@ -3224,7 +3224,8 @@ ADMX Info:
-**ADMX_MicrosoftDefenderAntivirus/Reporting_DisablegenericrePorts**
+
+**ADMX_MicrosoftDefenderAntivirus/Reporting_DisablegenericrePorts**
@@ -3357,7 +3358,8 @@ ADMX Info:
-**ADMX_MicrosoftDefenderAntivirus/Reporting_RecentlyCleanedTimeout**
+
+**ADMX_MicrosoftDefenderAntivirus/Reporting_RecentlyCleanedTimeout**
@@ -4249,7 +4251,8 @@ ADMX Info:
-**ADMX_MicrosoftDefenderAntivirus/Scan_DisableScanningMappedNetworkDrivesForFullScan**
+
+**ADMX_MicrosoftDefenderAntivirus/Scan_DisableScanningMappedNetworkDrivesForFullScan**
@@ -6135,7 +6138,8 @@ ADMX Info:
-**ADMX_MicrosoftDefenderAntivirus/SignatureUpdate_SignatureDisableNotification**
+
+ **ADMX_MicrosoftDefenderAntivirus/SignatureUpdate_SignatureDisableNotification**
From 9b4fa09f94ee1d03b695d94073c3a28d8af6cafe Mon Sep 17 00:00:00 2001
From: Reece Peacock <49645174+Reeced40@users.noreply.github.com>
Date: Mon, 8 Feb 2021 14:44:02 +0200
Subject: [PATCH 010/434] Update resolution-procedures.md
Added links
---
windows/deployment/upgrade/resolution-procedures.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/windows/deployment/upgrade/resolution-procedures.md b/windows/deployment/upgrade/resolution-procedures.md
index 1d75d19367..91143d34da 100644
--- a/windows/deployment/upgrade/resolution-procedures.md
+++ b/windows/deployment/upgrade/resolution-procedures.md
@@ -345,3 +345,5 @@ Also see the following sequential list of modern setup (mosetup) error codes wit
- [Windows 10 Specifications](https://www.microsoft.com/windows/Windows-10-specifications)
- [Windows 10 IT pro forums](https://social.technet.microsoft.com/Forums/home?category=Windows10ITPro)
- [Fix Windows Update errors by using the DISM or System Update Readiness tool](https://support.microsoft.com/kb/947821)
+- [Win 7 to Win 10 upgrade error (0x800707E7 - 0x3000D)](https://answers.microsoft.com/en-us/windows/forum/all/win-7-to-win-10-upgrade-error-0x800707e7-0x3000d/1273bc1e-8a04-44d4-a6b2-808c9feeb020))
+- [Win 10 upgrade error: User profile suffix mismatch, 0x800707E7 - 0x3000D](https://answers.microsoft.com/en-us/windows/forum/windows_10-windows_install/win-10-upgrade-error-user-profile-suffix-mismatch/0f006733-2af5-4b42-a2d4-863fad05273d?page=3)
From d3f0971f885f75e4765b7246c416efd1d7c72a66 Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Tue, 9 Feb 2021 16:11:56 +0530
Subject: [PATCH 011/434] updated
---
.../mdm/policy-csp-admx-filerecovery.md | 129 ++++++++++++++++++
1 file changed, 129 insertions(+)
create mode 100644 windows/client-management/mdm/policy-csp-admx-filerecovery.md
diff --git a/windows/client-management/mdm/policy-csp-admx-filerecovery.md b/windows/client-management/mdm/policy-csp-admx-filerecovery.md
new file mode 100644
index 0000000000..6ffae36c4d
--- /dev/null
+++ b/windows/client-management/mdm/policy-csp-admx-filerecovery.md
@@ -0,0 +1,129 @@
+---
+title: Policy CSP - ADMX_FileRecovery
+description: Policy CSP - ADMX_FileRecovery
+ms.author: dansimp
+ms.localizationpriority: medium
+ms.topic: article
+ms.prod: w10
+ms.technology: windows
+author: manikadhiman
+ms.date: 09/02/2021
+ms.reviewer:
+manager: dansimp
+---
+
+# Policy CSP - ADMX_FileRecovery
+> [!WARNING]
+> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here.
+
+
+
+
+## ADMX_FileRecovery
+
+
+ -
+ ADMX_FileRecovery/WdiScenarioExecutionPolicy
+
+
+
+
+
+
+
+**ADMX_FileRecovery/WdiScenarioExecutionPolicy**
+
+
+
+
+ Windows Edition |
+ Supported? |
+
+
+ Home |
+  |
+
+
+ Pro |
+  |
+
+
+ Business |
+  |
+
+
+ Enterprise |
+  |
+
+
+ Education |
+  |
+
+
+
+
+
+
+
+[Scope](./policy-configuration-service-provider.md#policy-scope):
+
+> [!div class = "checklist"]
+> * Device
+
+
+
+
+
+Available in the latest Windows 10 Insider Preview Build. This policy setting allows you to configure the recovery behavior for corrupted files to one of three states:
+- Regular: Detection, troubleshooting, and recovery of corrupted files will automatically start with a minimal UI display. Windows will attempt to present you with a dialog box when a system restart is required. This is the default recovery behavior for all corrupted files.
+- Silent: Detection, troubleshooting, and recovery of corrupted files will automatically start with no UI. Windows will log an administrator event when a system restart is required. This behavior is recommended for headless operation.
+- Troubleshooting Only: Detection and troubleshooting of corrupted files will automatically start with no UI. Recovery is not attempted automatically.
+
+Windows will log an administrator event with instructions if manual recovery is possible.
+- If you enable this setting, the recovery behavior for corrupted files will be set to either the regular (default), silent, or troubleshooting only state.
+- If you disable this setting, the recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.
+
+If you do not configure this setting, the recovery behavior for corrupted files will be set to the regular recovery behavior.
+No system or service restarts are required for changes to this policy to take immediate effect after a Group Policy refresh.
+
+> [!NOTE]
+> This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state.
+
+When the service is stopped or disabled, system file recovery will not be attempted.
+The DPS can be configured with the Services snap-in to the Microsoft Management Console.
+
+> [!NOTE]
+> This policy setting applies to all sites in Trusted zones.
+
+
+> [!TIP]
+> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md).
+>
+> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy).
+>
+> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect).
+
+
+ADMX Info:
+- GP English name: *Configure Corrupted File Recovery behavior*
+- GP name: *WdiScenarioExecutionPolicy*
+- GP path: *System\Troubleshooting and Diagnostics\Corrupted File Recovery*
+- GP ADMX file name: *FileRecovery.admx*
+
+
+
+
+
+Footnotes:
+
+- 1 - Available in Windows 10, version 1607.
+- 2 - Available in Windows 10, version 1703.
+- 3 - Available in Windows 10, version 1709.
+- 4 - Available in Windows 10, version 1803.
+- 5 - Available in Windows 10, version 1809.
+- 6 - Available in Windows 10, version 1903.
+- 7 - Available in Windows 10, version 1909.
+- 8 - Available in Windows 10, version 2004.
+
+
+
From e6d46a647c53c8813ef774f487c6df0633d1063b Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Thu, 11 Feb 2021 00:12:53 +0530
Subject: [PATCH 012/434] Updated
---
.../client-management/mdm/policies-in-policy-csp-admx-backed.md | 1 +
windows/client-management/mdm/policy-csp-admx-filerecovery.md | 2 +-
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
index c6e37891f5..cf1e2f06cb 100644
--- a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
+++ b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
@@ -275,6 +275,7 @@ ms.date: 10/08/2020
- [ADMX_FileSys/ShortNameCreationSettings](./policy-csp-admx-filesys.md#admx-filesys-shortnamecreationsettings)
- [ADMX_FileSys/SymlinkEvaluation](./policy-csp-admx-filesys.md#admx-filesys-symlinkevaluation)
- [ADMX_FileSys/TxfDeprecatedFunctionality](./policy-csp-admx-filesys.md#admx-filesys-txfdeprecatedfunctionality)
+- [ADMX_FileRecovery/WdiScenarioExecutionPolicy](./policy-csp-admx-filerecovery.md#admx-filerecovery-WdiScenarioExecutionPolicy)
- [ADMX_FolderRedirection/DisableFRAdminPin](./policy-csp-admx-folderredirection.md#admx-folderredirection-disablefradminpin)
- [ADMX_FolderRedirection/DisableFRAdminPinByFolder](./policy-csp-admx-folderredirection.md#admx-folderredirection-disablefradminpinbyfolder)
- [ADMX_FolderRedirection/FolderRedirectionEnableCacheRename](./policy-csp-admx-folderredirection.md#admx-folderredirection-folderredirectionenablecacherename)
diff --git a/windows/client-management/mdm/policy-csp-admx-filerecovery.md b/windows/client-management/mdm/policy-csp-admx-filerecovery.md
index 6ffae36c4d..a40883ca0e 100644
--- a/windows/client-management/mdm/policy-csp-admx-filerecovery.md
+++ b/windows/client-management/mdm/policy-csp-admx-filerecovery.md
@@ -6,7 +6,7 @@ ms.localizationpriority: medium
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: manikadhiman
+author: Nimisha
ms.date: 09/02/2021
ms.reviewer:
manager: dansimp
From 92fc62a3fc336c449c68994b3c00fdb9e2996392 Mon Sep 17 00:00:00 2001
From: greg-lindsay
Date: Fri, 12 Feb 2021 10:43:34 -0800
Subject: [PATCH 013/434] yml index and toc
---
.openpublishing.redirection.json | 5 +
windows/configuration/TOC.md | 177 -------------
windows/configuration/TOC.yml | 24 ++
...change-history-for-configure-windows-10.md | 236 ------------------
windows/configuration/docfx.json | 3 +-
windows/configuration/index.md | 41 ---
windows/configuration/index.yml | 68 +++++
7 files changed, 99 insertions(+), 455 deletions(-)
delete mode 100644 windows/configuration/TOC.md
create mode 100644 windows/configuration/TOC.yml
delete mode 100644 windows/configuration/change-history-for-configure-windows-10.md
delete mode 100644 windows/configuration/index.md
create mode 100644 windows/configuration/index.yml
diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json
index f072b252df..5c5f396138 100644
--- a/.openpublishing.redirection.json
+++ b/.openpublishing.redirection.json
@@ -16534,6 +16534,11 @@
"source_path": "windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md",
"redirect_url": "https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-asr",
"redirect_document_id": false
+ },
+ {
+ "source_path": "windows/configuration/change-history-for-configure-windows-10.md",
+ "redirect_url": "https://docs.microsoft.com/windows/configuration",
+ "redirect_document_id": false
}
]
}
diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md
deleted file mode 100644
index 0d01784273..0000000000
--- a/windows/configuration/TOC.md
+++ /dev/null
@@ -1,177 +0,0 @@
-# [Configure Windows 10](index.md)
-## [Accessibility information for IT Pros](windows-10-accessibility-for-ITPros.md)
-## [Configure access to Microsoft Store](stop-employees-from-using-microsoft-store.md)
-## [Configure Cortana in Windows 10](cortana-at-work/cortana-at-work-overview.md)
-## [Set up and test Cortana in Windows 10, version 2004 and later](cortana-at-work/set-up-and-test-cortana-in-windows-10.md)
-## [Testing scenarios using Cortana in your business or organization](cortana-at-work/cortana-at-work-testing-scenarios.md)
-### [Test scenario 1 - Sign into Azure AD, enable the wake word, and try a voice query](cortana-at-work/cortana-at-work-scenario-1.md)
-### [Test scenario 2 - Perform a Bing search with Cortana](cortana-at-work/cortana-at-work-scenario-2.md)
-### [Test scenario 3 - Set a reminder](cortana-at-work/cortana-at-work-scenario-3.md)
-### [Test scenario 4 - Use Cortana to find free time on your calendar](cortana-at-work/cortana-at-work-scenario-4.md)
-### [Test scenario 5 - Find out about a person](cortana-at-work/cortana-at-work-scenario-5.md)
-### [Test scenario 6 - Change your language and perform a quick search with Cortana](cortana-at-work/cortana-at-work-scenario-6.md)
-## [Send feedback about Cortana back to Microsoft](cortana-at-work/cortana-at-work-feedback.md)
-## [Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization](cortana-at-work/cortana-at-work-o365.md)
-## [Testing scenarios using Cortana in your business or organization](cortana-at-work/cortana-at-work-testing-scenarios.md)
-### [Test scenario 1 - Sign into Azure AD, enable the wake word, and try a voice query](cortana-at-work/test-scenario-1.md)
-### [Test scenario 2 - Perform a quick search with Cortana at work](cortana-at-work/test-scenario-2.md)
-### [Test scenario 3 - Set a reminder for a specific location using Cortana at work](cortana-at-work/test-scenario-3.md)
-### [Test scenario 4 - Use Cortana at work to find your upcoming meetings](cortana-at-work/test-scenario-4.md)
-### [Test scenario 5 - Use Cortana to send email to a co-worker](cortana-at-work/test-scenario-5.md)
-### [Test scenario 6 - Review a reminder suggested by Cortana based on what you’ve promised in email](cortana-at-work/test-scenario-6.md)
-### [Test scenario 7 - Use Cortana and Windows Information Protection (WIP) to help protect your organization’s data on a device](cortana-at-work/cortana-at-work-scenario-7.md)
-## [Set up and test custom voice commands in Cortana for your organization](cortana-at-work/cortana-at-work-voice-commands.md)
-## [Use Group Policy and mobile device management (MDM) settings to configure Cortana in your organization](cortana-at-work/cortana-at-work-policy-settings.md)
-## [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md)
-## [Configure kiosks and digital signs on Windows desktop editions](kiosk-methods.md)
-### [Prepare a device for kiosk configuration](kiosk-prepare.md)
-### [Set up digital signs on Windows 10](setup-digital-signage.md)
-### [Set up a single-app kiosk](kiosk-single-app.md)
-### [Set up a multi-app kiosk](lock-down-windows-10-to-specific-apps.md)
-### [More kiosk methods and reference information](kiosk-additional-reference.md)
-#### [Find the Application User Model ID of an installed app](find-the-application-user-model-id-of-an-installed-app.md)
