Merge remote-tracking branch 'refs/remotes/origin/master' into live
@ -29,7 +29,7 @@ For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThre
|
|||||||
|
|
||||||
For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx).
|
For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx).
|
||||||
|
|
||||||
### Onboard and monitor endpoints
|
### Onboard and monitor endpoints using the classic Intune console
|
||||||
|
|
||||||
1. Open the Microsoft Intune configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
|
1. Open the Microsoft Intune configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
|
||||||
|
|
||||||
@ -98,6 +98,53 @@ Configuration for onboarded machines: telemetry reporting frequency | ./Device/V
|
|||||||
> - The **Health Status for onboarded machines** policy uses read-only properties and can't be remediated.
|
> - The **Health Status for onboarded machines** policy uses read-only properties and can't be remediated.
|
||||||
> - Configuration of telemetry reporting frequency is only available for machines on Windows 10, version 1703.
|
> - Configuration of telemetry reporting frequency is only available for machines on Windows 10, version 1703.
|
||||||
|
|
||||||
|
### Using the Azure Intune Portal to deploy Windows Defender Advanced Threat Protection policies on Windows 10 1607 and higher
|
||||||
|
|
||||||
|
1. Open the Microsoft Intune configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from the [Windows Defender ATP portal](https://securitycenter.windows.com/):
|
||||||
|
|
||||||
|
a. Select **Endpoint Management** on the **Navigation pane**.
|
||||||
|
|
||||||
|
b. Select **Mobile Device Management/Microsoft Intune** > **Download package** and save the .zip file.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2. Extract the contents of the .zip file to a shared, read-only location that can be accessed by the network administrators who will deploy the package. You should have a file named *WindowsDefenderATP.onboarding*.
|
||||||
|
|
||||||
|
3. Login to the [Microsoft Azure portal](https://portal.azure.com).
|
||||||
|
|
||||||
|
4. From the Intune blade, choose **Device configuration**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
5. Under **Manage**, choose **Profiles** and click **Create Profile**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
4. Type a name, description and choose **Windows 10 and later** as the Platform and **Windows Defender ATP (Windows 10 Desktop)** as the Profile type.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
7. Click **Settings** > **Configure**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
8. Click the folder icon and select the WindowsDefenderATP.onboarding file you extracted earlier. Configure whether you want to allow sample collection from endpoints for [Deep Analysis](investigate-files-windows-defender-advanced-threat-protection.md) by choosing **All**, or disable this feature by choosing **None**. When complete, click **OK**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
9. Click **Create**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
10. Search for and select the Group you want to apply the Configuration Policy to, then click **Select**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
11. Click **Save** to finish deploying the Configuration Policy.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
### Offboard and monitor endpoints
|
### Offboard and monitor endpoints
|
||||||
|
|
||||||
For security reasons, the package used to offboard endpoints will expire 30 days after the date it was downloaded. Expired offboarding packages sent to an endpoint will be rejected. When downloading an offboarding package you will be notified of the packages expiry date and it will also be included in the package name.
|
For security reasons, the package used to offboard endpoints will expire 30 days after the date it was downloaded. Expired offboarding packages sent to an endpoint will be rejected. When downloading an offboarding package you will be notified of the packages expiry date and it will also be included in the package name.
|
||||||
|
@ -14,8 +14,8 @@ localizationpriority: high
|
|||||||
|
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- Windows 10, version 1703
|
- Windows 10, version 1607 and later
|
||||||
- Windows 10 Mobile, version 1703 (except Microsoft Azure Rights Management, which is only available on the desktop)
|
- Windows 10 Mobile, version 1607 and later (except Microsoft Azure Rights Management, which is only available on the desktop)
|
||||||
|
|
||||||
Microsoft Azure Intune helps you create and deploy your Windows Information Protection (WIP) policy, including letting you choose your allowed apps, your WIP-protection level, and how to find enterprise data on the network.
|
Microsoft Azure Intune helps you create and deploy your Windows Information Protection (WIP) policy, including letting you choose your allowed apps, your WIP-protection level, and how to find enterprise data on the network.
|
||||||
|
|
||||||
|
@ -14,8 +14,8 @@ localizationpriority: high
|
|||||||
# Deploy your Windows Information Protection (WIP) policy using Microsoft Azure Intune
|
# Deploy your Windows Information Protection (WIP) policy using Microsoft Azure Intune
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
- Windows 10, version 1703
|
- Windows 10, version 1607 and later
|
||||||
- Windows 10 Mobile, version 1703 (except Microsoft Azure Rights Management, which is only available on the desktop)
|
- Windows 10 Mobile, version 1607 and later (except Microsoft Azure Rights Management, which is only available on the desktop)
|
||||||
|
|
||||||
After you’ve created your Windows Information Protection (WIP) policy, you'll need to deploy it to your organization's enrolled devices. Enrollment can be done for business or personal devices, allowing the devices to use your managed apps and to sync with your managed content and information.
|
After you’ve created your Windows Information Protection (WIP) policy, you'll need to deploy it to your organization's enrolled devices. Enrollment can be done for business or personal devices, allowing the devices to use your managed apps and to sync with your managed content and information.
|
||||||
|
|
||||||
|
BIN
windows/keep-secure/images/atp-azure-intune-category.png
Normal file
After Width: | Height: | Size: 56 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-configure.png
Normal file
After Width: | Height: | Size: 106 KiB |
After Width: | Height: | Size: 43 KiB |
After Width: | Height: | Size: 42 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-create-policy.png
Normal file
After Width: | Height: | Size: 49 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-create-profile.png
Normal file
After Width: | Height: | Size: 68 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-create.png
Normal file
After Width: | Height: | Size: 67 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-device-config.png
Normal file
After Width: | Height: | Size: 132 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-save-policy.png
Normal file
After Width: | Height: | Size: 103 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-save.png
Normal file
After Width: | Height: | Size: 81 KiB |
BIN
windows/keep-secure/images/atp-azure-intune-select-group.png
Normal file
After Width: | Height: | Size: 68 KiB |
After Width: | Height: | Size: 103 KiB |
BIN
windows/keep-secure/images/atp-azure-intune.png
Normal file
After Width: | Height: | Size: 82 KiB |
@ -14,8 +14,8 @@ localizationpriority: high
|
|||||||
**Applies to:**
|
**Applies to:**
|
||||||
|
|
||||||
|
|
||||||
- Windows 10, version 1703
|
- Windows 10, version 1607 and later
|
||||||
- Windows 10 Mobile
|
- Windows 10 Mobile, version 1607 and later
|
||||||
|
|
||||||
This table provides info about the most common problems you might encounter while running WIP in your organization.
|
This table provides info about the most common problems you might encounter while running WIP in your organization.
|
||||||
|
|
||||||
|