diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 599204ce64..19546735ca 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -4907,7 +4907,7 @@ }, { "source_path": "windows/manage/configure-windows-telemetry-in-your-organization.md", -"redirect_url": "/windows/configuration/configure-windows-telemetry-in-your-organization", +"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization", "redirect_document_id": true }, { @@ -5932,7 +5932,12 @@ }, { "source_path": "windows/configure/configure-windows-telemetry-in-your-organization.md", -"redirect_url": "/windows/configuration/configure-windows-telemetry-in-your-organization", +"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization", +"redirect_document_id": true +}, +{ +"source_path": "windows/configuration/configure-windows-telemetry-in-your-organization.md", +"redirect_url": "/windows/configuration/configure-windows-diagnostic-data-in-your-organization", "redirect_document_id": true }, { diff --git a/browsers/edge/available-policies.md b/browsers/edge/available-policies.md index 215e7cc5a8..70a990a885 100644 --- a/browsers/edge/available-policies.md +++ b/browsers/edge/available-policies.md @@ -7,15 +7,14 @@ ms.mktglfcycl: explore ms.sitesec: library title: Group Policy and Mobile Device Management settings for Microsoft Edge (Microsoft Edge for IT Pros) ms.localizationpriority: high -ms.date: 09/13/2017 +ms.date: 09/13/2017 #Previsou release date --- + + # Group Policy and Mobile Device Management (MDM) settings for Microsoft Edge -**Applies to:** - -- Windows 10 -- Windows 10 Mobile +> Applies to: Windows 10, Windows 10 Mobile Microsoft Edge works with Group Policy and Microsoft Intune to help you manage your organization's computer settings. Group Policy objects (GPO's) can include registry-based Administrative Template policy settings, security settings, software deployment information, scripts, folder redirection, and preferences. @@ -25,348 +24,359 @@ By using Group Policy and Intune, you can set up a policy setting once, and then > For more info about the tools you can use to change your Group Policy objects, see the Internet Explorer 11 topics, [Group Policy and the Group Policy Management Console (GPMC)](https://go.microsoft.com/fwlink/p/?LinkId=617921), [Group Policy and the Local Group Policy Editor](https://go.microsoft.com/fwlink/p/?LinkId=617922), [Group Policy and the Advanced Group Policy Management (AGPM)](https://go.microsoft.com/fwlink/p/?LinkId=617923), and [Group Policy and Windows PowerShell](https://go.microsoft.com/fwlink/p/?LinkId=617924). ## Group Policy settings +Microsoft Edge works with the following Group Policy settings to help you manager your company's web browser configurations. The Group Policy settings are found in the Group Policy Editor in the following location: + +`Computer Configuration\Administrative Templates\Windows Components\Microsoft Edge\` + + ### Allow Address bar drop-down list suggestions -- **Supported versions:** Windows 10, version 1703 - -- **Description:** This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services. - - - If you enable or don't configure this setting (default), employees can see the Address bar drop-down functionality in Microsoft Edge. - - - If you disable this setting, employees won't see the Address bar drop-down functionality in Microsoft Edge. This setting also disables the user-defined setting, "Show search and site suggestions as I type". - - > [!Note] - > Disabling this setting turns off the Address bar drop-down functionality. Therefore, because search suggestions are shown in the drop-down, this setting takes precedence over the "Configure search suggestions in Address bar" setting. +>*Supporteded versions: Windows 10, version 1703* +This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services. +| If you... | Then... | +| --- | --- | +| Enable this setting (default) | Employees can see the Address bar drop-down functionality in Microsoft Edge. | +| Disable this setting | Employees do not see the Address bar drop-down functionality in Microsoft Edge. This setting also disables the user-defined setting, "Show search and site suggestions as I type."
Disabling this setting turns off the Address bar drop-down functionality. Therefore, because search suggestions are shown in the drop-down, this setting takes precedence over the "Configure search suggestions in Address bar" setting. |
+|
+
### Allow Adobe Flash
-- **Supported versions:** Windows 10 or later
+>*Supporteded version: Windows 10*
-- **Description:** This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.
-
- - If you enable or don't configure this setting (default), employees can use Adobe Flash.
-
- - If you disable this setting, employees can't use Adobe Flash.
+This policy setting lets you decide whether employees can run Adobe Flash on Microsoft Edge.
+| If you… | Then… |
+| --- | --- |
+| Enable or don’t configure this setting (default) | Employees can use Adobe Flash. |
+| Disable this setting | Employees cannot use Adobe Flash. |
+|
### Allow clearing browsing data on exit
-- **Supported versions:** Windows 10, version 1703
+>*Supporteded versions: Windows 10, version 1703*
-- **Description:** This policy setting allows the automatic clearing of browsing data when Microsoft Edge closes.
-
- - If you enable this policy setting, clearing browsing history on exit is turned on.
-
- - If you disable or don't configure this policy setting (default), it can be turned on and configured by the employee in the Clear browsing data options area, under Settings.
+This policy setting allows the automatic clearing of browsing data when Microsoft Edge closes.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Clear browsing history on exit is turned on. |
+| Disable or don’t configure this setting (default) | Employees can turn on and configure the Clear browsing data option under Settings. |
+|
### Allow Developer Tools
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supporteded versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you decide whether F12 Developer Tools are available on Microsoft Edge.
- - If you enable or don’t configure this setting (default), the F12 Developer Tools are available in Microsoft Edge.
-
- - If you disable this setting, the F12 Developer Tools aren’t available in Microsoft Edge.
+This policy setting lets you decide whether F12 Developer Tools are available on Microsoft Edge.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | F12 Developer Tools are available. |
+| Disable this setting | F12 Developer Tools are not available. |
+|
### Allow Extensions
-- **Supported versions:** Windows 10, version 1607 or later
+>*Supporteded versions: Windows 10, version 1607 or later*
-- **Description:** This policy setting lets you decide whether employees can use Edge Extensions.
-
- - If you enable or don’t configure this setting, employees can use Edge Extensions.
-
- - If you disable this setting, employees can’t use Edge Extensions.
+This policy setting lets you decide whether employees can use Edge Extensions.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees can use Edge Extensions. |
+| Disable this setting | Employees cannot use Edge Extensions. |
+|
### Allow InPrivate browsing
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supporteded versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you decide whether employees can browse using InPrivate website browsing.
-
- - If you enable or don’t configure this setting (default), employees can use InPrivate website browsing.
-
- - If you disable this setting, employees can’t use InPrivate website browsing.
+This policy setting lets you decide whether employees can browse using InPrivate website browsing.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | Employees can use InPrivate website browsing. |
+| Disable this setting | Employees cannot use InPrivate website browsing. |
+|
### Allow Microsoft Compatibility List
-- **Supported versions:** Windows 10, version 1607 or later
+>*Supporteded versions: Windows 10, version 1607 or later*
-- **Description:** This policy setting lets you decide whether to use the Microsoft Compatibility List (a Microsoft-provided list that helps sites with known compatibility issues to display properly) in Microsoft Edge. By default, the Microsoft Compatibility List is enabled and can be viewed by visiting about:compat.
-
- - If you enable or don’t configure this setting (default), Microsoft Edge periodically downloads the latest version of the list from Microsoft, applying the updates during browser navigation. Visiting any site on the Microsoft Compatibility List prompts the employee to use Internet Explorer 11, where the site is automatically rendered as though it’s in whatever version of IE is necessary for it to appear properly.
-
- - If you disable this setting, the Microsoft Compatibility List isn’t used during browser navigation.
+This policy setting lets you decide whether to use the Microsoft Compatibility List (a Microsoft-provided list that helps sites with known compatibility issues to display properly) in Microsoft Edge. By default, the Microsoft Compatibility List is enabled and can be viewed by visiting about:compat.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | Microsoft Edge periodically downloads the latest version of the list from Microsoft, applying the updates during browser navigation . Visiting any site on the Microsoft Compatibility List prompts the employee to use Internet Explorer 11, where the site renders as though it’s in whatever version of IE is necessary for it to appear properly. |
+| Disable this setting | Browser navigation does not use the Microsoft Compatibility List. |
+|
### Allow search engine customization
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy setting lets you decide whether users can change their search engine.
+This policy setting lets you decide whether users can change their search engine. Important. You can only use this setting with domain-joined or MDM-enrolled devices.
- >[!Important]
- >This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).
+For more info, see the [Microsoft browser extension policy](http://aka.ms/browserpolicy).
- - If you enable or don't configure this policy (default), users can add new search engines and change the default used in the Address bar from within Microsoft Edge Settings.
-
- - If you disable this setting, users can't add search engines or change the default used in the address bar.
+| If you… | Then… |
+| --- | --- |
+| Enable or don’t configure this setting (default) | Employees can add new search engines and change the default used in the Address bar from within Microsoft Edge Settings. |
+| Disable this setting | Employees cannot add search engines or change the default used in the Address bar. |
+|
### Allow web content on New Tab page
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you configure what appears when Microsoft Edge opens a new tab. By default, Microsoft Edge opens the New Tab page. If you use this setting, employees can’t change it.
-
- - If you enable this setting, Microsoft Edge opens a new tab with the New Tab page.
-
- - If you disable this setting, Microsoft Edge opens a new tab with a blank page.
-
- - If you don’t configure this setting (default), employees can choose how new tabs appears.
