mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Merge branch 'main' into prisettings
This commit is contained in:
commit
ae003b1cf2
@ -20519,6 +20519,96 @@
|
|||||||
"source_path": "windows/client-management/mdm/policy-ddf-file.md",
|
"source_path": "windows/client-management/mdm/policy-ddf-file.md",
|
||||||
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-ddf",
|
"redirect_url": "/windows/client-management/mdm/configuration-service-provider-ddf",
|
||||||
"redirect_document_id": true
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "education/windows/education-scenarios-store-for-business.md",
|
||||||
|
"redirect_url": "/windows/resources",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "education/windows/teacher-get-minecraft.md",
|
||||||
|
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "education/windows/school-get-minecraft.md",
|
||||||
|
"redirect_url": "/education/windows/get-minecraft-for-education",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/identity-protection/credential-guard/dg-readiness-tool.md",
|
||||||
|
"redirect_url": "/windows/security/identity-protection/credential-guard/credential-guard",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/information-protection/tpm/change-the-tpm-owner-password.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/get-support-for-security-baselines.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/mbsa-removal-and-guidance.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/information-protection/bitlocker/bitlocker-recovery-loop-break.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/identity-protection/credential-guard/credential-guard-scripts.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/information-protection/tpm/manage-tpm-commands.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/information-protection/tpm/manage-tpm-lockout.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/device-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-set-individual-device.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/windows-defender-application-control/audit-and-enforce-windows-defender-application-control-policies.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/windows-firewall/procedures-used-in-this-guide.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/whats-new/windows-10-insider-preview.md",
|
||||||
|
"redirect_url": "/windows/whats-new",
|
||||||
|
"redirect_document_id": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md",
|
||||||
|
"redirect_url": "/windows/security",
|
||||||
|
"redirect_document_id": false
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
@ -2,6 +2,7 @@
|
|||||||
metadata:
|
metadata:
|
||||||
title: Microsoft Edge - Frequently Asked Questions (FAQ) for IT Pros
|
title: Microsoft Edge - Frequently Asked Questions (FAQ) for IT Pros
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
|
ms.date: 12/14/2020
|
||||||
audience: itpro
|
audience: itpro
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
description: Answers to frequently asked questions about Microsoft Edge features, integration, support, and potential problems.
|
description: Answers to frequently asked questions about Microsoft Edge features, integration, support, and potential problems.
|
||||||
|
@ -11,7 +11,7 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
title: Enterprise Mode for Microsoft Edge
|
title: Enterprise Mode for Microsoft Edge
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.date: ''
|
ms.date: 07/17/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Enterprise Mode for Microsoft Edge
|
# Enterprise Mode for Microsoft Edge
|
||||||
@ -55,5 +55,3 @@ You can build and manage your Enterprise Mode Site List is by using any generic
|
|||||||
|
|
||||||
|
|
||||||
### Add multiple sites to the site list
|
### Add multiple sites to the site list
|
||||||
|
|
||||||
|
|
||||||
|
@ -1,3 +1,6 @@
|
|||||||
|
---
|
||||||
|
ms.date: 07/17/2018
|
||||||
|
---
|
||||||
Before you can use a site list with Enterprise Mode, you must turn the functionality on and set up the system for centralized control. By allowing
|
Before you can use a site list with Enterprise Mode, you must turn the functionality on and set up the system for centralized control. By allowing
|
||||||
centralized control, you can create one global list of websites that render using Enterprise Mode. Approximately 65 seconds after Internet Explorer 11 starts, it looks for a properly formatted site list. If a new site list if found, with a different version number than the active list, IE11 loads and uses the newer version. After the initial check, IE11 won’t look for an updated list again until you restart the browser.
|
centralized control, you can create one global list of websites that render using Enterprise Mode. Approximately 65 seconds after Internet Explorer 11 starts, it looks for a properly formatted site list. If a new site list if found, with a different version number than the active list, IE11 loads and uses the newer version. After the initial check, IE11 won’t look for an updated list again until you restart the browser.
|
||||||
|
|
||||||
|
@ -1,4 +1,7 @@
|
|||||||
|
---
|
||||||
|
ms.date: 07/17/2018
|
||||||
|
---
|
||||||
## What is Enterprise Mode?
|
## What is Enterprise Mode?
|
||||||
Enterprise Mode, a compatibility mode that runs on Internet Explorer 11 on Windows 10, Windows 8.1, and Windows 7 devices, lets websites render using a modified browser configuration that’s designed to emulate either Windows Internet Explorer 7 or Windows Internet Explorer 8. Running in this mode helps to avoid many of the common compatibility problems associated with web apps written and tested on older versions of Internet Explorer.
|
Enterprise Mode, a compatibility mode that runs on Internet Explorer 11 on Windows 10, Windows 8.1, and Windows 7 devices, lets websites render using a modified browser configuration that’s designed to emulate either Windows Internet Explorer 7 or Windows Internet Explorer 8. Running in this mode helps to avoid many of the common compatibility problems associated with web apps written and tested on older versions of Internet Explorer.
|
||||||
|
|
||||||
Many customers identify web app compatibility as a significant cost to upgrading because web apps need to be tested and upgraded before adopting a new browser. The improved compatibility provided by Enterprise Mode can help give customers confidence to upgrade to IE11, letting customers benefit from modern web standards, increased performance, improved security, and better reliability.
|
Many customers identify web app compatibility as a significant cost to upgrading because web apps need to be tested and upgraded before adopting a new browser. The improved compatibility provided by Enterprise Mode can help give customers confidence to upgrade to IE11, letting customers benefit from modern web standards, increased performance, improved security, and better reliability.
|
||||||
|
@ -57,7 +57,7 @@ If you use Automatic Updates in your company, but want to stop your users from a
|
|||||||
> The toolkit won't stop users with local administrator accounts from manually installing Internet Explorer 11. Using this toolkit also prevents your users from receiving automatic upgrades from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11. For more information, see the [Internet Explorer 11 Blocker Toolkit frequently asked questions](../ie11-faq/faq-ie11-blocker-toolkit.yml).
|
> The toolkit won't stop users with local administrator accounts from manually installing Internet Explorer 11. Using this toolkit also prevents your users from receiving automatic upgrades from Internet Explorer 8, Internet Explorer 9, or Internet Explorer 10 to Internet Explorer 11. For more information, see the [Internet Explorer 11 Blocker Toolkit frequently asked questions](../ie11-faq/faq-ie11-blocker-toolkit.yml).
|
||||||
|
|
||||||
- **Use an update management solution to control update deployment.**
|
- **Use an update management solution to control update deployment.**
|
||||||
If you already use an update management solution, like [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or the more advanced [Microsoft Endpoint Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), you should use that instead of the Internet Explorer Blocker Toolkit.
|
If you already use an update management solution, like [Windows Server Update Services (WSUS)](/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) or the more advanced [Microsoft Configuration Manager](/previous-versions/system-center/system-center-2012-R2/gg682129(v=technet.10)), you should use that instead of the Internet Explorer Blocker Toolkit.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you use WSUS to manage updates, and Update Rollups are configured for automatic installation, Internet Explorer will automatically install throughout your company.
|
> If you use WSUS to manage updates, and Update Rollups are configured for automatic installation, Internet Explorer will automatically install throughout your company.
|
||||||
@ -66,7 +66,7 @@ Additional information on Internet Explorer 11, including a Readiness Toolkit, t
|
|||||||
|
|
||||||
## Availability of Internet Explorer 11
|
## Availability of Internet Explorer 11
|
||||||
|
|
||||||
Automatic Updates will start to distribute Internet Explorer 11 shortly after the final release of the product and will distribute it through the Microsoft Endpoint Manager and WSUS.
|
Automatic Updates will start to distribute Internet Explorer 11 shortly after the final release of the product and will distribute it through the Microsoft Configuration Manager and WSUS.
|
||||||
|
|
||||||
## Prevent automatic installation of Internet Explorer 11 with WSUS
|
## Prevent automatic installation of Internet Explorer 11 with WSUS
|
||||||
|
|
||||||
|
@ -9,6 +9,7 @@ title: Internet Explorer 11 (IE11) - Deployment Guide for IT Pros (Internet Expl
|
|||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
|
ms.date: 02/24/2016
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
||||||
@ -62,4 +63,4 @@ IE11 offers differing experiences in Windows 8.1:
|
|||||||
## Related topics
|
## Related topics
|
||||||
- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.yml)
|
- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.yml)
|
||||||
- [Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide](../ie11-ieak/index.md)
|
- [Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide](../ie11-ieak/index.md)
|
||||||
- [Microsoft Edge - Deployment Guide for IT Pros](/microsoft-edge/deploy/)
|
- [Microsoft Edge - Deployment Guide for IT Pros](/microsoft-edge/deploy/)
|
||||||
|
@ -50,7 +50,7 @@ Internet Explorer 11 gives you some new Group Policy settings to help you manage
|
|||||||
| Turn off the ability to launch report site problems using a menu option | Administrative Templates\Windows Components\Internet Explorer\Browser menus | Internet Explorer 11 | This policy setting allows you to manage whether users can start the **eport Site Problems** dialog box from the **Internet Explorer** settings area or from the **Tools** menu.<p>If you enable this policy setting, users won’t be able to start the **Report Site Problems** dialog box from the Internet Explorer settings or the Tools menu.<p>If you disable or don’t configure this policy setting, users will be able to start the **Report Site Problems** dialog box from the **Internet Explorer** settings area or from the **Tools** menu. |
|
| Turn off the ability to launch report site problems using a menu option | Administrative Templates\Windows Components\Internet Explorer\Browser menus | Internet Explorer 11 | This policy setting allows you to manage whether users can start the **eport Site Problems** dialog box from the **Internet Explorer** settings area or from the **Tools** menu.<p>If you enable this policy setting, users won’t be able to start the **Report Site Problems** dialog box from the Internet Explorer settings or the Tools menu.<p>If you disable or don’t configure this policy setting, users will be able to start the **Report Site Problems** dialog box from the **Internet Explorer** settings area or from the **Tools** menu. |
|
||||||
| Turn off the flip ahead with page prediction feature | Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page | At least Internet Explorer 10 on Windows 8 | This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.<p>If you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn’t loaded into the background.<p>If you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.<p>If you don’t configure this setting, users can turn this behavior on or off, using the **Settings** charm.<p>**Note**<br>Microsoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn’t available for Internet Explorer for the desktop. |
|
| Turn off the flip ahead with page prediction feature | Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page | At least Internet Explorer 10 on Windows 8 | This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.<p>If you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn’t loaded into the background.<p>If you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.<p>If you don’t configure this setting, users can turn this behavior on or off, using the **Settings** charm.<p>**Note**<br>Microsoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn’t available for Internet Explorer for the desktop. |
|
||||||
| Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows | Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page | IE11 on Windows 10 | This policy setting determines whether IE11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you enable this policy setting, IE11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you disable this policy setting, IE11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you don't configure this policy setting, users can turn this feature on or off using IE settings. This feature is turned off by default.<p>**Important**<br>When using 64-bit processes, some ActiveX controls and toolbars might not be available. |
|
| Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows | Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page | IE11 on Windows 10 | This policy setting determines whether IE11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you enable this policy setting, IE11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you disable this policy setting, IE11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.<p>If you don't configure this policy setting, users can turn this feature on or off using IE settings. This feature is turned off by default.<p>**Important**<br>When using 64-bit processes, some ActiveX controls and toolbars might not be available. |
|
||||||
| Turn on Site Discovery WMI output | Administrative Templates\Windows Components\Internet Explorer | At least Internet Explorer 8 | This policy setting allows you to manage the WMI output functionality of the Internet Explorer Site Discovery Toolkit.<p>If you enable this policy setting, the Internet Explorer Site Discovery Toolkit will log its collected data to an WMI class, which can be aggregated by using a client-management solution, such as Microsoft Endpoint Configuration Manager.<p>If you disable or don’t configure this setting, the Internet Explorer Site Discovery Toolkit won’t log its collected data to an WMI class.<p>**Note:**<br>Enabling or disabling this setting won’t impact any other output methods available to the Internet Explorer Site Discovery Toolkit. |
|
| Turn on Site Discovery WMI output | Administrative Templates\Windows Components\Internet Explorer | At least Internet Explorer 8 | This policy setting allows you to manage the WMI output functionality of the Internet Explorer Site Discovery Toolkit.<p>If you enable this policy setting, the Internet Explorer Site Discovery Toolkit will log its collected data to an WMI class, which can be aggregated by using a client-management solution, such as Microsoft Configuration Manager.<p>If you disable or don’t configure this setting, the Internet Explorer Site Discovery Toolkit won’t log its collected data to an WMI class.<p>**Note:**<br>Enabling or disabling this setting won’t impact any other output methods available to the Internet Explorer Site Discovery Toolkit. |
|
||||||
| Turn on Site Discovery XML output | Administrative Templates\Windows Components\Internet Explorer | At least Internet Explorer 8 | This policy setting allows you to manage the XML output functionality of the Internet Explorer Site Discovery Toolkit.<p>If you enable this policy setting, the Internet Explorer Site Discovery Toolkit will log its collected data to an XML file, stored in your specified location.<p>If you disable or don’t configure this setting, the Internet Explorer Site Discovery Toolkit won’t log its collected data to an XML file.<p>**Note:**<br>Enabling or disabling this setting won’t impact any other output methods available to the Internet Explorer Site Discovery Toolkit. |
|
| Turn on Site Discovery XML output | Administrative Templates\Windows Components\Internet Explorer | At least Internet Explorer 8 | This policy setting allows you to manage the XML output functionality of the Internet Explorer Site Discovery Toolkit.<p>If you enable this policy setting, the Internet Explorer Site Discovery Toolkit will log its collected data to an XML file, stored in your specified location.<p>If you disable or don’t configure this setting, the Internet Explorer Site Discovery Toolkit won’t log its collected data to an XML file.<p>**Note:**<br>Enabling or disabling this setting won’t impact any other output methods available to the Internet Explorer Site Discovery Toolkit. |
|
||||||
| Use the Enterprise Mode IE website list | Administrative Templates\Windows Components\Internet Explorer | IE11 on Windows 10, version 1511 | This policy setting lets you specify where to find the list of websites you want opened using Enterprise Mode, instead of Standard mode, because of compatibility issues. Users can’t edit this list.<p>If you enable this policy setting, Internet Explorer downloads the Enterprise Mode website list from the `HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE`\Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode hive, opening all included websites using Enterprise Mode. We recommend storing and downloading your list from a secure web server `(https://)`, to help protect against data tampering.<p>If you disable or don’t configure this policy setting, Internet Explorer opens all websites using **Standard** mode. |
|
| Use the Enterprise Mode IE website list | Administrative Templates\Windows Components\Internet Explorer | IE11 on Windows 10, version 1511 | This policy setting lets you specify where to find the list of websites you want opened using Enterprise Mode, instead of Standard mode, because of compatibility issues. Users can’t edit this list.<p>If you enable this policy setting, Internet Explorer downloads the Enterprise Mode website list from the `HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE`\Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode hive, opening all included websites using Enterprise Mode. We recommend storing and downloading your list from a secure web server `(https://)`, to help protect against data tampering.<p>If you disable or don’t configure this policy setting, Internet Explorer opens all websites using **Standard** mode. |
|
||||||
|
|
||||||
|
@ -33,7 +33,7 @@ Before you begin, you should:
|
|||||||
|
|
||||||
- **Check the operating system requirements.** Check that the requirements for the computer you're building your installation package from, and the computers you're installing IE11 to, all meet the system requirements for IEAK 11 and IE11. For Internet Explorer requirements, see [System requirements and language support for Internet Explorer 11 (IE11)](system-requirements-and-language-support-for-ie11.md). For IEAK 11 requirements, see [Internet Explorer Administration Kit 11 (IEAK 11) - Administration Guide for IT Pros](../ie11-ieak/index.md).
|
- **Check the operating system requirements.** Check that the requirements for the computer you're building your installation package from, and the computers you're installing IE11 to, all meet the system requirements for IEAK 11 and IE11. For Internet Explorer requirements, see [System requirements and language support for Internet Explorer 11 (IE11)](system-requirements-and-language-support-for-ie11.md). For IEAK 11 requirements, see [Internet Explorer Administration Kit 11 (IEAK 11) - Administration Guide for IT Pros](../ie11-ieak/index.md).
|
||||||
|
|
||||||
- **Decide on your distribution method.** Decide how to distribute your custom installation package: Windows Update, Microsoft Endpoint Configuration Manager, or your network.
|
- **Decide on your distribution method.** Decide how to distribute your custom installation package: Windows Update, Microsoft Configuration Manager, or your network.
|
||||||
|
|
||||||
- **Gather URLs and branding and custom graphics.** Collect the URLs for your company's own **Home**, **Search**, and **Support** pages, plus any custom branding and graphic files for the browser toolbar button and the **Favorites** list icons.
|
- **Gather URLs and branding and custom graphics.** Collect the URLs for your company's own **Home**, **Search**, and **Support** pages, plus any custom branding and graphic files for the browser toolbar button and the **Favorites** list icons.
|
||||||
|
|
||||||
|
@ -6,6 +6,7 @@ author: dansimp
|
|||||||
ms.prod: ie11
|
ms.prod: ie11
|
||||||
ms.assetid: 9cb8324e-d73b-41ba-ade9-3acc796e21d8
|
ms.assetid: 9cb8324e-d73b-41ba-ade9-3acc796e21d8
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
|
ms.date: 03/15/2016
|
||||||
audience: itpro
|
audience: itpro
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: dansimp
|
ms.author: dansimp
|
||||||
@ -60,8 +61,3 @@ You can also click **Select All** to add, or **Clear All** to remove, all of the
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
@ -9,6 +9,7 @@ title: Internet Explorer Administration Kit 11 (IEAK 11) - Administrator's Guide
|
|||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
|
ms.date: 03/15/2016
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
||||||
@ -49,4 +50,4 @@ IE11 and IEAK 11 offers differing experiences between Windows 7 and Windows 8.1
|
|||||||
- [IEAK 11 licensing guidelines](licensing-version-and-features-ieak11.md)
|
- [IEAK 11 licensing guidelines](licensing-version-and-features-ieak11.md)
|
||||||
- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.yml)
|
- [Internet Explorer 11 - FAQ for IT Pros](../ie11-faq/faq-for-it-pros-ie11.yml)
|
||||||
- [Internet Explorer 11 (IE11) - Deployment Guide for IT Pros](../ie11-deploy-guide/index.md)
|
- [Internet Explorer 11 (IE11) - Deployment Guide for IT Pros](../ie11-deploy-guide/index.md)
|
||||||
- [Microsoft Edge - Deployment Guide for IT Pros](/microsoft-edge/deploy/)
|
- [Microsoft Edge - Deployment Guide for IT Pros](/microsoft-edge/deploy/)
|
||||||
|
@ -1,16 +1,12 @@
|
|||||||
---
|
---
|
||||||
author: aczechowski
|
author: aczechowski
|
||||||
ms.author: aaroncz
|
ms.author: aaroncz
|
||||||
ms.date: 12/16/2022
|
ms.date: 02/14/2023
|
||||||
ms.reviewer: cathask
|
ms.reviewer: cathask
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.prod: ie11
|
ms.prod: ie11
|
||||||
ms.topic: include
|
ms.topic: include
|
||||||
---
|
---
|
||||||
|
|
||||||
> [!WARNING]
|
> [!CAUTION]
|
||||||
> **Update:** The retired, out-of-support Internet Explorer 11 desktop application is scheduled to be permanently disabled through a Microsoft Edge update on certain versions of Windows 10 on February 14, 2023.
|
> **Update:** The retired, out-of-support Internet Explorer 11 desktop application has been permanently disabled through a Microsoft Edge update on certain versions of Windows 10. For more information, see [Internet Explorer 11 desktop app retirement FAQ](https://aka.ms/iemodefaq).
|
||||||
>
|
|
||||||
> We highly recommend setting up IE mode in Microsoft Edge and disabling IE11 prior to this date to ensure your organization does not experience business disruption.
|
|
||||||
>
|
|
||||||
> For more information, see [Internet Explorer 11 desktop app retirement FAQ](https://aka.ms/iemodefaq).
|
|
||||||
|
@ -1,3 +1,6 @@
|
|||||||
|
---
|
||||||
|
ms.date: 10/24/2020
|
||||||
|
---
|
||||||
<!-- This file is generated automatically each week. Changes made to this file will be overwritten.-->
|
<!-- This file is generated automatically each week. Changes made to this file will be overwritten.-->
|
||||||
|
|
||||||
|
|
||||||
|
@ -46,6 +46,8 @@ items:
|
|||||||
href: configure-aad-google-trust.md
|
href: configure-aad-google-trust.md
|
||||||
- name: Configure Shared PC
|
- name: Configure Shared PC
|
||||||
href: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context
|
href: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context
|
||||||
|
- name: Get and deploy Minecraft Education
|
||||||
|
href: get-minecraft-for-education.md
|
||||||
- name: Use the Set up School PCs app
|
- name: Use the Set up School PCs app
|
||||||
href: use-set-up-school-pcs-app.md
|
href: use-set-up-school-pcs-app.md
|
||||||
- name: Change Windows edition
|
- name: Change Windows edition
|
||||||
@ -56,16 +58,6 @@ items:
|
|||||||
href: change-to-pro-education.md
|
href: change-to-pro-education.md
|
||||||
- name: Upgrade Windows Home to Windows Education on student-owned devices
|
- name: Upgrade Windows Home to Windows Education on student-owned devices
|
||||||
href: change-home-to-edu.md
|
href: change-home-to-edu.md
|
||||||
- name: "Get and deploy Minecraft: Education Edition"
|
|
||||||
items:
|
|
||||||
- name: "Get Minecraft: Education Edition"
|
|
||||||
href: get-minecraft-for-education.md
|
|
||||||
- name: "For IT administrators: get Minecraft Education Edition"
|
|
||||||
href: school-get-minecraft.md
|
|
||||||
- name: "For teachers: get Minecraft Education Edition"
|
|
||||||
href: teacher-get-minecraft.md
|
|
||||||
- name: Work with Microsoft Store for Education
|
|
||||||
href: education-scenarios-store-for-business.md
|
|
||||||
- name: Migrate from Chromebook to Windows
|
- name: Migrate from Chromebook to Windows
|
||||||
items:
|
items:
|
||||||
- name: Chromebook migration guide
|
- name: Chromebook migration guide
|
||||||
|
@ -74,7 +74,7 @@ It's critical that MAKs are protected whenever they're used. The following proce
|
|||||||
- Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](/windows/client-management/mdm/windowslicensing-csp);
|
- Mobile Device Management (like Microsoft Intune) via [WindowsLicensing CSP](/windows/client-management/mdm/windowslicensing-csp);
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key isn't accessible by students.
|
> If you are using a Mobile Device Management product other than Microsoft Intune, ensure the key isn't accessible by students.
|
||||||
- Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Endpoint Configuration Manager.
|
- Operating System Deployment processes with tools such as Microsoft Deployment Toolkit or Microsoft Configuration Manager.
|
||||||
|
|
||||||
For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades).
|
For a full list of methods to perform a Windows edition upgrade and more details, see [Windows 10 edition upgrade](/windows/deployment/upgrade/windows-10-edition-upgrades).
|
||||||
|
|
||||||
@ -117,7 +117,7 @@ These steps provide instructions on how to use Microsoft Intune to upgrade devic
|
|||||||
|
|
||||||
These steps configure a filter that will only apply to devices running the *Windows Home edition*. This filter will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters).
|
These steps configure a filter that will only apply to devices running the *Windows Home edition*. This filter will ensure only devices running *Windows Home edition* are upgraded. For more information about filters, see [Create filters in Microsoft Intune](/mem/intune/fundamentals/filters).
|
||||||
|
|
||||||
- Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com)
|
- Start in the [**Microsoft Intune admin center**](https://go.microsoft.com/fwlink/?linkid=2109431)
|
||||||
- Select **Tenant administration** > **Filters**
|
- Select **Tenant administration** > **Filters**
|
||||||
- Select **Create**
|
- Select **Create**
|
||||||
- Specify a name for the filter (for example *Windows Home edition*)
|
- Specify a name for the filter (for example *Windows Home edition*)
|
||||||
@ -142,7 +142,7 @@ These steps configure a filter that will only apply to devices running the *Wind
|
|||||||
|
|
||||||
These steps create and assign a Windows edition upgrade policy. For more information, see [Windows 10/11 device settings to upgrade editions or enable S mode in Intune](/mem/intune/configuration/edition-upgrade-windows-settings).
|
These steps create and assign a Windows edition upgrade policy. For more information, see [Windows 10/11 device settings to upgrade editions or enable S mode in Intune](/mem/intune/configuration/edition-upgrade-windows-settings).
|
||||||
|
|
||||||
- Start in the [**Microsoft Endpoint Manager admin console**](https://endpoint.microsoft.com)
|
- Start in the [**Microsoft Intune admin center**](https://go.microsoft.com/fwlink/?linkid=2109431)
|
||||||
- Select **Devices** > **Configuration profiles**
|
- Select **Devices** > **Configuration profiles**
|
||||||
- Select **Create profile**
|
- Select **Create profile**
|
||||||
- Select the **Platform** as **Windows 10 or later**
|
- Select the **Platform** as **Windows 10 or later**
|
||||||
@ -177,9 +177,9 @@ The edition upgrade policy will now apply to all existing and new Windows Home e
|
|||||||
|
|
||||||
### Step 3: Report on device edition
|
### Step 3: Report on device edition
|
||||||
|
|
||||||
You can check the Windows versions of managed devices in the Microsoft Endpoint Manager admin console.
|
You can check the Windows versions of managed devices in the Microsoft Intune admin center.
|
||||||
|
|
||||||
- Start in the **Microsoft Endpoint Manager admin console**
|
- Start in the **Microsoft Intune admin center**
|
||||||
- Select **Devices** > **Windows**
|
- Select **Devices** > **Windows**
|
||||||
- Select the **Columns** button
|
- Select the **Columns** button
|
||||||
- Select **Sku Family**
|
- Select **Sku Family**
|
||||||
|
@ -346,7 +346,7 @@ Table 5. Select on-premises AD DS, Azure AD, or hybrid
|
|||||||
|--- |--- |--- |--- |
|
|--- |--- |--- |--- |
|
||||||
|Use Office 365||✔️|✔️|
|
|Use Office 365||✔️|✔️|
|
||||||
|Use Intune for management||✔️|✔️|
|
|Use Intune for management||✔️|✔️|
|
||||||
|Use Microsoft Endpoint Manager for management|✔️||✔️|
|
|Use Microsoft Configuration Manager for management|✔️||✔️|
|
||||||
|Use Group Policy for management|✔️||✔️|
|
|Use Group Policy for management|✔️||✔️|
|
||||||
|Have devices that are domain-joined|✔️||✔️|
|
|Have devices that are domain-joined|✔️||✔️|
|
||||||
|Allow faculty and students to Bring Your Own Device (BYOD) which aren't domain-joined||✔️|✔️|
|
|Allow faculty and students to Bring Your Own Device (BYOD) which aren't domain-joined||✔️|✔️|
|
||||||
@ -359,7 +359,7 @@ You may ask the question, “Why plan for device, user, and app management befor
|
|||||||
|
|
||||||
Also, planning management before deployment is essential to being ready to support the devices as you deploy them. You want to have your management processes and technology in place when the first teachers, facility, or students start using their new Windows device.
|
Also, planning management before deployment is essential to being ready to support the devices as you deploy them. You want to have your management processes and technology in place when the first teachers, facility, or students start using their new Windows device.
|
||||||
|
|
||||||
Table 6 is a decision matrix that lists the device, user, and app management products and technologies and the features supported by each product or technology. The primary device, user, and app management products and technologies include Group Policy, Microsoft Endpoint Configuration Manager, Intune, and the Microsoft Deployment Toolkit (MDT). Use this decision matrix to help you select the right combination of products and technologies for your plan.
|
Table 6 is a decision matrix that lists the device, user, and app management products and technologies and the features supported by each product or technology. The primary device, user, and app management products and technologies include Group Policy, Microsoft Configuration Manager, Intune, and the Microsoft Deployment Toolkit (MDT). Use this decision matrix to help you select the right combination of products and technologies for your plan.
|
||||||
|
|
||||||
Table 6. Device, user, and app management products and technologies
|
Table 6. Device, user, and app management products and technologies
|
||||||
|
|
||||||
@ -464,7 +464,7 @@ Use the following Microsoft management systems and the deployment resources to p
|
|||||||
|
|
||||||
- [Windows Autopilot](/mem/autopilot/windows-autopilot)
|
- [Windows Autopilot](/mem/autopilot/windows-autopilot)
|
||||||
|
|
||||||
- Microsoft Endpoint Configuration Manager [core infrastructure documentation](/mem/configmgr/core/)
|
- Microsoft Configuration Manager [core infrastructure documentation](/mem/configmgr/core/)
|
||||||
|
|
||||||
- Provisioning packages:
|
- Provisioning packages:
|
||||||
|
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Deploy Windows 10 in a school district (Windows 10)
|
title: Deploy Windows 10 in a school district (Windows 10)
|
||||||
description: Learn how to deploy Windows 10 in a school district. Integrate the school environment with Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD), use Microsoft Endpoint Configuration Manager, Intune, and Group Policy to manage devices.