-#### [Validate your kiosk configuration](kiosk-validate.md)
-#### [Guidelines for choosing an app for assigned access (kiosk mode)](guidelines-for-assigned-access-app.md)
-#### [Policies enforced on kiosk devices](kiosk-policies.md)
-#### [Assigned access XML reference](kiosk-xml.md)
-#### [Use AppLocker to create a Windows 10 kiosk](lock-down-windows-10-applocker.md)
-#### [Use Shell Launcher to create a Windows 10 kiosk](kiosk-shelllauncher.md)
-#### [Use MDM Bridge WMI Provider to create a Windows 10 kiosk](kiosk-mdm-bridge.md)
-#### [Troubleshoot kiosk mode issues](kiosk-troubleshoot.md)
-## [Configure Windows Spotlight on the lock screen](windows-spotlight.md)
-## [Manage Windows 10 and Microsoft Store tips, "fun facts", and suggestions](manage-tips-and-suggestions.md)
-## [Manage Windows 10 Start and taskbar layout](windows-10-start-layout-options-and-policies.md)
-### [Configure Windows 10 taskbar](configure-windows-10-taskbar.md)
-### [Customize and export Start layout](customize-and-export-start-layout.md)
-### [Add image for secondary tiles](start-secondary-tiles.md)
-### [Start layout XML for desktop editions of Windows 10 (reference)](start-layout-xml-desktop.md)
-### [Customize Windows 10 Start and taskbar with Group Policy](customize-windows-10-start-screens-by-using-group-policy.md)
-### [Customize Windows 10 Start and taskbar with provisioning packages](customize-windows-10-start-screens-by-using-provisioning-packages-and-icd.md)
-### [Customize Windows 10 Start and taskbar with mobile device management (MDM)](customize-windows-10-start-screens-by-using-mobile-device-management.md)
-### [Troubleshoot Start menu errors](start-layout-troubleshoot.md)
-### [Changes to Start policies in Windows 10](changes-to-start-policies-in-windows-10.md)
-## [Provisioning packages for Windows 10](provisioning-packages/provisioning-packages.md)
-### [How provisioning works in Windows 10](provisioning-packages/provisioning-how-it-works.md)
-### [Introduction to configuration service providers (CSPs)](provisioning-packages/how-it-pros-can-use-configuration-service-providers.md)
-### [Install Windows Configuration Designer](provisioning-packages/provisioning-install-icd.md)
-### [Create a provisioning package](provisioning-packages/provisioning-create-package.md)
-### [Apply a provisioning package](provisioning-packages/provisioning-apply-package.md)
-### [Settings changed when you uninstall a provisioning package](provisioning-packages/provisioning-uninstall-package.md)
-### [Provision PCs with common settings for initial deployment (desktop wizard)](provisioning-packages/provision-pcs-for-initial-deployment.md)
-### [Provision PCs with apps](provisioning-packages/provision-pcs-with-apps.md)
-### [Use a script to install a desktop app in provisioning packages](provisioning-packages/provisioning-script-to-install-app.md)
-### [Create a provisioning package with multivariant settings](provisioning-packages/provisioning-multivariant.md)
-### [PowerShell cmdlets for provisioning Windows 10 (reference)](provisioning-packages/provisioning-powershell.md)
-### [Windows Configuration Designer command-line interface (reference)](provisioning-packages/provisioning-command-line.md)
-### [Windows Configuration Designer provisioning settings (reference)](wcd/wcd.md)
-#### [Changes to settings in Windows Configuration Designer](wcd/wcd-changes.md)
-#### [AccountManagement](wcd/wcd-accountmanagement.md)
-#### [Accounts](wcd/wcd-accounts.md)
-#### [ADMXIngestion](wcd/wcd-admxingestion.md)
-#### [AssignedAccess](wcd/wcd-assignedaccess.md)
-#### [AutomaticTime](wcd/wcd-automatictime.md)
-#### [Browser](wcd/wcd-browser.md)
-#### [CallAndMessagingEnhancement](wcd/wcd-callandmessagingenhancement.md)
-#### [Calling](wcd/wcd-calling.md)
-#### [CellCore](wcd/wcd-cellcore.md)
-#### [Cellular](wcd/wcd-cellular.md)
-#### [Certificates](wcd/wcd-certificates.md)
-#### [CleanPC](wcd/wcd-cleanpc.md)
-#### [Connections](wcd/wcd-connections.md)
-#### [ConnectivityProfiles](wcd/wcd-connectivityprofiles.md)
-#### [CountryAndRegion](wcd/wcd-countryandregion.md)
-#### [DesktopBackgroundAndColors](wcd/wcd-desktopbackgroundandcolors.md)
-#### [DeveloperSetup](wcd/wcd-developersetup.md)
-#### [DeviceFormFactor](wcd/wcd-deviceformfactor.md)
-#### [DeviceInfo](wcd/wcd-deviceinfo.md)
-#### [DeviceManagement](wcd/wcd-devicemanagement.md)
-#### [DeviceUpdateCenter](wcd/wcd-deviceupdatecenter.md)
-#### [DMClient](wcd/wcd-dmclient.md)
-#### [EditionUpgrade](wcd/wcd-editionupgrade.md)
-#### [EmbeddedLockdownProfiles](wcd/wcd-embeddedlockdownprofiles.md)
-#### [FirewallConfiguration](wcd/wcd-firewallconfiguration.md)
-#### [FirstExperience](wcd/wcd-firstexperience.md)
-#### [Folders](wcd/wcd-folders.md)
-#### [HotSpot](wcd/wcd-hotspot.md)
-#### [InitialSetup](wcd/wcd-initialsetup.md)
-#### [InternetExplorer](wcd/wcd-internetexplorer.md)
-#### [KioskBrowser](wcd/wcd-kioskbrowser.md)
-#### [Licensing](wcd/wcd-licensing.md)
-#### [Location](wcd/wcd-location.md)
-#### [Maps](wcd/wcd-maps.md)
-#### [Messaging](wcd/wcd-messaging.md)
-#### [ModemConfigurations](wcd/wcd-modemconfigurations.md)
-#### [Multivariant](wcd/wcd-multivariant.md)
-#### [NetworkProxy](wcd/wcd-networkproxy.md)
-#### [NetworkQOSPolicy](wcd/wcd-networkqospolicy.md)
-#### [NFC](wcd/wcd-nfc.md)
-#### [OOBE](wcd/wcd-oobe.md)
-#### [OtherAssets](wcd/wcd-otherassets.md)
-#### [Personalization](wcd/wcd-personalization.md)
-#### [Policies](wcd/wcd-policies.md)
-#### [Privacy](wcd/wcd-privacy.md)
-#### [ProvisioningCommands](wcd/wcd-provisioningcommands.md)
-#### [RcsPresence](wcd/wcd-rcspresence.md)
-#### [SharedPC](wcd/wcd-sharedpc.md)
-#### [Shell](wcd/wcd-shell.md)
-#### [SMISettings](wcd/wcd-smisettings.md)
-#### [Start](wcd/wcd-start.md)
-#### [StartupApp](wcd/wcd-startupapp.md)
-#### [StartupBackgroundTasks](wcd/wcd-startupbackgroundtasks.md)
-#### [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md)
-#### [SurfaceHubManagement](wcd/wcd-surfacehubmanagement.md)
-#### [TabletMode](wcd/wcd-tabletmode.md)
-#### [TakeATest](wcd/wcd-takeatest.md)
-#### [TextInput](wcd/wcd-textinput.md)
-#### [Theme](wcd/wcd-theme.md)
-#### [Time](wcd/wcd-time.md)
-#### [UnifiedWriteFilter](wcd/wcd-unifiedwritefilter.md)
-#### [UniversalAppInstall](wcd/wcd-universalappinstall.md)
-#### [UniversalAppUninstall](wcd/wcd-universalappuninstall.md)
-#### [UsbErrorsOEMOverride](wcd/wcd-usberrorsoemoverride.md)
-#### [WeakCharger](wcd/wcd-weakcharger.md)
-#### [WindowsHelloForBusiness](wcd/wcd-windowshelloforbusiness.md)
-#### [WindowsTeamSettings](wcd/wcd-windowsteamsettings.md)
-#### [WLAN](wcd/wcd-wlan.md)
-#### [Workplace](wcd/wcd-workplace.md)
-## [Configure cellular settings for tablets and PCs](provisioning-apn.md)
-## [Lockdown features from Windows Embedded 8.1 Industry](lockdown-features-windows-10.md)
-## [User Experience Virtualization (UE-V) for Windows](ue-v/uev-for-windows.md)
-### [Get Started with UE-V](ue-v/uev-getting-started.md)
-#### [What's New in UE-V for Windows 10, version 1607](ue-v/uev-whats-new-in-uev-for-windows.md)
-#### [User Experience Virtualization Release Notes](ue-v/uev-release-notes-1607.md)
-#### [Upgrade to UE-V for Windows 10](ue-v/uev-upgrade-uev-from-previous-releases.md)
-### [Prepare a UE-V Deployment](ue-v/uev-prepare-for-deployment.md)
-#### [Deploy Required UE-V Features](ue-v/uev-deploy-required-features.md)
-#### [Deploy UE-V for use with Custom Applications](ue-v/uev-deploy-uev-for-custom-applications.md)
-### [Administering UE-V](ue-v/uev-administering-uev.md)
-#### [Manage Configurations for UE-V](ue-v/uev-manage-configurations.md)
-##### [Configuring UE-V with Group Policy Objects](ue-v/uev-configuring-uev-with-group-policy-objects.md)
-##### [Configuring UE-V with Microsoft Endpoint Configuration Manager](ue-v/uev-configuring-uev-with-system-center-configuration-manager.md)
-##### [Administering UE-V with Windows PowerShell and WMI](ue-v/uev-administering-uev-with-windows-powershell-and-wmi.md)
-###### [Managing the UE-V Service and Packages with Windows PowerShell and WMI](ue-v/uev-managing-uev-agent-and-packages-with-windows-powershell-and-wmi.md)
-###### [Managing UE-V Settings Location Templates Using Windows PowerShell and WMI](ue-v/uev-managing-settings-location-templates-using-windows-powershell-and-wmi.md)
-#### [Working with Custom UE-V Templates and the UE-V Template Generator](ue-v/uev-working-with-custom-templates-and-the-uev-generator.md)
-#### [Manage Administrative Backup and Restore in UE-V](ue-v/uev-manage-administrative-backup-and-restore.md)
-#### [Changing the Frequency of UE-V Scheduled Tasks](ue-v/uev-changing-the-frequency-of-scheduled-tasks.md)
-#### [Migrating UE-V Settings Packages](ue-v/uev-migrating-settings-packages.md)
-#### [Using UE-V with Application Virtualization Applications](ue-v/uev-using-uev-with-application-virtualization-applications.md)
-### [Troubleshooting UE-V](ue-v/uev-troubleshooting.md)
-### [Technical Reference for UE-V](ue-v/uev-technical-reference.md)
-#### [Sync Methods for UE-V](ue-v/uev-sync-methods.md)
-#### [Sync Trigger Events for UE-V](ue-v/uev-sync-trigger-events.md)
-#### [Synchronizing Microsoft Office with UE-V](ue-v/uev-synchronizing-microsoft-office-with-uev.md)
-#### [Application Template Schema Reference for UE-V](ue-v/uev-application-template-schema-reference.md)
-#### [Security Considerations for UE-V](ue-v/uev-security-considerations.md)
-## [Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md)
-## [Configure Windows 10 Mobile devices](mobile-devices/configure-mobile.md)
-### [Set up a kiosk on Windows 10 Mobile or Windows 10 Mobile Enterprise](mobile-devices/set-up-a-kiosk-for-windows-10-for-mobile-edition.md)
-### [Use Windows Configuration Designer to configure Windows 10 Mobile devices](mobile-devices/provisioning-configure-mobile.md)
-#### [NFC-based device provisioning](mobile-devices/provisioning-nfc.md)
-#### [Barcode provisioning and the package splitter tool](mobile-devices/provisioning-package-splitter.md)
-### [Use the Lockdown Designer app to create a Lockdown XML file](mobile-devices/mobile-lockdown-designer.md)
-### [Configure Windows 10 Mobile using Lockdown XML](mobile-devices/lockdown-xml.md)
-### [Settings and quick actions that can be locked down in Windows 10 Mobile](mobile-devices/settings-that-can-be-locked-down.md)
-### [Product IDs in Windows 10 Mobile](mobile-devices/product-ids-in-windows-10-mobile.md)
-### [Start layout XML for mobile editions of Windows 10 (reference)](mobile-devices/start-layout-xml-mobile.md)
-## [Change history for Configure Windows 10](change-history-for-configure-windows-10.md)
diff --git a/windows/configuration/TOC.yml b/windows/configuration/TOC.yml
new file mode 100644
index 0000000000..a0d1667af2
--- /dev/null
+++ b/windows/configuration/TOC.yml
@@ -0,0 +1,24 @@
+- name: What's new in Windows 10
+ href: index.yml
+- name: What's new in Windows 10, version 20H2
+ href: whats-new-windows-10-version-20H2.md
+- name: What's new in Windows 10, version 2004
+ href: whats-new-windows-10-version-2004.md
+- name: What's new in Windows 10, version 1909
+ href: whats-new-windows-10-version-1909.md
+- name: What's new in Windows 10, version 1903
+ href: whats-new-windows-10-version-1903.md
+- name: What's new in Windows 10, version 1809
+ href: whats-new-windows-10-version-1809.md
+- name: What's new in Windows 10, version 1803
+ href: whats-new-windows-10-version-1803.md
+- name: Previous versions
+ items:
+ - name: What's new in Windows 10, version 1709
+ href: whats-new-windows-10-version-1709.md
+ - name: What's new in Windows 10, version 1703
+ href: whats-new-windows-10-version-1703.md
+ - name: What's new in Windows 10, version 1607
+ href: whats-new-windows-10-version-1607.md
+ - name: What's new in Windows 10, versions 1507 and 1511
+ href: whats-new-windows-10-version-1507-and-1511.md
\ No newline at end of file
diff --git a/windows/configuration/change-history-for-configure-windows-10.md b/windows/configuration/change-history-for-configure-windows-10.md
deleted file mode 100644
index 875beb0290..0000000000
--- a/windows/configuration/change-history-for-configure-windows-10.md
+++ /dev/null
@@ -1,236 +0,0 @@
----
-title: Change history for Configure Windows 10 (Windows 10)
-ms.reviewer:
-manager: dansimp
-description: Learn about new and updated topics in the Configure Windows 10 documentation for Windows 10 and Windows 10 Mobile.
-keywords:
-ms.prod: w10
-ms.mktglfcycl: manage
-ms.sitesec: library
-ms.pagetype: security
-ms.localizationpriority: medium
-author: dansimp
-ms.author: dansimp
-ms.topic: article
-ms.date: 10/03/2019
----
-
-# Change history for Configure Windows 10
-
-This topic lists new and updated topics in the [Configure Windows 10](index.md) documentation for Windows 10 and Windows 10 Mobile.
-
-## April 2019
-
-New or changed topic | Description
---- | ---
-[Use Shell Launcher to create a Windows 10 kiosk](kiosk-shelllauncher.md) | Added information for Shell Launcher v2, coming in the next feature update to Windows 10.
-[Prepare a device for kiosk configuration](kiosk-prepare.md) | Added new recommendations for policies to manage updates.
