diff --git a/education/docfx.json b/education/docfx.json index eea7a3655b..cc2b912248 100644 --- a/education/docfx.json +++ b/education/docfx.json @@ -51,19 +51,16 @@ }, "titleSuffix": "Windows Education", "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", - "Kellylorenebaker", - "jborsecnik", - "dstrome", - "garycentric", - "v-stsavell", - "beccarobins", - "Stacyrch140", + "dstrome2", + "rjagiewich", "American-Dipper", + "claydetels19", + "jborsecnik", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome" ] }, "fileMetadata": { diff --git a/store-for-business/docfx.json b/store-for-business/docfx.json index 25f77170a7..4d87a128eb 100644 --- a/store-for-business/docfx.json +++ b/store-for-business/docfx.json @@ -55,19 +55,17 @@ } }, "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", - "Kellylorenebaker", - "jborsecnik", - "dstrome", - "garycentric", - "v-stsavell", - "beccarobins", - "Stacyrch140", + "dstrome2", + "rjagiewich", "American-Dipper", + "claydetels19", + "jborsecnik", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome", + "alekyaj" ] }, "fileMetadata": {}, @@ -75,4 +73,4 @@ "dest": "store-for-business", "markdownEngineName": "markdig" } -} \ No newline at end of file +} diff --git a/windows/application-management/docfx.json b/windows/application-management/docfx.json index aaf0200895..7b7f7eed47 100644 --- a/windows/application-management/docfx.json +++ b/windows/application-management/docfx.json @@ -52,17 +52,17 @@ }, "titleSuffix": "Windows Application Management", "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", - "jborsecnik", - "garycentric", - "beccarobins", - "Stacyrch140", - "v-stsavell", + "dstrome2", + "rjagiewich", "American-Dipper", + "claydetels19", + "jborsecnik", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome", + "beccarobins" ], "searchScope": [ "Windows 10" diff --git a/windows/client-management/docfx.json b/windows/client-management/docfx.json index 7cf011a598..07e6f430e8 100644 --- a/windows/client-management/docfx.json +++ b/windows/client-management/docfx.json @@ -58,17 +58,17 @@ }, "titleSuffix": "Windows Client Management", "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", + "dstrome2", + "rjagiewich", + "American-Dipper", + "claydetels19", "jborsecnik", - "garycentric", - "beccarobins", - "american-dipper", - "v-stsavell", - "stacyrch140", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome", + "beccarobins" ], "searchScope": [ "Windows 10" diff --git a/windows/client-management/mdm/policy-csp-admx-icm.md b/windows/client-management/mdm/policy-csp-admx-icm.md index 17e2fbb340..643e4044d3 100644 --- a/windows/client-management/mdm/policy-csp-admx-icm.md +++ b/windows/client-management/mdm/policy-csp-admx-icm.md @@ -1,7 +1,7 @@ --- title: ADMX_ICM Policy CSP description: Learn more about the ADMX_ICM Area in Policy CSP. -ms.date: 01/18/2024 +ms.date: 02/28/2024 --- @@ -843,7 +843,7 @@ Also see the "Configure Error Reporting", "Display Error Notification" and "Disa This policy setting allows you to remove access to Windows Update. -- If you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at , from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you'll neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website. +- If you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at `https://windowsupdate.microsoft.com`, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you'll neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website. - If you disable or don't configure this policy setting, users can access the Windows Update website and enable automatic updating to receive notifications and critical updates from Windows Update. diff --git a/windows/client-management/mdm/policy-csp-defender.md b/windows/client-management/mdm/policy-csp-defender.md index ce5814933e..ba4d3d7bde 100644 --- a/windows/client-management/mdm/policy-csp-defender.md +++ b/windows/client-management/mdm/policy-csp-defender.md @@ -712,7 +712,9 @@ Allows or disallows Windows Defender Realtime Monitoring functionality. -This policy setting allows you to configure real-time scanning for files that are accessed over the network. It is recommended to enable this setting. +This policy setting allows you to configure scheduled scans and on-demand (manually initiated) scans for files that are accessed over the network. It is recommended to enable this setting. +>[!NOTE] +> Real-time protection (on-access) scanning is not impacted by this policy. - If you enable this setting or do not configure this setting, network files will be scanned. - If you disable this setting, network files will not be scanned. diff --git a/windows/configuration/docfx.json b/windows/configuration/docfx.json index 2e2a420982..6bb76e2b5c 100644 --- a/windows/configuration/docfx.json +++ b/windows/configuration/docfx.json @@ -56,17 +56,18 @@ }, "titleSuffix": "Configure