|
description: Learn how to deploy Windows 10 in a school district. Integrate the school environment with Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD), use Microsoft Configuration Manager, Intune, and Group Policy to manage devices.
|
||||||
ms.topic: how-to
|
ms.topic: how-to
|
||||||
ms.date: 08/10/2022
|
ms.date: 08/10/2022
|
||||||
appliesto:
|
appliesto:
|
||||||
@ -9,7 +9,7 @@ appliesto:
|
|||||||
|
|
||||||
# Deploy Windows 10 in a school district
|
# Deploy Windows 10 in a school district
|
||||||
|
|
||||||
This guide shows you how to deploy the Windows 10 operating system in a school district. You learn how to deploy Windows 10 in classrooms; integrate the school environment with Microsoft Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD); and deploy Windows 10 and your apps to new devices or upgrade existing devices to Windows 10. This guide also describes how to use Microsoft Endpoint Configuration Manager, Microsoft Intune, and Group Policy to manage devices. Finally, the guide discusses common, ongoing maintenance tasks that you'll perform after initial deployment and the automated tools and built-in features of the operating system.
|
This guide shows you how to deploy the Windows 10 operating system in a school district. You learn how to deploy Windows 10 in classrooms; integrate the school environment with Microsoft Office 365, Active Directory Domain Services (AD DS), and Microsoft Azure Active Directory (Azure AD); and deploy Windows 10 and your apps to new devices or upgrade existing devices to Windows 10. This guide also describes how to use Microsoft Configuration Manager, Microsoft Intune, and Group Policy to manage devices. Finally, the guide discusses common, ongoing maintenance tasks that you'll perform after initial deployment and the automated tools and built-in features of the operating system.
|
||||||
|
|
||||||
## Prepare for district deployment
|
## Prepare for district deployment
|
||||||
|
|
||||||
@ -125,7 +125,7 @@ Now that you've the plan (blueprint) for your district and individual schools an
|
|||||||
|
|
||||||
The primary tool you'll use to deploy Windows 10 in your school is MDT, which uses Windows ADK components to make deployment easier. You could just use the Windows ADK to perform your deployment, but MDT simplifies the process by providing an intuitive, wizard-driven user interface (UI).
|
The primary tool you'll use to deploy Windows 10 in your school is MDT, which uses Windows ADK components to make deployment easier. You could just use the Windows ADK to perform your deployment, but MDT simplifies the process by providing an intuitive, wizard-driven user interface (UI).
|
||||||
|
|
||||||
You can use MDT as a stand-alone tool or integrate it with Microsoft Endpoint Configuration Manager. As a stand-alone tool, MDT performs Lite Touch Installation (LTI) deployments—deployments that require minimal infrastructure and allow you to control the level of automation. When integrated with Configuration Manager, MDT performs Zero Touch Installation (ZTI) deployments, which require more infrastructure (such as Configuration Manager) but result in fully automated deployments.
|
You can use MDT as a stand-alone tool or integrate it with Microsoft Configuration Manager. As a stand-alone tool, MDT performs Lite Touch Installation (LTI) deployments—deployments that require minimal infrastructure and allow you to control the level of automation. When integrated with Configuration Manager, MDT performs Zero Touch Installation (ZTI) deployments, which require more infrastructure (such as Configuration Manager) but result in fully automated deployments.
|
||||||
|
|
||||||
This guide focuses on LTI deployments to deploy the reference device. You can use ZTI deployments with Configuration Manager or LTI deployments to deploy the reference images to your faculty and student devices. If you want to only use MDT, see [Deploy Windows 10 in a school](./deploy-windows-10-in-a-school.md).
|
This guide focuses on LTI deployments to deploy the reference device. You can use ZTI deployments with Configuration Manager or LTI deployments to deploy the reference images to your faculty and student devices. If you want to only use MDT, see [Deploy Windows 10 in a school](./deploy-windows-10-in-a-school.md).
|
||||||
|
|
||||||
@ -163,7 +163,7 @@ The high-level process for deploying and configuring devices within individual c
|
|||||||
|
|
||||||
6. On the reference devices, deploy Windows 10 and the Windows desktop apps on the device, and then capture the reference image from the devices.
|
6. On the reference devices, deploy Windows 10 and the Windows desktop apps on the device, and then capture the reference image from the devices.
|
||||||
|
|
||||||
7. Import the captured reference images into MDT or Microsoft Endpoint Configuration Manager.
|
7. Import the captured reference images into MDT or Microsoft Configuration Manager.
|
||||||
|
|
||||||
8. On the student and faculty devices, deploy Windows 10 to new or existing devices, or upgrade eligible devices to Windows 10.
|
8. On the student and faculty devices, deploy Windows 10 to new or existing devices, or upgrade eligible devices to Windows 10.
|
||||||
|
|
||||||
@ -191,9 +191,9 @@ Before you select the deployment and management methods, you need to review the
|
|||||||
|Scenario feature |Cloud-centric|On-premises and cloud|
|
|Scenario feature |Cloud-centric|On-premises and cloud|
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
|Identity management | Azure AD (stand-alone or integrated with on-premises AD DS) | AD DS integrated with Azure AD |
|
|Identity management | Azure AD (stand-alone or integrated with on-premises AD DS) | AD DS integrated with Azure AD |
|
||||||
|Windows 10 deployment | MDT only | Microsoft Endpoint Manager with MDT |
|
|Windows 10 deployment | MDT only | Microsoft Configuration Manager with MDT |
|
||||||
|Configuration setting management | Intune | Group Policy<br/><br/>Intune|
|
|Configuration setting management | Intune | Group Policy<br/><br/>Intune|
|
||||||
|App and update management | Intune |Microsoft Endpoint Configuration Manager<br/><br/>Intune|
|
|App and update management | Intune |Microsoft Configuration Manager<br/><br/>Intune|
|
||||||
|
|
||||||
*Table 1. Deployment and management scenarios*
|
*Table 1. Deployment and management scenarios*
|
||||||
|
|
||||||
@ -205,19 +205,19 @@ These scenarios assume the need to support:
|
|||||||
Some constraints exist in these scenarios. As you select the deployment and management methods for your device, keep the following constraints in mind:
|
Some constraints exist in these scenarios. As you select the deployment and management methods for your device, keep the following constraints in mind:
|
||||||
|
|
||||||
* You can use Group Policy or Intune to manage configuration settings on a device but not both.
|
* You can use Group Policy or Intune to manage configuration settings on a device but not both.
|
||||||
* You can use Microsoft Endpoint Manager or Intune to manage apps and updates on a device but not both.
|
* You can use Configuration Manager or Intune to manage apps and updates on a device but not both.
|
||||||
* You can't manage multiple users on a device with Intune if the device is AD DS domain joined.
|
* You can't manage multiple users on a device with Intune if the device is AD DS domain joined.
|
||||||
|
|
||||||
Use the cloud-centric scenario and on-premises and cloud scenario as a guide for your district. You may need to customize these scenarios, however, based on your district. As you go through the [Select the deployment methods](#select-the-deployment-methods), [Select the configuration setting management methods](#select-the-configuration-setting-management-methods), and the [Select the app and update management products](#select-the-app-and-update-management-products) sections, remember these scenarios and use them as the basis for your district.
|
Use the cloud-centric scenario and on-premises and cloud scenario as a guide for your district. You may need to customize these scenarios, however, based on your district. As you go through the [Select the deployment methods](#select-the-deployment-methods), [Select the configuration setting management methods](#select-the-configuration-setting-management-methods), and the [Select the app and update management products](#select-the-app-and-update-management-products) sections, remember these scenarios and use them as the basis for your district.
|
||||||
|
|
||||||
### Select the deployment methods
|
### Select the deployment methods
|
||||||
|
|
||||||
To deploy Windows 10 and your apps, you can use MDT by itself or Microsoft Endpoint Manager and MDT together. For a district, there are a few ways to deploy Windows 10 to devices. Table 2 lists the methods that this guide describes and recommends. Use this information to determine which combination of deployment methods is right for your institution.
|
To deploy Windows 10 and your apps, you can use MDT by itself or Microsoft Configuration Manager and MDT together. For a district, there are a few ways to deploy Windows 10 to devices. Table 2 lists the methods that this guide describes and recommends. Use this information to determine which combination of deployment methods is right for your institution.
|
||||||
|
|
||||||
|Method|Description|
|
|Method|Description|
|
||||||
|--- |--- |
|
|--- |--- |
|
||||||
|MDT|MDT is an on-premises solution that supports initial operating system deployment and upgrade. You can use MDT to deploy and upgrade Windows 10. In addition, you can initially deploy Windows desktop and Microsoft Store apps and software updates.<br> Select this method when you: <li> Want to deploy Windows 10 to institution-owned and personal devices. (Devices need not be domain joined.) <li> Don’t have an existing AD DS infrastructure. <li> Need to manage devices regardless of where they are (on or off premises). <br>The advantages of this method are that: <br> <li> You can deploy Windows 10 operating systems <li> You can manage device drivers during initial deployment. <li>You can deploy Windows desktop apps (during initial deployment)<li> It doesn’t require an AD DS infrastructure.<li>It doesn’t have extra infrastructure requirements.<li>MDT doesn’t incur extra cost: it’s a free tool.<li>You can deploy Windows 10 operating systems to institution-owned and personal devices. <br> The disadvantages of this method are that it:<br> <li>Can’t manage applications throughout entire application life cycle (by itself).<li>Can’t manage software updates for Windows 10 and apps (by itself).<li>Doesn’t provide antivirus and malware protection (by itself).<li>Has limited scaling to large numbers of users and devices.|
|
|MDT|MDT is an on-premises solution that supports initial operating system deployment and upgrade. You can use MDT to deploy and upgrade Windows 10. In addition, you can initially deploy Windows desktop and Microsoft Store apps and software updates.<br> Select this method when you: <li> Want to deploy Windows 10 to institution-owned and personal devices. (Devices need not be domain joined.) <li> Don’t have an existing AD DS infrastructure. <li> Need to manage devices regardless of where they are (on or off premises). <br>The advantages of this method are that: <br> <li> You can deploy Windows 10 operating systems <li> You can manage device drivers during initial deployment. <li>You can deploy Windows desktop apps (during initial deployment)<li> It doesn’t require an AD DS infrastructure.<li>It doesn’t have extra infrastructure requirements.<li>MDT doesn’t incur extra cost: it’s a free tool.<li>You can deploy Windows 10 operating systems to institution-owned and personal devices. <br> The disadvantages of this method are that it:<br> <li>Can’t manage applications throughout entire application life cycle (by itself).<li>Can’t manage software updates for Windows 10 and apps (by itself).<li>Doesn’t provide antivirus and malware protection (by itself).<li>Has limited scaling to large numbers of users and devices.|
|
||||||
|Microsoft Endpoint Configuration Manager|<li> Configuration Manager is an on-premises solution that supports operating system management throughout the entire operating system life cycle <li>You can use Configuration Manager to deploy and upgrade Windows 10. In addition, you can manage Windows desktop and Microsoft Store apps and software updates as well as provide antivirus and antimalware protection. <br> Select this method when you: <li> Want to deploy Windows 10 to institution-owned devices that are domain joined (personal devices are typically not domain joined). <li>Have an existing AD DS infrastructure (or plan to deploy an AD DS infrastructure). <li>Typically deploy Windows 10 to on-premises devices. <br> The advantages of this method are that: <li>You can deploy Windows 10 operating systems.<li>You can manage (deploy) Windows desktop and Microsoft Store apps throughout entire application life cycle.<li>You can manage software updates for Windows 10 and apps.<li>You can manage antivirus and malware protection.<li>It scales to large number of users and devices. <br>The disadvantages of this method are that it:<li>Carries an extra cost for Microsoft Endpoint Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Can deploy Windows 10 only to domain-joined (institution-owned devices).<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).|
|
|Microsoft Configuration Manager|<li> Configuration Manager is an on-premises solution that supports operating system management throughout the entire operating system life cycle <li>You can use Configuration Manager to deploy and upgrade Windows 10. In addition, you can manage Windows desktop and Microsoft Store apps and software updates as well as provide antivirus and antimalware protection. <br> Select this method when you: <li> Want to deploy Windows 10 to institution-owned devices that are domain joined (personal devices are typically not domain joined). <li>Have an existing AD DS infrastructure (or plan to deploy an AD DS infrastructure). <li>Typically deploy Windows 10 to on-premises devices. <br> The advantages of this method are that: <li>You can deploy Windows 10 operating systems.<li>You can manage (deploy) Windows desktop and Microsoft Store apps throughout entire application life cycle.<li>You can manage software updates for Windows 10 and apps.<li>You can manage antivirus and malware protection.<li>It scales to large number of users and devices. <br>The disadvantages of this method are that it:<li>Carries an extra cost for Microsoft Configuration Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Can deploy Windows 10 only to domain-joined (institution-owned devices).<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).|
|
||||||
|
|
||||||
*Table 2. Deployment methods*
|
*Table 2. Deployment methods*
|
||||||
|
|
||||||
@ -226,7 +226,7 @@ Record the deployment methods you selected in Table 3.
|
|||||||
|Selection | Deployment method|
|
|Selection | Deployment method|
|
||||||
|--------- | -----------------|
|
|--------- | -----------------|
|
||||||
| |MDT by itself |
|
| |MDT by itself |
|
||||||
| |Microsoft Endpoint Manager and MDT|
|
| |Microsoft Configuration Manager and MDT|
|
||||||
|
|
||||||
*Table 3. Deployment methods selected*
|
*Table 3. Deployment methods selected*
|
||||||
|
|
||||||
@ -260,9 +260,9 @@ Use the information in Table 6 to determine which combination of app and update
|
|||||||
|
|
||||||
|Selection|Management method|
|
|Selection|Management method|
|
||||||
|--- |--- |
|
|--- |--- |
|
||||||
|Microsoft Endpoint Configuration Manager|Configuration Manager is an on-premises solution that allows you to specify configuration settings for Windows 10; previous versions of Windows; and other operating systems, such as iOS or Android, through integration with Intune.Configuration Manager supports application management throughout the entire application life cycle. You can deploy, upgrade, manage multiple versions, and retire applications by using Configuration Manager. You can also manage Windows desktop and Microsoft Store applications. Select this method when you:<li>Selected Configuration Manager to deploy Windows 10.<li>Want to manage institution-owned devices that are domain joined (personally owned devices are typically not domain joined).<li>Want to manage AD DS domain-joined devices.<li>Have an existing AD DS infrastructure.<li>Typically manage on-premises devices.<li>Want to deploy operating systems.<li>Want to provide application management for the entire application life cycle.<br>The advantages of this method are that:<li>You can deploy Windows 10 operating systems.<li>You can manage applications throughout the entire application life cycle.<li>You can manage software updates for Windows 10 and apps.<li>You can manage antivirus and malware protection.<li>It scales to large numbers of users and devices.<br>The disadvantages of this method are that it:<li>Carries an extra cost for Configuration Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Carries an extra cost for Windows Server licenses and the corresponding server hardware.<li>Can only manage domain-joined (institution-owned devices).<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).<li>Typically manages on-premises devices (unless devices through VPN or DirectAccess).|
|
|Microsoft Configuration Manager|Configuration Manager is an on-premises solution that allows you to specify configuration settings for Windows 10; previous versions of Windows; and other operating systems, such as iOS or Android, through integration with Intune.Configuration Manager supports application management throughout the entire application life cycle. You can deploy, upgrade, manage multiple versions, and retire applications by using Configuration Manager. You can also manage Windows desktop and Microsoft Store applications. Select this method when you:<li>Selected Configuration Manager to deploy Windows 10.<li>Want to manage institution-owned devices that are domain joined (personally owned devices are typically not domain joined).<li>Want to manage AD DS domain-joined devices.<li>Have an existing AD DS infrastructure.<li>Typically manage on-premises devices.<li>Want to deploy operating systems.<li>Want to provide application management for the entire application life cycle.<br>The advantages of this method are that:<li>You can deploy Windows 10 operating systems.<li>You can manage applications throughout the entire application life cycle.<li>You can manage software updates for Windows 10 and apps.<li>You can manage antivirus and malware protection.<li>It scales to large numbers of users and devices.<br>The disadvantages of this method are that it:<li>Carries an extra cost for Configuration Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Carries an extra cost for Windows Server licenses and the corresponding server hardware.<li>Can only manage domain-joined (institution-owned devices).<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).<li>Typically manages on-premises devices (unless devices through VPN or DirectAccess).|
|
||||||
|Intune|Intune is a cloud-based solution that allows you to manage apps and software updates for Windows 10, previous versions of Windows, and other operating systems (such as iOS or Android). Intune is a subscription-based cloud service that integrates with Office 365 and Azure AD.<br>Select this method when you:<li>Selected MDT only to deploy Windows 10.<li>Want to manage institution-owned and personal devices that aren't domain joined.<li>Want to manage Azure AD domain-joined devices.<li>Need to manage devices regardless of where they are (on or off premises).<li>Want to provide application management for the entire application life cycle.<br>The advantages of this method are that:<li>You can manage institution-owned and personal devices.<li>It doesn’t require that devices be domain joined.<li>It doesn’t require on-premises infrastructure.vIt can manage devices regardless of their location (on or off premises).<li>You can deploy keys to perform in-place Windows 10 upgrades (such as upgrading from Windows 10 Pro to Windows 10 Education edition).<br>The disadvantages of this method are that it:<li>Carries an extra cost for Intune subscription licenses.<li>can't deploy Windows 10 operating systems.|
|
|Intune|Intune is a cloud-based solution that allows you to manage apps and software updates for Windows 10, previous versions of Windows, and other operating systems (such as iOS or Android). Intune is a subscription-based cloud service that integrates with Office 365 and Azure AD.<br>Select this method when you:<li>Selected MDT only to deploy Windows 10.<li>Want to manage institution-owned and personal devices that aren't domain joined.<li>Want to manage Azure AD domain-joined devices.<li>Need to manage devices regardless of where they are (on or off premises).<li>Want to provide application management for the entire application life cycle.<br>The advantages of this method are that:<li>You can manage institution-owned and personal devices.<li>It doesn’t require that devices be domain joined.<li>It doesn’t require on-premises infrastructure.vIt can manage devices regardless of their location (on or off premises).<li>You can deploy keys to perform in-place Windows 10 upgrades (such as upgrading from Windows 10 Pro to Windows 10 Education edition).<br>The disadvantages of this method are that it:<li>Carries an extra cost for Intune subscription licenses.<li>can't deploy Windows 10 operating systems.|
|
||||||
|Microsoft Endpoint Manager and Intune (hybrid)|Configuration Manager and Intune together extend Configuration Manager from an on-premises management system for domain-joined devices to a solution that can manage devices regardless of their location and connectivity options. This hybrid option provides the benefits of both Configuration Manager and Intune.<br>Configuration Manager and Intune in the hybrid configuration allows you to support application management throughout the entire application life cycle. You can deploy, upgrade, manage multiple versions, and retire applications by using Configuration Manager, and you can manage Windows desktop and Microsoft Store applications for both institution-owned and personal devices. <br>Select this method when you:<li>Selected Microsoft Endpoint Manager to deploy Windows 10.<li>Want to manage institution-owned and personal devices (doesn't require that the device be domain joined).<li>Want to manage domain-joined devices.<li>Want to manage Azure AD domain-joined devices.<li>Have an existing AD DS infrastructure.<li>Want to manage devices regardless of their connectivity.vWant to deploy operating systems.<li>Want to provide application management for the entire application life cycle.<br>The advantages of this method are that:<li>You can deploy operating systems.<li>You can manage applications throughout the entire application life cycle.<li>You can scale to large numbers of users and devices.<li>You can support institution-owned and personal devices.<li>It doesn’t require that devices be domain joined.<li>It can manage devices regardless of their location (on or off premises).<br>The disadvantages of this method are that it:<li>Carries an extra cost for Configuration Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Carries an extra cost for Windows Server licenses and the corresponding server hardware.<li>Carries an extra cost for Intune subscription licenses.<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).|
|
|Microsoft Configuration Manager and Intune (hybrid)|Configuration Manager and Intune together extend Configuration Manager from an on-premises management system for domain-joined devices to a solution that can manage devices regardless of their location and connectivity options. This hybrid option provides the benefits of both Configuration Manager and Intune.<br><br>Configuration Manager and Intune in the hybrid configuration allows you to support application management throughout the entire application life cycle. You can deploy, upgrade, manage multiple versions, and retire applications by using Configuration Manager, and you can manage Windows desktop and Microsoft Store applications for both institution-owned and personal devices. <br><br>Select this method when you:<br><li>Selected Microsoft Configuration Manager to deploy Windows 10.<li>Want to manage institution-owned and personal devices (doesn't require that the device be domain joined).<li>Want to manage domain-joined devices.<li>Want to manage Azure AD domain-joined devices.<li>Have an existing AD DS infrastructure.<li>Want to manage devices regardless of their connectivity.vWant to deploy operating systems.<li>Want to provide application management for the entire application life cycle.<br><br>The advantages of this method are that:<li>You can deploy operating systems.<li>You can manage applications throughout the entire application life cycle.<li>You can scale to large numbers of users and devices.<li>You can support institution-owned and personal devices.<li>It doesn’t require that devices be domain joined.<li>It can manage devices regardless of their location (on or off premises).<br><br>The disadvantages of this method are that it:<li>Carries an extra cost for Configuration Manager server licenses (if the institution doesn't have Configuration Manager already).<li>Carries an extra cost for Windows Server licenses and the corresponding server hardware.<li>Carries an extra cost for Intune subscription licenses.<li>Requires an AD DS infrastructure (if the institution doesn't have AD DS already).|
|
||||||
|
|
||||||
*Table 6. App and update management products*
|
*Table 6. App and update management products*
|
||||||
|
|
||||||
@ -270,9 +270,9 @@ Record the app and update management methods that you selected in Table 7.
|
|||||||
|
|
||||||
|Selection | Management method|
|
|Selection | Management method|
|
||||||
|----------|------------------|
|
|----------|------------------|
|
||||||
| |Microsoft Endpoint Manager by itself|
|
| |Microsoft Configuration Manager by itself|
|
||||||
| |Intune by itself|
|
| |Intune by itself|
|
||||||
| |Microsoft Endpoint Manager and Intune (hybrid mode)|
|
| |Microsoft Configuration Manager and Intune (hybrid mode)|
|
||||||
|
|
||||||
*Table 7. App and update management methods selected*
|
*Table 7. App and update management methods selected*
|
||||||
|
|
||||||
@ -315,16 +315,16 @@ For more information about how to create a deployment share, see [Step 3-1: Crea
|
|||||||
### Install the Configuration Manager console
|
### Install the Configuration Manager console
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you selected Microsoft Endpoint Manager to deploy Windows 10 or manage your devices (in the [Select the deployment methods](#select-the-deployment-methods) and [Select the configuration setting management methods](#select-the-configuration-setting-management-methods) sections, respectively), perform the steps in this section. Otherwise, skip this section and continue to the next.
|
> If you selected Microsoft Configuration Manager to deploy Windows 10 or manage your devices (in the [Select the deployment methods](#select-the-deployment-methods) and [Select the configuration setting management methods](#select-the-configuration-setting-management-methods) sections, respectively), perform the steps in this section. Otherwise, skip this section and continue to the next.
|
||||||
|
|
||||||
You can use Configuration Manager to manage Windows 10 deployments, Windows desktop apps, Microsoft Store apps, and software updates. To manage Configuration Manager, you use the Configuration Manager console. You must install the Configuration Manager console on every device you use to manage Configuration Manager (specifically, the admin device). The Configuration Manager console is automatically installed when you install Configuration Manager primary site servers.
|
You can use Configuration Manager to manage Windows 10 deployments, Windows desktop apps, Microsoft Store apps, and software updates. To manage Configuration Manager, you use the Configuration Manager console. You must install the Configuration Manager console on every device you use to manage Configuration Manager (specifically, the admin device). The Configuration Manager console is automatically installed when you install Configuration Manager primary site servers.
|
||||||
|
|
||||||
For more information about how to install the Configuration Manager console, see [Install Microsoft Endpoint Manager consoles](/mem/configmgr/core/servers/deploy/install/installing-sites#bkmk_InstallConsole).
|
For more information about how to install the Configuration Manager console, see [Install Microsoft Configuration Manager consoles](/mem/configmgr/core/servers/deploy/install/installing-sites#bkmk_InstallConsole).
|
||||||
|
|
||||||
### Configure MDT integration with the Configuration Manager console
|
### Configure MDT integration with the Configuration Manager console
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you selected MDT only to deploy Windows 10 and your apps (and not Microsoft Endpoint Configuration Manager) in [Select the deployment methods](#select-the-deployment-methods), earlier in this article, then skip this section and continue to the next.
|
> If you selected MDT only to deploy Windows 10 and your apps (and not Microsoft Configuration Manager) in [Select the deployment methods](#select-the-deployment-methods), earlier in this article, then skip this section and continue to the next.
|
||||||
|
|
||||||
You can use MDT with Configuration Manager to make ZTI operating system deployment easier. To configure MDT integration with Configuration Manager, run the Configure ConfigMgr Integration Wizard. This wizard is installed when you install MDT.
|
You can use MDT with Configuration Manager to make ZTI operating system deployment easier. To configure MDT integration with Configuration Manager, run the Configure ConfigMgr Integration Wizard. This wizard is installed when you install MDT.
|
||||||
|
|
||||||
@ -841,7 +841,7 @@ At the end of this section, you should know the Windows 10 editions and processo
|
|||||||
|
|
||||||
## Prepare for deployment
|
## Prepare for deployment
|
||||||
|
|
||||||
Before you can deploy Windows 10 and your apps to devices, you need to prepare your MDT environment, Windows Deployment Services, and Microsoft Endpoint Manager (if you selected it to do operating system deployment in the [Select the deployment methods](#select-the-deployment-methods) section). In this section, you ensure that the deployment methods you selected in the [Select the deployment methods](#select-the-deployment-methods) section have the necessary Windows 10 editions and versions, Windows desktop apps, Microsoft Store apps, and device drivers.
|
Before you can deploy Windows 10 and your apps to devices, you need to prepare your MDT environment, Windows Deployment Services, and Microsoft Configuration Manager (if you selected it to do operating system deployment in the [Select the deployment methods](#select-the-deployment-methods) section). In this section, you ensure that the deployment methods you selected in the [Select the deployment methods](#select-the-deployment-methods) section have the necessary Windows 10 editions and versions, Windows desktop apps, Microsoft Store apps, and device drivers.