+This policy setting lets you configure what appears when Microsoft Edge opens a new tab. By default, Microsoft Edge opens the New Tab page. If you use this setting, employees can’t change it.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Microsoft Edge opens a new tab with the New Tab page. |
+| Disable this setting | Microsoft Edge opens a new tab with a blank page. |
+| Do not configure this setting (default) | Employees can choose how new tabs appear. |
+|
### Configure additional search engines
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy setting lets you add up to 5 additional search engines, which can't be removed by your employees, but can be made a personal default engine. This setting doesn't set the default search engine. For that, you must use the "Set default search engine" setting.
-
- > [!Important]
- > This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).
-
- - If you enable this setting, you can add up to 5 additional search engines. For each additional engine, you must also add a link to your OpenSearch XML file, including at least the short name and https: URL of the search engine, using this format:
-
- For more info about creating the OpenSearch XML file, see the [Understanding OpenSearch Standards](https://msdn.microsoft.com/en-us/library/dd163546.aspx) topic. | Disable this setting (default) | Any added search engines are removed from the employee’s device. |
+| Do not configure this setting | The search engine list is set to what is specified in App settings. |
+|
### Configure Autofill
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge. By default, employees can choose whether to use Autofill.
-
- - If you enable this setting, employees can use Autofill to automatically fill in forms while using Microsoft Edge.
-
- - If you disable this setting, employees can’t use Autofill to automatically fill in forms while using Microsoft Edge.
-
- - If you don’t configure this setting (default), employees can choose whether to use Autofill to automatically fill in forms while using Microsoft Edge.
+This policy setting lets you decide whether employees can use Autofill the form fields automatically while using Microsoft Edge. By default, employees can choose whether to use Autofill.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees can use Autofill to populate form fields automatically. |
+| Disable this setting | Employees cannot use Autofill to populate form fields automatically. |
+| Do not configure this setting (default) | Employees can choose whether to use Autofill to populate the form fields automatically. |
+|
### Configure cookies
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This setting lets you configure how to work with cookies.
-
- - If you enable this setting, you must also decide whether to:
- - **Allow all cookies (default):** Allows all cookies from all websites.
-
- - **Block all cookies:** Blocks all cookies from all websites.
-
- - **Block only 3rd-party cookies:** Blocks only cookies from 3rd-party websites.
-
- - If you disable or don't configure this setting, all cookies are allowed from all sites.
+This setting lets you configure how to work with cookies.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | You must also decide whether to:
- >If you’re already using a site list, enterprise mode continues to work during the 65 second wait; it just uses your existing site list instead of your new one.
+>[!Note]
+>If there is a .xml file in the cache container, IE waits 65 seconds and then checks the local cache for a newer version of the file from the server, based on standard caching rules. If the server has a different version number than the version in the cache container, the server file is used and stored in the cache container.
- >If you'd like your employees to use the default Microsoft Edge settings for each market, you can set the string to EDGEDEFAULT. If you'd like your employees to use Microsoft Bing as the default search engine, you can set the string to EDGEBING.
+For more info, see the [Microsoft browser extension policy](http://aka.ms/browserpolicy).
- - If you enable this setting, you can choose a default search engine for your employees. To choose the default engine, you must add a link to your OpenSearch XML file, including at least the short name and https: URL of the search engine, using this format:
-
- https://fabrikam.com/opensearch.xml
-
- - If you disable this setting, the policy-set default search engine is removed. If this is also the current in-use default, the engine changes to the Microsoft Edge specified engine for the market.
-
- - If you don't configure this setting (default), the default search engine is set to the one specified in App settings.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | To set a default search engine, you must add a link to your OpenSearch XML file, including at least the short name and https URL of the search engine, using this format: Determines the type of content that can be copied from the host to Application Guard environment and vice versa. Value type is integer. Supported operations are Add, Get, Replace, and Delete. This policy setting allows you to decide how the clipboard behaves while in Application Guard. Value type is integer. Supported operations are Add, Get, Replace, and Delete
`
|
+| Disable or do not configure this setting | All cookies are allowed from all sites. |
+|
### Configure Do Not Track
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether employees can send Do Not Track requests to websites that ask for tracking info. By default, Do Not Track requests aren’t sent, but employees can choose to turn on and send requests.
-
- - If you enable this setting, Do Not Track requests are always sent to websites asking for tracking info.
-
- - If you disable this setting, Do Not Track requests are never sent to websites asking for tracking info.
-
- - If you don’t configure this setting (default), employees can choose whether to send Do Not Track requests to websites asking for tracking info.
+This policy setting lets you decide whether employees can send Do Not Track requests to websites that ask for tracking info. By default, Do Not Track requests are never sent, but employees can choose to turn on and send requests.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Do Not Track requests are always sent to websites asking for tracking information. |
+| Disable this setting | Do Not Track requests are never sent to websites asking for tracking information. |
+| Do not configure this setting (default) | Employees can choose whether to send Do Not Track requests to websites asking for tracking information. |
+|
### Configure Favorites
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supported versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you configure the default list of Favorites that appear for your employees. Employees can change their Favorites by adding or removing items at any time.
-
- - If you enable this setting, you can configure what default Favorites appear for your employees. If this setting is enabled, you must also provide a list of Favorites in the Options section. This list is imported after your policy is deployed.
-
- - If you disable or don’t configure this setting, employees will see the Favorites that they set in the Favorites hub.
+This policy setting lets you configure the default list of Favorites that appear for your employees. Employees can change their Favorites by adding or removing items at any time.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | You must provide a list of Favorites in the Options section. The list imports automatically after you deploy this policy. |
+| Disable or do not configure this setting | Employees will see the Favorites that they set in the Favorites hub. |
+|
### Configure Password Manager
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether employees can save their passwords locally, using Password Manager. By default, Password Manager is turned on.
-
- - If you enable this setting (default), employees can use Password Manager to save their passwords locally.
-
- - If you disable this setting, employees can’t use Password Manager to save their passwords locally.
-
- - If you don’t configure this setting, employees can choose whether to use Password Manager to save their passwords locally.
+This policy setting lets you decide whether employees can save their passwords locally, using Password Manager. By default, Password Manager is turned on.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | Employees can use Password Manager to save their passwords locally. |
+| Disable this setting | Employees can’t use Password Manager to save their passwords locally. |
+| Do not configure this setting | Employees can choose whether to use Password Manager to save their passwords locally. |
+|
### Configure Pop-up Blocker
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether to turn on Pop-up Blocker. By default, Pop-up Blocker is turned on.
-
- - If you enable this setting (default), Pop-up Blocker is turned on, stopping pop-up windows from appearing.
-
- - If you disable this setting, Pop-up Blocker is turned off, letting pop-ups windows appear.
-
- - If you don’t configure this setting, employees can choose whether to use Pop-up Blocker.
+This policy setting lets you decide whether to turn on Pop-up Blocker. By default, Pop-up Blocker is turned on.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting (default) | Pop-up Blocker is turned on, stopping pop-up windows from appearing. |
+| Disable this setting | Pop-up Blocker is turned off, letting pop-up windows appear. |
+| Do not configure this setting | Employees can choose whether to use Pop-up Blocker. |
+|
### Configure search suggestions in Address bar
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether search suggestions appear in the Address bar of Microsoft Edge. By default, employees can choose whether search suggestions appear in the Address bar of Microsoft Edge.
-
- - If you enable this setting, employees can see search suggestions in the Address bar of Microsoft Edge.
-
- - If you disable this setting, employees can't see search suggestions in the Address bar of Microsoft Edge.
-
- - If you don’t configure this setting (default), employees can choose whether search suggestions appear in the Address bar of Microsoft Edge.
+This policy setting lets you decide whether search suggestions appear in the Address bar of Microsoft Edge. By default, employees can choose whether search suggestions appear in the Address bar of Microsoft Edge.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees can see search suggestions in the Address bar. |
+| Disable this setting | Employees cannot see search suggestions in the Address bar. |
+| Do not configure this setting (default) | Employees can choose whether search suggestions appear in the Address bar. |
+|
### Configure Start pages
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supported versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you configure one or more Start pages, for domain-joined devices. Your employees won't be able to change this after you set it.
-
- - If you enable this setting, you can configure one or more Start pages. If this setting is enabled, you must also include URLs to the pages, separating multiple pages by using angle brackets in this format:
-
-
`
+>If you already use a site list, enterprise mode continues to work during the 65-second wait; it just uses the existing site list instead of the new one.
### Configure Windows Defender SmartScreen
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you configure whether to turn on Windows Defender SmartScreen. Windows Defender SmartScreen provides warning messages to help protect your employees from potential phishing scams and malicious software. By default, Windows Defender SmartScreen is turned on.
-
- - If you enable this setting, Windows Defender SmartScreen is turned on and employees can’t turn it off.
-
- - If you disable this setting, Windows Defender SmartScreen is turned off and employees can’t turn it on.
-
- - If you don’t configure this setting (default), employees can choose whether to use Windows Defender SmartScreen.
+This policy setting lets you configure whether to turn on Windows Defender SmartScreen. Windows Defender SmartScreen provides warning messages to help protect your employees from potential phishing scams and malicious software. By default, Windows Defender SmartScreen is turned on.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Windows Defender SmartScreen is turned on, and employees cannot turn it off. |
+| Disable this setting | Windows Defender SmartScreen is turned off, and employees cannot turn it on. |
+| Do not configure this setting | Employees can choose whether to use Windows Defender SmartScreen. |
+|
### Disable lockdown of Start pages
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy setting lets you disable the lock down of Start pages, letting employees modify the Start pages when the "Configure Start pages" setting is in effect.
+This policy setting lets you disable the lockdown of Start pages if the Configure Start pages setting is in effect . This setting only applies to domain-joined or MDM-enrolled devices.
- >[!Important]
- >This setting only applies when you're using the “Configure Start pages" setting and can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).