Windows", "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", - "jborsecnik", - "garycentric", - "beccarobins", - "Stacyrch140", - "v-stsavell", + "dstrome2", + "rjagiewich", "American-Dipper", + "claydetels19", + "jborsecnik", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome", + "beccarobins", + "alekyaj" ], "searchScope": [ "Windows 10" diff --git a/windows/deployment/deploy-enterprise-licenses.md b/windows/deployment/deploy-enterprise-licenses.md index c02e0390cd..4fde853386 100644 --- a/windows/deployment/deploy-enterprise-licenses.md +++ b/windows/deployment/deploy-enterprise-licenses.md @@ -11,7 +11,7 @@ ms.topic: how-to ms.collection: - highpri - tier2 -ms.date: 02/13/2024 +ms.date: 03/04/2024 zone_pivot_groups: windows-versions-11-10 appliesto: - ✅ Windows 11 @@ -65,7 +65,7 @@ To update contact information and resend the activation email, use the following 1. Update the contact information, then select **Update Contact Details**. This action triggers a new email. -## Preparing for deployment: reviewing requirements +## Prepare for deployment: reviewing requirements - Devices must be running a supported version of Windows Pro. - Microsoft Entra joined, or hybrid domain joined with Microsoft Entra Connect. Customers who are federated with Microsoft Entra ID are also eligible. @@ -82,7 +82,7 @@ For more information about integrating on-premises AD DS domains with Microsoft - [What is hybrid identity with Microsoft Entra ID?](/azure/active-directory/hybrid/whatis-hybrid-identity) - [Microsoft Entra Connect and Microsoft Entra Connect Health installation roadmap](/azure/active-directory/hybrid/how-to-connect-install-roadmap) -## Assigning licenses to users +## Assign licenses to users After the Windows subscription is ordered, an email is sent with guidance on how to use Windows as an online service. The following methods are available to assign licenses: @@ -292,15 +292,15 @@ Once the **System > Activation** pane is open: 1. Under **Activation state**, verify that Windows is activated. It should display the message: - `Windows is activated with a digital license` + `Windows is activated with a digital license` 1. Under **Subscription**, verify that the Windows 11 Enterprise subscription is active. It should display the message: - `Windows 11 Enterprise subscription is active` + `Windows 11 Enterprise subscription is active` - > [!NOTE] - > - > If the Windows Enterprise subscription hasn't yet been applied, the **Subscription** pane isn't displayed. + > [!NOTE] + > + > If the Windows Enterprise subscription hasn't yet been applied, the **Subscription** pane isn't displayed. ::: zone-end @@ -340,24 +340,24 @@ A device is healthy when both the subscription and activation are active. If the 1. To get basic licensing information, run the following command at the command prompt: - ```cmd - slmgr /dli - ``` + ```cmd + slmgr /dli + ``` - A window with output similar to the following opens: + A window with output similar to the following opens: - ```console - Name: Windows(R), Professional edition - Description: Windows(R) Operating System, RETAIL channel - Partial Product Key: 3V66T - License Status: Licensed - ``` + ```console + Name: Windows(R), Professional edition + Description: Windows(R) Operating System, RETAIL channel + Partial Product Key: 3V66T + License Status: Licensed + ``` - To instead get detailed licensing information, run the following command: +To instead get detailed licensing information, run the following command: - ```cmd - slmgr /dlv - ``` +```cmd +slmgr /dlv +``` For more information on **Slmgr**, see [Slmgr.vbs options for obtaining volume activation information](/windows-server/get-started/activation-slmgr-vbs-options). @@ -368,11 +368,11 @@ In some instances, users might experience problems with activation of the Window - The Windows Enterprise E3 or E5 subscription has lapsed, was removed, or isn't applied. - Windows Pro was never activated. -When there are problems with Windows Enterprise E3 or E5 subscription activation, the following are errors can occur in the [Activation](ms-settings:activation) pane: +When there are problems with Windows Enterprise E3 or E5 subscription activation, the following are errors can occur in the [**Activation**](ms-settings:activation) pane: - **Windows Pro isn't activated** - When Windows Pro isn't activated on a device, the following message is displayed for **Activation** in the [Activation](ms-settings:activation) pane: + When Windows Pro isn't activated on a device, the following message is displayed for **Activation** in the [**Activation**](ms-settings:activation) pane: `Windows is not activated` @@ -389,7 +389,7 @@ When there are problems with Windows Enterprise E3 or E5 subscription activation - **Windows Enterprise subscription isn't active** - When a device with a Windows Enterprise subscription has lapsed or has been removed, the following message is displayed for **Subscription** in the [Activation](ms-settings:activation) pane: + When a device with a Windows Enterprise subscription has lapsed or has been removed, the following message is displayed for **Subscription** in the [**Activation**](ms-settings:activation) pane: `Windows Enterprise subscription isn't valid.