Merge remote-tracking branch 'refs/remotes/origin/master' into jdRS

This commit is contained in:
jdeckerMS
2016-04-22 10:14:10 -07:00
1761 changed files with 164185 additions and 206 deletions

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
Add multiple apps to your enterprise data protection (EDP) **Protected Apps** list at the same time, by using the Microsoft Intune Custom URI functionality and the AppLocker Group Policy. For more info about how to create a custom URI using Intune, see [Windows 10 custom policy settings in Microsoft Intune](http://go.microsoft.com/fwlink/p/?LinkID=691330).

View File

@ -15,7 +15,7 @@ author: brianlic-msft
- Windows 10
\[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.\]
\[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.\]
This topic for the IT professional describes the advanced security audit policy setting, **Audit PNP Activity**, which determines when plug and play detects an external device.

View File

@ -15,7 +15,7 @@ author: brianlic-msft
- Windows 10
\[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.\]
\[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.\]
Determines whether to audit the event of a user accessing an Active Directory object that has its own system access control list (SACL) specified.

View File

@ -15,7 +15,7 @@ author: brianlic-msft
- Windows 10
\[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.\]
\[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.\]
Determines whether to audit each instance of a user logging on to or logging off from a device.

View File

@ -9,107 +9,63 @@ author: brianlic-msft
---
# Change history for Keep Windows 10 secure
This topic lists new and updated topics in the [Keep Windows 10 secure](index.md) documentation for [Windows 10 and Windows 10 Mobile](../index.md).
<table>
<colgroup>
<col width="50%" />
<col width="50%" />
</colgroup>
<thead>
<tr class="header">
<th align="left">New or changed topic</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr class="odd">
<td align="left">[Protect derived domain credentials with Credential Guard](credential-guard.md)</td>
<td align="left"><p>Clarified Credential Guard protections</p></td>
</tr>
<tr class="even">
<td align="left">[Requirements to use AppLocker](requirements-to-use-applocker.md)</td>
<td align="left"><p>Added that MDM can be used to manage any edition of Windows 10. Windows 10 Enterprise or Windows Server 2016 Technical Preview is required to manage AppLocker by using Group Policy.</p></td>
</tr>
<tr class="odd">
<td align="left">[Protect your enterprise data using enterprise data protection (EDP)](protect-enterprise-data-using-edp.md)</td>
<td align="left"><p>Added pre-release content about how to set up and deploy enterprise data protection (EDP) in an enterprise environment.</p></td>
</tr>
</tbody>
</table>
## April 2016
 
|New or changed topic | Description |
|----------------------|-------------|
|[Protect derived domain credentials with Credential Guard](credential-guard.md) |Clarified Credential Guard protections |
## March 2016
|New or changed topic | Description |
|----------------------|-------------|
|[Requirements to use AppLocker](requirements-to-use-applocker.md) |Added that MDM can be used to manage any edition of Windows 10. Windows 10 Enterprise or Windows Server 2016 Technical Preview is required to manage AppLocker by using Group Policy.|
|[Protect your enterprise data using enterprise data protection (EDP)](protect-enterprise-data-using-edp.md) |Added pre-release content about how to set up and deploy enterprise data protection (EDP) in an enterprise environment.|
## February 2016
| New or changed topic | Description |
|-------------------------------------------------------------------------------------------------------------------------------------|-------------|
| [Configure S/MIME for Windows 10 and Windows 10 Mobile](configure-s-mime.md) | New |
| [Install digital certificates on Windows 10 Mobile](installing-digital-certificates-on-windows-10-mobile.md) | New |
| [Use Windows Event Forwarding to help with intrusion detection](use-windows-event-forwarding-to-assist-in-instrusion-detection.md) | New |
| [Encrypted Hard Drive](encrypted-hard-drive.md) | New |
 