-
-## February 2019
-
-New or changed topic | Description
---- | ---
-[Set up a single-app kiosk](kiosk-single-app.md) | Replaced instructions for Microsoft Intune with a link to the Intune documentation.
-[Set up a multi-app kiosk](lock-down-windows-10-to-specific-apps.md) | Replaced instructions for Intune with a link to the Intune documentation.
-
-## January 2019
-
-New or changed topic | Description
---- | ---
-[Prepare a device for kiosk configuration](kiosk-prepare.md) | Added how to connect to a single-app kiosk in a virtual machine (VM) for testing.
-
-## November 2018
-
-New or changed topic | Description
---- | ---
-[Use MDM Bridge WMI Provider to create a Windows 10 kiosk](kiosk-mdm-bridge.md) | Updated script.
-
-## October 2018
-
-New or changed topic | Description
---- | ---
-[Troubleshoot multi-app kiosk](multi-app-kiosk-troubleshoot.md) and [Set up a single-app kiosk](kiosk-single-app.md) | Added event log path for auto-logon issues.
-
-## RELEASE: Windows 10, version 1809
-
-The topics in this library have been updated for Windows 10, version 1809. The following new topic has been added:
-
-- [Changes to settings in Windows Configuration Designer](wcd/wcd-changes.md)
-
-## September 2018
-
-New or changed topic | Description
---- | ---
-[Find the Application User Model ID of an installed app](find-the-application-user-model-id-of-an-installed-app.md) | New
-[Start layout XML for desktop editions of Windows 10 (reference)](start-layout-xml-desktop.md) | Add required order of elements in XML.
-
-## August 2018
-
-New or changed topic | Description
---- | ---
-[Guidelines for choosing an app for assigned access (kiosk mode)](guidelines-for-assigned-access-app.md) | Added instructions for specifying multiple URLs in configuration settings for Kiosk Browser.
-
-## July 2018
-
-New or changed topic | Description
---- | ---
-[Configure kiosks and child topics](kiosk-methods.md) | Reorganized the information for configuring kiosks into new topics, and moved [Set up shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md).
-
-## June 2018
-
-New or changed topic | Description
---- | ---
-[Set up a kiosk or digital signage on Windows 10 Pro, Enterprise, or Education](setup-kiosk-digital-signage.md) and [Create a Windows 10 kiosk that runs multiple apps](lock-down-windows-10-to-specific-apps.md) | Updated instructions for using Microsoft Intune to configure a kiosk. Added instructions for showing local accounts on the sign-in screen for domain-joined devices.
-[Manage Windows 10 Start and taskbar layout](windows-10-start-layout-options-and-policies.md) | Added new Group Policy to remove "Recently added" list from Start menu.
-|[Add image for secondary tiles](start-secondary-tiles.md#using-mdm) | Updated mobile device management (MDM) instructions. |
-
-## May 2018
-
-New or changed topic | Description
---- | ---
-[Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Added note that Wi-Fi Sense is no longer available.
-Topics about Windows 10 diagnostic data | Moved to [Windows Privacy](https://docs.microsoft.com/windows/privacy/).
-[Guidelines for choosing an app for assigned access (kiosk mode)](guidelines-for-assigned-access-app.md) | Added information on Kiosk Browser settings and URL filtering.
-[Manage Windows 10 Start and taskbar layout](windows-10-start-layout-options-and-policies.md) | Added details of event log entries to check for when customization is not applied as expected.
-[Set up a kiosk or digital signage on Windows 10 Pro, Enterprise, or Education](setup-kiosk-digital-signage.md) | Added Active Directory domain account to provisioning method.
-
-## RELEASE: Windows 10, version 1803
-
-The topics in this library have been updated for Windows 10, version 1803. The following new topics have been added:
-
-- Windows Configuration Designer setting: [AccountManagement](wcd/wcd-accountmanagement.md)
-- Windows Configuration Designer setting: [RcsPresence](wcd/wcd-rcspresence.md)
-
-The following topics were moved into the [Privacy](/windows/privacy/index) library:
-
-- [Configure Windows diagnostic data in your organization](/windows/privacy/configure-windows-diagnostic-data-in-your-organization)
-- [Diagnostic Data Viewer Overview](/windows/privacy/diagnostic-data-viewer-overview)
-- [Windows 10, version 1803 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields)
-- [Windows 10, version 1709 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709)
-- [Windows 10, version 1703 basic level Windows diagnostic events and fields](/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)
-- [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields)
-- [Windows 10, version 1709 diagnostic data for the Full level](/windows/privacy/windows-diagnostic-data)
-- [Windows 10, version 1703 diagnostic data for the Full level](/windows/privacy/windows-diagnostic-data-1703)
-- [Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](/windows/privacy/gdpr-win10-whitepaper)
-- [Manage connections from Windows operating system components to Microsoft services](/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services)
-- [Manage Windows 10 connection endpoints](/windows/privacy/manage-windows-endpoints-version-1709)
-
-## April 2018
-
-New or changed topic | Description
---- | ---
-[Configure Windows diagnostic data in your organization](https://docs.microsoft.com/windows/privacy/configure-windows-diagnostic-data-in-your-organization) | Updated endpoints.
-[Configure cellular settings for tablets and PCs](provisioning-apn.md) | Added instructions for confirming that the settings were applied.
-
-## March 2018
-
-New or changed topic | Description
---- | ---
-[Windows 10, version 1709 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709) and [Windows 10, version 1703 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703) | Added events and fields that were added in the March update.
-Set up a kiosk on Windows 10 Pro, Enterprise, or Education | Renamed it **Set up a kiosk or digital signage on Windows 10 Pro, Enterprise, or Education** and reorganized the information to make the choices clearer.
-
-
-## February 2018
-
-New or changed topic | Description
---- | ---
-[Windows 10, version 1709 basic diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709) and [Windows 10, version 1703 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703) | Added events and fields that were added in the February update.
-[Create a Windows 10 kiosk that runs multiple apps](lock-down-windows-10-to-specific-apps.md) | Added steps for configuring a kiosk in Microsoft Intune.
-[Customize Windows 10 Start and taskbar with mobile device management (MDM)](customize-windows-10-start-screens-by-using-mobile-device-management.md) | Updated the instructions for applying a customized Start layout using Microsoft Intune.
-
-## January 2018
-
-New or changed topic | Description
---- | ---
-[Create a Windows 10 kiosk that runs multiple apps](lock-down-windows-10-to-specific-apps.md) | Added videos demonstrating how to use Microsoft Intune and how to use provisioning packages to configure multi-app kiosks.
-[ConnectivityProfiles](wcd/wcd-connectivityprofiles.md) | Added settings for VPN **Native** and **Third Party** profile types.
-[Start layout XML for desktop editions of Windows 10 (reference)](start-layout-xml-desktop.md) | Clarified that the TopMFUApps elements in layoutmodification.xml are not supported in Windows 10, version 1709.
-| [Diagnostic Data Viewer Overview](https://docs.microsoft.com/windows/privacy/diagnostic-data-viewer-overviewd) | New topic |
-[Configure Windows 10 taskbar](configure-windows-10-taskbar.md) | Added section for removing default apps from the taskbar.
-[Manage Windows 10 connection endpoints](https://docs.microsoft.com/windows/privacy/manage-windows-1709-endpoints) | New topic for Windows 10, version 1709 that explains the purpose for connections to Microsoft services and how to manage them.
-[Configure Windows Spotlight on the lock screen](windows-spotlight.md) | Added section for resolution of custom lock screen images.
-[Set up a kiosk on Windows 10 Pro, Enterprise, or Education](set-up-a-kiosk-for-windows-10-for-desktop-editions.md) | Added section for automatic sign-in after restart on unmanaged devices.
-
-
-## November 2017
-
-New or changed topic | Description
---- | ---
-|[Windows 10, version 1703 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)| Added events that were added in November. |
-[Create a provisioning package with multivariant settings](provisioning-packages/provisioning-multivariant.md) | Add support for desktop to [Conditions](provisioning-packages/provisioning-multivariant.md#conditions) table.
-
-## October 2017
-
-| New or changed topic | Description |
-|---------------------------------------------------------------------------------------------|----------------------------------------------------------------|
-| [Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added that Microsoft Edge is not supported for assigned access |
-
-## RELEASE: Windows 10, version 1709
-
-The topics in this library have been updated for Windows 10, version 1709 (also known as the Fall Creators Update). The following new topics have been added:
-
-- [Create a Windows 10 kiosk that runs multiple apps](lock-down-windows-10-to-specific-apps.md)
-- [Multi-app kiosk XML reference](multi-app-kiosk-xml.md)
-- [Windows 10, version 1709 basic diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709)
-- [Windows 10, version 1709 enhanced diagnostic data events and fields used by Windows Analytics](https://docs.microsoft.com/windows/privacy/enhanced-diagnostic-data-windows-analytics-events-and-fields)
-
-
-## September 2017
-
-|New or changed topic | Description|
-|--- | ---|
-|[Beginning your General Data Protection Regulation (GDPR) journey for Windows 10](https://docs.microsoft.com/windows/privacy/gdpr-win10-whitepaper)|New conceptual info about Windows 10 and the upcoming GDPR-compliance requirements.|
-|[Manage connections from Windows operating system components to Microsoft services](https://docs.microsoft.com/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) | Added that Windows Spotlight can be managed by the Experience/AllowWindowsSpotlight MDM policy. |
-
-
-
-## August 2017
-
-|New or changed topic | Description|
-|--- | ---|
-|[Windows Configuration Designer provisioning settings (reference)](wcd/wcd.md) | New section; reference content from [Windows Provisioning settings reference](https://msdn.microsoft.com/library/windows/hardware/dn965990.aspx) is being relocated here from MSDN. |
-
-
-## July 2017
-
-| New or changed topic | Description |
-| --- | --- |
-|[Windows 10, version 1703 Diagnostic Data](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)|Updated categories and included diagnostic data.|
-|[Add image for secondary tiles](start-secondary-tiles.md) | Added XML example for Edge secondary tiles and **ImportEdgeAssets** |
-|[Customize and export Start layout](customize-and-export-start-layout.md) | Added explanation for tile behavior when the app is not installed |
-|[Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added that Microsoft Edge is not supported for assigned access |
-|[Windows 10, version 1703 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)|Updated several Appraiser events and added Census.Speech. |
-|[Manage connections from Windows operating system components to Microsoft-services](https://docs.microsoft.com/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) | Updated Date & Time and Windows spotlight sections. |
-
-## June 2017
-
-| New or changed topic | Description |
-| --- | --- |
-| [Guidelines for choosing an app for assigned access](guidelines-for-assigned-access-app.md) | Added guidelines for using Remote Desktop app as the kiosk app and added a general guideline that apps generated using the Desktop App Converter cannot be used for kiosk apps |
-| [Set up a kiosk on Windows 10 Pro, Enterprise, or Education](set-up-a-kiosk-for-windows-10-for-desktop-editions.md) | Added warning about using Shell Launcher to set a custom shell with an application that launches a different process and then exits |
-| [Windows Configuration Designer command-line interface (reference)](provisioning-packages/provisioning-command-line.md) | Removed references to imaging |
-
-## May 2017
-
-| New or changed topic | Description |
-| --- | --- |
-| [Configure cellular settings for tablets and PCs](provisioning-apn.md) | New |
-| [Manage connections from Windows operating system components to Microsoft services](https://docs.microsoft.com/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) | Added MDM policies for privacy settings |
-
-
-## April 2017
-
-| New or changed topic | Description |
-| --- | --- |
-| [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md) | Added instructions for using WMI bridge to configure shared PC |
-
-
-
-## RELEASE: Windows 10, version 1703
-
-The topics in this library have been updated for Windows 10, version 1703 (also known as the Creators Update). The following new topics have been added:
-
-- [Use the Lockdown Designer app to create a Lockdown XML file](mobile-devices/mobile-lockdown-designer.md)
-- [Add image for secondary tiles](start-secondary-tiles.md)
-- [Provision PCs with apps](provisioning-packages/provision-pcs-with-apps.md)
-- [Windows 10, version 1703 basic level Windows diagnostic events and fields](https://docs.microsoft.com/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703)
diff --git a/windows/configuration/docfx.json b/windows/configuration/docfx.json
index 7b6e54aa9f..fb4beeae51 100644
--- a/windows/configuration/docfx.json
+++ b/windows/configuration/docfx.json
@@ -3,7 +3,8 @@
"content": [
{
"files": [
- "**/*.md"
+ "**/*.md",
+ "**/*.yml"
],
"exclude": [
"**/obj/**",
diff --git a/windows/configuration/index.md b/windows/configuration/index.md
deleted file mode 100644
index 6d72ff398f..0000000000
--- a/windows/configuration/index.md
+++ /dev/null
@@ -1,41 +0,0 @@
----
-title: Configure Windows 10 (Windows 10)
-description: Apply custom accessibility configurations to devices for their users using the all the features and methods available with Windows 10.
-keywords: Windows 10, MDM, WSUS, Windows update
-ms.prod: w10
-ms.mktglfcycl: manage
-ms.sitesec: library
-ms.pagetype: security
-ms.localizationpriority: high
-manager: dansimp
-author: dansimp
-ms.author: dansimp
-ms.topic: article
----
-
-# Configure Windows 10
-
-Enterprises often need to apply custom configurations to devices for their users. Windows 10 provides a number of features and methods to help you configure or lock down specific parts of Windows 10.