|
||||||
|
|
||||||
### Configure the MDT deployment share
|
### Configure the MDT deployment share
|
||||||
|
|
||||||
@ -851,17 +851,17 @@ The first step in preparing for Windows 10 deployment is to configure—that is,
|
|||||||
|--- |--- |
|
|--- |--- |
|
||||||
|1. Import operating systems|Import the operating systems that you selected in the [Select the operating systems](#select-the-operating-systems) section into the deployment share. For more information about how to import operating systems, see [Import Device Drivers into the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#ImportDeviceDriversintotheDeploymentWorkbench)|
|
|1. Import operating systems|Import the operating systems that you selected in the [Select the operating systems](#select-the-operating-systems) section into the deployment share. For more information about how to import operating systems, see [Import Device Drivers into the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#ImportDeviceDriversintotheDeploymentWorkbench)|
|
||||||
|2. Import device drivers|Device drivers allow Windows 10 to know a device’s hardware resources and connected hardware accessories. Without the proper device drivers, certain features may be unavailable. For example, without the proper audio driver, a device can't play sounds; without the proper camera driver, the device can't take photos or use video chat.<br>Import device drivers for each device in your institution. For more information about how to import device drivers, see [Import Device Drivers into the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#ImportDeviceDriversintotheDeploymentWorkbench)|
|
|2. Import device drivers|Device drivers allow Windows 10 to know a device’s hardware resources and connected hardware accessories. Without the proper device drivers, certain features may be unavailable. For example, without the proper audio driver, a device can't play sounds; without the proper camera driver, the device can't take photos or use video chat.<br>Import device drivers for each device in your institution. For more information about how to import device drivers, see [Import Device Drivers into the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#ImportDeviceDriversintotheDeploymentWorkbench)|
|
||||||
|3. Create MDT applications for Microsoft Store apps|Create an MDT application for each Microsoft Store app you want to deploy. You can deploy Microsoft Store apps by using sideloading, which allows you to use the **Add-AppxPackage** Windows PowerShell cmdlet to deploy the .appx files associated with the app (called provisioned apps). Use this method to deploy up to 24 apps to Windows 10.<br>Prior to sideloading the .appx files, obtain the Microsoft Store .appx files that you'll use to deploy (sideload) the apps in your provisioning package. For apps in Microsoft Store, you'll need to obtain the .appx files by performing one of the following tasks:<li>For offline-licensed apps, download the .appx files from the Microsoft Store for Business.<li>For apps that aren't offline licensed, obtain the .appx files from the app software vendor directly.<br> <br> If you are unable to obtain the .appx files from the app software vendor, then you or the students will need to install the apps on the student devices directly from Microsoft Store or Microsoft Store for Business.<br>If you've Intune or Microsoft Endpoint Configuration Manager, you can deploy Microsoft Store apps after you deploy Windows 10, as described in the [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune) and [Deploy and manage apps by using Microsoft Endpoint Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-endpoint-configuration-manager). This method provides granular deployment of Microsoft Store apps, and you can use it for ongoing management of Microsoft Store apps. This is the preferred method of deploying and managing Microsoft Store apps.<br>In addition, you must prepare your environment for sideloading Microsoft Store apps. For more information about how to:<li>Prepare your environment for sideloading, see [Try it out: sideload Microsoft Store apps](/previous-versions/windows/).<li>Create an MDT application, see [Create a New Application in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewApplicationintheDeploymentWorkbench).|
|
|3. Create MDT applications for Microsoft Store apps|Create an MDT application for each Microsoft Store app you want to deploy. You can deploy Microsoft Store apps by using sideloading, which allows you to use the **Add-AppxPackage** Windows PowerShell cmdlet to deploy the .appx files associated with the app (called provisioned apps). Use this method to deploy up to 24 apps to Windows 10.<br>Prior to sideloading the .appx files, obtain the Microsoft Store .appx files that you'll use to deploy (sideload) the apps in your provisioning package. For apps in Microsoft Store, you'll need to obtain the .appx files by performing one of the following tasks:<li>For offline-licensed apps, download the .appx files from the Microsoft Store for Business.<li>For apps that aren't offline licensed, obtain the .appx files from the app software vendor directly.<br> <br> If you are unable to obtain the .appx files from the app software vendor, then you or the students will need to install the apps on the student devices directly from Microsoft Store or Microsoft Store for Business.<br>If you've Intune or Microsoft Configuration Manager, you can deploy Microsoft Store apps after you deploy Windows 10, as described in the [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune) and [Deploy and manage apps by using Microsoft Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-configuration-manager). This method provides granular deployment of Microsoft Store apps, and you can use it for ongoing management of Microsoft Store apps. This is the preferred method of deploying and managing Microsoft Store apps.<br>In addition, you must prepare your environment for sideloading Microsoft Store apps. For more information about how to:<li>Prepare your environment for sideloading, see [Try it out: sideload Microsoft Store apps](/previous-versions/windows/).<li>Create an MDT application, see [Create a New Application in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewApplicationintheDeploymentWorkbench).|
|
||||||
|4. Create MDT applications for Windows desktop apps|You need to create an MDT application for each Windows desktop app you want to deploy. You can obtain the Windows desktop apps from any source, but ensure that you've sufficient licenses for them.<br>To help reduce the effort needed to deploy Microsoft Office 2016 desktop apps, use the Office Deployment Tool, as described in[Deploy Click-to-Run for Office 365 products by using the Office Deployment Tool](/deployoffice/deploy-microsoft-365-apps-local-source).<br> If you've Intune, you can [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune), as described in the Deploy and manage apps by using Intune section. This method provides granular deployment of Windows desktop apps, and you can use it for ongoing management of the apps.<br>This is the preferred method for deploying and managing Windows desktop apps.<br>**Note:** You can also deploy Windows desktop apps after you deploy Windows 10, as described in the [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune) <br>For more information about how to create an MDT application for Windows desktop apps, see [Create a New Application in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt).|
|
|4. Create MDT applications for Windows desktop apps|You need to create an MDT application for each Windows desktop app you want to deploy. You can obtain the Windows desktop apps from any source, but ensure that you've sufficient licenses for them.<br>To help reduce the effort needed to deploy Microsoft Office 2016 desktop apps, use the Office Deployment Tool, as described in[Deploy Click-to-Run for Office 365 products by using the Office Deployment Tool](/deployoffice/deploy-microsoft-365-apps-local-source).<br> If you've Intune, you can [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune), as described in the Deploy and manage apps by using Intune section. This method provides granular deployment of Windows desktop apps, and you can use it for ongoing management of the apps.<br>This is the preferred method for deploying and managing Windows desktop apps.<br>**Note:** You can also deploy Windows desktop apps after you deploy Windows 10, as described in the [Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune) <br>For more information about how to create an MDT application for Windows desktop apps, see [Create a New Application in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt).|
|
||||||
|5. Create task sequences|You must create separate task sequences for each Windows 10 edition, processor architecture, operating system upgrade process, and new operating system deployment process. Minimally, create a task sequence for each Windows 10 operating system you imported in step 1—for example, (1) if you want to deploy Windows 10 Education to new devices or refresh existing devices with a new deployment of Windows 10 Education, (2) if you want to upgrade existing devices running Windows 8.1 or Windows 7 to Windows 10 Education, or (3) if you want to run deployments and upgrades for both 32-bit and 64-bit versions of Windows 10. To do so, you must create task sequences that will:<li>Deploy 64-bit Windows 10 Education to devices.<li>Deploy 32-bit Windows 10 Education to devices.<li>Upgrade existing devices to 64-bit Windows 10 Education.<li>Upgrade existing devices to 32-bit Windows 10 Education.<br> <br>Again, you'll create the task sequences based on the operating systems that you imported in step 1. For more information about how to create a task sequence, see [Create a New Task Sequence in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewTaskSequenceintheDeploymentWorkbench).|
|
|5. Create task sequences|You must create separate task sequences for each Windows 10 edition, processor architecture, operating system upgrade process, and new operating system deployment process. Minimally, create a task sequence for each Windows 10 operating system you imported in step 1—for example, (1) if you want to deploy Windows 10 Education to new devices or refresh existing devices with a new deployment of Windows 10 Education, (2) if you want to upgrade existing devices running Windows 8.1 or Windows 7 to Windows 10 Education, or (3) if you want to run deployments and upgrades for both 32-bit and 64-bit versions of Windows 10. To do so, you must create task sequences that will:<li>Deploy 64-bit Windows 10 Education to devices.<li>Deploy 32-bit Windows 10 Education to devices.<li>Upgrade existing devices to 64-bit Windows 10 Education.<li>Upgrade existing devices to 32-bit Windows 10 Education.<br> <br>Again, you'll create the task sequences based on the operating systems that you imported in step 1. For more information about how to create a task sequence, see [Create a New Task Sequence in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewTaskSequenceintheDeploymentWorkbench).|
|
||||||
|6. Update the deployment share|Updating a deployment share generates the MDT boot images you use to initiate the Windows 10 deployment process. You can configure the process to create 32-bit and 64-bit versions of the .iso and .wim files you can use to create bootable media or in Windows Deployment Services.<br>For more information about how to update a deployment share, see [Update a Deployment Share in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#UpdateaDeploymentShareintheDeploymentWorkbench).|
|
|6. Update the deployment share|Updating a deployment share generates the MDT boot images you use to initiate the Windows 10 deployment process. You can configure the process to create 32-bit and 64-bit versions of the .iso and .wim files you can use to create bootable media or in Windows Deployment Services.<br>For more information about how to update a deployment share, see [Update a Deployment Share in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#UpdateaDeploymentShareintheDeploymentWorkbench).|
|
||||||
|
|
||||||
*Table 16. Tasks to configure the MDT deployment share*
|
*Table 16. Tasks to configure the MDT deployment share*
|
||||||
|
|
||||||
### Configure Microsoft Endpoint Configuration Manager
|
### Configure Microsoft Configuration Manager
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you've already configured your Microsoft Endpoint Manager infrastructure to support the operating system deployment feature or if you selected to deploy Windows 10 by using MDT only, then skip this section and continue to the next section.
|
> If you've already configured your Microsoft Configuration Manager infrastructure to support the operating system deployment feature or if you selected to deploy Windows 10 by using MDT only, then skip this section and continue to the next section.
|
||||||
|
|
||||||
Before you can use Configuration Manager to deploy Windows 10 and manage your apps and devices, you must configure Configuration Manager to support the operating system deployment feature. If you don’t have an existing Configuration Manager infrastructure, you'll need to deploy a new infrastructure.
|
Before you can use Configuration Manager to deploy Windows 10 and manage your apps and devices, you must configure Configuration Manager to support the operating system deployment feature. If you don’t have an existing Configuration Manager infrastructure, you'll need to deploy a new infrastructure.
|
||||||
|
|
||||||
@ -871,21 +871,21 @@ Deploying a new Configuration Manager infrastructure is beyond the scope of this
|
|||||||
* [Start using Configuration Manager](/mem/configmgr/core/servers/deploy/start-using)
|
* [Start using Configuration Manager](/mem/configmgr/core/servers/deploy/start-using)
|
||||||
|
|
||||||
|
|
||||||
#### To configure an existing Microsoft Endpoint Manager infrastructure for operating system deployment
|
#### To configure an existing Microsoft Configuration Manager infrastructure for operating system deployment
|
||||||
|
|
||||||
1. Perform any necessary infrastructure remediation.
|
1. Perform any necessary infrastructure remediation.
|
||||||
|
|
||||||
Ensure that your existing infrastructure can support the operating system deployment feature. For more information, see [Infrastructure requirements for operating system deployment in Microsoft Endpoint Configuration Manager](/mem/configmgr/osd/plan-design/infrastructure-requirements-for-operating-system-deployment).
|
Ensure that your existing infrastructure can support the operating system deployment feature. For more information, see [Infrastructure requirements for operating system deployment in Microsoft Configuration Manager](/mem/configmgr/osd/plan-design/infrastructure-requirements-for-operating-system-deployment).
|
||||||
2. Add the Windows PE boot images, Windows 10 operating systems, and other content.
|
2. Add the Windows PE boot images, Windows 10 operating systems, and other content.
|
||||||
|
|
||||||
You need to add the Windows PE boot images, Windows 10 operating system images, and other deployment content that you'll use to deploy Windows 10 with ZTI. To add this content, use the Create MDT Task Sequence Wizard.
|
You need to add the Windows PE boot images, Windows 10 operating system images, and other deployment content that you'll use to deploy Windows 10 with ZTI. To add this content, use the Create MDT Task Sequence Wizard.
|
||||||
|
|
||||||
You can add this content by using Microsoft Endpoint Manager only (without MDT), but the Create MDT Task Sequence Wizard is the preferred method because the wizard prompts you for all the deployment content you need for a task sequence and provides a much more intuitive user experience. For more information, see [Create ZTI Task Sequences Using the Create MDT Task Sequence Wizard in Configuration Manager](/mem/configmgr/mdt/use-the-mdt#CreateZTITaskSequencesUsingtheCreateMDTTaskSequenceWizardinConfigurationManager).
|
You can add this content by using Microsoft Configuration Manager only (without MDT), but the Create MDT Task Sequence Wizard is the preferred method because the wizard prompts you for all the deployment content you need for a task sequence and provides a much more intuitive user experience. For more information, see [Create ZTI Task Sequences Using the Create MDT Task Sequence Wizard in Configuration Manager](/mem/configmgr/mdt/use-the-mdt#CreateZTITaskSequencesUsingtheCreateMDTTaskSequenceWizardinConfigurationManager).
|
||||||
3. Add device drivers.
|
3. Add device drivers.
|
||||||
|
|
||||||
You must add device drivers for the different device types in your district. For example, if you've a mixture of Surface, HP Stream, Dell Inspiron, and Lenovo Yoga devices, then you must have the device drivers for each device.
|
You must add device drivers for the different device types in your district. For example, if you've a mixture of Surface, HP Stream, Dell Inspiron, and Lenovo Yoga devices, then you must have the device drivers for each device.
|
||||||
|
|
||||||
Create a Microsoft Endpoint Manager driver package for each device type in your district. For more information, see [Manage drivers in Configuration Manager](/mem/configmgr/osd/get-started/manage-drivers).
|
Create a Microsoft Configuration Manager driver package for each device type in your district. For more information, see [Manage drivers in Configuration Manager](/mem/configmgr/osd/get-started/manage-drivers).
|
||||||
4. Add Windows apps.
|
4. Add Windows apps.
|
||||||
|
|
||||||
Install the Windows apps (Windows desktop and Microsoft Store apps) that you want to deploy after the task sequence deploys your customized image (a thick, reference image that includes Windows 10 and your core Windows desktop apps). These apps are in addition to the apps included in your reference image. You can only deploy Microsoft Store apps after you deploy Windows 10 because you can't capture Microsoft Store apps in a reference image. Microsoft Store apps target users, not devices.
|
Install the Windows apps (Windows desktop and Microsoft Store apps) that you want to deploy after the task sequence deploys your customized image (a thick, reference image that includes Windows 10 and your core Windows desktop apps). These apps are in addition to the apps included in your reference image. You can only deploy Microsoft Store apps after you deploy Windows 10 because you can't capture Microsoft Store apps in a reference image. Microsoft Store apps target users, not devices.
|
||||||
@ -914,14 +914,14 @@ You can use Windows Deployment Services in conjunction with MDT to automatically
|
|||||||
|
|
||||||
For more information about how to perform this step, see [Add LTI Boot Images to Windows Deployment Services](/mem/configmgr/mdt/use-the-mdt#AddLTIBootImagestoWindowsDeploymentServices).
|
For more information about how to perform this step, see [Add LTI Boot Images to Windows Deployment Services](/mem/configmgr/mdt/use-the-mdt#AddLTIBootImagestoWindowsDeploymentServices).
|
||||||
|
|
||||||
### Configure Windows Deployment Services for Microsoft Endpoint Configuration Manager
|
### Configure Windows Deployment Services for Microsoft Configuration Manager
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you've already configured your Microsoft Endpoint Manager infrastructure to support PXE boot or selected to deploy Windows 10 by using MDT only, then skip this section and continue to the next.
|
> If you've already configured your Microsoft Configuration Manager infrastructure to support PXE boot or selected to deploy Windows 10 by using MDT only, then skip this section and continue to the next.
|
||||||
|
|
||||||
You can use Windows Deployment Services in conjunction with Configuration Manager to automatically initiate boot images on target devices. These boot images are Windows PE images that you use to boot the target devices, and then initiate Windows 10, app, and device driver deployment.
|
You can use Windows Deployment Services in conjunction with Configuration Manager to automatically initiate boot images on target devices. These boot images are Windows PE images that you use to boot the target devices, and then initiate Windows 10, app, and device driver deployment.
|
||||||
|
|
||||||
#### To configure Windows Deployment Services for Microsoft Endpoint Configuration Manager
|
#### To configure Windows Deployment Services for Microsoft Configuration Manager
|
||||||
|
|
||||||
1. Set up and configure Windows Deployment Services.
|
1. Set up and configure Windows Deployment Services.
|
||||||
|
|
||||||
@ -944,7 +944,7 @@ You can use Windows Deployment Services in conjunction with Configuration Manage
|
|||||||
|
|
||||||
#### Summary
|
#### Summary
|
||||||
|
|
||||||
Your MDT deployment share and Microsoft Endpoint Manager are now ready for deployment. Windows Deployment Services is ready to initiate the LTI or ZTI deployment process. You've set up and configured Windows Deployment Services for MDT and for Configuration Manager. You've also ensured that your boot images are available to Windows Deployment Services (for LTI) or the distribution points (for ZTI and Configuration Manager). Now, you’re ready to capture the reference images for the different devices you've in your district.
|
Your MDT deployment share and Microsoft Configuration Manager are now ready for deployment. Windows Deployment Services is ready to initiate the LTI or ZTI deployment process. You've set up and configured Windows Deployment Services for MDT and for Configuration Manager. You've also ensured that your boot images are available to Windows Deployment Services (for LTI) or the distribution points (for ZTI and Configuration Manager). Now, you’re ready to capture the reference images for the different devices you've in your district.
|
||||||
|
|
||||||
## Capture the reference image
|
## Capture the reference image
|
||||||
|
|
||||||
@ -1015,7 +1015,7 @@ Both the Deployment Workbench and the Configuration Manager console have wizards
|
|||||||
For more information about how to import the reference image into:
|
For more information about how to import the reference image into:
|
||||||
|
|
||||||
* An MDT deployment share, see [Import a Previously Captured Image of a Reference Computer](/mem/configmgr/mdt/use-the-mdt#ImportaPreviouslyCapturedImageofaReferenceComputer).
|
* An MDT deployment share, see [Import a Previously Captured Image of a Reference Computer](/mem/configmgr/mdt/use-the-mdt#ImportaPreviouslyCapturedImageofaReferenceComputer).
|
||||||
* Microsoft Endpoint Configuration Manager, see [Manage operating system images with Microsoft Endpoint Configuration Manager](/mem/configmgr/osd/get-started/manage-operating-system-images) and [Customize operating system images with Microsoft Endpoint Configuration Manager](/mem/configmgr/osd/get-started/customize-operating-system-images).
|
* Microsoft Configuration Manager, see [Manage operating system images with Microsoft Configuration Manager](/mem/configmgr/osd/get-started/manage-operating-system-images) and [Customize operating system images with Microsoft Configuration Manager](/mem/configmgr/osd/get-started/customize-operating-system-images).
|
||||||
|
|
||||||
### Create a task sequence to deploy the reference image
|
### Create a task sequence to deploy the reference image
|
||||||
|
|
||||||
@ -1026,10 +1026,10 @@ As you might expect, both the Deployment Workbench and the Configuration Manager
|
|||||||
For more information about how to create a task sequence in the:
|
For more information about how to create a task sequence in the:
|
||||||
|
|
||||||
* Deployment Workbench for a deployment share, see [Create a New Task Sequence in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewTaskSequenceintheDeploymentWorkbench).
|
* Deployment Workbench for a deployment share, see [Create a New Task Sequence in the Deployment Workbench](/mem/configmgr/mdt/use-the-mdt#CreateaNewTaskSequenceintheDeploymentWorkbench).
|
||||||
* Configuration Manager console, see [Create a task sequence to install an operating system in Microsoft Endpoint Configuration Manager](/mem/configmgr/osd/deploy-use/create-a-task-sequence-to-install-an-operating-system).
|
* Configuration Manager console, see [Create a task sequence to install an operating system in Microsoft Configuration Manager](/mem/configmgr/osd/deploy-use/create-a-task-sequence-to-install-an-operating-system).
|
||||||
|
|
||||||
#### Summary
|
#### Summary
|
||||||
In this section, you customized the MDT deployment share to deploy Windows 10 and desktop apps to one or more reference devices by creating and customizing MDT applications, device drivers, and applications. Next, you ran the task sequence, which deploys Windows 10, deploys your apps, deploys the appropriate device drivers, and captures an image of the reference device. Then, you imported the captured reference image into a deployment share or Microsoft Endpoint Configuration Manager. Finally, you created a task sequence to deploy your captured reference image to faculty and student devices. At this point in the process, you’re ready to deploy Windows 10 and your apps to your devices.
|
In this section, you customized the MDT deployment share to deploy Windows 10 and desktop apps to one or more reference devices by creating and customizing MDT applications, device drivers, and applications. Next, you ran the task sequence, which deploys Windows 10, deploys your apps, deploys the appropriate device drivers, and captures an image of the reference device. Then, you imported the captured reference image into a deployment share or Microsoft Configuration Manager. Finally, you created a task sequence to deploy your captured reference image to faculty and student devices. At this point in the process, you’re ready to deploy Windows 10 and your apps to your devices.
|
||||||
|
|
||||||
## Prepare for device management
|
## Prepare for device management
|
||||||
|
|
||||||
@ -1095,7 +1095,7 @@ For more information about Intune, see [Microsoft Intune Documentation](/intune/
|
|||||||
|
|
||||||
### Deploy and manage apps by using Intune
|
### Deploy and manage apps by using Intune
|
||||||
|
|
||||||
If you selected to deploy and manage apps by using Microsoft Endpoint Manager and Intune in a hybrid configuration, then skip this section and continue to the [Deploy and manage apps by using Microsoft Endpoint Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-endpoint-configuration-manager) section.
|
If you selected to deploy and manage apps by using Microsoft Configuration Manager and Intune in a hybrid configuration, then skip this section and continue to the [Deploy and manage apps by using Microsoft Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-configuration-manager) section.
|
||||||
|
|
||||||
You can use Intune to deploy Microsoft Store and Windows desktop apps. Intune provides improved control over which users receive specific apps. In addition, Intune allows you to deploy apps to companion devices (such as iOS or Android devices). Finally, Intune helps you manage app security and features, such as mobile application management policies that let you manage apps on devices that aren't enrolled in Intune or that another solution manages.
|
You can use Intune to deploy Microsoft Store and Windows desktop apps. Intune provides improved control over which users receive specific apps. In addition, Intune allows you to deploy apps to companion devices (such as iOS or Android devices). Finally, Intune helps you manage app security and features, such as mobile application management policies that let you manage apps on devices that aren't enrolled in Intune or that another solution manages.
|
||||||
|
|
||||||
@ -1106,9 +1106,9 @@ For more information about how to configure Intune to manage your apps, see the
|
|||||||
- [Protect apps and data with Microsoft Intune](/mem/intune/apps/app-protection-policy)
|
- [Protect apps and data with Microsoft Intune](/mem/intune/apps/app-protection-policy)
|
||||||
- [Help protect your data with full or selective wipe using Microsoft Intune](/mem/intune/remote-actions/devices-wipe)
|
- [Help protect your data with full or selective wipe using Microsoft Intune](/mem/intune/remote-actions/devices-wipe)
|
||||||
|
|
||||||
### Deploy and manage apps by using Microsoft Endpoint Configuration Manager
|
### Deploy and manage apps by using Microsoft Configuration Manager
|
||||||
|
|
||||||
You can use Microsoft Endpoint Manager to deploy Microsoft Store and Windows desktop apps. Configuration Manager allows you to create a Configuration Manager application that you can use to deploy apps to different devices (such as Windows 10 desktop, iOS, or Android devices) by using *deployment types*. You can think of a Configuration Manager application as a box. You can think of deployment types as one or more sets of installation files and installation instructions within that box.
|
You can use Microsoft Configuration Manager to deploy Microsoft Store and Windows desktop apps. Configuration Manager allows you to create a Configuration Manager application that you can use to deploy apps to different devices (such as Windows 10 desktop, iOS, or Android devices) by using *deployment types*. You can think of a Configuration Manager application as a box. You can think of deployment types as one or more sets of installation files and installation instructions within that box.
|
||||||
|
|
||||||
For example, you could create a Skype application that contains a deployment type for Windows 10 desktop, iOS, and Android. You can deploy the one application to multiple device types.
|
For example, you could create a Skype application that contains a deployment type for Windows 10 desktop, iOS, and Android. You can deploy the one application to multiple device types.
|
||||||
|
|
||||||
@ -1121,7 +1121,7 @@ For more information about how to configure Configuration Manager to deploy and
|
|||||||
|
|
||||||
### Manage updates by using Intune
|
### Manage updates by using Intune
|
||||||
|
|
||||||
If you selected to manage updates by using Configuration Manager and Intune in a hybrid configuration, then skip this section and continue to the [Manage updates by using Microsoft Endpoint Configuration Manager](#manage-updates-by-using-microsoft-endpoint-configuration-manager) section.
|
If you selected to manage updates by using Configuration Manager and Intune in a hybrid configuration, then skip this section and continue to the [Manage updates by using Microsoft Configuration Manager](#manage-updates-by-using-microsoft-configuration-manager) section.
|
||||||
|
|
||||||
To help ensure that your users have the most current features and security protection, keep Windows 10 and your apps current with updates. To configure Windows 10 and app updates, use the **Updates** workspace in Intune.
|
To help ensure that your users have the most current features and security protection, keep Windows 10 and your apps current with updates. To configure Windows 10 and app updates, use the **Updates** workspace in Intune.
|
||||||
|
|
||||||
@ -1133,7 +1133,7 @@ For more information about how to configure Intune to manage updates and malware
|
|||||||
- [Keep Windows PCs up to date with software updates in Microsoft Intune](/mem/intune/protect/windows-update-for-business-configure)
|
- [Keep Windows PCs up to date with software updates in Microsoft Intune](/mem/intune/protect/windows-update-for-business-configure)
|
||||||
- [Help secure Windows PCs with Endpoint Protection for Microsoft Intune](/mem/intune/protect/endpoint-protection-configure)
|
- [Help secure Windows PCs with Endpoint Protection for Microsoft Intune](/mem/intune/protect/endpoint-protection-configure)
|
||||||
|
|
||||||
### Manage updates by using Microsoft Endpoint Configuration Manager
|
### Manage updates by using Microsoft Configuration Manager
|
||||||
|
|
||||||
To ensure that your users have the most current features and security protection, use the software updates feature in Configuration Manager to manage updates. The software updates feature works in conjunction with WSUS to manage updates for Windows 10 devices.
|
To ensure that your users have the most current features and security protection, use the software updates feature in Configuration Manager to manage updates. The software updates feature works in conjunction with WSUS to manage updates for Windows 10 devices.
|
||||||
|
|
||||||
@ -1146,7 +1146,7 @@ For more information about how to configure Configuration Manager to manage Wind
|
|||||||
|
|
||||||
#### Summary
|
#### Summary
|
||||||
|
|
||||||
In this section, you prepared your institution for device management. You identified the configuration settings that you want to use to manage your users and devices. You configured Group Policy or Intune to manage these configuration settings. You configured Intune or Microsoft Endpoint Manager to manage your apps. Finally, you configured Intune or Microsoft Endpoint Manager to manage software updates for Windows 10 and your apps.
|
In this section, you prepared your institution for device management. You identified the configuration settings that you want to use to manage your users and devices. You configured Group Policy or Intune to manage these configuration settings. You configured Intune or Microsoft Configuration Manager to manage your apps. Finally, you configured Intune or Microsoft Configuration Manager to manage software updates for Windows 10 and your apps.