| New or changed topic | Description |
|----------------------|-------------|
|[Configure S/MIME for Windows 10 and Windows 10 Mobile](configure-s-mime.md) |New |
|[Install digital certificates on Windows 10 Mobile](installing-digital-certificates-on-windows-10-mobile.md) |New |
|[Use Windows Event Forwarding to help with intrusion detection](use-windows-event-forwarding-to-assist-in-instrusion-detection.md) |New |
|[Encrypted Hard Drive](encrypted-hard-drive.md) |New |
## January 2016
| New or changed topic | Description |
|------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------|
| [Device Guard deployment guide](device-guard-deployment-guide.md) | Updated recommendations in Bring Your Own Device section |
| [Implement Microsoft Passport in your organization](implement-microsoft-passport-in-your-organization.md) | Updated the prerequisites for an Azure Active Directory/Active Directory hybrid environment |
| [Microsoft Passport and password changes](microsoft-passport-and-password-changes.md) | Updated to clarify that this procedure is not needed for Passport for Work |
| [Microsoft Passport guide](microsoft-passport-guide.md) | Updated the prerequisites for an Azure Active Directory/Active Directory hybrid environment |
| [Windows 10 Mobile security guide](windows-10-mobile-security-guide.md) | New |
 
|New or changed topic |Description |
|---------------------|------------|
|[Device Guard deployment guide](device-guard-deployment-guide.md) |Updated recommendations in Bring Your Own Device section |
|[Implement Microsoft Passport in your organization](implement-microsoft-passport-in-your-organization.md) |Updated the prerequisites for an Azure Active Directory/Active Directory hybrid environment |
|[Microsoft Passport and password changes](microsoft-passport-and-password-changes.md) |Updated to clarify that this procedure is not needed for Passport for Work |
|[Microsoft Passport guide](microsoft-passport-guide.md) |Updated the prerequisites for an Azure Active Directory/Active Directory hybrid environment |
|[Windows 10 Mobile security guide](windows-10-mobile-security-guide.md) |New |
## December 2015
| New or changed topic | Description |
|----------------------------------------------------------------------------------------------------|-------------|
| [Device Guard certification and compliance](device-guard-certification-and-compliance.md) | Updated |
| [Microsoft Passport errors during PIN creation](microsoft-passport-errors-during-pin-creation.md) | Updated |
| [Protect derived domain credentials with Credential Guard](credential-guard.md) | Updated |
| [Security policy settings](security-policy-settings.md) (multiple topics) | Updated |
 
|New or changed topic |Description |
|---------------------|------------|
|[Device Guard certification and compliance](device-guard-certification-and-compliance.md) |Updated |
|[Microsoft Passport errors during PIN creation](microsoft-passport-errors-during-pin-creation.md) |Updated |
|[Protect derived domain credentials with Credential Guard](credential-guard.md) |Updated |
|[Security policy settings](security-policy-settings.md) (multiple topics) |Updated |
## November 2015
| New or changed topic | Description |
|----------------------------------------------------------------------------------------------|-------------|
| [Windows Defender in Windows 10](windows-defender-in-windows-10.md) | New |
| [Windows Hello biometrics in the enterprise](windows-hello-in-enterprise.md) | New |
| [AppLocker](applocker-overview.md) (multiple topics) | Updated |
| [Device Guard certification and compliance](device-guard-certification-and-compliance.md) | Updated |
| [Device Guard deployment guide](device-guard-deployment-guide.md) | Updated |
| [Security auditing](security-auditing-overview.md) (multiple topics) | Updated |
| [Why a PIN is better than a password](why-a-pin-is-better-than-a-password.md) | Updated |
 
|New or changed topic |Description |
|---------------------|-------------|
|[Windows Defender in Windows 10](windows-defender-in-windows-10.md) |New |
|[Windows Hello biometrics in the enterprise](windows-hello-in-enterprise.md)|New |
|[AppLocker](applocker-overview.md) (multiple topics) |Updated |
|[Device Guard certification and compliance](device-guard-certification-and-compliance.md) |Updated |
|[Device Guard deployment guide](device-guard-deployment-guide.md) |Updated |
|[Security auditing](security-auditing-overview.md) (multiple topics) |Updated |
|[Why a PIN is better than a password](why-a-pin-is-better-than-a-password.md) |Updated |
## Related topics
[Change history for What's new in Windows 10](../whats-new/change-history-for-what-s-new-in-windows-10.md)
[Change history for Plan for Windows 10 deployment](../plan/change-history-for-plan-for-windows-10-deployment.md)
[Change history for Deploy Windows 10](../deploy/change-history-for-deploy-windows-10.md)
[Change history for Manage and update Windows 10](../manage/change-history-for-manage-and-update-windows-10.md)
 