-
- - If you enable this setting, you can't lock down any Start pages that are configured using the "Configure Start pages" setting, which means that employees can modify them.
-
- - If you disable or don't configure this setting (default), employees can't change any Start pages configured using the "Configure Start pages" setting, thereby locking down the Start pages.
+For more info, see the [Microsoft browser extension policy](http://aka.ms/browserpolicy).
+
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | You cannot lock down Start pages that are configured using the “Configure Start pages” setting. Employees can, therefore, modify the pages. |
+| Disable or do not configure this setting (default) | Employees cannot change Start pages configured using the “Configure Start pages” setting. |
+|
### Keep favorites in sync between Internet Explorer and Microsoft Edge
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This setting lets you decide whether people can sync their favorites between Internet Explorer and Microsoft Edge, including additions, deletions, changes, and position.
+This policy setting lets you decide whether people can sync their favorites between Internet Explorer and Microsoft Edge, including additions, deletions, changes, and position.
- >[!Note]
- >Enabling this setting stops Edge favorites from syncing between connected Windows 10 devices.
-
- - If you enable this setting, employees can sync their favorites between Internet Explorer and Microsoft Edge.
-
- - If you disable or don't configure this setting (default), employees can’t sync their favorites between Internet Explorer and Microsoft Edge.
+
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees can sync their favorites between Internet Explorer and Microsoft Edge.
Enabling this setting stops Edge favorites from syncing between connected Windows 10 devices. |
+| Disable or do not configure this setting | Employees cannot sync their favorites between Internet Explorer and Microsoft Edge. |
+|
### Prevent access to the about:flags page
-- **Supported versions:** Windows 10, version 1607 or later
+>*Supported versions: Windows 10, version 1607 or later*
-- **Description:** This policy setting lets you decide whether employees can access the about:flags page, which is used to change developer settings and to enable experimental features.
-
- - If you enable this policy setting, employees can’t access the about:flags page.
-
- - If you disable or don’t configure this setting (default), employees can access the about:flags page.
+This policy setting lets you decide whether employees can access the about:flags page, which is used to change developer settings and to enable experimental features.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees cannot access the about:flags page. |
+| Disable or do not configure this setting (default) | Employees can access the about:flags page. |
+|
### Prevent bypassing Windows Defender SmartScreen prompts for files
-- **Supported versions:** Windows 10, version 1511 or later
-
-- **Description:** This policy setting lets you decide whether employees can override the Windows Defender SmartScreen warnings about downloading unverified files.
-
- - If you enable this setting, employees can’t ignore Windows Defender SmartScreen warnings and they’re blocked from downloading the unverified files.
-
- - If you disable or don’t configure this setting (default), employees can ignore Windows Defender SmartScreen warnings and continue the download process.
+>*Supported versions: Windows 10, version 1511 or later*
+This policy setting lets you decide whether employees can override the Windows Defender SmartScreen warnings about downloading unverified files.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees cannot ignore Windows Defender SmartScreen warnings when downloading files. |
+| Disable or do not configure this setting (default) | Employees can ignore Windows Defender SmartScreen warnings and can continue the download process. |
+|
### Prevent bypassing Windows Defender SmartScreen prompts for sites
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supported versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you decide whether employees can override the Windows Defender SmartScreen warnings about potentially malicious websites.
-
- - If you enable this setting, employees can’t ignore Windows Defender SmartScreen warnings and they’re blocked from continuing to the site.
-
- - If you disable or don’t configure this setting (default), employees can ignore Windows Defender SmartScreen warnings and continue to the site.
+This policy setting lets you decide whether employees can override the Windows Defender SmartScreen warnings about potentially malicious websites.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees cannot ignore Windows Defender SmartScreen warnings and prevents them from continuing to the site. |
+| Disable or do not configure this setting (default) | Employees can ignore Windows Defender SmartScreen warnings, allowing them to continue to the site. |
+|
### Prevent Microsoft Edge from gathering Live Tile information when pinning a site to Start
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.
+This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Microsoft Edge does not gather the Live Tile metadata, providing a minimal experience. |
+| Disable or do not configure this setting (default) | Microsoft Edge gathers the Live Tile metadata, providing a fuller and complete experience. |
+|
- - If you enable this setting, Microsoft Edge won't gather the Live Tile metadata, providing a minimal experience when a user pins a Live Tile to the Start menu.
-
- - If you disable or don't configure this setting (default), Microsoft Edge gathers the Live Tile metadata, providing a fuller and more complete experience when a user pins a Live Tile to the Start menu.
### Prevent the First Run webpage from opening on Microsoft Edge
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy setting lets you decide whether employees see Microsoft's First Run webpage when opening Microsoft Edge for the first time.
-
- - If you enable this setting, employees won't see the First Run page when opening Microsoft Edge for the first time.
-
- - If you disable or don't configure this setting (default), employees will see the First Run page when opening Microsoft Edge for the first time.
+This policy setting lets you decide whether employees see Microsoft's First Run webpage when opening Microsoft Edge for the first time.
+| If you… | Then… |
+| --- | --- |
+| Enable this settin | Employees do not see the First Run page. |
+| Disable or do not configure this setting (default) | Employees see the First Run page. |
+|
### Prevent using Localhost IP address for WebRTC
-- **Supported versions:** Windows 10, version 1511 or later
+>*Supported versions: Windows 10, version 1511 or later*
-- **Description:** This policy setting lets you decide whether an employee’s Localhost IP address shows while making calls using the WebRTC protocol. By default, this setting is turned off.
-
- - If you enable this setting, Localhost IP addresses are hidden while making calls using the WebRTC protocol.
-
- - If you disable or don’t configure this setting (default), Localhost IP addresses are shown while making calls using the WebRTC protocol.
+This policy setting lets you decide whether localhost IP addresses are visible or hidden while making calls to the WebRTC protocol.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Localhost IP addresses are hidden. |
+| Disable or do not configure this setting (default) | Localhost IP addresses are visible. |
+|
### Send all intranet sites to Internet Explorer 11
-- **Supported versions:** Windows 10 or later
+>*Supported versions: Windows 10*
-- **Description:** This policy setting lets you decide whether your intranet sites should all open using Internet Explorer 11. This setting should only be used if there are known compatibility problems with Microsoft Edge.
-
- - If you enable this setting, all intranet sites are automatically opened using Internet Explorer 11.
-
- - If you disable or don’t configure this setting (default), all websites, including intranet sites, are automatically opened using Microsoft Edge.
+This policy setting lets you decide whether your intranet sites should all open using Internet Explorer 11. This setting should only be used if there are known compatibility problems with Microsoft Edge.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | All intranet sites are opened in Internet Explorer 11 automatically. |
+| Disable or do not configure this setting (default) | All websites, including intranet sites, open in Microsoft Edge. |
+|
### Set default search engine
-- **Supported versions:** Windows 10, version 1703
+>*Supported versions: Windows 10, version 1703*
-- **Description:** This policy setting lets you configure the default search engine for your employees. Employees can change the default search engine at any time unless you disable the "Allow search engine customization" setting, which restricts any changes.
+This policy setting applies only to domain-joined or MDM-enrolled devices and lets you configure the default search engine for Microsoft Edge. Employees can change the default search engine at any time unless you disable the "Allow search engine customization" setting, which restricts any changes.
- >[!Important]
- >This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).
`https://fabrikam.com/opensearch.xml` |
+| Disable this setting | The policy-set default search engine is removed. If this is also the current in-use default, the search engine changes to the Microsoft Edge specified engine for the market . |
+| Do not configure this setting | The default search engine is set to the one specified in App settings. |
+|
+>[!Important]
+>If you'd like your employees to use the default Microsoft Edge settings for each market , you can set the string to EDGEDEFAULT. If you'd like your employees to use Microsoft Bing as the default search engine, you can set the string to EDGEBING.
### Show message when opening sites in Internet Explorer
-- **Supported versions:** Windows 10, version 1607 and later
+>*Supported versions: Windows 10, version 1607 and later*
-- **Description:** This policy setting lets you decide whether employees see an additional page in Microsoft Edge, stating that a site has been opened using Internet Explorer 11.
-
- - If you enable this setting, employees see an additional page in Microsoft Edge, stating that a site has been opened using Internet Explorer 11.
-
- - If you disable or don’t configure this setting (default), the default app behavior occurs and no additional page appears.
+This policy setting lets you decide whether employees see an additional page in Microsoft Edge, stating that a site has been opened using Internet Explorer 11.
+| If you… | Then… |
+| --- | --- |
+| Enable this setting | Employees see an additional page. |
+| Disable or do not configure this setting (default) | No additional pages display. |
+|
## Using Microsoft Intune to manage your Mobile Device Management (MDM) settings for Microsoft Edge
If you manage your policies using Intune, you'll want to use these MDM policy settings. You can see the full list of available policies, on the [Policy CSP]( https://go.microsoft.com/fwlink/p/?LinkId=722885) page.
@@ -397,7 +407,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1 (default).** Allowed. Address bar drop-down is enabled.
### AllowAutofill
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Desktop
@@ -414,7 +424,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1 (default).** Employees can use Autofill to complete form fields.
### AllowBrowser
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Mobile
@@ -431,7 +441,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1 (default).** Employees can use Microsoft Edge.
### AllowCookies
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Both
@@ -462,12 +472,12 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **Allowed values:**
- - **0.** Employees can't use the F12 Developer Tools.
+ - **0.** Employees cannot use the F12 Developer Tools.
- **1 (default).** Employees can use the F12 Developer Tools.
### AllowDoNotTrack
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Both
@@ -501,7 +511,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1 (default).** Employees can use Edge Extensions.