|
||||||
|
|
||||||
## Deploy Windows 10 to devices
|
## Deploy Windows 10 to devices
|
||||||
|
|
||||||
@ -1159,7 +1159,7 @@ Prior to deployment of Windows 10, complete the tasks in Table 18. Most of these
|
|||||||
| | Task |
|
| | Task |
|
||||||
|:---|:---|
|
|:---|:---|
|
||||||
|**1.** |Ensure that the target devices have sufficient system resources to run Windows 10.|
|
|**1.** |Ensure that the target devices have sufficient system resources to run Windows 10.|
|
||||||
|**2.** |Identify the necessary devices drivers, and then import them into the MDT deployment share or Microsoft Endpoint Configuration Manager.|
|
|**2.** |Identify the necessary devices drivers, and then import them into the MDT deployment share or Microsoft Configuration Manager.|
|
||||||
|**3.** |For each Microsoft Store and Windows desktop app, create an MDT application or Configuration Manager application.|
|
|**3.** |For each Microsoft Store and Windows desktop app, create an MDT application or Configuration Manager application.|
|
||||||
|**4.** |Notify the students and faculty about the deployment.|
|
|**4.** |Notify the students and faculty about the deployment.|
|
||||||
|
|
||||||
@ -1243,11 +1243,11 @@ Table 19 lists the school and individual classroom maintenance tasks, the resour
|
|||||||
|Verify that Windows Update is active and current with operating system and software updates.<br>For more information about completing this task when you have:<li>Intune, see [Keep Windows PCs up to date with software updates in Microsoft Intune](/mem/intune/protect/windows-update-for-business-configure)<li>Group Policy, see [Windows Update for Business](/windows/deployment/update/waas-manage-updates-wufb).<li>WSUS, see [Windows Server Update Services](/windows/deployment/deploy-whats-new).<br>Neither Intune, Group Policy, nor WSUS, see "Install, upgrade, & activate" in Windows 10 help.|✔️|✔️|✔️|
|
|Verify that Windows Update is active and current with operating system and software updates.<br>For more information about completing this task when you have:<li>Intune, see [Keep Windows PCs up to date with software updates in Microsoft Intune](/mem/intune/protect/windows-update-for-business-configure)<li>Group Policy, see [Windows Update for Business](/windows/deployment/update/waas-manage-updates-wufb).<li>WSUS, see [Windows Server Update Services](/windows/deployment/deploy-whats-new).<br>Neither Intune, Group Policy, nor WSUS, see "Install, upgrade, & activate" in Windows 10 help.|✔️|✔️|✔️|
|
||||||
|Verify that Windows Defender is active and current with malware Security intelligence.<br>For more information about completing this task, see [Turn Windows Defender on or off](/mem/intune/user-help/turn-on-defender-windows) and [Updating Windows Defender](/mem/intune/user-help/turn-on-defender-windows).|✔️|✔️|✔️|
|
|Verify that Windows Defender is active and current with malware Security intelligence.<br>For more information about completing this task, see [Turn Windows Defender on or off](/mem/intune/user-help/turn-on-defender-windows) and [Updating Windows Defender](/mem/intune/user-help/turn-on-defender-windows).|✔️|✔️|✔️|
|
||||||
|Verify that Windows Defender has run a scan in the past week and that no viruses or malware were found.<br>For more information about completing this task, see the “How do I find and remove a virus?” topic in [Protect my PC from viruses](https://support.microsoft.com/help/17228/windows-protect-my-pc-from-viruses).|✔️|✔️|✔️|
|
|Verify that Windows Defender has run a scan in the past week and that no viruses or malware were found.<br>For more information about completing this task, see the “How do I find and remove a virus?” topic in [Protect my PC from viruses](https://support.microsoft.com/help/17228/windows-protect-my-pc-from-viruses).|✔️|✔️|✔️|
|
||||||
|Download and approve updates for Windows 10, apps, device driver, and other software.<br>For more information, see:<li>[Manage updates by using Intune](#manage-updates-by-using-intune)<li>[Manage updates by using Microsoft Endpoint Configuration Manager](#manage-updates-by-using-microsoft-endpoint-configuration-manager)|✔️|✔️|✔️|
|
|Download and approve updates for Windows 10, apps, device driver, and other software.<br>For more information, see:<li>[Manage updates by using Intune](#manage-updates-by-using-intune)<li>[Manage updates by using Microsoft Configuration Manager](#manage-updates-by-using-microsoft-configuration-manager)|✔️|✔️|✔️|
|
||||||
|Verify that you’re using the appropriate Windows 10 servicing options for updates and upgrades (such as selecting whether you want to use Current Branch or Current Branch for Business).<br>For more information about Windows 10 servicing options for updates and upgrades, see [Windows 10 servicing options](/windows/deployment/update/).||✔️|✔️|
|
|Verify that you’re using the appropriate Windows 10 servicing options for updates and upgrades (such as selecting whether you want to use Current Branch or Current Branch for Business).<br>For more information about Windows 10 servicing options for updates and upgrades, see [Windows 10 servicing options](/windows/deployment/update/).||✔️|✔️|
|
||||||
|Refresh the operating system and apps on devices.<br>For more information about completing this task, see the following resources:<li>[Prepare for deployment](#prepare-for-deployment)<li>[Capture the reference image](#capture-the-reference-image)<li>[Deploy Windows 10 to devices](#deploy-windows-10-to-devices)||✔️|✔️|
|
|Refresh the operating system and apps on devices.<br>For more information about completing this task, see the following resources:<li>[Prepare for deployment](#prepare-for-deployment)<li>[Capture the reference image](#capture-the-reference-image)<li>[Deploy Windows 10 to devices](#deploy-windows-10-to-devices)||✔️|✔️|
|
||||||
|Install any new Windows desktop apps, or update any Windows desktop apps used in the curriculum.<br>For more information, see:<li>[Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune)<li>[Deploy and manage apps by using Microsoft Endpoint Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-endpoint-configuration-manager)||✔️|✔️|
|
|Install any new Windows desktop apps, or update any Windows desktop apps used in the curriculum.<br>For more information, see:<li>[Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune)<li>[Deploy and manage apps by using Microsoft Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-configuration-manager)||✔️|✔️|
|
||||||
|Install new or update existing Microsoft Store apps used in the curriculum.<br>Microsoft Store apps are automatically updated from Microsoft Store. The menu bar in the Microsoft Store app shows whether any Microsoft Store app updates are available for download.<br>You can also deploy Microsoft Store apps directly to devices by using Intune, Microsoft Endpoint Configuration Manager, or both in a hybrid configuration. <br>For more information, see:<li>[Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune)<li>[Deploy and manage apps by using Microsoft Endpoint Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-endpoint-configuration-manager)||✔️|✔️|
|
|Install new or update existing Microsoft Store apps used in the curriculum.<br>Microsoft Store apps are automatically updated from Microsoft Store. The menu bar in the Microsoft Store app shows whether any Microsoft Store app updates are available for download.<br>You can also deploy Microsoft Store apps directly to devices by using Intune, Microsoft Configuration Manager, or both in a hybrid configuration. <br>For more information, see:<li>[Deploy and manage apps by using Intune](#deploy-and-manage-apps-by-using-intune)<li>[Deploy and manage apps by using Microsoft Configuration Manager](#deploy-and-manage-apps-by-using-microsoft-configuration-manager)||✔️|✔️|
|
||||||
|Remove unnecessary user accounts (and corresponding licenses) from AD DS and Office 365 (if you've an on-premises AD DS infrastructure).<br>For more information about how to:<li>Remove unnecessary user accounts, see [Active Directory Administrative Center](/windows-server/identity/ad-ds/get-started/adac/active-directory-administrative-center) <li>Remove licenses, see [Add users and assign licenses](/microsoft-365/admin/add-users/add-users)||✔️|✔️|
|
|Remove unnecessary user accounts (and corresponding licenses) from AD DS and Office 365 (if you've an on-premises AD DS infrastructure).<br>For more information about how to:<li>Remove unnecessary user accounts, see [Active Directory Administrative Center](/windows-server/identity/ad-ds/get-started/adac/active-directory-administrative-center) <li>Remove licenses, see [Add users and assign licenses](/microsoft-365/admin/add-users/add-users)||✔️|✔️|
|
||||||
|Add new accounts (and corresponding licenses) to AD DS (if you've an on-premises AD DS infrastructure).<br>For more information about how to:<li>Add user accounts, see [Bulk-import user and group accounts into AD DS](#bulk-import-user-and-group-accounts-into-ad-ds)<li>Assign licenses, see [Add users and assign licenses](/microsoft-365/admin/add-users/add-users)||✔️|✔️|
|
|Add new accounts (and corresponding licenses) to AD DS (if you've an on-premises AD DS infrastructure).<br>For more information about how to:<li>Add user accounts, see [Bulk-import user and group accounts into AD DS](#bulk-import-user-and-group-accounts-into-ad-ds)<li>Assign licenses, see [Add users and assign licenses](/microsoft-365/admin/add-users/add-users)||✔️|✔️|
|
||||||
|Remove unnecessary user accounts (and corresponding licenses) from Office 365 (if you don't have an on-premises AD DS infrastructure).<br>For more information about how to:<li>Remove unnecessary user accounts, see [Delete or restore users](/microsoft-365/admin/add-users/delete-a-user)<li> Remove licenses, [Assign or remove licenses for Microsoft 365](/microsoft-365/admin/add-users/add-users).||✔️|✔️|
|
|Remove unnecessary user accounts (and corresponding licenses) from Office 365 (if you don't have an on-premises AD DS infrastructure).<br>For more information about how to:<li>Remove unnecessary user accounts, see [Delete or restore users](/microsoft-365/admin/add-users/delete-a-user)<li> Remove licenses, [Assign or remove licenses for Microsoft 365](/microsoft-365/admin/add-users/add-users).||✔️|✔️|
|
||||||
|
@ -79,13 +79,13 @@ Now that you've the plan (blueprint) for your classroom, you’re ready to learn
|
|||||||
|
|
||||||
The primary tool you'll use to deploy Windows 10 in your school is MDT, which uses Windows ADK components to make deployment easier. You could just use the Windows ADK to perform your deployment, but MDT simplifies the process by providing an intuitive, wizard-driven user interface (UI).
|
The primary tool you'll use to deploy Windows 10 in your school is MDT, which uses Windows ADK components to make deployment easier. You could just use the Windows ADK to perform your deployment, but MDT simplifies the process by providing an intuitive, wizard-driven user interface (UI).
|
||||||
|
|
||||||
You can use MDT as a stand-alone tool or integrate it with Microsoft Endpoint Configuration Manager. As a stand-alone tool, MDT performs Lite Touch Installation (LTI) deployments—deployments that require minimal infrastructure and allow you to control the level of automation. When integrated with Configuration Manager, MDT performs Zero Touch Installation (ZTI) deployments, which require more infrastructure (such as Configuration Manager) but result in fully automated deployments.
|
You can use MDT as a stand-alone tool or integrate it with Microsoft Configuration Manager. As a stand-alone tool, MDT performs Lite Touch Installation (LTI) deployments—deployments that require minimal infrastructure and allow you to control the level of automation. When integrated with Configuration Manager, MDT performs Zero Touch Installation (ZTI) deployments, which require more infrastructure (such as Configuration Manager) but result in fully automated deployments.
|
||||||
|
|
||||||
MDT includes the Deployment Workbench—a console from which you can manage the deployment of Windows 10 and your apps. You configure the deployment process in the Deployment Workbench, including the management of operating systems, device drivers, apps, and migration of user settings on existing devices.
|
MDT includes the Deployment Workbench—a console from which you can manage the deployment of Windows 10 and your apps. You configure the deployment process in the Deployment Workbench, including the management of operating systems, device drivers, apps, and migration of user settings on existing devices.
|
||||||
|
|
||||||
LTI performs deployment from a *deployment share*—a network-shared folder on the device where you installed MDT. You can perform over-the-network deployments from the deployment share or perform deployments from a local copy of the deployment share on a USB drive or DVD. You'll learn more about MDT in the [Prepare the admin device](#prepare-the-admin-device) section.
|
LTI performs deployment from a *deployment share*—a network-shared folder on the device where you installed MDT. You can perform over-the-network deployments from the deployment share or perform deployments from a local copy of the deployment share on a USB drive or DVD. You'll learn more about MDT in the [Prepare the admin device](#prepare-the-admin-device) section.
|
||||||
|
|
||||||
The focus of MDT is deployment, so you also need tools that help you manage your Windows 10 devices and apps. You can manage Windows 10 devices and apps with [Microsoft Endpoint Manager](/mem/), the Compliance Management feature in Office 365, or Group Policy in AD DS. You can use any combination of these tools based on your school requirements.
|
The focus of MDT is deployment, so you also need tools that help you manage your Windows 10 devices and apps. You can manage Windows 10 devices and apps with [Microsoft Intune](/mem/intune/fundamentals/what-is-intune), [Configuration Manager](/mem/configmgr/core/understand/introduction), the Compliance Management feature in Office 365, or Group Policy in AD DS. You can use any combination of these tools based on your school requirements.
|
||||||
|
|
||||||
The configuration process requires the following devices:
|
The configuration process requires the following devices:
|
||||||
|
|
||||||
|
@ -1,144 +0,0 @@
|
|||||||
---
|
|
||||||
title: Education scenarios Microsoft Store for Education
|
|
||||||
description: Learn how IT admins and teachers can use Microsoft Store for Education to acquire and manage apps in schools.
|
|
||||||
ms.topic: article
|
|
||||||
ms.date: 08/10/2022
|
|
||||||
appliesto:
|
|
||||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10 and later</a>
|
|
||||||
---
|
|
||||||
|
|
||||||
# Working with Microsoft Store for Education
|
|
||||||
|
|
||||||
Learn about education scenarios for Microsoft Store for Education. IT admins and teachers can use Microsoft Store to find, acquire, distribute, and manage apps.
|
|
||||||
|
|
||||||
Many of the [settings in Microsoft Store for Business](/microsoft-store/settings-reference-microsoft-store-for-business) also apply in Microsoft Store for Education. Several of the items in this topic are unique to Microsoft Store for Education.
|
|
||||||
|
|
||||||
## Basic Purchaser role
|
|
||||||
Applies to: IT admins
|
|
||||||
|
|
||||||
By default, when a teacher with a work or school account signs up for Microsoft Store for Education, the **Basic Purchaser** role is assigned to them. **Basic Purchaser** role allows teachers to:
|
|
||||||
- View the Minecraft: Education Edition product description page
|
|
||||||
- Acquire and manage Minecraft: Education Edition, and other apps from Store for Education
|
|
||||||
- Use info on **Support** (including links to documentation and access to support through customer service)
|
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> People with the **Basic Purchaser** role can only manage (assign and reclaim licenses) for apps that they purchased. They can't manage apps purchased by people with **Purchaser** or **Admin** roles.
|
|
||||||
|
|
||||||
Admins can control whether or not teachers are automatically assigned the **Basic Purchaser** role. You can configure this with **Make everyone a Basic Purchaser**. You'll find this on **Settings**, with **Shop** settings.
|
|
||||||
|
|
||||||
**To manage Make everyone a Basic Purchaser**
|
|
||||||
1. Sign in to [Microsoft Store for Education](https://educationstore.microsoft.com)
|
|
||||||
2. Click **Manage**, and then click **Settings**.
|
|
||||||
3. On **Shop**, select or clear **Make everyone a Basic Purchaser**.
|
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> **Make everyone a Basic Purchaser** is on by default.
|
|
||||||
|
|
||||||
When **Make everyone a Basic Purchaser** is turned off, admins can manually assign the role to teachers.
|
|
||||||
|
|
||||||
**To assign Basic Purchaser role**
|
|
||||||
|
|
||||||
1. Sign in to [Microsoft Store for Education](https://educationstore.microsoft.com)
|
|
||||||
2. Click **Manage**, and then choose **Permissions**.
|
|
||||||
3. On **Roles**, click **Assign roles**, type and select a name, choose the role you want to assign, and then click **Save**.
|
|
||||||
|
|
||||||
|
|
||||||
**Blocked Basic Purchasers**
|
|
||||||
|
|
||||||
When **Make everyone a Basic Purchaser** is on, admins can still manage which users have the **Basic Purchaser** role. An admin can unassign the **Basic Purchaser** role from a user, and the user is added to a list of **Blocked Basic Purchasers**. Admins can review who are **Basic Purchasers** and **Blocked Basic Purchasers** on **Permissions**.
|
|
||||||
|
|
||||||
## Private store
|
|
||||||
|
|
||||||
Applies to: IT admins
|
|
||||||
|
|
||||||
When you create your Microsoft Store for Education account, you'll have a set of apps included for free in your private store. Apps in your private store are available for all people in your organization to install and use.
|
|
||||||
|
|
||||||
These apps will automatically be in your private store:
|
|
||||||
- Word mobile
|
|
||||||
- Excel mobile
|
|
||||||
- PowerPoint mobile
|
|
||||||
- OneNote
|
|
||||||
- Sway
|
|
||||||
- Fresh Paint
|
|
||||||
- Minecraft: Education Edition
|
|
||||||
|
|
||||||
As an admin, you can remove any of these apps from the private store if you'd prefer to control how apps are distributed.
|
|
||||||
|
|
||||||
## Manage domain settings
|
|
||||||
|
|
||||||
Applies to: IT admins
|
|
||||||
|
|
||||||
### Self-service sign up
|
|
||||||
Self-service sign-up makes it easier for users in your organization to sign up for online services from Microsoft. We call this sign up process "self-service sign-up" because your users can sign up to use services paid by your subscription, or use free services, without asking you to take action on their behalf. For more information on self-service sign up, see [Using self-service sign up in your organization](https://support.office.com/article/Using-self-service-sign-up-in-your-organization-4f8712ff-9346-4c6c-bb63-a21ad7a62cbd?ui=en-US&rs=en-US&ad=US).
|
|
||||||
|
|
||||||
### Domain verification
|
|
||||||
For education organizations, domain verification ensures you are on the academic verification list. As an admin, you might need to verify your domain using the Microsoft 365 admin center. For more information, see [Verify your Office 365 domain to prove ownership, nonprofit or education status](https://support.office.com/article/Verify-your-Office-365-domain-to-prove-ownership-nonprofit-or-education-status-or-to-activate-Yammer-87d1844e-aa47-4dc0-a61b-1b773fd4e590?ui=en-US&rs=en-US&ad=US).
|
|
||||||
|
|
||||||
## Acquire apps
|
|
||||||
Applies to: IT admins and teachers
|
|
||||||
|
|
||||||
Find apps for your school using Microsoft Store for Business. Admins in an education setting can use the same processes as Admins in an enterprise setting to find and acquire apps.
|
|
||||||
|
|
||||||
**To acquire apps**
|
|
||||||
- For info on how to acquire apps, see [Acquire apps in Microsoft Store for Business](/microsoft-store/acquire-apps-windows-store-for-business#acquire-apps)
|
|
||||||
|
|
||||||
**To add a payment method - debit or credit card**
|
|
||||||
|
|
||||||
If the app you purchase has a price, you’ll need to provide a payment method.
|
|
||||||
- During your purchase, click **Get started! Add a way to pay.** Provide the info needed for your debit or credit card.
|
|
||||||
|
|
||||||
For more information on payment options, see [payment options](/microsoft-store/acquire-apps-windows-store-for-business#payment-options).
|
|
||||||
|
|
||||||
For more information on tax rates, see [tax information](/microsoft-store/update-windows-store-for-business-account-settings#organization-tax-information).
|
|
||||||
|
|
||||||
## Manage apps and software
|
|
||||||
Applies to: IT admins and teachers
|
|
||||||
|
|
||||||
## Manage purchases
|
|
||||||
IT admins and teachers in educational settings can purchase apps from Microsoft Store for Education. Teachers need to have the Basic purchaser role, but if they've acquired Minecraft: Education Edition, they have the role by default.
|
|
||||||
|
|
||||||
While both groups can purchase apps, they can't manage purchases made by the other group.
|
|
||||||
|
|
||||||
Admins can:
|
|
||||||
- Manage and distribute apps they purchased and apps purchased by other admins in the organization.
|
|
||||||
- View apps purchased by teachers.
|
|
||||||
- View and manage apps on **Manage**, under **Apps & software**.
|
|
||||||
|
|
||||||
Teachers can:
|
|
||||||
- Manage and distribute apps they purchased.
|
|
||||||
- View and manage apps on **Manage**, under **Apps & software**.
|
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> Teachers with the Basic purchaser role can't manage or view apps purchased by other teachers, or purchased by admins. Teachers can only work with the apps they purchased.
|
|
||||||
|
|
||||||
## Distribute apps
|
|
||||||
|
|
||||||
**To manage and distribute apps**
|
|
||||||
- For info on how to manage and distribute apps, see [App inventory management - Microsoft Store for Business](/microsoft-store/app-inventory-management-windows-store-for-business)
|
|
||||||
|
|
||||||
**To assign an app to a student**
|
|
||||||
|
|
||||||
1. Sign in to [Microsoft Store for Education](https://educationstore.microsoft.com).
|
|
||||||
2. Click **Manage**, and then choose **Apps & software**.
|
|
||||||
3. Find an app, click the ellipses under **Action**, and then choose **Assign to people**.
|
|
||||||
4. Type the email address, or name for the student that you're assigning the app to, and click **Assign**.
|
|
||||||
|
|
||||||
Employees will receive an email with a link that will install the app on their device. Click the link to start the Microsoft Store app, and then click **Install**. Also, in the Microsoft Store app, they can find the app under **My Library**.
|
|
||||||
|
|
||||||
### Purchase more licenses
|
|
||||||
Applies to: IT admins and teachers
|
|
||||||
|
|
||||||
You can manage current app licenses, or purchase more licenses for apps in **Apps & software**.
|
|
||||||
|
|
||||||
**To purchase additional app licenses**
|
|
||||||
1. Click **Manage**, click **Apps & software**, and then click an app.
|
|
||||||
2. Click **Buy more** to purchase more licenses</br>
|
|
||||||
|
|
||||||
You'll have a summary of current license availability.
|
|
||||||
|
|
||||||
## Manage order history
|
|
||||||
Applies to: IT admins and teachers
|
|
||||||
|
|
||||||
You can manage your orders through Microsoft Store for Business. For info on order history and how to refund an order, see [Manage app orders in Microsoft Store for Business](/microsoft-store/manage-orders-microsoft-store-for-business).
|
|
||||||
|
|
||||||
It can take up to 24 hours after a purchase, before a receipt is available on your **Order history page**.
|
|
@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: Get Minecraft Education Edition
|
title: Get and deploy Minecraft Education
|
||||||
description: Learn how to get and distribute Minecraft Education Edition.
|
description: Learn how to obtain and distribute Minecraft Education to Windows devices.
|
||||||
ms.topic: how-to
|
ms.topic: how-to
|
||||||
ms.date: 08/10/2022
|
ms.date: 02/23/2023
|
||||||
appliesto:
|
appliesto:
|
||||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10 and later</a>
|
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10 and later</a>
|
||||||
ms.collection:
|
ms.collection:
|
||||||
@ -11,20 +11,139 @@ ms.collection:
|
|||||||
- tier2
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Get Minecraft: Education Edition
|
# Get and deploy Minecraft Education
|
||||||
|
|
||||||
[Minecraft: Education Edition](https://education.minecraft.net/) is built for learning. Watch this video to learn more about Minecraft.
|
Minecraft Education is a game-based platform that inspires creative and inclusive learning through play. Explore blocky worlds that unlock new ways to tackle any subject or challenge. Dive into subjects like reading, math, history, and coding with lessons and standardized curriculum designed for all types of learners. Or explore and build together in creative open worlds.
|
||||||
|
|
||||||
<iframe width="501" height="282" src="https://www.youtube-nocookie.com/embed/hl9ZQiektJE" frameborder="0" allowfullscreen></iframe>
|
**Use it your way**: with hundreds of ready-to-teach lessons, creative challenges, and blank canvas worlds, there are lots of ways to make Minecraft Education work for your students. It's easy to get started, no gaming experience necessary.
|
||||||
|
|
||||||
Teachers and IT administrators can now get access to **Minecraft: Education Edition** and add it their Microsoft Admin Center for distribution.
|
**Prepare students for the future**: learners develop key skills like problem solving, collaboration, digital citizenship, and critical thinking to help them thrive now and in the future workplace. Spark a passion for STEM.
|
||||||
|
|
||||||
## Prerequisites
|
**Game based learning**: unlock creativity and deep learning with immersive content created with partners including BBC Earth, NASA, and the Nobel Peace Center. Inspire students to engage in real-world topics, with culturally relevant lessons and build challenges.
|
||||||
|
|
||||||
- For a complete list of Operating Systems supported by **Minecraft: Education Edition**, see [here](https://educommunity.minecraft.net/hc/articles/360047556591-System-Requirements).
|
|
||||||
- Trials or subscriptions of **Minecraft: Education Edition** are offered to education tenants that are managed by Azure Active Directory (Azure AD).
|
|
||||||
- If your school doesn't have an Azure AD tenant, the [IT administrator can set one up](school-get-minecraft.md) as part of the process of getting **Minecraft: Education Edition**.
|
|
||||||
- Office 365 Education, which includes online versions of Office apps plus 1 TB online storage. [Sign up your school for Office 365 Education.](https://www.microsoft.com/education/products/office)
|
|
||||||
- If your school has an Office 365 Education subscription, it includes a free Azure AD subscription. [Register your free Azure AD subscription.](/windows/client-management/mdm/register-your-free-azure-active-directory-subscription)
|
|
||||||
|
|
||||||
[Learn how IT administrators can get and distribute **Minecraft: Education Edition**](school-get-minecraft.md), and how to manage permissions for Minecraft.
|
## Minecraft Education key features
|
||||||
|
|
||||||
|
- Multiplayer mode enables collaboration in-game across platforms, devices, and hybrid environments
|
||||||
|
- Code Builder supports block-based coding, JavaScript, and Python with intuitive interface and in-game execution
|
||||||
|
- Immersive Reader helps players read and translate text
|
||||||
|
- Camera and Book & Quill items allow documentation and export of in-game creations
|
||||||
|
- Integration with Microsoft Teams and Flipgrid supports assessment and teacher controls
|
||||||
|
|
||||||
|
## Try or purchase Minecraft Education
|
||||||
|
|
||||||
|
Users in a Microsoft-verified academic organization with Microsoft 365 accounts have [access to a free trial][EDU-1] for Minecraft Education. This grants faculty accounts 25 free logins, and student accounts 10 free logins before a paid license is required to continue playing. Users in non-Microsoft-verified academic organizations have 10 free logins.
|
||||||
|
|
||||||
|
Organizations can [purchase subscriptions][EDU-2] directly in the *Microsoft 365 admin center*, via volume licensing agreements, or through partner resellers.
|
||||||
|
|
||||||
|
When you sign up for a Minecraft Education trial, or purchase a subscription, Minecraft Education licenses are linked to your Azure Active Directory (Azure AD) tenant. If you don't have an Azure AD tenant:
|
||||||
|
|
||||||
|
- Microsoft-verified academic organizations can set up a free [Office 365 Education subscription][EDU-3], which includes an Azure AD tenant
|
||||||
|
- Non-Microsoft-verified academic organizations can set up a free Azure AD tenant when they [purchase Minecraft Education commercial licenses][EDU-4]
|
||||||
|
|
||||||
|
### Direct purchase
|
||||||
|
|
||||||
|
To purchase direct licenses:
|
||||||
|
|
||||||
|
1. Go to [https://education.minecraft.net/](https://education.minecraft.net/) and select **How to Buy** in the top navigation bar
|
||||||
|
1. Scroll down and select **Buy Now** under **Direct Purchase**
|
||||||
|
1. In the *purchase* page, sign in with an account that has *Billing Admin* privileges in your organization
|
||||||
|
1. If necessary, fill in any requested organization or payment information
|
||||||
|
1. Select the quantity of licenses you'd like to purchase and select **Place Order**
|
||||||
|
1. After you've purchased licenses, you'll need to [assign Minecraft Education licenses to your users](#assign-minecraft-education-licenses)
|
||||||
|
|
||||||
|
If you need more licenses for Minecraft Education, see [Buy or remove subscription licenses](/microsoft-365/commerce/licenses/buy-licenses).
|
||||||
|
|
||||||
|
### Volume licensing
|
||||||
|
|
||||||
|
Qualified education institutions can purchase Minecraft Education licenses through their Microsoft channel partner. Schools need to be part of the *Enrollment for Education Solutions* (EES) volume licensing program. Educational institutions should work with their channel partner to determine which Minecraft Education licensing offer is best for their institution. The process looks like this:
|
||||||
|
|
||||||
|
1. Your channel partner will submit and process your volume license order
|
||||||
|
1. Your licenses will show on [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx)
|
||||||
|
1. After you've purchased licenses, you'll need to [assign Minecraft Education licenses to your users](#assign-minecraft-education-licenses)
|
||||||
|
|
||||||
|
### Payment options
|
||||||
|
|
||||||
|
You can pay for Minecraft Education with a debit or credit card, or with an invoice.
|
||||||
|
|
||||||
|
#### Debit or credit cards
|
||||||
|
|
||||||
|
During the purchase, select **Add a new payment method**. Provide the information needed for your debit or credit card.
|
||||||
|
|
||||||
|
#### Invoices
|
||||||
|
|
||||||
|
Invoices are a supported payment method for Minecraft Education. There are a few requirements:
|
||||||
|
|
||||||
|
- $500 invoice minimum for your initial purchase
|
||||||
|
- $15,000 invoice maximum (for all invoices within your organization)
|
||||||
|
|
||||||
|
To pay with an invoice:
|
||||||
|
|
||||||
|
1. During the purchase, select **Add a new payment method.**
|
||||||
|
2. Select the **Invoice** option, and provide the information needed for an invoice. The **PO number** item allows you to add a tracking number or info that is meaningful to your organization.
|
||||||
|
|
||||||
|
For more information about invoices and how to pay by invoice, see [Payment options for your Microsoft subscription][M365-1].
|
||||||
|
|
||||||
|
## Assign Minecraft Education licenses
|
||||||
|
|
||||||
|
You can assign and manage Minecraft Education licenses from the Microsoft 365 admin center.\
|
||||||
|
You must be a *Global*, *License*, or *User admin* to assign licenses. For more information, see [About Microsoft 365 admin roles][M365-2].
|
||||||
|
|
||||||
|
1. Go to [https://admin.microsoft.com](https://admin.microsoft.com) and sign in with an account that can assign licenses in your organization
|
||||||
|
1. From the left-hand menu in Microsoft Admin Center, select *Users*
|
||||||
|
1. From the Users list, select the users you want to add or remove for Minecraft Education access
|
||||||
|
1. Add the relevant Minecraft Education, A1 for device or A3/A5 license if it not assigned already
|
||||||
|
> [!Note]
|
||||||
|
> If you add a faculty license, the user will be assigned a *teacher* role in the application and will have elevated permissions.
|
||||||
|
1. If you've assigned a Microsoft 365 A3 or A5 license, after selecting the product license, ensure to toggle *Minecraft Education* on
|
||||||
|
> [!Note]
|
||||||
|
> If you turn off this setting after students have been using Minecraft Education, they will have up to 30 more days to use Minecraft Education before they don't have access
|
||||||
|
|
||||||
|
:::image type="content" source="images/minecraft/admin-center-minecraft-license.png" alt-text="Screenshot of the Microsoft 365 admin center - assignment of a Minecraft Education license to a user." lightbox="images/minecraft/admin-center-minecraft-license.png":::
|
||||||
|
|
||||||
|
For more information about license assignment, see [Manage Licenses in the Admin Center][EDU-5].
|
||||||
|
|
||||||
|
## Distribute Minecraft Education
|
||||||
|
|
||||||
|
There are different ways to install Minecraft Education on Windows devices. You can manually install the app on each device, or you can use a deployment tool to distribute the app to multiple devices.
|
||||||
|
If you're using Microsoft Intune to manage your devices, follow these steps to deploy Minecraft Education:
|
||||||
|
|
||||||
|
1. Go to the <a href="https://intune.microsoft.com" target="_blank"><b>Microsoft Intune admin center</b></a>
|
||||||
|
1. Select **Apps > Windows > Add**
|
||||||
|
1. Under *App type*, select **Microsoft Store app (new)** and choose **Select**
|
||||||
|
1. Select **Search the Microsoft Store app (new)** and search for **Minecraft Education**
|
||||||
|
1. Select the app and choose **Select**
|
||||||
|
1. On the *App information* screen, select **Next**
|
||||||
|
1. On the *Assignments* screen, choose how you want to target the installation of Minecraft Education
|
||||||
|
- *Required* means that Intune installs the app without user interaction
|
||||||
|
- *Available* enables Minecraft Education in the Company Portal, where users can install the app on-demand
|
||||||
|
1. Select **Next**
|
||||||
|
1. On the *Review + Create* screen, select **Create**
|
||||||
|
|
||||||
|
Intune will install Minecraft Education at the next device check-in, or will make it available in Company Portal for on-demand installs.
|
||||||
|
|
||||||
|
:::image type="content" source="images/minecraft/win11-minecraft-education.png" alt-text="Screenshot of Minecraft Education executing on a Windows 11 device.":::
|
||||||
|
|
||||||
|
For more information how to deploy Minecraft Education, see:
|
||||||
|
|
||||||
|
- [Windows installation guide][EDU-6]
|
||||||
|
- [Chromebook installation guide][EDU-7]
|
||||||
|
- [iOS installation guide][EDU-8]
|
||||||
|
- [macOS installation guide][EDU-9]
|
||||||
|
|
||||||
|
If you're having trouble installing the app, you can get more help on the [Minecraft Education support page][AKA-1].
|
||||||
|
|
||||||
|
<!--links-->
|
||||||
|
[EDU-1]: https://educommunity.minecraft.net/hc/articles/360047116432
|
||||||
|
[EDU-2]: https://educommunity.minecraft.net/hc/articles/360061371532
|
||||||
|
[EDU-3]: https://www.microsoft.com/education/products/office
|
||||||
|
[EDU-4]: https://educommunity.minecraft.net/hc/articles/360061369812
|
||||||
|
[EDU-6]: https://educommunity.minecraft.net/hc/articles/13106858087956
|
||||||
|
[EDU-5]: https://educommunity.minecraft.net/hc/articles/360047118672
|
||||||
|
[EDU-7]: https://educommunity.minecraft.net/hc/articles/4404625978516
|
||||||
|
[EDU-8]: https://educommunity.minecraft.net/hc/articles/360047556351
|
||||||
|
[EDU-9]: https://educommunity.minecraft.net/hc/articles/360047118792
|
||||||
|
|
||||||
|
[M365-1]: /microsoft-365/commerce/billing-and-payments/pay-for-your-subscription
|
||||||
|
[M365-2]: /microsoft-365/admin/add-users/about-admin-roles
|
||||||
|
|
||||||
|
[AKA-1]: https://aka.ms/minecraftedusupport
|
||||||
|
Binary file not shown.