-
-## In this section
-
-| Topic | Description |
-| --- | --- |
-| [Accessibility information for IT Pros](windows-10-accessibility-for-ITPros.md) | Windows 10 includes accessibility features that benefit all users. These features make it easier to customize the computer and give users with different abilities options to improve their experience with Windows. This topic helps IT administrators learn about built-in accessibility features. |
-| [Configure access to Microsoft Store](stop-employees-from-using-the-windows-store.md) | IT Pros can configure access to Microsoft Store for client computers in their organization. For some organizations, business policies require blocking access to Microsoft Store. |
-| [Cortana integration in your business or enterprise](cortana-at-work/cortana-at-work-overview.md) | The world’s first personal digital assistant helps users get things done, even at work. Cortana includes powerful configuration options specifically to optimize for unique small to medium-sized business and enterprise environments. |
-| [Set up a shared or guest PC with Windows 10](set-up-shared-or-guest-pc.md) | Windows 10, version 1607, introduced *shared PC mode*, which optimizes Windows 10 for shared use scenarios, such as touchdown spaces in an enterprise and temporary customer use in retail. |
-| [Configure kiosk and digital signage devices running Windows 10 desktop editions](kiosk-methods.md) | These topics help you configure Windows 10 devices to run as a kiosk device. |
-| [Windows Spotlight on the lock screen](windows-spotlight.md) | Windows Spotlight is an option for the lock screen background that displays different background images and occasionally offers suggestions on the lock screen.**Note:** You can also use the [Personalization CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/personalization-csp) settings to set lock screen and desktop background images. |
-| [Manage Windows 10 and Microsoft Store tips, tricks, and suggestions](manage-tips-and-suggestions.md) | Options to manage the tips, tricks, and suggestions offered by Windows and Microsoft Store. |
-| [Manage Windows 10 Start and taskbar layout](windows-10-start-layout-options-and-policies.md) | Organizations might want to deploy a customized Start screen and menu to devices running Windows 10 Pro, Enterprise, or Education. A standard Start layout can be useful on devices that are common to multiple users and devices that are locked down for specialized purposes. |
-| [Provisioning packages for Windows 10](provisioning-packages/provisioning-packages.md) | Learn how to use the Windows Configuration Designer and provisioning packages to easily configure multiple devices. |
-| [Configure cellular settings for tablets and PCs](provisioning-apn.md) | Enterprises can provision cellular settings for tablets and PC with built-in cellular modems or plug-in USB modem dongles. |
-| [Lockdown features from Windows Embedded 8.1 Industry](lockdown-features-windows-10.md) | Many of the lockdown features available in Windows Embedded 8.1 Industry have been modified in some form for Windows 10. |
-| [Manage Wi-Fi Sense in your company](manage-wifi-sense-in-enterprise.md) | Wi-Fi Sense automatically connects you to Wi-Fi, so you can get online quickly in more places. It can connect you to open Wi-Fi hotspots it knows about through crowdsourcing, or to Wi-Fi networks your contacts have shared with you by using Wi-Fi Sense. The initial settings for Wi-Fi Sense are determined by the options you chose when you first set up your PC with Windows 10.|
-| [Configure Windows 10 Mobile devices](mobile-devices/configure-mobile.md) | These topics help you configure the features and apps and Start screen for a device running Windows 10 Mobile, as well as how to configure a kiosk device that runs a single app. |
-| [Change history for Configure Windows 10](change-history-for-configure-windows-10.md) | This topic lists new and updated topics in the Configure Windows 10 documentation for Windows 10 and Windows 10 Mobile. |
-
-
-
-
diff --git a/windows/configuration/index.yml b/windows/configuration/index.yml
new file mode 100644
index 0000000000..20d56ff5c8
--- /dev/null
+++ b/windows/configuration/index.yml
@@ -0,0 +1,68 @@
+### YamlMime:Landing
+
+title: What's new in Windows 10 # < 60 chars
+summary: Find out about new features and capabilities in the latest release of Windows 10. # < 160 chars
+
+metadata:
+ title: What's new in Windows 10 # Required; page title displayed in search results. Include the brand. < 60 chars.
+ description: Find out about new features and capabilities in the latest release of Windows 10. # Required; article description that is displayed in search results. < 160 chars.
+ services: windows-10
+ ms.service: windows-10 #Required; service per approved list. service slug assigned to your service by ACOM.
+ ms.subservice: subservice
+ ms.topic: landing-page # Required
+ ms.collection: windows-10
+ author: greg-lindsay #Required; your GitHub user alias, with correct capitalization.
+ ms.author: greglin #Required; microsoft alias of author; optional team alias.
+ ms.date: 02/09/2021 #Required; mm/dd/yyyy format.
+ localization_priority: medium
+
+# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | video | whats-new
+
+landingContent:
+# Cards and links should be based on top customer tasks or top subjects
+# Start card title with a verb
+ # Card (optional)
+ - title: What's new in Windows 10
+ linkLists:
+ - linkListType: overview
+ links:
+ - text: What's new in Windows 10, version 20H2
+ url: whats-new-windows-10-version-20H2.md
+ - text: What's new in Windows 10, version 2004
+ url: whats-new-windows-10-version-2004.md
+ - text: What's new in Windows 10, version 1909
+ url: whats-new-windows-10-version-1909.md
+ - text: What's new in Windows 10, version 1903
+ url: whats-new-windows-10-version-1903.md
+ - text: What's new in Windows 10, version 1809
+ url: whats-new-windows-10-version-1809.md
+ - text: What's new in Windows 10, version 1803
+ url: whats-new-windows-10-version-1803.md
+
+ # Card (optional)
+ - title: Learn more
+ linkLists:
+ - linkListType: overview
+ links:
+ - text: Windows 10 release information
+ url: https://docs.microsoft.com/en-us/windows/release-health/release-information
+ - text: Windows 10 release health dashboard
+ url: https://docs.microsoft.com/windows/release-information/
+ - text: Windows 10 update history
+ url: https://support.microsoft.com/topic/windows-10-update-history-7dd3071a-3906-fa2c-c342-f7f86728a6e3
+ - text: Windows 10 features we’re no longer developing
+ url: https://docs.microsoft.com/windows/deployment/planning/windows-10-deprecated-features
+ - text: Features and functionality removed in Windows 10
+ url: https://docs.microsoft.com/windows/deployment/planning/windows-10-removed-features
+ - text: Compare Windows 10 Editions
+ url: https://go.microsoft.com/fwlink/p/?LinkId=690485
+
+ # Card (optional)
+ - title: See also
+ linkLists:
+ - linkListType: overview
+ links:
+ - text: Windows 10 Enterprise LTSC
+ url: ltsc/index.md
+ - text: Edit an existing topic using the Edit link
+ url: contribute-to-a-topic.md
\ No newline at end of file
From bbcc5d04919353d2d2c915733352ff7e1a4f484e Mon Sep 17 00:00:00 2001
From: greg-lindsay
Date: Tue, 16 Feb 2021 12:24:05 -0800
Subject: [PATCH 014/434] new
---
windows/configuration/TOC.yml | 48 +++++++++++++++++++----------------
1 file changed, 26 insertions(+), 22 deletions(-)
diff --git a/windows/configuration/TOC.yml b/windows/configuration/TOC.yml
index a0d1667af2..e810469e0d 100644
--- a/windows/configuration/TOC.yml
+++ b/windows/configuration/TOC.yml
@@ -1,24 +1,28 @@
-- name: What's new in Windows 10
+- name: Configure Windows 10
href: index.yml
-- name: What's new in Windows 10, version 20H2
- href: whats-new-windows-10-version-20H2.md
-- name: What's new in Windows 10, version 2004
- href: whats-new-windows-10-version-2004.md
-- name: What's new in Windows 10, version 1909
- href: whats-new-windows-10-version-1909.md
-- name: What's new in Windows 10, version 1903
- href: whats-new-windows-10-version-1903.md
-- name: What's new in Windows 10, version 1809
- href: whats-new-windows-10-version-1809.md
-- name: What's new in Windows 10, version 1803
- href: whats-new-windows-10-version-1803.md
-- name: Previous versions
+- name: Accessibility information for IT Pros
+ href: windows-10-accessibility-for-ITPros.md
+- name: Configure access to Microsoft Store
+ href: stop-employees-from-using-microsoft-store.md
+- name: Configure Cortana in Windows 10
+ href: cortana-at-work/cortana-at-work-overview.md
+- name: Set up and test Cortana in Windows 10, version 2004 and later
+ href: cortana-at-work/set-up-and-test-cortana-in-windows-10.md
+- name: Testing scenarios using Cortana in your business or organization
items:
- - name: What's new in Windows 10, version 1709
- href: whats-new-windows-10-version-1709.md
- - name: What's new in Windows 10, version 1703
- href: whats-new-windows-10-version-1703.md
- - name: What's new in Windows 10, version 1607
- href: whats-new-windows-10-version-1607.md
- - name: What's new in Windows 10, versions 1507 and 1511
- href: whats-new-windows-10-version-1507-and-1511.md
\ No newline at end of file
+ - name: Testing scenarios using Cortana in your business or organization
+ href: cortana-at-work/cortana-at-work-testing-scenarios.md
+ - name: Test scenario 1 - Sign into Azure AD, enable the wake word, and try a voice query
+ href: cortana-at-work/cortana-at-work-scenario-1.md
+ - name: Test scenario 2 - Perform a Bing search with Cortana
+ href: cortana-at-work/cortana-at-work-scenario-2.md
+ - name: Test scenario 3 - Set a reminder
+ href: cortana-at-work/cortana-at-work-scenario-3.md
+ - name: Test scenario 4 - Use Cortana to find free time on your calendar
+ href: cortana-at-work/cortana-at-work-scenario-4.md
+ - name: Test scenario 5 - Find out about a person
+ href: cortana-at-work/cortana-at-work-scenario-5.md
+ - name: Test scenario 6 - Change your language and perform a quick search with Cortana
+ href: cortana-at-work/cortana-at-work-scenario-6.md
+- name: Send feedback about Cortana back to Microsoftr
+ href: cortana-at-work/cortana-at-work-feedback.md
\ No newline at end of file
From 28319aff41da8bf65816f6ba16c56c052c024186 Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Fri, 26 Feb 2021 00:39:25 +0530
Subject: [PATCH 015/434] updated
---
windows/client-management/mdm/TOC.md | 1 +
.../mdm/policies-in-policy-csp-admx-backed.md | 1 +
.../policy-configuration-service-provider.md | 8 ++
.../mdm/policy-csp-admx-winsrv.md | 119 ++++++++++++++++++
4 files changed, 129 insertions(+)
create mode 100644 windows/client-management/mdm/policy-csp-admx-winsrv.md
diff --git a/windows/client-management/mdm/TOC.md b/windows/client-management/mdm/TOC.md
index 3675333e76..d2e032e691 100644
--- a/windows/client-management/mdm/TOC.md
+++ b/windows/client-management/mdm/TOC.md
@@ -272,6 +272,7 @@
#### [ADMX_WindowsStore](policy-csp-admx-windowsstore.md)
#### [ADMX_WinInit](policy-csp-admx-wininit.md)
#### [ADMX_WinLogon](policy-csp-admx-winlogon.md)
+#### [ADMX-Winsrv](policy-csp-admx-winsrv.md)
#### [ADMX_wlansvc](policy-csp-admx-wlansvc.md)
#### [ADMX_WPN](policy-csp-admx-wpn.md)
#### [ApplicationDefaults](policy-csp-applicationdefaults.md)
diff --git a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
index a93f4e23d3..f745a9f9ad 100644
--- a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
+++ b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
@@ -1333,6 +1333,7 @@ ms.date: 10/08/2020
- [ADMX_WinLogon/LogonHoursPolicyDescription](./policy-csp-admx-winlogon.md#admx-winlogon-logonhourspolicydescription)
- [ADMX_WinLogon/ReportCachedLogonPolicyDescription](./policy-csp-admx-winlogon.md#admx-winlogon-reportcachedlogonpolicydescription)
- [ADMX_WinLogon/SoftwareSASGeneration](./policy-csp-admx-winlogon.md#admx-winlogon-softwaresasgeneration)
+- [ADMX_Winsrv/AllowBlockingAppsAtShutdown](./policy-csp-admx-winsrv.md#admx-winsrv-allowblockingappsatshutdown)
- [ADMX_wlansvc/SetCost](./policy-csp-admx-wlansvc.md#admx-wlansvc-setcost)
- [ADMX_wlansvc/SetPINEnforced](./policy-csp-admx-wlansvc.md#admx-wlansvc-setpinenforced)
- [ADMX_wlansvc/SetPINPreferred](./policy-csp-admx-wlansvc.md#admx-wlansvc-setpinpreferred)
diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md
index 5056143d53..3b90c561dd 100644
--- a/windows/client-management/mdm/policy-configuration-service-provider.md
+++ b/windows/client-management/mdm/policy-configuration-service-provider.md
@@ -8547,6 +8547,14 @@ The following diagram shows the Policy configuration service provider in tree fo
+### Winsrv policies
+
+
+ -
+ Winsrv/AllowBlockingAppsAtShutdown
+
+
+
## Policies in Policy CSP supported by Group Policy and ADMX-backed policies in Policy CSP
- [Policies in Policy CSP supported by Group Policy](policy-csps-supported-by-group-policy.md)
- [ADMX-backed policies in Policy CSP](policy-csps-admx-backed.md)
diff --git a/windows/client-management/mdm/policy-csp-admx-winsrv.md b/windows/client-management/mdm/policy-csp-admx-winsrv.md
new file mode 100644
index 0000000000..56a6b7c6a2
--- /dev/null
+++ b/windows/client-management/mdm/policy-csp-admx-winsrv.md
@@ -0,0 +1,119 @@
+---
+title: Policy CSP - ADMX_Winsrv
+description: Policy CSP - ADMX_Winsrv
+ms.author: dansimp
+ms.localizationpriority: medium
+ms.topic: article
+ms.prod: w10
+ms.technology: windows
+author: manikadhiman
+ms.date: 02/25/2021
+ms.reviewer:
+manager: dansimp
+---
+
+# Policy CSP - ADMX_Winsrv
+> [!WARNING]
+> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here.
+
+
+
+
+## ADMX_Winsrv policies
+
+
+ -
+ ADMX_Winsrv/AllowBlockingAppsAtShutdown
+
+
+
+
+
+
+
+**ADMX_Winsrv/AllowBlockingAppsAtShutdown**
+
+
+
+
+ Windows Edition |
+ Supported? |
+
+
+ Home |
+  |
+
+
+ Pro |
+  |
+
+
+ Business |
+  |
+
+
+ Enterprise |
+  |
+
+
+ Education |
+  |
+
+
+
+
+
+
+
+[Scope](./policy-configuration-service-provider.md#policy-scope):
+
+> [!div class = "checklist"]
+> * Device
+
+
+
+
+
+Available in the latest Windows 10 Insider Preview Build. This policy setting specifies whether Windows will allow console applications and GUI applications without visible top-level windows to block or cancel shutdown.
+
+By default, such applications are automatically terminated if they attempt to cancel shutdown or block it indefinitely.
+
+- If you enable this setting, console applications or GUI applications without visible top-level windows that block or cancel shutdown will not be automatically terminated during shutdown.
+- If you disable or do not configure this setting, these applications will be automatically terminated during shutdown, helping to ensure that windows can shut down faster and more smoothly.
+
+> [!NOTE]
+> This policy setting applies to all sites in Trusted zones.
+
+
+> [!TIP]
+> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md).
+>
+> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy).
+>
+> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect).