### AllowFlash
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Desktop
@@ -564,12 +574,12 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **Allowed values:**
- - **0.** Additional search engines aren't allowed and the default can’t be changed in the Address bar.
+ - **0.** Additional search engines are not allowed and the default can’t be changed in the Address bar.
- **1 (default).** Additional search engines are allowed and the default can be changed in the Address bar.
### AllowPasswordManager
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Both
@@ -581,12 +591,12 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **Allowed values:**
- - **0 (default).** Employees can't use Password Manager to save passwords locally.
+ - **0 (default).** Employees cannot use Password Manager to save passwords locally.
- **1.** Employees can use Password Manager to save passwords locally.
### AllowPopups
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Desktop
@@ -621,7 +631,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
### AllowSearchSuggestionsinAddressBar
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Both
@@ -638,7 +648,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1.** Employees can see search suggestions in the Address bar of Microsoft Edge.
### AllowSmartScreen
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Both
@@ -706,7 +716,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
- **1.** Disable lockdown of the Start pages and allow users to modify them.
### EnterpriseModeSiteList
-- **Supported versions:** Windows 10 or later
+- **Supported versions:** Windows 10
- **Supported devices:** Desktop
@@ -747,7 +757,7 @@ All devices must be enrolled with Intune if you want to use the Windows Custom U
+
+[@Reviewer: will RS5 have the need for the following note?]
+>[!NOTE]
>If you want to use Group Policy to set Internet Explorer as your default browser, you can find the info here, [Set the default browser using Group Policy]( https://go.microsoft.com/fwlink/p/?LinkId=620714).
## Fix specific websites
@@ -98,7 +98,5 @@ You can add the **Send all intranet traffic over to Internet Explorer** Group Po
* [Set the default browser using Group Policy]( https://go.microsoft.com/fwlink/p/?LinkId=620714)
-
-
diff --git a/browsers/edge/hardware-and-software-requirements.md b/browsers/edge/hardware-and-software-requirements.md
index 6c45062cc6..81c4a2c980 100644
--- a/browsers/edge/hardware-and-software-requirements.md
+++ b/browsers/edge/hardware-and-software-requirements.md
@@ -13,15 +13,13 @@ ms.date: 07/27/2017
# Microsoft Edge requirements and language support
-**Applies to:**
-
-- Windows 10
-- Windows 10 Mobile
+>Applies to: Windows 10, Windows 10 Mobile
Microsoft Edge is pre-installed on all Windows 10-capable devices that meet the minimum system requirements and are on the supported language list.
->**Note**
The Long-Term Servicing Branch (LTSB) versions of Windows, including Windows Server 2016, don't include Microsoft Edge or many other Universal Windows Platform (UWP) apps. These apps and their services are frequently updated with new functionality, and can't be supported on systems running the LTSB operating systems. For customers who require the LTSB for specialized devices, we recommend using Internet Explorer 11.
+>[!NOTE]
+>The Long-Term Servicing Branch (LTSB) versions of Windows, including Windows Server 2016, don't include Microsoft Edge or many other Universal Windows Platform (UWP) apps. These apps and their services are frequently updated with new functionality, and can't be supported on systems running the LTSB operating systems. For customers who require the LTSB for specialized devices, we recommend using Internet Explorer 11.
## Minimum system requirements
Some of the components in this table might also need additional system resources. Check the component's documentation for more information.
diff --git a/browsers/edge/microsoft-edge-faq.md b/browsers/edge/microsoft-edge-faq.md
index ca6eea8b48..05335d7416 100644
--- a/browsers/edge/microsoft-edge-faq.md
+++ b/browsers/edge/microsoft-edge-faq.md
@@ -12,10 +12,7 @@ ms.date: 09/19/2017
# Microsoft Edge - Frequently Asked Questions (FAQs) for IT Pros
-**Applies to:**
-
-- Windows 10
-- Windows 10 Mobile
+>Applies to: Windows 10, Windows 10 Mobile
**Q: What is the difference between Microsoft Edge and Internet Explorer 11? How do I know which one to use?**
diff --git a/browsers/edge/security-enhancements-microsoft-edge.md b/browsers/edge/security-enhancements-microsoft-edge.md
index 2e06bbe027..40952d55dc 100644
--- a/browsers/edge/security-enhancements-microsoft-edge.md
+++ b/browsers/edge/security-enhancements-microsoft-edge.md
@@ -11,19 +11,16 @@ ms.date: 10/16/2017
# Security enhancements for Microsoft Edge
-**Applies to:**
-
-- Windows 10
-- Windows 10 Mobile
+>Applies to: Windows 10, Windows 10 Mobile
Microsoft Edge is designed with significant security improvements, helping to defend people from increasingly sophisticated and prevalent web-based attacks against Windows.
## Help to protect against web-based security threats
While most websites are safe, some sites have been designed to steal personal information or gain access to your system’s resources. Thieves by nature don’t care about rules, and will use any means to take advantage of victims, most often using trickery or hacking:
-- **Trickery.** Means using things like “phishing” attacks to convince a person to enter a banking password into a website that looks like the bank, but isn’t.
+- **Trickery** uses things like “phishing” attacks to convince a person to enter a banking password into a website that looks like the bank, but isn’t.
-- **Hacking.** Means attacking a system through malformed content that exploits subtle flaws in a browser, or in various browser extensions, such as video decoders. This exploit lets an attacker run code on a device, taking over first a browsing session, and perhaps ultimately the entire device.
+- **Hacking** attacks a system through malformed content that exploits subtle flaws in a browser, or in various browser extensions, such as video decoders. This exploit lets an attacker run code on a device, taking over first a browsing session, and perhaps ultimately the entire device.
While trickery and hacking are threats faced by every browser, it’s important that we explore how Microsoft Edge addresses these threats and is helping make the web a safer experience.
@@ -55,8 +52,8 @@ The Microsoft EdgeHTML engine also helps to defend against hacking through these
- Support for the [HTTP Strict Transport Security (HSTS)](https://developer.microsoft.com/microsoft-edge/platform/documentation/dev-guide/security/HSTS/) security feature (IETF-standard compliant). This helps ensure that connections to important sites, such as to your bank, are always secured.
- **Note**
- Both Microsoft Edge and Internet Explorer 11 support HSTS.
+>[!NOTE]
+>Both Microsoft Edge and Internet Explorer 11 support HSTS.
#### All web content runs in an app container sandbox
Internet Explorer 7 on Windows Vista was the first web browser to provide a browsing sandbox, called [Protected Mode](http://windows.microsoft.com/windows-vista/What-does-Internet-Explorer-protected-mode-do). Protected Mode forced the part of the browser that rendered web content to run with less privilege than the browser controls or the user, providing a level of isolation and protection should a malicious website attempt to exploit a bug in the browser or one of its plug-ins.
diff --git a/devices/hololens/hololens-enroll-mdm.md b/devices/hololens/hololens-enroll-mdm.md
index 428a49e956..1412357e31 100644
--- a/devices/hololens/hololens-enroll-mdm.md
+++ b/devices/hololens/hololens-enroll-mdm.md
@@ -12,7 +12,7 @@ ms.date: 07/27/2017
# Enroll HoloLens in MDM
-You can manage multiple Microsoft HoloLens devices simultaneously using solutions like Microsoft Intune. You will be able to manage settings, select apps to install and set security configurations tailored to your organization's need. See the [configuration service providers (CSPs) that are supported in Windows Holographic](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/configuration-service-provider-reference#hololens) and the [policies supported by Windows Holographic for Business](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#hololenspolicies).
+You can manage multiple Microsoft HoloLens devices simultaneously using solutions like Microsoft Intune. You will be able to manage settings, select apps to install and set security configurations tailored to your organization's need. See [Manage devices running Windows Holographic with Microsoft Intune](https://docs.microsoft.com/intune/windows-holographic-for-business), the [configuration service providers (CSPs) that are supported in Windows Holographic](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/configuration-service-provider-reference#hololens), and the [policies supported by Windows Holographic for Business](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#hololenspolicies).
>[!NOTE]
>Mobile device management (MDM), including the VPN, Bitlocker, and kiosk mode features, is only available when you [upgrade to Windows Holographic for Business](hololens-upgrade-enterprise.md).
diff --git a/devices/surface-hub/change-history-surface-hub.md b/devices/surface-hub/change-history-surface-hub.md
index 595a61e131..efa2e4ddcf 100644
--- a/devices/surface-hub/change-history-surface-hub.md
+++ b/devices/surface-hub/change-history-surface-hub.md
@@ -8,7 +8,7 @@ ms.sitesec: library
ms.pagetype: surfacehub
author: jdeckerms
ms.author: jdecker
-ms.date: 01/17/2018
+ms.date: 02/16/2018
ms.localizationpriority: medium
---
@@ -16,6 +16,12 @@ ms.localizationpriority: medium
This topic lists new and updated topics in the [Surface Hub Admin Guide]( surface-hub-administrators-guide.md).
+## February 2018
+
+New or changed topic | Description
+--- | ---
+[Manage settings with an MDM provider (Surface Hub)](manage-settings-with-mdm-for-surface-hub.md) | Updated instructions for custom settings using Microsoft Intune.
+
## January 2018
New or changed topic | Description
diff --git a/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md b/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
index 23eb0e418f..7e530429bf 100644
--- a/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
+++ b/devices/surface-hub/manage-settings-with-mdm-for-surface-hub.md
@@ -9,7 +9,7 @@ ms.sitesec: library
ms.pagetype: surfacehub, mobility
author: jdeckerms
ms.author: jdecker
-ms.date: 01/17/2018
+ms.date: 02/16/2018
ms.localizationpriority: medium
---
@@ -212,38 +212,9 @@ The data type is also stated in the CSP documentation. The most common data type
## Example: Manage Surface Hub settings with Microsoft Intune
-You can use Microsoft Intune to manage Surface Hub settings.