` @@ -482,45 +482,75 @@ Use the following guides to verify each one of these requirements: - **Make sure the Microsoft Entra user has been assigned a license**. - For more information, see [Assigning licenses to users](#assigning-licenses-to-users). + For more information, see [Assigning licenses to users](#assign-licenses-to-users). -## Known issues +## Recommended practices -- If a device isn't able to connect to Windows Update, it can lose activation status or be blocked from upgrading to Windows Enterprise. Make sure that Windows Update isn't blocked on the device: +### Adding Conditional Access policy - - Using `gpedit.msc` or group policy editor in the domain, make sure that the following group policy setting is set to **Disabled** or **Not Configured**: +When a device has been offline for an extended period of time, the Subscription Activation might not reactivate automatically on the device. To resolve this issue, use Conditional Access policies to control access by excluding one of the following cloud apps from their Conditional Access policies using **Select Excluded Cloud Apps**: - ::: zone pivot="windows-11" +- [Universal Store Service APIs and Web Application, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). - **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Update** > **Manage updates offered from Windows Server Update Service** > **Do not connect to any Windows Update Internet locations** +- [Windows Store for Business, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). - ::: zone-end +Although the app ID is the same in both instances, the name of the cloud app depends on the tenant. - ::: zone pivot="windows-10" +For more information about configuring exclusions in Conditional Access policies, see [Application exclusions](/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa#application-exclusions). - **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Update** > **Do not connect to any Windows Update Internet locations** + - ::: zone-end +Setting this Conditional Access policy ensures that Subscription Activation continues to work seamlessly. - If this policy is set to **Enabled**, it must be changed to **Disabled** or **Not Configured**. +Starting with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later, users are prompted for authentication with a toast notification when Subscription Activation needs to reactivate. The toast notification will show the following message: - - In the following registry key: +> **Your account requires authentication** +> +> **Please sign in to your work or school account to verify your information.** - `HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate` +Additionally, in the [**Activation**](ms-settings:activation) pane, the following message might appear: - check if the value `DoNotConnectToWindowsUpdateInternetLocations` exists. If the value does exist, verify that it has a REG_DWORD value of `0`. If the value is instead set to `1`, it must be changed to `0`. The value can be changed by running the following command from an elevated command prompt: +> **Please sign in to your work or school account to verify your information.** - ```cmd - reg.exe add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v DoNotConnectToWindowsUpdateInternetLocations /t REG_DWORD /d 1 /f - ``` +The prompt for authentication usually occurs when a device has been offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired. - > [!NOTE] - > - > Make sure to first check the group policy of **Do not connect to any Windows Update Internet locations**. If the policy is **Enabled**, then this registry key will eventually be reset back to `1` even after it's manually set to `0` via `reg.exe`. Setting the policy of **Do not connect to any Windows Update Internet locations** to **Disabled** or **Not Configured** will make sure the registry value remains as `0`. +### Make sure Windows Update isn't blocked -- Delay in the activation of Enterprise license of Windows. +If a device isn't able to connect to Windows Update, it can lose activation status or be blocked from upgrading to Windows Enterprise. Make sure that Windows Update isn't blocked on the device: - There might be a delay in the activation of the Enterprise license in Windows. This delay is by design. Windows uses a built-in cache when determining upgrade eligibility. This behavior includes processing responses that indicate that the device isn't eligible for an upgrade. It can take up to four days after a qualifying purchase before the upgrade eligibility is enabled and the cache expires. +- Using `gpedit.msc` or group policy editor in the domain, make sure that the following group policy