After Width: | Height: | Size: 287 KiB |
Binary file not shown.
Before Width: | Height: | Size: 14 KiB |
BIN
education/windows/images/minecraft/win11-minecraft-education.png
Normal file
BIN
education/windows/images/minecraft/win11-minecraft-education.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 1.7 MiB |
BIN
education/windows/images/suspcs/2023-02-16_13-02-37.png
Normal file
BIN
education/windows/images/suspcs/2023-02-16_13-02-37.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 221 KiB |
@ -1,13 +1,13 @@
|
|||||||
---
|
---
|
||||||
author: paolomatarazzo
|
author: paolomatarazzo
|
||||||
ms.author: paoloma
|
ms.author: paoloma
|
||||||
ms.date: 11/08/2022
|
ms.date: 02/22/2022
|
||||||
ms.topic: include
|
ms.topic: include
|
||||||
---
|
---
|
||||||
|
|
||||||
To configure devices with Microsoft Intune, use a custom policy:
|
To configure devices with Microsoft Intune, use a custom policy:
|
||||||
|
|
||||||
1. Go to the <a href="https://go.microsoft.com/fwlink/?linkid=2109431" target="_blank"><b>Microsoft Endpoint Manager admin center</b></a>
|
1. Go to the <a href="https://intune.micorsoft.com" target="_blank"><b>Microsoft Intune admin center</b></a>
|
||||||
2. Select **Devices > Configuration profiles > Create profile**
|
2. Select **Devices > Configuration profiles > Create profile**
|
||||||
3. Select **Platform > Windows 10 and later** and **Profile type > Templates > Custom**
|
3. Select **Platform > Windows 10 and later** and **Profile type > Templates > Custom**
|
||||||
4. Select **Create**
|
4. Select **Create**
|
||||||
|
@ -12,6 +12,7 @@ metadata:
|
|||||||
ms.collection:
|
ms.collection:
|
||||||
- education
|
- education
|
||||||
- highpri
|
- highpri
|
||||||
|
- tier1
|
||||||
author: paolomatarazzo
|
author: paolomatarazzo
|
||||||
ms.author: paoloma
|
ms.author: paoloma
|
||||||
ms.date: 08/10/2022
|
ms.date: 08/10/2022
|
||||||
@ -100,5 +101,5 @@ landingContent:
|
|||||||
url: edu-take-a-test-kiosk-mode.md
|
url: edu-take-a-test-kiosk-mode.md
|
||||||
- text: Configure Shared PC
|
- text: Configure Shared PC
|
||||||
url: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context
|
url: /windows/configuration/set-up-shared-or-guest-pc?context=/education/context/context
|
||||||
- text: "Deploy Minecraft: Education Edition"
|
- text: Get and deploy Minecraft Education
|
||||||
url: get-minecraft-for-education.md
|
url: get-minecraft-for-education.md
|
@ -1,100 +0,0 @@
|
|||||||
---
|
|
||||||
title: For IT administrators get Minecraft Education Edition
|
|
||||||
description: Learn how IT admins can get and distribute Minecraft in their schools.
|
|
||||||
ms.topic: how-to
|
|
||||||
ms.date: 08/10/2022
|
|
||||||
appliesto:
|
|
||||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10</a>
|
|
||||||
ms.collection:
|
|
||||||
- highpri
|
|
||||||
- education
|
|
||||||
- tier2
|
|
||||||
---
|
|
||||||
|
|
||||||
# For IT administrators - get Minecraft: Education Edition
|
|
||||||
|
|
||||||
When you sign up for a [Minecraft: Education Edition](https://education.minecraft.net) trial, or purchase a [Minecraft: Education Edition](https://education.minecraft.net) subscription, Minecraft: Education Edition will be added to the inventory in your Microsoft Admin Center which is associated with your Azure Active Directory (Azure AD) tenant. Your Microsoft Admin Center is only displayed to members of your organization with administrative roles.
|
|
||||||
|
|
||||||
>[!Note]
|
|
||||||
>If you don't have an Azure AD or Office 365 tenant, you can set up a free Office 365 Education subscription when you purchase Minecraft: Education Edition. For more information, see [Office 365 Education plans and pricing](https://products.office.com/academic/compare-office-365-education-plans).
|
|
||||||
|
|
||||||
## Settings for Microsoft 365 A3 or Microsoft 365 A5 customers
|
|
||||||
|
|
||||||
Schools that purchased Microsoft 365 A3 or Microsoft 365 A5 have an extra option for making Minecraft: Education Edition available to their students:
|
|
||||||
|
|
||||||
If your school has these products in your tenant, admins can choose to enable Minecraft: Education Edition for students using Microsoft 365 A3 or Microsoft 365 A5. From the left-hand menu in Microsoft Admin Center, select Users. From the Users list, select the users you want to add or remove for Minecraft: Education Edition access. Add the relevant A3 or A5 license if it hasn't been assigned already.
|
|
||||||
|
|
||||||
> [!Note]
|
|
||||||
> If you add a faculty license, the user will be assigned an instructor role in the application and will have elevated permissions.
|
|
||||||
|
|
||||||
After selecting the appropriate product license, ensure Minecraft: Education Edition is toggled on or off, depending on if you want to add or remove Minecraft: Education Edition from the user (it will be on by default).
|
|
||||||
|
|
||||||
If you turn off this setting after students have been using Minecraft: Education Edition, they will have up to 30 more days to use Minecraft: Education Edition before they don't have access.
|
|
||||||
|
|
||||||
## How to get Minecraft: Education Edition
|
|
||||||
|
|
||||||
Users in a Microsoft verified academic institution account will have access to the free trial limited logins for Minecraft: Education Edition. This grants faculty accounts 25 free logins and student accounts 10 free logins. To purchase direct licenses, see [Minecraft: Education Edition - direct purchase](#individual-copies).
|
|
||||||
|
|
||||||
If you've been approved and are part of the Enrollment for Education Solutions volume license program, you can purchase a volume license for Minecraft: Education Edition. For more information, see [Minecraft: Education Edition - volume license](#volume-license).
|
|
||||||
|
|
||||||
### <a href="" id="individual-copies"></a>Minecraft: Education Edition - direct purchase
|
|
||||||
|
|
||||||
1. Go to [https://education.minecraft.net/](https://education.minecraft.net/) and select **How to Buy** in the top navigation bar.
|
|
||||||
|
|
||||||
2. Scroll down and select **Buy Now** under Direct Purchase.
|
|
||||||
|
|
||||||
3. This will route you to the purchase page in the Microsoft Admin center. You will need to log in to your Administrator account.
|
|
||||||
|
|
||||||
4. If necessary, fill in any requested organization or payment information.
|
|
||||||
|
|
||||||
5. Select the quantity of licenses you would like to purchase and select **Place Order**.
|
|
||||||
|
|
||||||
6. After you've purchased licenses, you'll need to [assign them to users in the Admin Center](/microsoft-365/admin/manage/assign-licenses-to-users).
|
|
||||||
|
|
||||||
If you need additional licenses for **Minecraft: Education Edition**, see [Buy or remove subscription licenses](/microsoft-365/commerce/licenses/buy-licenses).
|
|
||||||
|
|
||||||
### <a href="" id="volume-license"></a>Minecraft: Education Edition - volume licensing
|
|
||||||
|
|
||||||
Qualified education institutions can purchase Minecraft: Education Edition licenses through their Microsoft channel partner. Schools need to be part of the Enrollment for Education Solutions (EES) volume licensing program. Educational institutions should work with their channel partner to determine which Minecraft: Education Edition licensing offer is best for their institution. The process looks like this:
|
|
||||||
|
|
||||||
- Your channel partner will submit and process your volume license order, your licenses will be shown on [Volume Licensing Service Center](https://www.microsoft.com/Licensing/servicecenter/default.aspx), and the licenses will be available in your [Microsoft Store for Education](https://www.microsoft.com/business-store) inventory.
|
|
||||||
- You'll receive an email with a link to Microsoft Store for Education.
|
|
||||||
- Sign in to [Microsoft Store for Education](https://educationstore.microsoft.com) to distribute and manage the Minecraft: Education Edition licenses. For more information on distribution options, see [Distribute Minecraft](#distribute-minecraft)
|
|
||||||
|
|
||||||
## Minecraft: Education Edition payment options
|
|
||||||
|
|
||||||
You can pay for Minecraft: Education Edition with a debit or credit card, or with an invoice.
|
|
||||||
|
|
||||||
### Debit or credit cards
|
|
||||||
|
|
||||||
During the purchase, click **Add a new payment method**. Provide the info needed for your debit or credit card.
|
|
||||||
|
|
||||||
### Invoices
|
|
||||||
|
|
||||||
Invoices are now a supported payment method for Minecraft: Education Edition. There are a few requirements:
|
|
||||||
|
|
||||||
- Admins only (not supported for Teachers)
|
|
||||||
- $500 invoice minimum for your initial purchase
|
|
||||||
- $15,000 invoice maximum (for all invoices within your organization)
|
|
||||||
|
|
||||||
**To pay with an invoice**
|
|
||||||
|
|
||||||
1. During the purchase, click **Add a new payment method.**
|
|
||||||
|
|
||||||
2. Select the Invoice option, and provide the info needed for an invoice. The **PO number** item allows you to add a tracking number or info that is meaningful to your organization.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
For more info on invoices and how to pay by invoice, see [How to pay for your subscription](/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription?).
|
|
||||||
|
|
||||||
## Distribute Minecraft
|
|
||||||
|
|
||||||
After Minecraft: Education Edition is added to your Microsoft Admin Center inventory, you can [assign these licenses to your users](/microsoft-365/admin/manage/assign-licenses-to-users) or [download the app](https://aka.ms/downloadmee).
|
|
||||||
|
|
||||||
## Learn more
|
|
||||||
|
|
||||||
[About Intune Admin roles in the Microsoft 365 admin center](/microsoft-365/business-premium/m365bp-intune-admin-roles-in-the-mac)
|
|
||||||
|
|
||||||
## Related topics
|
|
||||||
|
|
||||||
[Get Minecraft: Education Edition](get-minecraft-for-education.md)
|
|
@ -1,41 +0,0 @@
|
|||||||
---
|
|
||||||
title: For teachers get Minecraft Education Edition
|
|
||||||
description: Learn how teachers can obtain and distribute Minecraft.
|
|
||||||
ms.topic: how-to
|
|
||||||
ms.date: 08/10/2022
|
|
||||||
appliesto:
|
|
||||||
- ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 10 and later</a>
|
|
||||||
ms.collection:
|
|
||||||
- highpri
|
|
||||||
- education
|
|
||||||
- tier2
|
|
||||||
---
|
|
||||||
|
|
||||||
# For teachers - get Minecraft: Education Edition
|
|
||||||
|
|
||||||
The following article describes how teachers can get and distribute Minecraft: Education Edition at their school. Minecraft: Education Edition is available for anyone to trial, and subscriptions can be purchased by qualified educational institutions directly in the [Microsoft Admin Center by IT Admins](/education/windows/school-get-minecraft), via volume licensing agreements and through partner resellers.
|
|
||||||
|
|
||||||
|
|
||||||
## Try Minecraft: Education Edition for Free
|
|
||||||
|
|
||||||
Minecraft: Education Edition is available for anyone to try for free! The free trial is fully functional but limited by the number of logins (25 for teachers and 10 for students) before a paid license will be required to continue playing.
|
|
||||||
|
|
||||||
To learn more and get started, [download the Minecraft: Education Edition app here.](https://aka.ms/download)
|
|
||||||
|
|
||||||
## Purchase Minecraft: Education Edition for Teachers and Students
|
|
||||||
|
|
||||||
As a teacher, you will need to have your IT Admin purchase licenses for you and your students directly through the Microsoft Admin Center, or you may already have access to licenses at your school (through a volume license agreement) if you have an Office 365 subscription.
|
|
||||||
|
|
||||||
M:EE is included in many volume license agreements, however, only the administrators at your school will be able to assign and manage those licenses. If you have an Office 365 account, check with your school administration or IT administrator prior to purchasing M:EE directly.
|
|
||||||
|
|
||||||
|
|
||||||
#### Troubleshoot
|
|
||||||
|
|
||||||
If you're having trouble installing the app, you can get more help on our [Support page](https://aka.ms/minecraftedusupport).
|
|
||||||
|
|
||||||
## Related topics
|
|
||||||
|
|
||||||
[Get Minecraft: Education Edition](get-minecraft-for-education.md)
|
|
||||||
[For IT admins: get Minecraft: Education Edition](school-get-minecraft.md)
|
|
||||||
|
|
||||||
|
|
@ -70,7 +70,7 @@ To create a Windows Update policy:
|
|||||||
For more information, see [Updates and upgrade][INT-6].
|
For more information, see [Updates and upgrade][INT-6].
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you require a more complex Windows Update policy, you can create it in Microsoft Endpoint Manager. For more information:
|
> If you require a more complex Windows Update policy, you can create it in Microsoft Intune. For more information:
|
||||||
> - [<u>What is Windows Update for Business?</u>][WIN-1]
|
> - [<u>What is Windows Update for Business?</u>][WIN-1]
|
||||||
> - [<u>Manage Windows software updates in Intune</u>][MEM-1]
|
> - [<u>Manage Windows software updates in Intune</u>][MEM-1]
|
||||||
|
|
||||||
@ -92,7 +92,7 @@ To create a security policy:
|
|||||||
For more information, see [Security][INT-4].
|
For more information, see [Security][INT-4].
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you require more sophisticated security policies, you can create them in Microsoft Endpoint Manager. For more information:
|
> If you require more sophisticated security policies, you can create them in Microsoft Intune. For more information:
|
||||||
> - [<u>Antivirus</u>][MEM-2]
|
> - [<u>Antivirus</u>][MEM-2]
|
||||||
> - [<u>Disk encryption</u>][MEM-3]
|
> - [<u>Disk encryption</u>][MEM-3]
|
||||||
> - [<u>Firewall</u>][MEM-4]
|
> - [<u>Firewall</u>][MEM-4]
|
||||||
|
@ -54,7 +54,7 @@ Here are the steps for creating a dynamic group for the devices that have an ass
|
|||||||
1. Select **Create group**
|
1. Select **Create group**
|
||||||
:::image type="content" source="./images/intune-education-autopilot-group.png" alt-text="Intune for Education - creation of a dynamic group for Autopilot devices" border="true":::
|
:::image type="content" source="./images/intune-education-autopilot-group.png" alt-text="Intune for Education - creation of a dynamic group for Autopilot devices" border="true":::
|
||||||
|
|
||||||
More advanced dynamic membership rules can be created from Microsoft Endpoint Manager admin center. For more information, see [Create an Autopilot device group using Intune][MEM-3].
|
More advanced dynamic membership rules can be created from Microsoft Intune admin center. For more information, see [Create an Autopilot device group using Intune][MEM-3].
|
||||||
|
|
||||||
> [!TIP]
|
> [!TIP]
|
||||||
> You can use these dynamic groups not only to assign Autopilot profiles, but also to target applications and settings.
|
> You can use these dynamic groups not only to assign Autopilot profiles, but also to target applications and settings.
|
||||||
@ -76,7 +76,7 @@ To create an Autopilot deployment profile:
|
|||||||
1. Ensure that **User account type** is configured as **Standard**
|
1. Ensure that **User account type** is configured as **Standard**
|
||||||
1. Select **Save**
|
1. Select **Save**
|
||||||
|
|
||||||
While Intune for Education offers simple options for Autopilot configurations, more advanced deployment profiles can be created from Microsoft Endpoint Manager admin center. For more information, see [Windows Autopilot deployment profiles][MEM-4].
|
While Intune for Education offers simple options for Autopilot configurations, more advanced deployment profiles can be created from Microsoft Intune admin center. For more information, see [Windows Autopilot deployment profiles][MEM-4].
|
||||||
|
|
||||||
### Configure an Enrollment Status Page
|
### Configure an Enrollment Status Page
|
||||||
|
|
||||||
@ -87,7 +87,7 @@ An Enrollment Status Page (ESP) is a greeting page displayed to users while enro
|
|||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Some Windows Autopilot deployment profiles **require** the ESP to be configured.
|
> Some Windows Autopilot deployment profiles **require** the ESP to be configured.
|
||||||
|
|
||||||
To deploy the ESP to devices, you need to create an ESP profile in Microsoft Endpoint Manager.
|
To deploy the ESP to devices, you need to create an ESP profile in Microsoft Intune.
|
||||||
|
|
||||||
> [!TIP]
|
> [!TIP]
|
||||||
> While testing the deployment process, you can configure the ESP to:
|
> While testing the deployment process, you can configure the ESP to:
|
||||||
|
@ -29,8 +29,8 @@ This content provides a comprehensive path for schools to deploy and manage new
|
|||||||
|
|
||||||
Historically, school IT administrators and educators have struggled to find an easy-to-use, flexible, and secure way to manage the lifecycle of the devices in their schools. In response, Microsoft has developed integrated suites of products for streamlined, cost-effective device lifecycle management.
|
Historically, school IT administrators and educators have struggled to find an easy-to-use, flexible, and secure way to manage the lifecycle of the devices in their schools. In response, Microsoft has developed integrated suites of products for streamlined, cost-effective device lifecycle management.
|
||||||
|
|
||||||
Microsoft 365 Education provides tools and services that enable simplified management of all devices through Microsoft Endpoint Manager (MEM). With Microsoft's solutions, IT administrators have the flexibility to support diverse scenarios, including school-owned devices and bring-your-own devices.
|
Microsoft 365 Education provides tools and services that enable simplified management of all devices through Microsoft Intune services. With Microsoft's solutions, IT administrators have the flexibility to support diverse scenarios, including school-owned devices and bring-your-own devices.
|
||||||
Microsoft Endpoint Manager services include:
|
Microsoft Intune services include:
|
||||||
|
|
||||||
- [Microsoft Intune][MEM-1]
|
- [Microsoft Intune][MEM-1]
|
||||||
- [Microsoft Intune for Education][INT-1]
|
- [Microsoft Intune for Education][INT-1]
|
||||||
|
@ -17,25 +17,25 @@ Surface devices use a Unified Extensible Firmware Interface (UEFI) setting that
|
|||||||
|
|
||||||
DFCI supports zero-touch provisioning, eliminates BIOS passwords, and provides control of security settings for boot options, cameras and microphones, built-in peripherals, and more. For more information, see [Manage DFCI on Surface devices][SURF-1] and [Manage DFCI with Windows Autopilot][MEM-1], which includes a list of requirements to use DFCI.
|
DFCI supports zero-touch provisioning, eliminates BIOS passwords, and provides control of security settings for boot options, cameras and microphones, built-in peripherals, and more. For more information, see [Manage DFCI on Surface devices][SURF-1] and [Manage DFCI with Windows Autopilot][MEM-1], which includes a list of requirements to use DFCI.
|
||||||
|
|
||||||
:::image type="content" source="./images/dfci-profile.png" alt-text="Creation of a DFCI profile from Microsoft Endpoint Manager" lightbox="./images/dfci-profile-expanded.png" border="true":::
|
:::image type="content" source="./images/dfci-profile.png" alt-text="Creation of a DFCI profile from Microsoft Intune" lightbox="./images/dfci-profile-expanded.png" border="true":::
|
||||||
|
|
||||||
## Microsoft Surface Management Portal
|
## Microsoft Surface Management Portal
|
||||||
|
|
||||||
Located in the Microsoft Endpoint Manager admin center, the Microsoft Surface Management Portal enables you to self-serve, manage, and monitor your school's Intune-managed Surface devices at scale. Get insights into device compliance, support activity, warranty coverage, and more.
|
Located in the Microsoft Intune admin center, the Microsoft Surface Management Portal enables you to self-serve, manage, and monitor your school's Intune-managed Surface devices at scale. Get insights into device compliance, support activity, warranty coverage, and more.
|
||||||
|
|
||||||
When Surface devices are enrolled in cloud management and users sign in for the first time, information automatically flows into the Surface Management Portal, giving you a single pane of glass for Surface-specific administration activities.
|
When Surface devices are enrolled in cloud management and users sign in for the first time, information automatically flows into the Surface Management Portal, giving you a single pane of glass for Surface-specific administration activities.
|
||||||
|
|
||||||
To access and use the Surface Management Portal:
|
To access and use the Surface Management Portal:
|
||||||
|
|
||||||
1. Sign in to <a href="https://endpoint.microsoft.com/" target="_blank"><b>Microsoft Endpoint Manager admin center</b></a>
|
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||||
1. Select **All services** > **Surface Management Portal**
|
2. Select **All services** > **Surface Management Portal**
|
||||||
:::image type="content" source="./images/surface-management-portal.png" alt-text="Surface Management Portal within Microsoft Endpoint Manager" lightbox="./images/surface-management-portal-expanded.png" border="true":::
|
:::image type="content" source="./images/surface-management-portal.png" alt-text="Surface Management Portal within Microsoft Intune" lightbox="./images/surface-management-portal-expanded.png" border="true":::
|
||||||
1. To obtain insights for all your Surface devices, select **Monitor**
|
3. To obtain insights for all your Surface devices, select **Monitor**
|
||||||
- Devices that are out of compliance or not registered, have critically low storage, require updates, or are currently inactive, are listed here
|
- Devices that are out of compliance or not registered, have critically low storage, require updates, or are currently inactive, are listed here
|
||||||
1. To obtain details on each insights category, select **View report**
|
4. To obtain details on each insights category, select **View report**
|
||||||
- This dashboard displays diagnostic information that you can customize and export
|
- This dashboard displays diagnostic information that you can customize and export
|
||||||
1. To obtain the device's warranty information, select **Device warranty and coverage**
|
5. To obtain the device's warranty information, select **Device warranty and coverage**
|
||||||
1. To review a list of support requests and their status, select **Support requests**
|
6. To review a list of support requests and their status, select **Support requests**
|
||||||
|
|
||||||
<!-- Reference links in article -->
|
<!-- Reference links in article -->
|
||||||
|
|
||||||
|
@ -30,7 +30,7 @@ For more information, see [Create your Office 365 tenant account][M365-1]
|
|||||||
|
|
||||||
The **Microsoft 365 admin center** is the hub for all administrative consoles for the Microsoft 365 cloud. To access the <a href="https://entra.microsoft.com" target="_blank"><u>Microsoft Entra admin center</u></a>, sign in with the same global administrator account when you [created the Microsoft 365 tenant](#create-a-microsoft-365-tenant).
|
The **Microsoft 365 admin center** is the hub for all administrative consoles for the Microsoft 365 cloud. To access the <a href="https://entra.microsoft.com" target="_blank"><u>Microsoft Entra admin center</u></a>, sign in with the same global administrator account when you [created the Microsoft 365 tenant](#create-a-microsoft-365-tenant).
|
||||||
|
|
||||||
From the Microsoft 365 admin center, you can access different administrative dashboards: Azure Active Directory, Microsoft Endpoint Manager, Intune for Education, and others:
|
From the Microsoft 365 admin center, you can access different administrative dashboards: Azure Active Directory, Microsoft Intune, Intune for Education, and others:
|
||||||
|
|
||||||
:::image type="content" source="./images/m365-admin-center.png" alt-text="*All admin centers* page in *Microsoft 365 admin center*" lightbox="./images/m365-admin-center.png" border="true":::
|
:::image type="content" source="./images/m365-admin-center.png" alt-text="*All admin centers* page in *Microsoft 365 admin center*" lightbox="./images/m365-admin-center.png" border="true":::
|
||||||
|
|
||||||
|
@ -7,9 +7,9 @@ ms.topic: tutorial
|
|||||||
|
|
||||||
# Set up Microsoft Intune
|
# Set up Microsoft Intune
|
||||||
|
|
||||||
Without the proper tools and resources, managing hundreds or thousands of devices in a school environment can be a complex and time-consuming task. Microsoft Endpoint Manager provides a collection of services that simplifies the management of devices at scale.
|
Without the proper tools and resources, managing hundreds or thousands of devices in a school environment can be a complex and time-consuming task. Microsoft Intune is a collection of services that simplifies the management of devices at scale.
|
||||||
|
|
||||||
Microsoft Intune is one of the services provided by Microsoft Endpoint Manager. The Microsoft Intune service can be managed in different ways, and one of them is **Intune for Education**, a web portal designed for education environments.
|
The Microsoft Intune service can be managed in different ways, and one of them is **Intune for Education**, a web portal designed for education environments.
