mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-16 15:27:22 +00:00
Merge remote-tracking branch 'refs/remotes/origin/rs1' into Aug2
# Conflicts: # windows/keep-secure/TOC.md # windows/keep-secure/implement-microsoft-passport-in-your-organization.md # windows/keep-secure/index.md # windows/keep-secure/prepare-people-to-use-microsoft-passport.md # windows/keep-secure/windows-hello-in-enterprise.md
This commit is contained in:
commit
d18148961f
@ -8,6 +8,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu, devices
|
||||
author: craigash
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Chromebook migration guide
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.pagetype: edu
|
||||
ms.sitesec: library
|
||||
author: craigash
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Deploy Windows 10 in a school district
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.pagetype: edu
|
||||
ms.sitesec: library
|
||||
author: craigash
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Deploy Windows 10 in a school
|
||||
|
@ -5,6 +5,7 @@ keywords: ["Windows 10 deployment", "recommendations", "privacy settings", "scho
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: CelesteDG
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Deployment recommendations for school IT administrators
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Get Minecraft Education Edition
|
||||
|
@ -6,6 +6,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Windows 10 for Education
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# For IT administrators: get Minecraft Education Edition
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Technical reference for the Set up School PCs app
|
||||
@ -90,7 +91,6 @@ The **Set up School PCs** app produces a specialized provisioning package that m
|
||||
|
||||
- Saving content locally to the PC is disabled. This prevents data loss by forcing students to save to the cloud.
|
||||
- A custom Start layout and sign in background image are set.
|
||||
- Prohibits Microsoft Accounts (MSAs) from being created.
|
||||
- Prohibits unlocking the PC to developer mode.
|
||||
- Prohibits untrusted Windows Store apps from being installed.
|
||||
- Prohibits students from removing MDM.
|
||||
@ -242,7 +242,7 @@ The **Set up School PCs** app produces a specialized provisioning package that m
|
||||
</tr>
|
||||
<tr> <td colspan="2"> <p> <strong>Windows Settings</strong> > <strong>Security Settings</strong> > <strong>Local Policies</strong> > <strong>Security Options</strong></p> </td>
|
||||
</tr>
|
||||
<tr><td><p>Accounts: Block Microsoft accounts</p></td><td><p>Enabled</p></td></tr>
|
||||
<tr><td><p>Accounts: Block Microsoft accounts</p><p>**Note** Microsoft accounts can still be used in apps.</p></td><td><p>Enabled</p></td></tr>
|
||||
<tr> <td> <p> Interactive logon: Do not display last user name </p> </td> <td> <p> Enabled</p> </td>
|
||||
</tr>
|
||||
<tr> <td> <p> Interactive logon: Sign-in last interactive user automatically after a system-initiated restart</p> </td> <td> <p> Disabled</p> </td>
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Set up student PCs to join domain
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Provision student PCs with apps
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Provisioning options for Windows 10
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Take a Test app technical reference
|
||||
@ -31,7 +32,9 @@ When running above the lock screen:
|
||||
|
||||
- The hardware print screen button is disabled
|
||||
|
||||
- Content within the app will show up as black in screen capturing/sharing software Copy/paste is disabled
|
||||
- Content within the app will show up as black in screen capturing/sharing software
|
||||
|
||||
- System clipboard is cleared
|
||||
|
||||
- Web apps can query the processes currently running in the user’s device
|
||||
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Set up Take a Test on multiple PCs
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Set up Take a Test on a single PC
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Take tests in Windows 10
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# For teachers: get Minecraft Education Edition
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Use the Set up School PCs app
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: plan
|
||||
ms.sitesec: library
|
||||
ms.pagetype: edu
|
||||
author: CelesteDG
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Windows 10 editions for education customers
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: greg-lindsay
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Activate using Active Directory-based activation
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Activate using Key Management Service
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Activate clients running Windows 10
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
# Appendix: Information sent to Microsoft during activation
|
||||
**Applies to**
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: greg-lindsay
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Monitor activation
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Plan for volume activation
|
||||
|
@ -7,6 +7,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Provision PCs with common settings for initial deployment (simple provisioning)
|
||||
|
@ -7,6 +7,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Provision PCs with apps and certificates for initial deployment (advanced provisioning)
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Use the Volume Activation Management Tool
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: activation
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Volume Activation for Windows 10
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Enable phone sign-in to PC or VPN
|
||||
@ -18,20 +19,24 @@ author: jdeckerMS
|
||||
|
||||
In Windows 10, Version 1607, your network users can use Windows Phone with Windows Hello to sign in to a PC, connect to VPN, and sign in to Office 365 in a browser. Phone sign-in uses Bluetooth, which means no need to wait for a phone call -- just unlock the phone and tap the app.