setting is set to **Disabled** or **Not Configured**: + + ::: zone pivot="windows-11" + + **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Update** > **Manage updates offered from Windows Server Update Service** > **Do not connect to any Windows Update Internet locations** + + ::: zone-end + + ::: zone pivot="windows-10" + + **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Update** > **Do not connect to any Windows Update Internet locations** + + ::: zone-end + + If this policy is set to **Enabled**, it must be changed to **Disabled** or **Not Configured**. + +- In the following registry key of the registry: + + `HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate` + + check if the value `DoNotConnectToWindowsUpdateInternetLocations` exists. If the value does exist, verify that it has a REG_DWORD value of `0`. If the value is instead set to `1`, it must be changed to `0`. The value can be changed by running the following command from an elevated command prompt: + + ```cmd + reg.exe add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v DoNotConnectToWindowsUpdateInternetLocations /t REG_DWORD /d 1 /f + ``` + + > [!NOTE] + > + > Make sure to first check the group policy of **Do not connect to any Windows Update Internet locations**. If the policy is **Enabled**, then this registry key will eventually be reset back to `1` even after it's manually set to `0` via `reg.exe`. Setting the policy of **Do not connect to any Windows Update Internet locations** to **Disabled** or **Not Configured** will make sure the registry value remains as `0`. + +### Delay in the activation of Enterprise license of Windows + +There might be a delay in the activation of the Enterprise license in Windows. This delay is by design. Windows uses a built-in cache when determining upgrade eligibility. This behavior includes processing responses that indicate that the device isn't eligible for an upgrade. It can take up to four days after a qualifying purchase before the upgrade eligibility is enabled and the cache expires. ## Virtual Desktop Access (VDA) @@ -528,6 +558,7 @@ Subscriptions to Windows Enterprise are also available for virtualized clients. Virtual machines (VMs) must be configured to enable Windows Enterprise subscriptions for VDA. Active Directory-joined and Microsoft Entra joined clients are supported. For more information, see [Enable VDA for Enterprise subscription activation](vda-subscription-activation.md). -## Related articles +## Related content +- [Windows subscription activation](windows-subscription-activation.md). - [MDM enrollment of Windows devices](/windows/client-management/mdm-enrollment-of-windows-devices). diff --git a/windows/deployment/docfx.json b/windows/deployment/docfx.json index bec5d5f304..0ec95143b6 100644 --- a/windows/deployment/docfx.json +++ b/windows/deployment/docfx.json @@ -51,17 +51,17 @@ }, "titleSuffix": "Windows Deployment", "contributors_to_exclude": [ - "rjagiewich", - "claydetels19", - "jborsecnik", - "garycentric", - "beccarobins", - "Stacyrch140", - "v-stsavell", + "dstrome2", + "rjagiewich", "American-Dipper", + "claydetels19", + "jborsecnik", + "v-stchambers", "shdyas", - "alekyaj", - "rmca14" + "Stacyrch140", + "garycentric", + "dstrome", + "alekyaj" ], "searchScope": [ "Windows 10" diff --git a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md index 27c2f9f084..b7245596bf 100644 --- a/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md +++ b/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices.md @@ -62,7 +62,7 @@ An [Microsoft Entra dual state](/azure/active-directory/devices/hybrid-azuread-j In the dual state, you end up having two Microsoft Entra device records with different join types for the same device. In this case, the Hybrid Microsoft Entra device record takes precedence over the Microsoft Entra registered device record for any type of authentication in Microsoft Entra ID, which makes the Microsoft Entra registered device record stale. -It's recommended to detect and clean up stale devices in Microsoft Entra ID before registering devices with Windows Autopatch, see [How To: Manage state devices in Microsoft Entra ID](/azure/active-directory/devices/manage-stale-devices). +It's recommended to detect and clean up stale devices in Microsoft Entra ID before registering devices with Windows Autopatch, see [How To: Manage stale devices in Microsoft Entra ID](/azure/active-directory/devices/manage-stale-devices). > [!WARNING] > If you don't clean up stale devices in Microsoft Entra ID before registering devices with Windows Autopatch, you might end up seeing devices failing to meet the **Intune or Cloud-Attached (Device must be either Intune-managed or Co-managed)** pre-requisite check in the **Not ready** tab because it's expected that these stale Microsoft Entra devices aren't enrolled into the Intune service anymore. diff --git a/windows/deployment/windows-subscription-activation.md