+You can use Microsoft Intune to manage Surface Hub settings. For custom settings, follow the instructions in [How to configure custom device settings in Microsoft Intune](https://docs.microsoft.com/intune/custom-settings-configure). For **Platform**, select **Windows 10 and later**, and in **Profile type**, select **Device restrictions (Windows 10 Team)**.
-**To create a configuration policy from a template**
-You'll use the **Windows 10 Team general configuration policy** as the template.
-
-1. On the [Intune management portal](https://manage.microsoft.com), sign in with your Intune administrator account.
-2. On the left-hand navigation menu, click **Policy**.
-3. In the Overview page, click **Add Policy**.
-4. On **Select a template for the new policy**, expand **Windows**, select **General Configuration (Windows 10 Team and later)**, and then click **Create Policy**.
-
- 
-5. Configure your policy, then click **Save Policy**
-
- 
-6. When prompted, click **Yes** to deploy your new policy to a user or device group. For more information, see [Use groups to manage users and devices in Microsoft Intune](https://docs.microsoft.com/intune/deploy-use/use-groups-to-manage-users-and-devices-with-microsoft-intune).
-
-**To create a custom configuration policy**
-
-You’ll need to create a custom policy using the **Custom Configuration (Windows 10 Desktop and Mobile and later)** template to manage settings that are not available in the **Windows 10 Team general configuration policy** template.
-
-1. On the [Intune management portal](https://manage.microsoft.com), sign in with your Intune administrator account.
-2. On the left-hand navigation menu, click **Policy**.
-3. On the Overview page, click **Add Policy**.
-4. On **Select a template for the new policy**, expand **Windows**, select **Custom Configuration (Windows 10 Desktop and Mobile and later)**, and then click **Create Policy**.
-5. Type a name and optional description for the policy.
-6. Under OMA-URI Settings, click **Add**.
-7. Complete the form to create a new setting, and then click **OK**.
-
- 
-8. Repeat Steps 6 and 7 for each setting you want to configure with this policy.
-9. After you're done, click **Save Policy** and deploy it to a user or device group.
## Example: Manage Surface Hub settings with System Center Configuration Manager
diff --git a/devices/surface-hub/surface-hub-start-menu.md b/devices/surface-hub/surface-hub-start-menu.md
index dccacb8551..07671c8e12 100644
--- a/devices/surface-hub/surface-hub-start-menu.md
+++ b/devices/surface-hub/surface-hub-start-menu.md
@@ -28,7 +28,7 @@ The customized Start menu is defined in a Start layout XML file. You have two op
- Configure the desired Start menu on a desktop (pinning only apps that are available on Surface Hub), and then [export the layout](https://docs.microsoft.com/windows/configuration/customize-and-export-start-layout#export-the-start-layout).
>[!TIP]
->To add a tile with a web link to your desktop start menu, go the the link in Microsoft Edge, select `...` in the top right corner, and select **Pin this page to Start**. See [a Start layout that includes a Microsoft Edge link](#edge) for an example of how links will appear in the XML.
+>To add a tile with a web link to your desktop start menu, go to the link in Microsoft Edge, select `...` in the top right corner, and select **Pin this page to Start**. See [a Start layout that includes a Microsoft Edge link](#edge) for an example of how links will appear in the XML.
To edit the default XML or the exported layout, familiarize yourself with the [Start layout XML](https://docs.microsoft.com/en-us/windows/configuration/start-layout-xml-desktop). There are a few [differences between Start layout on a deskop and a Surface Hub.](#differences)
@@ -180,4 +180,4 @@ This example shows a link to a website and a link to a .pdf file.
## More information
-- [Blog post: Changing Surface Hub’s Start Menu](https://blogs.technet.microsoft.com/y0av/2018/02/13/47/)
\ No newline at end of file
+- [Blog post: Changing Surface Hub’s Start Menu](https://blogs.technet.microsoft.com/y0av/2018/02/13/47/)
diff --git a/mdop/mbam-v25/TOC.md b/mdop/mbam-v25/TOC.md
index d465652210..22008a42bb 100644
--- a/mdop/mbam-v25/TOC.md
+++ b/mdop/mbam-v25/TOC.md
@@ -55,6 +55,7 @@
#### [How to Enable BitLocker by Using MBAM as Part of a Windows Deployment](how-to-enable-bitlocker-by-using-mbam-as-part-of-a-windows-deploymentmbam-25.md)
#### [How to Deploy the MBAM Client by Using a Command Line](how-to-deploy-the-mbam-client-by-using-a-command-line.md)
### [MBAM 2.5 Deployment Checklist](mbam-25-deployment-checklist.md)
+### [Upgrading to MBAM 2.5 SP1 from MBAM 2.5](upgrading-to-mbam-25-sp1-from-mbam-25.md)
### [Upgrading to MBAM 2.5 or MBAM 2.5 SP1 from Previous Versions](upgrading-to-mbam-25-or-mbam-25-sp1-from-previous-versions.md)
### [Removing MBAM Server Features or Software](removing-mbam-server-features-or-software.md)
## [Operations for MBAM 2.5](operations-for-mbam-25.md)
diff --git a/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md
new file mode 100644
index 0000000000..f650f130b3
--- /dev/null
+++ b/mdop/mbam-v25/upgrading-to-mbam-25-sp1-from-mbam-25.md
@@ -0,0 +1,44 @@
+---
+title: Upgrading to MBAM 2.5 SP1 from MBAM 2.5
+description: Upgrading to MBAM 2.5 SP1 from MBAM 2.5
+author: kaushika-msft
+ms.assetid:
+ms.pagetype: mdop, security
+ms.mktglfcycl: manage
+ms.sitesec: library
+ms.prod: w10
+ms.date: 2/16/2018
+---
+
+# Upgrading to MBAM 2.5 SP1 from MBAM 2.5
+This topic describes the process for upgrading the Microsoft BitLocker Administration and Monitoring (MBAM) Server 2.5 and the MBAM Client from 2.5 to MBAM 2.5 SP1.
+
+### Before you begin, download the September 2017 servicing release
+[Desktop Optimization Pack](https://www.microsoft.com/en-us/download/details.aspx?id=56126)
+
+#### Steps to upgrade the MBAM Database (SQL Server)
+1. Using the MBAM Configurator; remove the Reports roll from the SQL server, or wherever the SSRS database is housed (Could be on the same server or different one, depending on your environment)
+Note: You will not see an option to remove the Databases; this is expected.
+2. Install 2.5 SP1 (Located with MDOP - Microsoft Desktop Optimization Pack 2015 from the Volume Licensing Service Center site:
The new **Products & services** page in Microsoft Store for Business and Education gives customers a single place to manage all products and services. This includes Apps, Software, and Subscriptions that your organization acquired or manages through Microsoft Store for Business. This change centralizes these products, but the platform changes also improve overall performance.
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
+|  |**Create collections of apps in your private store**
Use **collections** to customize your private store. Collections allow you to create groups of apps that are commonly used in your organization or school -- you might create a collection for a Finance department, or a 6th-grade class.
[Get more info](https://docs.microsoft.com/microsoft-store/manage-private-store-settings#private-store-collections)
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
|  |**Upgrade Office 365 trial subscription**
Customers with Office 365 trials can now transition their trial to a paid subscription in Microsoft Store for Business. This works for trials you acquired from Microsoft Store for Business, or Office Admin Portal.
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
|  |**Supporting Microsoft Product and Services Agreement customers**
If you are purchasing under the Microsoft Products and Services Agreement (MPSA), you can use Microsoft Store for Business. Here you will find access to Products & Services purchased, Downloads & Keys, Software Assurance benefits, Order history, and Agreement details. Also, we added the ability to associate your purchasing account to your tenant.
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
|  |**Microsoft Product and Services Agreement customers can invite people to take roles**
MPSA admins can invite people to take Microsoft Store for Business roles even if the person is not in their tenant. You provide an email address when you assign the role, and we'll add the account to your tenant and assign the role.
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
@@ -30,6 +31,7 @@ Microsoft Store for Business and Education regularly releases new and improved f
We’ve been working on bug fixes and performance improvements to provide you a better experience. Stay tuned for new features!
| | |
|-----------------------|---------------------------------|
+|  |**Performance improvements in private store**
We've made it significantly faster for you to update the private store. Many changes to the private store are available immediately after you make them.
[Get more info](https://docs.microsoft.com/microsoft-store/manage-private-store-settings#private-store-performance)
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
| | **Manage Windows device deployment with Windows AutoPilot Deployment**
In Microsoft Store for Business, you can manage devices for your organization and apply an AutoPilot deployment profile to your devices. When people in your organization run the out-of-box experience on the device, the profile configures Windows, based on the AutoPilot deployment profile you applied to the device.
[Get more info](add-profile-to-devices.md)
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
|  |**Request an app**
People in your organization can reqest additional licenses for apps in your private store, and then Admins or Purchasers can make the purchases.
[Get more info](https://docs.microsoft.com/microsoft-store/acquire-apps-microsoft-store-for-business#request-apps)
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
||  |**Private store collections**
You can groups of apps in your private store with **Collections**. This can help you organize apps and help people find apps for their job or classroom.