 
- [Change history for What's new in Windows 10](../whats-new/change-history-for-what-s-new-in-windows-10.md)
- [Change history for Plan for Windows 10 deployment](../plan/change-history-for-plan-for-windows-10-deployment.md)
- [Change history for Deploy Windows 10](../deploy/change-history-for-deploy-windows-10.md)
- [Change history for Manage and update Windows 10](../manage/change-history-for-manage-and-update-windows-10.md)

View File

@ -14,7 +14,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
Microsoft Intune helps you create and deploy your enterprise data protection (EDP) policy, including letting you choose your protected apps, your EDP-protection level, and how to find enterprise data on the network.

View File

@ -16,7 +16,7 @@ author: eross-msft
- Windows 10 Mobile Preview
- System Center Configuration Manager (version 1511 or later)
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
Configuration Manager (version 1511 or later) helps you create and deploy your enterprise data protection (EDP) policy, including letting you choose your protected apps, your EDP-protection level, and how to find enterprise data on the network.

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
After you've created and deployed your enterprise data protection (EDP) policy, you can use Microsoft Intune to create and deploy your Virtual Private Network (VPN) policy, linking it to your EDP policy.

View File

@ -180,7 +180,7 @@ First, you must add the virtualization-based security features. You can do this
2. Add the Hyper-V Hypervisor by running the following command:
``` syntax
dism /image:<WIM file name> /Enable-Feature /FeatureName:Microsoft-Hyper-V-Hypervisor
dism /image:<WIM file name> /Enable-Feature /FeatureName:Microsoft-Hyper-V-Hypervisor /all
```
3. Add Isolated User Mode by running the following command:

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
After youve created your enterprise data protection (EDP) policy, you'll need to deploy it to your organization's enrolled devices. Enrollment can be done for business or personal devices, allowing the devices to use your managed apps and to sync with your managed content and information.

View File

@ -16,7 +16,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
Learn the difference between enlightened and unenlightened apps, and then review the list of enlightened apps provided by Microsoft along with the text you will need to use to add them to your **Protected Apps** list.

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
This section includes info about the enlightened Microsoft apps, including how to add them to your **Protected Apps** list in Microsoft Intune. It also includes some testing scenarios that we recommend running through with enterprise data protection (EDP).

View File

@ -99,6 +99,8 @@ When identity providers such as Active Directory or Azure AD enroll a certificat
## Learn more
[Introduction to Windows Hello](http://go.microsoft.com/fwlink/p/?LinkId=786649), video presentation on Microsoft Virtual Academy
[What's new in Active Directory Domain Services (AD DS) in Windows Server Technical Preview](http://go.microsoft.com/fwlink/p/?LinkId=708533)
[Windows Hello face authentication](http://go.microsoft.com/fwlink/p/?LinkId=626024)

View File

@ -6,7 +6,7 @@ keywords: ["security", "credential", "password", "authentication"]
ms.prod: W10
ms.mktglfcycl: plan
ms.sitesec: library
author: brianlic-msft
author: challum
---
# Microsoft Passport guide

View File

@ -14,7 +14,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
Microsoft Intune and System Center Configuration Manager (version 1511 or later) helps you create and deploy your enterprise data protection (EDP) policy, including letting you choose your protected apps, your EDP-protection level, and how to find enterprise data on the network.

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
With the increase of employee-owned devices in the enterprise, theres also an increasing risk of accidental data leak through apps and services, like email, social media, and the public cloud, which are outside of the enterprises control. For example, when an employee sends the latest engineering pictures to their personal email account, copies and pastes product info to a public Yammer group or tweet, or saves an in-progress sales report to their public cloud storage.