b/windows/deployment/windows-subscription-activation.md index 9c15d279f1..539f012a42 100644 --- a/windows/deployment/windows-subscription-activation.md +++ b/windows/deployment/windows-subscription-activation.md @@ -1,6 +1,6 @@ --- title: Windows subscription activation -description: Learn how to dynamically enable Windows Enterprise or Education subscriptions. +description: Learn how to step up from Windows Pro to a Windows Enterprise subscription or from Windows Eduction Pro to a Windows Education subscription. ms.service: windows-client ms.subservice: itpro-fundamentals ms.localizationpriority: medium @@ -10,8 +10,9 @@ manager: aaroncz ms.collection: - highpri - tier2 -ms.topic: conceptual -ms.date: 02/13/2024 +ms.topic: concept-article +zone_pivot_groups: windows-versions-11-10 +ms.date: 03/04/2024 appliesto: - ✅ Windows 11 - ✅ Windows 10 @@ -33,17 +34,6 @@ The subscription activation feature eliminates the need to manually deploy Enter For more information on how to deploy Enterprise licenses, see [Deploy Windows Enterprise licenses](deploy-enterprise-licenses.md). -> [!NOTE] -> -> Organizations that use the Subscription Activation feature to enable users to upgrade from one version of Windows to another and use Conditional Access policies to control access need to exclude one of the following cloud apps from their Conditional Access policies using **Select Excluded Cloud Apps**: -> -> - [Universal Store Service APIs and Web Application, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). -> - [Windows Store for Business, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). -> -> Although the app ID is the same in both instances, the name of the cloud app depends on the tenant. -> -> For more information about configuring exclusions in Conditional Access policies, see [Application exclusions](/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa#application-exclusions). - ## Subscription activation for Enterprise Windows Enterprise E3 and E5 are available as online services via subscription. Windows Enterprise can be deployed in an organization without keys and reboots. @@ -57,6 +47,34 @@ Organizations that have an enterprise agreement can also benefit from the servic > > Subscription activation is available for qualifying devices running currently supported versions of Windows. Subscription activation can't be used to upgrade to a newer version of Windows. +### Adding Conditional Access policy + +Organizations that use the Subscription Activation feature to enable users to "step-up" from one version of Windows to another and use Conditional Access policies to control access need to exclude one of the following cloud apps from their Conditional Access policies using **Select Excluded Cloud Apps**: + +- [Universal Store Service APIs and Web Application, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). + +- [Windows Store for Business, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f](/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in#application-ids-of-commonly-used-microsoft-applications). + +Although the app ID is the same in both instances, the name of the cloud app depends on the tenant. + +For more information about configuring exclusions in Conditional Access policies, see [Application exclusions](/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa#application-exclusions). + + + +When a device has been offline for an extended period of time, the device might not reactivate automatically if this Conditional Access exclusion isn't in place. Setting this Conditional Access exclusion ensures that Subscription Activation continues to work seamlessly. + +Starting with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later, users are prompted for authentication with a toast notification when Subscription Activation needs to reactivate. The toast notification will show the following message: + +> **Your account requires authentication** +> +> **Please sign in to your work or school account to verify your information.** + +Additionally, in the [**Activation**](ms-settings:activation) pane, the following message might appear: + +> **Please sign in to your work or school account to verify your information.