|
||||||
|
|
||||||
:::image type="content" source="./images/intune-education-portal.png" alt-text="Intune for Education dashboard" lightbox="./images/intune-education-portal.png" border="true":::
|
:::image type="content" source="./images/intune-education-portal.png" alt-text="Intune for Education dashboard" lightbox="./images/intune-education-portal.png" border="true":::
|
||||||
|
|
||||||
@ -44,13 +44,13 @@ With enrollment restrictions, you can prevent certain types of devices from bein
|
|||||||
|
|
||||||
To block personally owned Windows devices from enrolling:
|
To block personally owned Windows devices from enrolling:
|
||||||
|
|
||||||
1. Sign in to the <a href="https://endpoint.microsoft.com/" target="_blank"><b>Microsoft Endpoint Manager admin center</b></a>
|
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||||
1. Select **Devices** > **Enroll devices** > **Enrollment device platform restrictions**
|
1. Select **Devices** > **Enroll devices** > **Enrollment device platform restrictions**
|
||||||
1. Select the **Windows restrictions** tab
|
1. Select the **Windows restrictions** tab
|
||||||
1. Select **Create restriction**
|
1. Select **Create restriction**
|
||||||
1. On the **Basics** page, provide a name for the restriction and, optionally, a description > **Next**
|
1. On the **Basics** page, provide a name for the restriction and, optionally, a description > **Next**
|
||||||
1. On the **Platform settings** page, in the **Personally owned devices** field, select **Block** > **Next**
|
1. On the **Platform settings** page, in the **Personally owned devices** field, select **Block** > **Next**
|
||||||
:::image type="content" source="./images/enrollment-restrictions.png" alt-text="Device enrollment restriction page in Microsoft Endpoint Manager admin center" lightbox="./images/enrollment-restrictions.png" border="true":::
|
:::image type="content" source="./images/enrollment-restrictions.png" alt-text="This screenshot is of the device enrollment restriction page in Microsoft Intune admin center." lightbox="./images/enrollment-restrictions.png":::
|
||||||
1. Optionally, on the **Scope tags** page, add scope tags > **Next**
|
1. Optionally, on the **Scope tags** page, add scope tags > **Next**
|
||||||
1. On the **Assignments** page, select **Add groups**, and then use the search box to find and choose groups to which you want to apply the restriction > **Next**
|
1. On the **Assignments** page, select **Add groups**, and then use the search box to find and choose groups to which you want to apply the restriction > **Next**
|
||||||
1. On the **Review + create** page, select **Create** to save the restriction
|
1. On the **Review + create** page, select **Create** to save the restriction
|
||||||
@ -63,13 +63,13 @@ Windows Hello for Business is a biometric authentication feature that allows use
|
|||||||
It's suggested to disable Windows Hello for Business on Windows devices at the tenant level, and enabling it only for devices that need it, for example for teachers and staff devices.
|
It's suggested to disable Windows Hello for Business on Windows devices at the tenant level, and enabling it only for devices that need it, for example for teachers and staff devices.
|
||||||
To disable Windows Hello for Business at the tenant level:
|
To disable Windows Hello for Business at the tenant level:
|
||||||
|
|
||||||
1. Sign in to the <a href="https://endpoint.microsoft.com/" target="_blank"><b>Microsoft Endpoint Manager admin center</b></a>
|
1. Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||||
1. Select **Devices** > **Windows** > **Windows Enrollment**
|
1. Select **Devices** > **Windows** > **Windows Enrollment**
|
||||||
1. Select **Windows Hello for Business**
|
1. Select **Windows Hello for Business**
|
||||||
1. Ensure that **Configure Windows Hello for Business** is set to **disabled**
|
1. Ensure that **Configure Windows Hello for Business** is set to **disabled**
|
||||||
1. Select **Save**
|
1. Select **Save**
|
||||||
|
|
||||||
:::image type="content" source="./images/whfb-disable.png" alt-text="Disablement of Windows Hello for Business from Microsoft Endpoint Manager admin center." border="true" lightbox="./images/whfb-disable.png":::
|
:::image type="content" source="./images/whfb-disable.png" alt-text="Disablement of Windows Hello for Business from Microsoft Intune admin center." lightbox="./images/whfb-disable.png":::
|
||||||
|
|
||||||
For more information how to enable Windows Hello for Business on specific devices, see [Create a Windows Hello for Business policy][MEM-4].
|
For more information how to enable Windows Hello for Business on specific devices, see [Create a Windows Hello for Business policy][MEM-4].
|
||||||
|
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Troubleshoot Windows devices
|
title: Troubleshoot Windows devices
|
||||||
description: Learn how to troubleshoot Windows devices from Intune and contact Microsoft Support for issues related to Intune and other Endpoint Manager services.
|
description: Learn how to troubleshoot Windows devices from Intune and contact Microsoft Support for issues related to Intune and other services.
|
||||||
ms.date: 08/31/2022
|
ms.date: 08/31/2022
|
||||||
ms.topic: tutorial
|
ms.topic: tutorial
|
||||||
appliesto:
|
appliesto:
|
||||||
@ -9,7 +9,7 @@ appliesto:
|
|||||||
|
|
||||||
# Troubleshoot Windows devices
|
# Troubleshoot Windows devices
|
||||||
|
|
||||||
Microsoft Endpoint Manager provides many tools that can help you troubleshoot Windows devices.
|
Microsoft Intune provides many tools that can help you troubleshoot Windows devices.
|
||||||
Here's a collection of resources to help you troubleshoot Windows devices managed by Intune:
|
Here's a collection of resources to help you troubleshoot Windows devices managed by Intune:
|
||||||
|
|
||||||
- [Troubleshooting device enrollment in Intune][MEM-2]
|
- [Troubleshooting device enrollment in Intune][MEM-2]
|
||||||
@ -27,11 +27,12 @@ Here's a collection of resources to help you troubleshoot Windows devices manage
|
|||||||
|
|
||||||
Microsoft provides global technical, pre-sales, billing, and subscription support for cloud-based device management services. This support includes Microsoft Intune, Configuration Manager, Windows 365, and Microsoft Managed Desktop.
|
Microsoft provides global technical, pre-sales, billing, and subscription support for cloud-based device management services. This support includes Microsoft Intune, Configuration Manager, Windows 365, and Microsoft Managed Desktop.
|
||||||
|
|
||||||
Follow these steps to obtain support in Microsoft Endpoint Manager:
|
Follow these steps to obtain support in Microsoft Intune provides many tools that can help you troubleshoot Windows devices.
|
||||||
|
:
|
||||||
|
|
||||||
- Sign in to the <a href="https://endpoint.microsoft.com" target="_blank"><b>Microsoft Endpoint Manager admin center</b></a>
|
- Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||||
- Select **Troubleshooting + support** > **Help and support**
|
- Select **Troubleshooting + support** > **Help and support**
|
||||||
:::image type="content" source="images/advanced-support.png" alt-text="Screenshot that shows how to obtain support from Microsoft Endpoint Manager." lightbox="images/advanced-support.png":::
|
:::image type="content" source="images/advanced-support.png" alt-text="Screenshot that shows how to obtain support from Microsoft Intune." lightbox="images/advanced-support.png":::
|
||||||
- Select the required support scenario: Configuration Manager, Intune, Co-management, or Windows 365
|
- Select the required support scenario: Configuration Manager, Intune, Co-management, or Windows 365
|
||||||
- Above **How can we help?**, select one of three icons to open different panes: *Find solutions*, *Contact support*, or *Service requests*
|
- Above **How can we help?**, select one of three icons to open different panes: *Find solutions*, *Contact support*, or *Service requests*
|
||||||
- In the **Find solutions** pane, use the text box to specify a few details about your issue. The console may offer suggestions based on what you've entered. Depending on the presence of specific keywords, the console provides help like:
|
- In the **Find solutions** pane, use the text box to specify a few details about your issue. The console may offer suggestions based on what you've entered. Depending on the presence of specific keywords, the console provides help like:
|
||||||
@ -43,7 +44,7 @@ Follow these steps to obtain support in Microsoft Endpoint Manager:
|
|||||||
> When opening a case, be sure to include as many details as possible in the *Description* field. Such information includes: timestamp and date, device ID, device model, serial number, OS version, and any other details relevant to the issue.
|
> When opening a case, be sure to include as many details as possible in the *Description* field. Such information includes: timestamp and date, device ID, device model, serial number, OS version, and any other details relevant to the issue.
|
||||||
- To review your case history, select the **Service requests** pane. Active cases are at the top of the list, with closed issues also available for review
|
- To review your case history, select the **Service requests** pane. Active cases are at the top of the list, with closed issues also available for review
|
||||||
|
|
||||||
For more information, see [Microsoft Endpoint Manager support page][MEM-1]
|
For more information, see [Microsoft Intune support page][MEM-1]
|
||||||
|
|
||||||
<!-- Reference links in article -->
|
<!-- Reference links in article -->
|
||||||
[MEM-1]: /mem/get-support
|
[MEM-1]: /mem/get-support
|
||||||
|
@ -13,7 +13,7 @@ IT administrators and technical teachers can use the **Set up School PCs** app t
|
|||||||
Set up School PCs also:
|
Set up School PCs also:
|
||||||
* Joins each student PC to your organization's Office 365 and Azure Active Directory tenant.
|
* Joins each student PC to your organization's Office 365 and Azure Active Directory tenant.
|
||||||
* Enables the optional Autopilot Reset feature, to return devices to a fully configured or known IT-approved state.
|
* Enables the optional Autopilot Reset feature, to return devices to a fully configured or known IT-approved state.
|
||||||
* Utilizes Windows Update and maintenance hours to keeps student PCs up-to-date, without interfering with class time.
|
* Utilizes Windows Update and maintenance hours to keep student PCs up-to-date, without interfering with class time.
|
||||||
* Locks down the student PC to prevent activity that isn't beneficial to their education.
|
* Locks down the student PC to prevent activity that isn't beneficial to their education.
|
||||||
|
|
||||||
This article describes how to fill out your school's information in the Set up School PCs app. To learn more about the app's functionality, start with the [Technical reference for the Set up School PCs app](set-up-school-pcs-technical.md).
|
This article describes how to fill out your school's information in the Set up School PCs app. To learn more about the app's functionality, start with the [Technical reference for the Set up School PCs app](set-up-school-pcs-technical.md).
|
||||||
@ -23,8 +23,6 @@ Before you begin, make sure that you, your computer, and your school's network a
|
|||||||
|
|
||||||
* Office 365 and Azure Active Directory
|
* Office 365 and Azure Active Directory
|
||||||
* [Latest Set up School PCs app](https://www.microsoft.com/store/apps/9nblggh4ls40)
|
* [Latest Set up School PCs app](https://www.microsoft.com/store/apps/9nblggh4ls40)
|
||||||
* Permission to buy apps in Microsoft Store for Education
|
|
||||||
* Set up School PCs app has permission to access the Microsoft Store for Education
|
|
||||||
* A NTFS-formatted USB drive that is at least 1 GB, if not installing Office; and at least 8 GB, if installing Office
|
* A NTFS-formatted USB drive that is at least 1 GB, if not installing Office; and at least 8 GB, if installing Office
|
||||||
* Student PCs must either:
|
* Student PCs must either:
|
||||||
* Be within range of the Wi-Fi network that you configured in the app.
|
* Be within range of the Wi-Fi network that you configured in the app.
|
||||||
@ -170,9 +168,9 @@ The following table describes each setting and lists the applicable Windows 10 v
|
|||||||
|---------|---------|---------|---------|---------|---------|---------|
|
|---------|---------|---------|---------|---------|---------|---------|
|
||||||
|Remove apps pre-installed by the device manufacturer |X|X|X|X| Uninstalls apps that came loaded on the computer by the device's manufacturer. |Adds about 30 minutes to the provisioning process.|
|
|Remove apps pre-installed by the device manufacturer |X|X|X|X| Uninstalls apps that came loaded on the computer by the device's manufacturer. |Adds about 30 minutes to the provisioning process.|
|
||||||
|Allow local storage (not recommended for shared devices) |X|X|X|X| Lets students save files to the Desktop and Documents folder on the Student PC. |Not recommended if the device will be shared between different students.|
|
|Allow local storage (not recommended for shared devices) |X|X|X|X| Lets students save files to the Desktop and Documents folder on the Student PC. |Not recommended if the device will be shared between different students.|
|
||||||
|Optimize device for a single student, instead of a shared cart or lab |X|X|X|X|Optimizes the device for use by a single student, rather than many students. |Recommended if the device will be shared between different students. Single-optimized accounts are set to expire, and require a signin, 180 days after setup. This setting increases the maximum PC storage to 100% of the available disk space. In this case, student accounts aren't deleted unless the account has been inactive for 180 days. |
|
|Optimize device for a single student, instead of a shared cart or lab |X|X|X|X|Optimizes the device for use by a single student, rather than many students. |Recommended if the device will be shared between different students. Single-optimized accounts are set to expire, and require a sign-in, 180 days after setup. This setting increases the maximum PC storage to 100% of the available disk space. In this case, student accounts aren't deleted unless the account has been inactive for 180 days. |
|
||||||
|Let guests sign in to these PCs |X|X|X|X|Allows guests to use student PCs without a school account. |Common to use within a public, shared space, such as a library. Also used when a student loses their password. Adds a **Guest** account to the PC sign-in screen that anyone can sign in to.|
|
|Let guests sign in to these PCs |X|X|X|X|Allows guests to use student PCs without a school account. |Common to use within a public, shared space, such as a library. Also used when a student loses their password. Adds a **Guest** account to the PC sign-in screen that anyone can sign in to.|
|
||||||
|Enable Autopilot Reset |Not available|X|X|X|Lets you remotely reset a student’s PC from the lock screen, apply the device’s original settings, and enroll it in device management (Azure AD and MDM). |Requires Windows 10, version 1709 and WinRE must be enabled on the PC. Setup will fail if both requirements aren't met.|
|
|Enable Autopilot Reset |Not available|X|X|X|Lets you remotely reset a student's PC from the lock screen, apply the device's original settings, and enroll it in device management (Azure AD and MDM). |Requires Windows 10, version 1709 and WinRE must be enabled on the PC. Setup will fail if both requirements aren't met.|
|
||||||
|Lock screen background|X|X|X|X|Change the default screen lock background to a custom image.|Click **Browse** to search for an image file on your computer. Accepted image formats are jpg, jpeg, and png.|
|
|Lock screen background|X|X|X|X|Change the default screen lock background to a custom image.|Click **Browse** to search for an image file on your computer. Accepted image formats are jpg, jpeg, and png.|
|
||||||
|
|
||||||
After you've made your selections, click **Next**.
|
After you've made your selections, click **Next**.
|
||||||
|
@ -94,6 +94,7 @@ The following applications can also run on Windows 11 SE, and can be deployed us
|
|||||||
| `Class Policy` | 114.0.0 | Win32 | `Class Policy` |
|
| `Class Policy` | 114.0.0 | Win32 | `Class Policy` |
|
||||||
| `Classroom.cloud` | 1.40.0004 | Win32 | `NetSupport` |
|
| `Classroom.cloud` | 1.40.0004 | Win32 | `NetSupport` |
|
||||||
| `CoGat Secure Browser` | 11.0.0.19 | Win32 | `Riverside Insights` |
|
| `CoGat Secure Browser` | 11.0.0.19 | Win32 | `Riverside Insights` |
|
||||||
|
| `ColorVeil` | 4.0.0.175 | Win32 | `East-Tec` |
|
||||||
| `ContentKeeper Cloud` | 9.01.45 | Win32 | `ContentKeeper Technologies` |
|
| `ContentKeeper Cloud` | 9.01.45 | Win32 | `ContentKeeper Technologies` |
|
||||||
| `Dragon Professional Individual` | 15.00.100 | Win32 | `Nuance Communications` |
|
| `Dragon Professional Individual` | 15.00.100 | Win32 | `Nuance Communications` |
|
||||||
| `DRC INSIGHT Online Assessments` | 12.0.0.0 | `Store` | `Data recognition Corporation` |
|
| `DRC INSIGHT Online Assessments` | 12.0.0.0 | `Store` | `Data recognition Corporation` |
|
||||||
@ -107,6 +108,7 @@ The following applications can also run on Windows 11 SE, and can be deployed us
|
|||||||
| `Ghotit Real Writer & Reader` | 10.14.2.3 | Win32 | `Ghotit Ltd` |
|
| `Ghotit Real Writer & Reader` | 10.14.2.3 | Win32 | `Ghotit Ltd` |
|
||||||
| `GoGuardian` | 1.4.4 | Win32 | `GoGuardian` |
|
| `GoGuardian` | 1.4.4 | Win32 | `GoGuardian` |
|
||||||
| `Google Chrome` | 109.0.5414.75 | Win32 | `Google` |
|
| `Google Chrome` | 109.0.5414.75 | Win32 | `Google` |
|
||||||
|
| `GuideConnect` | 1.23 | Win32 | `Dolphin Computer Access` |
|
||||||
| `Illuminate Lockdown Browser` | 2.0.5 | Win32 | `Illuminate Education` |
|
| `Illuminate Lockdown Browser` | 2.0.5 | Win32 | `Illuminate Education` |
|
||||||
| `Immunet` | 7.5.8.21178 | Win32 | `Immunet` |
|
| `Immunet` | 7.5.8.21178 | Win32 | `Immunet` |
|
||||||
| `Impero Backdrop Client` | 4.4.86 | Win32 | `Impero Software` |
|
| `Impero Backdrop Client` | 4.4.86 | Win32 | `Impero Software` |
|
||||||
|
@ -53,7 +53,7 @@ The following settings can't be changed.
|
|||||||
| Allowed Account Types | Microsoft accounts and Azure AD accounts are allowed. |
|
| Allowed Account Types | Microsoft accounts and Azure AD accounts are allowed. |
|
||||||
| Virtual Desktops | Virtual Desktops are blocked. |
|
| Virtual Desktops | Virtual Desktops are blocked. |
|
||||||
| Microsoft Store | The Microsoft Store is blocked. |
|
| Microsoft Store | The Microsoft Store is blocked. |
|
||||||
| Administrative tools | Administrative tools, such as the command prompt and Windows PowerShell, can't be opened. Windows PowerShell scripts deployed using Microsoft Endpoint Manager can run. |
|
| Administrative tools | Administrative tools, such as the command prompt and Windows PowerShell, can't be opened. Windows PowerShell scripts deployed using Microsoft Intune can run. |
|
||||||
| Apps | Only certain apps are allowed to run on Windows 11 SE. For more info on what apps can run on Windows 11 SE, see [Windows 11 SE for Education overview](windows-11-se-overview.md). |
|
| Apps | Only certain apps are allowed to run on Windows 11 SE. For more info on what apps can run on Windows 11 SE, see [Windows 11 SE for Education overview](windows-11-se-overview.md). |
|
||||||
|
|
||||||
## Next steps
|
## Next steps
|
||||||
|
@ -16,7 +16,7 @@ ms.date: 07/21/2021
|
|||||||
# Acquire apps in Microsoft Store for Business and Education
|
# Acquire apps in Microsoft Store for Business and Education
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
||||||
|
@ -19,7 +19,7 @@ ms.localizationpriority: medium
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Windows Autopilot simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows Autopilot](/windows/deployment/windows-autopilot/windows-10-autopilot).
|
Windows Autopilot simplifies device set up for IT Admins. For an overview of benefits, scenarios, and prerequisites, see [Overview of Windows Autopilot](/windows/deployment/windows-autopilot/windows-10-autopilot).
|
||||||
|
|
||||||
|
@ -20,7 +20,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
You can manage all apps that you've acquired on your **Apps & software** page. This page shows all of the content you've acquired, including apps that from Microsoft Store, and line-of-business (LOB) apps that you've accepted into your inventory. After LOB apps are submitted to your organization, you'll see a notification on your **Apps & software** page. On the **New LOB apps** tab, you can accept, or reject the LOB apps. For more information on LOB apps, see [Working with line-of-business apps](working-with-line-of-business-apps.md). The inventory page includes apps acquired by all people in your organization with the Store for Business Admin role.
|
You can manage all apps that you've acquired on your **Apps & software** page. This page shows all of the content you've acquired, including apps that from Microsoft Store, and line-of-business (LOB) apps that you've accepted into your inventory. After LOB apps are submitted to your organization, you'll see a notification on your **Apps & software** page. On the **New LOB apps** tab, you can accept, or reject the LOB apps. For more information on LOB apps, see [Working with line-of-business apps](working-with-line-of-business-apps.md). The inventory page includes apps acquired by all people in your organization with the Store for Business Admin role.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Education has thousands of apps from many different categories.
|
Microsoft Store for Business and Education has thousands of apps from many different categories.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Admins, Purchasers, and Basic Purchasers can assign online-licensed apps to employees or students in their organization.
|
Admins, Purchasers, and Basic Purchasers can assign online-licensed apps to employees or students in their organization.
|
||||||
|
|
||||||
|
@ -17,7 +17,7 @@ manager: dansimp
|
|||||||
# Billing and payments
|
# Billing and payments
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Access invoices and managed your payment methods.
|
Access invoices and managed your payment methods.
|
||||||
|
|
||||||
|
@ -17,7 +17,7 @@ manager: dansimp
|
|||||||
# Understand billing profiles
|
# Understand billing profiles
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
For commercial customers purchasing software or hardware products from Microsoft using a Microsoft customer agreement, billing profiles let you customize what products are included on your invoice, and how you pay your invoices.
|
For commercial customers purchasing software or hardware products from Microsoft using a Microsoft customer agreement, billing profiles let you customize what products are included on your invoice, and how you pay your invoices.
|
||||||
|
|
||||||
|
@ -16,7 +16,7 @@ manager: dansimp
|
|||||||
# Understand your Microsoft Customer Agreement invoice
|
# Understand your Microsoft Customer Agreement invoice
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
The invoice provides a summary of your charges and provides instructions for payment. It's available for
|
The invoice provides a summary of your charges and provides instructions for payment. It's available for
|
||||||
download in the Portable Document Format (.pdf) for commercial customers from Microsoft Store for Business [Microsoft Store for Business - Invoice](https://businessstore.microsoft.com/manage/payments-billing/invoices) or can be sent via email. This article applies to invoices generated for a Microsoft Customer Agreement billing account. Check if you have a [Microsoft Customer Agreement](https://businessstore.microsoft.com/manage/organization/agreements).
|
download in the Portable Document Format (.pdf) for commercial customers from Microsoft Store for Business [Microsoft Store for Business - Invoice](https://businessstore.microsoft.com/manage/payments-billing/invoices) or can be sent via email. This article applies to invoices generated for a Microsoft Customer Agreement billing account. Check if you have a [Microsoft Customer Agreement](https://businessstore.microsoft.com/manage/organization/agreements).
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content.
|
For companies or organizations using mobile device management (MDM) tools, those tools can synchronize with Microsoft Store for Business inventory to manage apps with offline licenses. Store for Business management tool services work with your third-party management tool to manage content.
|
||||||
|
|
||||||
@ -45,6 +45,6 @@ After your management tool is added to your Azure AD directory, you can configur
|
|||||||
|
|
||||||
Your MDM tool is ready to use with Microsoft Store. To learn how to configure synchronization and deploy apps, see these topics:
|
Your MDM tool is ready to use with Microsoft Store. To learn how to configure synchronization and deploy apps, see these topics:
|
||||||
- [Manage apps you purchased from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business)
|
- [Manage apps you purchased from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business)
|
||||||
- [Manage apps from Microsoft Store for Business with Microsoft Endpoint Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
- [Manage apps from Microsoft Store for Business with Microsoft Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
||||||
|
|
||||||
For third-party MDM providers or management servers, check your product documentation.
|
For third-party MDM providers or management servers, check your product documentation.
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
The private store is a feature in Microsoft Store for Business and Education that organizations receive during the signup process. When admins add apps to the private store, all employees in the organization can view and download the apps. Your private store is available as a tab in Microsoft Store app, and is usually named for your company or organization. Only apps with online licenses can be added to the private store.
|
The private store is a feature in Microsoft Store for Business and Education that organizations receive during the signup process. When admins add apps to the private store, all employees in the organization can view and download the apps. Your private store is available as a tab in Microsoft Store app, and is usually named for your company or organization. Only apps with online licenses can be added to the private store.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Distribute apps to your employees from Microsoft Store for Business and Microsoft Store for Education. You can assign apps to employees, or let employees install them from your private store.
|
Distribute apps to your employees from Microsoft Store for Business and Microsoft Store for Education. You can assign apps to employees, or let employees install them from your private store.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
You can configure a mobile device management (MDM) tool to synchronize your Microsoft Store for Business or Microsoft Store for Education inventory. Microsoft Store management tool services work with MDM tools to manage content.
|
You can configure a mobile device management (MDM) tool to synchronize your Microsoft Store for Business or Microsoft Store for Education inventory. Microsoft Store management tool services work with MDM tools to manage content.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
>
|
>
|
||||||
Offline licensing is a new licensing option for Windows 10 with Microsoft Store for Business and Microsoft Store for Education. With offline licenses, organizations can download apps and their licenses to deploy within their network, or on devices that are not connected to the Internet. ISVs or devs can opt-in their apps for offline licensing when they submit them to the Windows Dev Center. Only apps that are opted in to offline licensing will show that they are available for offline licensing in Microsoft Store for Business and Microsoft Store for Education. This model allows organizations to deploy apps when users or devices do not have connectivity to the Store.
|
Offline licensing is a new licensing option for Windows 10 with Microsoft Store for Business and Microsoft Store for Education. With offline licenses, organizations can download apps and their licenses to deploy within their network, or on devices that are not connected to the Internet. ISVs or devs can opt-in their apps for offline licensing when they submit them to the Windows Dev Center. Only apps that are opted in to offline licensing will show that they are available for offline licensing in Microsoft Store for Business and Microsoft Store for Education. This model allows organizations to deploy apps when users or devices do not have connectivity to the Store.
|
||||||
|
|
||||||
@ -45,7 +45,7 @@ You can't distribute offline-licensed apps directly from Microsoft Store. Once y
|
|||||||
- **Create provisioning package**. You can use Windows Imaging and Configuration Designer (ICD) to create a provisioning package for your offline app. Once you have the package, there are options to [apply the provisioning package](/windows/configuration/provisioning-packages/provisioning-apply-package). For more information, see [Provisioning Packages for Windows 10](/windows/configuration/provisioning-packages/provisioning-packages).
|
- **Create provisioning package**. You can use Windows Imaging and Configuration Designer (ICD) to create a provisioning package for your offline app. Once you have the package, there are options to [apply the provisioning package](/windows/configuration/provisioning-packages/provisioning-apply-package). For more information, see [Provisioning Packages for Windows 10](/windows/configuration/provisioning-packages/provisioning-packages).
|
||||||
|
|
||||||
- **Mobile device management provider or management server.** You can use a mobile device management (MDM) provider or management server to distribute offline apps. For more information, see these topics:
|
- **Mobile device management provider or management server.** You can use a mobile device management (MDM) provider or management server to distribute offline apps. For more information, see these topics:
|
||||||
- [Manage apps from Microsoft Store for Business with Microsoft Endpoint Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
- [Manage apps from Microsoft Store for Business with Microsoft Configuration Manager](/configmgr/apps/deploy-use/manage-apps-from-the-windows-store-for-business)
|
||||||
- [Manage apps from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business)<br>
|
- [Manage apps from Microsoft Store for Business with Microsoft Intune](/mem/intune/apps/windows-store-for-business)<br>
|
||||||
|
|
||||||
For third-party MDM providers or management servers, check your product documentation.
|
For third-party MDM providers or management servers, check your product documentation.
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Use the Microsoft Store for Business and Education to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization.
|
Use the Microsoft Store for Business and Education to find apps for your organization. You can also work with developers to create line-of-business apps that are only available to your organization.
|
||||||
|
|
||||||
|
@ -1,3 +1,6 @@
|
|||||||
|
---
|
||||||
|
ms.date: 10/31/2020
|
||||||
|
---
|
||||||
<!-- This file is generated automatically each week. Changes made to this file will be overwritten.-->
|
<!-- This file is generated automatically each week. Changes made to this file will be overwritten.-->
|
||||||
|
|
||||||
|
|
||||||
|
@ -20,7 +20,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Welcome to the Microsoft Store for Business and Education! You can use Microsoft Store to find, acquire, distribute, and manage apps for your organization or school.
|
Welcome to the Microsoft Store for Business and Education! You can use Microsoft Store to find, acquire, distribute, and manage apps for your organization or school.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
You can manage access to your private store in Microsoft Store for Business and Microsoft Store for Education.
|
You can manage access to your private store in Microsoft Store for Business and Microsoft Store for Education.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Manage products and services in Microsoft Store for Business and Microsoft Store for Education. This includes apps, software, products, devices, and services available under **Products & services**.
|
Manage products and services in Microsoft Store for Business and Microsoft Store for Education. This includes apps, software, products, devices, and services available under **Products & services**.
|
||||||
|
|
||||||
|
@ -16,7 +16,7 @@ manager: dansimp
|
|||||||
# Manage app orders in Microsoft Store for Business and Education
|
# Manage app orders in Microsoft Store for Business and Education
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
After you've acquired apps, you can review order information and invoices on **Order history**. On this page, you can view invoices, and request refunds.
|
After you've acquired apps, you can review order information and invoices on **Order history**. On this page, you can view invoices, and request refunds.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.localizationpriority: medium
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
The private store is a feature in Microsoft Store for Business and Education that organizations receive during the sign up process. When admins add apps to the private store, all people in the organization can view and download the apps. Only online-licensed apps can be distributed from your private store.
|
The private store is a feature in Microsoft Store for Business and Education that organizations receive during the sign up process. When admins add apps to the private store, all people in the organization can view and download the apps. Only online-licensed apps can be distributed from your private store.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
You can add users and groups, as well as update some of the settings associated with the Azure Active Directory (AD) tenant.
|
You can add users and groups, as well as update some of the settings associated with the Azure Active Directory (AD) tenant.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Education manages permissions with a set of roles. Currently, you can [assign these roles to individuals in your organization](roles-and-permissions-microsoft-store-for-business.md), but not to groups.
|
Microsoft Store for Business and Education manages permissions with a set of roles. Currently, you can [assign these roles to individuals in your organization](roles-and-permissions-microsoft-store-for-business.md), but not to groups.
|
||||||
|
|
||||||
|
@ -19,7 +19,7 @@ manager: dansimp
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Education PowerShell module (preview) is now available on [PowerShell Gallery](https://go.microsoft.com/fwlink/?linkid=853459).
|
Microsoft Store for Business and Education PowerShell module (preview) is now available on [PowerShell Gallery](https://go.microsoft.com/fwlink/?linkid=853459).