[Get more info](https://review.docs.microsoft.com/microsoft-store/manage-private-store-settings?branch=msfb-14856406#add-a-collection)
**Applies to**:
Microsoft Store for Business
Microsoft Store for Education |
diff --git a/windows/application-management/apps-in-windows-10.md b/windows/application-management/apps-in-windows-10.md
index 521038e82e..08850b0417 100644
--- a/windows/application-management/apps-in-windows-10.md
+++ b/windows/application-management/apps-in-windows-10.md
@@ -117,7 +117,7 @@ Here are the typical provisioned Windows apps in Windows 10 versions 1607, 1703,
| Get Skype/Skype (preview)/Skype | Microsoft.SkypeApp | x | x | x | Yes |
| Get Started/Tips | Microsoft.Getstarted | x | x | x | Yes |
| Groove | Microsoft.ZuneMusic | x | x | x | No |
-| Mail and Calendar | Microsoft.windows communicationsapps | x | x | x | No |
+| Mail and Calendar | microsoft.windowscommunicationsapps | x | x | x | No |
| Maps | Microsoft.WindowsMaps | x | x | x | No |
| Messaging | Microsoft.Messaging | x | x | x | No |
| Microsoft 3D Viewer | Microsoft.Microsoft3DViewer | | x | x | No |
@@ -128,11 +128,11 @@ Here are the typical provisioned Windows apps in Windows 10 versions 1607, 1703,
| People | Microsoft.People | x | x | x | No |
| Photos | Microsoft.Windows.Photos | x | x | x | No |
| Print 3D | Microsoft.Print3D | | | x | No |
-| Solitaire | Microsoft.Microsoft SolitaireCollection | x | x | x | Yes |
+| Solitaire | Microsoft.MicrosoftSolitaireCollection | x | x | x | Yes |
| Sticky Notes | Microsoft.MicrosoftStickyNotes | x | x | x | No |
| Store | Microsoft.WindowsStore | x | x | x | No |
| Sway | Microsoft.Office.Sway | * | * | x | Yes |
-| Voice Recorder | Microsoft.SoundRecorder | x | x | x | No |
+| Voice Recorder | Microsoft.WindowsSoundRecorder | x | x | x | No |
| Wallet | Microsoft.Wallet | | x | x | No |
| Weather | Microsoft.BingWeather | x | x | x | Yes |
| Xbox | Microsoft.XboxApp | x | x | x | No |
@@ -143,4 +143,4 @@ Here are the typical provisioned Windows apps in Windows 10 versions 1607, 1703,
| | Microsoft.XboxIdentityProvider | x | x | * | No |
| | Microsoft.XboxSpeech ToTextOverlay | | x | x | No |
-\* moved from "provisioned" to "installed" in this version.
\ No newline at end of file
+\* moved from "provisioned" to "installed" in this version.
diff --git a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
index 6b6afaec07..710bbc8021 100644
--- a/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
+++ b/windows/client-management/mdm/windowsdefenderapplicationguard-csp.md
@@ -34,14 +34,18 @@ The following diagram shows the WindowsDefenderApplicationGuard configuration se
**Settings/ClipboardFileType**
|
+
+## Device, Connectivity, and Configuration data
+This type of data includes details about the device, its configuration and connectivity capabilities, and status. Device, Connectivity, and Configuration Data is equivalent to ISO/IEC 19944:2017, 8.2.3.2.3 Connectivity data.
+
+### Data Use for Device, Connectivity, and Configuration data
+
+**For Diagnostics:**
+[Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft products and services. For example:
+
+- Device, Connectivity, and Configuration data is used to understand the unique device characteristics that can contribute to an error experienced on the device, to identify patterns, and to more quickly resolve problems that impact devices with unique hardware, capabilities, or settings. For example:
+
+ - Data about the use of cellular modems and their configuration on your devices is used to troubleshoot cellular modem issues.
+
+ - Data about the use of USB hubs use and their configuration on your devices is used to troubleshoot USB hub issues.
+
+ - Data about the use of connected Bluetooth devices is used to troubleshoot compatibility issues with Bluetooth devices.
+
+- Data about device properties, such as the operating system version and available memory, is used to determine whether the device is due to, and able to, receive a Windows update.
+
+- Data about device peripherals is used to determine whether a device has installed drivers that might be negatively impacted by a Windows update.
+
+- Data about which devices, peripherals, and settings are most-used by customers, is used to prioritize Windows 10 improvements to determine the greatest positive impact to the most Windows 10 users.
+
+**With (optional) Tailored experiences:**
+If a user has enabled Tailored experiences on the device, [Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [Pseudonymized](#pseudo) Device, Connectivity, and Configuration data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
+
+- Data about device properties and capabilities is used to provide tips about how to use or configure the device to get the best performance and user experience.
+
+- Data about device capabilities, such as whether the device is pen-enabled, is used to recommend (Microsoft and third-party) apps that are appropriate for the device. These may be free or paid apps.
+
+### Data Description for Device, Connectivity, and Configuration data type
+|Sub-type|Description and examples|
+|- |- |
+|Device properties |Information about the operating system and device hardware, such as:
|
+|Device capabilities|Information about the specific device capabilities, such as:
|
+|Device preferences and settings |Information about the device settings and user preferences, such as:
|
+|Device peripherals |Information about the device peripherals, such as:
|
+|Device network info |Information about the device network configuration, such as:
+
+## Product and Service Usage data
+This type of data includes details about the usage of the device, operating system, applications and services. Product and Service Usage data is equivalent to ISO/IEC 19944:2017, 8.2.3.2.4 Observed Usage of the Service Capability.
+
+### Data Use for Product and Service Usage data
+
+**For Diagnostics:**
+[Pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
+
+- Data about the specific apps that are in-use when an error occurs is used to troubleshoot and repair issues with Windows features and Microsoft apps.
+
+- Data about the specific apps that are most-used by customers, is used to prioritize Windows 10 improvements to determine the greatest positive impact to the most Windows 10 users.
+
+- Data about whether devices have Suggestions turned off from the **Settings Phone** screen is to improve the Suggestions feature.
+
+- Data about whether a user canceled the authentication process in their browser is used to help troubleshoot issues with and improve the authentication process.
+
+- Data about when and what feature invoked Cortana is used to prioritize efforts for improvement and innovation in Cortana.
+
+- Data about when a context menu in the photo app is closed is used to troubleshoot and improve the photo app.
+
+**With (optional) Tailored experiences:**
+If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Usage data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
+
+- If data shows that a user has not used a particular feature of Windows, we may recommend that the user try that feature.
+
+- Data about which apps are most-used on a device is used to provide recommendations for similar or complementary (Microsoft or third-party) apps. These may be free or paid apps.
+
+
+### Data Description for Product and Service Usage data type
+|Sub-type|Description and examples |
+|- |- |
+|App usage|Information about Windows and application usage, such as:
|
+|App or product state|Information about Windows and application state, such as:
|
+|Purchasing|Information about purchases made on the device, such as:
|
+|Login properties|Information about logins on the device, such as:
|
+
+## Product and Service Performance data
+This type of data includes details about the health of the device, operating system, apps, and drivers. Product and Service Performance data is equivalent to ISO/IEC 19944:2017 8.2.3.2.2 EUII Telemetry data.
+
+### Data Use for Product and Service Performance data
+
+**For Diagnostics:**
+[Pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
+
+- Data about the reliability of content that appears in the [Windows Spotlight](https://docs.microsoft.com/en-us/windows/configuration/windows-spotlight) (rotating lock screen images) is used for Windows Spotlight reliability investigations.
+
+- Timing data about how quickly Cortana responds to voice commands is used to improve Cortana listening peformance.
+
+- Timing data about how quickly the facial recognition feature starts up and finishes is used to improve facial recognition performance.
+
+- Data about when an Application Window fails to appear is used to investigate issues with Application Window reliability and performance.
+
+**With (optional) Tailored experiences:**
+If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Product and Service Performance data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users.
+
+- Data about battery performance on a device may be used to recommend settings changes that can improve battery performance.
+
+- If data shows a device is running low on file storage, we may recommend Windows-compatible cloud storage solutions to free up space.
+
+- If data shows the device is experiencing performance issues, we may provide recommendations for Windows apps that can help diagnose or resolve these issues. These may be free or paid apps.
+
+**Microsoft doesn't use crash and hang dump data to [personalize](#personalize), [recommend](#recommend), [offer](#offer), or [promote](#promote) any product or service.**
+
+### Data Description for Product and Service Performance data type
+|Sub-type|Description and examples |
+|- |- |
+|Device health and crash data|Information about the device and software health, such as:
|
+|Device performance and reliability data|Information about the device and software performance, such as:
|
+|Movies|Information about movie consumption functionality on the device. This isn't intended to capture user viewing, listening, or habits.
|
+|Music & TV|Information about music and TV consumption on the device. This isn't intended to capture user viewing, listening, or habits.
|
+|Reading|Information about reading consumption functionality on the device. This isn't intended to capture user viewing, listening, or habits.
|
+|Photos App|Information about photos usage on the device. This isn't intended to capture user viewing, listening, or habits.
|
+|On-device file query |Information about local search activity on the device, such as:
|
+|Entitlements |Information about entitlements on the device, such as:
|
+
+## Software Setup and Inventory data
+This type of data includes software installation and update information on the device. Software Setup and Inventory Data is a sub-type of ISO/IEC 19944:2017 8.2.3.2.4 Observed Usage of the Service Capability.
+
+### Data Use for Software Setup and Inventory data
+
+**For Diagnostics:**
+[Pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
+
+- Data about the specific drivers that are installed on a device is used to understand whether there are any hardware or driver compatibility issues which should block or delay a Windows update.
+
+- Data about when a download starts and finishes on a device is used to understand and address download problems.