|
||||
|
||||
(add screenshot when I can get the app working)
|
||||

|
||||
|
||||
> [!NOTE]
|
||||
> Phone sign-in is currently limited to select Technology Adoption Program (TAP) participants.
|
||||
|
||||
You can create a Group Policy or mobile device management (MDM) policy that will allow users to sign in to a work PC or their company's VPN using the credentials stored on their Windows 10 phone.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Both phone and PC must be running Windows 10, Version 1607.
|
||||
- Both phone and PC must be running Windows 10, version 1607.
|
||||
- The PC must be running Windows 10 Pro, Enterprise, or Education
|
||||
- Both phone and PC must have Bluetooth.
|
||||
- The **Microsoft Authenticator** app must be installed on the phone.
|
||||
- The PC must be joined to an Active Directory domain that is connected to an Azure Active Directory (Azure AD) domain, or the PC must be joined to Azure AD.
|
||||
- The phone must be joined to Azure AD or have a work account added.
|
||||
- VPN configuration profile must use certificate-based authentication.
|
||||
- The VPN configuration profile must use certificate-based authentication.
|
||||
|
||||
## Set policies and get the app
|
||||
## Set policies
|
||||
|
||||
To enable phone sign-in, you must enable the following policies using Group Policy or MDM.
|
||||
|
||||
@ -42,13 +47,20 @@ To enable phone sign-in, you must enable the following policies using Group Poli
|
||||
- Set **UsePassportForWork** to **True**
|
||||
- Set **Remote\UseRemotePassport** to **True**
|
||||
|
||||
Everyone can get the **Microsoft Authenticator** app from the Windows Store. If you want to distribute the **Microsoft Authenticator** app, your organization must have set up Windows Store for Business, with Microsoft added as a Line of Business (LOB) publisher.
|
||||
## Configure VPN
|
||||
|
||||
To enable phone sign-in to VPN, you must enable the [policy](#set-policies) for phone sign-in and ensure that VPN is configured as follows:
|
||||
|
||||
- For inbox VPN, set up the VPN profile with Extensible Authentication Protocol (EAP) with the **Smart card or other certificate (TLS)** EAP type, also known as EAP-Transport Level Security (EAP-TLS). To exclusively access the VPN certificates on the phone, in the EAP filtering XML, add either **EKU** or **Issuer** (or both) filtering to make sure it picks only the Remote NGC certificate.
|
||||
- For a Universal Windows Platform (UWP) VPN plug-in, add filtering criteria based on the 3rd party mechanism for the Remote NGC Certificate.
|
||||
|
||||
## Get the app
|
||||
|
||||
If you want to distribute the **Microsoft Authenticator** app, your organization must have set up Windows Store for Business, with Microsoft added as a [Line of Business (LOB) publisher](../manage/working-with-line-of-business-apps.md).
|
||||
|
||||
[Tell people how to sign in using their phone.](prepare-people-to-use-microsoft-passport.md#bmk-remote)
|
||||
|
||||
|
||||
|
||||
|
||||
## Related topics
|
||||
|
||||
[Manage identity verification using Windows Hello for Business](manage-identity-verification-using-microsoft-passport.md)
|
||||
|
BIN
windows/keep-secure/images/phone-signin-device-select.png
Normal file
BIN
windows/keep-secure/images/phone-signin-device-select.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 22 KiB |
BIN
windows/keep-secure/images/phone-signin-menu.png
Normal file
BIN
windows/keep-secure/images/phone-signin-menu.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 17 KiB |
BIN
windows/keep-secure/images/phone-signin-settings.png
Normal file
BIN
windows/keep-secure/images/phone-signin-settings.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 22 KiB |
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Implement Microsoft Passport in your organization
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Install digital certificates on Windows 10 Mobile
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, mobile
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
# Manage identity verification using Microsoft Passport
|
||||
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
# Microsoft Passport and password changes
|
||||
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Microsoft Passport errors during PIN creation
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Event ID 300 - Passport successfully created
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Prepare people to use Microsoft Passport
|
||||
@ -52,16 +53,23 @@ If your policy allows it, people can add Windows Hello to their Passport. Window
|
||||
|
||||

|
||||
|
||||
## <a href="" id="bmk-remote"></a>Use a phone to sign in to a PC
|
||||
## <a href="" id="bmk-remote"></a>Use a phone to sign in to a PC or VPN
|
||||
|
||||
If your enterprise enables phone sign-in, users can pair a phone running Windows 10 Mobile to a PC running Windows 10 and then use an app on the phone to sign in to the PC using their Microsoft Passport credentials.