View File

@ -15,7 +15,7 @@ author: eross-msft
- Windows 10 Insider Preview
- Windows 10 Mobile Preview
<span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. An app that calls an API introduced in Windows 10 Anniversary SDK Preview Build 14295 cannot be ingested into the Windows Store during the Preview period.]</span>
<span style="color:#ED1C24;">[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.]</span>
We've come up with a list of suggested testing scenarios that you can use to test enterprise data protection (EDP) in your company.

View File

@ -5,7 +5,7 @@ ms.assetid: 733263E5-7FD1-45D2-914A-184B9E3E6A3F
ms.prod: W10
ms.mktglfcycl: deploy
ms.sitesec: library
author: brianlic-msft
author: tedhardyMSFT
---
# Use Windows Event Forwarding to help with intrusion detection

View File

@ -32,6 +32,10 @@ This topic lists new and updated topics in the [Manage and update Windows 10](in
<td align="left">[Configure telemetry and other settings in your organization](disconnect-your-organization-from-microsoft.md)</td>
<td align="left"><p>Added the font streaming section.</p></td>
</tr>
<tr class="odd">
<td align="left">[Set up a kiosk on Windows 10 Pro, Enterprise, or Education](set-up-a-kiosk-for-windows-10-for-desktop-editions.md)</td>
<td align="left"><p>Made corrections to script and instructions for Shell Launcher.</p></td>
</tr>
</tbody>
</table>