+
+
+ADMX Info:
+- GP English name: *Turn off automatic termination of applications that block or cancel shutdown*
+- GP name: *AllowBlockingAppsAtShutdown*
+- GP path: *System\Shutdown Options*
+- GP ADMX file name: *Winsrv.admx*
+
+
+
+
+
+Footnotes:
+
+- 1 - Available in Windows 10, version 1607
+- 2 - Available in Windows 10, version 1703
+- 3 - Available in Windows 10, version 1709
+- 4 - Available in Windows 10, version 1803
+- 5 - Available in Windows 10, version 1809
+- 6 - Available in Windows 10, version 1903
+- 7 - Available in Windows 10, version 1909
+- 8 - Available in Windows 10, version 2004
+- 9 - Available in Windows 10, version 20H2
+
+
+
From 6490bb57ca76baa0dfc5b1cf15d4a581504ed9c0 Mon Sep 17 00:00:00 2001
From: VLG17 <41186174+VLG17@users.noreply.github.com>
Date: Fri, 26 Feb 2021 13:12:02 +0200
Subject: [PATCH 016/434] add note about enabling Sandbox using Powershell
https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9098
---
.../windows-sandbox/windows-sandbox-overview.md | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
index 81f95a98be..f64548bb5f 100644
--- a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
+++ b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
@@ -53,6 +53,10 @@ The following video provides an overview of Windows Sandbox.
1. Use the search bar on the task bar and type **Turn Windows Features on and off** to access the Windows Optional Features tool. Select **Windows Sandbox** and then **OK**. Restart the computer if you're prompted.
- If the **Windows Sandbox** option is unavailable, your computer doesn't meet the requirements to run Windows Sandbox. If you think this is incorrect, review the prerequisite list as well as steps 1 and 2.
+
+>[!NOTE]
+> To enable Sandbox using Powershell, open Powershell as Administrator and run **Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online**
+
1. Locate and select **Windows Sandbox** on the Start menu to run it for the first time.
## Usage
From 986550052a720f47092a28fd51c8ca11ad8a1dd5 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Sun, 28 Feb 2021 21:49:18 +0500
Subject: [PATCH 017/434] Update active-directory-security-groups.md
---
.../access-control/active-directory-security-groups.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/security/identity-protection/access-control/active-directory-security-groups.md b/windows/security/identity-protection/access-control/active-directory-security-groups.md
index e408ad9ba8..76ef2c7179 100644
--- a/windows/security/identity-protection/access-control/active-directory-security-groups.md
+++ b/windows/security/identity-protection/access-control/active-directory-security-groups.md
@@ -1853,7 +1853,7 @@ The Enterprise Key Admins group was introduced in Windows Server 2016.
| Default container | CN=Users, DC=<domain>, DC= |
| Default members | None |
| Default member of | None |
-| Protected by ADMINSDHOLDER? | No |
+| Protected by ADMINSDHOLDER? | Yes |
| Safe to move out of default container? | Yes |
| Safe to delegate management of this group to non-Service admins? | No |
| Default User Rights | None |
@@ -2331,7 +2331,7 @@ The Key Admins group applies to versions of the Windows Server operating system
| Default container | CN=Users, DC=<domain>, DC= |
| Default members | None |
| Default member of | None |
-| Protected by ADMINSDHOLDER? | No |
+| Protected by ADMINSDHOLDER? | Yes |
| Safe to move out of default container? | Yes |
| Safe to delegate management of this group to non-Service admins? | No |
| Default User Rights | None |
From ccc262199ac3b8ee10e2fc2412b9229affeddd02 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 28 Feb 2021 22:32:52 +0500
Subject: [PATCH 018/434] Minor Modification in Note Section
I have made a minor modifications in the note section so that it can reflect the correct information.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9070
---
.../client-management/mdm/policy-csp-controlpolicyconflict.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
index 2cde160250..2ad708eb51 100644
--- a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
+++ b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
@@ -77,7 +77,7 @@ manager: dansimp
Added in Windows 10, version 1803. This policy allows the IT admin to control which policy will be used whenever both the MDM policy and its equivalent Group Policy (GP) are set on the device.
> [!NOTE]
-> MDMWinsOverGP only applies to policies in Policy CSP. It does not apply to other MDM settings with equivalent GP settings that are defined on other configuration service providers.
+> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable, not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined on other CSPs.
This policy is used to ensure that MDM policy wins over GP when policy is configured on MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set 1.
Note: This policy doesn’t support the Delete command and doesn’t support setting the value to 0 again after it was previously set to 1. Windows 10 version 1809 will support using the Delete command to set the value to 0 again, if it was previously set to 1.
From 9d9ddaa541b5c29ff2e60acb1b7f58e52bc02486 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 28 Feb 2021 22:55:22 +0500
Subject: [PATCH 019/434] Added another cause of boot failure
If there is a blank GPT entry, the boot partition will not work. Added this info.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9145
---
.../client-management/troubleshoot-inaccessible-boot-device.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/windows/client-management/troubleshoot-inaccessible-boot-device.md b/windows/client-management/troubleshoot-inaccessible-boot-device.md
index bdb67e2528..ceefb0fe5e 100644
--- a/windows/client-management/troubleshoot-inaccessible-boot-device.md
+++ b/windows/client-management/troubleshoot-inaccessible-boot-device.md
@@ -37,6 +37,8 @@ Any one of the following factors might cause the stop error:
* Corrupted files in the **Boot** partition (for example, corruption in the volume that's labeled **SYSTEM** when you run the `diskpart` > `list vol` command)
+* If there is a blank GPT entry before the entry of the boot partition.
+
## Troubleshoot this error
Start the computer in [Windows Recovery Mode (WinRE)](https://docs.microsoft.com/windows-hardware/manufacture/desktop/windows-recovery-environment--windows-re--technical-reference#span-identrypointsintowinrespanspan-identrypointsintowinrespanspan-identrypointsintowinrespanentry-points-into-winre). To do this, follow these steps.
From 162615d8464f280b903126f194f7fa2b93ba2a7a Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 28 Feb 2021 23:03:11 +0500
Subject: [PATCH 020/434] Update
windows/client-management/mdm/policy-csp-controlpolicyconflict.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../client-management/mdm/policy-csp-controlpolicyconflict.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
index 2ad708eb51..dc4e1091e9 100644
--- a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
+++ b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
@@ -77,7 +77,7 @@ manager: dansimp
Added in Windows 10, version 1803. This policy allows the IT admin to control which policy will be used whenever both the MDM policy and its equivalent Group Policy (GP) are set on the device.
> [!NOTE]
-> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable, not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined on other CSPs.
+> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable, not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.
This policy is used to ensure that MDM policy wins over GP when policy is configured on MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set 1.
Note: This policy doesn’t support the Delete command and doesn’t support setting the value to 0 again after it was previously set to 1. Windows 10 version 1809 will support using the Delete command to set the value to 0 again, if it was previously set to 1.
@@ -128,4 +128,3 @@ Footnotes:
- 8 - Available in Windows 10, version 2004.
-
From cb68de8b985e65faa8913cb889f5e61ae7b1365e Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 28 Feb 2021 23:29:07 +0500
Subject: [PATCH 021/434] Update
windows/client-management/troubleshoot-inaccessible-boot-device.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../client-management/troubleshoot-inaccessible-boot-device.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/troubleshoot-inaccessible-boot-device.md b/windows/client-management/troubleshoot-inaccessible-boot-device.md
index ceefb0fe5e..c56106854e 100644
--- a/windows/client-management/troubleshoot-inaccessible-boot-device.md
+++ b/windows/client-management/troubleshoot-inaccessible-boot-device.md
@@ -37,7 +37,7 @@ Any one of the following factors might cause the stop error:
* Corrupted files in the **Boot** partition (for example, corruption in the volume that's labeled **SYSTEM** when you run the `diskpart` > `list vol` command)
-* If there is a blank GPT entry before the entry of the boot partition.
+* If there is a blank GPT entry before the entry of the **Boot** partition.
## Troubleshoot this error
From 2d2969a93faf1bcd5f9dd53c3405fb08dcb092b8 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Mon, 1 Mar 2021 12:23:03 +0500
Subject: [PATCH 022/434] Update
windows/client-management/troubleshoot-inaccessible-boot-device.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../troubleshoot-inaccessible-boot-device.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/client-management/troubleshoot-inaccessible-boot-device.md b/windows/client-management/troubleshoot-inaccessible-boot-device.md
index c56106854e..5a4572c445 100644
--- a/windows/client-management/troubleshoot-inaccessible-boot-device.md
+++ b/windows/client-management/troubleshoot-inaccessible-boot-device.md
@@ -35,9 +35,9 @@ Any one of the following factors might cause the stop error:
* In unusual cases, the failure of the TrustedInstaller service to commit newly installed updates is because of component-based store corruptions
-* Corrupted files in the **Boot** partition (for example, corruption in the volume that's labeled **SYSTEM** when you run the `diskpart` > `list vol` command)
+* Corrupted files in the **Boot** partition (for example, corruption in the volume that's labeled **SYSTEM** when you run the `diskpart` > `list vol` command)
-* If there is a blank GPT entry before the entry of the **Boot** partition.
+* If there is a blank GPT entry before the entry of the **Boot** partition
## Troubleshoot this error
From a1afbcf7b9f3024aea6993c6b1a112e8bee52574 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Mon, 1 Mar 2021 12:28:54 +0500
Subject: [PATCH 023/434] Update
windows/client-management/mdm/policy-csp-controlpolicyconflict.md
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../client-management/mdm/policy-csp-controlpolicyconflict.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
index dc4e1091e9..29c6354afe 100644
--- a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
+++ b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
@@ -77,7 +77,7 @@ manager: dansimp
Added in Windows 10, version 1803. This policy allows the IT admin to control which policy will be used whenever both the MDM policy and its equivalent Group Policy (GP) are set on the device.
> [!NOTE]
-> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable, not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.
+> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable; not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.
This policy is used to ensure that MDM policy wins over GP when policy is configured on MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set 1.
Note: This policy doesn’t support the Delete command and doesn’t support setting the value to 0 again after it was previously set to 1. Windows 10 version 1809 will support using the Delete command to set the value to 0 again, if it was previously set to 1.
From 5440bfaaccdfd1f1e9dae94396d8157bc922678f Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Mon, 1 Mar 2021 12:29:06 +0500
Subject: [PATCH 024/434] Update
windows/client-management/mdm/policy-csp-controlpolicyconflict.md
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../client-management/mdm/policy-csp-controlpolicyconflict.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
index 29c6354afe..0bbc670a2b 100644
--- a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
+++ b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
@@ -79,7 +79,7 @@ Added in Windows 10, version 1803. This policy allows the IT admin to control wh
> [!NOTE]
> MDMWinsOverGP only applies to policies in Policy CSP. MDM policies win over Group Policies where applicable; not all Group Policies are available via MDM or CSP. It does not apply to other MDM settings with equivalent GP settings that are defined in other CSPs.
-This policy is used to ensure that MDM policy wins over GP when policy is configured on MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set 1.
+This policy is used to ensure that MDM policy wins over GP when the policy is configured on the MDM channel. The default value is 0. The MDM policies in Policy CSP will behave as described if this policy value is set to 1.
Note: This policy doesn’t support the Delete command and doesn’t support setting the value to 0 again after it was previously set to 1. Windows 10 version 1809 will support using the Delete command to set the value to 0 again, if it was previously set to 1.
The following list shows the supported values:
From 37c71692ba519f94970235215cad1151b91cc031 Mon Sep 17 00:00:00 2001
From: VLG17 <41186174+VLG17@users.noreply.github.com>
Date: Mon, 1 Mar 2021 10:27:52 +0200
Subject: [PATCH 025/434] Update
windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
.../windows-sandbox/windows-sandbox-overview.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
index f64548bb5f..e27f3c108c 100644
--- a/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
+++ b/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview.md
@@ -54,8 +54,8 @@ The following video provides an overview of Windows Sandbox.
- If the **Windows Sandbox** option is unavailable, your computer doesn't meet the requirements to run Windows Sandbox. If you think this is incorrect, review the prerequisite list as well as steps 1 and 2.
->[!NOTE]
-> To enable Sandbox using Powershell, open Powershell as Administrator and run **Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online**
+> [!NOTE]
+> To enable Sandbox using PowerShell, open PowerShell as Administrator and run **Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online**.
1. Locate and select **Windows Sandbox** on the Start menu to run it for the first time.
From ab042f611c03a632f3772cd13a35b47a30fc3acb Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 1 Mar 2021 11:56:10 -0800
Subject: [PATCH 026/434] Update policy-csp-controlpolicyconflict.md
---
.../client-management/mdm/policy-csp-controlpolicyconflict.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
index 0bbc670a2b..861d895848 100644
--- a/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
+++ b/windows/client-management/mdm/policy-csp-controlpolicyconflict.md
@@ -5,9 +5,8 @@ ms.author: dansimp
ms.topic: article
ms.prod: w10
ms.technology: windows
-author: manikadhiman
+author: dansimp
ms.localizationpriority: medium
-ms.date: 09/27/2019
ms.reviewer:
manager: dansimp
---
From 6d1eaa991f6c699126b09fda269662ad81017a53 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Thu, 4 Mar 2021 12:17:46 +0500
Subject: [PATCH 027/434] Updated the link
The old link was not working. Looks like its only available in English, because when I try to open it as https://www.microsoft.com/CloudandHosting/licensing_sca.aspx it says page not available.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9222
---
windows/deployment/deploy-enterprise-licenses.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/deploy-enterprise-licenses.md b/windows/deployment/deploy-enterprise-licenses.md
index 71c908be85..e49a7bba30 100644
--- a/windows/deployment/deploy-enterprise-licenses.md
+++ b/windows/deployment/deploy-enterprise-licenses.md
@@ -215,7 +215,7 @@ If there are any problems with the Windows 10 Enterprise E3 or E5 license or th
## Virtual Desktop Access (VDA)
-Subscriptions to Windows 10 Enterprise are also available for virtualized clients. Windows 10 Enterprise E3 and E5 are available for Virtual Desktop Access (VDA) in Windows Azure or in another [qualified multitenant hoster](https://www.microsoft.com/CloudandHosting/licensing_sca.aspx).
+Subscriptions to Windows 10 Enterprise are also available for virtualized clients. Windows 10 Enterprise E3 and E5 are available for Virtual Desktop Access (VDA) in Windows Azure or in another [qualified multitenant hoster](https://www.microsoft.com/en-us/CloudandHosting/licensing_sca.aspx).
Virtual machines (VMs) must be configured to enable Windows 10 Enterprise subscriptions for VDA. Active Directory-joined and Azure Active Directory-joined clients are supported. See [Enable VDA for Enterprise Subscription Activation](vda-subscription-activation.md).
From 398448b51fb6c47efc80e0afd6e13ef8f038fe03 Mon Sep 17 00:00:00 2001
From: Asha Iyengar
Date: Fri, 5 Mar 2021 08:40:02 +0530
Subject: [PATCH 028/434] Update remotering-csp.md
---
windows/client-management/mdm/remotering-csp.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/remotering-csp.md b/windows/client-management/mdm/remotering-csp.md
index d1db2f57e8..8125620d66 100644
--- a/windows/client-management/mdm/remotering-csp.md
+++ b/windows/client-management/mdm/remotering-csp.md
@@ -15,9 +15,9 @@ ms.date: 06/26/2017
# RemoteRing CSP
-The RemoteRing configuration service provider can be used to remotely trigger a device to produce an audible ringing sound regardless of the volume that is set on the device.