** + +The prompt for authentication usually occurs when a device has been offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired. + ## Subscription activation for Education Subscription activation for Education works the same as the Enterprise edition. However, in order to use subscription activation for Education, the device must have Windows Pro Education and an active subscription plan with an Enterprise license. For more information, see the [requirements](#windows-education-requirements) section. @@ -71,14 +89,6 @@ To support inherited activation, both the host computer and the VM must be runni ### Windows Enterprise requirements -> [!NOTE] -> -> The following requirements don't apply to general Windows client activation on Azure. Azure activation requires a connection to Azure KMS only. It supports workgroup, hybrid, and Microsoft Entra joined VMs. In most scenarios, activation of Azure VMs happens automatically. For more information, see [Understanding Azure KMS endpoints for Windows product activation of Azure virtual machines](/troubleshoot/azure/virtual-machines/troubleshoot-activation-problems#understanding-azure-kms-endpoints-for-windows-product-activation-of-azure-virtual-machines). - -> [!IMPORTANT] -> -> As of October 1, 2022, subscription activation is available for *commercial* and *GCC* tenants. It's currently not available on GCC High or DoD tenants. For more information, see [Enable subscription activation with an existing EA](deploy-enterprise-licenses.md#enable-subscription-activation-with-an-existing-ea). - For Microsoft customers with Enterprise Agreements (EA) or Microsoft Products & Services Agreements (MPSA), the following requirements must be met: - A supported version of Windows Pro or Enterprise edition installed on the devices to be upgraded. @@ -87,11 +97,32 @@ For Microsoft customers with Enterprise Agreements (EA) or Microsoft Products & For Microsoft customers that don't have EA or MPSA, Windows Enterprise E3/E5 or A3/A5 licenses can be obtained through a cloud solution provider (CSP). Identity management and device requirements are the same when using CSP to manage licenses. For more information about getting Windows Enterprise E3 through a CSP, see [Windows Enterprise E3 in CSP](windows-enterprise-e3-overview.md). +> [!NOTE] +> +> These requirements don't apply to general Windows client activation on Azure. Azure activation requires a connection to Azure KMS only. Azure KMS supports workgroup, hybrid, and Microsoft Entra joined VMs. In most scenarios, activation of Azure VMs happens automatically. For more information, see [Understanding Azure KMS endpoints for Windows product activation of Azure virtual machines](/troubleshoot/azure/virtual-machines/troubleshoot-activation-problems#understanding-azure-kms-endpoints-for-windows-product-activation-of-azure-virtual-machines). + +> [!IMPORTANT] +> +> As of October 1, 2022, subscription activation is available for *commercial* and *GCC* tenants. It's currently not available on GCC High or DoD tenants. For more information, see [Enable subscription activation with an existing EA](deploy-enterprise-licenses.md#enable-subscription-activation-with-an-existing-ea). + ### Windows Education requirements - A supported version of Windows Pro Education installed on the devices to be upgraded. -- A device with a Windows Pro Education digital license. This information can be confirmed under **Settings > System > Activation** or under **Settings > Update & Security > Activation**. + +::: zone pivot="windows-11" + +- A device with a Windows Pro Education digital license. This information can be confirmed in the [**Activation**](ms-settings:activation)pane of the **Settings** app under **Settings > System > Activation**. + +::: zone-end + +::: zone pivot="windows-10" + +- A device with a Windows Pro Education digital license. This information can be confirmed in the [**Activation**](ms-settings:activation)pane of the **Settings** app under **Settings > Update & Security > Activation**. + +::: zone-end + - The Education tenant must have an active subscription to Microsoft 365 with a Windows Enterprise license, or a Windows Enterprise or Education subscription. + - Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined. Workgroup-joined or Microsoft Entra registered devices aren't supported. > [!IMPORTANT] @@ -104,8 +135,8 @@ With Windows Enterprise or Education editions, an organization can benefit from To compare Windows editions and review pricing, see the following sites: -- [Compare Windows editions](https://www.microsoft.com/en-us/windows/business/windows-10-pro-vs-windows-11-pro) -- [Enterprise Mobility + Security Pricing Options](https://www.microsoft.com/en-us/microsoft-365/enterprise-mobility-security/compare-plans-and-pricing) +- [Compare Windows editions](https://www.microsoft.com/en-us/windows/business/windows-10-pro-vs-windows-11-pro) | 1909 | | Taskbar settings roaming | Roaming of taskbar settings is removed in this release. This feature was announced as no longer being developed in Windows 10, version 1903. | 1909 | | Desktop messaging app doesn't offer messages sync | The messaging app on Desktop has a sync feature that can be used to sync SMS text messages received from Windows Mobile and keep a copy of them on the Desktop. The sync feature has been removed from all devices. Due to this change, you'll only be able to access messages from the device that received the message. | 1903 | |Business Scanning also called Distributed Scan Management (DSM)|We're removing this secure scanning and scanner management capability - there are no devices that support this feature.| 1809 |