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
||||||
|
@ -23,7 +23,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Microsoft Store for Education use a set of notifications to alert admins if there is an issue or outage with Microsoft Store.
|
Microsoft Store for Business and Microsoft Store for Education use a set of notifications to alert admins if there is an issue or outage with Microsoft Store.
|
||||||
|
|
||||||
|
@ -17,7 +17,7 @@ manager: dansimp
|
|||||||
# Payment methods
|
# Payment methods
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
You can purchase products and services from Microsoft Store for Business using your credit card. You can enter your credit card information on **Payment methods**, or when you purchase an app. We currently accept these credit cards:
|
You can purchase products and services from Microsoft Store for Business using your credit card. You can enter your credit card information on **Payment methods**, or when you purchase an app. We currently accept these credit cards:
|
||||||
- VISA
|
- VISA
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
||||||
|
@ -15,7 +15,7 @@ manager: dansimp
|
|||||||
# Microsoft Store for Business and Education release history
|
# Microsoft Store for Business and Education release history
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Education regularly releases new and improved features. Here's a summary of new or updated features in previous releases.
|
Microsoft Store for Business and Education regularly releases new and improved features. Here's a summary of new or updated features in previous releases.
|
||||||
|
|
||||||
|
@ -22,7 +22,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
> Starting on April 14th, 2021, only free apps will be available in Microsoft Store for Business and Education. For more information, see [Microsoft Store for Business and Education](index.md).
|
||||||
|
@ -17,7 +17,7 @@ ms.date: 07/21/2021
|
|||||||
# Settings reference: Microsoft Store for Business and Education
|
# Settings reference: Microsoft Store for Business and Education
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
|
|
||||||
The Microsoft Store for Business and Education has a group of settings that admins use to manage the store.
|
The Microsoft Store for Business and Education has a group of settings that admins use to manage the store.
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
IT admins can sign up for Microsoft Store for Business and Education, and get started working with apps.
|
IT admins can sign up for Microsoft Store for Business and Education, and get started working with apps.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Troubleshooting topics for Microsoft Store for Business.
|
Troubleshooting topics for Microsoft Store for Business.
|
||||||
|
|
||||||
@ -53,7 +53,7 @@ The private store for your organization is a page in Microsoft Store app that co
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
## Troubleshooting Microsoft Store for Business integration with Microsoft Endpoint Configuration Manager
|
## Troubleshooting Microsoft Store for Business integration with Microsoft Configuration Manager
|
||||||
|
|
||||||
If you encounter any problems when integrating Microsoft Store for Business with Configuration Manager, use the [troubleshooting guide](/troubleshoot/mem/configmgr/troubleshoot-microsoft-store-for-business-integration).
|
If you encounter any problems when integrating Microsoft Store for Business with Configuration Manager, use the [troubleshooting guide](/troubleshoot/mem/configmgr/troubleshoot-microsoft-store-for-business-integration).
|
||||||
|
|
||||||
|
@ -17,7 +17,7 @@ manager: dansimp
|
|||||||
# Update Billing account settings
|
# Update Billing account settings
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
A billing account contains defining information about your organization.
|
A billing account contains defining information about your organization.
|
||||||
|
|
||||||
|
@ -15,7 +15,7 @@ manager: dansimp
|
|||||||
# What's new in Microsoft Store for Business and Education
|
# What's new in Microsoft Store for Business and Education
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Microsoft Store for Business and Education regularly releases new and improved features.
|
Microsoft Store for Business and Education regularly releases new and improved features.
|
||||||
|
|
||||||
|
@ -21,7 +21,7 @@ ms.date: 07/21/2021
|
|||||||
- Windows 10
|
- Windows 10
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Endpoint Manager integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
> Microsoft Store for Business and Microsoft Store for Education will be retired in the first quarter of 2023. You can continue to use the current capabilities of free apps until that time. For more information about this change, see [Update to Intune integration with the Microsoft Store on Windows](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/update-to-endpoint-manager-integration-with-the-microsoft-store/ba-p/3585077) and [FAQ: Supporting Microsoft Store experiences on managed devices](https://techcommunity.microsoft.com/t5/windows-management/faq-supporting-microsoft-store-experiences-on-managed-devices/m-p/3585286).
|
||||||
|
|
||||||
Your company or school can make line-of-business (LOB) applications available through Microsoft Store for Business or Microsoft Store for Education. These apps are custom to your school or organization – they might be internal apps, or apps specific to your school, business, or industry.
|
Your company or school can make line-of-business (LOB) applications available through Microsoft Store for Business or Microsoft Store for Education. These apps are custom to your school or organization – they might be internal apps, or apps specific to your school, business, or industry.
|
||||||
|
|
||||||
|
@ -290,4 +290,4 @@ Always include alt text for accessibility, and always end it with a period.
|
|||||||
## docs.ms extensions
|
## docs.ms extensions
|
||||||
|
|
||||||
> [!div class="nextstepaction"]
|
> [!div class="nextstepaction"]
|
||||||
> [Microsoft Endpoint Configuration Manager documentation](https://learn.microsoft.com/mem/configmgr)
|
> [Microsoft Configuration Manager documentation](https://learn.microsoft.com/mem/configmgr)
|
||||||
|
@ -65,7 +65,7 @@ To install the Company Portal app, you have some options:
|
|||||||
|
|
||||||
- **Use Windows Autopilot**: Windows Autopilot automatically provisions devices, registers them in your Azure AD organization (tenant), and gets them ready for production. If you're purchasing new devices, then we recommend using Windows Autopilot to preconfigure the devices, and get them ready for use.
|
- **Use Windows Autopilot**: Windows Autopilot automatically provisions devices, registers them in your Azure AD organization (tenant), and gets them ready for production. If you're purchasing new devices, then we recommend using Windows Autopilot to preconfigure the devices, and get them ready for use.
|
||||||
|
|
||||||
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), you add the Company Portal app from the Microsoft Store. Once it's added, the app can be included in your Windows Autopilot deployment. When the device turns on and is getting ready, the Company Portal app is also installed, before users sign in.
|
- In the [Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), you add the Company Portal app from the Microsoft Store. Once it's added, the app can be included in your Windows Autopilot deployment. When the device turns on and is getting ready, the Company Portal app is also installed, before users sign in.
|
||||||
|
|
||||||
- When the Company Portal app is installed from the Microsoft Store app, by default, it's automatically updated. Users can also open the Microsoft Store app, go to the **Library**, and check for updates.
|
- When the Company Portal app is installed from the Microsoft Store app, by default, it's automatically updated. Users can also open the Microsoft Store app, go to the **Library**, and check for updates.
|
||||||
|
|
||||||
@ -82,17 +82,17 @@ To install the Company Portal app, you have some options:
|
|||||||
|
|
||||||
## Customize the Company Portal app
|
## Customize the Company Portal app
|
||||||
|
|
||||||
Many organizations customize the Company Portal app to include their specific information. In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), you can customize the Company Portal app. For example, you can add a brand logo, include support information, add self-service device actions, and more.
|
Many organizations customize the Company Portal app to include their specific information. In the [Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), you can customize the Company Portal app. For example, you can add a brand logo, include support information, add self-service device actions, and more.
|
||||||
|
|
||||||
For more information, see [Configure the Intune Company Portal app](/mem/intune/apps/company-portal-app).
|
For more information, see [Configure the Intune Company Portal app](/mem/intune/apps/company-portal-app).
|
||||||
|
|
||||||
## Add your organization apps to the Company Portal app
|
## Add your organization apps to the Company Portal app
|
||||||
|
|
||||||
When you add an app in the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), there's a **Show this as a featured app in the Company Portal** setting. Be sure you use this setting.
|
When you add an app in the [Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), there's a **Show this as a featured app in the Company Portal** setting. Be sure you use this setting.
|
||||||
|
|
||||||
On co-managed devices (Microsoft Intune + Configuration Manager together), your Configuration Manager apps can also be shown in the Company Portal app. For more information, see [Use the Company Portal app on co-managed devices](/mem/configmgr/comanage/company-portal).
|
On co-managed devices (Microsoft Intune + Configuration Manager together), your Configuration Manager apps can also be shown in the Company Portal app. For more information, see [Use the Company Portal app on co-managed devices](/mem/configmgr/comanage/company-portal).
|
||||||
|
|
||||||
When the apps are shown, users can select and download the apps on their devices. You can add Microsoft Store apps, web apps, Microsoft 365 apps, LOB apps, Win32 apps, and sideload apps. For more information on adding apps to the Endpoint Manager admin center, see:
|
When the apps are shown, users can select and download the apps on their devices. You can add Microsoft Store apps, web apps, Microsoft 365 apps, LOB apps, Win32 apps, and sideload apps. For more information on adding apps to the Intune admin center, see:
|
||||||
|
|
||||||
- [Add Microsoft 365 apps using Intune](/mem/intune/apps/apps-add-office365)
|
- [Add Microsoft 365 apps using Intune](/mem/intune/apps/apps-add-office365)
|
||||||
- [Add web apps using Intune](/mem/intune/apps/web-app)
|
- [Add web apps using Intune](/mem/intune/apps/web-app)
|
||||||
|
@ -8,7 +8,9 @@ manager: aaroncz
|
|||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.date: 03/28/2022
|
ms.date: 03/28/2022
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
---
|
---
|
||||||
|
|
||||||
|
@ -1,14 +1,16 @@
|
|||||||
---
|
---
|
||||||
title: Azure Active Directory integration with MDM
|
title: Azure Active Directory integration with MDM
|
||||||
description: Azure Active Directory is the world's largest enterprise cloud identity management service.
|
description: Azure Active Directory is the world's largest enterprise cloud identity management service.
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.date: 12/31/2017
|
ms.date: 12/31/2017
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -46,7 +48,7 @@ Azure AD Join also enables company owned devices to be automatically enrolled in
|
|||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Every user enabled for automatic MDM enrollment with Azure AD Join must be assigned a valid [Azure Active Directory Premium](/previous-versions/azure/dn499825(v=azure.100)) license.
|
> Every user enabled for automatic MDM enrollment with Azure AD Join must be assigned a valid [Azure Active Directory Premium](/previous-versions/azure/dn499825(v=azure.100)) license.
|
||||||
|
|
||||||
|
|
||||||
### BYOD scenario
|
### BYOD scenario
|
||||||
|
|
||||||
Windows 10 also introduces a simpler way to configure personal devices to access work apps and resources. Users can add their Microsoft work account to Windows and enjoy simpler and safer access to the apps and resources of the organization. During this process, Azure AD detects if the organization has configured an MDM. If that’s the case, Windows attempts to enroll the device in MDM as part of the “add account” flow. In the BYOD case, users can reject the MDM Terms of Use. The device isn't enrolled in MDM and access to organization resources is typically restricted.
|
Windows 10 also introduces a simpler way to configure personal devices to access work apps and resources. Users can add their Microsoft work account to Windows and enjoy simpler and safer access to the apps and resources of the organization. During this process, Azure AD detects if the organization has configured an MDM. If that’s the case, Windows attempts to enroll the device in MDM as part of the “add account” flow. In the BYOD case, users can reject the MDM Terms of Use. The device isn't enrolled in MDM and access to organization resources is typically restricted.
|
||||||
@ -70,7 +72,7 @@ Once a user has an Azure AD account added to Windows and enrolled in MDM, the en
|
|||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Users can't remove the device enrollment through the **Work access** user interface because management is tied to the Azure AD or work account.
|
> Users can't remove the device enrollment through the **Work access** user interface because management is tied to the Azure AD or work account.
|
||||||
|
|
||||||
|
|
||||||
### MDM endpoints involved in Azure AD–integrated enrollment
|
### MDM endpoints involved in Azure AD–integrated enrollment
|
||||||
|
|
||||||
Azure AD MDM enrollment is a two-step process:
|
Azure AD MDM enrollment is a two-step process:
|
||||||
@ -187,7 +189,7 @@ The following image show how MDM applications show up in the Azure app gallery.
|
|||||||
### Add cloud-based MDM to the app gallery
|
### Add cloud-based MDM to the app gallery
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> You should work with the Azure AD engineering team if your MDM application is cloud-based and needs to be enabled as a multi-tenant MDM application
|
> You should work with the Azure AD engineering team if your MDM application is cloud-based and needs to be enabled as a multi-tenant MDM application
|
||||||
|
|
||||||
The following table shows the required information to create an entry in the Azure AD app gallery.
|
The following table shows the required information to create an entry in the Azure AD app gallery.
|
||||||
|
|
||||||
@ -200,7 +202,7 @@ The following table shows the required information to create an entry in the Azu
|
|||||||
|**Icons**|A set of logo icons for the MDM app. Dimensions: 45 X 45, 150 X 122, 214 X 215|
|
|**Icons**|A set of logo icons for the MDM app. Dimensions: 45 X 45, 150 X 122, 214 X 215|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
### Add on-premises MDM to the app gallery
|
### Add on-premises MDM to the app gallery
|
||||||
|
|
||||||
There are no special requirements for adding on-premises MDM to the app gallery. There's a generic entry for administrators to add an app to their tenant.
|
There are no special requirements for adding on-premises MDM to the app gallery. There's a generic entry for administrators to add an app to their tenant.
|
||||||
@ -232,7 +234,7 @@ An MDM page must adhere to a predefined theme depending on the scenario that is
|
|||||||
|--- |--- |--- |--- |--- |
|
|--- |--- |--- |--- |--- |
|
||||||
|FRX|OOBE|Dark theme + blue background color|Filename: Ui-dark.css|Filename: oobe-dekstop.css|
|
|FRX|OOBE|Dark theme + blue background color|Filename: Ui-dark.css|Filename: oobe-dekstop.css|
|
||||||
|MOSET|Settings/Post OOBE|Light theme|Filename: Ui-light.css|Filename: settings-desktop.css|
|
|MOSET|Settings/Post OOBE|Light theme|Filename: Ui-light.css|Filename: settings-desktop.css|
|
||||||
|
|
||||||
## Terms of Use protocol semantics
|
## Terms of Use protocol semantics
|
||||||
|
|
||||||
The Terms of Use endpoint is hosted by the MDM server. During the Azure AD Join protocol flow, Windows does a full-page redirect to this endpoint. This redirect enables the MDM to display the terms and conditions that apply. It allows the user to accept or reject the terms associated with enrollment. After the user accepts the terms, the MDM redirects back to Windows for the enrollment process to continue.
|
The Terms of Use endpoint is hosted by the MDM server. During the Azure AD Join protocol flow, Windows does a full-page redirect to this endpoint. This redirect enables the MDM to display the terms and conditions that apply. It allows the user to accept or reject the terms associated with enrollment. After the user accepts the terms, the MDM redirects back to Windows for the enrollment process to continue.
|
||||||
@ -332,7 +334,7 @@ The following table shows the error codes.
|
|||||||
|Azure AD token validation failed|302|unauthorized_client|unauthorized_client|
|
|Azure AD token validation failed|302|unauthorized_client|unauthorized_client|
|
||||||
|internal service error|302|server_error|internal service error|
|
|internal service error|302|server_error|internal service error|
|
||||||
|
|
||||||
|
|
||||||
## Enrollment protocol with Azure AD
|
## Enrollment protocol with Azure AD
|
||||||
|
|
||||||
With Azure integrated MDM enrollment, there's no discovery phase and the discovery URL is directly passed down to the system from Azure. The following table shows the comparison between the traditional and Azure enrollments.
|
With Azure integrated MDM enrollment, there's no discovery phase and the discovery URL is directly passed down to the system from Azure. The following table shows the comparison between the traditional and Azure enrollments.
|
||||||
|
@ -11,12 +11,12 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
---
|
---
|
||||||
|
|
||||||
# Azure AD and Microsoft Intune: Automatic MDM enrollment in the Endpoint Manager admin center
|
# Azure AD and Microsoft Intune: Automatic MDM enrollment in the Intune admin center
|
||||||
|
|
||||||
Microsoft Intune can be accessed directly using its own admin center. For more information, go to:
|
Microsoft Intune can be accessed directly using its own admin center. For more information, go to:
|
||||||
|
|
||||||
- [Tutorial: Walkthrough Intune in Microsoft Endpoint Manager admin center](/mem/intune/fundamentals/tutorial-walkthrough-endpoint-manager)
|
- [Tutorial: Walkthrough Intune in Microsoft Intune admin center](/mem/intune/fundamentals/tutorial-walkthrough-endpoint-manager)
|
||||||
- Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
- Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
|
||||||
|
|
||||||
If you use the Azure portal, then you can access Intune using the following steps:
|
If you use the Azure portal, then you can access Intune using the following steps:
|
||||||
|
|
||||||
|
@ -41,7 +41,7 @@ Config lock isn't enabled by default, or turned on by the OS during boot. Rather
|
|||||||
The steps to turn on config lock using Microsoft Intune are as follows:
|
The steps to turn on config lock using Microsoft Intune are as follows:
|
||||||
|
|
||||||
1. Ensure that the device to turn on config lock is enrolled in Microsoft Intune.
|
1. Ensure that the device to turn on config lock is enrolled in Microsoft Intune.
|
||||||
1. In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Configuration Profiles** > **Create a profile**.
|
1. In the [Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), select **Devices** > **Configuration Profiles** > **Create a profile**.
|
||||||
1. Select the following and press **Create**:
|
1. Select the following and press **Create**:
|
||||||
- **Platform**: Windows 10 and later
|
- **Platform**: Windows 10 and later
|
||||||
- **Profile type**: Templates
|
- **Profile type**: Templates
|
||||||
|
@ -6,10 +6,12 @@ author: vinaypamnani-msft
|
|||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.date: 01/18/2022
|
ms.date: 01/18/2022
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -29,23 +31,23 @@ From its release, Windows 10 has supported remote connections to PCs joined to A
|
|||||||
## Set up
|
## Set up
|
||||||
|
|
||||||
- Both PCs (local and remote) must be running Windows 10, version 1607 or later. Remote connections to an Azure AD-joined PC running earlier versions of Windows 10 aren't supported.
|
- Both PCs (local and remote) must be running Windows 10, version 1607 or later. Remote connections to an Azure AD-joined PC running earlier versions of Windows 10 aren't supported.
|
||||||
- Your local PC (where you're connecting from) must be either Azure AD-joined or Hybrid Azure AD-joined if using Windows 10, version 1607 and above, or [Azure AD registered](/azure/active-directory/devices/concept-azure-ad-register) if using Windows 10, version 2004 and above. Remote connections to an Azure AD-joined PC from an unjoined device or a non-Windows 10 device aren't supported.
|
- Your local PC (where you're connecting from) must be either Azure AD-joined or Hybrid Azure AD-joined if using Windows 10, version 1607 and above, or [Azure AD registered](/azure/active-directory/devices/concept-azure-ad-register) if using Windows 10, version 2004 and above. Remote connections to an Azure AD-joined PC from an unjoined device or a non-Windows 10 device aren't supported.
|
||||||
- The local PC and remote PC must be in the same Azure AD tenant. Azure AD B2B guests aren't supported for Remote desktop.
|
- The local PC and remote PC must be in the same Azure AD tenant. Azure AD B2B guests aren't supported for Remote desktop.
|
||||||
|
|
||||||
Ensure [Remote Credential Guard](/windows/access-protection/remote-credential-guard), a new feature in Windows 10, version 1607, is turned off on the client PC you're using to connect to the remote PC.
|
Ensure [Remote Credential Guard](/windows/access-protection/remote-credential-guard), a new feature in Windows 10, version 1607, is turned off on the client PC you're using to connect to the remote PC.
|
||||||
|
|
||||||
- On the PC you want to connect to:
|
- On the PC you want to connect to:
|
||||||
|
|
||||||
1. Open system properties for the remote PC.
|
1. Open system properties for the remote PC.
|
||||||
|
|
||||||
2. Enable **Allow remote connections to this computer** and select **Allow connections only from computers running Remote Desktop with Network Level Authentication**.
|
2. Enable **Allow remote connections to this computer** and select **Allow connections only from computers running Remote Desktop with Network Level Authentication**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
3. If the user who joined the PC to Azure AD is the only one who is going to connect remotely, no other configuration is needed. To allow more users or groups to connect to the PC, you must allow remote connections for the specified users or groups. Users can be added either manually or through MDM policies:
|
3. If the user who joined the PC to Azure AD is the only one who is going to connect remotely, no other configuration is needed. To allow more users or groups to connect to the PC, you must allow remote connections for the specified users or groups. Users can be added either manually or through MDM policies:
|
||||||
|
|
||||||
- Adding users manually
|
- Adding users manually
|
||||||
|
|
||||||
You can specify individual Azure AD accounts for remote connections by running the following PowerShell cmdlet:
|
You can specify individual Azure AD accounts for remote connections by running the following PowerShell cmdlet:
|
||||||
```powershell
|
```powershell
|
||||||
net localgroup "Remote Desktop Users" /add "AzureAD\the-UPN-attribute-of-your-user"
|
net localgroup "Remote Desktop Users" /add "AzureAD\the-UPN-attribute-of-your-user"
|
||||||
@ -62,7 +64,7 @@ Ensure [Remote Credential Guard](/windows/access-protection/remote-credential-gu
|
|||||||
> Starting in Windows 10, version 1709, you can add other Azure AD users to the **Administrators** group on a device in **Settings** and restrict remote credentials to **Administrators**. If there's a problem connecting remotely, make sure that both devices are joined to Azure AD and that TPM is functioning properly on both devices.
|
> Starting in Windows 10, version 1709, you can add other Azure AD users to the **Administrators** group on a device in **Settings** and restrict remote credentials to **Administrators**. If there's a problem connecting remotely, make sure that both devices are joined to Azure AD and that TPM is functioning properly on both devices.
|
||||||
|
|
||||||
- Adding users using policy
|
- Adding users using policy
|
||||||
|
|
||||||
Starting in Windows 10, version 2004, you can add users to the Remote Desktop Users using MDM policies as described in [How to manage the local administrators group on Azure AD-joined devices](/azure/active-directory/devices/assign-local-admin#manage-administrator-privileges-using-azure-ad-groups-preview).
|
Starting in Windows 10, version 2004, you can add users to the Remote Desktop Users using MDM policies as described in [How to manage the local administrators group on Azure AD-joined devices](/azure/active-directory/devices/assign-local-admin#manage-administrator-privileges-using-azure-ad-groups-preview).
|
||||||
|
|
||||||
> [!TIP]
|
> [!TIP]
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Mobile device management MDM for device updates
|
title: Mobile device management MDM for device updates
|
||||||
description: Windows 10 provides several APIs to help mobile device management (MDM) solutions manage updates. Learn how to use these APIs to implement update management.
|
description: Windows 10 provides several APIs to help mobile device management (MDM) solutions manage updates. Learn how to use these APIs to implement update management.
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
@ -9,7 +9,9 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 11/15/2017
|
ms.date: 11/15/2017
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Mobile device management (MDM) for device updates
|
# Mobile device management (MDM) for device updates
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Diagnose MDM failures in Windows 10
|
title: Diagnose MDM failures in Windows 10
|
||||||
description: Learn how to collect MDM logs. Examining these logs can help diagnose enrollment or device management issues in Windows 10 devices managed by an MDM server.
|
description: Learn how to collect MDM logs. Examining these logs can help diagnose enrollment or device management issues in Windows 10 devices managed by an MDM server.