+You can use the RemoteRing configuration service provider to remotely trigger a device to produce an audible ringing sound, regardless of the volume that is set on the device.
-The following shows the RemoteRing configuration service provider in tree format.
+The following DDF format shows the RemoteRing configuration service provider in tree format.
```
./User/Vendor/MSFT
RemoteRing
From 8bdb5b77a38c01166db34464e95add57735d139d Mon Sep 17 00:00:00 2001
From: Asha Iyengar
Date: Fri, 5 Mar 2021 08:48:03 +0530
Subject: [PATCH 029/434] Update reporting-csp.md
---
windows/client-management/mdm/reporting-csp.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/reporting-csp.md b/windows/client-management/mdm/reporting-csp.md
index efa527ae2d..c8bc78834a 100644
--- a/windows/client-management/mdm/reporting-csp.md
+++ b/windows/client-management/mdm/reporting-csp.md
@@ -17,7 +17,7 @@ ms.date: 06/26/2017
The Reporting configuration service provider is used to retrieve Windows Information Protection (formerly known as Enterprise Data Protection) and security auditing logs. This CSP was added in Windows 10, version 1511.
-The following shows the Reporting configuration service provider in tree format.
+The following DDF format shows the Reporting configuration service provider in tree format.
```
./Vendor/MSFT
Reporting
@@ -52,7 +52,7 @@ Here are the other possible scenarios:
- If the StartTime is specified, but the StopTime is not specified, then all that logs that exist from the StartTime are returned.
**RetrieveByCount**
-Interior node for retrieving a specified number of logs from the StartTime. The StartTime is expressed in ISO 8601 format. You can set the number of logs required by setting LogCount and StartTime. It returns the specified number of log or less, if the total number logs is less than LogCount.
+Interior node for retrieving a specified number of logs from the StartTime. The StartTime is expressed in ISO 8601 format. You can set the number of logs required by setting LogCount and StartTime. It returns the specified number of logs or less, if the total number of logs is less than LogCount.
**Logs**
Contains the reporting logs.
From d5efb4bf65a5802186c374a76fd0e31dd7271a09 Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 7 Mar 2021 21:34:52 +0500
Subject: [PATCH 030/434] Modification in Note Section
As mentioned in other GCC or DoD documentation, it states that GCC or DoD is only available using volume licensing.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9213
---
windows/deployment/windows-10-subscription-activation.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-10-subscription-activation.md b/windows/deployment/windows-10-subscription-activation.md
index 8ea91fd4cc..141efb336f 100644
--- a/windows/deployment/windows-10-subscription-activation.md
+++ b/windows/deployment/windows-10-subscription-activation.md
@@ -91,7 +91,7 @@ The following figure illustrates how deploying Windows 10 has evolved with each
> The following requirements do not apply to general Windows 10 activation on Azure. Azure activation requires a connection to Azure KMS only, and supports workgroup, Hybrid, and Azure AD-joined VMs. In most scenarios, activation of Azure VMs happens automatically. For more information, see [Understanding Azure KMS endpoints for Windows product activation of Azure Virtual Machines](https://docs.microsoft.com/azure/virtual-machines/troubleshooting/troubleshoot-activation-problems#understanding-azure-kms-endpoints-for-windows-product-activation-of-azure-virtual-machines).
> [!NOTE]
-> Currently, Subscription Activation is only available on commercial tenants and is not currently available on US GCC or GCC High tenants.
+> Currently, Subscription Activation is only available on commercial tenants and is not currently available on US GCC,GCC High or, DoD tenants.
For Microsoft customers with Enterprise Agreements (EA) or Microsoft Products & Services Agreements (MPSA), you must have the following:
From 19d744c8e3755c4143b0fad884d887efc478a23f Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Sun, 7 Mar 2021 21:56:14 +0500
Subject: [PATCH 031/434] Update
windows/deployment/windows-10-subscription-activation.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
windows/deployment/windows-10-subscription-activation.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-10-subscription-activation.md b/windows/deployment/windows-10-subscription-activation.md
index 141efb336f..1f059a990a 100644
--- a/windows/deployment/windows-10-subscription-activation.md
+++ b/windows/deployment/windows-10-subscription-activation.md
@@ -91,7 +91,7 @@ The following figure illustrates how deploying Windows 10 has evolved with each
> The following requirements do not apply to general Windows 10 activation on Azure. Azure activation requires a connection to Azure KMS only, and supports workgroup, Hybrid, and Azure AD-joined VMs. In most scenarios, activation of Azure VMs happens automatically. For more information, see [Understanding Azure KMS endpoints for Windows product activation of Azure Virtual Machines](https://docs.microsoft.com/azure/virtual-machines/troubleshooting/troubleshoot-activation-problems#understanding-azure-kms-endpoints-for-windows-product-activation-of-azure-virtual-machines).
> [!NOTE]
-> Currently, Subscription Activation is only available on commercial tenants and is not currently available on US GCC,GCC High or, DoD tenants.
+> Currently, Subscription Activation is only available on commercial tenants and is currently not available on US GCC, GCC High, or DoD tenants.
For Microsoft customers with Enterprise Agreements (EA) or Microsoft Products & Services Agreements (MPSA), you must have the following:
From 10c60a85720541bf64dfa0bf6385a5175503b36f Mon Sep 17 00:00:00 2001
From: ImranHabib <47118050+joinimran@users.noreply.github.com>
Date: Tue, 9 Mar 2021 14:58:55 +0500
Subject: [PATCH 032/434] Update instruction
The document was showing max inactivity time in seconds but in actual it is in minutes. Made the necessary changes.
Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/9266#issuecomment-793088819
---
windows/client-management/mdm/policy-csp-devicelock.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/client-management/mdm/policy-csp-devicelock.md b/windows/client-management/mdm/policy-csp-devicelock.md
index b106637736..f68a71f820 100644
--- a/windows/client-management/mdm/policy-csp-devicelock.md
+++ b/windows/client-management/mdm/policy-csp-devicelock.md
@@ -677,7 +677,7 @@ The following list shows the supported values:
-Specifies the maximum amount of time (in seconds) allowed after the device is idle that will cause the device to become PIN or password locked. Users can select any existing timeout value less than the specified maximum time in the Settings app.
+Specifies the maximum amount of time (in minutes) allowed after the device is idle that will cause the device to become PIN or password locked. Users can select any existing timeout value less than the specified maximum time in the Settings app.
* On Mobile, the Lumia 950 and 950XL have a maximum timeout value of 5 minutes, regardless of the value set by this policy.
* On HoloLens, this timeout is controlled by the device's system sleep timeout, regardless of the value set by this policy.
From 2d0bad64e34058bcc81ae94b6ab1f080bce84245 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Tue, 9 Mar 2021 21:01:41 +0500
Subject: [PATCH 033/434] Update hello-feature-dual-enrollment.md
---
.../hello-for-business/hello-feature-dual-enrollment.md | 1 +
1 file changed, 1 insertion(+)
diff --git a/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md b/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
index 028fdd4868..dbb7bc61b3 100644
--- a/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
+++ b/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
@@ -24,6 +24,7 @@ ms.reviewer:
* Hybrid and On-premises Windows Hello for Business deployments
* Enterprise Joined or Hybrid Azure joined devices
* Windows 10, version 1709
+* Certificate trust
> [!NOTE]
> This feature was previously known as **Privileged Credential** but was renamed to **Dual Enrollment** to prevent any confusion with the **Privileged Access Workstation** feature.
From e4923acc08dd04543134621fd7a1889153230042 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Wed, 10 Mar 2021 10:09:13 +0500
Subject: [PATCH 034/434] Update
windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../hello-for-business/hello-feature-dual-enrollment.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md b/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
index dbb7bc61b3..b71bc4c615 100644
--- a/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
+++ b/windows/security/identity-protection/hello-for-business/hello-feature-dual-enrollment.md
@@ -22,7 +22,7 @@ ms.reviewer:
**Requirements**
* Hybrid and On-premises Windows Hello for Business deployments
-* Enterprise Joined or Hybrid Azure joined devices
+* Enterprise joined or Hybrid Azure joined devices
* Windows 10, version 1709
* Certificate trust
From cabf1bc1b8105d09adeeced45b6419a46f452c58 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Wed, 10 Mar 2021 16:26:31 +0500
Subject: [PATCH 035/434] Update whats-new-windows-10-2019.md
---
windows/whats-new/ltsc/whats-new-windows-10-2019.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/whats-new/ltsc/whats-new-windows-10-2019.md b/windows/whats-new/ltsc/whats-new-windows-10-2019.md
index a34e99e632..4d6a6f8ef3 100644
--- a/windows/whats-new/ltsc/whats-new-windows-10-2019.md
+++ b/windows/whats-new/ltsc/whats-new-windows-10-2019.md
@@ -36,7 +36,7 @@ The Windows 10 Enterprise LTSC 2019 release is an important release for LTSC use
## Microsoft Intune
-Microsoft Intune supports Windows 10 Enterprise LTSC 2019 and later. This includes support for features such as [Windows Autopilot](#windows-autopilot). However, note that Windows Update for Business (WUfB) does not currently support any LTSC releases, therefore you should use WSUS or Configuration Manager for patching.
+Microsoft Intune supports Windows 10 Enterprise LTSC 2019 and later. This includes support for features such as [Windows Autopilot](#windows-autopilot). However, note that Windows 10 Update Rings Device profiles do not support LTSC releases, therefore you should use [Policy configuration service provider](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-update), WSUS, or Configuration Manager for patching.
## Security
From 430e50e77096dacfd9937dcd441b97b5b8a4b371 Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Wed, 10 Mar 2021 16:44:06 +0500
Subject: [PATCH 036/434] Update windows-10-subscription-activation.md
---
windows/deployment/windows-10-subscription-activation.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-10-subscription-activation.md b/windows/deployment/windows-10-subscription-activation.md
index 8ea91fd4cc..c572e5062e 100644
--- a/windows/deployment/windows-10-subscription-activation.md
+++ b/windows/deployment/windows-10-subscription-activation.md
@@ -215,7 +215,7 @@ If you’re running Windows 7, it can be more work. A wipe-and-load approach w
The following policies apply to acquisition and renewal of licenses on devices:
- Devices that have been upgraded will attempt to renew licenses about every 30 days, and must be connected to the Internet to successfully acquire or renew a license.
- If a device is disconnected from the Internet until its current subscription expires, the operating system will revert to Windows 10 Pro or Windows 10 Pro Education. As soon as the device is connected to the Internet again, the license will automatically renew.
-- Up to five devices can be upgraded for each user license.
+- Up to five devices can be upgraded for each user license. If user license is used for the sixth device, the operating system on the computer to which user has not logged in the longest will revert to Windows 10 Pro or Windows 10 Pro Education.
- If a device meets the requirements and a licensed user signs in on that device, it will be upgraded.
Licenses can be reallocated from one user to another user, allowing you to optimize your licensing investment against changing needs.
From 0fa5456cb0becb620bd71b2fa11ab3f2e3c243ef Mon Sep 17 00:00:00 2001
From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com>
Date: Sun, 14 Mar 2021 10:41:54 +0500
Subject: [PATCH 037/434] Update
windows/deployment/windows-10-subscription-activation.md
Co-authored-by: Trond B. Krokli <38162891+illfated@users.noreply.github.com>
---
windows/deployment/windows-10-subscription-activation.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/deployment/windows-10-subscription-activation.md b/windows/deployment/windows-10-subscription-activation.md
index c572e5062e..7a4fd93ef5 100644
--- a/windows/deployment/windows-10-subscription-activation.md
+++ b/windows/deployment/windows-10-subscription-activation.md
@@ -215,7 +215,7 @@ If you’re running Windows 7, it can be more work. A wipe-and-load approach w
The following policies apply to acquisition and renewal of licenses on devices:
- Devices that have been upgraded will attempt to renew licenses about every 30 days, and must be connected to the Internet to successfully acquire or renew a license.
- If a device is disconnected from the Internet until its current subscription expires, the operating system will revert to Windows 10 Pro or Windows 10 Pro Education. As soon as the device is connected to the Internet again, the license will automatically renew.
-- Up to five devices can be upgraded for each user license. If user license is used for the sixth device, the operating system on the computer to which user has not logged in the longest will revert to Windows 10 Pro or Windows 10 Pro Education.
+- Up to five devices can be upgraded for each user license. If the user license is used for a sixth device, the operating system on the computer to which a user has not logged in the longest will revert to Windows 10 Pro or Windows 10 Pro Education.
- If a device meets the requirements and a licensed user signs in on that device, it will be upgraded.
Licenses can be reallocated from one user to another user, allowing you to optimize your licensing investment against changing needs.