+
+- Data about the specific Microsoft Store apps that are installed on a device is used to determine which app updates to provide to the device.
+
+- Data about the antimalware installed on a device is used to understand malware transmissions vectors.
+
+**With (optional) Tailored experiences:**
+If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Software Setup and Inventory data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
+
+- Data about the specific apps that are installed on a device is used to provide recommendations for similar or complementary apps in the Microsoft Store.
+
+### Data Description for Software Setup and Inventory data type
+|Sub-type|Description and examples |
+|- |- |
+|Installed Applications and Install History|Information about apps, drivers, update packages, or operating system components installed on the device, such as:
|
+|Device update information |Information about Windows Update, such as:
|
+
+## Browsing History data
+This type of data includes details about web browsing in the Microsoft browsers. Browsing History data is equivalent to ISO/IEC 19944:2017 8.2.3.2.8 Client side browsing history.
+
+### Data Use for Browsing History data
+
+**For Diagnostics:**
+[Pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [provide](#provide) and [improve](#improve) Windows 10 and related Microsoft product and services. For example:
+
+- Data about when the **Block Content** dialog box has been shown is used for investigations of blocked content.
+
+- Data about potentially abusive or malicious domains is used to make updates to Microsoft Edge and Windows Defender SmartScreen to warn users about the domain.
+
+- Data about when the **Address** bar is used for navigation purposes is used to improve the Suggested Sites feature and to understand and address problems arising from navigation.
+
+- Data about when a Web Notes session starts is used to measure popular domains and URLs for the Web Notes feature.
+
+- Data about when a default **Home** page is changed by a user is used to measure which default **Home** pages are the most popular and how often users change the default **Home** page.
+
+**With (optional) Tailored experiences:**
+If a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [personalize](#personalize), [recommend](#recommend), and [offer](#offer) Microsoft products and services to Windows 10 users. Also, if a user has enabled Tailored experiences on the device, [pseudonymized](#pseudo) Browsing History data from Windows 10 is used by Microsoft to [promote](#promote) third-party Windows apps, services, hardware, and peripherals to Windows 10 users. For example:
+
+- We may recommend that a user download a compatible app from the Microsoft Store if they have browsed to the related website. For example, if a user uses the Facebook website, we may recommend the Facebook app.
+
+### Data Description for Browsing History data type
+|Sub-type|Description and examples |
+|- |- |
+|Microsoft browser data|Information about **Address** bar and **Search** box performance on the device, such as:
|
+
+## Inking Typing and Speech Utterance data
+This type of data gathers details about the voice, inking, and typing input features on the device. Inking, Typing and Speech Utterance data is a sub-type of ISO/IEC 19944:2017 8.2.3.2.1 End User Identifiable information.
+
+### Data Use for Inking, Typing, and Speech Utterance data
+
+**For Diagnostics:**
+[Anonymized](#anon) Inking, Typing, and Speech Utterance data from Windows 10 is used by Microsoft to [improve](#improve) natural language capabilities in Microsoft products and services. For example:
+
+- Data about words marked as spelling mistakes and replaced with another word from the context menu is used to improve the spelling feature.
+
+- Data about alternate words shown and selected by the user after right-clicking is used to improve the word recommendation feature.
+
+- Data about auto-corrected words that were restored back to the original word by the user is used to improve the auto-correct feature.
+
+- Data about whether Narrator detected and recognized a touch gesture is used to improve touch gesture recognition.
+
+- Data about handwriting samples sent from the Handwriting Panel is used to help Microsoft improve handwriting recognition.
+
+**With (optional) Tailored experiences:**
+
+**Microsoft doesn't use Windows Inking, Typing, and Speech Utterance data for Tailored experiences.**
+
+### Data Description for Inking, Typing, and Speech Utterance data type
+|Sub-type|Description and examples |
+|- |- |
+|Voice, inking, and typing|Information about voice, inking and typing features, such as:
|
+
+## ISO/IEC 19944:2017-specific terminology
+This table provides the ISO/IEC 19944:2017-specific definitions for use and de-identification qualifiers used in this article.
+
+|Term |ISO/IEC 19944:2017 Reference |Microsoft usage notes |
+|-|-|-|
+|Provide |9.3.2 Provide |Use of a specified data category by a Microsoft product or service to protect and provide the described service, including, (i) troubleshoot and fix issues with the product or service or (ii) provide product or service updates.|
+|Improve |9.3.3 Improve |Use of a specified data category to improve or increase the quality of a Microsoft product or service. Those improvements may be available to end users.|
+|Personalize |9.3.4 Personalize |Use of the specified data categories to create a customized experience for the end user in any Microsoft product or service.|
+|Recommend |9.3.4 Personalize |“Recommend” means use of the specified data categories to Personalize (9.3.4) the end user’s experience by recommending Microsoft products or services that can be accessed without the need to make a purchase or pay money.
Use of the specified data categories give recommendations about Microsoft products or services the end user may act on where the recommendation is (i) contextually relevant to the product or service in which it appears, (ii) that can be accessed without the need to make a purchase or pay money, and (iii) Microsoft receives no compensation for the placement.|
+|Offer |9.3.5 Offer upgrades or upsell |Implies the source of the data is Microsoft products and services, and the upgrades offered come from Microsoft products and services that are relevant to the context of the current capability. The target audience for the offer is Microsoft customers.
Specifically, use of the specified data categories to make an offer or upsell new capability or capacity of a Microsoft product or service which is (i) contextually relevant to the product or service in which it appears; (ii) likely to result in additional future revenue for Microsoft from end user; and (iii) Microsoft receives no consideration for placement.|
+|Promote|9.3.6 Market/advertise/promote|Use of the specified data categories to promote a product or service in or on a first-party Microsoft product or service.|
+
+
+|Data identification qualifiers |ISO/IEC 19944:2017 Reference |Microsoft usage notes |
+|-|-|-|
+|Pseudonymized Data |8.3.3 Pseudonymized data|As defined|
+|Anonymized Data |8.3.5 Anonymized data|As defined|
+|Aggregated Data |8.3.6 Aggregated data|As defined|
\ No newline at end of file
diff --git a/windows/deployment/TOC.md b/windows/deployment/TOC.md
index d306bd8ea5..c2d63ceca8 100644
--- a/windows/deployment/TOC.md
+++ b/windows/deployment/TOC.md
@@ -15,6 +15,7 @@
### [Overview of Windows AutoPilot](windows-autopilot/windows-10-autopilot.md)
### [Windows 10 upgrade paths](upgrade/windows-10-upgrade-paths.md)
+#### [Windows 10 downgrade paths](upgrade/windows-10-downgrade-paths.md)
### [Windows 10 edition upgrade](upgrade/windows-10-edition-upgrades.md)
### [Windows 10 volume license media](windows-10-media.md)
diff --git a/windows/deployment/update/olympia/olympia-enrollment-guidelines.md b/windows/deployment/update/olympia/olympia-enrollment-guidelines.md
index 91d87362f3..7fc29c58f5 100644
--- a/windows/deployment/update/olympia/olympia-enrollment-guidelines.md
+++ b/windows/deployment/update/olympia/olympia-enrollment-guidelines.md
@@ -31,7 +31,7 @@ To request an Olympia Corp account, please fill out the survey at [https://aka.m
## Enrollment guidelines
-Welcome to Olympia Corp. Here are the steps to add your account to your PC.
+Welcome to Olympia Corp. Here are the steps needed to Enroll.
As part of Windows Insider Lab for Enterprise, you can upgrade to Windows 10 Enterprise from Windows 10 Pro. This upgrade is optional. Since certain features such as Windows Defender Application Guard are only available on Windows 10 Enterprise, we recommend you to upgrade.
@@ -43,7 +43,9 @@ Choose one of the following two enrollment options:
-### Keep your current Windows 10 edition
+### Set up an Azure Active Directory REGISTERED Windows 10 device
+
+- This is the Bring Your Own Device (BYOD) method - your device will receive Olympia policies and features, but a new account will not be created ([additional info]).(https://docs.microsoft.com/en-us/azure/active-directory/device-management-azuread-registered-devices-windows10-setup)
1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)).
@@ -77,7 +79,9 @@ Choose one of the following two enrollment options:
-### Upgrade your Windows 10 edition from Pro to Enterprise
+### Set up Azure Active Directory JOINED Windows 10 device
+
+- This method will upgrade your Windows 10 Pro license to Enterprise and create a new account ([additional info]).(https://docs.microsoft.com/en-us/azure/active-directory/device-management-azuread-joined-devices-setup)
1. Go to **Start > Settings > Accounts > Access work or school**. To see this setting, you need to have administrator rights to your PC (see [local administrator](https://support.microsoft.com/en-us/instantanswers/5de907f1-f8ba-4fd9-a89d-efd23fee918c/create-a-local-user-or-administrator-account-in-windows-10)).
diff --git a/windows/deployment/upgrade/upgrade-readiness-get-started.md b/windows/deployment/upgrade/upgrade-readiness-get-started.md
index ae10dbe161..8691c8f111 100644
--- a/windows/deployment/upgrade/upgrade-readiness-get-started.md
+++ b/windows/deployment/upgrade/upgrade-readiness-get-started.md
@@ -57,7 +57,6 @@ If you are not using OMS:
5. To add the Upgrade Readiness solution to your workspace, go to the **Solutions Gallery**. Select the **Upgrade Readiness** tile in the gallery and then select **Add** on the solution’s details page. The solution is now visible on your workspace. Note that you may need to scroll to find Upgrade Readiness.