View File

@ -16,9 +16,7 @@ author: jdeckerMS
- Windows 10
**Looking for Windows Embedded 8.1 Industry information?**
- [Assigned Access]( http://go.microsoft.com/fwlink/p/?LinkId=613653)
> **Looking for Windows Embedded 8.1 Industry information?** See [Assigned Access]( http://go.microsoft.com/fwlink/p/?LinkId=613653)
A single-use device is easy to set up in Windows 10 for desktop editions (Pro, Enterprise, and Education). For a kiosk device to run a Universal Windows app, use the **assigned access** feature. For a kiosk device (Windows 10 Enterprise or Education) to run a Classic Windows application, use **Shell Launcher** to set a custom user interface as the shell. To return the device to the regular shell, see [Sign out of assigned access](#sign-out-of-assigned-access).
@ -288,19 +286,19 @@ Alternatively, you can turn on Shell Launcher using the Deployment Image Servici
**To set your custom shell**
Modify the following PowerShell script as appropriate and run the script on the kiosk device.
Modify the following PowerShell script as appropriate. The comments in the sample script explain the purpose of each section and tell you where you will want to change the script for your purposes. Save your script with the extension .ps1, open Windows PowerShell as administrator, and run the script on the kiosk device.
```
$COMPUTER = &quot;localhost&quot;
$NAMESPACE = &quot;root\standardcimv2\embedded&quot;
$COMPUTER = localhost
$NAMESPACE = root\standardcimv2\embedded
# Create a handle to the class instance so we can call the static methods.
$ShellLauncherClass = [wmiclass]&quot;\\$COMPUTER\${NAMESPACE}:WESL_UserSetting&quot;
$ShellLauncherClass = [wmiclass]\\$COMPUTER\${NAMESPACE}:WESL_UserSetting
# This well-known security identifier (SID) corresponds to the BUILTIN\Administrators group.
$Admins_SID = &quot;S-1-5-32-544&quot;
$Admins_SID = S-1-5-32-544
# Create a function to retrieve the SID for a user account on a machine.
@ -310,12 +308,12 @@ Modify the following PowerShell script as appropriate and run the script on the
$NTUserSID = $NTUserObject.Translate([System.Security.Principal.SecurityIdentifier])
return $NTUserSID.Value
}
# Get the SID for a user account named &quot;Cashier&quot;. Rename &quot;Cashier&quot; to an existing account on your system to test this script.
# Get the SID for a user account named Cashier. Rename Cashier to an existing account on your system to test this script.
$Cashier_SID = Get-UsernameSID(&quot;Cashier&quot;)
$Cashier_SID = Get-UsernameSID(Cashier)
# Define actions to take when the shell program exits.
@ -323,43 +321,43 @@ Modify the following PowerShell script as appropriate and run the script on the
$restart_device = 1
$shutdown_device = 2
# Examples
# Examples. You can change these examples to use the program that you want to use as the shell.
# Set the command prompt as the default shell, and restart the device if it&#39;s closed.
# This example sets the command prompt as the default shell, and restarts the device if the command prompt is closed.
$ShellLauncherClass.SetDefaultShell(&quot;cmd.exe&quot;, $restart_device)
$ShellLauncherClass.SetDefaultShell(cmd.exe, $restart_device)
# Display the default shell to verify that it was added correctly.
$DefaultShellObject = $ShellLauncherClass.GetDefaultShell()
&quot;`nDefault Shell is set to &quot; + $DefaultShellObject.Shell + &quot; and the default action is set to &quot; + $DefaultShellObject.defaultaction
“`nDefault Shell is set to + $DefaultShellObject.Shell + and the default action is set to + $DefaultShellObject.defaultaction
# Set Internet Explorer as the shell for &quot;Cashier&quot;, and restart the machine if it&#39;s closed.
# Set Internet Explorer as the shell for “Cashier”, and restart the machine if Internet Explorer is closed.
$ShellLauncherClass.SetCustomShell($Cashier_SID, &quot;c:\program files\internet explorer\iexplore.exe www.microsoft.com&quot;, ($null), ($null), $restart_shell)
$ShellLauncherClass.SetCustomShell($Cashier_SID, c:\program files\internet explorer\iexplore.exe www.microsoft.com, ($null), ($null), $restart_shell)
# Set Explorer as the shell for administrators.
$ShellLauncherClass.SetCustomShell($Admins_SID, &quot;explorer.exe&quot;)
$ShellLauncherClass.SetCustomShell($Admins_SID, explorer.exe)
# View all the custom shells defined.
&quot;`nCurrent settings for custom shells:&quot;
`nCurrent settings for custom shells:
Get-WmiObject -namespace $NAMESPACE -computer $COMPUTER -class WESL_UserSetting | Select Sid, Shell, DefaultAction
# Enable Shell Launcher
$ShellLauncherClass.SetEnabled($TRUE)
&quot;`nEnabled is set to &quot; + $DefaultShellObject.IsEnabled()
“`nEnabled is set to + $DefaultShellObject.IsEnabled()
# Remove the new custom shells.
$ShellLauncherClass.RemoveCustomShell($Admins_SID)
$ShellLauncherClass.RemoveCustomShell($Cashier_SID)
```
```
## Related topics

View File

@ -9,95 +9,52 @@ author: TrudyHa
---
# Change history for What's new in Windows 10
This topic lists new and updated topics in the [What's new in Windows 10](index.md) documentation for [Windows 10 and Windows 10 Mobile](../index.md).
## April 2016
|New or changed topic |Description |
|---------------------|------------|