From c2f3ba729e52c5e9e7604b729282f5d8c66eb4f0 Mon Sep 17 00:00:00 2001
From: nimishasatapathy <75668234+nimishasatapathy@users.noreply.github.com>
Date: Wed, 17 Mar 2021 20:00:31 +0530
Subject: [PATCH 038/434] Updated
---
.../client-management/mdm/policies-in-policy-csp-admx-backed.md | 2 +-
.../mdm/policy-configuration-service-provider.md | 2 +-
windows/client-management/mdm/policy-csp-admx-winsrv.md | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
index bf5102d568..aeca7d2f72 100644
--- a/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
+++ b/windows/client-management/mdm/policies-in-policy-csp-admx-backed.md
@@ -1334,7 +1334,7 @@ ms.date: 10/08/2020
- [ADMX_WinLogon/LogonHoursPolicyDescription](./policy-csp-admx-winlogon.md#admx-winlogon-logonhourspolicydescription)
- [ADMX_WinLogon/ReportCachedLogonPolicyDescription](./policy-csp-admx-winlogon.md#admx-winlogon-reportcachedlogonpolicydescription)
- [ADMX_WinLogon/SoftwareSASGeneration](./policy-csp-admx-winlogon.md#admx-winlogon-softwaresasgeneration)
-- [ADMX_Winsrv/AllowBlockingAppsAtShutdown](./policy-csp-admx-winsrv.md#admx-winsrv-allowblockingappsatshutdown)
+- [ADMX_Winsrv/AllowBlockingAppsAtShutdown](./policy-csp-admx-winsrv.md#admx-winsrv.-allowblockingappsatshutdown)
- [ADMX_wlansvc/SetCost](./policy-csp-admx-wlansvc.md#admx-wlansvc-setcost)
- [ADMX_wlansvc/SetPINEnforced](./policy-csp-admx-wlansvc.md#admx-wlansvc-setpinenforced)
- [ADMX_wlansvc/SetPINPreferred](./policy-csp-admx-wlansvc.md#admx-wlansvc-setpinpreferred)
diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md
index 6978c78e3d..7c8cb5bcf6 100644
--- a/windows/client-management/mdm/policy-configuration-service-provider.md
+++ b/windows/client-management/mdm/policy-configuration-service-provider.md
@@ -8558,7 +8558,7 @@ The following diagram shows the Policy configuration service provider in tree fo
-
- Winsrv/AllowBlockingAppsAtShutdown
+ Winsrv/AllowBlockingAppsAtShutdown
diff --git a/windows/client-management/mdm/policy-csp-admx-winsrv.md b/windows/client-management/mdm/policy-csp-admx-winsrv.md
index 56a6b7c6a2..1898b68b88 100644
--- a/windows/client-management/mdm/policy-csp-admx-winsrv.md
+++ b/windows/client-management/mdm/policy-csp-admx-winsrv.md
@@ -23,7 +23,7 @@ manager: dansimp
-
- ADMX_Winsrv/AllowBlockingAppsAtShutdown
+ ADMX_Winsrv/AllowBlockingAppsAtShutdown
From 8f5b09d2bb617d362443c7fc94c4b76d0bdd4175 Mon Sep 17 00:00:00 2001
From: mapalko
Date: Wed, 17 Mar 2021 09:40:04 -0700
Subject: [PATCH 039/434] Fixing note on NTAuth store
The NTauth store note should be updated to match the note here: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-pki
---
.../hello-for-business/hello-hybrid-key-whfb-settings-pki.md | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md
index c05de0195e..44b43a3491 100644
--- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md
+++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki.md
@@ -81,7 +81,8 @@ Sign-in a certificate authority or management workstations with _Enterprise Admi
The certificate template is configured to supersede all the certificate templates provided in the certificate templates superseded templates list. However, the certificate template and the superseding of certificate templates is not active until you publish the certificate template to one or more certificate authorities.
> [!NOTE]
-> The domain controller's certificate must chain to a root in the NTAuth store. By default, the Active Directory Certificate Authority's root certificate is added to the NTAuth store. If you are using a third-party CA, this may not be done by default. If the domain controller certificate does not chain to a root in the NTAuth store, user authentication will fail.
+> A domain controller's certificate must chain to a certificate in the NTAuth store in Active Directory. By default, online "Enterprise" Active Directory Certificate Authority certificates are added to the NTAuth store at installation time. If you are using a third-party CA, this is not done by default. If the domain controller certificate does not chain to a trusted CA in the NTAuth store, user authentication will fail.
+> You can view an AD forest's NTAuth store (NTAuthCertificates) using PKIVIEW.MSC from an ADCS CA. Open PKIView.msc, then click the Action menu -> Manage AD Containers.
### Publish Certificate Templates to a Certificate Authority
From 80adb60e9461a88789370aa680d995637890d23a Mon Sep 17 00:00:00 2001
From: Sunny Zankharia <67922512+sazankha@users.noreply.github.com>
Date: Thu, 18 Mar 2021 20:33:06 -0700
Subject: [PATCH 040/434] Update windowsdefenderapplicationguard-csp.md
Added clarification for implications of GP on uploads
---
.../mdm/windowsdefenderapplicationguard-csp.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
index 9c6de75b46..468313fb87 100644
--- a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
+++ b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
@@ -196,14 +196,14 @@ ADMX Info:
**Settings/SaveFilesToHost**
-Added in Windows 10, version 1803. This policy setting allows you to determine whether users can elect to download files from Edge in the container and persist files them from container to the host operating system.
+Added in Windows 10, version 1803. This policy setting allows you to determine whether users can elect to download files from Edge in the container and persist files them from container to the host operating system. This also enables users to elect files on the host operating system and upload it through Edge in the container.
Value type is integer. Supported operations are Add, Get, Replace, and Delete.
This policy setting is supported on Microsoft Edge on Windows 10 Enterprise or Windows 10 Education with Microsoft Defender Application Guard in Enterprise mode.
The following list shows the supported values:
-- 0 (default) - The user cannot download files from Edge in the container to the host file system. When the policy is not configured, it is the same as disabled (0).
+- 0 (default) - The user cannot download files from Edge in the container to the host file system, or upload files from host file system to Edge in the container. When the policy is not configured, it is the same as disabled (0).
- 1 - Turns on the functionality to allow users to download files from Edge in the container to the host file system.
From 8b7cacb6ce0f28ad385b76c966c60c325cf3ef28 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Fri, 19 Mar 2021 12:22:01 +0530
Subject: [PATCH 041/434] added TPM 1.2
as per user feedback #9322 so I added TPM v1.2 applies to
---
.../information-protection/tpm/change-the-tpm-owner-password.md | 1 +
1 file changed, 1 insertion(+)
diff --git a/windows/security/information-protection/tpm/change-the-tpm-owner-password.md b/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
index 7854157fed..84e7313b5c 100644
--- a/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
+++ b/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
@@ -21,6 +21,7 @@ ms.date: 04/19/2017
**Applies to**
- Windows 10, version 1511
- Windows 10, version 1507
+- TPM v1.2
This topic for the IT professional describes how to change the password or PIN for the owner of the Trusted Platform Module (TPM) that is installed on your system.
From f18afc7c9610928f93a4a48eca1e2db2179953f8 Mon Sep 17 00:00:00 2001
From: VARADHARAJAN K <3296790+RAJU2529@users.noreply.github.com>
Date: Fri, 19 Mar 2021 14:22:20 +0530
Subject: [PATCH 042/434] Update
windows/security/information-protection/tpm/change-the-tpm-owner-password.md
accepted
Co-authored-by: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
---
.../information-protection/tpm/change-the-tpm-owner-password.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/information-protection/tpm/change-the-tpm-owner-password.md b/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
index 84e7313b5c..8ab05d6e0f 100644
--- a/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
+++ b/windows/security/information-protection/tpm/change-the-tpm-owner-password.md
@@ -21,7 +21,7 @@ ms.date: 04/19/2017
**Applies to**
- Windows 10, version 1511
- Windows 10, version 1507
-- TPM v1.2
+- TPM 1.2
This topic for the IT professional describes how to change the password or PIN for the owner of the Trusted Platform Module (TPM) that is installed on your system.
From 1d114cf297a513825cb94b049dc1e2bbfe61e7bc Mon Sep 17 00:00:00 2001
From: greg-lindsay
Date: Fri, 19 Mar 2021 15:55:16 -0700
Subject: [PATCH 043/434] 1
---
windows/configuration/index.yml | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/windows/configuration/index.yml b/windows/configuration/index.yml
index 20d56ff5c8..f08dc5b3c9 100644
--- a/windows/configuration/index.yml
+++ b/windows/configuration/index.yml
@@ -22,7 +22,7 @@ landingContent:
# Cards and links should be based on top customer tasks or top subjects
# Start card title with a verb
# Card (optional)
- - title: What's new in Windows 10
+ - title: Cart 1 title
linkLists:
- linkListType: overview
links:
@@ -40,7 +40,7 @@ landingContent:
url: whats-new-windows-10-version-1803.md
# Card (optional)
- - title: Learn more
+ - title: Card 2 title
linkLists:
- linkListType: overview
links:
@@ -58,7 +58,7 @@ landingContent:
url: https://go.microsoft.com/fwlink/p/?LinkId=690485
# Card (optional)
- - title: See also
+ - title: Card 3 title
linkLists:
- linkListType: overview
links:
From cc5e701651050063b3d399cbb59a589204faaf6a Mon Sep 17 00:00:00 2001
From: "Nisha Mittal (Wipro Ltd.)"
Date: Sun, 21 Mar 2021 20:48:57 -0700
Subject: [PATCH 044/434] Added a new page for M365 WRH
---
windows/deployment/TOC.yml | 2 +
.../deployment/update/check-release-health.md | 149 ++++++++++++++++++
.../update/images/WRH-history-20H2.png | Bin 0 -> 274522 bytes
.../update/images/WRH-known-issue-detail.png | Bin 0 -> 326298 bytes
.../update/images/WRH-known-issues-20H2.png | Bin 0 -> 316698 bytes
windows/deployment/update/images/WRH-menu.png | Bin 0 -> 265149 bytes
.../WRH-message-history-example-padded.png | Bin 0 -> 365990 bytes
.../images/WRH-message-history-example.png | Bin 0 -> 344713 bytes
.../WRH-view-message-history-padded.png | Bin 0 -> 179000 bytes
.../images/WRH-view-message-history.png | Bin 0 -> 169859 bytes
10 files changed, 151 insertions(+)
create mode 100644 windows/deployment/update/check-release-health.md
create mode 100644 windows/deployment/update/images/WRH-history-20H2.png
create mode 100644 windows/deployment/update/images/WRH-known-issue-detail.png
create mode 100644 windows/deployment/update/images/WRH-known-issues-20H2.png
create mode 100644 windows/deployment/update/images/WRH-menu.png
create mode 100644 windows/deployment/update/images/WRH-message-history-example-padded.png
create mode 100644 windows/deployment/update/images/WRH-message-history-example.png
create mode 100644 windows/deployment/update/images/WRH-view-message-history-padded.png
create mode 100644 windows/deployment/update/images/WRH-view-message-history.png
diff --git a/windows/deployment/TOC.yml b/windows/deployment/TOC.yml
index fdc36528a1..d96215c892 100644
--- a/windows/deployment/TOC.yml
+++ b/windows/deployment/TOC.yml
@@ -87,6 +87,8 @@
items:
- name: Build deployment rings for Windows 10 updates
href: update/waas-deployment-rings-windows-10-updates.md
+ - name: Check release health
+ href: update/check-release-health.md
- name: Prepare updates using Windows Update for Business
href: update/waas-manage-updates-wufb.md
- name: Prepare updates using WSUS
diff --git a/windows/deployment/update/check-release-health.md b/windows/deployment/update/check-release-health.md
new file mode 100644
index 0000000000..20fb0ab88e
--- /dev/null
+++ b/windows/deployment/update/check-release-health.md
@@ -0,0 +1,149 @@
+---
+title: "How to check Windows release health"
+ms.author: DocsPreview
+author: Nisha
+manager: jren
+audience: Admin
+ms.topic: article
+ms.service: o365-administration
+localization_priority: Normal
+f1.keywords:
+- CSH
+ms.custom:
+- Adm_O365
+- 'O365P_ServiceHealthModern'
+- 'O365M_ServiceHealthModern'
+- 'O365E_ViewStatusServices'
+- 'O365E_ServiceHealthModern'
+- 'seo-marvel-apr2020'
+ms.collection:
+- Ent_O365
+- M365-subscription-management
+search.appverid:
+- MET150
+- MOE150
+- BCS160
+- IWA160
+ms.assetid: 932ad3ad-533c-418a-b938-6e44e8bc33b0
+description: "View the health status of Microsoft 365 services before you call support to see if there is an active service interruption."
+---
+
+# How to check Windows release health
+
+The Windows release health page in the Microsoft 365 admin center enables you to view the latest information on known issues for Windows monthly and feature updates. A known issue is an issue that has been identified in a Windows monthly update or feature update that impacts Windows devices. The Windows release health page is designed to inform you about known issues so you can troubleshoot issues your users may be experiencing and/or to determine when, and at what scale, to deploy an update in your organization.
+
+If you are unable to sign in to the Microsoft 365 admin portal, check the [Microsoft 365 service health](https://status.office365.com) status page to check for known issues preventing you from logging into your tenant.
+
+To be informed about the latest updates and releases, follow us on Twitter [@WindowsUpdate](https://twitter.com/windowsupdate).
+
+## How to review Windows release health information
+
+1. Go to the Microsoft 365 admin center at [https://admin.microsoft.com](https://go.microsoft.com/fwlink/p/?linkid=2024339), and sign in with an administrator account.
+
+ > [!NOTE]
+ > By default, the Windows release health page is available to individuals who have been assigned the global admin or service administrator role for their tenant. To allow Exchange, SharePoint, and Skype for Business admins to view the Windows release health page, you must first assign them to a Service admin role. For more information about roles that can view service health, see [About admin roles](https://docs.microsoft.com/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide&preserve-view=true#roles-available-in-the-microsoft-365-admin-center).
+
+2. To view Windows release health in the Microsoft 365 Admin Center, go to **Health > Windows release health**.
+
+3. On the **Windows release health** page, you will have access to known issue information for all supported versions of the Windows operating system.
+
+ The **All versions** tab (the default view) shows all Windows products with access to their posted known issues.
+
+ 
+
+ A known issue is an issue that has been identified in a Windows monthly update or feature update that impacts Windows devices. The **Active and recently resolved** column provides a link to the **Known issues** tab filtered to the version selected. Selecting the **Known issues** tab will show known issues that are active or resolved within the last 30 days.
+
+ 
+
+ The **History** tab shows the history of known issues that have been resolved for up to 6 months.
+
+ 
+
+ The known issue summary provides the following information:
+
+ - **Title** - A summary of the problem.
+ - **Version** - The name of the affected Windows product version.
+ - **Status** - The current status of the issue.
+ - **Originating KB** - The KB number where the issue was first identified.
+ - **Originating build** - The build number for the KB.
+
+ Select the **Issue title** to access more information, including a link to the history of all status updates posted while we work on a solution. Here is an example:
+
+ 
+
+## Status definitions
+
+In the **Windows release health** experience, every known issue is assigned as status. Those statuses are defined as follows:
+
+
+| Status | Definition |
+|:-----|:-----|
+|**Reported** | An issue has been brought to the attention of Windows teams. At this stage, there is no confirmation that users are affected. |
+|**Confirmed** | A known issue has been confirmed but details are emerging regarding the issue’s scope of impact, root cause, and mitigation steps. |
+|**Mitigated** | A workaround is available and communicated to Windows customers. A known issue will stay in this state until a KB is released by Microsoft to resolve the known issue. |
+|**Mitigated: External** | A Microsoft partner has a workaround for a known issue created by component released by them. A known issue will stay in this state until a fix is released by the partner to resolve the known issue. |
+|**Resolved** | A solution has been released by Microsoft and has been documented in a KB article that will resolve the known issue once it’s deployed in the customer’s environment. |
+|**Resolved: External** | A solution has been released by a Microsoft partner that will resolve the known issue once it’s deployed in the customer’s environment. |
+
+## Known issue history
+
+The Windows release health page lets you view the history of all status updates posted for a specific known issue. To view all past updates posted for a given issue, select **View history** on the issue detail page.
+
+
+
+A list of all status updates posted in the selected timeframe will be displayed, as shown below. You can expand any row to view the specific information provided in that status update.
+
+
+
+## Frequently asked questions
+
+### Windows release health coverage
+
+- **What is Windows release health?**
+ Windows release health is a Microsoft informational service created to keep licensed Windows customers aware of identified known issues and important announcements.