-
### Copy your commercial ID key
Microsoft uses a unique commercial ID to map information from user computers to your OMS workspace. This should be generated for you automatically. Copy your commercial ID key in OMS and then deploy it to user computers.
@@ -85,7 +84,7 @@ To enable data sharing, whitelist the following endpoints. Note that you may nee
| `https://v10.vortex-win.data.microsoft.com` | Connected User Experience and Telemetry component endpoint for Windows 10 computers. User computers send data to Microsoft through this endpoint.
| `https://vortex-win.data.microsoft.com` | Connected User Experience and Telemetry component endpoint for operating systems older than Windows 10
| `https://settings-win.data.microsoft.com` | Enables the compatibility update to send data to Microsoft.
-| `https://adl.windows.com` | Allows the compatibility update to receive the latest compatibility data from Microsoft. |
+| `http://adl.windows.com` | Allows the compatibility update to receive the latest compatibility data from Microsoft. |
Note: The compatibility update KB runs under the computer’s system account.
diff --git a/windows/deployment/upgrade/windows-10-downgrade-paths.md b/windows/deployment/upgrade/windows-10-downgrade-paths.md
new file mode 100644
index 0000000000..d095a3d449
--- /dev/null
+++ b/windows/deployment/upgrade/windows-10-downgrade-paths.md
@@ -0,0 +1,160 @@
+---
+title: Windows 10 downgrade paths (Windows 10)
+description: You can downgrade Windows 10 if the downgrade path is supported.
+ms.prod: w10
+ms.mktglfcycl: deploy
+ms.sitesec: library
+ms.localizationpriority: high
+ms.pagetype: mobile
+author: greg-lindsay
+ms.date: 02/15/2018
+---
+
+# Windows 10 downgrade paths
+**Applies to**
+
+- Windows 10
+
+## Downgrading Windows 10
+
+This topic provides a summary of supported Windows 10 downgrade paths. You might need to downgrade the edition of Windows 10, for example, if an Enterprise license is expired.
+
+If a downgrade is supported, then your apps and settings can be migrated from the current edition to the downgraded edition. If a path is not supported, then a clean install is required.
+
+To perform a downgrade, you can use the same methods as when performing an [edition upgrade](windows-10-edition-upgrades.md).
+
+Downgrading from any edition of Windows 10 to Windows 7, 8, or 8.1 is not supported, unless you are performing a rollback of a previous upgrade. You also cannot downgrade from a later version to an earlier version of the same edition (Ex: Windows 10 Pro 1709 to 1703) unless the rollback process is used.
+
+>**Windows 10 LTSC/LTSB**: Due to [naming changes](https://docs.microsoft.com/en-us/windows/deployment/update/waas-overview#naming-changes), product versions that display Windows 10 LTSB will be replaced with Windows 10 LTSC in subsequent feature updates. The term LTSC is used here to refer to all long term servicing versions.
+
+>**Windows N/KN**: Windows "N" and "KN" SKUs follow the same rules shown below.
+
+### Supported Windows 10 downgrade paths
+
+>[!NOTE]
+>Edition changes that are considered upgrades (Ex: Pro to Enterprise) are not shown here. Switching between different editions of Pro is supported. This is not strictly considered an edition downgrade, but is included here for clarity.
+
+✔ = Supported downgrade path
+
+
+
+
+
+
+## Related Topics
+
+[Windows 10 deployment scenarios](../windows-10-deployment-scenarios.md)
+
+ Destination edition
+
+
+
+
+ Home
+ Pro
+ Pro for Workstations
+ Pro Education
+ S
+ Education
+ Enterprise LTSC
+ Enterprise
+
+
+ Starting edition
+
+
+ Home
+
+
+
+
+
+
+
+
+
+
+ Pro
+
+
+ ✔
+ ✔
+ ✔
+
+
+
+
+
+ Pro for Workstations
+
+ ✔
+
+ ✔
+ ✔
+
+
+
+
+
+ Pro Education
+
+ ✔
+ ✔
+
+ ✔
+
+
+
+
+
+ S
+
+ ✔
+ ✔
+ ✔
+
+
+
+
+
+
+ Education
+
+ ✔
+ ✔
+ ✔
+ ✔
+
+
+
+
+
+ Enterprise LTSC
+
+
+
+
+
+
+
+
+
+
+Enterprise
+
+ ✔
+ ✔
+ ✔
+ ✔
+ ✔
+
+
+
+[Windows upgrade and migration considerations](windows-upgrade-and-migration-considerations.md)
+[Windows 10 edition upgrade](windows-10-edition-upgrades.md)
+[Windows 10 upgrade paths](windows-10-upgrade-paths.md)
+
+
+
+
+
diff --git a/windows/deployment/upgrade/windows-10-edition-upgrades.md b/windows/deployment/upgrade/windows-10-edition-upgrades.md
index b139ec0d0a..f46f0eb146 100644
--- a/windows/deployment/upgrade/windows-10-edition-upgrades.md
+++ b/windows/deployment/upgrade/windows-10-edition-upgrades.md
@@ -91,6 +91,11 @@ You can run the changepk.exe command-line tool to upgrade devices to a supported
`changepk.exe /ProductKey
D = Edition downgrade; personal data is maintained, applications and settings are removed.
+
@@ -380,7 +381,8 @@ D = Edition downgrade; personal data is maintained, applications and settings ar
[Windows 10 deployment scenarios](../windows-10-deployment-scenarios.md)
[Windows upgrade and migration considerations](windows-upgrade-and-migration-considerations.md)
-[Windows 10 edition upgrade](windows-10-edition-upgrades.md)
+[Windows 10 edition upgrade](windows-10-edition-upgrades.md)
+[Windows 10 downgrade paths](windows-10-downgrade-paths.md)
diff --git a/windows/deployment/windows-10-enterprise-subscription-activation.md b/windows/deployment/windows-10-enterprise-subscription-activation.md
index f7f5d176dd..de3ae148a3 100644
--- a/windows/deployment/windows-10-enterprise-subscription-activation.md
+++ b/windows/deployment/windows-10-enterprise-subscription-activation.md
@@ -68,7 +68,7 @@ With Windows 10 Enterprise, businesses can benefit from enterprise-level securit
You can benefit by moving to Windows as an online service in the following ways:
1. Licenses for Windows 10 Enterprise are checked based on Azure Active Directory (Azure AD) credentials, so now businesses have a systematic way to assign licenses to end users and groups in their organization.
-2. Azure AD logon triggers a silent edition upgrade, with no reboot required
+2. User logon triggers a silent edition upgrade, with no reboot required
3. Support for mobile worker/BYOD activation; transition away from on-prem KMS and MAK keys.
4. Compliance support via seat assignment.
diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md
index 577476a9d9..2a5317a961 100644
--- a/windows/security/threat-protection/TOC.md
+++ b/windows/security/threat-protection/TOC.md
@@ -189,9 +189,6 @@
#### [Review events and errors on endpoints with Event Viewer](windows-defender-atp\event-error-codes-windows-defender-advanced-threat-protection.md)
### [Windows Defender Antivirus compatibility with Windows Defender ATP](windows-defender-atp\defender-compatibility-windows-defender-advanced-threat-protection.md)
-
-## [Windows Defender Antivirus in Windows 10](windows-defender-antivirus\windows-defender-antivirus-in-windows-10.md)
-### [Windows Defender AV in the Windows Defender Security Center app](windows-defender-antivirus\windows-defender-security-center-antivirus.md)
## [Windows Defender Antivirus in Windows 10](windows-defender-antivirus\windows-defender-antivirus-in-windows-10.md)
### [Windows Defender AV in the Windows Defender Security Center app](windows-defender-antivirus\windows-defender-security-center-antivirus.md)
diff --git a/windows/security/threat-protection/change-history-for-threat-protection.md b/windows/security/threat-protection/change-history-for-threat-protection.md
index 9c6c3d0c31..4fd99aa471 100644
--- a/windows/security/threat-protection/change-history-for-threat-protection.md
+++ b/windows/security/threat-protection/change-history-for-threat-protection.md
@@ -12,6 +12,12 @@ ms.date: 10/31/2017
# Change history for threat protection
This topic lists new and updated topics in the [Threat protection](index.md) documentation.
+## February 2018
+
+New or changed topic | Description
+---------------------|------------
+[Security Compliance Toolkit](security-compliance-toolkit-10.md) | Added Office 2016 Security Baseline.
+
## January 2018
|New or changed topic |Description |
|---------------------|------------|
diff --git a/windows/security/threat-protection/security-compliance-toolkit-10.md b/windows/security/threat-protection/security-compliance-toolkit-10.md
index 06f04138ac..28676d4b1b 100644
--- a/windows/security/threat-protection/security-compliance-toolkit-10.md
+++ b/windows/security/threat-protection/security-compliance-toolkit-10.md
@@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.localizationpriority: high
ms.author: sagaudre
author: brianlic-msft
-ms.date: 10/16/2017
+ms.date: 02/16/2018
---
# Microsoft Security Compliance Toolkit 1.0
@@ -32,6 +32,9 @@ The Security Compliance Toolkit consists of:
- Windows Server 2016
- Windows Server 2012 R2
+- Microsoft Office Security Baselines
+ - Office 2016
+
- Tools
- Policy Analyzer tool
- Local Group Policy Object (LGPO) tool
diff --git a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
index 6ab49143bd..75dda71497 100644
--- a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
+++ b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
@@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: security
author: tedhardyMSFT
-ms.date: 10/27/2017
+ms.date: 02/16/2018
---
# Use Windows Event Forwarding to help with intrusion detection
@@ -636,9 +636,9 @@ Here are the minimum steps for WEF to operate:
-