From 6d3464b2d76b95907f1ec2aec48e9f7277b0a900 Mon Sep 17 00:00:00 2001 From: Sandeep Deo <38295759+SanDeo-MSFT@users.noreply.github.com> Date: Fri, 16 Aug 2019 14:47:13 -0700 Subject: [PATCH 001/303] Update hello-hybrid-cert-trust-devreg.md --- .../hello-for-business/hello-hybrid-cert-trust-devreg.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md index 433457239a..e4c7ce1506 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md @@ -205,7 +205,7 @@ When you're using AD FS, you need to enable the following WS-Trust endpoints: `/adfs/services/trust/13/certificatemixed` > [!WARNING] -> Both **adfs/services/trust/2005/windowstransport** or **adfs/services/trust/13/windowstransport** should be enabled as intranet facing endpoints only and must NOT be exposed as extranet facing endpoints through the Web Application Proxy. To learn more on how to disable WS-Trust WIndows endpoints, see [Disable WS-Trust Windows endpoints on the proxy](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs#disable-ws-trust-windows-endpoints-on-the-proxy-ie-from-extranet). You can see what endpoints are enabled through the AD FS management console under **Service** > **Endpoints**. +> Both **adfs/services/trust/2005/windowstransport** or **adfs/services/trust/13/windowstransport** should be enabled as intranet facing endpoints only and must NOT be exposed as extranet facing endpoints through the Web Application Proxy. To learn more on how to disable WS-Trust Windows endpoints, see [Disable WS-Trust Windows endpoints on the proxy](https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs#disable-ws-trust-windows-endpoints-on-the-proxy-ie-from-extranet). You can see what endpoints are enabled through the AD FS management console under **Service** > **Endpoints**. > [!NOTE] >If you don’t have AD FS as your on-premises federation service, follow the instructions from your vendor to make sure they support WS-Trust 1.3 or 2005 endpoints and that these are published through the Metadata Exchange file (MEX). From 35877f8ea56f9c22f57568acff724f650c6ee949 Mon Sep 17 00:00:00 2001 From: Spencer Shumway <45644477+spshumwa@users.noreply.github.com> Date: Wed, 11 Sep 2019 10:31:53 -0700 Subject: [PATCH 002/303] Adding TPM networking requirements --- .../windows-autopilot/windows-autopilot-requirements.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/deployment/windows-autopilot/windows-autopilot-requirements.md b/windows/deployment/windows-autopilot/windows-autopilot-requirements.md index 1baaf03dea..cb83ea8034 100644 --- a/windows/deployment/windows-autopilot/windows-autopilot-requirements.md +++ b/windows/deployment/windows-autopilot/windows-autopilot-requirements.md @@ -78,6 +78,7 @@ If the Microsoft Store is not accessible, the AutoPilot process will still conti