+
+- **Microsoft 365 service health content is specific to my tenants and services. Is the content in Windows release health specific to my Windows environment?**
+ Windows release health does not monitor user environments or collect customer environment information. In Windows release health, all known issue content across all supported Windows versions is published to all subscribed customers. Future iterations of the solution may target content based on customer location, industry, or Windows version.
+
+- **Where do I find Windows release health?**
+ After logging into Microsoft 365 admin center, expand the left-hand menu using **…Show All**, click **Health** and you’ll see **Windows release health**.
+
+- **Is the Windows release health content published to Microsoft 365 admin center the same as the content on Windows release health on Docs.microsoft.com?**
+ No. While the content is similar, you may see more issues and more technical details published to Windows release health on Microsoft 365 admin center to better support the IT admin. For example, you’ll find details to help you diagnose issues in your environment, steps to mitigate issues, and root cause analysis.
+
+- **How often will content be updated?**
+ In an effort to ensure Windows customers have important information as soon as possible, all major known issues will be shared with Windows customers on both Docs.microsoft.com and the Microsoft 365 admin center. We may also update the details available for Windows release health in the Microsoft 365 admin center when we have additional details on workarounds, root cause, or other information to help you be planful in your environment.
+
+- **Can I share this content publicly or with other Windows customers?**
+ Windows release health is provided to you as a licensed Windows customer and is not to be shared publicly.
+
+- **Is the content redundant? How is the content organized in the different tabs?**
+ Windows release health provides three tabs. The landing **All versions** tab allows you to click into a specific version of Windows. The Known issues tab shows the list of issues that are active or resolved in the past 30 days. The History tab shows a six-month history of known issues that have been resolved.
+
+- **How do I find information for the versions of Windows I’m managing?**
+ On the **All versions** tab, you can select any Windows version. This will take you to the Known issues tab filtered for the version you selected. The known issues tab provides the list of active known issues and those resolved in the last 30 days. This selection persists throughout your session until changed. From the History tab you can view the list of resolved issues for that version. To change versions, use the filter in the tab.
+
+### Microsoft 365 Admin Center functions
+
+- **How do I best search for issues impacting my environment?**
+ You can search Microsoft 365 admin center pages using keywords. For Windows release health, go to the desired product page and search using KB numbers, build numbers, or keywords.
+
+- **How do I add other Windows admins?**
+ Using the left-hand menu, go to Users, then select the Active Users tab and follow the prompts to add a new user, or assign an existing user, to the role of “Service Support admin.”
+
+- **Why can’t I click to the KB article from the Known issues or History tabs?**
+ Within the issue description, you’ll find links to the KB articles. In the Known issue and History tabs, the entire row is a clickable entry to the issue’s Details pane.
+
+- **Microsoft 365 admin center has a mobile app but I don’t see Windows release health under the Health menu. Is this an open issue?**
+ We are working to build the Windows release health experience on mobile devices in a future release.
+
+### Help and support
+
+- **What should I do if I have an issue with Windows that is not reported in Windows release health?**
+ Seek assistance through Premier support, the [Microsoft Support website](http://support.microsoft.com), or connect with your normal channels for Windows support.
+
+- **When reaching out to Support, they asked me for an advisory ID. What is this and where can it?**
+ The advisory ID can be found in the upper left-hand corner of the known issue Details pane. To find it, select the Known issue you’re seeking help on, click the Details pane and you’ll find the ID under the issue title. It will be the letters WI followed by a number, similar to “WI123456”.
+
+- **How can I learn more about expanding my use of Microsoft 365 admin center?**
+ To learn more, see the [Microsoft 365 admin center documentation](https://docs.microsoft.com/en-us/microsoft-365/admin/admin-overview/about-the-admin-center).
diff --git a/windows/deployment/update/images/WRH-history-20H2.png b/windows/deployment/update/images/WRH-history-20H2.png
new file mode 100644
index 0000000000000000000000000000000000000000..c00e041b690bfbc727abaef2d981e9cea1e53614
GIT binary patch
literal 274522
zcmZs?b9`M**D%~RO&T?}ZQE&V+qUhbv7Hm0ps{T?wr$(yN#6Fl?)!Q1eShrV-h1}U
zEbUoqW+7Z&R_r@87WAi2pT0|o3oCy51itp^6WAdn#Ge*c^%#avp9nrl2n#5?XPjkz
zOF~h3Y0560Xz@YZTcocJZK7;r>IQ>emVB-kGWg^Jq$v$D9H)9`o3LXbGZu=s?>
z5VBXHQ|XJW3OrbO?kWBf{1so;u0g4t%4VyJoy+`X=i{R!zTaC-#18@l$gf}g|Ib?h
zu^`$w`TwW+OLx4{nqN?g-dl>f?Ef|3-{J2hYSHbgn*zekF#pelf42>*EWCMDM
zzPkN`Rt$oSb*wN^>()l2jn>J0S?IL++y@%H(SJaav(?fN6Dnw`j@;~1Q_#|OpSzw;
z{@l@!`^$-saD+ARza2TgJVc(O)deG_#Qbu*+;Hc?1NBR{|AhLNw2UY7NiVDws)2DJ
z`|V65eU0P1q&A(}z1cr7&cq-u{&~Rptcl`91u%RH+lIyEN*WoFjEIaBNre8-B*x~{
z7(h0gks~e9+pR$OTBAWY9JtWtv47xyjb~B$i%|gak6UZIY%ck))B+MQ#s$gZ#ixn|
zgrvz5|0Vc}I%tdTFKfF$;z9K4D>sJQ%m2Ll|F~N0HkahSi#X)}JN}Ja&>sCC$v{qf
zul0{6|0~sQy>I8wcKkb>@_#Y-M*KgrxK1GbJMG_T1ijvoCx8B>?uqt4(Ei2fA7=f9
zt?=VNoO{DZK$Q7!^FN*5k#}os5oO}yrj$JJZ<+qDZ~yS~$;#2*URzW2ebZ`qP}n}j
zBwU?GgaoH_VK6!&VtxAuAbKT@SPE%6NKlzRPc_AX1Bap(N*P=uz+4cdk`@?C{12L2
z^44tJWQo^t#=1xF*vI($;v|AZ@x||2|FZlaVh5>_;?)C$S)xb+1-^u?!$BZJf%oJf
z6jRaynO)1E68mMjte>lLfReg_|D(~6#qYCJ24NA~t
zs5Ie_kJ>(L-`n5`ze;Cug*I$<`VW$x7W6~qhRMh69+
z<_=wMNy;9}lNexoi2PO8+YYX*u)}{b=a*z*o{rBy%#sza*YMUzzINw9K}WAMpB6lr
z01hUPYe|soG_Tomxt$0-iq{<6_tdU}HcCC?wp@29W`XM(r$
zrhxOavch$g~rfyUFxDntFadJ%*jJ7Y46(|V&mrT
zeP9J^%#H+>c{$!!7v$F34RJ?V>vKc)#LH{NBjKBHU7-RYKVTF54Y?Xi2dC;FW{ZXJ
zXzpYhP>N`lCwLY|-mXL4AGUa@7XAWa%g<@@1wnAVhYo
z$eRIdyQ`Z~dS>Gx1iG#_N6UqB2@j7Jg!O;4#ou42o00glI(1;iYU?MxQ8@8Z=Q(Y@
zI}Te^WeJo0R_FyfVB~mZ@O{>kKbta$*SV5GcLuBV>w}*5
zaur=5T?bTgcUqD2)@niU+tdAFxi(*{@-dxp-t)(+2M%@p;?hlZ1f}j+@8Vs~BdU=<
z?9T739^Sbd0p0O0vKC6e$DHW4-oFhhb)J9Y>7-G#bG`Ov$5Jhj!C0v=eQJ~GYVqq1S_2i_{#TwlGti&QbJ75D(YZL;(x?1bL?_B<3
zJwKfNsDdoG6Co+$0j|m!K6)ww2r7u#+WP@qh8tA+Iyz#{DZQkFCwl{>?!Q%>8-5NE
zD9~i=1-f7Kcnc@D*sR1&B$LS%xkWR6@_yln9NaxyX^2c?HoF;Po~(90R?PA|p|qSY
z6(K-C$o=2;f`hE@lbi%+o~KKn&-?vgdHm)J)x;V;-GFM*UOvJabpWF+*4FOXYBo_^
z5V`L2XS?k|?fb2csOEQwjkO!x#dUi|uj1~fZ@SxdtdSV@{r9lu>=8L~^F_`l9ZT)Y
zgWYL3*v@82=1{R~Oks3~{3FSb?M%li3uCYTKlb^&>C!wqv9vuL{5(B1XYYK7`ZLqca5IYp_S_iGUu-F
zq;%T&d}Xs;3h%X@H*xO2&|i-rb;iS*#<93(q9(5Hw1BlMy>;8i695!l^o-$F
z^tzJC@-8Y0WD<@RwG_k$47rlH#!VB?WFki?-gi=F+$o+&4qxN32febalqcNafLZ?lu<{b|?O
z#N;@caoSv&Uu)d9P@~SY-h4U$jW(UxbS!ht<4}j^5S1OE
z%vkt4F-<{76dNJlJ}D_lxD=M*AVT1-hL<{bq#aGeNU9pmQ*ySzsOMj&Ag!QXi6r+sKe`)~
z6!4?XJgC5TK3%)fM|KouzY$|^OBP-WdlaZaD~
zu8%I`1T;ulmJHbZ-&9NWkm@TkBQsi
zM%5k+m{Axe$N3&r(;K>{{k_`W-5w+kw|#w!#i@^QEe)3b8Od#|qzmWO3OJHiQ$g@)
zGv#3D&bWPDs}BZ~Ym^*L=jrIvj3t|YHx{F&?4>~{=!yLA!6kJU1gQ*&RW$v85|N6+
z-6Yxs!KI|(+iaTsjx;v}X{>PYk*j803XD4@GG!uH`bnS8FgHIe853R
zAKp~Z$Tj=-{KKi$GON0Bn*Qd~3j)y9N5%ZCCoVBsmugjlx>UY~#OT5FS7q^Q9C{fcZ=!gE_F7rj(oZvYR;X7-q
zZMVNIWiWNir`l8eoVDyrj1SDsf3Nltoc;>_OgC}N|5Hg0KZ3c)*HcwNLIF+o=DCUg
z_PEUsiEcG${Io2lbHS^Qq^7ApV1YF%!)u}cj?aq$&CZ5IV&U>W7yxzQzRgS3<$+kY
zDmH|_cWHC#G|it4p*@s-bcat(U`VA6ns9#T^v=f9dG8`YiJ2y#53F4GJlf=9W)^%p
zN53vm6w|SfB|*xFKhN{6y1nb-o~xcMHPY+UykdEHES)ux*X!ZtN@(}GnfGkHNiEj=gSP%#d2TL|XO<_GS*8nG
zw$D4KPzc<7-X7~}8nK9%FY_=}S{k2gFo|zE2xk8knz2~ohUu){Y7uQXS%^sSx$NwE
z5KJ?gCyk9SU1yA!xbpDcA^O<$omly6Z_kL#|NO;Y0%}NDf3AK^qaS(A0hth29R&5V
z?6tei;GA|@53AW0f_hLRA(O3%P}c^3i=y#evE&i4WZyf$G;QAU)E>+9grl%giq04m
zg|CKJT01s
z{!$J3-Y}wL$iMPx*Erkvz^m%}et~YA(wvEJfQjMsAmno3$-ylH_GKxEB)3HbJ0iAwD^%EF4dltj?-|eHI#YQHf
zb$jDP$a@C0jR&mz>PrZ^aqqcuheqSm|K53V>DVnnX<2c%t4qiW4L?*(SC_FGGE-6-@`;=FSqe$DB5~BZ5zsyonMnEbg
zF3Jo++5Zb~{CL5P;Fb-*Xme7wgge1+9nIty_eysudMS1BJa6WTt^E=EndQWr3Vzca
z{Q5VVG+gYv1`?E?#7`$KV~1BEc>U4ir!o*sIa)dG%GL)>Ygb;J0h3{q8Llg&<@Gg$
z8-(RaEICXJTY7;sM|$zd5iK$`y{MMEGffa9aCmI?f;!TXH-Gy}Dd{J4LUvclZ4?
z>>O)2sZo_!;IgrSqe9IOP0Z=}ri1-D$SvS`?}-rw2b)DfCsO+3`7rxI$V!R;
zi=%428EfhTkSsWwZ$syQ=LiJ9MQ1QRiX%o_Ysj`M6X@R>Hry$Kd4Ae2qTJ|+kC;(3
zX7yJH*|0ffx*iT?+D`g@LFiXeBUP9VUyw`$Ow^JW+HA*iG+7|#%hZN_l*R)!gN5MfWSbk}QvT}(mQ
zYsiKaHG=XyN~n@6R$=C;gF$0U1^Uc3`4(r;QE9YfRi%2V1vQq|8M9+zw_D303r(vK
zJ;*RWL|kB6=i~6n$OFNW+tYh{j^&n!e22r5zjHRA1@8(iRu@
zgZC_a`wiu-uJ_M1E?rnr`clT>{Xieswr!}m4rQ9<3G^ztm#VLBGNiT5yvoAcx0k-A
zvp3n*Wxg*i76OC5W&wRj%>wucns#Y?cBo#eps3}n$|AIDJoeOZ8g-41
zbK`znrdrYh``zZ08n3Q=9%w{AMmV>J@J^(&E>Z4ragm<}HYbkrvvPqYXyHumZYP88
z2?~FFIKJp0H}ZJ>+XLFWqiLb0lxMqggS$7VZh~lRwgJ8CApvNdmTwa03Q=g8Qt30i`Zo+c@`t6}WKYxGLuwh4>D^Zt3?&hNEB>y{#Hsll01
z|8*bPqf9x@Ti8)671D=X>h&FsivWz@{230EF^X0ri7?;iMrLwHP!8}EUcPr>1lBA-
zd8MIX;?#Uae>+$1F}9yvpPW@+k=``$GZKgoOv%a!BCm;Cq$_2
z%3RuAD&}F;ZMa<=fwVZHe#bOyFaG#L%~+~6>T6DF1QxssJ~<}ziG+$u;C^$X=2RsR
z3D(G&^Jtk0$iA8-Xt<4y!F*e4hr>uatrMKh2YL;p1lmhW&7cif^AJ>9m>n^UoY5*Q
z={9S}K97$&2eL|yPHE`KBFohm@7Z&NrAw;Xv15{G+me$dMpx$|Q7oGNPEe0ZkL_%9
z{A8E|4Ql2~!5u!B>$ed}aQ2E+=WrJPqEM$Wu