|[Enterprise data protection (EDP) overview](edp-whats-new-overview.md) |Updated to remove content that's duplicated in the EDP content and added pointer. |
## February 2016
<table>
<colgroup>
<col width="50%" />
<col width="50%" />
</colgroup>
<thead>
<tr class="header">
<th align="left">New or changed topic</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr class="odd">
<td align="left">[Lockdown features from Windows Embedded Industry 8.1](lockdown-features-windows-10.md)</td>
<td align="left"><p>Updated to include policy setting names for USB filter and Toast notification filter</p></td>
</tr>
</tbody>
</table>
 
|New or changed topic |Description |
|---------------------|------------|
|[Lockdown features from Windows Embedded Industry 8.1](lockdown-features-windows-10.md) |Updated to include policy setting names for USB filter and Toast notification filter|
## January 2016
<table>
<colgroup>
<col width="50%" />
<col width="50%" />
</colgroup>
<thead>
<tr class="header">
<th align="left">New or changed topic</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr class="odd">
<td align="left">[Browser: Microsoft Edge and Internet Explorer 11](edge-ie11-whats-new-overview.md)</td>
<td align="left"><p>Updated to include the &quot;Applies to&quot; section</p></td>
</tr>
</tbody>
</table>
 
|New or changed topic |Description |
|---------------------|------------|
|[Browser: Microsoft Edge and Internet Explorer 11](edge-ie11-whats-new-overview.md) |Updated to include the **Applies to** section |
## December 2015
| New or changed topic | Description |
|---------------------------------------------------------------|-------------|
| [Security](security.md) | New |
| [Windows Update for Business](windows-update-for-business.md) | New |
 
|New or changed topic |Description |
|---------------------|------------|
|[Security](security.md) |New |
|[Windows Update for Business](windows-update-for-business.md) |New |
## November 2015
| New or changed topic | Description |
|------------------------------------------------------------------------------------------------------------------|-------------|
| [AppLocker](applocker.md) | New |
| [BitLocker](bitlocker.md) | New |
| [Credential Guard](credential-guard.md) | New |
| [Device Guard](device-guard-overview.md) | New |
| [Lockdown features from Windows Embedded 8.1 Industry](lockdown-features-windows-10.md) | New |
| [Security auditing](security-auditing.md) | New |
| [Trusted Platform Module](trusted-platform-module.md) | New |
| [Windows spotlight on the lock screen](windows-spotlight.md) | New |
| [Windows Store for Business overview](windows-store-for-business-overview.md) | New |
 
|New or changed topic |Description |
|---------------------|------------|
|[AppLocker](applocker.md) |New |
|[BitLocker](bitlocker.md) |New |
|[Credential Guard](credential-guard.md) |New |
|[Device Guard](device-guard-overview.md) |New |
|[Lockdown features from Windows Embedded 8.1 Industry](lockdown-features-windows-10.md) |New |
|[Security auditing](security-auditing.md) |New |
|[Trusted Platform Module](trusted-platform-module.md) |New |
|[Windows spotlight on the lock screen](windows-spotlight.md) |New |
|[Windows Store for Business overview](windows-store-for-business-overview.md) |New |
## Related topics
[Change history for Plan for Windows 10 deployment](../plan/change-history-for-plan-for-windows-10-deployment.md)
[Change history for Deploy Windows 10](../deploy/change-history-for-deploy-windows-10.md)
[Change history for Keep Windows 10 secure](../keep-secure/change-history-for-keep-windows-10-secure.md)
[Change history for Manage and update Windows 10](../manage/change-history-for-manage-and-update-windows-10.md)
- [Change history for Plan for Windows 10 deployment](../plan/change-history-for-plan-for-windows-10-deployment.md)
- [Change history for Deploy Windows 10](../deploy/change-history-for-deploy-windows-10.md)
- [Change history for Keep Windows 10 secure](../keep-secure/change-history-for-keep-windows-10-secure.md)
- [Change history for Manage and update Windows 10](../manage/change-history-for-manage-and-update-windows-10.md)
 

View File

@ -17,6 +17,10 @@ author: brianlic-msft
User Account Control (UAC) helps prevent malware from damaging a computer and helps organizations deploy a better-managed desktop environment.
You should not turn off UAC because this is not a supported scenario for devices running Windows 10. If you do turn off UAC, all Univeral Windows Platform apps stop working. You must always set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA** registry value to 1. If you need to provide auto elevation for programmatic access or installation, you could set the **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin** registry value to 0, which is the same as setting the UAC slider Never Notify. This is not recommended for devices running Windows 10.
For more info about how manage UAC, see [UAC Group Policy Settings and Registry Key Settings](https://technet.microsoft.com/library/dd835564.aspx#BKMK_AdminApprovalMode).
In Windows 10, User Account Control has added some improvements.
## New features in Windows 10

BIN
windows/yw45mjxz.3sx.json Normal file

Binary file not shown.