H-9#5
z{k1}~nyJm{Z9(oFprn85U 0X;jEhFJsATOmth@ajO5I_88mn
zrzaX5k?x@9y&@P?CJc=69hkqbUwaEhBsm=N`$pUtT4u7vDOa~t`J?sxjp1<^OSMlC
zJMow&mnTyc#*~nvavu0q{YFhudefw2gN&8#IhkyQ)O;BmN7x #cZGwp%6}}GB
zvEtdQwCghAnnY6cZcvcb?#oo$`*DEUdqdY3)~O&VH*jUjGg%pQFGW;LCR|5uLUBPk
zN(X_4GFL|K0gYFPbxayOIn^wOK@}h$JBL0(voOi`E2S2&73FLKV?K`6blc3oGhf%3
zjm7Uy|8BXdmsBRx@Wr94Pp`3zqAayk%@Uj?(@f@L*(3PsJa~jYl?Uqn4@TuQE|PU0
zYp@u}Z!PP40}a&^HsQ!pV{2wu-fJ!p*Ix_;56093+3!1Dz4@2_HSVfR*B2~ztlqu#
z_Bj^@KnE==TF!v1wxz1j&m&G#2TP$4yH(h^p@@RBd9rti
zXl$I+$N^!#I`+dbUKTooRgti`h@IwoW+e_2J<7Oumy&&f|6ZCWxtOk5)+evNUj`ONGMYg5J%YF
zyh~L;<^C+eT_r7?5)Wmn>w*OZeLUM({l0klUbpVD|JeS!wR2AqMe=#f^G~5_!uWvj
z9anU8)Pfj)hiSB4KIqeM_g-u9i%8m~?|M1O*NKeq1AU)IpqKnVV>gy^07}}#4bNrc
z$QK^bK>P;NNw!1c&QdAFew*Z=8viJab0;1@#>2Z6hM}+D=F&5fCt!?`T^%8`GRFEc
zcELxrRQ
m5e@)`M0=(S;
z0F6|a+T~X-lF6MGrJXGne~Pl1JI4>3FMktWnm{RLP@e#u^?Y_i35j?PSW-zbBSnm2
zS>8M4Xk|;c6eG2kS1wCggQR~H^))p)7ra&5+S(0;O<^nf9xsaPisaMM(+$aX5{)(S
z7*qw*!9c6HQ0tX6ot8H+fz;O3$;ox?lQX?x79jYmjZNb7q*UvHtxfI>H}C}n3C7pZ
zG-TTQSNT8FS#v
wAk@(}AVSn=IcGm-RP5Un8g
zgamIvhP#^iyYIN>@P<-5CaR}dziJ>`Tgt`{Weoz2Q1ws%n{|?KV@a<;xj9EEM!Srn
zbaPQPxfV%Lt%G02w2ba{-6@gCUvuKv*6eLvbbZRobLh2*y#<-}J2
zT+tKU<741?Pd%M-B;=0kVQ0hyGLrn9By`UryUEK!@7=h-8gW*B!ECkOap>N1Lx`FF
zb3GLT!@a`n0SO@(AgxE*Qbr7_;tZG!>;1FYg@ijKK;O4wwY!54n6aQB?t>#0GOb;j+`d4%VOC5?qG2J@Ne>tQqE+Zp|+Sc
z;!(Ep(LLIqnv_*UTy{qh=SjzZSGux}IfqNvU#goi=c1d4EKSXFD!5%J#E2@?rU{A)
z^C}Epa5FD-C@^PE3wN*>#YUL7ejI?B7wb908WPmv&c}c{V}4hAPVn%dk=xaC8jo?W
z)yiPlIlS}42gG?j5o+Fjf2F?Z8yLTXAC2*)~FIS6!r@MV*P0~>zk|8
9jA)&%GD{)8R9{SfPYGMtdHvO|dQO<0s~cX2;y}u;
zq?`E#8(7b_=lJ)Rg9m={fRTrLF1AV!5DPK360G|#-1E*jnNMIvU9kQ}>Q{@XgUF6u
zNvLLc%LYXCipDX0y5#e|mF)T?sqW0I=GceT3th|MAToxz*Ry^xPB_?*c-s)4c&(wv
zQ(ae}MXnOFL$+v1y|LLr$92&rD_U3em}s5({H43Z}^$0qwI7Mr<6~oGGY>mKfrj
z&9w)up1=Jqfi;;Pi;8vL@ALVvxg*F<`?zJG
^p?+u?xt&3j8;mg&3PrZ6WrdsgsTshA*a0w%4
z^Lc@1z-cflX&`BMtUV4VH$
}GAA%^=NKJ$U$K?#ii>3~D*p%PXx*N@(yKp2HF6qJ@yMm
m>LT5Aybp;wOMO<>caR{sw;n!SahU#clu!}?nLYLFbfod
zgc1!d@gR(|KKAnXmnCUCe#k>~-jAVqkfO7g%U%ZJSHDb}h}f8s`7pri<6W4m`xT>H
zmkuUs3Dj5czdCjax`Lo%(QEMk!7Bks^Ad^_V~(=W5?ulou#5{iU9b9f(2oq8PQizc
zvX0%~(n1}gWGO`lL$U}pU+Hfpf1Bwi{m}>i-#g`7_LR=EN_Q(Y<|}*Q?|DSQph9tP
z%Wohzu$?)ACcn)UAIU%u6j>$tdN*HUbnM!ts~1``yCT7Oejb69L)}GHlDyleju9
z`WtW0J2IhbSb^oiuXqP$Cl##b=4$m1Z;1$*V
mmaY-H!x5Cj#;A$OBqH&*x3R
zufZU|$ZBH$Z?@8M$IpmSCec%@e?;d^l8&2T@Oj3XGZ-oR;t}6h>(P6xuDB-gUJEhYk(hcO`55zb
zgFgUDbv7b7#P_|CN(lik91dUqe)9yxqDmdJnU>FU<}??O?|?&sE@BAha9rhG@YL7q
zADz+2N6NS4FnVKpa1h$$I)qAsBX(*YJUTiUi#teLCiz8Oqxq$S=!SS}q<*0Nv_Fzg
z#SkhNP8`gNspee2B!O;?{$HAzzKsg00G>SXaWs8VFbX*qyGnDwaNrCUXz5z8il(T!l@i4
zu_+faN^uKeocQbhl+DI