|
||||
> **Note:** Phone sign-in is currently limited to select Technology Adoption Program (TAP) participants.
|
||||
If your enterprise enables phone sign-in, users can pair a phone running Windows 10 Mobile to a PC running Windows 10 and then use an app on the phone to sign in to the PC using their Windows Hello credentials.
|
||||
|
||||
> [!NOTE]
|
||||
> Phone sign-in is currently limited to select Technology Adoption Program (TAP) participants.
|
||||
|
||||
**Prerequisites:**
|
||||
- The PC must be joined to the Active Directory domain or Azure AD cloud domain.
|
||||
- The PC must have Bluetooth connectivity.
|
||||
- The phone must be joined to the Azure AD cloud domain, or the user must have added a work account to their personal phone.
|
||||
- The free **Phone Sign-in** app must be installed on the phone.
|
||||
|
||||
- Both phone and PC must be running Windows 10, version 1607.
|
||||
- The PC must be running Windows 10 Pro, Enterprise, or Education
|
||||
- Both phone and PC must have Bluetooth.
|
||||
- The **Microsoft Authenticator** app must be installed on the phone.
|
||||
- The PC must be joined to an Active Directory domain that is connected to an Azure Active Directory (Azure AD) domain, or the PC must be joined to Azure AD.
|
||||
- The phone must be joined to Azure AD or have a work account added.
|
||||
- The VPN configuration profile must use certificate-based authentication.
|
||||
|
||||
**Pair the PC and phone**
|
||||
1. On the PC, go to **Settings** > **Devices** > **Bluetooth**. Tap the name of the phone and then tap **Pair** to begin pairing.
|
||||
|
||||
@ -73,11 +81,19 @@ If your enterprise enables phone sign-in, users can pair a phone running Windows
|
||||
|
||||
3. On the PC, tap **Yes**.
|
||||
**Sign in to PC using the phone**
|
||||
1. Open the **Phone Sign-in** app and tap the name of the PC to sign in to.
|
||||
> **Note: ** The first time that you run the Phone-Sign app, you must add an account.
|
||||
|
||||
1. Open the **Microsoft Authenticator** app, choose your account, and tap the name of the PC to sign in to.
|
||||
> **Note: ** The first time that you run the **Microsoft Authenticator** app, you must add an account.
|
||||
|
||||

|
||||
|
||||
|
||||
2. Enter the work PIN that you set up when you joined the phone to the cloud domain or added a work account.
|
||||
|
||||
**Connect to VPN**
|
||||
|
||||
You simply connect to VPN as you normally would. If the phone's certificates are being used, a notification will be pushed to the phone asking if you approve. If you click **allow** in the notification, you will be prompted for your PIN. After you enter your PIN, the VPN session will connect.
|
||||
|
||||
## Related topics
|
||||
|
||||
[Manage identity verification using Microsoft Passport](manage-identity-verification-using-microsoft-passport.md)
|
||||
|
@ -7,6 +7,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security, networking
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# VPN profile options
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Why a PIN is better than a password
|
||||
|
@ -7,7 +7,8 @@ ms.prod: w10
|
||||
ms.mktglfcycl: explore
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
author: eross-msft
|
||||
author: jdeckerMS
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# Windows Hello biometrics in the enterprise
|
||||
@ -17,21 +18,23 @@ author: eross-msft
|
||||
|
||||
Windows Hello is the biometric authentication feature that helps strengthen authentication and helps to guard against potential spoofing through fingerprint matching and facial recognition.
|
||||
|
||||
> **Note:** When Windows 10 first shipped, it included Microsoft Passport and Windows Hello, which worked together to provide multi-factor authentication. To simplify deployment and improve supportability, Microsoft has combined these technologies into a single solution under the Windows Hello name. Customers who have already deployed these technologies will not experience any change in functionality. Customers who have yet to evaluate Windows Hello will find it easier to deploy due to simplified policies, documentation, and semantics.