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
@ -9,7 +9,9 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 06/25/2018
|
ms.date: 06/25/2018
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Diagnose MDM failures in Windows 10
|
# Diagnose MDM failures in Windows 10
|
||||||
|
@ -7,9 +7,11 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 04/30/2022
|
ms.date: 04/30/2022
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Enroll a Windows 10 device automatically using Group Policy
|
# Enroll a Windows 10 device automatically using Group Policy
|
||||||
@ -188,19 +190,19 @@ Requirements:
|
|||||||
- 1903 --> [Administrative Templates (.admx) for Windows 10 May 2019 Update (1903)](https://www.microsoft.com/download/details.aspx?id=58495)
|
- 1903 --> [Administrative Templates (.admx) for Windows 10 May 2019 Update (1903)](https://www.microsoft.com/download/details.aspx?id=58495)
|
||||||
|
|
||||||
- 1909 --> [Administrative Templates (.admx) for Windows 10 November 2019 Update (1909)](https://www.microsoft.com/download/confirmation.aspx?id=100591)
|
- 1909 --> [Administrative Templates (.admx) for Windows 10 November 2019 Update (1909)](https://www.microsoft.com/download/confirmation.aspx?id=100591)
|
||||||
|
|
||||||
- 2004 --> [Administrative Templates (.admx) for Windows 10 May 2020 Update (2004)](https://www.microsoft.com/download/confirmation.aspx?id=101445)
|
- 2004 --> [Administrative Templates (.admx) for Windows 10 May 2020 Update (2004)](https://www.microsoft.com/download/confirmation.aspx?id=101445)
|
||||||
|
|
||||||
- 20H2 --> [Administrative Templates (.admx) for Windows 10 October 2020 Update (20H2)](https://www.microsoft.com/download/details.aspx?id=102157)
|
- 20H2 --> [Administrative Templates (.admx) for Windows 10 October 2020 Update (20H2)](https://www.microsoft.com/download/details.aspx?id=102157)
|
||||||
|
|
||||||
- 21H1 --> [Administrative Templates (.admx) for Windows 10 May 2021 Update (21H1)](https://www.microsoft.com/download/details.aspx?id=103124)
|
- 21H1 --> [Administrative Templates (.admx) for Windows 10 May 2021 Update (21H1)](https://www.microsoft.com/download/details.aspx?id=103124)
|
||||||
|
|
||||||
- 21H2 --> [Administrative Templates (.admx) for Windows 10 November 2021 Update (21H2)-v2.0](https://www.microsoft.com/download/details.aspx?id=104042)
|
- 21H2 --> [Administrative Templates (.admx) for Windows 10 November 2021 Update (21H2)-v2.0](https://www.microsoft.com/download/details.aspx?id=104042)
|
||||||
|
|
||||||
- 22H2 --> [Administrative Templates (.admx) for Windows 10 October 2022 Update (22H2)](https://www.microsoft.com/download/104677)
|
- 22H2 --> [Administrative Templates (.admx) for Windows 10 October 2022 Update (22H2)](https://www.microsoft.com/download/104677)
|
||||||
|
|
||||||
- 22H2 --> [Administrative Templates (.admx) for Windows 11 2022 September Update (22H2)](https://www.microsoft.com/download/details.aspx?id=104593)
|
- 22H2 --> [Administrative Templates (.admx) for Windows 11 2022 September Update (22H2)](https://www.microsoft.com/download/details.aspx?id=104593)
|
||||||
|
|
||||||
2. Install the package on the Domain Controller.
|
2. Install the package on the Domain Controller.
|
||||||
|
|
||||||
3. Navigate, depending on the version to the folder:
|
3. Navigate, depending on the version to the folder:
|
||||||
@ -214,13 +216,13 @@ Requirements:
|
|||||||
- 1909 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 November 2019 Update (1909)**
|
- 1909 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 November 2019 Update (1909)**
|
||||||
|
|
||||||
- 2004 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 May 2020 Update (2004)**
|
- 2004 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 May 2020 Update (2004)**
|
||||||
|
|
||||||
- 20H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 October 2020 Update (20H2)**
|
- 20H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 October 2020 Update (20H2)**
|
||||||
|
|
||||||
- 21H1 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 May 2021 Update (21H1)**
|
- 21H1 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 May 2021 Update (21H1)**
|
||||||
|
|
||||||
- 21H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 November 2021 Update V2 (21H2)**
|
- 21H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 November 2021 Update V2 (21H2)**
|
||||||
|
|
||||||
- 22H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 October 2022 Update (22H2)**
|
- 22H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 October 2022 Update (22H2)**
|
||||||
|
|
||||||
- 22H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 11 September 2022 Update (22H2)**
|
- 22H2 --> **C:\Program Files (x86)\Microsoft Group Policy\Windows 11 September 2022 Update (22H2)**
|
||||||
|
@ -11,6 +11,7 @@ metadata:
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
|
- tier1
|
||||||
author: aczechowski
|
author: aczechowski
|
||||||
ms.author: aaroncz
|
ms.author: aaroncz
|
||||||
manager: dougeby
|
manager: dougeby
|
||||||
|
@ -5,10 +5,12 @@ ms.prod: windows-client
|
|||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.date: 09/14/2021
|
ms.date: 09/14/2021
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -51,7 +53,7 @@ First, you create a default user profile with the customizations that you want,
|
|||||||
1. Sign in to a computer running Windows 10 as a member of the local Administrator group. Do not use a domain account.
|
1. Sign in to a computer running Windows 10 as a member of the local Administrator group. Do not use a domain account.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Use a lab or extra computer running a clean installation of Windows 10 to create a default user profile. Do not use a computer that is required for business (that is, a production computer). This process removes all domain accounts from the computer, including user profile folders.
|
> Use a lab or extra computer running a clean installation of Windows 10 to create a default user profile. Do not use a computer that is required for business (that is, a production computer). This process removes all domain accounts from the computer, including user profile folders.
|
||||||
|
|
||||||
1. Configure the computer settings that you want to include in the user profile. For example, you can configure settings for the desktop background, uninstall default apps, install line-of-business apps, and so on.
|
1. Configure the computer settings that you want to include in the user profile. For example, you can configure settings for the desktop background, uninstall default apps, install line-of-business apps, and so on.
|
||||||
|
|
||||||
|
@ -1,17 +1,19 @@
|
|||||||
---
|
---
|
||||||
title: MDM enrollment of Windows 10-based devices
|
title: MDM enrollment of Windows 10-based devices
|
||||||
description: Learn about mobile device management (MDM) enrollment of Windows 10-based devices to simplify access to your organization’s resources.
|
description: Learn about mobile device management (MDM) enrollment of Windows 10-based devices to simplify access to your organization’s resources.
|
||||||
MS-HAID:
|
MS-HAID:
|
||||||
- 'p\_phdevicemgmt.enrollment\_ui'
|
- 'p\_phdevicemgmt.enrollment\_ui'
|
||||||
- 'p\_phDeviceMgmt.mdm\_enrollment\_of\_windows\_devices'
|
- 'p\_phDeviceMgmt.mdm\_enrollment\_of\_windows\_devices'
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.date: 12/31/2017
|
ms.date: 12/31/2017
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -35,7 +37,7 @@ Devices running Windows 10 Pro, Windows 10 Enterprise, or Windows 10 Educatio
|
|||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Mobile devices can't be connected to an Active Directory domain.
|
> Mobile devices can't be connected to an Active Directory domain.
|
||||||
|
|
||||||
### Out-of-box-experience
|
### Out-of-box-experience
|
||||||
|
|
||||||
Joining your device to an Active Directory domain during the out-of-box-experience (OOBE) isn't supported. To join a domain:
|
Joining your device to an Active Directory domain during the out-of-box-experience (OOBE) isn't supported. To join a domain:
|
||||||
|
|
||||||
@ -90,7 +92,7 @@ There are a few instances where your device can't be connected to an Active Dire
|
|||||||
| You're logged in as a standard user. | Your device can only be connected to an Azure AD domain if you're logged in as an administrative user. You’ll need to switch to an administrator account to continue. |
|
| You're logged in as a standard user. | Your device can only be connected to an Azure AD domain if you're logged in as an administrative user. You’ll need to switch to an administrator account to continue. |
|
||||||
| Your device is running Windows 10 Home. | This feature isn't available on Windows 10 Home, so you'll be unable to connect to an Active Directory domain. You'll need to upgrade to Windows 10 Pro, Windows 10 Enterprise, or Windows 10 Education to continue. |
|
| Your device is running Windows 10 Home. | This feature isn't available on Windows 10 Home, so you'll be unable to connect to an Active Directory domain. You'll need to upgrade to Windows 10 Pro, Windows 10 Enterprise, or Windows 10 Education to continue. |
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
### Connect your device to an Azure AD domain (join Azure AD)
|
### Connect your device to an Azure AD domain (join Azure AD)
|
||||||
|
|
||||||
@ -167,9 +169,9 @@ There are a few instances where your device can't be connected to an Azure AD do
|
|||||||
| Your device is already managed by MDM. | The connect to Azure AD flow will attempt to enroll your device into MDM if your Azure AD tenant has a preconfigured MDM endpoint. Your device must be unenrolled from MDM to be able to connect to Azure AD in this case. |
|
| Your device is already managed by MDM. | The connect to Azure AD flow will attempt to enroll your device into MDM if your Azure AD tenant has a preconfigured MDM endpoint. Your device must be unenrolled from MDM to be able to connect to Azure AD in this case. |
|
||||||
| Your device is running Windows 10 Home. | This feature isn't available on Windows 10 Home, so you'll be unable to connect to an Azure AD domain. You'll need to upgrade to Windows 10 Pro, Windows 10 Enterprise, or Windows 10 Education to continue. |
|
| Your device is running Windows 10 Home. | This feature isn't available on Windows 10 Home, so you'll be unable to connect to an Azure AD domain. You'll need to upgrade to Windows 10 Pro, Windows 10 Enterprise, or Windows 10 Education to continue. |
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## Connect personally owned devices
|
|
||||||
|
## Connect personally owned devices
|
||||||
|
|
||||||
|
|
||||||
Personally owned devices, also known as bring your own device (BYOD), can be connected to a work or school account, or to MDM. Windows 10 doesn't require a personal Microsoft account on devices to connect to work or school.
|
Personally owned devices, also known as bring your own device (BYOD), can be connected to a work or school account, or to MDM. Windows 10 doesn't require a personal Microsoft account on devices to connect to work or school.
|
||||||
@ -247,7 +249,7 @@ To create a local account and connect the device:
|
|||||||

|

|
||||||
|
|
||||||
After you complete the flow, your device will be connected to your organization’s MDM.
|
After you complete the flow, your device will be connected to your organization’s MDM.
|
||||||
|
|
||||||
### Help with connecting personally owned devices
|
### Help with connecting personally owned devices
|
||||||
|
|
||||||
There are a few instances where your device may not be able to connect to work.
|
There are a few instances where your device may not be able to connect to work.
|
||||||
@ -260,7 +262,7 @@ There are a few instances where your device may not be able to connect to work.
|
|||||||
| You don’t have the right privileges to perform this operation. Talk to your admin. | You can't enroll your device into MDM as a standard user. You must be on an administrator account. |
|
| You don’t have the right privileges to perform this operation. Talk to your admin. | You can't enroll your device into MDM as a standard user. You must be on an administrator account. |
|
||||||
| We couldn’t auto-discover a management endpoint matching the username entered. Check your username and try again. If you know the URL to your management endpoint, enter it. | You need to provide the server URL for your MDM or check the spelling of the username you entered. |
|
| We couldn’t auto-discover a management endpoint matching the username entered. Check your username and try again. If you know the URL to your management endpoint, enter it. | You need to provide the server URL for your MDM or check the spelling of the username you entered. |
|
||||||
|
|
||||||
|
|
||||||
## Connect your Windows 10-based device to work using a deep link
|
## Connect your Windows 10-based device to work using a deep link
|
||||||
|
|
||||||
|
|
||||||
@ -283,13 +285,13 @@ The deep link used for connecting your device to work will always use the follow
|
|||||||
| ownership | Custom parameter for MDM servers to use as they see fit. Typically, this parameter's value can be used to determine whether the device is BYOD or Corp Owned. Added in Windows 10, version 1703. | 1, 2, or 3. Where "1" means ownership is unknown, "2" means the device is personally owned, and "3" means the device is corporate-owned |
|
| ownership | Custom parameter for MDM servers to use as they see fit. Typically, this parameter's value can be used to determine whether the device is BYOD or Corp Owned. Added in Windows 10, version 1703. | 1, 2, or 3. Where "1" means ownership is unknown, "2" means the device is personally owned, and "3" means the device is corporate-owned |
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> AWA and Azure Active Directory-joined values for mode are only supported on Windows 10, version 1709 and later.
|
> AWA and Azure Active Directory-joined values for mode are only supported on Windows 10, version 1709 and later.
|
||||||
|
|
||||||
### Connect to MDM using a deep link
|
### Connect to MDM using a deep link
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Deep links only work with Internet Explorer or Microsoft Edge browsers. Examples of URI's that may be used to connect to MDM using a deep link:
|
> Deep links only work with Internet Explorer or Microsoft Edge browsers. Examples of URI's that may be used to connect to MDM using a deep link:
|
||||||
>
|
>
|
||||||
> - **ms-device-enrollment:?mode=mdm**
|
> - **ms-device-enrollment:?mode=mdm**
|
||||||
> - **ms-device-enrollment:?mode=mdm&username=`someone@example.com`&servername=`https://example.server.com`**
|
> - **ms-device-enrollment:?mode=mdm&username=`someone@example.com`&servername=`https://example.server.com`**
|
||||||
|
|
||||||
@ -342,7 +344,7 @@ Starting in Windows 10, version 1709, selecting the **Info** button will show a
|
|||||||

|

|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Starting in Windows 10, version 1709, the **Manage** button is no longer available.
|
> Starting in Windows 10, version 1709, the **Manage** button is no longer available.
|
||||||
|
|
||||||
### Disconnect
|
### Disconnect
|
||||||
|
|
||||||
@ -363,7 +365,7 @@ Starting in Windows 10, version 1709, you can get the advanced diagnostic report
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
@ -9,7 +9,9 @@ ms.localizationpriority: medium
|
|||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Mobile Device Management overview
|
# Mobile Device Management overview
|
||||||
|
@ -9,7 +9,9 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/18/2020
|
ms.date: 09/18/2020
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Configuration service provider DDF files
|
# Configuration service provider DDF files
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Configuration service provider support
|
title: Configuration service provider support
|
||||||
description: Learn more about configuration service provider (CSP) supported scenarios.
|
description: Learn more about configuration service provider (CSP) supported scenarios.
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
@ -9,7 +9,9 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/18/2020
|
ms.date: 09/18/2020
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Configuration service provider support
|
# Configuration service provider support
|
||||||
|
@ -7,9 +7,11 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 06/26/2017
|
ms.date: 06/26/2017
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# DynamicManagement CSP
|
# DynamicManagement CSP
|
||||||
|
@ -11,6 +11,7 @@ metadata:
|
|||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
|
- tier1
|
||||||
ms.custom: intro-hub-or-landing
|
ms.custom: intro-hub-or-landing
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
|
@ -836,7 +836,7 @@ Volume: Low.
|
|||||||
|
|
||||||
<!-- AccountLogonLogoff_AuditSpecialLogon-Description-Begin -->
|
<!-- AccountLogonLogoff_AuditSpecialLogon-Description-Begin -->
|
||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
This policy setting allows you to audit events generated by special logons such as the following : The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see [article 947223 in the Microsoft Knowledge Base](<https://go.microsoft.com/fwlink/?LinkId=121697>).
|
This policy setting allows you to audit events generated by special logons such as the following: The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see [article 947223 in the Microsoft Knowledge Base](<https://go.microsoft.com/fwlink/?LinkId=121697>).
|
||||||
<!-- AccountLogonLogoff_AuditSpecialLogon-Description-End -->
|
<!-- AccountLogonLogoff_AuditSpecialLogon-Description-End -->
|
||||||
|
|
||||||
<!-- AccountLogonLogoff_AuditSpecialLogon-Editable-Begin -->
|
<!-- AccountLogonLogoff_AuditSpecialLogon-Editable-Begin -->
|
||||||
@ -2774,7 +2774,7 @@ This policy setting allows you to audit events generated by attempts to access t
|
|||||||
- If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made.
|
- If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume High on domain controllers. For information about reducing the amount of events generated in this subcategory, see [article 841001 in the Microsoft Knowledge Base](https//go.microsoft.com/fwlink/?LinkId=121698).
|
> Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume High on domain controllers. For information about SACL, see [Access control lists](/windows/win32/secauthz/access-control-lists).
|
||||||
<!-- ObjectAccess_AuditSAM-Description-End -->
|
<!-- ObjectAccess_AuditSAM-Description-End -->
|
||||||
|
|
||||||
<!-- ObjectAccess_AuditSAM-Editable-Begin -->
|
<!-- ObjectAccess_AuditSAM-Editable-Begin -->
|
||||||
|
@ -1767,7 +1767,7 @@ _**Turn syncing off by default but don’t disable**_
|
|||||||
|
|
||||||
<!-- EnableOrganizationalMessages-Description-Begin -->
|
<!-- EnableOrganizationalMessages-Description-Begin -->
|
||||||
<!-- Description-Source-DDF -->
|
<!-- Description-Source-DDF -->
|
||||||
Organizational messages allow Administrators to deliver messages to their end users on selected Windows 11 experiences. Organizational messages are available to Administrators via services like Microsoft Endpoint Manager. By default, this policy is disabled.
|
Organizational messages allow Administrators to deliver messages to their end users on selected Windows 11 experiences. Organizational messages are available to Administrators via services like Microsoft Intune. By default, this policy is disabled.
|
||||||
- If you enable this policy, these experiences will show content booked by Administrators. Enabling this policy will have no impact on existing MDM policy settings governing delivery of content from Microsoft on Windows experiences.
|
- If you enable this policy, these experiences will show content booked by Administrators. Enabling this policy will have no impact on existing MDM policy settings governing delivery of content from Microsoft on Windows experiences.
|
||||||
<!-- EnableOrganizationalMessages-Description-End -->
|
<!-- EnableOrganizationalMessages-Description-End -->
|
||||||
|
|
||||||
|
@ -150,7 +150,7 @@ Descriptions of the properties:
|
|||||||
|
|
||||||
**Policy timeline**:
|
**Policy timeline**:
|
||||||
|
|
||||||
The behavior of this policy setting differs in different Windows 10 versions. For Windows 10, version 1809 through version 1909, you can use name in `<accessgroup dec>` and SID in `<member name>`. For Windows 10, version 2004, you can use name or SID for both the elements, as described in the example.
|
The behavior of this policy setting differs in different Windows 10 versions. For Windows 10, version 1809 through version 1909, you can use name in `<accessgroup desc>` and SID in `<member name>`. For Windows 10, version 2004, you can use name or SID for both the elements, as described in the example.
|
||||||
|
|
||||||
The following table describes how this policy setting behaves in different Windows 10 versions:
|
The following table describes how this policy setting behaves in different Windows 10 versions:
|
||||||
|
|
||||||
|
@ -40,6 +40,7 @@ WindowsAdvancedThreatProtection
|
|||||||
----Configuration
|
----Configuration
|
||||||
--------SampleSharing
|
--------SampleSharing
|
||||||
--------TelemetryReportingFrequency
|
--------TelemetryReportingFrequency
|
||||||
|
--------AadDdeviceId
|
||||||
----Offboarding
|
----Offboarding
|
||||||
----DeviceTagging
|
----DeviceTagging
|
||||||
--------Group
|
--------Group
|
||||||
@ -48,34 +49,34 @@ WindowsAdvancedThreatProtection
|
|||||||
|
|
||||||
The following list describes the characteristics and parameters.
|
The following list describes the characteristics and parameters.
|
||||||
|
|
||||||
<a href="" id="--device-vendor-msft-windowsadvancedthreatprotection"></a>**./Device/Vendor/MSFT/WindowsAdvancedThreatProtection**
|
**./Device/Vendor/MSFT/WindowsAdvancedThreatProtection**
|
||||||
The root node for the Windows Defender Advanced Threat Protection configuration service provider.
|
The root node for the Windows Defender Advanced Threat Protection configuration service provider.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
|
|
||||||
<a href="" id="onboarding"></a>**Onboarding**
|
**Onboarding**
|
||||||
Sets Windows Defender Advanced Threat Protection Onboarding blob and initiates onboarding to Windows Defender Advanced Threat Protection.
|
Sets Windows Defender Advanced Threat Protection Onboarding blob and initiates onboarding to Windows Defender Advanced Threat Protection.
|
||||||
|
|
||||||
The data type is a string.
|
The data type is a string.
|
||||||
|
|
||||||
Supported operations are Get and Replace.
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
<a href="" id="healthstate"></a>**HealthState**
|
**HealthState**
|
||||||
Node that represents the Windows Defender Advanced Threat Protection health state.
|
Node that represents the Windows Defender Advanced Threat Protection health state.
|
||||||
|
|
||||||
<a href="" id="healthstate-lastconnected"></a>**HealthState/LastConnected**
|
**HealthState/LastConnected**
|
||||||
Contains the timestamp of the last successful connection.
|
Contains the timestamp of the last successful connection.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
|
|
||||||
<a href="" id="healthstate-senseisrunning"></a>**HealthState/SenseIsRunning**
|
**HealthState/SenseIsRunning**
|
||||||
Boolean value that identifies the Windows Defender Advanced Threat Protection Sense running state.
|
Boolean value that identifies the Windows Defender Advanced Threat Protection Sense running state.
|
||||||
|
|
||||||
The default value is false.
|
The default value is false.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
|
|
||||||
<a href="" id="healthstate-onboardingstate"></a>**HealthState/OnboardingState**
|
**HealthState/OnboardingState**
|
||||||
Represents the onboarding state.
|
Represents the onboarding state.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
@ -85,15 +86,15 @@ The following list shows the supported values:
|
|||||||
- 0 (default) – Not onboarded
|
- 0 (default) – Not onboarded
|
||||||
- 1 – Onboarded
|
- 1 – Onboarded
|
||||||
|
|
||||||
<a href="" id="healthstate-orgid"></a>**HealthState/OrgId**
|
**HealthState/OrgId**
|
||||||
String that represents the OrgID.
|
String that represents the OrgID.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
|
|
||||||
<a href="" id="configuration"></a>**Configuration**
|
**Configuration**
|
||||||
Represents Windows Defender Advanced Threat Protection configuration.
|
Represents Windows Defender Advanced Threat Protection configuration.
|
||||||
|
|
||||||
<a href="" id="configuration-samplesharing"></a>**Configuration/SampleSharing**
|
**Configuration/SampleSharing**
|
||||||
Returns or sets the Windows Defender Advanced Threat Protection Sample Sharing configuration parameter.
|
Returns or sets the Windows Defender Advanced Threat Protection Sample Sharing configuration parameter.
|
||||||
|
|
||||||
The following list shows the supported values:
|
The following list shows the supported values:
|
||||||
@ -103,7 +104,7 @@ The following list shows the supported values:
|
|||||||
|
|
||||||
Supported operations are Get and Replace.
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
<a href="" id="configuration-telemetryreportingfrequency"></a>**Configuration/TelemetryReportingFrequency**
|
**Configuration/TelemetryReportingFrequency**
|
||||||
Added in Windows 10, version 1703. Returns or sets the Windows Defender Advanced Threat Protection diagnostic data reporting frequency.
|
Added in Windows 10, version 1703. Returns or sets the Windows Defender Advanced Threat Protection diagnostic data reporting frequency.
|
||||||
|
|
||||||
The following list shows the supported values:
|
The following list shows the supported values:
|
||||||
@ -113,26 +114,31 @@ The following list shows the supported values:
|
|||||||
|
|
||||||
Supported operations are Get and Replace.
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
<a href="" id="offboarding"></a>**Offboarding**
|
**Configuration/AadDeviceId**
|
||||||
|
Returns or sets the Intune's reported known AadDeviceId for the machine
|
||||||
|
|
||||||
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
|
**Offboarding**
|
||||||
Sets the Windows Defender Advanced Threat Protection Offboarding blob and initiates offboarding to Windows Defender Advanced Threat Protection.
|
Sets the Windows Defender Advanced Threat Protection Offboarding blob and initiates offboarding to Windows Defender Advanced Threat Protection.
|
||||||
|
|
||||||
The data type is a string.
|
The data type is a string.
|
||||||
|
|
||||||
Supported operations are Get and Replace.
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
<a href="" id="devicetagging"></a>**DeviceTagging**
|
**DeviceTagging**
|
||||||
Added in Windows 10, version 1709. Represents Windows Defender Advanced Threat Protection configuration for managing role based access and device tagging.
|
Added in Windows 10, version 1709. Represents Windows Defender Advanced Threat Protection configuration for managing role based access and device tagging.
|
||||||
|
|
||||||
Supported operation is Get.
|
Supported operation is Get.
|
||||||
|
|
||||||
<a href="" id="group"></a>**DeviceTagging/Group**
|
**DeviceTagging/Group**
|
||||||
Added in Windows 10, version 1709. Device group identifiers.
|
Added in Windows 10, version 1709. Device group identifiers.
|
||||||
|
|
||||||
The data type is a string.
|
The data type is a string.
|
||||||
|
|
||||||
Supported operations are Get and Replace.
|
Supported operations are Get and Replace.
|
||||||
|
|
||||||
<a href="" id="criticality"></a>**DeviceTagging/Criticality**
|
**DeviceTagging/Criticality**
|
||||||
Added in Windows 10, version 1709. Asset criticality value. Supported values:
|
Added in Windows 10, version 1709. Asset criticality value. Supported values:
|
||||||
|
|
||||||
- 0 - Normal
|
- 0 - Normal
|
||||||
@ -217,6 +223,16 @@ Supported operations are Get and Replace.
|
|||||||
</Target>
|
</Target>
|
||||||
</Item>
|
</Item>
|
||||||
</Get>
|
</Get>
|
||||||
|
<Get>
|
||||||
|
<CmdID>7</CmdID>
|
||||||
|
<Item>
|
||||||
|
<Target>
|
||||||
|
<LocURI>
|
||||||
|
./Device/Vendor/MSFT/WindowsAdvancedThreatProtection/Configuration/AadDeviceId
|
||||||
|
</LocURI>
|
||||||
|
</Target>
|
||||||
|
</Item>
|
||||||
|
</Get>
|
||||||
<Get>
|
<Get>
|
||||||
<CmdID>11</CmdID>
|
<CmdID>11</CmdID>
|
||||||
<Item>
|
<Item>
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Mobile device enrollment
|
title: Mobile device enrollment
|
||||||
description: Learn how mobile device enrollment verifies that only authenticated and authorized devices can be managed by their enterprise.
|
description: Learn how mobile device enrollment verifies that only authenticated and authorized devices can be managed by their enterprise.
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
@ -9,7 +9,9 @@ ms.prod: windows-client
|
|||||||
ms.technology: itpro-manage
|
ms.technology: itpro-manage
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 08/11/2017
|
ms.date: 08/11/2017
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
---
|
---
|
||||||
|
|
||||||
# Mobile device enrollment
|
# Mobile device enrollment
|
||||||
|
@ -9,7 +9,9 @@ author: vinaypamnani-msft
|
|||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.reviewer: pmadrigal
|
ms.reviewer: pmadrigal
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier1
|
||||||
ms.date: 08/26/2022
|
ms.date: 08/26/2022
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -120,13 +122,13 @@ For more information, visit [Install Quick Assist](https://support.microsoft.com
|
|||||||
|
|
||||||
Before installing Quick Assist, you'll need to set up synchronization between Intune and Microsoft Store for Business. If you've already set up sync, log into [Microsoft Store for Business](https://businessstore.microsoft.com) and skip to step 5.
|
Before installing Quick Assist, you'll need to set up synchronization between Intune and Microsoft Store for Business. If you've already set up sync, log into [Microsoft Store for Business](https://businessstore.microsoft.com) and skip to step 5.
|
||||||
|
|
||||||
1. In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Tenant administration** / **Connectors and tokens** / **Microsoft Store for Business** and verify that **Microsoft Store for Business sync** is set to **Enable**.
|
1. In the [Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Tenant administration** / **Connectors and tokens** / **Microsoft Store for Business** and verify that **Microsoft Store for Business sync** is set to **Enable**.
|
||||||
1. Using your Global Admin account, log into [Microsoft Store for Business](https://businessstore.microsoft.com).
|
1. Using your Global Admin account, log into [Microsoft Store for Business](https://businessstore.microsoft.com).
|
||||||
1. Select **Manage** / **Settings** and turn on **Show offline apps**.
|
1. Select **Manage** / **Settings** and turn on **Show offline apps**.
|
||||||
1. Choose the **Distribute** tab and verify that **Microsoft Intune** is **Active**. You may need to use the **+Add management tool** link if it's not.
|
1. Choose the **Distribute** tab and verify that **Microsoft Intune** is **Active**. You may need to use the **+Add management tool** link if it's not.
|
||||||
1. Search for **Quick Assist** and select it from the Search results.
|
1. Search for **Quick Assist** and select it from the Search results.
|
||||||
1. Choose the **Offline** license and select **Get the app**
|
1. Choose the **Offline** license and select **Get the app**
|
||||||
1. In the Endpoint Manager admin center, choose **Sync**.
|
1. In the Intune admin center, choose **Sync**.
|
||||||
1. Navigate to **Apps** / **Windows** and you should see **Quick Assist (Offline)** in the list.
|
1. Navigate to **Apps** / **Windows** and you should see **Quick Assist (Offline)** in the list.
|
||||||
1. Select it to view its properties. By default, the app won't be assigned to anyone or any devices, select the **Edit** link.
|
1. Select it to view its properties. By default, the app won't be assigned to anyone or any devices, select the **Edit** link.
|
||||||
1. Assign the app to the required group of devices and choose **Review + save** to complete the application install.
|
1. Assign the app to the required group of devices and choose **Review + save** to complete the application install.
|
||||||
|
@ -1,10 +1,7 @@
|
|||||||
---
|
---
|
||||||
title: Configure Windows 10 taskbar (Windows 10)
|
title: Configure Windows 10 taskbar
|
||||||
description: Administrators can pin more apps to the taskbar and remove default pinned apps from the taskbar by adding a section to a layout modification XML file.
|
description: Administrators can pin more apps to the taskbar and remove default pinned apps from the taskbar by adding a section to a layout modification XML file.
|
||||||
keywords: [taskbar layout, pin apps]
|
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: manage
|
|
||||||
ms.sitesec: library
|
|
||||||
author: lizgt2000
|
author: lizgt2000
|
||||||
ms.author: lizlong
|
ms.author: lizlong
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
@ -12,9 +9,12 @@ ms.localizationpriority: medium
|
|||||||
ms.date: 01/18/2018
|
ms.date: 01/18/2018
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.collection: highpri
|
ms.collection:
|
||||||
|
- highpri
|
||||||
|
- tier2
|
||||||
ms.technology: itpro-configure
|
ms.technology: itpro-configure
|
||||||
---
|
---
|
||||||
|
|
||||||
# Configure Windows 10 taskbar
|
# Configure Windows 10 taskbar
|
||||||
|
|
||||||
Starting in Windows 10, version 1607, administrators can pin more apps to the taskbar and remove default pinned apps from the taskbar by adding a `<TaskbarLayout>` section to a layout modification XML file. This method never removes user-pinned apps from the taskbar.
|
Starting in Windows 10, version 1607, administrators can pin more apps to the taskbar and remove default pinned apps from the taskbar by adding a `<TaskbarLayout>` section to a layout modification XML file. This method never removes user-pinned apps from the taskbar.
|
||||||
|
@ -2,6 +2,7 @@
|
|||||||
title: Send feedback about Cortana at work back to Microsoft
|
title: Send feedback about Cortana at work back to Microsoft
|
||||||
description: Learn how to send feedback to Microsoft about Cortana at work so you can provide more information to help diagnose reported issues.
|
description: Learn how to send feedback to Microsoft about Cortana at work so you can provide more information to help diagnose reported issues.
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
|
ms.collection: tier3
|
||||||
author: aczechowski
|
author: aczechowski
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.author: aaroncz
|
ms.author: aaroncz
|
||||||
|
@ -2,6 +2,7 @@
|
|||||||
title: Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization
|
title: Set up and test Cortana in Windows 10, versions 1909 and earlier, with Microsoft 365 in your organization
|
||||||
description: Learn how to connect Cortana to Office 365 so employees are notified about regular meetings and unusual events. You can even set an alarm for early meetings.
|
description: Learn how to connect Cortana to Office 365 so employees are notified about regular meetings and unusual events. You can even set an alarm for early meetings.
|
||||||
ms.prod: windows-client
|
ms.prod: windows-client
|
||||||
|
ms.collection: tier3
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: aczechowski
|
author: aczechowski
|
||||||
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
x
Reference in New Issue
Block a user