|
||||
|
||||
Because we realize your employees are going to want to use this new technology in your enterprise, we’ve been actively working with the device manufacturers to create strict design and performance recommendations that help to ensure that you can more confidently introduce Windows Hello biometrics into your organization.
|
||||
|
||||
##How does Windows Hello work?
|
||||
Windows Hello lets your employees use fingerprint or facial recognition as an alternative method to unlocking a device. With Windows Hello, authentication happens when the employee provides his or her unique biometric identifier while accessing the device-specific Microsoft Passport credentials.
|
||||
Windows Hello lets your employees use fingerprint or facial recognition as an alternative method to unlocking a device. With Windows Hello, authentication happens when the employee provides his or her unique biometric identifier while accessing the device-specific Windows Hello credentials.
|
||||
|
||||
The Windows Hello authenticator works with Microsoft Passport to authenticate and allow employees onto your enterprise network. Authentication doesn’t roam among devices, isn’t shared with a server, and can’t easily be extracted from a device. If multiple employees share a device, each employee will use his or her own biometric data on the device.
|
||||
The Windows Hello authenticator works to authenticate and allow employees onto your enterprise network. Authentication doesn’t roam among devices, isn’t shared with a server, and can’t easily be extracted from a device. If multiple employees share a device, each employee will use his or her own biometric data on the device.
|
||||
|
||||
## Why should I let my employees use Windows Hello?
|
||||
Windows Hello provides many benefits, including:
|
||||
|
||||
- Combined with Microsoft Passport, it helps to strengthen your protections against credential theft. Because an attacker must have both the device and the biometric info or PIN, it’s much more difficult to gain access without the employee’s knowledge.
|
||||
- It helps to strengthen your protections against credential theft. Because an attacker must have both the device and the biometric info or PIN, it’s much more difficult to gain access without the employee’s knowledge.
|
||||
|
||||
- Employees get a simple authentication method (backed up with a PIN) that’s always with them, so there’s nothing to lose. No more forgetting passwords!
|
||||
|
||||
- Support for Windows Hello is built into the operating system so you can add additional biometric devices and polices as part of a coordinated rollout or to individual employees or groups using Group Policy or Mobile Device Management (MDM) configurations service provider (CSP) policies.<br>For more info about the available Group Policies and MDM CSPs, see the [Implement Microsoft Passport in your organization](implement-microsoft-passport-in-your-organization.md) topic.
|
||||
- Support for Windows Hello is built into the operating system so you can add additional biometric devices and polices as part of a coordinated rollout or to individual employees or groups using Group Policy or Mobile Device Management (MDM) configurations service provider (CSP) policies.<br>For more info about the available Group Policies and MDM CSPs, see the [Implement Windows Hello for Business in your organization](implement-microsoft-passport-in-your-organization.md) topic.
|
||||
|
||||
## Where is Microsoft Hello data stored?
|
||||
The biometric data used to support Windows Hello is stored on the local device only. It doesn’t roam and is never sent to external devices or servers. This separation helps to stop potential attackers by providing no single collection point that an attacker could potentially compromise to steal biometric data. Additionally, even if an attacker was actually able to get the biometric data, it still can’t be easily converted to a form that could be recognized by the biometric sensor.
|
||||
@ -72,8 +75,8 @@ To allow facial recognition, you must have devices with integrated special infra
|
||||
- Effective, real world FRR with Anti-spoofing or liveness detection: <10%
|
||||
|
||||
## Related topics
|
||||
- [Manage identity verification using Microsoft Passport](manage-identity-verification-using-microsoft-passport.md)
|
||||
- [Implement Microsoft Passport in your organization](implement-microsoft-passport-in-your-organization.md)
|
||||
- [Manage identity verification using Windows Hello for Business](manage-identity-verification-using-microsoft-passport.md)
|
||||
- [Implement Windows Hello for Business in your organization](implement-microsoft-passport-in-your-organization.md)
|
||||
- [Microsoft Passport guide](microsoft-passport-guide.md)
|
||||
- [Prepare people to use Microsoft Passport](prepare-people-to-use-microsoft-passport.md)
|
||||
- [PassportforWork CSP](http://go.microsoft.com/fwlink/p/?LinkId=708219)
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
# Configure Windows 10 taskbar
|
||||
|
||||
|
@ -8,6 +8,7 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: devices
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Connect to remote Azure Active Directory-joined PC
|
||||
|
@ -16,7 +16,6 @@ author: jdeckerMS
|
||||
|
||||
- Windows 10
|
||||
|
||||
> <span style="color:#ED1C24;">[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. ]</span>
|
||||
|
||||
Since its inception, Windows 10 has included a number of user experience features that provide useful tips, tricks, and suggestions as you use Windows, as well as app suggestions from the Windows Store. These features are designed to help people get the most out of their Windows 10 experience by, for example, sharing new features, providing more details on the features they use, or sharing content available in the Windows Store. Examples of such user experiences include:
|
||||
|
||||
|
@ -6,6 +6,7 @@ ms.prod: W10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
author: jdeckerMS
|
||||
localizationpriority: medium
|
||||
---
|
||||
|
||||
# Set up a shared or guest PC with Windows 10
|
||||
@ -15,7 +16,7 @@ author: jdeckerMS
|
||||
|
||||
- Windows 10
|
||||
|
||||
Windows 10, version 1607, introduces *shared PC mode*, which optimizes Windows 10 for shared use scenarios, such as touchdown spaces in an enterprise and temporary customer use in retail. You can apply shared PC mode to Windows 10 Pro, Education, and Enterprise.
|
||||
Windows 10, version 1607, introduces *shared PC mode*, which optimizes Windows 10 for shared use scenarios, such as touchdown spaces in an enterprise and temporary customer use in retail. You can apply shared PC mode to Windows 10 Pro, Pro Education, Education, and Enterprise.
|
||||
|
||||
> **Note:** If you're interested in using Windows 10 for shared PCs in a school, see [Use Set up School PCs app](https://technet.microsoft.com/edu/windows/use-set-up-school-pcs-app) which provides a simple way to configure PCs with shared PC mode plus additional settings specific for education.
|
||||
|
||||
@ -245,8 +246,8 @@ Shared PC mode sets local group policies to configure the device. Some of these
|
||||
<tr> <td colspan="3"> <p><strong>Admin Templates</strong>><strong>System</strong>><strong>User Profiles</strong></p></td></tr>
|
||||
<tr> <td> <p>Turn off the advertising ID</p></td> <td> <p>Enabled</p></td><td><p>SetEduPolicies=True</p></td></tr>
|
||||
<tr> <td colspan="3"> <p><strong>Admin Templates</strong>><strong>Windows Components </strong></p></td></tr>
|
||||
<tr> <td> <p>Do not show Windows Tips </p>*Only on Pro, Enterprise, and Education* </td> <td> <p>Enabled</p></td><td><p>SetEduPolicies=True</p></td></tr>
|
||||
<tr> <td> <p>Turn off Microsoft consumer experiences </p>*Only on Pro, Enterprise, and Education* </td> <td> <p>Enabled</p></td><td><p>SetEduPolicies=True</p></td></tr>
|
||||
<tr> <td> <p>Do not show Windows Tips </p>*Only on Pro, Enterprise, Pro Education, and Education* </td> <td> <p>Enabled</p></td><td><p>SetEduPolicies=True</p></td></tr>
|
||||
<tr> <td> <p>Turn off Microsoft consumer experiences </p>*Only on Pro, Enterprise, Pro Education, and Education* </td> <td> <p>Enabled</p></td><td><p>SetEduPolicies=True</p></td></tr>
|
||||
<tr> <td> <p>Microsoft Passport for Work</p></td> <td> <p>Disabled</p></td><td><p>Always</p></td></tr>
|
||||
<tr> <td> <p>Prevent the usage of OneDrive for file storage</p></td> <td> <p>Enabled</p></td><td><p>Always</p></td></tr>
|
||||
<tr> <td colspan="3"> <p><strong>Admin Templates</strong>><strong>Windows Components</strong>><strong>Biometrics</strong></p></td></tr>
|
||||
|
@ -5,6 +5,7 @@ ms.assetid: F1867017-76A1-4761-A200-7450B96AEF44
|
||||
keywords: ["What's new in Windows 10", "Windows 10", "anniversary update"]
|
||||
ms.prod: w10
|
||||
author: TrudyHa
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# What's new in Windows 10
|
||||
|
@ -6,6 +6,7 @@ ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
author: TrudyHa
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# What's new in Windows 10, versions 1507 and 1511
|
||||
|
@ -7,6 +7,7 @@ ms.prod: w10
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
author: TrudyHa
|
||||
localizationpriority: high
|
||||
---
|
||||
|
||||
# What's new in Windows 10, version 1607
|
||||
|
Loading…
x
Reference in New Issue
Block a user